Single Sign-On User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Size: px
Start display at page:

Download "Single Sign-On User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA"

Transcription

1 Single Sign-On User Guide 2018 Cvent, Inc 1765 Greensboro Station Place McLean, VA

2 Contents Single Sign-On User Guide... 3 Key Terms... 3 Features Using SSO to Login... 4 Meeting Planners and Survey Authors... 4 OnArrival... 5 Event Websites... 6 Meeting Request Forms...10 Portals...11 Contact Websites...13 Parked Reports...14 Working with SSO...15 Identity Provider Initiated Model...15 Configuration Requirements...16 Implementation Options User Interface (UI) Changes...18 Authentication Procedure

3 Single Sign-On User Guide Welcome to the Single Sign-On User Guide! Single sign-on (SSO) is Cvent s latest method for securing efficient access control. The purpose of SSO is to help you centralize and simplify your user experience. By acting as a central identity authenticator, SSO enables you to send your users directly to Cvent without forcing them to visit Cvent s login page. In this guide, you will learn the basic steps to setting up SSO within your account. In addition, the guide outlines the SSO standards Cvent supports, the configurations needed to add your SSO login details to an account, and the process of implementing SSO. For more information, please submit a case through the Cvent Community. This process relies on client systems to authenticate the user s credentials within their own system before the user is directed to Cvent s application. NOTE Key Terms Security Assertion Markup Language (SAML): An XML-based standard for exchanging authentication and authorization data between security domains. Identity Provider (IdP): The producer of assertions. Service Provider (SP): The consumer of assertions. Federated ID: An identifier that the client provides for the purpose of ensuring that IDs are consistent. 3

4 Features Using SSO to Login Hotels, Meeting Planners, and Survey Authors Endpoint In a Cvent production account, the endpoint of a meeting planner login should be: If you are setting up SSO in a sandbox environment, the endpoint should be: Note: Cvent will provide you with your account stub or a sandbox account upon request. RelayState An optional RelayState parameter can be included in the assertion. This determines the page on which the user will land after successfully logging into Cvent through SSO. For example, a user can be taken directly to an RFP that they received immediately after authenticating, rather than landing on their default homepage and manually navigating to that RFP. Provisioning SSO cannot be the mechanism for provisioning meeting planner users. This is a licensing restriction. You must manually provision these users. Assertion Attributes You can include the following attributes in your assertion payloads. The fields with an asterisk (*) are required: Note: The NameID of the assertion must match the Federated ID attribute when Federated SSO is being used or the Username attribute when Direct SSO is being used. User Field Federated ID Username* First Name* Last Name* Prefix Title Company Address* Address 1 Address 2 Address 3 City State Code Zip/Postal Code Country Code Attribute federated_id username first_name last_name prefix title company _address address1 address2 address3 city state_code postal_code country_code 4

5 Home Phone Work Phone Home Fax Work Fax Mobile Phone Pager Number User Custom Fields home_phone work_phone home_fax work_fax mobile_phone pager_number field_stub1 field1 Only required when configuring Federated SSO 5

6 OnArrival To enable SSO for OnArrival, you must have SSO for Meeting Planners already set up. If you already have it, contact your customer success consultant to setup SSO for OnArrival. If you do not have it, contact your customer success consultant to turn on SSO for your account. For more information on SSO for meeting planners, refer to page 4. To setup SSO for OnArrival, complete the following steps: 1. Create your unique subdomain. Only one subdomain per configuration is available. 2. Input the unique subdomain value into OnArrival to trigger the SSO request. 3. Notify your customer success consultant of the login interface URL. After you have notified your customer success consultant, you will be redirected back to OnArrival, and will be able to login. If your login credentials have been input incorrectly, you will receive an error message. If this occurs, retry your credentials and make sure they are typed in correctly. If they are correct and you are still receiving an error, contact your customer success consultant for assistance. 6

7 Event Websites With SSO, you can validate invitees prior to their registration for an event. You can also use SSO to send a full contact profile to Cvent. Note: This is only appropriate if your invitees are able to interact with your identity store. Endpoint The endpoint is consistent. This is where you submit your SAML assertion to have the user sign on: Note: Cvent will provide you with your account stub upon request. If you have been provisioned with a sandbox account for SSO testing, then the SAML consumption endpoint should be: Relaystate You need to define the RelayState in the assertion. This determines whether the invitee will be sent to the Registration page or the Summary page once the SSO is validated. The RelayState component can be dynamically generated by Cvent by enabling an external authentication process for the event using the URL that is generated by your Identity Provider system. To do this, open the event in Cvent and go to Events > Website & Registration > Website > Security. Then, under the Website Authentication section, select Use an external authentication process and enter the authentication URL. When someone arrives at the event website or attempts to register for the event (depending on which option is selected), Cvent will redirect that user to the login page and dynamically append the RelayState parameter to the URL. This will allow the same authentication URL to be utilized across all events. Note: If your invitees will determine their registration type by going through a custom process, make sure the Display personal information for invitees who arrive from a Cvent option is set to Yes. Assertion Attributes The SSO process for invitees varies from the process for meeting planners on page 4. For the invitee process, there is no Username, Federated ID, or Password attribute. The required fields are First Name, Last Name, Address, and Source ID. You can see the names of the contact profile attributes on page 7. Note: The NameID of the assertion must match the Address attribute. Required Fields first_name last_name _address source_id 7

8 Optional Fields Field Name Passing Parameter Max Length Contact Type Code reg_code 30 Prefix prefix 30 Designation designation 30 Middle Name middle_name 30 Nickname nickname 30 Company company 100 Title title 50 Home Address 1 home_address1 40 Home Address 2 home_address2 40 Home Address 3 home_address3 40 Home City home_city 40 Home State Code home_state_code unlimited Home Postal Code home_postal_code 25 Home Country Code home_country 3 Home Phone home_phone 30 Home Fax home_fax 30 Work Address 1 work_address1 40 Work Address 2 work_address2 40 Work Address 3 work_address3 40 Work City work_city 40 Work State Code work_state_code unlimited Work Postal Code work_postal_code 25 Work Country Code work_country 3 Work Phone work_phone 30 Work Fax work_fax 30 Mobile Phone mobile 30 Pager pager 30 Reference ID ref_id 100 Target Landing Page target ~ Internal Survey Question Fields question_code1 30 question_answer1 Custom Contact Fields* field_stub1 36 field1 300 Timestamp timestamp 10 Signature reg_signature unlimited 8

