STIGQter STIGQter: STIG Summary: Okta Identity as a Service (IDaaS) Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Okta must be configured to use only DOD-approved certificate authorities.

DISA Rule

SV-273207r1098888_rule

Vulnerability Number

V-273207

Group Title

SRG-APP-000427

Rule Version

OKTA-APP-001920

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the Admin Console:
1. Go to Security >> Identity Providers.
2. Click "Add identity provider."
3. Click "Smart Card IdP". Click "Next".
4. Enter the name of the identity provider.
5. Build a certificate chain:
- Click "Browse" to open a file explorer. Select the certificate file to add and click "Open".
- To add another certificate, click "Add Another" and repeat step 1.
- Click "Build certificate chain". On success, the chain and its certificates are shown. If the build failed, correct any issues and try again.
- Click "Reset certificate chain" if replacing the current chain with a new one.
6. In "IdP username", select the "idpuser.subjectAltNameUpn" attribute. This is the attribute that stores the Electronic Data Interchange Personnel Identifier (EDIPI) on the CAC.
7. In the "Match Against" field, select the Okta Profile Attribute in which the EDIPI is to be stored.

Check Contents

From the Admin Console:
1. Select Security >> Identity Providers (IdPs).
2. Review the list of IdPs with "Type" as "Smart Card".

If the IdP is not listed as "Active", this is a finding.

3. Select Actions >> Configure.
4. Under "Certificate chain", verify the certificate is from a DOD-approved CA.

If the certificate is not from a DOD-approved CA, this is a finding.

Vulnerability Number

V-273207

Documentable

False

Rule Version

OKTA-APP-001920

Severity Override Guidance

From the Admin Console:
1. Select Security >> Identity Providers (IdPs).
2. Review the list of IdPs with "Type" as "Smart Card".

If the IdP is not listed as "Active", this is a finding.

3. Select Actions >> Configure.
4. Under "Certificate chain", verify the certificate is from a DOD-approved CA.

If the certificate is not from a DOD-approved CA, this is a finding.

Check Content Reference

M

Target Key

5694