Single Sign-On (SSO) Using SAML

Size: px
Start display at page:

Download "Single Sign-On (SSO) Using SAML"

Transcription

1 Single Sign-On (SSO) Using SAML V.2.4 AS OF Visit the SAML SSO Integration section in SCU for additional information

2 OVERVIEW ServiceChannel offers a full-featured single sign-on (SSO) system to improve the security of your team s access to ServiceChannel while making it easier for them to gain access. Our SSO system allows your users to sign in to your system once and then access ServiceChannel as the correct user account with correct permissions without the need to log in again. ServiceChannel supports SAML SSO an enterprise solution for single sign-on supported by all major 3 rd party vendors and tools such as ADFS, SiteMinder, Okta, Ping One/Federate/Identity. In general, SAML SSO is a system level integration where parameters are discussed ahead of time and are passed through an assertion. The assertion can be encrypted and signed, and ServiceChannel will validate the assertion and log in the user to the appropriate application. New users can be created on the fly if the required fields are available in the assertion. ServiceChannel supports Identity Provider Initiated SAML SSO. We do not currently support Service Provider Initiated SAML SSO. This document describes all the details required to complete this integration. For more details on the SAML, see Security Assertion Markup Language in Wikipedia. 2

3 SAML SSO CONCEPTS Step 1. A user authenticates with (logs in to) Identity Provider system (ADFS, SiteMinder, PingFederate, etc). Step 2. The Identity Provider system sends SAML Assertion to Service Provider system (ServiceChannel). Step 3. The Service Provider system (ServiceChannel) validates data provided in SAML Assertion, activates a logged in session, and provides user access to the logged in session with their user s access permissions. 3

4 USER FEED CONCEPTS Note: The User Feed is not required for SAML SSO, but we recommend it as a best practice. There are several options to create user accounts in ServiceChannel: Manually via UI Using User Feed templates (this option is recommended) Using SAML SSO with Just-in-Time Provisioning Regardless the way selected to create user accounts, we highly recommend to use an address as a user identifier in ServiceChannel instead of a username (e.g. JohnDoe@yourcompany.com instead of JohnDoe) to ensure uniqueness of your user identifiers. The following data is provided in a User Feed Template: Subscriber ID Username address Userid Password (should be empty if you are going to limit a user to SSO logins only) Locations/districts/regions this user should have an access to Role NTE, proposal approval and invoice approval limits status (active/inactive) A User Feed Template can be uploaded into ServiceChannel once during initial setup or on a regular basis. Your ServiceChannel SSO Implementation manager will supply a copy of the User Feed template. We recommend automating the process nightly by having an application on your system create a list of all your users that will need access to ServiceChannel in the standard User Feed template format and upload the file to the ServiceChannel servers for processing. 4

5 SAML SSO IMPLEMENTATION ROADMAP Items to Clarify Before Implementation Is SAML going to be used for authentication only? Should users be created/managed through SAML assertions or User Feed? Do you want users to be redirected to some specific page after logging off from ServiceChannel portal? Note: We recommend authentication only SAML SSO with a User Feed as the fastest solution to deploy. Implementation Steps In general, the following steps should be performed to setup SAML SSO: 1. The CLIENT configures the connection to ServiceChannel testing environment. 2. The CLIENT provides the Issuer and certificate (optional) to ServiceChannel. 3. ServiceChannel configures connection in ServiceChannel testing environment. 4. ServiceChannel provides notice to the CLIENT team that the connection is ready for testing. 5. The CLIENT tests the connection with 2 to 3 users to confirm that the access is granted and the person is logged in as correct user. 6. The CLIENT alerts ServiceChannel that the connection is working well and can be deployed into production. 7. The CLIENT selects the day and time when the connection can be deployed into production. 8. ServiceChannel team deploys the connection configuration into the production environment on the selected day and time. Data Required to Configure SAML SSO Connections On the CLIENT side ServiceChannel Certificate (see Appendix A) and endpoints: Production Testing On ServiceChannel side CLIENT certificate and Issuer value from SAML assertions. 5

6 DATA TO BE PROVIDED IN SAML ASSERTIONS ServiceChannel will expect the following information passed in assertions: Field Required Field explanation NameID Required User ID in SC. Should be in the Subject section of SAML assertion. Name Optional Username. Optional User s address. Role Optional User Role as defined in uploaded User Role template. Location Optional Org Unit for the user Location/Store ID, comma-separated list. The user will have an access to all locations if this field is not provided. Region Optional Org Unit for the user Region, comma-separated list. The user will have an access to all regions if this field is not provided. District Optional Org Unit for the user District, comma-separated list. The user will have an access to all districts if this field is not provided. NTELimit Optional NTE limit value. The current value in SC will remain unchanged if this field is not provided. ProposalApprovalLimit Optional Proposal approval limit value. The current value in SC will remain unchanged if this field is not provided. InvoiceApprovalLimit Optional Invoice approval limit. The current value in SC will remain unchanged if this field is not provided. Currency Optional Currency for limits mentioned above. "USD" will be used if this field is not provided. Note: Only the NameID value is required for authentication-only SAML SSO. 6

