01-12-2023 11:04 AM
Hello! I've had PaloAlto/Okta captive portal authentication working for awhile now. I recently upgraded Okta to Okta Identity Engine, and also upgraded my PA to the latest 10.x.x version. One of those upgrades appears to have broken the Okta/PA integration. SP initiated authentications STILL WORK. IDP initiated authentications do NOT WORK - they redirect to Okta for entering credentials, and then hang on the re-direct back to the PA. i.e, they hang on:
https://xxxxxxxx.okta.com/login/token/redirect?stateToken=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
The Okta logs show only successful authentications, and no errors. Thus Okta support says the issue is outside of their control.
Any suggestions?
Thank you!
01-18-2023 03:54 PM
I opened a case with PA about this and it turns out that broken OKTA SAML authentication is a known bug PAN-OS 10.2.3 (version I'm on)!
PA engineering is working on a fix. PAN-OS 10.2.4 / 11.0.1 is the target fix version, with an ETA is "TBD"....
01-18-2023 03:54 PM
I opened a case with PA about this and it turns out that broken OKTA SAML authentication is a known bug PAN-OS 10.2.3 (version I'm on)!
PA engineering is working on a fix. PAN-OS 10.2.4 / 11.0.1 is the target fix version, with an ETA is "TBD"....
01-26-2023 01:46 PM - edited 01-26-2023 01:47 PM
FYI the Okta doc about setting up PA CaptivePortal SSO (https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-CaptivePortal.h...) currently states that Idp-Initiated is not supported. Not sure if that has always been there or is something new just for this issue.
Quote:
SP-initiated flows are supported.
IdP-initiated flows and Just In Time (JIT) Provisioning are not supported.
01-26-2023 08:38 PM
Hmm, very interesting. It has worked for me for years, and is set up following the standard procedure Okta outlines for integration. I suspect this must be a tacit acknowledgment of the bug. Update from PA support on this is that the fix is supposed to be released sometime in March....
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!