<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OKTA SSO Activation for Panorama &amp;amp; FWs attached to Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/okta-sso-activation-for-panorama-amp-fws-attached-to-panorama/m-p/1002999#M2739</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253410"&gt;@Yuvaraj.Karvekar&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to activate the Okta SSO login for the Panorama &amp;amp; individual FWs login too via Okta.&lt;/P&gt;
&lt;P&gt;I am having the Active Panorama login working with okta SSO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Somehow with same config on the passive panorama while login getting the following error message.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Error Displaying SAML error response page"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Same cert installed on both the Panorama . Active is working , Passive is not .&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Anything I like to check, missing please ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks &amp;amp; Best Regards&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Yuvi&lt;/STRONG&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253410"&gt;@Yuvaraj.Karvekar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It sounds like you're almost there with setting up Okta SSO for both Active and Passive Panorama! Here are a few things to check that might help resolve the issue:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL class="relative list-outside marker:text-foreground-750 dark:marker:text-foreground-600 flex flex-col ms-5 marker:normal-nums marker:text-sm-strong" start="1"&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Certificate Consistency&lt;/STRONG&gt;: Ensure that the SAML certificates on both the Active and Passive Panorama are identical. Even slight differences can cause inconsistencies.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="ps-2"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;SAML Settings&lt;/STRONG&gt;: Verify that all SAML settings, including the SAML response, are correctly configured on the Passive Panorama. Sometimes, an incomplete attribute statement can cause issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="ps-2"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Time Sync&lt;/STRONG&gt;: Ensure both active and passive devices are time-synchronized. SAML relies heavily on accurate timestamps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Log Review&lt;/STRONG&gt;: Check the Okta logs and Panorama system logs for detailed error messages that might give more insight into what's causing the issue.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;James Goff&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Sat, 11 Jan 2025 08:52:31 GMT</pubDate>
    <dc:creator>james589goff</dc:creator>
    <dc:date>2025-01-11T08:52:31Z</dc:date>
    <item>
      <title>OKTA SSO Activation for Panorama &amp; FWs attached to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/okta-sso-activation-for-panorama-amp-fws-attached-to-panorama/m-p/1002998#M2738</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to activate the Okta SSO login for the Panorama &amp;amp; individual FWs login too via Okta.&lt;/P&gt;
&lt;P&gt;I am having the Active Panorama login working with okta SSO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Somehow with same config on the passive panorama while login getting the following error message.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Error Displaying SAML error response page"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Same cert installed on both the Panorama . Active is working , Passive is not .&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Anything I like to check, missing please ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks &amp;amp; Best Regards&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Yuvi&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2025 08:06:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/okta-sso-activation-for-panorama-amp-fws-attached-to-panorama/m-p/1002998#M2738</guid>
      <dc:creator>Yuvaraj.Karvekar</dc:creator>
      <dc:date>2025-01-11T08:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: OKTA SSO Activation for Panorama &amp; FWs attached to Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/okta-sso-activation-for-panorama-amp-fws-attached-to-panorama/m-p/1002999#M2739</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253410"&gt;@Yuvaraj.Karvekar&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to activate the Okta SSO login for the Panorama &amp;amp; individual FWs login too via Okta.&lt;/P&gt;
&lt;P&gt;I am having the Active Panorama login working with okta SSO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Somehow with same config on the passive panorama while login getting the following error message.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Error Displaying SAML error response page"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Same cert installed on both the Panorama . Active is working , Passive is not .&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Anything I like to check, missing please ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks &amp;amp; Best Regards&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Yuvi&lt;/STRONG&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253410"&gt;@Yuvaraj.Karvekar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It sounds like you're almost there with setting up Okta SSO for both Active and Passive Panorama! Here are a few things to check that might help resolve the issue:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL class="relative list-outside marker:text-foreground-750 dark:marker:text-foreground-600 flex flex-col ms-5 marker:normal-nums marker:text-sm-strong" start="1"&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Certificate Consistency&lt;/STRONG&gt;: Ensure that the SAML certificates on both the Active and Passive Panorama are identical. Even slight differences can cause inconsistencies.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="ps-2"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;SAML Settings&lt;/STRONG&gt;: Verify that all SAML settings, including the SAML response, are correctly configured on the Passive Panorama. Sometimes, an incomplete attribute statement can cause issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="ps-2"&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Time Sync&lt;/STRONG&gt;: Ensure both active and passive devices are time-synchronized. SAML relies heavily on accurate timestamps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Log Review&lt;/STRONG&gt;: Check the Okta logs and Panorama system logs for detailed error messages that might give more insight into what's causing the issue.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;James Goff&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sat, 11 Jan 2025 08:52:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/okta-sso-activation-for-panorama-amp-fws-attached-to-panorama/m-p/1002999#M2739</guid>
      <dc:creator>james589goff</dc:creator>
      <dc:date>2025-01-11T08:52:31Z</dc:date>
    </item>
  </channel>
</rss>

