<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008dHCqxCAGOkta Classic EngineAdministrationAnswered2024-08-07T09:00:17.000Z2023-01-06T09:55:16.000Z2023-01-10T21:56:26.000Z

afd68 (afd68) asked a question.

Devices without certificates still in managed status

Hi everyone,

 

We deployed certificates to have our devices managed (we are on OIE). We made a test, we deleted the certificate from the device and then we are still able to access to our applications and still have the managed status. how often certificates are checked on managed devices?

 

Thank you in advanced

Regards


  • Hello @afd68 (afd68)​ Thank you for reacting out to our Community!

     

    As per our doc below, the issue you are experiencing might be expected:

    " When you provide your own CA, Okta supports certificate revocation. Okta checks the certificate revocation list (CRL) for revoked or on-hold certificates, and then blocks those certificates from sending any management signals. Okta only supports CRL endpoints that use the HTTP or HTTPS protocol, and CRLs that are signed by the same intermediate certificate that the admin uploaded. The client certificate should also include the certificate distribution point uniform resource identifier (URI). When these conditions are met, Okta downloads the CRL, and then revokes any certificates that are on the CRL. The certificate revocation task occurs in a background process that runs a few times each day. When a certificate is marked as revoked, the client cannot use the certificate to set management status. Check your system log events, to see details about when a certificate is revoked.

    Manually delete intermediate CAs that are revoked by the root CA. These are not automatically deleted."

    https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/configure-ca-main.htm

     

    The Okta Community Catalysts Program is now live. Collect online badges when you participate in the Okta Help Center Questions community. Learn more here.

    Community members help others by clicking Upvote or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
  • Hello @afd68 (afd68)​ Thank you for reacting out to our Community!

     

    As per our doc below, the issue you are experiencing might be expected:

    " When you provide your own CA, Okta supports certificate revocation. Okta checks the certificate revocation list (CRL) for revoked or on-hold certificates, and then blocks those certificates from sending any management signals. Okta only supports CRL endpoints that use the HTTP or HTTPS protocol, and CRLs that are signed by the same intermediate certificate that the admin uploaded. The client certificate should also include the certificate distribution point uniform resource identifier (URI). When these conditions are met, Okta downloads the CRL, and then revokes any certificates that are on the CRL. The certificate revocation task occurs in a background process that runs a few times each day. When a certificate is marked as revoked, the client cannot use the certificate to set management status. Check your system log events, to see details about when a certificate is revoked.

    Manually delete intermediate CAs that are revoked by the root CA. These are not automatically deleted."

    https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/configure-ca-main.htm

     

    The Okta Community Catalysts Program is now live. Collect online badges when you participate in the Okta Help Center Questions community. Learn more here.

    Community members help others by clicking Upvote or Select as Best on responses. Try it today.

    Expand Post
    Selected as Best
This question is closed.
Loading
Devices without certificates still in managed status