Okta Advanced Server Access and Okta Privileged Access SSH Prompts for Password When Using Hostname
Last Updated:
Overview
When attempting to SSH from a jump host to an Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA) enrolled server, a password prompt appears. This occurs because the provided server hostname does not match the name present in the Okta platform, causing the client to fall back to a standard SSH flow. Resolve this by using the correct server name from the Okta dashboard or by configuring a canonical name in the server daemon configuration file.
<user>@jumphost:~$ sft ssh <servername>
<user>@<server>'s password:
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
- Okta Privileged Access (OPA)
Cause
The provided server hostname does not match the server name present in Okta Advanced Server Access or Okta Privileged Access. When the server name is absent from the Okta platform, the client defaults to a standard SSH flow and prompts for a password.
Solution
What steps identify the correct server name?
Identify the correct server name present in the Okta platform using the administrator dashboard or the command line interface.
- Check the server name in the project from the Okta Advanced Server Access or Okta Privileged Access administrator dashboard.
- Run
sft loginfollowed bysft list-serversfrom any client machine to view the available server names.
What steps configure a canonical name for the server?
Override the default hostname by configuring a canonical name in the server daemon configuration file and restarting the service.
- Open the
/etc/sft/sftd.yamlfile on the target server. - Add the entry
CanonicalName: <server_hostname>to the file. - Restart the server daemon service to apply the changes.