9 How do you assign names to contact custom fields? Here is an example of field_stub1 and field1, you can find the field stub in Admin > Account > Account and select Custom Contact Fields from the View dropdown. </Attribute> <Attribute Name= field_stub1 NameFormat= urn:oasis:names:tc:saml:2.0:attrname-format:basic > <AttributeValue xmlns:q5= p6:type= q5:string xmlns:p6= >ba2e1901-6efc-4b5c f0a5d</attributevalue> </Attribute> </Attribute> <Attribute Name= field1 NameFormat= urn:oasis:names:tc:saml:2.0:attrname-format:basic > <AttributeValue xmlns:q5= p6:type= q5:string xmlns:p6= >ClientValueHere</AttributeValue> </Attribute> 9

10 To add multiple user custom fields, you must specify each custom field counting up from field_stub1 with a corresponding field1 value. field_stub1 field_stub2 field_stub3 field1 field2 field3 What would one of these fields look like in an XML node? Here is an example of RegCode, which is used to determine which registration path an invitee is sent to: </Attribute> <Attribute Name= Reg_Code NameFormat= urn:oasis:names:tc:saml:2.0:attrname-format:basic > <AttributeValue xmlns:q5= p6:type= q5:string xmlns:p6= >GoldMember</AttributeValue> </Attribute> 10

11 Meeting Request Forms Cvent supports SSO for individual meeting request forms. Endpoint In a Cvent production account, the endpoint of a meeting request form should be: Note: Cvent will provide you with your account stub upon request. [Guest_Side_URL] is the link to the form. If you have been provisioned with a sandbox account for SSO testing, then the endpoint for the request form is: Relaystate Notice that the relaystate is referenced in the endpoint. For 80% of clients, this is not an issue. But 20% use SSO tools that need consistent endpoints. For these clients, the RelayState= portion can be dropped from the endpoint URL. However, it must be referenced in the SAM response. Provisioning Users of a request form can be provisioned via the SSO process. This alleviates the need to manually add or rely on API to add the users. Note: There is a flag that Cvent needs to activate for this to work. Profile Updating The user profile can be updated via the assertion except for the Federated ID, which is used to match. Administrators can also have their profiles updated via the assertion. Assertion Attributes This is identical to the list on page 4 for meeting planners. 11

12 Portals Cvent supports SSO for portals. Endpoint In a Cvent production account, the endpoint of a portal should be: id]?relaystate=[portal_url] Note: Cvent will provide you with your customer ID and Portal_URL upon request. Relaystate Notice that the relaystate is referenced in the endpoint. For 80% of clients, this is not an issue. But 20% use SSO tools that need consistent endpoints. For these clients, the RelayState= portion can be dropped from the endpoint URL. However, it must be referenced in the Relaystate Node of the assertion payload. Provisioning SSO cannot be the mechanism for provisioning portal users. This is a licensing restriction. You must manually provision these users. Profile Updating Portal users can have their profiles updated via the assertion. Assertion Attributes You can include the following attributes in your assertion payloads. The fields with an asterisk (*) are required: User Field Federated ID* Username* First Name* Last Name* Prefix Title Company Address* Address 1 Address 2 Address 3 City State Code Zip/Postal Code Country Code Home Phone Work Phone Home Fax Work Fax Mobile Phone Attribute federated_id login firstname lastname honorificprefix title company streetaddress streetaddress2 streetaddress3 city state zipcode countrycode homephone workphone homefax workfax mobilephone 12

13 Pager Number User Custom Fields* pager field_stub1 field1 13

14 Contact Websites Endpoint In a Cvent production account, the endpoint of a contact website should be: Note: Cvent will provide you with your account stub upon request. [Guest_Side_URL] is the link to the website. If you have been provisioned with a sandbox account for SSO testing, then the endpoint for the contact website is: Relaystate Notice that the relaystate is referenced in the endpoint. For 80% of clients, this is not an issue. But 20% use SSO tools that need consistent endpoints. For these clients, the RelayState= portion can be dropped from the endpoint URL. However, it must be referenced in the Relaystate Node of the assertion payload. Profile Updating Contacts can have their profiles updated through the assertion. Assertion Attributes Attributes are identical to those for event websites on page 7. The First Name, Last Name, and Address fields are required. If any of these fields are missing, the user will be redirected to the contact website s login page. Additional Info If someone s contact type has visibility rights to the website, you should direct them to the configured landing page. If someone s contact type does not have visibility rights to the website, you should direct them to the login page and display the existing No Access error message. 14

15 Parked Reports Note: You cannot use this feature to create users as you go. Endpoint In a Cvent production account, the endpoint of a parked report should be: The relaystate s URL (RelayState=[Guest_Side_URL]) will be the parked report s URL. Note: Cvent will provide you with your account stub upon request. [Guest_Side_URL] is the link to the parked report. If you have been provisioned with a sandbox account for SSO testing, then the endpoint for the parked report is: The parked report s URL will be RelayState=[Guest_Side_URL]. Relaystate Notice that the relaystate is referenced in the endpoint. For 80% of clients, this is not an issue. But 20% use SSO tools that need consistent endpoints. For these clients, the RelayState= portion can be dropped from the endpoint URL. However, it must be referenced in the Relaystate Node of the assertion payload. Profile Updating The Administrator profile can be updated via the assertion except for the Federated ID, which is used to match. Assertion Attributes This is identical to the list on page 4 for meeting planners. 15

16 Working with SSO Identity Provider Initiated Model Cvent s SSO method follows the identity provider (client) initiated model. Cvent acts as the SP, hosting the Cvent resource for which the user requests access. Using an HTTP POST binding technique, Cvent passes an SAML assertion through the user s web browser to a designated location in the Cvent application. The origin of the assertion is then verified via public/private key cryptography and used to determine the user s identity. If the process is successful, the user will be given access to the Cvent resource. The process: 1. The IdP requests credentials from the user. 2. The user provides valid credentials and is provided a local security context. 3. The user chooses to navigate to the remote resource (via a menu option or link to Cvent). 4. The IdP s SSO service builds a SAML assertion, signs it with an XML signature, and places it within a <Response> message. This message is placed in a HTML form as a hidden form control called SAMLResponse, and sent back to the user s browser. 5. The <Response> message is posted to a designated location on the SP (Cvent s) site. This either happens automatically through an auto-submit script, or manually through the action of the user. 6. The SP parses the <Response> message, validates the XML signature to verify the message origin, and captures the identity information from the assertion. The SP compares the identity information with its internal user records. If there is a match, a new local security context is created for the user within the SP site. 7. If the user has the proper authorization, then the user s browser is redirected to the Cvent resource. 16

