Difference between revisions of "Template:VALT 6 SSO Configuration"
IVSWikiBlue (talk | contribs) (Created page with "__NOTOC__ {{Article | title = SSO Configuration | content = {{Aside - Warning | hue = 50 | content = VALT is compatible with <b>SAML 2.0</b>.}} {{Aside | content = To access...") |
IVSWikiBlue (talk | contribs) |
||
Line 6: | Line 6: | ||
{{hr}} | {{hr}} | ||
− | == | + | ==Scheduling an SSO Configuration== |
Before configuring SSO in VALT, please make sure you've completed our [[SSO Check List]]. | Before configuring SSO in VALT, please make sure you've completed our [[SSO Check List]]. | ||
− | You can also schedule a <b>SSO Discovery</b> at our [https://ivs.help booking site] under <b>Schedule a Support Session</b>. | + | You can also schedule a <b>SSO Discovery</b> at our [https://ivs.help booking site] under <b>Schedule a Support Session</b>. During that call, we will discuss the prerequisites for configuring your VALT server to utilize SSO Authentication. |
{{hr}} | {{hr}} | ||
==Required Information from IdP== | ==Required Information from IdP== | ||
− | + | <dt>IdP Metadata File</dt> | |
− | + | <dd class="singleLineHeight">To integrate your IdP with VALT, the metadata files from both will need to be exchanged. The VALT metadata file will be generated after the IdP metadata file is uploaded to VALT.</dd> | |
− | <dt> | + | <dt>User Mapping</dt> |
− | <dd class="singleLineHeight"> | + | <dd class="singleLineHeight">VALT's SSO uses a 1:1 mapping to add users to the correct groups. To achieve this, we require the following attributes: |
− | |||
− | |||
− | |||
− | |||
− | <dt> | ||
− | <dd class="singleLineHeight"> | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | + | <b>Unique User Identifier</b> - This attribute will be used as the username | |
− | < | + | <b>Groups</b> - This attribute will be used to define which group the user is assigned to within VALT. In addition to the name of the Group attribute, VALT will need the value associated with each group that will be logging into VALT |
− | |||
+ | <b>Display Name</b> - If the Unique User identifier does not correspond with the person's name, this attribute will set an easy-to-identify display name for the user</dd> | ||
{{hr - 2}} | {{hr - 2}} | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
<h3>Optional Items</h3> | <h3>Optional Items</h3> | ||
Line 57: | Line 31: | ||
<dl> | <dl> | ||
− | |||
− | |||
− | |||
<dt>PIN</dt> | <dt>PIN</dt> | ||
<dd class="singleLineHeight">This specifies the code used for authentication into [[BEAM]].</dd> | <dd class="singleLineHeight">This specifies the code used for authentication into [[BEAM]].</dd> |
Revision as of 11:38, 22 November 2024
SSO Configuration
⚠VALT is compatible with SAML 2.0.
✎To access SSO on your system, you may need to reach out to our support team. IVS Support
Scheduling an SSO Configuration
Before configuring SSO in VALT, please make sure you've completed our SSO Check List.
You can also schedule a SSO Discovery at our booking site under Schedule a Support Session. During that call, we will discuss the prerequisites for configuring your VALT server to utilize SSO Authentication.
Required Information from IdP
Unique User Identifier - This attribute will be used as the username
Groups - This attribute will be used to define which group the user is assigned to within VALT. In addition to the name of the Group attribute, VALT will need the value associated with each group that will be logging into VALT
Display Name - If the Unique User identifier does not correspond with the person's name, this attribute will set an easy-to-identify display name for the user
Optional Items
VALT is also able to map custom attributes to some of the following fields for a user. Below are the user account fields that can be assigned through SSO.
- PIN
- This specifies the code used for authentication into BEAM.
- Without one set, no pin is needed to enter BEAM.
- Card Number
- This specifies the card number associated with a user.
- Only applies to customers with VALT Card Reader.
- The users email can also be pulled into the system.
- If the VALT application is not connected to mail server, this field is not used for anything.
Additional Settings
Shibboleth needs the following settings configured to function with VALT.
- signAssertions:
- true
- signResponses:
- true
- encryptNameIDs:
- true
- encryptAssertions:
- false
⤺ Back to VALT SSO Main Page