<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006cne04SAAOkta Classic EngineSingle Sign-OnAnswered2024-04-02T16:02:14.000Z2019-09-06T17:34:29.000Z2019-09-23T22:37:39.000Z

RobM.62038 (Customer) asked a question.

Does okta support EncryptedAssertion in an inbound federation scenario?

I am currently attempting to integrate a client that uses a third-party IdP into our SP. Login is failing. The okta logs are indicating the following failures:

  • Authenticate user via IDP failure: Unknown Profile Attribute
  • Authenticate user via IDP failure: User Not Found
  • Authenticate user via IDP failure: Unable to match transformed username.

The details within these events don't point me in any particular direction (E.g. What was the unknown profile attribute?)

My Identity Provider is using NameId to determine the okta user but I can't find a NameId in the saml-tracer output for the response message. I see that the IdP's response contained an EncryptedAssertion. Does okta support this out of the box? If so, how do I configure the IdP for this?


This question is closed.
Loading
Does okta support EncryptedAssertion in an inbound federation scenario?