17 Configuration Requirements To begin setting up SSO, you will need to provide Cvent with the following: Client Public Encryption Key Static HTML Custom Header Image Client Public Encryption Key This solution uses public/private key cryptography to authenticate the origin of the SAML assertion. To verify a message s signature value, the client must provide Cvent with the public key of their public/private key pair. The public key will be used to sign the assertion message. It should be delivered as a certificate represented in Base64. Provide your assigned Cvent Client Services personnel with a text version of the X509 node from your certificate. Example: <X509Certificate>JI2C/jCCAeagAwIBAgIQYOXU5SeLuK5HTzuRHv7lWTANBgkqhkiG9w0BAQsFADA7MTkwNwY- DVQQDEzBBREZTIFNpZ25pbmcgLSBkZWhlci5mZWRlcmF0aW9uLmFkaWRhcy1ncm91cC5jb20wHhcNMTEw- NDE4MjAwMzIwWhcNMTIwNDE3MjAwMzIwWjA7MTkwNwYDVQQDEzBBREZTIFNpZ25pbmcgLSBkZWhlci5m- ZWRlcmF0aW9uLmFkaWRhcy1ncm91cC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDlABIySzAkx+uDvHnw1Lv8lqdvUq5sMbwUHIBTynEtW82Bpsz6H+Ta0ACTKAr6QFzoviLKtiMY6n/4o4wT16eC1We7VowrcFTlhhjCDNrmO4E1SROT6C70lHg8GCvagy6rkcni/2vmX3dMgsmjbjcLsW2H80aQp2x2XufsuKeSBKweuqd- COTLgfpR+Ka94bH4C+0NxDbRhJkJREJuu3Y5hDJ/B0jw1MNgJBeFbfDWQkW94GccxadI8j8rCr8XmV5yP7YTiqjD/ BDu5X6TqPaBQa+6NDYmjRaTngZ3CzbR1GRbG3MZ2Cz+9kKvU87F/oFMpEx+mp9I2Pe5FDUpP4AbfAgMBAAEwD- QYJKoZIhvcNAQELBQADggEBAH5udTVcGT6eJmzqz3kqAn/XR8LyTsxceIU0EdROy8HRrU8rryKBawtk+vKM8/JLC7X- N4oFJ6B4c0RrEC0GLDs/aldN2zGaMJl+M5pCjhUU1kQS+sW6TXypZ5zaPE1Lqac2NdA2JuQUUjGNd82zTmtIOM/jwEKLSO/ mwe1lm24cbswzy0+c92v1qvrea7yebi0bs9ojkbv7x1pou9+hdvhxcgrkyoi6oc6cl2rhlu4dgplz+a08v/yy0agh97/4bxnoffrhikudtg47wcsxhjy9kb6ad4cm3mwq+mthg3vsdhyfluzsdz2/bktbgumdsuwuw4xzyecqjjftkekoohl=</x509certificate> Static HTML At the time of configuration, the client will provide static HTML blocks that will be displayed in Cvent for the following scenarios: Login Page: If users attempt to access the application from the Cvent login page, they will see a static page with a link redirecting them to an internal page. This page should explain why they cannot access the application, tell them what to do next, and provide a link to an internal site. Logout Page: When users click Logout, they will no longer be directed to the Cvent login page. Instead, they will be directed to an internal SSO login page when attempting to log back in. Timeout Page: Cvent can redirect SSO users to a predefined timeout page if their browser sessions expire. Clients must provide Cvent with a link to the page that users will be redirected to when such a timeout happens. Custom Header Image By default, the Cvent header image will be displayed on all static HTML and error pages. If a client would like to customize this header, a URL of an image must be provided during SSO configuration. Recommended Size: 800 px x 90 px is the standard size recommended for a custom header. Restrictions: The header images cannot be written in JavaScript or contained in a Flash file. 17

18 Implementation Options You will also need to choose the following for your configuration: SSO Solution: SAML 1.1 or 2.0 Client Public Encryption Key: SHA-1 or SHA-256 Cvent Login Page: Disable the Cvent login page or keep it active Certificate Name: Only needed if you are using multiple certificates SSO Solution The Cvent application supports two types of standard SSO solutions: SAML 1.1 SAML 2.0 Each solution has a different way of determining the origin of the SSO message and acquiring the user s identification. SAML 1.1 and SAML 2.0 are incompatible with each other and use different processes for authentication. Refer to the appropriate procedure in this guide when beginning the configuration process. NOTE Cvent Login Page You have the option to disable Cvent s login page for your account. Disabling the login page will turn off your ability to manage passwords for users. Upon creating a new user, the administrator will not have to enter and confirm a password. Disabling Cvent s login page applies to users on the backend of Cvent s application. Passwords for meeting request users will still function the same way. NOTE Certificate Name Cvent supports multiple public keys for a single Cvent account. You will need to assign a name to each certificate and send an issuer attribute within each SAML assertion dictating which certificate you would like to use. The format of the issue field should be similar to: <saml:issuer> 18

19 User Interface (UI) Changes Once you have configured SSO, there will be changes made to your password rights as well as your users rights for adding and editing. Disabled Passwords If the Cvent login page has been turned off: All password functionalities will be disabled. Users logging in will never be prompted for a password change. Federated SSO vs. Direct SSO If the client SSO configuration calls for a Federated ID type: Administrators will be able to use the application to add and edit the Linked IDs of the account s other users. The required text must be entered in the Federated ID field on the User Information page. This text field will only appear after the account has been configured for SSO with a federated user ID type. A user cannot edit their own Federated ID value in Cvent; another administrator must edit this value on that user s behalf. NOTE If the client SSO configuration calls for a Direct type, users will not be able to change their usernames at any given time. Administrators will be the only ones given permission to change other usernames. Any discrepancy between usernames will result in access to the application being denied. WARNING 19

20 Authentication Procedure For the purpose of receiving the SAML assertion message, two pages have been created at the following dynamic URLs: To authenticate application users: Note: The account stub is a 36-character GUID. This can only be provided by Cvent. To authenticate meeting request users: Note: The endpoint will vary depending on your SSO use case. Refer to the sections near the beginning of the guide for information about each use case. Your account identifier, which must be embedded into the dynamic URL, will be provided at the time of configuration. A target URL must be provided in the query string for any user authenticating to a meeting request form or site. To authenticate a user in the Cvent system, a valid SAML token must be submitted through a HTTP POST form via the user s browser to one of the above URLs. The name of the POST form field must be SAMLResponse. SAML 1.1 Standard The message will contain a protocol structure similar to the following, contained within a SOAP envelope: <samlp:response xmlns:samlp= urn:oasis:names:tc:saml:1.0:protocol MajorVersion= 1 MinorVersion= 1 ResponseID= (RESPONSE_ID) InResponseTo= (MESSAGE_ID) IssueInstant= (TIMESTAMP) > <! Signature > <! Assertions and Statements > </samlp:response> Within this protocol, there will be a standard XML signature as well as an assertion that contains authentication information and the identity of the user. The XML signature must be generated using the private key from the public/private key pair, as previously noted in the Configuration Requirements section. 20