7 APPENDIX A. SERVICECHANNEL CERTIFICATE Here is the ServiceChannel certificate used with SAML SSO in the CRT format BEGIN CERTIFICATE----- MIIG5DCCBcygAwIBAgIQKZhilpvHXfx2onKlnJ+XMTANBgkqhkiG9w0BAQsFADCB kdelmakga1uebhmcr0ixgzazbgnvbagtekdyzwf0zxigtwfuy2hlc3rlcjeqma4g A1UEBxMHU2FsZm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxNjA0BgNV BAMTLUNPTU9ETyBSU0EgRG9tYWluIFZhbGlkYXRpb24gU2VjdXJlIFNlcnZlciBD QTAeFw0xODA3MDUwMDAwMDBaFw0yMDA3MDQyMzU5NTlaMGIxITAfBgNVBAsTGERv bwfpbibdb250cm9sifzhbglkyxrlzdeembwga1uecxmvrxnzzw50awfsu1nmifdp bgrjyxjkmr0wgwydvqqddbqqlnnlcnzpy2vjagfubmvslmnvbtccasiwdqyjkozi hvcnaqebbqadggepadccaqocggebamvoevoaze3xht3bjy92shlssy4bnbi1z462 u/ubhdddbdk62efjwnvsphus7xv2gkf2czfpgxt6ll7ztg9nk3ctw1tewbw1wpvl YGMh4V+CyDnO9i/iDCz4F/IwHj2mFMgJ5V60BJP83Y5p5hQOwZPwX1CZEHkDicZ2 QJ8ZZBo9GjPfLPQC5VngVSgEg+63RZ/QwTSrs8shMTUEnZGrevH2i3CKkNIu51fW VX66Hv6egqzf8D6c7xECGaBJNGTXDbr5dGDZjoOa5orxbIs3LbytjrBSqCwiD92s 0uqw1VunRSqN5k/14SustJ/3a3FByZe2jshqqIUctNx2qDSzJksCAwEAAaOCA2Uw ggnhmb8ga1udiwqymbaafjcvajquwgvykoosvnpfq7q6knrnmb0ga1uddgqwbbtx tmy/idgtmvuxnmdhfbe/tdcxzdaobgnvhq8baf8ebamcbaawdaydvr0taqh/baiw ADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwTwYDVR0gBEgwRjA6Bgsr BgEEAbIxAQICBzArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8u Y29tL0NQUzAIBgZngQwBAgEwVAYDVR0fBE0wSzBJoEegRYZDaHR0cDovL2NybC5j b21vzg9jys5jb20vq09nt0rpulnbrg9tywluvmfsawrhdglvblnly3vyzvnlcnzl cknblmnybdcbhqyikwybbquhaqeeetb3me8gccsgaqufbzachknodhrwoi8vy3j0 LmNvbW9kb2NhLmNvbS9DT01PRE9SU0FEb21haW5WYWxpZGF0aW9uU2VjdXJlU2Vy dmvyq0euy3j0mcqgccsgaqufbzabhhhodhrwoi8vb2nzcc5jb21vzg9jys5jb20w MwYDVR0RBCwwKoIUKi5zZXJ2aWNlY2hhbm5lbC5jb22CEnNlcnZpY2VjaGFubmVs LmNvbTCCAXwGCisGAQQB1nkCBAIEggFsBIIBaAFmAHYA7ku9t3XOYLrhQmkfq+Ge ZqMPfl+wctiDAMR7iXqo/csAAAFka9y5cAAABAMARzBFAiBckcW0NjKlaXG8ZEMP u71blbalg1qhvblw5sc9f1n3bgihaijfak6z29fkfkgo2+eesmw1mvxoujcw9nww dnwerojhahuaxqdz+d9wwoe1nkh90engmnqrmgyeorishbh1lofxrvgaaafka9y5 tqaabamarjbeaiaqstfxy0iuel7gx2uwvq4dpzcnzvvgdjksmm0mtdfkgaigrfht nrbjjuknpvncr/poyomie93kiyakjcsp18jxpb0adqbvgdtcfpa2aurqc5txpfpw woq4ehalcbcvo6odbxptdaaaawrr3lmvaaaeawbgmeqcihltsb+dvjsmdg9xowb+ BZfAN3BmB97pcy7IzPDaj3sFAiBLTZEiOpY5a1Jw6ikTsEhJeHgAmk2naQXb2yBX TtkQUzANBgkqhkiG9w0BAQsFAAOCAQEAAj9VgpgOnbf1JnJclMSQ26dEp3IFiWwj itnr81dzeaisbrflq97xqqgv3tnlcxhq75wszg7wijvjidudzjps0vvuuuysx2on /6+zqQYZqSWJOHK3QTG7pDFynwmowz9RlaEADKd5+oNSyL4Z7uj1ZXbAsGYn49hR 8BOHrlB/4fitw+VNqtlY5cV8g/dotTp4gGeORhhp0Rg6HMZ3paicUTDQHi5HqKmg ah9igx0dnx0ipf7dhiwmunwxtkeftdffvmbnzrm9hiuxjehuspixl4jeb3zumvch tvot9iawf2h3qiyag2ab2z/r+s9b9muntdf7vgkfhyrmxto2cvyyog== -----END CERTIFICATE

8 APPENDIX B. SAML ASSERTION SAMPLES Authorization-Only SSO Here is a sample of SAML assertion for an authorization-only SSO. Note: Most important fields (Issuer and NameID) are highlighted. <samlp:response ID="_abcd4562-aabb-435f-bcdf " Version="2.0" IssueInstant=" T20:14:25.281Z" Destination=" Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified" xmlns:samlp="urn:oasis:names:tc:saml:2.0:protocol"> <Issuer xmlns="urn:oasis:names:tc:saml:2.0:assertion"> ces/trust</issuer> <samlp:status> <samlp:statuscode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /> </samlp:status> <Assertion ID="_abcd4562-aabb-435f-bcdf " IssueInstant=" T20:14:25.281Z" Version="2.0" xmlns="urn:oasis:names:tc:saml:2.0:assertion"> <Issuer> <ds:signature xmlns:ds=" some-values-here </ds:signature> <Subject> <NameID>user_name_here@mydomain.com</NameID> <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> <SubjectConfirmationData NotOnOrAfter=" T20:19:25.281Z" Recipient=" /> </SubjectConfirmation> </Subject> <Conditions NotBefore=" T20:14:25.277Z" NotOnOrAfter=" T21:14:25.277Z"> <AudienceRestriction> <Audience> </AudienceRestriction> </Conditions> <AuthnStatement AuthnInstant=" T20:14:25.256Z" SessionIndex="_abcd4562-aabb-435f-bcdf "> <AuthnContext> <AuthnContextClassRef>urn:federation:authentication:windows</AuthnContextClassRef > </AuthnContext> </AuthnStatement> </Assertion> 8

