<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Identity Provider Issuer URL Uses HTTP Instead of HTTPS in SAML Setup Instructions

Single Sign-On
Integrations
Okta Classic Engine
Okta Identity Engine

Overview

Administrators configuring a Security Assertion Markup Language (SAML) application often notice that the Identity Provider (IdP) Issuer URL uses HTTP instead of HTTPS. The HTTP designation does not affect security, as the Issuer ID in a SAML assertion serves as an identifier rather than a valid URL path. The value must match the service provider's expected value, and the Assertion Consumer Service (ACS) URL must always use SSL.


HTTP

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Identity Provider (IdP) Issuer URL
  • Security Assertion Markup Language (SAML) Applications

Solution

Why does the Identity Provider Issuer URL use HTTP instead of HTTPS?

The Issuer or Identifier ID in a SAML assertion acts as a unique identifier and does not function as a valid URL path. The HTTP prefix in the Issuer URL does not relate to security protocols. The configured value must exactly match the service provider's expectations. Conversely, the ACS URL must always utilize SSL and function as a valid URL.

 

Related References

Loading
Okta Identity Provider Issuer URL Uses HTTP Instead of HTTPS in SAML Setup Instructions | Okta Support