Skip to main content

Cyware Threat Intelligence eXchange

Add Subscribers Using Okta

If you are using Okta for authentication in your organization, you can add subscribers to CTIX using Okta. You can set up synchronization with your Okta account so that all the users in your Okta account are automatically added to the CTIX application as subscribers. You have to configure a few sequences of steps on Okta and then add the subscribers into the CTIX application.

Before you Start

You must have access to Okta.

Steps

Configure the following setups in Okta to sync with CTIX:

Configure Custom User Attributes in Okta

You can configure certain subscriber-related attributes such as Organization Type, Confidence, STIX collection, Allowed IP address, and organization name as custom attributes to your Okta users. You must do this configuration on the Okta platform. After you add these custom attributes, you will get an option to specify these values to your Okta users.

Steps

  1. Sign in to your Okta account as an administrator.

  2. In the Okta Admin Console, open Directory, and select Profile Editor.

  3. In Users, select Okta under Filters.

  4. Click Okta User (default) profile, and click Add Attribute.

  5. To add Confidence as a custom attribute, do the following:

    1. Select number as Data type.

    2. Enter Confidence in the Display name.

    3. Enter confidence as the Variable name.

    4. Select Attribute required.

    5. Click Save and Add Another to add more attributes.

  6. To add Organization Type as a custom attribute, do the following:

    1. Select string array as the Data type.

    2. Enter Organization Type as the Display name.

    3. Enter organization_type as the Variable name.

    4. Select Define enumerated list of values to add the organization type names present in CTIX to Okta.

      1. In Display name, enter the organization type. This must be the same as the organization type defined in CTIX. It is case-sensitive.

      2. In Value, enter the value for organization type. This must be the same as the organization type defined in CTIX. It is case-sensitive.

      3. Click + Add Another to add more organization types.

    5. Click Save and Add Another to add more attributes.

  7. To add the STIX collection as a custom attribute, do the following:

    1. Select string array as the Data type.

    2. Enter STIX Collection as the Display name.

    3. Enter stix_collection as the Variable name.

    4. Select Define enumerated list of values to add the organization type names present in CTIX to Okta.

      1. In Display name, enter the STIX collection names. This must be the same as the STIX collection defined in CTIX. It is case-sensitive.

      2. In Value, enter the value for the STIX collection. This must be the same as the STIX collection defined in CTIX. It is case-sensitive.

      3. Click + Add Another to add more STIX collections.

    5. Click Save and Add Another to add more attributes.

  8. To add Allowed IP address as a custom attribute, do the following:

    1. Select string array as the Data type.

    2. Enter Allowed IP as the Display name.

    3. Enter allowed_ip as the Variable name.

    4. Select Define enumerated list of values to add the organization type names present in CTIX to Okta.

      1. In Display name, enter the Allowed IP names. This must be the same as the Allowed IPs defined in CTIX. It is case-sensitive.

      2. In Value, enter the value for the Allowed IP. This must be the same as the Allowed IPs defined in CTIX. It is case-sensitive.

      3. Click + Add Another to add more Allowed IPs.

    5. Click Save and Add Another to add more attributes.

  9. To add the Organization name as a custom attribute, do the following:

    1. Select string as the Data type.

    2. Enter Organization Name as the Display name.

    3. Enter organization_name as the Variable name.

    4. Click Save.

Add Users in Okta

Add users into Okta and define the subscriber-related attributes such as Organization Type, Confidence, STIX collection, Allowed IP address, and Organization Name. Optionally, you can also edit your existing users and associate them with these custom attributes.

  1. In the Okta Admin Console, open Directory, and select People.

  2. Click Add person and fill the form for the user.

  3. Enter values for the subscriber-related attributes such as Organization Type, Confidence, STIX collection, Allowed IP address, and organization name for the user.

  4. Click Save and Add Another to add more users.

  5. Click Save.

Generate API Token in Okta

You must generate an API token for your Okta user on the Okta platform.

Before you Start

You must have administrator privilege on Okta to perform API call actions.

Steps

  1. In the Okta admin console, open Security and select API.

  2. In Tokens, click Create Token.

  3. Enter a name for your token, and click Create Token.

  4. Copy the token and retain it to configure the Okta subscriber sync in CTIX.

After you close the screen, you cannot get the token again.

Configure Okta Sync in CTIX

To automatically add Okta users as subscribers to CTIX, configure Okta Sync in CTIX.

Before you Start

  • You must have View Subscribers, Create Subscribers, and Update Subscribers permissions to access the Subscribers module.

  • You should have generated an API token in Okta.

Steps

  1. Sign in to CTIX.

  2. From Administration, select Integration Management, and select Subscribers under FEED CONSUMERS.

  3. Click the ellipsis on the top right corner of the screen, next to Add Subscriber, and select OKTA Sync.

  4. Select Enable Okta Sync.

  5. Enter the base URL of your Okta account.

  6. Enter the Okta generated API token.

  7. Enter the frequency in seconds that you want CTIX to connect to Okta and fetch your users.

  8. Select Alert and select the internal applicants that receive the alert whenever subscribers are fetched and which subscribers are fetched into the CTIX application.

  9. Click Test Connectivity to test if the connection with your Okta account has been successful.

  10. Click Save.

All the subscribers that are fetched into CTIX are sent an email with the TAXII URLs.