9 </samlp:response> Just-In-Time Provisioning SSO Here is a sample of SAML assertion for a Just-In-Time Provisioning only SSO. Important fields are highlighted; Issuer and NameID are required; Region/District/Location and Role are optional and used if you need to restrict user access to some specific locations. <samlp:response xmlns:samlp="urn:oasis:names:tc:saml:2.0:protocol" xmlns:saml="urn:oasis:names:tc:saml:2.0:assertion" ID="_abcd4562-aabb-435f-bcdf " Version="2.0" IssueInstant=" T17:23:50.347Z" Destination=" Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified"> <saml:issuer> <samlp:status> <samlp:statuscode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/> </samlp:status> <saml:assertion ID="_abcd4562-aabb-435f-bcdf " IssueInstant=" T17:23:50.347Z" Version="2.0"> <saml:issuer> <ds:signature xmlns:ds=" some-values-here </ds:signature> <saml:subject> <saml:nameid>user_name_here@mydomain.net</saml:nameid> <saml:subjectconfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> <saml:subjectconfirmationdata NotOnOrAfter=" T17:28:50.347Z" Recipient=" </saml:subjectconfirmation> </saml:subject> <saml:conditions NotBefore=" T17:23:50.331Z" NotOnOrAfter=" T18:23:50.331Z"> <saml:audiencerestriction> <saml:audience> </saml:audiencerestriction> </saml:conditions> <saml:attributestatement> <saml:attribute Name="Name"> <saml:attributevalue>user_name_here</saml:attributevalue> <saml:attribute Name=" "> <saml:attributevalue>user_name_here@mydomain.net</saml:attributevalue> <saml:attribute Name="Location"> 9

10 <saml:attributevalue>4155</saml:attributevalue> <saml:attribute Name="Region"> <saml:attributevalue>california</saml:attributevalue> <saml:attribute Name="District"> <saml:attributevalue>west</saml:attributevalue> <saml:attribute Name="Role"> <saml:attributevalue>associate</saml:attributevalue> <saml:attribute Name="NTELimit"> <saml:attributevalue>3000</saml:attributevalue> <saml:attribute Name="ProposalApprovalLimit"> <saml:attributevalue>4000</saml:attributevalue> <saml:attribute Name="InvoiceApprovalLimit"> <saml:attributevalue>5000</saml:attributevalue> <saml:attribute Name="Currency"> <saml:attributevalue>cad</saml:attributevalue> </saml:attributestatement> <saml:authnstatement AuthnInstant=" T17:23:26.425Z" SessionIndex="_abcd4562-aabb-435f-bcdf "> <saml:authncontext> <AuthnContextClassRef>urn:federation:authentication:windows</AuthnContextClassRef > </saml:authncontext> </saml:authnstatement> </saml:assertion> </samlp:response> 10

Kaltura MediaSpace SAML Integration Guide. Version: 5.0

Kaltura MediaSpace SAML Integration Guide. Version: 5.0 Kaltura MediaSpace SAML Integration Guide Version: 5.0 Kaltura Business Headquarters 200 Park Avenue South, New York, NY. 10003, USA Tel.: +1 800 871 5224 Copyright 2014 Kaltura Inc. All Rights Reserved.

More information

Leave Policy. SAML Support for PPO

Leave Policy. SAML Support for PPO Leave Policy SAML Support for PPO January 2015 Table of Contents Why SAML Support for PPO... 3 Introduction to SAML... 3 PPO Implementation... 6 ComponentSpace SAML v2.0 for.net... 6 SAML Security mode...

More information

Security Assertion Markup Language (SAML) applied to AppGate XDP

Security Assertion Markup Language (SAML) applied to AppGate XDP 1 Security Assertion Markup Language (SAML) applied to AppGate XDP Jamie Bodley-Scott AppGate Product Manager May 2016 version2 This document provides background on SAML for those of you who have not used

More information

Session 2.1: Federations: Foundation. Scott Koranda Support provided by the National Institute of Allergy and Infectious Diseases

Session 2.1: Federations: Foundation. Scott Koranda Support provided by the National Institute of Allergy and Infectious Diseases Session 2.1: Federations: Foundation Scott Koranda Support provided by the National Institute of Allergy and Infectious Diseases Scott Koranda's participation has been funded in whole or in part with federal

More information

Directories Services and Single Sign-On for Collaboration

Directories Services and Single Sign-On for Collaboration Directories Services and Single Sign-On for Collaboration Paulo Jorge Correia BRKUCC-2664 Agenda Identity Challenges and Market Analysis SSO Technologies and protocol Deep Dive OAuth Protocol SAML Protocol

More information

Implement SAML 2.0 SSO in WLS using IDM Federation Services

Implement SAML 2.0 SSO in WLS using IDM Federation Services Implement SAML 2.0 SSO in WLS using IDM Federation Services Who we are Experts At Your Service > Over 60 specialists in IT infrastructure > Certified, experienced, passionate Based In Switzerland > 100%

More information

i-ready Support for Single Sign-On (SSO)

i-ready Support for Single Sign-On (SSO) i-ready Support for Single Sign-On (SSO) Contents Benefits... 2 Supported Security Protocols... 2 How It Works... 2 SAML Workflow... 3 Clever Workflow... 4 Implementation Details... 5 Basic Assumption...

