What is the change?
In Nov 2024, Okta released an LDAP agent that introduced new security improvements including adopting OIDC and Demonstrating Proof of Possession (DPoP). The updates to the LDAP agent secures the agent deployment and communication with Okta. This effort, a part of Okta’s Secure Identity Commitment, is aimed towards securing all Okta LDAP agents deployed by customers. Okta wants to ensure all Okta customers have at least upgraded their agents to an OIDC supported version (v5.22.0).
Okta has taken definitive steps to fight against identity based attacks as documented in Okta’s Secure Identity Commitment. Okta strongly recommends customers upgrade their LDAP agents to v5.22.0 or higher.
This includes investing in market-leading products and championing customer best practices for our 19,000+ customers.
As a part of this commitment, Okta has built and released key security improvements to our LDAP agent. The agent improvements make it secure to deploy and improve protection during agent to Okta communications. These changes were shipped as a part of Okta’s July 2024 Monthly release to the Okta LDAP Agent version 5.22.0.
- Cryptographically bound tokens with OIDC and DPoP
- Eliminate Okta Super Administrator dependency
- Device-based registration flow for new LDAP agents
With these improvements, Okta recommends customers to upgrade to the latest agent version to secure your LDAP agent and its communication with Okta.
Okta also recommends customers deploy a process to regularly upgrade Okta LDAP agents. Features such as LDAP Agent Auto-update allow ease of upgrade either through an update schedule or through one-click updates via Okta Admin Console.
How to upgrade to this new LDAP agent version?
-
Latest agent versions and notes are available at this site: Okta LDAP Agent version history
-
If you are currently using an LDAP agent version 5.16.0 or later, you can update your LDAP agent with one click via Okta admin console or set an auto-update schedule: Automatically update Okta LDAP agents
-
Agent installation steps reflect the process for a new installation of the latest version of the LDAP agent: Install the Okta LDAP Agent
