<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z000071SOWDCA4Okta Classic EngineSingle Sign-OnAnswered2021-06-21T13:06:59.000Z2021-06-17T16:28:05.000Z2021-06-21T13:06:59.000Z

JeremyH.86309 (Customer) asked a question.

Cisco AnyConnect SAML config error

Hi,

I am attempting to configure Okta SAML authentication on my Cisco ASA. I have done this 3 times on 3 other ASA's with no issue. This time when I am trying to configure the SSO server SAML I keep getting an error saying SAML IDP certificate failed.

 

I have already deleted and re-imported the cert. I also verified it is the same as the other 3 I configured. I have also deleted and recreated the Okta app.

 

Any idea on what could be causing this or where I could look to identify exactly why it is failing?

 

Thanks


  • User15730827840579969856 (Vendor Management)

    Cezar here.Please open a ticket with okta support so we can take a look at the logs, the flow and troubleshoot the issue.

  • JeremyH.86309 (Customer)

    1. Saying "Open a ticket" is not helpful for the community. It means that when other search for answers to this issue there is no discussion or possible solutions. Very poor service from someone labeled "Employee"
    2. I already had a ticket opened and already tried the "Look at the logs/flow etc" with Okta support. This was no help. There were no Okta log to inspect because the ASA could not use the Okta certificate to contact Okta. The ASA also did not have helpful logs showing why it failed. It simply shows the config commands I issues. If you had responded with at least the minimum amount of fact finding question you would know that.
    3. For anyone who searches this topic, I was able to resolve it. With Cisco OS being based on Linux/Unix it is case sensitive. During configuration I ended up with a trustpoint "Okta" and a trustpoint "okta". The no ca-check was applied to one and not the other. I am not sure exactly which caused the SAML IDP certificate fail error. Either the one Okta/okta trustpoint not having the no ca-check command or if it was because there were 2 Okta/okta trustpoints and when the ASA was trying to reach out it had mis-match issues. To fix it I removed both trustpoints completely and recreated the "okta" trust point with the no ca-check command included.

     

    I hope this is helpful for other Okta customers who want to use this community as a problem solving resource rather than just recieve the "Open a ticket" guidance.

    Expand Post
This question is closed.
Loading
Cisco AnyConnect SAML config error