More information

Generic Structure of the Treatment Relationship Assertion

Generic Structure of the Treatment Relationship Assertion epsos ECCF Artifact Matrix Excerpt: Context and elated Information epsos Conceptual Logical Implementable Enterprise Dimension "Why" - Policy Information Dimension "What" - Content Computational Dimension

More information

Configure ISE 2.3 Guest Portal with OKTA SAML SSO

Configure ISE 2.3 Guest Portal with OKTA SAML SSO Configure ISE 2.3 Guest Portal with OKTA SAML SSO Contents Introduction Prerequisites Requirements Components Used Background Information Federated SSO Network Flow Configure Step 1. Configure SAML Identity

More information

Single Sign-On Implementation Guide

Single Sign-On Implementation Guide Single Sign-On Implementation Guide Salesforce, Winter 18 @salesforcedocs Last updated: November 13, 2017 Copyright 2000 2017 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark

More information

Introducing Shibboleth. Sebastian Rieger

Introducing Shibboleth. Sebastian Rieger Introducing Shibboleth Sebastian Rieger sebastian.rieger@gwdg.de Gesellschaft für wissenschaftliche Datenverarbeitung mbh Göttingen, Germany CLARIN AAI Hands On Workshop, 25.02.2009, Oxford eresearch Center

More information

Network Security. Chapter 10. XML and Web Services. Part II: II: Securing Web Services Part III: Identity Federation

Network Security. Chapter 10. XML and Web Services. Part II: II: Securing Web Services Part III: Identity Federation Network Architectures and Services, Georg Carle Faculty of Informatics Technische Universität München, Germany Network Security Chapter 10 Application Layer Security: Web Services (Part 2) Part I: Introduction

More information

AdminCamp Christian Henseler, Christian Henseler,

AdminCamp Christian Henseler, Christian Henseler, AdminCamp 2013 Christian Henseler, 24.09.2013 Christian Henseler, 24.09.2013 1 Introduction What are we coming from Yet another SSO mechanism!? SAML basics Domino 9 requirements and limitations SAML use

More information

Single Sign-On Implementation Guide

Single Sign-On Implementation Guide Single Sign-On Implementation Guide Salesforce, Spring 16 @salesforcedocs Last updated: April 6, 2016 Copyright 2000 2016 salesforce.com, inc. All rights reserved. Salesforce is a registered trademark

More information

Media Shuttle SAML Configuration. October 2017 Revision 2.0

Media Shuttle SAML Configuration. October 2017 Revision 2.0 Media Shuttle SAML Configuration October 2017 Revision 2.0 Table of Contents Overview... 3 End User Experience... 5 Portal Authentication Flow... 6 Configuration Steps... 7 Technical Details... 11 SAML

More information

DocuSign Single Sign On Implementation Guide Published: June 8, 2016

DocuSign Single Sign On Implementation Guide Published: June 8, 2016 DocuSign Single Sign On Implementation Guide Published: June 8, 2016 Copyright Copyright 2003-2016 DocuSign, Inc. All rights reserved. For information about DocuSign trademarks, copyrights and patents

More information

Single Sign-On User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA

Single Sign-On User Guide. Cvent, Inc 1765 Greensboro Station Place McLean, VA Single Sign-On User Guide 2018 Cvent, Inc 1765 Greensboro Station Place McLean, VA 22102 www.cvent.com Contents Single Sign-On User Guide... 3 Key Terms... 3 Features Using SSO to Login... 4 Meeting Planners

More information

AAI Login Demo. SWITCHaai Introduction Course Bern, 1. March Daniel Lutz

AAI Login Demo. SWITCHaai Introduction Course Bern, 1. March Daniel Lutz SWITCHaai Introduction Course Bern, 1. March 2013 Daniel Lutz aai@switch.ch Agenda Illustration of protocol flow SAML2, Web Browser SSO Live demonstration 2 Protocol Flow IdP SP http://www.switch.ch/aai/demo/

More information

Building a Well Managed Cloud Application. Okta Inc. 301 Brannan Street San Francisco, CA

Building a Well Managed Cloud Application. Okta Inc. 301 Brannan Street San Francisco, CA Building a Well Managed Cloud Application Okta Inc. 301 Brannan Street San Francisco, CA 94107 info@okta.com 1-888-722-7871 Contents 1 Introduction 1 Working with Okta 2 A Well Managed Cloud Application

More information

Suomi.fi e-identification Technical interface description

Suomi.fi e-identification Technical interface description Suomi.fi e-identification Technical interface description 1 Suomi.fi e-identification operating environment Suomi.fi e-identification offers a user authentication service for e-services across a SAML 2.0

More information

Research Collaboration IAM Needs

Research Collaboration IAM Needs Outline Research Collaboration IAM Needs Federated Identity for Authentication SAML Federations Hands-on with SAML Hands-on with OpenID Connect (OIDC) 2 Research Collaboration IAM Needs 3 What Is A Collaboration?