21 The identity assertion within the <Response> message should look similar to this: <Assertion AssertionID= (ASSERTION_ID) IssueInstant= (TIMESTAMP) Issuer= (IDP_ID) MajorVersion= 1 MinorVersion= 1 xmlns= urn:oasis:names:tc:saml:1.0:assertion xmlns:xsd= xmlns:xsi= > <Conditions NotBefore= T00:46:02Z NotOnOrAfter= T00:51:02Z > <AudienceRestrictionCondition> <Audience>(SP_BASE_URL)</Audience> </AudienceRestrictionCondition> </Conditions> <AuthenticationStatement AuthenticationInstant= (ASSERTION_TIME) AuthenticationMethod= urn:oasis:names:tc:saml:1.0:am:password > <Subject> <NameIdentifier Format= urn:oasis:names:tc:saml:1.1:nameid-format: address > (LOCAL_ACCOUNT_ID) </NameIdentifier> <SubjectConfirmation> <ConfirmationMethod> urn:oasis:names:tc:saml:1.0:cm:bearer </ConfirmationMethod> </SubjectConfirmation> </Subject> <SubjectLocality IPAddress= /> </AuthenticationStatement> <ds:signature><! Signature (if assertion is signed) ></ds:signature> </Assertion> 21

22 SAML 2.0 Standard The protocol structure of this newer SAML 2.0 Standard will be similar to SAML 1.1 Standard. <samlp:response xmlns:samlp= urn:oasis:names:tc:saml:2.0:protocol ID= (RESPONSE_ID) InResponseTo= (MESSAGE_ID) Version= 2.0 IssueInstant= (TIMESTAMP) Destination= (DESTINATION_URL) > <! Signature > <! Assertions and Statements > </samlp:response> However, the structure of the assertion within this protocol will hold some key differences from SAML 1.1 Standard. The following is an example of what an SAML 2.0 Identity Assertion may look like: <saml:assertion xmlns:saml= urn:oasis:names:tc:saml:2.0:assertion Version= 2.0 ID= (ASSERTION_ID) > <saml:issuer>(idp_id)</saml:issuer> <ds:signature><! Signature (if assertion is signed) ></ds:signature> <saml:authnstatement AuthnInstant= (ASSERTION_TIME) SessionIndex= > <saml:authncontext> <saml:authncontextclassref> urn:oasis:names:tc:saml:2.0:ac:classes:password </saml:authncontextclassref> </saml:authncontext> </saml:authnstatement> <saml:subject> <saml:nameid>(local_account_id)</saml:nameid> </saml:subject> <saml:audiencerestriction> <saml:audience>(sp_base_url)</saml:audience> </saml:audiencerestriction> </saml:assertion> 22

Leave Policy. SAML Support for PPO

Leave Policy. SAML Support for PPO Leave Policy SAML Support for PPO January 2015 Table of Contents Why SAML Support for PPO... 3 Introduction to SAML... 3 PPO Implementation... 6 ComponentSpace SAML v2.0 for.net... 6 SAML Security mode...

More information

Higgins SAML2 IdP Tutorial

Higgins SAML2 IdP Tutorial Higgins SAML2 IdP Tutorial Version 1.1, Oct 18 th 2007, msabadello@parityinc.net The Higgins SAML2 IdP supports the SP initiated SSO profile defined by SAML2 specifications. Two parties are involved in

More information

Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide

Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide Version 12.0-4/17/2018 Copyright Copyright 2018 Upland Qvidian. All rights reserved. Information in this document is subject to change

More information

Concur Travel Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Concur Travel Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA Concur Travel Integration User Guide 2017 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents Concur Travel Integration User Guide... 3 Enabling Concur Travel Integration in

More information

Salesforce Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Salesforce Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA Salesforce Integration User Guide 2017 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents Salesforce Integration User Guide... 3 Setting Up Your Account... 4 Helpful Hints...

More information

Single Sign-On (SSO) Using SAML

Single Sign-On (SSO) Using SAML Single Sign-On (SSO) Using SAML V.2.4 AS OF 2018-07-26 Visit the SAML SSO Integration section in SCU for additional information OVERVIEW ServiceChannel offers a full-featured single sign-on (SSO) system

More information

Implement SAML 2.0 SSO in WLS using IDM Federation Services

Implement SAML 2.0 SSO in WLS using IDM Federation Services Implement SAML 2.0 SSO in WLS using IDM Federation Services Who we are Experts At Your Service > Over 60 specialists in IT infrastructure > Certified, experienced, passionate Based In Switzerland > 100%

More information

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5 esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5 Phone: 1-855-MYESIGN Fax: (514) 337-5258 Web: www.esignlive.com

More information

Configure ISE 2.3 Guest Portal with OKTA SAML SSO

Configure ISE 2.3 Guest Portal with OKTA SAML SSO Configure ISE 2.3 Guest Portal with OKTA SAML SSO Contents Introduction Prerequisites Requirements Components Used Background Information Federated SSO Network Flow Configure Step 1. Configure SAML Identity

More information

Security Assertion Markup Language (SAML) applied to AppGate XDP

Security Assertion Markup Language (SAML) applied to AppGate XDP 1 Security Assertion Markup Language (SAML) applied to AppGate XDP Jamie Bodley-Scott AppGate Product Manager May 2016 version2 This document provides background on SAML for those of you who have not used

More information

Oracle Utilities Opower Solution Extension Partner SSO

Oracle Utilities Opower Solution Extension Partner SSO Oracle Utilities Opower Solution Extension Partner SSO Integration Guide E84763-01 Last Updated: Friday, January 05, 2018 Oracle Utilities Opower Solution Extension Partner SSO Integration Guide Copyright

More information

Kaltura MediaSpace SAML Integration Guide. Version: 5.0

Kaltura MediaSpace SAML Integration Guide. Version: 5.0 Kaltura MediaSpace SAML Integration Guide Version: 5.0 Kaltura Business Headquarters 200 Park Avenue South, New York, NY. 10003, USA Tel.: +1 800 871 5224 Copyright 2014 Kaltura Inc. All Rights Reserved.

More information

Marketo Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Marketo Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA Marketo Integration User Guide 2017 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents Marketo Integration User Guide... 3 Enabling Marketo Integration for Your Account...

