PCI Compliance SAML Integration with Okta

This article describes the typical Okta IdP SSO-initiated SAML 2.0 integration with Qualys.

Ensure you create a new Qualys application and avoid using community-created applications. When sending the SAML assertion response to Qualys, you can use SHA1 or SHA256 as the signing algorithm. If you are doing an IdP-initiated SSO SAML 2.0 integration, leave the Default Relay State field blank.

Perform the following steps to configure Okta for SSO integration with Qualys:

  1. Log in to Okta. 
  2. Click Applications.

  3. Select Create App Integration.
  4. Select SAML 2.0.

  5. Provide the application certificates to Qualys Support. 
  6. Follow the on-screen instructions to configure your SSO application.

    Example: SAML Configuration for US POD1.
     

Refer to the following table for more information on SAML configuration.

Attribute Description
Single Sign on URL PCI Platform: (username: xxxx_xx)
PCI Platform: https://pci.qualys.com/IdM_UUID/saml2/
Audience URI (IdP Entity ID) QualysPCI_SharedPlatform-SAML20-IdP
Default Relay State idm_key in case of IdP initiated SSO.
idm_key=saml2_xxxxxxxxxx
Name ID format Unspecified
Application Username Okta username
Response Signed
Assertion Signature Signed
Signature Algorithm RSA SHA1/SHA2
Digest Algorithm SHA1
Assertion Encryption Unencrypted
Enable Single Logout Depending on user requirements
Authentication Context Class Password Protected Transport
Request Compression Compressed
Honor Force Authentication Yes
SAML USer ID http://www.okta.com/$(org.externalKey)
Attribute Statement (Optional) This is a mandatory field for successful authentication:
  • Name: external_id
  • Name format: Basic
  • Value: user.email