More information

SAML 2.0 SSO Extension for Dynamically Choosing Attribute Values

SAML 2.0 SSO Extension for Dynamically Choosing Attribute Values SAML 2.0 SSO Extension for Dynamically Choosing Attribute Values Authors: George Inman University of Kent g.inman@kent.ac.uk David Chadwick University of Kent d.w.chadwick@kent.ac.uk Status of This Document

More information

OIO Bootstrap Token Profile

OIO Bootstrap Token Profile > OIO Bootstrap Token Profile Version 1.0.1 IT- & Telestyrelsen March 2010 2 Content [ Document History 4 Introduction 5 Characteristics of bootstrap tokens 5 Related profiles 6 Assumptions 6 Token Requirements

More information

Higgins SAML2 IdP Tutorial

Higgins SAML2 IdP Tutorial Higgins SAML2 IdP Tutorial Version 1.1, Oct 18 th 2007, msabadello@parityinc.net The Higgins SAML2 IdP supports the SP initiated SSO profile defined by SAML2 specifications. Two parties are involved in

More information

SAML 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants

SAML 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants OAuth Working Group Internet-Draft Intended status: Standards Track Expires: September 30, 2013 B. Campbell Ping Identity C. Mortimore Salesforce M.B. Jones Microsoft March 29, 2013 SAML 2.0 Profile for

More information

Web Based Single Sign-On and Access Control

Web Based Single Sign-On and Access Control 0-- Web Based Single Sign-On and Access Control Different username and password for each website Typically, passwords will be reused will be weak will be written down Many websites to attack when looking

More information

SAML 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants

SAML 2.0 Profile for OAuth 2.0 Client Authentication and Authorization Grants OAuth Working Group Internet-Draft Intended status: Standards Track Expires: June 12, 2014 B. Campbell Ping Identity C. Mortimore Salesforce M. Jones Microsoft December 9, 2013 SAML 2.0 Profile for OAuth

More information

Web Services Security - Focus on SAML and XACML

Web Services Security - Focus on SAML and XACML The Open University of Israel Department of Mathematics and Computer Science Web Services Security - Focus on SAML and XACML Final Paper submitted as partial fulfillment of the requirements towards an

More information

Udemy for Business SSO. Single Sign-On (SSO) capability for the UFB portal

Udemy for Business SSO. Single Sign-On (SSO) capability for the UFB portal Single Sign-On (SSO) capability for the UFB portal Table of contents Overview SSO and SAML PingOne and Ping Federate Data Flow FAQ What is the End User Experience With SSO? Can users access the Udemy app

More information

SAML V2.0 Deployment Profiles for X.509 Subjects

SAML V2.0 Deployment Profiles for X.509 Subjects 1 2 3 4 5 SAML V2.0 Deployment Profiles for X.509 Subjects Committee Specification 01 27 March 2008 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 Specification URIs:

More information

Web Services Security: SAML Interop 1 Scenarios

Web Services Security: SAML Interop 1 Scenarios 1 2 3 4 Web Services Security: SAML Interop 1 Scenarios Working Draft 04, Jan 29, 2004 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 Document identifier: Location: http://www.oasis-open.org/committees/wss/

More information

SAML V2.0 EAP GSS SSO Profile Version 1.0

SAML V2.0 EAP GSS SSO Profile Version 1.0 SAML V2.0 EAP GSS SSO Profile Version 1.0 Committee Draft 00 March 18, 2010 Specification URIs: This Version: http://docs.oasis-open.org/[tc-short-name]/[additional path/filename].html http://docs.oasis-open.org/[tc-short-name]/[additional

More information

eidas-node and SAML Version 2.0

eidas-node and SAML Version 2.0 eidas-node and SAML Version 2.0 Document history Version Date Modification reason Modified by 1.0 06/10/2017 Origination DIGIT 2.0 11/04/2018 Editorial improvements DIGIT Disclaimer This document is for

More information

Integrating PingFederate with Citrix NetScaler Unified Gateway as SAML IDP

Integrating PingFederate with Citrix NetScaler Unified Gateway as SAML IDP Integrating PingFederate with Citrix NetScaler Unified Gateway as SAML IDP This guide focuses on defining the process for deploying PingFederate as an SP, with NetScaler Unified Gateway acting as the SAML

More information

Add OKTA as an Identity Provider in EAA

Add OKTA as an Identity Provider in EAA Add OKTA as an Identity Provider in EAA Log in to Akamai Luna control center with administrative privileges. Select the correct contract which is provisioned for Enterprise Application Access (EAA). In

More information

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments.

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments. TECHNICAL GUIDE SSO SAML At 360Learning, we don t make promises about technical solutions, we make commitments. This technical guide is part of our Technical Documentation. 2 360Learning is a Leading European

More information

Juniper Networks SSL VPN Integration Guide

Juniper Networks SSL VPN Integration Guide Juniper Networks SSL VPN Integration Guide Introduction Overview Terms Setting Up an Authentication Server Creating a User Role Creating a User Realm Setting Up Your Sign In URL top Introduction This document

More information

Enterprise Adoption Best Practices

Enterprise Adoption Best Practices Enterprise Adoption Best Practices Integrating FIDO & Federation Protocols December 2017 Copyright 2013-2017 FIDO Alliance All Rights Reserved. Audience This white paper is aimed at enterprises deploying

More information

4.2. Authenticating to REST Services. Q u i c k R e f e r e n c e G u i d e. 1. IdentityX 4.2 Updates

4.2. Authenticating to REST Services. Q u i c k R e f e r e n c e G u i d e. 1. IdentityX 4.2 Updates 4.2 Authenticating to REST Services Q u i c k R e f e r e n c e G u i d e In IdentityX 4.1, REST services have an authentication and signing requirement that is handled by the IdentityX REST SDKs. In order

More information

Security Analysis of eidas The Cross-Country Authentication Scheme in Europe

Security Analysis of eidas The Cross-Country Authentication Scheme in Europe Security Analysis of eidas The Cross-Country Authentication Scheme in Europe Nils Engelbertz, Nurullah Erinola, David Herring, Juraj Somorovsky, Vladislav Mladenov, Jörg Schwenk Ruhr University Bochum

More information

FAS SAML Integration Guide

FAS SAML Integration Guide FAS SAML Integration Guide Digitale Transformatie Date 04/01/2018 Version 0.5 DOCUMENT INFORMATION Document Title FAS SAML Integration Guide File Name FAS SAML_Integration_Guide_v0.5.docx Subject Document

