PingOne Provider Setup¶
This document describes the steps to configure PingOne as an Identity Provider to integrate with Cyderes. Cyderes will act as the SAML Service Provider or "SAML SP".
Configuring SSO¶
Adding a New Application¶
- Log in to the PingOne organization admin console
- Click on the Applications link in the top navigation bar
- Click on the Add Application > New SAML Application option
- In the New Application wizard that appears, provider an Application Name, Application Description, and a Category. Optionally provide a custom Application Icon graphic.
- Click Continue to Next Step
- In Application Configuration, ensure the I have the SAML configuration option is selected. In the Assertion Consumer Service (ACS) form field, paste the ACS URL provided by Cyderes.
- In the Entity ID field, paste the Audience URI value provided by Cyderes. Click the Continue to Next Step button at the button of the screen.
-
In the SSO Attribute Mapping section, add the three attribute statements:
Application Attribute Identity Bridge Attribute or Literal Value Required FirstName First Name Yes LastName Last Name Yes Email Email Yes -
Click Continue to Next Step
- On the Group Access assignment page, assign the necessary users from the IdP with access to this SAML application. Only these users will be able to access Cyderes applications from the IdP.
- Click Continue to Next Step
- On the Review Setup page, select Finish
Gather Information¶
Send the SAML metadata as well as the Signing Certificate from PingOne to Cyderes in order to allow Cyderes to add the PingOne instance as an IdP. Both pieces of information can be downloaded from the PingOne console by viewing the newly SAML application details and clicking on the Download links for both items.