<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Understanding the Certificate Renewal and Authority Change for ProofPoint Protection Server Certificates in Okta
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

This article explores the certificate renewal and certificate authority change of *.pphosted.com and *.gslb.pphosted.com for the application ProofPoint Protection Server found in Okta Integration Network (OIN). Notably, within the current user interface, there does not appear to be an option for altering the service provider's certificate. This has led to uncertainty regarding the need for backend modifications on the part of Okta. 

Applies To
  • ProofPoint Protection Server Certificate Renewal
  • Single Sign-On (SSO)
  • Service Provider (SP) Certificate Changes
Cause

Proofpoint's notification about a mandatory certificate renewal and change of certificate authority has raised questions, particularly for those utilizing the Okta Integration Network application. With no visible means to modify the service provider's certificate within the current Okta setup, users may wonder whether additional actions are needed on their end, or if Okta is making requisite changes on the backend.

Solution

In instances where the ProofPoint Protection Server from the OIN catalog is in use, Okta functions as the Identity Provider (IdP). This setup does not necessitate any extra configuration that would require a certificate from the Service Provider. As such, it is likely that the certificate change will not affect ProofPoint Protection Server and Okta Integration.

Finally, it is important to emphasize that the SP Certificate is irrelevant in this context since the application integration does not support Single Log-Out (SLO). 

 

Related References

Loading
Understanding the Certificate Renewal and Authority Change for ProofPoint Protection Server Certificates in Okta