More information

Network Security. Chapter 10. XML and Web Services. Part II: II: Securing Web Services Part III: Identity Federation

Network Security. Chapter 10. XML and Web Services. Part II: II: Securing Web Services Part III: Identity Federation Network Architectures and Services, Georg Carle Faculty of Informatics Technische Universität München, Germany Network Security Chapter 10 Application Layer Security: Web Services (Part 2) Part I: Introduction

More information

Session 2.1: Federations: Foundation. Scott Koranda Support provided by the National Institute of Allergy and Infectious Diseases

Session 2.1: Federations: Foundation. Scott Koranda Support provided by the National Institute of Allergy and Infectious Diseases Session 2.1: Federations: Foundation Scott Koranda Support provided by the National Institute of Allergy and Infectious Diseases Scott Koranda's participation has been funded in whole or in part with federal

More information

Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML)

Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML) Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML) 1. Overview This document is intended to guide users on how to integrate their institution s Dell Cloud Access Manager

More information

WebEx Connector. Version 2.0. User Guide

WebEx Connector. Version 2.0. User Guide WebEx Connector Version 2.0 User Guide 2016 Ping Identity Corporation. All rights reserved. PingFederate WebEx Connector User Guide Version 2.0 May, 2016 Ping Identity Corporation 1001 17th Street, Suite

More information

Web Based Single Sign-On and Access Control

Web Based Single Sign-On and Access Control 0-- Web Based Single Sign-On and Access Control Different username and password for each website Typically, passwords will be reused will be weak will be written down Many websites to attack when looking

More information

Introduction to application management

Introduction to application management Introduction to application management To deploy web and mobile applications, add the application from the Centrify App Catalog, modify the application settings, and assign roles to the application to

More information

WebEx Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

WebEx Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA WebEx Integration User Guide 2018 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents WebEx Integration User Guide... 3 Enabling WebEx Integration in Your Account... 4 Setting

More information

Introducing Shibboleth. Sebastian Rieger

Introducing Shibboleth. Sebastian Rieger Introducing Shibboleth Sebastian Rieger sebastian.rieger@gwdg.de Gesellschaft für wissenschaftliche Datenverarbeitung mbh Göttingen, Germany CLARIN AAI Hands On Workshop, 25.02.2009, Oxford eresearch Center

More information

Webthority can provide single sign-on to web applications using one of the following authentication methods:

Webthority can provide single sign-on to web applications using one of the following authentication methods: Webthority HOW TO Configure Web Single Sign-On Webthority can provide single sign-on to web applications using one of the following authentication methods: HTTP authentication (for example Kerberos, NTLM,

More information

This section includes troubleshooting topics about single sign-on (SSO) issues.

This section includes troubleshooting topics about single sign-on (SSO) issues. This section includes troubleshooting topics about single sign-on (SSO) issues. SSO Fails After Completing Disaster Recovery Operation, page 1 SSO Protocol Error, page 1 SSO Redirection Has Failed, page

More information

Add OKTA as an Identity Provider in EAA

Add OKTA as an Identity Provider in EAA Add OKTA as an Identity Provider in EAA Log in to Akamai Luna control center with administrative privileges. Select the correct contract which is provisioned for Enterprise Application Access (EAA). In

More information

Eloqua Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Eloqua Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA Eloqua Integration User Guide 2017 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents Eloqua Integration User Guide... 3 Enabling Eloqua Integration in Your Account... 4 Helpful

More information

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow)

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow) Integration Guide PingFederate SAML Integration Guide (SP-Initiated Workflow) Copyright Information 2018. SecureAuth is a registered trademark of SecureAuth Corporation. SecureAuth s IdP software, appliances,

More information

All about SAML End-to-end Tableau and OKTA integration

All about SAML End-to-end Tableau and OKTA integration Welcome # T C 1 8 All about SAML End-to-end Tableau and OKTA integration Abhishek Singh Senior Manager, Regional Delivery Tableau Abhishek Singh Senior Manager Regional Delivery asingh@tableau.com Agenda

More information

Building a Well Managed Cloud Application. Okta Inc. 301 Brannan Street San Francisco, CA

Building a Well Managed Cloud Application. Okta Inc. 301 Brannan Street San Francisco, CA Building a Well Managed Cloud Application Okta Inc. 301 Brannan Street San Francisco, CA 94107 info@okta.com 1-888-722-7871 Contents 1 Introduction 1 Working with Okta 2 A Well Managed Cloud Application

More information

Quick Connection Guide

Quick Connection Guide ServiceNow Connector Version 1.0 Quick Connection Guide 2015 Ping Identity Corporation. All rights reserved. PingFederate ServiceNow Connector Quick Connection Guide Version 1.0 August, 2015 Ping Identity

More information

DocuSign Single Sign On Implementation Guide Published: June 8, 2016

DocuSign Single Sign On Implementation Guide Published: June 8, 2016 DocuSign Single Sign On Implementation Guide Published: June 8, 2016 Copyright Copyright 2003-2016 DocuSign, Inc. All rights reserved. For information about DocuSign trademarks, copyrights and patents

More information

Integrating the YuJa Enterprise Video Platform with ADFS (SAML)

Integrating the YuJa Enterprise Video Platform with ADFS (SAML) Integrating the YuJa Enterprise Video Platform with ADFS (SAML) Overview This document is intended to guide users on how to setup a secure connection between the YuJa Enterprise Video Platform referred

More information

ONE ID Provincial Identity Federation

ONE ID Provincial Identity Federation ONE ID Provincial Identity Federation Overview of SAML Configuration Version: 1.49 Table of Contents 1.0 About This Document 5 1.1 Audience...5 1.2 Reference material...5 2.0 Introduction Identity Federation

More information

Suomi.fi e-identification Technical interface description

Suomi.fi e-identification Technical interface description Suomi.fi e-identification Technical interface description 1 Suomi.fi e-identification operating environment Suomi.fi e-identification offers a user authentication service for e-services across a SAML 2.0

More information

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29 Oracle Access Manager Configuration Guide 16 R1 March 2016 Contents Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 8 Installing Oracle HTTP Server...

More information

Oracle Access Manager Configuration Guide

Oracle Access Manager Configuration Guide Oracle Access Manager Configuration Guide 16 R2 September 2016 Contents Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server...

More information

Integrating YuJa Active Learning with ADFS (SAML)

Integrating YuJa Active Learning with ADFS (SAML) Integrating YuJa Active Learning with ADFS (SAML) 1. Overview This document is intended to guide users on how to setup a secure connection between the YuJa Active Learning Platform referred to as the Service

More information

Enabling Single Sign-On Using Okta in Axon Data Governance 5.4

Enabling Single Sign-On Using Okta in Axon Data Governance 5.4 Enabling Single Sign-On Using Okta in Axon Data Governance 5.4 Copyright Informatica LLC 2018. Informatica and the Informatica logo are trademarks or registered trademarks of Informatica LLC in the United

More information

Quick Connection Guide

Quick Connection Guide WebEx Connector Version 1.0.1 Quick Connection Guide 2014 Ping Identity Corporation. All rights reserved. PingFederate WebEx Connector Quick Connection Guide Version 1.0.1 March, 2014 Ping Identity Corporation

More information

ISA 767, Secure Electronic Commerce Xinwen Zhang, George Mason University

ISA 767, Secure Electronic Commerce Xinwen Zhang, George Mason University Identity Management and Federated ID (Liberty Alliance) ISA 767, Secure Electronic Commerce Xinwen Zhang, xzhang6@gmu.edu George Mason University Identity Identity is the fundamental concept of uniquely

