Okta Identity Provider Issuer URL Uses HTTP Instead of HTTPS in SAML Setup Instructions
Last Updated:
Overview
Administrators configuring a Security Assertion Markup Language (SAML) application often notice that the Identity Provider (IdP) Issuer URL uses HTTP instead of HTTPS. The HTTP designation does not affect security, as the Issuer ID in a SAML assertion serves as an identifier rather than a valid URL path. The value must match the service provider's expected value, and the Assertion Consumer Service (ACS) URL must always use SSL.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Identity Provider (IdP) Issuer URL
- Security Assertion Markup Language (SAML) Applications
Solution
Why does the Identity Provider Issuer URL use HTTP instead of HTTPS?
The Issuer or Identifier ID in a SAML assertion acts as a unique identifier and does not function as a valid URL path. The HTTP prefix in the Issuer URL does not relate to security protocols. The configured value must exactly match the service provider's expectations. Conversely, the ACS URL must always utilize SSL and function as a valid URL.
