Duo Security Authentication
Important Duo Security Certificate Authority Changes
Cisco Duo is replacing its root certificate authority (CA) bundle. The impact on you depends on the application type configured in your Duo Admin Panel. Follow the steps below:
Determine your Application Type
In the Duo Admin Panel, go to Applications > Applications and check the Application Type column.
| Application Type | Action |
|---|---|
| Delinea Secret Server |
Minimal—Duo granted an automatic extension until March 31, 2026 |
| Auth API, Web SDK, or other custom application | Urgent—authentication failures may begin February 2, 2026 |
If You Have a Published Secret Server
Secret Server uses Windows certificate validation, not embedded certificate pinning. Secret Server Cloud integrations require no changes. Secret Server On-Premises integrations continue to function as long as the web server receives regular Windows Updates to maintain current root CA certificates.
If You Have a Custom Application
Administrators using custom applications, such as Auth API or Web SDK, must take one of the following actions to avoid authentication failures:
- Either contact Duo (support@duo.com) to request an extension.
- Or switch to the published Delinea Secret Server application in the Duo Admin Panel, and update the credentials in Secret Server at Admin > Configuration > Login > Duo.
Key Dates
| Date | Event |
|---|---|
| February 2, 2026 | Intermittent authentication failures begin for custom applications |
| March 31, 2026 | Duo rotates CA roots; servers with outdated root certificates fail to connect |
For details, see Duo's knowledge base article.
Setup
Task 1: Create a Duo Application Representing Your Secret Server (Admin)
-
Sign up for a new Duo account, or log in to an existing one at Duo Security.
-
Under Applications, create a new application of the DelineaSecret Server type. Name the application as you wish.
-
Record the API hostname, integration key, and secret key from the new Duo application you just created.
Task 2: Configure Secret Server to Use Duo (Admin)
-
Open the Administration page in Secret Server.
-
Under Login, select Duo.
-
Click Edit.
-
Select the Enable Duo Integration check box.
-
Enter the API Hostname, Integration Key, Use RADIUS Username for DUO, and Secret Key values.
-
Click Save.
-
Search for Users to create a test user. The Users page appears.
-
Click the Create New button. The Add User window appears:
-
Click the Two Factor dropdown list and select Duo.
-
Type or select the other parameters for the new user.
-
Log on as the test user. If there are multiple two-factor devices available, you will be prompted to select one. If you are un-enrolled you will be given a link to perform self-enrollment. You are contacted via the Duo app, SMS, or a phone call for the second factor.
-
Add or configure actual users one at a time or by using bulk operations.
Task 3: Setting up Duo (User)
-
Log on to Secret Server.
-
After successful authentication, a new screen appears with the option to select a method to authenticate with.
-
Select one of the options (Duo Push, Send SMS, or Phone), depending on your setup with Duo) and complete the selected authentication process to log in.