More information

Using Microsoft Azure Active Directory MFA as SAML IdP with Pulse Connect Secure. Deployment Guide

Using Microsoft Azure Active Directory MFA as SAML IdP with Pulse Connect Secure. Deployment Guide Using Microsoft Azure Active Directory MFA as SAML IdP with Pulse Connect Secure Deployment Guide v1.0 May 2018 Introduction This document describes how to set up Pulse Connect Secure for SP-initiated

More information

RSA SecurID Access SAML Configuration for Datadog

RSA SecurID Access SAML Configuration for Datadog RSA SecurID Access SAML Configuration for Datadog Last Modified: Feb 17, 2017 Datadog is a monitoring service for cloud-scale applications, bringing together data from servers, databases, tools, and services

More information

Single Sign-On Implementation Guide

Single Sign-On Implementation Guide Single Sign-On Implementation Guide Salesforce, Winter 18 @salesforcedocs Last updated: November 13, 2017 Copyright 2000 2017 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark

More information

Connect-2-Everything SAML SSO (client documentation)

Connect-2-Everything SAML SSO (client documentation) Connect-2-Everything SAML SSO (client documentation) Table of Contents Summary Overview Refined tags Summary The Connect-2-Everything landing page by Refined Data allows Adobe Connect account holders to

More information

SAML-Based SSO Solution

SAML-Based SSO Solution About SAML SSO Solution, page 1 SAML-Based SSO Features, page 2 Basic Elements of a SAML SSO Solution, page 2 SAML SSO Web Browsers, page 3 Cisco Unified Communications Applications that Support SAML SSO,

More information

SafeNet Authentication Manager

SafeNet Authentication Manager SafeNet Authentication Manager INTEGRATION GUIDE Using SAM as an Identity Provider for Remedyforce Contents Support Contacts... 2 Description... 3 Single Sign-On Dataflow... 3 Configuring SAM as an Identity

More information

Integrating YuJa Active Learning into Google Apps via SAML

Integrating YuJa Active Learning into Google Apps via SAML Integrating YuJa Active Learning into Google Apps via SAML 1. Overview This document is intended to guide users on how to integrate YuJa as a Service Provider (SP) using Google as the Identity Provider

More information

SAML-Based SSO Solution

SAML-Based SSO Solution About SAML SSO Solution, page 1 Single Sign on Single Service Provider Agreement, page 2 SAML-Based SSO Features, page 2 Basic Elements of a SAML SSO Solution, page 3 Cisco Unified Communications Applications

More information

Configuring Single Sign-on from the VMware Identity Manager Service to Marketo

Configuring Single Sign-on from the VMware Identity Manager Service to Marketo Configuring Single Sign-on from the VMware Identity Manager Service to Marketo VMware Identity Manager JANUARY 2016 V1 Configuring Single Sign-On from VMware Identity Manager to Marketo Table of Contents

More information

Administering Workspace ONE in VMware Identity Manager Services with AirWatch. VMware AirWatch 9.1.1

Administering Workspace ONE in VMware Identity Manager Services with AirWatch. VMware AirWatch 9.1.1 Administering Workspace ONE in VMware Identity Manager Services with AirWatch VMware AirWatch 9.1.1 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

Configuring Alfresco Cloud with ADFS 3.0

Configuring Alfresco Cloud with ADFS 3.0 Configuring Alfresco Cloud with ADFS 3.0 Prerequisites: You have a working domain on your Windows Server 2012 and successfully installed ADFS. For these instructions, I created: alfresco.me as a domain

More information

Review of differences in SAML V2.0 from SAML V1.1 and ID-FF V1.2

Review of differences in SAML V2.0 from SAML V1.1 and ID-FF V1.2 Review of differences in SAML V2.0 from SAML V1.1 and ID-FF V1.2 Eve Maler 21 April 2004 Thanks to Scott and JohnK for comments (line numbers are from sstc-saml-core-08-diff-from-02) SAML V2.0 diffs in

More information

DCCKI Interface Design Specification. and. DCCKI Repository Interface Design Specification

DCCKI Interface Design Specification. and. DCCKI Repository Interface Design Specification DCCKI Interface Design Specification and DCCKI Repository Interface Design Specification 1 INTRODUCTION Document Purpose 1.1 Pursuant to Section L13.13 of the Code (DCCKI Interface Design Specification),

More information

SecureAuth IdP Realm Guide

SecureAuth IdP Realm Guide SecureAuth IdP Realm Guide What is a Realm? A realm is a configured workflow that leads end-users to a target resource (application, IdM page, certificate enrollment page, etc.). Each SecureAuth IdP realm

More information

Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server...

Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server... Oracle Access Manager Configuration Guide for On-Premises Version 17 October 2017 Contents Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing

More information

Zendesk Connector. Version 2.0. User Guide

Zendesk Connector. Version 2.0. User Guide Zendesk Connector Version 2.0 User Guide 2015 Ping Identity Corporation. All rights reserved. PingFederate Zendesk Connector Quick Connection Guide Version 2.0 November, 2015 Ping Identity Corporation

More information

SAML 2.0 SSO. Set up SAML 2.0 SSO. SAML 2.0 Terminology. Prerequisites

SAML 2.0 SSO. Set up SAML 2.0 SSO. SAML 2.0 Terminology. Prerequisites SAML 2.0 SSO Agiloft integrates with a variety of SAML authentication providers, or Identity Providers (IdPs). SAML-based SSO is a leading method for providing federated access to multiple applications

More information

ComponentSpace SAML v2.0 Developer Guide

ComponentSpace SAML v2.0 Developer Guide ComponentSpace SAML v2.0 Developer Guide Copyright ComponentSpace Pty Ltd 2017-2018. All rights reserved. www.componentspace.com Contents Introduction... 1 Visual Studio and.net Core Support... 1 Application

More information

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments.

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments. TECHNICAL GUIDE SSO SAML At 360Learning, we don t make promises about technical solutions, we make commitments. This technical guide is part of our Technical Documentation. 2 360Learning is a Leading European

More information

Single Sign-On Administrator Guide

Single Sign-On Administrator Guide Single Sign-On Administrator Guide Last Revised February 15, 2018 Version 1.7 Disclaimer LinkedIn Corporation 1000 W. Maude Ave. Sunnyvale, CA 94085 This document may contain forward looking statements.

