<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Using a Third-Party WAF With Okta Managed Certificates for Custom Domains

Okta Classic Engine
Okta Identity Engine
Custom URL Domains

Overview

Administrators must switch the certificate source type and manually manage the Transport Layer Security (TLS) certificate on both the Web Application Firewall (WAF) and Okta when a custom domain uses a third-party WAF. The Okta-managed certificate fails during renewal because the Canonical Name (CNAME) record no longer points directly to Okta.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Custom Domains
  • Certificates

Cause

The Okta-managed certificate fails during renewal because the CNAME record no longer directs traffic to Okta, which is a requirement for Okta to automatically manage and renew the certificate.

Solution

How is a third-party WAF configured with a custom domain?

If the architecture requires an external WAF to inspect or filter traffic before it reaches the Okta login pages, administrators must switch the certificate source type. Generate a custom TLS certificate externally, upload the certificate and private key to the third-party WAF, and upload the exact same certificate chain to the Okta Admin Console.

  1. Navigate to Customizations, then Brands, and then Domains in the Okta Admin Console.
  2. Upload the externally managed TLS certificate chain.

 

NOTE: Because administrators use a custom certificate instead of an Okta-managed certificate, they must manually update the certificate on both the WAF and Okta before expiration.

 

Loading
Using a Third-Party WAF With Okta Managed Certificates for Custom Domains | Okta Support