This section explains how to configure Okta as an IdP using version 2024.01.2 C for reference purposes only. Please be advised that the options displayed herein are subject to the version utilized. It is recommended to verify the specific features and functionalities of Okta relevant to the version currently in use for accurate configuration.
Avi Load Balancer as SP and Okta as IdP
The sequence of events from the user access request is illustrated here:
Configuring Okta as IdP
Login to the Okta developer account with admin access and click the Applications dropdown.
Select Applications and click Create App Integration.
-
Click SAML 2.0 to connect Okta with the SAML application and click Next.
Enter the App name. Click Next,
In SAML Settings, provide the SSO URL in the format
https://SPresource/sso/acs/
, for example, https://sales.avi.com/sso/acs/ and the Audience URI must be same as Entity ID. Click Next.
Note:The trailing slash (/) after acs is mandatory.
Ensure that the SSO URL and Entity ID are the same in the IDP configuration and Avi Load Balancer configuration.
-
Configure the optional settings, as required and click Next,
Choose the relevant options in the n
Click Finish.
Configuring Metadata
Under the Sign on tab, the metadata details are available.
Copy theMetadata URL and paste it as IDP Metadata URL in the SAML auth Profile in Avi Load Balancer.
Alternatively, copy the Metadata URL to your browser to access the metadata file. Copy the metadata and paste it as IDP Metadata in the SAML auth profile in Avi Load Balancer.
Assign the Apps to Users
To assign the apps to the local users, groups, or AD users,
Click the Assignments tab.
Click the Assign dropdown and select Assign to People or Assign to Groups, as required. In this example. Assign to People is selected.
To assign to a specific user, search for the user and click Assign.
4. Click Done.
This completes the process of creating an application on Okta.
Once configuration is complete on Okta, configure an Avi Load Balancer virtual service to act as service provider. For more information, see SAML Configuration on Avi Load Balancer.