More information

SAML-Based SSO Solution

SAML-Based SSO Solution About SAML SSO Solution, page 1 Single Sign on Single Service Provider Agreement, page 2 SAML-Based SSO Features, page 2 Basic Elements of a SAML SSO Solution, page 3 Cisco Unified Communications Applications

More information

All about SAML End-to-end Tableau and OKTA integration

All about SAML End-to-end Tableau and OKTA integration Welcome # T C 1 8 All about SAML End-to-end Tableau and OKTA integration Abhishek Singh Senior Manager, Regional Delivery Tableau Abhishek Singh Senior Manager Regional Delivery asingh@tableau.com Agenda

More information

JBoss Federated SSO Framework

JBoss Federated SSO Framework JBoss Federated SSO Framework Presenter: Sohil Shah Company: Red Hat, JBoss Division Title: Software Engineer Projects: JBoss Portal, JBoss Federated SSO Date: February 14, 2008 Agenda Single Sign On Benefits

More information

ADP Federated Single Sign On. Integration Guide

ADP Federated Single Sign On. Integration Guide ADP Federated Single Sign On Integration Guide September 2017 Version 4.4 ADP and the ADP logo are registered trademarks of ADP, LLC. Contents Overview of Federation with ADP... 3 Security Information...

More information

Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide

Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide Version 12.0-4/17/2018 Copyright Copyright 2018 Upland Qvidian. All rights reserved. Information in this document is subject to change

More information

Kerberos SAML Profiles

Kerberos SAML Profiles 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 Kerberos SAML Profiles Working Draft 03, 10 th February 2004 Document identifier: draft-sstc-solution-profile-kerberos-03

More information

eidas SAML Message Format

eidas SAML Message Format eidas SAML Message Format Version 1.1 1 Introduction The eidas interoperability framework including its national entities (eidas-connector and eidas- Service) need to exchange messages including personal

More information

Internet-Draft Intended status: Informational Expires: July 29, 2016 M. Machulak Cloud Identity D. Catalano Oracle January 26, 2016

Internet-Draft Intended status: Informational Expires: July 29, 2016 M. Machulak Cloud Identity D. Catalano Oracle January 26, 2016 Network Working Group Internet-Draft Intended status: Informational Expires: July 29, 2016 T. Hardjono, Ed. MIT E. Maler ForgeRock M. Machulak Cloud Identity D. Catalano Oracle January 26, 2016 User-Managed

More information

April Understanding Federated Single Sign-On (SSO) Process

April Understanding Federated Single Sign-On (SSO) Process April 2013 Understanding Federated Single Sign-On (SSO) Process Understanding Federated Single Sign-On Process (SSO) Disclaimer The following is intended to outline our general product direction. It is

More information

Electronic ID at work: issues and perspective

Electronic ID at work: issues and perspective Electronic ID at work: issues and perspective Antonio Lioy < lioy @ polito.it > Politecnico di Torino Dip. Automatica e Informatica Why should I have/use an (e-) ID? to prove my identity to an "authority":

More information

TECHNICAL GUIDE SSO SAML Azure AD

TECHNICAL GUIDE SSO SAML Azure AD 1 TECHNICAL GUIDE SSO SAML Azure AD At 360Learning, we don t make promises about technical solutions, we make commitments. This technical guide is part of our Technical Documentation. Version 1.0 2 360Learning

More information

Qualys SAML & Microsoft Active Directory Federation Services Integration

Qualys SAML & Microsoft Active Directory Federation Services Integration Qualys SAML & Microsoft Active Directory Federation Services Integration Microsoft Active Directory Federation Services (ADFS) is currently supported for authentication. The Qualys ADFS integration must

More information

SAML-Based SSO Solution

SAML-Based SSO Solution About SAML SSO Solution, page 1 SAML-Based SSO Features, page 2 Basic Elements of a SAML SSO Solution, page 2 SAML SSO Web Browsers, page 3 Cisco Unified Communications Applications that Support SAML SSO,

More information

ONE ID Provincial Identity Federation

ONE ID Provincial Identity Federation ONE ID Provincial Identity Federation Overview of SAML Configuration Version: 1.49 Table of Contents 1.0 About This Document 5 1.1 Audience...5 1.2 Reference material...5 2.0 Introduction Identity Federation

More information

GFIPM Web Browser User-to-System Profile Version 1.2

GFIPM Web Browser User-to-System Profile Version 1.2 About the Document Justice organizations are looking for ways to provide secured access to multiple agency information systems with a single logon. The Global Federated Identity and Privilege Management

More information

SAML V2.0 Basics. Eve Maler Sun Microsystems, Inc.

SAML V2.0 Basics. Eve Maler Sun Microsystems, Inc. SAML V2.0 Basics Eve Maler eve.maler@sun.com Sun Microsystems, Inc. Updated 2 October 2006 This presentation may be copied and reused with attribution Topics The big picture The standards landscape SAML

More information

This section includes troubleshooting topics about single sign-on (SSO) issues.

