Managed OpenStack
Latest
Frequently Asked Questions
Solution
How To
Internal Only
Templates
Powered By

Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
OpenStack CLI Not Working With Okta MFA
Copy Markdown
Open in ChatGPT
Open in Claude
Problem
OpenStack CLI tends to not work with Okta Multi-Factor Authentication. The following error message is observed while running any OpenStack command with--debug option.
starting new HTTPS connection (1): *******.okta.comhttps://*******.okta.com:443 "POST /api/v1/authn HTTP/1.1" 200 NoneUser "username" password validates, checking second factorStarting new HTTPS connection (1): *******.okta.comhttps://*******.okta.com:443 "POST /api/v1/authn/factors/ost1hlvxdmcNbMSaD0h8/verify HTTP/1.1" 200 NoneUnable to obtain SAML assertion. Authentication failed or server error.Environment
- Platform9 Managed OpenStack - All Versions
- Okta, Google G Suite, One Login, Microsoft ADFS
Cause
Identity provider plugins do not support Multi-Factor Authentication for the command-line interface.
Resolution
We have two workarounds for this issue.
- Disable the MFA for the user in Okta or the identity provider plugin mentioned above.
- Instead of using SSO user-id, you can create a local user-id that can be used for accessing OpenStack through CLI.
VariableType to search · ESC to discard
GlossaryType to search · ESC to discard
InsertType to search · ESC to discard
No matches
Last updated on
Was this page helpful?
Next to read:
Host Unable to Converge Due to Untrusted Package ErrorDiscard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message