More information

Single Sign On for GoToMeeting with NetScaler Unified Gateway

Single Sign On for GoToMeeting with NetScaler Unified Gateway Deployment Guide Single Sign On for GoToMeeting with NetScaler Unified Gateway Deployment Guide This deployment guide focuses on defining the process for enabling Single Sign On into GoToMeeting with Citrix

More information

Security Analysis of eidas The Cross-Country Authentication Scheme in Europe

Security Analysis of eidas The Cross-Country Authentication Scheme in Europe Security Analysis of eidas The Cross-Country Authentication Scheme in Europe Nils Engelbertz, Nurullah Erinola, David Herring, Juraj Somorovsky, Vladislav Mladenov, Jörg Schwenk Ruhr University Bochum

More information

Oracle Utilities Opower Energy Efficiency Web Portal - Classic Single Sign-On

Oracle Utilities Opower Energy Efficiency Web Portal - Classic Single Sign-On Oracle Utilities Opower Energy Efficiency Web Portal - Classic Single Sign-On Configuration Guide E84772-01 Last Update: Monday, October 09, 2017 Oracle Utilities Opower Energy Efficiency Web Portal -

More information

AAI Login Demo. SWITCHaai Introduction Course Bern, 1. March Daniel Lutz

AAI Login Demo. SWITCHaai Introduction Course Bern, 1. March Daniel Lutz SWITCHaai Introduction Course Bern, 1. March 2013 Daniel Lutz aai@switch.ch Agenda Illustration of protocol flow SAML2, Web Browser SSO Live demonstration 2 Protocol Flow IdP SP http://www.switch.ch/aai/demo/

More information

SAML-Based SSO Configuration

SAML-Based SSO Configuration Prerequisites, page 1 SAML SSO Configuration Task Flow, page 5 Reconfigure OpenAM SSO to SAML SSO Following an Upgrade, page 9 SAML SSO Deployment Interactions and Restrictions, page 9 Prerequisites NTP

More information

Single Sign-On Administrator Guide

Single Sign-On Administrator Guide Single Sign-On Administrator Guide Last Revised October 2018 Version 1.8 Disclaimer LinkedIn Corporation 1000 W. Maude Ave. Sunnyvale, CA 94085 This document may contain forward looking statements. Any

More information

Morningstar ByAllAccounts SAML Connectivity Guide

Morningstar ByAllAccounts SAML Connectivity Guide Morningstar ByAllAccounts SAML Connectivity Guide 2018 Morningstar. All Rights Reserved. AccountView Version: 1.55 Document Version: 1 Document Issue Date: May 25, 2018 Technical Support: (866) 856-4951

More information

RSA SecurID Access SAML Configuration for Kanban Tool

RSA SecurID Access SAML Configuration for Kanban Tool RSA SecurID Access SAML Configuration for Kanban Tool Last Modified: October 4, 2016 Kanban Tool is a visual product management application based on the Kanban methodology (development) which was initially

More information

TECHNICAL GUIDE SSO SAML Azure AD

TECHNICAL GUIDE SSO SAML Azure AD 1 TECHNICAL GUIDE SSO SAML Azure AD At 360Learning, we don t make promises about technical solutions, we make commitments. This technical guide is part of our Technical Documentation. Version 1.0 2 360Learning

More information

Integrating YuJa Active Learning into ADFS via SAML

Integrating YuJa Active Learning into ADFS via SAML Integrating YuJa Active Learning into ADFS via SAML 1. Overview This document is intended to guide users on how to setup a secure connection between YuJa (the Service Provider, or SP) and ADFS (the Identity

More information

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE GUIDE MARCH 2019 PRINTED 28 MARCH 2019 CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE VMware Workspace ONE Table of Contents Overview Introduction Audience AD FS

More information

Passkey Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Passkey Integration User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA Passkey Integration User Guide 2018 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents Passkey Integration User Guide... 3 Key Terms... 3 Enabling Passkey Integration for

More information

Identity Provider for SAP Single Sign-On and SAP Identity Management

Identity Provider for SAP Single Sign-On and SAP Identity Management Implementation Guide Document Version: 1.0 2017-05-15 PUBLIC Identity Provider for SAP Single Sign-On and SAP Identity Management Content 1....4 1.1 What is SAML 2.0.... 5 SSO with SAML 2.0.... 6 SLO with

More information

RSA SecurID Access SAML Configuration for StatusPage

RSA SecurID Access SAML Configuration for StatusPage RSA SecurID Access SAML Configuration for StatusPage Last Modified: Feb 22, 2017 StatusPage specializes in helping companies deal with the inevitable crisis of their website going down. Whether it s scheduled

More information

Enabling Single Sign-On Using Microsoft Azure Active Directory in Axon Data Governance 5.2

Enabling Single Sign-On Using Microsoft Azure Active Directory in Axon Data Governance 5.2 Enabling Single Sign-On Using Microsoft Azure Active Directory in Axon Data Governance 5.2 Copyright Informatica LLC 2018. Informatica and the Informatica logo are trademarks or registered trademarks of

More information

i-ready Support for Single Sign-On (SSO)

i-ready Support for Single Sign-On (SSO) i-ready Support for Single Sign-On (SSO) Contents Benefits... 2 Supported Security Protocols... 2 How It Works... 2 SAML Workflow... 3 Clever Workflow... 4 Implementation Details... 5 Basic Assumption...

More information

RSA SecurID Ready Implementation Guide. Last Modified: December 13, 2013

RSA SecurID Ready Implementation Guide. Last Modified: December 13, 2013 Ping Identity RSA SecurID Ready Implementation Guide Partner Information Last Modified: December 13, 2013 Product Information Partner Name Ping Identity Web Site www.pingidentity.com Product Name PingFederate

More information

Electronic ID at work: issues and perspective

Electronic ID at work: issues and perspective Electronic ID at work: issues and perspective Antonio Lioy < lioy @ polito.it > Politecnico di Torino Dip. Automatica e Informatica Why should I have/use an (e-) ID? to prove my identity to an "authority":

More information

IBM Security Access Manager Single Sign-on with Federation

IBM Security Access Manager Single Sign-on with Federation IBM Security Access Manager Single Sign-on with Federation IBM SECURITY SUPPORT OPEN MIC To hear the WebEx audio, select an option in the Audio Connection dialog or by access the Communicate > Audio Connection

More information

Delegated authentication Electronic identity: delegated and federated authentication, policy-based access control

Delegated authentication Electronic identity: delegated and federated authentication, policy-based access control Delegated authentication Electronic identity: delegated and federated authentication, policy-based access control Antonio Lioy < lioy @ polito.it > several RPs (Replying Party) may decide to delegate authentication

More information

RECOMMENDED DEPLOYMENT PRACTICES. The F5 and Okta Solution for High Security SSO

RECOMMENDED DEPLOYMENT PRACTICES. The F5 and Okta Solution for High Security SSO July 2017 Contents Introduction...3 The Integrated Solution...3 Prerequisites...4 Configuration...4 Set up BIG-IP APM to be a SAML IdP...4 Create a self-signed certificate for signing SAML assertions...4