This section includes troubleshooting topics about single sign-on (SSO) issues. This section includes troubleshooting topics about single sign-on (SSO) issues. SSO Fails After Completing Disaster Recovery Operation, page 1 SSO Protocol Error, page 1 SSO Redirection Has Failed, page

More information

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow)

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow) Integration Guide PingFederate SAML Integration Guide (SP-Initiated Workflow) Copyright Information 2018. SecureAuth is a registered trademark of SecureAuth Corporation. SecureAuth s IdP software, appliances,

More information

Advanced Configuration for SAML Authentication

Advanced Configuration for SAML Authentication The advanced configuration for SAML authentication includes: Configuring Multiple Identity Providers Multiple Identity Providers can be configured to a SAML authentication service on the Barracuda Web

More information

SAML-Based SSO Configuration

SAML-Based SSO Configuration Prerequisites, page 1 SAML SSO Configuration Task Flow, page 5 Reconfigure OpenAM SSO to SAML SSO Following an Upgrade, page 9 SAML SSO Deployment Interactions and Restrictions, page 9 Prerequisites NTP

More information

Morningstar ByAllAccounts SAML Connectivity Guide

Morningstar ByAllAccounts SAML Connectivity Guide Morningstar ByAllAccounts SAML Connectivity Guide 2018 Morningstar. All Rights Reserved. AccountView Version: 1.55 Document Version: 1 Document Issue Date: May 25, 2018 Technical Support: (866) 856-4951

More information

SAML 2.0 SSO. Set up SAML 2.0 SSO. SAML 2.0 Terminology. Prerequisites

SAML 2.0 SSO. Set up SAML 2.0 SSO. SAML 2.0 Terminology. Prerequisites SAML 2.0 SSO Agiloft integrates with a variety of SAML authentication providers, or Identity Providers (IdPs). SAML-based SSO is a leading method for providing federated access to multiple applications

More information

Integrating VMware Workspace ONE with Okta. VMware Workspace ONE

Integrating VMware Workspace ONE with Okta. VMware Workspace ONE Integrating VMware Workspace ONE with Okta VMware Workspace ONE You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have comments about this

More information

Single Sign-On Administrator Guide

Single Sign-On Administrator Guide Single Sign-On Administrator Guide Last Revised February 15, 2018 Version 1.7 Disclaimer LinkedIn Corporation 1000 W. Maude Ave. Sunnyvale, CA 94085 This document may contain forward looking statements.

More information

Single Sign-On Administrator Guide

Single Sign-On Administrator Guide Single Sign-On Administrator Guide Last Revised October 2018 Version 1.8 Disclaimer LinkedIn Corporation 1000 W. Maude Ave. Sunnyvale, CA 94085 This document may contain forward looking statements. Any

More information

K-PAC Reporting Guide

K-PAC Reporting Guide K-PAC Reporting Guide Access the K-PAC Report Web application by requesting access through the KSDE Application Portal. The KSDE Application Portal requires that permissions for log-in be approved by the

More information

http://hdl.handle.net/2022/21724 https://registry.vo.idm.training/slides Research Identity Management Process Needs 1 What Is A Collaboration? A cross-organizational collecton of people who come together

More information

CA SiteMinder. Federation in Your Enterprise 12.51

CA SiteMinder. Federation in Your Enterprise 12.51 CA SiteMinder Federation in Your Enterprise 12.51 This Documentation, which includes embedded help systems and electronically distributed materials (hereinafter referred to as the Documentation ), is for

More information

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29 Oracle Access Manager Configuration Guide 16 R1 March 2016 Contents Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 8 Installing Oracle HTTP Server...

More information

Table of Contents. Single Sign On 1

Table of Contents. Single Sign On 1 Table of Contents Table of Contents Single Sign On SAML Authentication Using SAML SSO Authentication Setting up SAML SSO Authentication Configuring OneLogin as an Identity Provider LDAP Authentication

More information

NETOP PORTAL ADFS & AZURE AD INTEGRATION

NETOP PORTAL ADFS & AZURE AD INTEGRATION 22.08.2018 NETOP PORTAL ADFS & AZURE AD INTEGRATION Contents 1 Description... 2 Benefits... 2 Implementation... 2 2 Configure the authentication provider... 3 Azure AD... 3 2.1.1 Create the enterprise

More information

RSA SecurID Access SAML Configuration for Datadog

RSA SecurID Access SAML Configuration for Datadog RSA SecurID Access SAML Configuration for Datadog Last Modified: Feb 17, 2017 Datadog is a monitoring service for cloud-scale applications, bringing together data from servers, databases, tools, and services

More information

Quick Connection Guide

Quick Connection Guide WebEx Connector Version 1.0.1 Quick Connection Guide 2014 Ping Identity Corporation. All rights reserved. PingFederate WebEx Connector Quick Connection Guide Version 1.0.1 March, 2014 Ping Identity Corporation

More information

Enabling Single Sign-On Using Okta in Axon Data Governance 5.4

Enabling Single Sign-On Using Okta in Axon Data Governance 5.4 Enabling Single Sign-On Using Okta in Axon Data Governance 5.4 Copyright Informatica LLC 2018. Informatica and the Informatica logo are trademarks or registered trademarks of Informatica LLC in the United

More information

Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML)

Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML) Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML) 1. Overview This document is intended to guide users on how to integrate their institution s Dell Cloud Access Manager

More information

RSA SecurID Ready Implementation Guide. Last Modified: December 13, 2013

RSA SecurID Ready Implementation Guide. Last Modified: December 13, 2013 Ping Identity RSA SecurID Ready Implementation Guide Partner Information Last Modified: December 13, 2013 Product Information Partner Name Ping Identity Web Site www.pingidentity.com Product Name PingFederate

More information

Configure Unsanctioned Device Access Control

Configure Unsanctioned Device Access Control Configure Unsanctioned Device Access Control paloaltonetworks.com/documentation Contact Information Corporate Headquarters: Palo Alto Networks 3000 Tannery Way Santa Clara, CA 95054 www.paloaltonetworks.com/company/contact-support

More information

Oracle Access Manager Configuration Guide

Oracle Access Manager Configuration Guide Oracle Access Manager Configuration Guide 16 R2 September 2016 Contents Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server...

