- 26 Aug 2024
- 1 Minute to read
- Print
- DarkLight
- PDF
Configure other SSO Identity Providers
- Updated on 26 Aug 2024
- 1 Minute to read
- Print
- DarkLight
- PDF
Ping Setup
On the PingOne administrator console, go to Connection :: Applications and click Add Application.
Under Advanced Configuration, select the option for SAML
Enter these details:
ACS URL (https://api.zpecloud.com/saml/2-0/<sso_name>) or (https://api.zpecloud.eu/saml/2-0/<sso_name>) depending upon the region.
Entity ID (any meaningful ID for the service)
Download the signing certificate.
On the Mapping Attributes tab, add the mail attribute.
(optional) To enable SLO, enter:
SLO Endpoint (https://api.zpecloud.com/saml/2-0/<sso_name>/logout) or (https://api.zpecloud.eu/saml/2-0/<sso_name>/logout) depending upon the region.
SLO Binding (HTTP Post)
Verification Certificate (click Import and choose the certificate previously downloaded from ZPE Cloud at SETTINGS :: SSO :: CERTIFICATE)
Click Save.
PingID Cloud Setup
On the PingOne Administrator Console, access the application.
Enter these configuration details:
Entity ID (Entity ID configured earlier)
SSO URL (Single Sign-On Service web address)
Issuer (Issuer ID)
(optional) Download metadata and upload the SSO form.
NOTE
To use the logout function, select the Single Logout checkbox, and add the single logout URL from the identity provider. If the XML file is loaded, this is automatic.
Duo
To authenticate, Duo requires the Duo Access Gateway (DAG). DAG requires a configuration specific to the selected authentication method. See the DUO website for further information.
To set up the authentication source, refer to Duo Guide (available here). Options include an external IdP, Active Directory and LDAP. After the authentication source is configured, setup the Duo Cloud application. On the Application menu, load the JSON to DAG application.
Create Application on Duo Cloud
Login to the Duo administrator account.
On the Application menu, click Protect an Application.
Use Search to locate the Generic Service Provider for DAG.
Click Protect.
Enter these details:
Service Provider Name (Name to identify the service)
Entity ID (meaningful ID to identify the service)
Assertion Consumer Service (https://api.zpecloud.com/saml/2-0/<sso_name>) or (https://api.zpecloud.eu/saml/2-0/<sso_name>) depending upon the region.
(optional) Single Logout URL (https://api.zpecloud.com/saml/2-0/<sso_name>/logout) or (https://api.zpecloud.eu/saml/2-0/<sso_name>/logout) depending upon the region.
On the SAML Response menu:
On NameID format drop-down, select unspecified.
On NameIDattribute, enter mail.
Complete these:
Unselect Sign response checkbox.
On IdP Attribute, enter mail.
On SAML Response Attribute, enter mail.
Click Save.
Download the application: JSON. In the Application menu, upload it to Duo DAG.
Duo Cloud Setup
This requires Administrator credentials.
Login to ZPE Cloud and go to SETTINGS :: SSO.
Follow the Add a new Identity Provider procedure with the required fields (located within Duo DAG at Application :: Metadata):
Entity ID (configured earlier)
SSO URL (same as metadata)
Issuer (Entity ID shown on metadata)
Download the certificate and upload it to ZPE Cloud.
(optional) To download the XML metadata and click LOAD METADATA.