<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

OAG: Password Protected SSL Certificate

Access Gateway
Okta Classic Engine
Okta Identity Engine

Overview

A password-protected certificate is not supported and cannot be used. A certificate without a password must be supplied and used to work with the Okta Access Gateway.

For more specific information, please see the Obtain certificates documentation.

Applies To

  • Okta Access Gateway (OAG)

Cause

If a password-protected certificate is used, a password prompt will be shown during the upload process. If this password is entered, it will work, but on a service restart or system reboot, the password will be required, and if it is not entered, it will bring the service down.

An error similar to below will be seen:

Enter PEM pass phrase: service: [emerg] cannot load certificate key "test.key": PEM_read_bio_PrivateKey() failed (SSL: error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 cipherfinal error error:2306A075:PKCS12 routines:PKCS12_item_decrypt_d2i:pkcs12 pbe crypt error error:0907B00D:PEM routines:PEM_read_bio_PrivateKey:ASN1 lib)

Solution

A certificate that is not password-protected will need to be generated and used. Since the signed certificate cannot be generated on OAG, admins will need to work directly with the authority issuing the certificate.
Loading
Okta Support - OAG: Password Protected SSL Certificate