Skip to main content

Get help for ARIS

Configure SSO

You can enable and configure SSO.

Prerequisite

Server

  • The SAML identity provider supports the HTTP POST binding as specified by the SAML 2.0 specification.

  • SSO must be configured for the servers.

  • You have access to the metadata XML file only if SAML is enabled.

  • ARIS must be registered as a trusted service provider at the SAML identity provider.

    Client

    Your web browser supports JavaScript.

General

Procedure. Procedure
  1. Click Application launcher Application launcher > Administration Administration.

  2. Click Settings > User Management.

  3. Check whether POST is configured for the binding.

  4. Enter the ID of the identity provider in the Identity provider ID field (entityID in the IdP metadata.xml file).

  5. Enter the ID of the service provider in the Service provider ID field, for example http(s)://<ARIS server name>.

  6. Enter the endpoint of the identity provider that is used for single sign-on in the Single sign-on URL field (SingleSignOnService URL in the IdP metadata.xml file).

  7. Enter the endpoint of the identity provider that is used for single log-out in in the Single logout URL field (SingleSignLogoutService URL in the IdP metadata.xml file).

Optional: Signature

Procedure. Procedure

    Enable the options you want to set:

    • Enforce signing of assertions

    • Enforce signing of requests

    • Enforce signing of responses

    • Enforce signing of metadata

    • Select signature algorithm

    You have enabled the signing. Depending on the signing configuration, you have to configure the truststore and keystore.

    Optional: Keystore

    1. Click Upload Upload. The dialog opens. Select the keystore file from your file system and click Upload.

    2. Configure your keystore.

    You have configured the keystore.

    Optional: Truststore

    1. Click Upload Upload. The dialog opens. Select the truststore file from your file system and click Upload.

    2. Configure your truststore.

    You have configured the truststore.

    Configure the user attributes

    • Specify the attribute fields, for example, the first name, the last name, or the e-mail.

    You have configured the user attributes.

    Advanced settings

    • Configure the authentication information according to your identity provider.

    • Authentication context classes

    • Authentication content comparison

    • NamedID format

    • Clock skew (in seconds)

    • Assertion lifetime (in seconds)