Step 3 – Download the Secure Access SP Metadata and Certificates
Download the Secure Access metadata files and use the service provider file to configure your instance of Okta.
The Secure Access service provider metadata includes the service provider Issuer ID, the assertion consumer endpoint URL, and the SAML request signing certificate from Secure Access. The Secure Access metadata is required when configuring your IdP.
|
Encrypted SAML assertions are a compliance standard in many industries and mitigate the risk of intercepted SAML assertions. For more information, see Prerequisites for SAML Authentication.
|
-
Check Manual Configuration.
-
Download the service provider files.
a. Click Download Service Provider XML file for the metadata XML file.
b. (Optional) To enable Secure Access to sign or encrypt the SAML communications, click Download Zip file.
-
Open the Cisco_SSE_SP_Metadata XML file.
a. The value of the
entityID
field issaml.fg.id.sse.cisco.com
, which is the same value that you copied in Step 2 – Select Okta SAML Identity Provider in Secure Access.b. Copy the value of
Location
,https://fg.id.sse.cisco.com/gw/auth/acs/response
.c. If you require a signing certificate, copy the value of
X509Certifcate
. -
Copy the certificates from the Cisco_SSE_SP_Metadata XML file to a new file and save. Use the certificate file in the next step when you create the app integration in Okta.