Configure SAML SSO between DigiCert and Okta
This guide walks you through setting up Single Sign-On (SSO) between your DigiCert® account and Okta using SAML 2.0.
You'll switch between DigiCert and Okta tabs to exchange metadata and URLs. Once setup is complete, users in your account can sign in to DigiCert using their Okta credentials, either from the Okta dashboard or the DigiCert sign-in page.
For more details about Okta configuration, refer to Okta Help Center.
Before you begin
To complete this setup, you need administrative access in both DigiCert and Okta:
Account admin user group required in DigiCert account.
Application Administrator or equivalent role required in Okta.
Access DigiCert's SAML configuration page and copy the SSO URL:
In DigiCert® account, select the Accounts icon > Sign-in methods.
Select Single sign-on with SAML.
In the Connect DigiCert to your IdP section, copy the SSO URL.
Leave this window open.
In another tab, create a SAML application for your DigiCert account in Okta:
Sign in to your Okta Admin dashboard.
Go to Applications > Applications.
Select Create App integration:
Select SAML 2.0 as the Sign-on method.
Select Next.
Enter DigiCert® account as the App name.
Optional: Add a logo to the App logo field.
On the Configure SAML tab, complete the following fields:
Paste the SSO URL that you copied in Step 1 into both of the following fields:
Single sign-on URL
Audience URI (SP Entity ID)
In the Name ID Format field, select Email address.
In the Application username field, select Email.
Select Next.
Select Finish.
Create the Okta metadata file that you'll need to provide to DigiCert in Step 3:
Select the Sign On tab > View SAML setup instructions.
In the Optional section, copy the IdP metadata.
Paste the IdP metadata into a notepad and save the file in
.xmlformat.
Leave this window open.
Back in your DigiCert® account tab, upload the Okta metadata that you created in Step 2 and enable SSO:
In the Connect your IdP to DigiCert section, select Upload metadata.
In the Enable/Disable SSO with SAML section, switch to enable SSO.
Select Save configuration.
Ensure that all users in your DigiCert account are assigned to the SAML application in Okta Admin dashboard:
Go to Applications > Applications.
Select DigiCert account app you just created.
Select the Assignments tab.
Select Assign > Assign People.
Next to the user's name, select Assign.
Select Save and Go Back.
Select Done.
Verify that you are able to sign in using your SAML application from Okta Admin dashboard:
In the top right corner, select ∷ > My end user dashboard.
Select the DigiCert account app that you just created.
Tip
Your SAML app is configured correctly if you are redirected to DigiCert account and asked to complete two-factor authentication (2FA).
If you are not redirected to the 2FA page in DigiCert account, please compare your app settings to the instructions above or contact DigiCert support for assistance.
DigiCert logos
Use of DigiCert's logo must at all times comply with DigiCert brand guidelines, including the DigiCert Trademark Usage Guidelines available at https://www.digicert.com/legal-repository/ (as updated from time to time).


DigiCert logo's for SSO configuration.