<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Vulnerability Scanners Flag the Okta SSO IWA Certificate as Untrusted

Directories
All Engines
Okta Classic Engine
Okta Identity Engine

Overview

Vulnerability scanners may flag the Secure Sockets Layer (SSL) certificate labeled "Okta SSO IWA Certificate" in the Internet Information Services (IIS) Personal Certificate Store of the Integrated Web Authentication (IWA) Agent server as untrusted due to its self-signed nature. IWA Agent-based Desktop Single Sign-On (DSSO) requires this certificate for basic functionality, preventing its removal while in use. Administrators must configure Agentless DSSO to migrate away from IWA DSSO if the environment requires the removal of the certificate.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Directories
  • Active Directory (AD)
  • Integrated Web Authentication (IWA)
  • Desktop Single Sign-On (DSSO)
  • IWA Single Sign-On (SSO) Agent

Cause

The IWA Agent installer installs this self-signed certificate by default. Vulnerability scanners flag this certificate as untrusted due to its self-signed nature.

Solution

Why is the Okta SSO IWA Certificate required?

IWA Agent-based DSSO relies on this certificate for basic functionality. The certificate cannot be removed while IWA Desktop SSO is in use.

 

 

Configure Agentless DSSO to Remove the Certificate

Administrators must configure Agentless DSSO to migrate away from IWA DSSO if the environment requires the removal of the certificate.

 

 

Related References

Loading
Okta Support - Vulnerability Scanners Flag the Okta SSO IWA Certificate as Untrusted