Integrating Zabbix SSO (SAML) with Okta And Cloudflare Zero Trust (OIDC)
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

This article addresses a common issue that occurs when integrating Zabbix with Okta and Cloudflare Zero Trust. The problem arises when the custom domain setup in Okta is made after the Cloudflare Zero Trust integration. Consequently, Zabbix uses the custom domain Single Sign-On (SSO) URL, causing double authentication due to different session cookies. This issue can also occur in reverse order.

Applies To
  • Zabbix (SAML)
  • Cloudflare Zero Trust (OIDC)
  • Custom Domain
  • Single Sign-On (SSO)
Cause

The issue stems from the discrepancy in session cookies. When authentication to Zero Trust is performed via the Okta Default and Zabbix uses the custom domain, two distinct session cookies are generated. However, both domains lead to the same Okta tenant.

Solution

To resolve this issue in Zabbix, follow these steps:

  1. Navigate to Administration/Users (this may vary depending on the Zabbix version).
  2. Select Authentication.
  3. Go to SAML Settings.
  4. In the SSO service URL, the domain must be adjusted according to the specific setup.

By completing these steps, it should be possible to integrate Zabbix SSO with Okta and Cloudflare Zero Trust without the double authentication issue.

Recommended content

No recommended content found...