More information

Qualys SAML & Microsoft Active Directory Federation Services Integration

Qualys SAML & Microsoft Active Directory Federation Services Integration Qualys SAML & Microsoft Active Directory Federation Services Integration Microsoft Active Directory Federation Services (ADFS) is currently supported for authentication. The Qualys ADFS integration must

More information

OIO Bootstrap Token Profile

OIO Bootstrap Token Profile > OIO Bootstrap Token Profile Version 1.0.1 IT- & Telestyrelsen March 2010 2 Content [ Document History 4 Introduction 5 Characteristics of bootstrap tokens 5 Related profiles 6 Assumptions 6 Token Requirements

More information

SAML 2.0 SSO Extension for Dynamically Choosing Attribute Values

SAML 2.0 SSO Extension for Dynamically Choosing Attribute Values SAML 2.0 SSO Extension for Dynamically Choosing Attribute Values Authors: George Inman University of Kent g.inman@kent.ac.uk David Chadwick University of Kent d.w.chadwick@kent.ac.uk Status of This Document

More information

SAML V2.0 EAP GSS SSO Profile Version 1.0

SAML V2.0 EAP GSS SSO Profile Version 1.0 SAML V2.0 EAP GSS SSO Profile Version 1.0 Committee Draft 00 March 18, 2010 Specification URIs: This Version: http://docs.oasis-open.org/[tc-short-name]/[additional path/filename].html http://docs.oasis-open.org/[tc-short-name]/[additional

More information

Udemy for Business SSO. Single Sign-On (SSO) capability for the UFB portal

Udemy for Business SSO. Single Sign-On (SSO) capability for the UFB portal Single Sign-On (SSO) capability for the UFB portal Table of contents Overview SSO and SAML PingOne and Ping Federate Data Flow FAQ What is the End User Experience With SSO? Can users access the Udemy app

More information

Single Sign-On (SSO)Technical Specification

Single Sign-On (SSO)Technical Specification Single Sign-On (SSO)Technical Specification Audience: Business Stakeholders IT/HRIS Table of Contents Document Version Control:... 3 1. Overview... 4 Summary:... 4 Acronyms and Definitions:... 4 Who Should

More information

Nimsoft Service Desk. Single Sign-On Configuration Guide. [assign the version number for your book]

Nimsoft Service Desk. Single Sign-On Configuration Guide. [assign the version number for your book] Nimsoft Service Desk Single Sign-On Configuration Guide [assign the version number for your book] Legal Notices Copyright 2012, CA. All rights reserved. Warranty The material contained in this document

More information

Five9 Plus Adapter for Agent Desktop Toolkit

Five9 Plus Adapter for Agent Desktop Toolkit Cloud Contact Center Software Five9 Plus Adapter for Agent Desktop Toolkit Administrator s Guide September 2017 The Five9 Plus Adapter for Agent Desktop Toolkit integrates the Five9 Cloud Contact Center

More information

Configuration Guide - Single-Sign On for OneDesk

Configuration Guide - Single-Sign On for OneDesk Configuration Guide - Single-Sign On for OneDesk Introduction Single Sign On (SSO) is a user authentication process that allows a user to access different services and applications across IT systems and

More information

SafeNet Authentication Manager

SafeNet Authentication Manager SafeNet Authentication Manager QUICK START GUIDE Using SAM as an Identity Provider for Citrix ShareFile Contents Support Contacts... 2 Description... 3 Single Sign-On Dataflow... 3 Configuring SAM as an

More information

Google SAML Integration

Google SAML Integration YuJa Enterprise Video Platform Google SAML Integration Overview This document is intended to guide users on how to integrate the YuJa Enterprise Video Platform as a Service Provider (SP) using Google as

More information

Configuring ServiceNow

Configuring ServiceNow Configuring ServiceNow Users can securely log on to ServiceNow using their enterprise credentials. To configure ServiceNow for SSO through SAML, follow the steps below: 1. In a browser, type https://.service-now.com/

More information

CoreBlox Integration Kit. Version 2.2. User Guide

CoreBlox Integration Kit. Version 2.2. User Guide CoreBlox Integration Kit Version 2.2 User Guide 2015 Ping Identity Corporation. All rights reserved. PingFederate CoreBlox Integration Kit User Guide Version 2.2 November, 2015 Ping Identity Corporation

More information

ArcGIS Server and Portal for ArcGIS An Introduction to Security

ArcGIS Server and Portal for ArcGIS An Introduction to Security ArcGIS Server and Portal for ArcGIS An Introduction to Security Jeff Smith & Derek Law July 21, 2015 Agenda Strongly Recommend: Knowledge of ArcGIS Server and Portal for ArcGIS Security in the context

More information

E X O S T A R, LLC D A T E : M AY V E R S I O N : 4.0

E X O S T A R, LLC D A T E : M AY V E R S I O N : 4.0 SECURE ACCESS MAN AG E R USER GUI DE E X O S T A R, LLC D A T E : M AY 2 0 1 7 V E R S I O N : 4.0 1 S E C U R E AC C E S S M A N A G E R 1 INTRODUCTION... 3 1.1 SUMMARY... 3 2 BASIC FUNCTIONS... 3 2.1

More information

Secure Access Manager (SAM) Administrator Guide December 2017

Secure Access Manager (SAM) Administrator Guide December 2017 Secure Access Manager (SAM) Administrator Guide December 2017 Copyright 2017 Exostar, LLC All rights reserved. 1 SECURE ACCESS MANAGER (SAM) OVERVIEW... 4 ADMINISTRATIVE ROLES OVERVIEW... 4 SAM NAVIGATIONAL

More information

Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief

Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief Qualys provides its customers the option to use SAML 2.0 Single SignOn (SSO) authentication with their Qualys subscription. When implemented, Qualys

More information

Integration Documentation. Automated User Provisioning Common Logon, Single Sign On or Federated Identity Local File Repository Space Pinger

Integration Documentation. Automated User Provisioning Common Logon, Single Sign On or Federated Identity Local File Repository Space Pinger Integration Documentation Automated User Provisioning Common Logon, Single Sign On or Federated Identity Local File Repository Space Pinger Revision History Version No. Release Date Author(s) Description

More information

Configure Unsanctioned Device Access Control

Configure Unsanctioned Device Access Control Configure Unsanctioned Device Access Control paloaltonetworks.com/documentation Contact Information Corporate Headquarters: Palo Alto Networks 3000 Tannery Way Santa Clara, CA 95054 www.paloaltonetworks.com/company/contact-support

More information

ADFS Authentication and Configuration January 2017

ADFS Authentication and Configuration January 2017 ADFS Authentication and Configuration January 2017 International Corporation 1 Table of Contents Introduction... 2 Changelog for Configure Active Directory Synchronization... 3 2.1. Changes in Configure

More information