Okta 400 Login Failed GENERAL_NONSUCCESS
Upon sign-in to Okta, presented with 400: Bad Request Error Code: GENERAL_NONSUCCESS
This error is presented alongside ADFS integrations.
Okta
ADFS
Expired CertificateÂ
TID-W
ADFS certificate has expired or is close to expiring
Changes to the ADFS certificate can also trigger this error. The ADFS system can auto-generate newer certificates. When this happens, the older one is displaced and the newer one is set as the Primary certificate, and the Primary certificate in ADFS is what Okta looks for
Expired Secret Value in Azure AD
Obtain the new ADFS certificate
Access the ADFS server with an administrative account.
Log in to the ADFS Management Console.
Expand the Service Certificates folder.
Right-click the certificate under Token-signing in the Certificates pane > View Certificate
Details > Copy to File
Select Base-64 encoded X.509 (.CER) as the format
Next > Enter the certificate file name and the location to export it to > Finish
Contact Tyler Systems Management Support or log a case via the Online Support Client Portal
If the ADFS certificate is not public-facing, it will need to be sent securely to Tyler to update.