---
title: "EasySSO SAML with Okta"
canonical: "https://www.techtime-initiative.com/space/EasySSO/6029475/EasySSO%20SAML%20with%20Okta"
format: markdown
---
Step-by-Step Instructions to configure EasySSO SAML with Okta as an Identity Provider

> ℹ️ This guide assumes you have access to an Okta Workforce Identity platform, access to your Okta Admin dashboard, and some experience with the platform

> Macro (toc)

## Step 1: create app integration in Okta

Navigate to Applications on your Okta Admin Dashboard, and click `Create App Integration`. Select Sign-in method "SAML 2.0", and click `Next`

![image-20240829-233035.png](media://f3759591-ee4b-4334-a700-1f654b4fc450)

![image-20240829-233049.png](media://8fe7dbdf-c91b-4fe1-9a42-7ea297c3ed28)

In "App name" enter a name for your integration (e.g. EasySSO Jira), and click `Next`

![image-20240829-233139.png](media://d5a1d424-f8ac-44b3-9009-4b3a709fbf27)

Under "Single sign on URL", enter your EasySSO Endpoint URL. Under "Audience URI", enter your EasySSO Entity ID. Both are found in your EasySSO SAML configuration screen.

![image-20240829-233202.png](media://1bca2b8e-64de-496a-8c60-38c47f2fd6a9)

## Optional step: Enable message signing and verification

Click `Show Advanced Settings`, change the Signature Algorithm to "RSA-SHA1", and the Digest Algorithm to "SHA1"

![image-20240829-233449.png](media://de8e2074-3810-415f-8bfb-ed0bcffa35e1)

In the EasySSO Configuration screen, ensure "Enable SAML" is checked to ensure you can modify the settings. 

![image-20240829-233735.png](media://b50588ef-5cf5-4b44-8177-072ab1524e76)

Go to the Certificates tab, and under SP Signing Certificate click `Generate Certificate`

![image-20240829-233802.png](media://bfa2ae68-7d6b-465e-bafb-41b6c61f7eb1)

- Copy the certificate and paste it into a new certificate file on your computer (e.g. spsigningcertificate.crt)
- Upload the SP Signing Certificate file to Okta using the "Browse files..." button next to "Signature Certificate"
- Click `Allow Application to initiate Single Logout`

![image-20240829-234048.png](media://acaeefd1-5fc3-462d-be0a-88ed5653ed74)

- Copy and paste the EasySSO Endpoint URL in the "Single Logout URL" field
- Copy and paste the EasySSO EntityID in the SP Issuer field
- Enable "Validate SAML requests with signature certificates"

![image-20240829-234123.png](media://d7f7cad9-a5b2-491d-bbbd-b1c859d0098d)


## Step 2: Configure attribute statements

Under **Attribute Statements**, add the following statements:

1. Username
  1. Name: urn:oid:0.9.2342.19200300.100.1.1
  2. Name Format: Unspecified
  3. Value: user.login
2. Email
  1. Name: urn:oid:0.9.2342.19200300.100.1.3
  2. Name Format: Unspecified
  3. Value: user.email
3. First Name
  1. Name: urn:oid:2.5.4.42
  2. Name Format: Unspecified
  3. Value: user.firstName
4. Last Name
  1. Name: urn:oid:2.5.4.4
  2. Name Format: Unspecified
  3. Value: user.lastName

At the bottom of the page, click `Next`

![image (5).png](media://b3e405e3-97cd-440a-88de-1527a7126e53)

You may see an Okta support form. Select "I'm an Okta customer adding an internal app" and click `Finish` 

![OktaEasySSO1.jpg](media://ef25d4fa-8a7f-43d2-b93f-6c7503d866bb)

> ⚠️ Make sure you have assigned the application to users or groups in Okta to enable them to sign-in to your application

## Step 3: Configure EasySSO Side

Navigate to the "Sign On" section of your Okta Application. Copy the Metadata URL

Note: you can click "View SAML setup instructions" to also find this URL, as well as the variables and metadata to configure EasySSO manually

![OktaEasySSO2.jpg](media://d722b6b1-cdd9-48ce-999c-a120f093ab88)

Visit the EasySSO SAML configuration screen, and make sure "Enable SAML" is ticked. On the "Certificates" page, ensure "URL" is selected for "Load Metadata"

Paste the Okta Metadata URL in the "Idp Metadata URL" field, and click "Load Certificate" to load the metadata.

![OktaEasySSO3.jpg](media://8ca4cba2-5438-4955-ac00-7bc817e75af3)

Navigate to the General page. You should see the required fields have now been filled.  

1. Set the "Login Binding Type" to either "POST" or "Redirect" - the Binding URL should have been configured by the Okta metadata
2. Set the "Logout Binding Type" to "POST", "Redirect", or "Disabled" - if the Logout Binding Type is not Disabled, the Logout URL should have been configured by the Okta metadata
3. Set the "Entity ID" to the "Identity Provider Issuer" URL under step 2 of the Okta Setup Instructions page

(Optional) Visit [EasySSO SAML Message Signing and Verification](https://techtime.co.nz/display/TECHTIME/EasySSO+SAML+Message+Signing+and+Verification) for signing and verification configuration options

Press `Save` at the bottom of the page

![OktaEasySSO4.jpg](media://07e5c5a3-6e7b-4ed6-858c-e87c325130f1)

## Encrypted Assertions (Optional)

### EasySSO Service Provider

1. Open the EasySSO Admin page
2. Click the SAML button to be taken to the SAML Admin configuration
3. Check the 'Encrypt Assertions' check box
4. Click the Save button at the bottom of the page to save the updated configuration
5. Click the 'Certificates' tab
6. Copy the contents of the sp certificate text box into a new file and save it with the name of 'myeasyssosp.crt'

### In Okta

1. Open your SAML Administration page
2. Open the SAML Client configuration
3. Click the Assertion Encryption dropdown and select 'Encrypted'
  1. Set Encryption Algorithm to AES256-GCM
  2. Set Key Transport Algorithm to RSA-OAEP
4. Upload the SP Certificate file previously saved ('myeasyssosp.crt')

![image-20240829-235244.png](media://45bbc3b9-a61c-4158-9e86-d756dcb61cfe)

## More Configuration

You've completed the configuration of EasySSO SAML with OKTA!

For more customisation options, check out [EasySSO with SAML - Configuration](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4948647).