Vulnerability Scanners Flag the Okta SSO IWA Certificate as Untrusted
Last Updated:
Overview
Vulnerability scanners may flag the Secure Sockets Layer (SSL) certificate labeled "Okta SSO IWA Certificate" in the Internet Information Services (IIS) Personal Certificate Store of the Integrated Web Authentication (IWA) Agent server as untrusted due to its self-signed nature. IWA Agent-based Desktop Single Sign-On (DSSO) requires this certificate for basic functionality, preventing its removal while in use. Administrators must configure Agentless DSSO to migrate away from IWA DSSO if the environment requires the removal of the certificate.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Directories
- Active Directory (AD)
- Integrated Web Authentication (IWA)
- Desktop Single Sign-On (DSSO)
- IWA Single Sign-On (SSO) Agent
Cause
The IWA Agent installer installs this self-signed certificate by default. Vulnerability scanners flag this certificate as untrusted due to its self-signed nature.
Solution
Why is the Okta SSO IWA Certificate required?
IWA Agent-based DSSO relies on this certificate for basic functionality. The certificate cannot be removed while IWA Desktop SSO is in use.
Configure Agentless DSSO to Remove the Certificate
Administrators must configure Agentless DSSO to migrate away from IWA DSSO if the environment requires the removal of the certificate.
