<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Access Gateway Reserved Attribute Names

Access Gateway
Okta Classic Engine
Okta Identity Engine

Overview

Okta Access Gateway (OAG) reserves specific attribute names for internal functionality, preventing their reuse in custom configurations. When an administrator attempts to use a reserved attribute name, Okta displays a warning message in the web interface. Configuring a non-reserved attribute name and adding a proxy header directive in the relevant policies resolves this issue when the backend application requires a reserved value as the header name.

 

Attribute must not be a reserved word


Attribute must not be a reserved word

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Access Gateway (OAG)
  • Header Attributes

Cause

Okta reserves specific attribute names for internal product functionality. Because an attribute name requires a unique identifier, Okta restricts these internal names from being assigned to new attributes.

Solution

What attribute names are reserved in Okta Access Gateway?

The following list contains the reserved attribute names that Okta restricts from reuse.

  • UserName
  • oag_username
  • RemoteIP
  • RelayDomain
  • Remote_user
  • SESSIONID
  • creationTime
  • maxInactiveInterval
  • maxActiveInterval
  • lastAccessedTime
  • USER_AGENT
  • SourceAuthNType

 

If the backend application requires a reserved value as the header name, how can OAG send it?

Change the attribute name to a non-reserved value and add a proxy header directive in the relevant policies to send a reserved value as the header name.

  1. Change the attribute Name value to something that's not reserved.
  2. Note the position of the attribute in the ordered list (for example, 1st, 2nd, 3rd, and so on).
  3. In all relevant policies, add a proxy_set_header directive with the reserved name as the field and $_N as the value, where N is the position of the attribute on the attributes page.
    • For example, if remote_user is the 3rd attribute configured:
      proxy_set_header remote_user $_3;
Loading
Okta Access Gateway Reserved Attribute Names | Okta Support