More information

Single Sign-On (SSO)Technical Specification

Single Sign-On (SSO)Technical Specification Single Sign-On (SSO)Technical Specification Audience: Business Stakeholders IT/HRIS Table of Contents Document Version Control:... 3 1. Overview... 4 Summary:... 4 Acronyms and Definitions:... 4 Who Should

More information

Cisco Webex Control Hub

Cisco Webex Control Hub Data Sheet Cisco Webex Control Hub (Management and Analytics) 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 12 Management and analytics overview

More information

Configuration Guide - Single-Sign On for OneDesk

Configuration Guide - Single-Sign On for OneDesk Configuration Guide - Single-Sign On for OneDesk Introduction Single Sign On (SSO) is a user authentication process that allows a user to access different services and applications across IT systems and

More information

WebEx Connector. Version 2.0. User Guide

WebEx Connector. Version 2.0. User Guide WebEx Connector Version 2.0 User Guide 2016 Ping Identity Corporation. All rights reserved. PingFederate WebEx Connector User Guide Version 2.0 May, 2016 Ping Identity Corporation 1001 17th Street, Suite

More information

Single Sign-On for PCF. User's Guide

Single Sign-On for PCF. User's Guide Single Sign-On for PCF Version 1.2 User's Guide 2018 Pivotal Software, Inc. Table of Contents Table of Contents Single Sign-On Overview Installation Getting Started with Single Sign-On Manage Service Plans

More information

About This Document 3. Overview 3. System Requirements 3. Installation & Setup 4

About This Document 3. Overview 3. System Requirements 3. Installation & Setup 4 About This Document 3 Overview 3 System Requirements 3 Installation & Setup 4 Step By Step Instructions 5 1. Login to Admin Console 6 2. Show Node Structure 7 3. Create SSO Node 8 4. Create SAML IdP 10

More information

RECOMMENDED DEPLOYMENT PRACTICES. The F5 and Okta Solution for High Security SSO

RECOMMENDED DEPLOYMENT PRACTICES. The F5 and Okta Solution for High Security SSO July 2017 Contents Introduction...3 The Integrated Solution...3 Prerequisites...4 Configuration...4 Set up BIG-IP APM to be a SAML IdP...4 Create a self-signed certificate for signing SAML assertions...4

More information

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE GUIDE MARCH 2019 PRINTED 28 MARCH 2019 CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE VMware Workspace ONE Table of Contents Overview Introduction Audience AD FS

More information

User Management Interfaces for Earth Observation Services

User Management Interfaces for Earth Observation Services Open Geospatial Consortium Inc. Date: 2009-06-30 Reference number of this OGC project document: 07-118r1 Version: 0.0.4 Category: OGC Interoperability Program Report Editors: R.Smillie, A.Cucumel SPACEBEL

More information

ComponentSpace SAML v2.0 Okta Integration Guide

ComponentSpace SAML v2.0 Okta Integration Guide ComponentSpace SAML v2.0 Okta Integration Guide Copyright ComponentSpace Pty Ltd 2017-2018. All rights reserved. www.componentspace.com Contents Introduction... 1 Adding a SAML Application... 1 Service

More information

Oracle Utilities Opower Energy Efficiency Web Portal - Classic Single Sign-On

Oracle Utilities Opower Energy Efficiency Web Portal - Classic Single Sign-On Oracle Utilities Opower Energy Efficiency Web Portal - Classic Single Sign-On Configuration Guide E84772-01 Last Update: Monday, October 09, 2017 Oracle Utilities Opower Energy Efficiency Web Portal -

More information

Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief

Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief Qualys SAML 2.0 Single Sign-On (SSO) Technical Brief Qualys provides its customers the option to use SAML 2.0 Single SignOn (SSO) authentication with their Qualys subscription. When implemented, Qualys

More information

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate SafeNet Authentication Manager Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

ArcGIS Server and Portal for ArcGIS An Introduction to Security

ArcGIS Server and Portal for ArcGIS An Introduction to Security ArcGIS Server and Portal for ArcGIS An Introduction to Security Jeff Smith & Derek Law July 21, 2015 Agenda Strongly Recommend: Knowledge of ArcGIS Server and Portal for ArcGIS Security in the context

More information

SAML 2.0 Single Sign On with Citrix NetScaler

SAML 2.0 Single Sign On with Citrix NetScaler SAML 2.0 Single Sign On with Citrix NetScaler This guide focuses on defining the process for deploying NetScaler as a SAML IdP for most enterprise applications that support SAML 2.0. Citrix.com 1 Citrix

More information

Slack Connector. Version 2.0. User Guide

Slack Connector. Version 2.0. User Guide Slack Connector Version 2.0 User Guide 2015 Ping Identity Corporation. All rights reserved. PingFederate Slack Connector User Guide Version 2.0 December, 2015 Ping Identity Corporation 1001 17th Street,

More information

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5 esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5 Phone: 1-855-MYESIGN Fax: (514) 337-5258 Web: www.esignlive.com

More information

Mozy. Implementing with Federated Identity

Mozy. Implementing with Federated Identity Mozy Implementing with Federated Identity Preface 2017 Mozy, Inc. All rights reserved. Information in this document is subject to change without notice. The software described in this document is furnished

More information

SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.0(1)

SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.0(1) SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.0(1) First Published: 2017-08-31 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706

More information

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. PingIdentity PingFederate 8

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. PingIdentity PingFederate 8 RSA SECURID ACCESS Implementation Guide PingIdentity John Sammon & Gina Salvalzo, RSA Partner Engineering Last Modified: February 27 th, 2018 Solution Summary Ping Identity

More information

Connect-2-Everything SAML SSO (client documentation)

Connect-2-Everything SAML SSO (client documentation) Connect-2-Everything SAML SSO (client documentation) Table of Contents Summary Overview Refined tags Summary The Connect-2-Everything landing page by Refined Data allows Adobe Connect account holders to

More information