<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Advanced Server Access and Okta Privileged Access SSH Prompts for Password When Using Hostname

Advanced Server Access
Okta Classic Engine
Okta Identity Engine

Overview

When attempting to SSH from a jump host to an Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA) enrolled server, a password prompt appears. This occurs because the provided server hostname does not match the name present in the Okta platform, causing the client to fall back to a standard SSH flow. Resolve this by using the correct server name from the Okta dashboard or by configuring a canonical name in the server daemon configuration file.

 

<user>@jumphost:~$ sft ssh <servername>

<user>@<server>'s password:

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Advanced Server Access (ASA)
  • Okta Privileged Access (OPA)

Cause

The provided server hostname does not match the server name present in Okta Advanced Server Access or Okta Privileged Access. When the server name is absent from the Okta platform, the client defaults to a standard SSH flow and prompts for a password.

Solution

What steps identify the correct server name?

Identify the correct server name present in the Okta platform using the administrator dashboard or the command line interface.

  • Check the server name in the project from the Okta Advanced Server Access or Okta Privileged Access administrator dashboard.
  • Run sft login followed by sft list-servers from any client machine to view the available server names.

What steps configure a canonical name for the server?

Override the default hostname by configuring a canonical name in the server daemon configuration file and restarting the service.

  1. Open the /etc/sft/sftd.yaml file on the target server.
  2. Add the entry CanonicalName: <server_hostname> to the file.
  3. Restart the server daemon service to apply the changes.
Loading
Okta Advanced Server Access and Okta Privileged Access SSH Prompts for Password When Using Hostname | Okta Support