- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-12-2023 11:04 AM
Hello! I've had PaloAlto/Okta captive portal authentication working for awhile now. I recently upgraded Okta to Okta Identity Engine, and also upgraded my PA to the latest 10.x.x version. One of those upgrades appears to have broken the Okta/PA integration. SP initiated authentications STILL WORK. IDP initiated authentications do NOT WORK - they redirect to Okta for entering credentials, and then hang on the re-direct back to the PA. i.e, they hang on:
https://xxxxxxxx.okta.com/login/token/redirect?stateToken=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
The Okta logs show only successful authentications, and no errors. Thus Okta support says the issue is outside of their control.
Any suggestions?
Thank you!
01-18-2023 03:54 PM
I opened a case with PA about this and it turns out that broken OKTA SAML authentication is a known bug PAN-OS 10.2.3 (version I'm on)!
PA engineering is working on a fix. PAN-OS 10.2.4 / 11.0.1 is the target fix version, with an ETA is "TBD"....
01-18-2023 03:54 PM
I opened a case with PA about this and it turns out that broken OKTA SAML authentication is a known bug PAN-OS 10.2.3 (version I'm on)!
PA engineering is working on a fix. PAN-OS 10.2.4 / 11.0.1 is the target fix version, with an ETA is "TBD"....
01-26-2023 01:46 PM - edited 01-26-2023 01:47 PM
FYI the Okta doc about setting up PA CaptivePortal SSO (https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-CaptivePortal.h...) currently states that Idp-Initiated is not supported. Not sure if that has always been there or is something new just for this issue.
Quote:
SP-initiated flows are supported.
IdP-initiated flows and Just In Time (JIT) Provisioning are not supported.
01-26-2023 08:38 PM
Hmm, very interesting. It has worked for me for years, and is set up following the standard procedure Okta outlines for integration. I suspect this must be a tacit acknowledgment of the bug. Update from PA support on this is that the fix is supposed to be released sometime in March....
02-16-2023 01:09 PM
A few months back I updated to 10.2.x, then my CP seemed to break using SAML to Ping. I went back to 10.1.x. I just saw in 10.2.3-h4, (PAN-210513) they fixed a CP SAML issue. Maybe that is your fix and maybe mine as well, will need to re-update and test later. Maybe if you test it first, reply and let us know if that addresses your issue.
02-16-2023 06:51 PM - edited 02-16-2023 06:52 PM
Yes I noticed that too. I updated to 10.2.3-h4 today, but it unfortunately did not fix the issue for me. The rep told me earlier that I'll have to wait until 10.2.4 for the fix.
02-17-2023 04:02 AM
unfortunate, guess i'll wait too before i try mine again, last time i did this i saw the redirect back to the PA and where it also hung and ended up needing to drive to office to restore.
03-31-2023 03:35 AM
I see 10.2.4 is out, if you get to test it and if fixes your issue, would like that feedback.
06-23-2023 04:37 AM
@pomologist - curious if you made the jump to 10.2.4-h2 and if that fixed your captive portal issue?
06-28-2023 12:59 AM
I'll be running the update in a couple weeks and will report at that time!
08-05-2023 10:34 AM
@pomologist - I updated to 10.2.4-h3 and that seemed to address my CP issues we saw in 10.2.2
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!