Configure SSO
You can enable and configure SSO.
Prerequisite
Server
The SAML identity provider supports the HTTP POST binding as specified by the SAML 2.0 specification.
SSO must be configured for the servers.
You have access to the metadata XML file only if SAML is enabled.
ARIS must be registered as a trusted service provider at the SAML identity provider.
Client
Your web browser supports JavaScript.
General
Click
Application launcher >
Administration.
Click Settings > User Management.
Check whether POST is configured for the binding.
Enter the ID of the identity provider in the Identity provider ID field (entityID in the IdP metadata.xml file).
Enter the ID of the service provider in the Service provider ID field, for example http(s)://<ARIS server name>.
Enter the endpoint of the identity provider that is used for single sign-on in the Single sign-on URL field (SingleSignOnService URL in the IdP metadata.xml file).
Enter the endpoint of the identity provider that is used for single log-out in in the Single logout URL field (SingleSignLogoutService URL in the IdP metadata.xml file).
Optional: Signature
Enable the options you want to set:
Enforce signing of assertions
Enforce signing of requests
Enforce signing of responses
Enforce signing of metadata
Select signature algorithm
You have enabled the signing. Depending on the signing configuration, you have to configure the truststore and keystore.
Optional: Keystore
Click
Upload. The dialog opens. Select the keystore file from your file system and click Upload.Configure your keystore.
You have configured the keystore.
Optional: Truststore
Click
Upload. The dialog opens. Select the truststore file from your file system and click Upload.Configure your truststore.
You have configured the truststore.
Configure the user attributes
Specify the attribute fields, for example, the first name, the last name, or the e-mail.
You have configured the user attributes.
Advanced settings
Configure the authentication information according to your identity provider.
Authentication context classes
Authentication content comparison
NamedID format
Clock skew (in seconds)
Assertion lifetime (in seconds)