Using a Third-Party WAF With Okta Managed Certificates for Custom Domains
Last Updated:
Overview
Administrators must switch the certificate source type and manually manage the Transport Layer Security (TLS) certificate on both the Web Application Firewall (WAF) and Okta when a custom domain uses a third-party WAF. The Okta-managed certificate fails during renewal because the Canonical Name (CNAME) record no longer points directly to Okta.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Custom Domains
- Certificates
Cause
The Okta-managed certificate fails during renewal because the CNAME record no longer directs traffic to Okta, which is a requirement for Okta to automatically manage and renew the certificate.
Solution
How is a third-party WAF configured with a custom domain?
If the architecture requires an external WAF to inspect or filter traffic before it reaches the Okta login pages, administrators must switch the certificate source type. Generate a custom TLS certificate externally, upload the certificate and private key to the third-party WAF, and upload the exact same certificate chain to the Okta Admin Console.
- Navigate to Customizations, then Brands, and then Domains in the Okta Admin Console.
- Upload the externally managed TLS certificate chain.
NOTE: Because administrators use a custom certificate instead of an Okta-managed certificate, they must manually update the certificate on both the WAF and Okta before expiration.
