<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Does Okta Support SAN Certificates when Using an Okta CA for SCEP Challenges
Okta Classic Engine
Okta Identity Engine
Administration
Overview

When an Okta Certificate Authority (CA) issues a certificate via Simple Certificate Enrollment Protocol (SCEP), the Common Name/Subject is populated, but the Subject Alternative Name (SAN) extension cannot be set. This article details whether it is possible to get the "Subject Alternative Name Value" to populate the SAN extension in the certificate.

Applies To
  • Device Trust
  • Certificates
  • Simple Certificate Enrollment Protocol (SCEP)
Cause
The Okta CA does not support issuing certificates with SAN (Subject Alternative Name) extensions.
Solution

If certificates with a populated SAN extension are desired, use your own certificate authority (CA).  To accomplish this, see Option 2: Provide your own CA section from the Configure a Certificate Authority documentation.

Loading
Does Okta Support SAN Certificates when Using an Okta CA for SCEP Challenges