<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000ARIFuVSQXOkta Classic EngineOkta Integration NetworkAnswered2024-03-08T00:44:18.000Z2021-02-08T14:53:34.000Z2021-02-11T17:29:16.000Z

JohnPaulT.67567 (Customer) asked a question.

AES encryption for Okta Kerberos authentication

Has anyone completed the actions found in the link below yet? Were there any additional steps taken besides enabling the service account for AES encryption? Our concern is once this change is made, are there going to be kerberos ticket issues or will we be required to reboot all clients to generate a new ticket with AES. We are trying to plan for worse case scenario, primary with O365. Thanks!

 

https://support.okta.com/help/s/article/Configuration-Steps-to-Update-to-AES-Due-to-End-of-Life-RC4-HMAC-MD5-Encryption-for-ADSSO-and-Silent-Activation?language=en_US


  • User15905896560008893663 (Vendor Management)

    There were several successful changes made with no problems being reported after the event. Most of them, like yours, wanted some additional information, and after doing the changes, reported no issues.

    There was an instance where the service account user name and the AD user account name didn't match, and the agentless DSSO failed with a GSS_ERR. When this happens, you are returned to the default sign on-page and a GSS_ERR error appears in the SysLog. The service account user name and the AD user account are case sensitive and must match.

    Expand Post
    Selected as Best
  • User15905896560008893663 (Vendor Management)

    There were several successful changes made with no problems being reported after the event. Most of them, like yours, wanted some additional information, and after doing the changes, reported no issues.

    There was an instance where the service account user name and the AD user account name didn't match, and the agentless DSSO failed with a GSS_ERR. When this happens, you are returned to the default sign on-page and a GSS_ERR error appears in the SysLog. The service account user name and the AD user account are case sensitive and must match.

    Expand Post
    Selected as Best
This question is closed.
Loading
AES encryption for Okta Kerberos authentication