Connect Okta to PE
Connect to Puppet Enterprise (PE) to Okta so that users can log in to PE with their Okta credentials.
These steps assume you're familiar with common SAML terminology and the basic process to Connect a SAML identity provider to PE.
You must have an Okta instance. To test this process, you might request a development instance from the Okta Developer Portal.
Configure the Okta application
Configure settings in Okta to connect your Okta instance to Puppet Enterprise (PE).
Before you begin
Get URLs and the signing and encryption certificate required to
connect Okta to PE.What to do next
Connect to Okta in the PE consoleConnect to Okta in the PE console
Configure your Okta integration settings in the Puppet Enterprise (PE) console.
Before you begin
You need the URLs and certificate from the How to Configure SAML 2.0 for
Puppet Enterprise Application page (which appears after you Configure the Okta application). You also need to know the values of the
Signature Algorithm and Authentication context
class settings in Okta.What to do next
Configure RBAC for an Okta integrationConfigure RBAC for an Okta integration
In the PE console, connect Okta user groups to PE RBAC roles.
Test your Okta SSO connection
Make sure you can log in to PE with Okta.
- Log out of PE.
- Go to the PE login screen (home page) and click Sign in with Okta SSO.
- Log in to PE using your Okta credentials.
Results
If the configuration is correct, you'll be redirected to the PE status page. Make sure you have the correct
permissions.