<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7VFmSANOkta Classic EngineOkta Integration NetworkAnswered2024-04-30T09:18:25.000Z2017-08-17T21:45:31.000Z2020-09-30T15:27:23.000Z
  • justin.bergez (Regional Customer Success, Bay Area)

    Hi Ramanan,

     

    Thank you for your question!

     

    In the vast majority of SAML apps, Okta does not pass or handle certs for login flows, whether IdP or SP initiated, because we don't validate the signature on the inbound SAML request. We simply grab the request ID of it.

     

    I can confirm that there are some apps that require encryption for the message coming back to us. In that scenario, Okta would need to upload a cert provided by the SP, and does have the capability to do so.

     

    If you have additional questions or need further clarification, I would recommend opening a ticket with Okta Support.

     

    Justin M. Bergez

    Technical Support Engineer - Tier 2

    0EM2A000000cGA5

    Expand Post
  • fy3qt (fy3qt)

    "I can confirm that there are some apps that require encryption for the message coming back to us. In that scenario, Okta would need to upload a cert provided by the SP, and does have the capability to do so." - How is this done??

  • JustinB.99953 (Customer)

    There are two scenarios in which Okta would need to upload a cert provided by the SP:

    • OIN apps that explicitly detail requirements for uploading the SP's certificate in the Setup Instructions
    • Custom SAML apps that are configured for an encrypted assertion and/or Single Logout (SLO)

    For OIN, it would be included with the Setup Instructions. If there is no mention in the Setup Instructions, there is no need to upload the cert. For Custom SAML apps, it would be uploaded through Advanced Settings, when Assertion Encryption and/or Enable Single Logout are configured.

    Expand Post
  • TomH.74883 (Customer)

    Has there been any updates to Okta to allow SP signing? This is becoming more of a requirement from a security perspective.

This question is closed.
Loading
Can Okta support SP certificate import ?