Okta - SAML Relying Party Configuration - RSA Ready Implementation Guide
Originally Published: 2021-11-07
Last Modified: 2026-10-09

This article describes how to integrate RSA Cloud Access Service (CAS) with Okta using a SAML Relying Party. 

       

Configure CAS

  1. Sign in to the RSA Cloud Administration Console.

  2. Click Authentication Clients > Relying Parties.

    Authentication Clients menu with Relying Parties selected

  3. On the My Relying Parties page, click Add a Relying Party.

  4. In the Relying Party Catalog, click Add for Service Provider SAML.

    Relying Party Catalog with the Service Provider SAML option

  5. On the Basic Information page, enter a name for the application, and then click Next Step.

    RSA Basic Information page with Okta entered as the application name

  6. On the Authentication page, configure the following settings, and then click Next Step:

    1. Choose RSA manages all authentication.

    2. In the 2.0 Access Policy for Authentication drop-down list, select a previously configured access policy.

    RSA Authentication page with RSA manages all authentication selected

  7. On the Connection Profile page, under Data Input Method, click Enter Manually.

    Note: The ACS URL and SP Entity ID entered in the next step are temporary. After you configure Okta, import the Okta metadata to replace these values automatically.
  8. In the Service Provider section, configure the temporary values:

    1. For Assertion Consumer Service (ACS) URL, enter any valid URL.

    2. For Service Provider Entity ID, keep the default value.

    RSA Service Provider section with temporary ACS URL and Entity ID values

  9. In the SAML Response Protection section, choose IdP signs SAML assertions, and then click Download Certificate. Save the certificate for the Okta configuration.

    RSA SAML Response Protection settings and Download Certificate button

  10. Expand Advanced Configuration.

  11. In the User Identity section, configure the following settings:

    1. Identifier Type: Auto Detect

    2. Property: Auto Detect

    RSA User Identity settings with Auto Detect selected

  12. In the Statement Attributes section, add the following attributes:

    1. Attribute Name: firstName
      Attribute Source: Identity Source
      Property: givenName, or the equivalent first-name attribute in your directory

    2. Attribute Name: lastName
      Attribute Source: Identity Source
      Property: sn, or the equivalent last-name attribute in your directory

    3. Attribute Name: email
      Attribute Source: Identity Source
      Property: mail, or the equivalent email attribute in your directory

    RSA Statement Attributes configured for first name, last name, and email

  13. In the Identity Provider section, make a note of the Entity ID and Identity Provider URL. You need these values when you configure Okta.

  14. Click Save and Finish.

  15. Click Publish Changes, and wait for the operation to finish.
    After publishing, your application is now enabled for SSO. 

         

Configure Okta

Perform these steps to configure Okta.

Procedure

  1. Log in to the Okta Admin Console with an administrator account.

  2. In the left pane, browse to Security > Identity Providers and click Add Identity Provider.

    Add Identity Provider option in the Okta Admin Console

  3. Choose SAML 2.0 IdP from the list of available identity providers and click Next.

    SAML 2.0 identity provider option in Okta

  4. Enter a name for the RSA Cloud Access Service IdP.

    Name field for the RSA identity provider in Okta

  5. Under Authentication Settings, enter the following:

    • In the IdP Usage drop-down list, choose SSO only.
    • Clear Account matching with Persistent Name ID.

    Okta authentication settings for SSO only

  6. Under Account matching with IdP Username, enter the following:

    1. IdP username: Choose idpuser.subjectNameId in the drop-down list.
    2. Match against: Choose Email in the drop-down list. This field specifies which attribute of an existing Okta user is compared to the IdP username to determine whether an account link must be established. If an existing account link is found, no comparison is performed.
    3. If no match is found: Choose the action for authentication responses that do not match an existing user in the Okta organization.

    Account matching settings for the identity provider

  7. Under SAML Protocol Settings, enter the following and click Finish:

    1. IdP Issuer URI: Enter the Identity Provider URL obtained from the RSA configuration.
    2. IdP Single Sign-On URL: Enter the Identity Provider URL obtained from the RSA configuration.
    3. IdP Signature Certificate: Upload the certificate downloaded from RSA.
    4. Request Binding: Choose HTTP POST.
    5. Request Signature: If selected, Okta signs its AuthnRequest. CAS must then be configured to validate the Okta signing certificate.
    6. Request Signature Algorithm: Choose SHA-256.
    7. Response Signature Verification: Choose Response or Assertion. Okta accepts the required signature when either the response or assertion is signed.
    8. Response Signature Algorithm: Choose SHA-256.
    9. Okta Assertion Consumer Service URL: Choose Trust-specific to generate an ACS URL dedicated to the RSA SAML IdP trust.

    SAML protocol settings for the RSA identity provider in Okta

  8. After creating the IdP, under Summary, download the metadata for the Okta service provider.

    Download metadata option on the Okta identity provider Summary page

  9. Navigate to Identity Providers > Routing rules and click Add Routing Rule under the Routing Rules tab.

    Add Routing Rule option in Okta

  10. Enter the rule name, choose the newly created RSA IdP, and click Create rule.

    Routing rules define the conditions for requests that are routed to RSA. Conditions can use network zones, specific applications, or user domains.

    Okta routing rule configured to use the RSA identity provider

  11. Return to the RSA Cloud Administration Console and navigate to the Okta application you created.

  12. On the Connection Profile page, under Data Input Method, choose Import Metadata and upload the downloaded Okta metadata.

    Accept the changes. The imported metadata replaces the temporary values that were entered earlier.

The configuration is complete.