Okta Smart Card Validation Fails With Certificate Validation Failed Error
Last Updated:
Overview
When attempting to sign in using a Personal Identity Verification (PIV) or Common Access Card (CAC), Okta generates a certificate validation error due to an invalid trust chain or an expired certificate. Resolve this issue by verifying the certificate chain's validity and uploading the correct, complete Certificate Authority (CA) chain to the Okta Admin Console. Users experience the following error when selecting a certificate and entering a PIN to unlock it during the login process:
Certificate Validation failed. Try again by quitting the browser then selecting another certificate.
Access the Okta login page and select Sign in with PIV/CAC Card as shown in the following image.
Check the validity of the certificate as shown in the following image.
Although the certificate appears valid on the local machine, Okta generates the error upon login.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Personal Identity Verification (PIV) / Common Access Card (CAC)
- Smart Card Validation
Cause
This issue occurs when Okta cannot establish a trust path to a trusted root for the incoming user certificate. The following factors may cause this issue:
- An incomplete or outdated Certificate Authority (CA) chain configuration exists within Okta (for example, the Public Key Infrastructure (PKI) team deployed a new Intermediate Issuing CA that requires an upload to Okta).
- The individual smart card certificate expires, or the Certificate Revocation List (CRL) explicitly revokes it.
The following image displays an example of an incomplete certificate chain configured in Okta.
The following image displays the complete certificate chain containing the required additional intermediate CAs.
A missing intermediate certificate authority causes the certificate validation failure.
Solution
How is the certificate validation error resolved?
Validate the user certificate status and upload the complete, corrected PKI chain to the Okta Admin Console.
- Verify the user-level certificate validity. Ensure the affected user's smart card certificate has a valid Serial Number, remains within the active expiration window, and the PKI provider does not revoke it.
- Obtain the updated CA chain. Contact the internal PKI team or third-party CA provider to obtain the complete, updated cryptographic chain. This chain includes all Root and Intermediate CAs currently signing user smart cards.
- Navigate to Security > Identity Providers in the Okta Admin Console.
- Select the name of the specific Smart Card / PIV / CAC Identity Provider (IdP).
- Choose the Actions dropdown menu and select Edit.
- Select Configure....
- Navigate to the Certificate chain section and select Edit.
- Select Browse and upload the new, complete root/intermediate certificate bundle.
