How to Set Up SSO Using Centrify
Apica supports Single Sign-On (SSO) using SAML and Centrify.
Centrify provides an identity provider (IdP) service with its own users and roles management, integrating with ASM.
How to Create a User in Centrify
Step
Screenshot
To access the SSO settings, click the button in the top right corner of the User view.
Click the green “Single Sign-On (SAML 2.0) button Settings Dialog screen.
The SSO view contains all settings needed to connect a user account with a SAML provider account.
SERVICE PROVIDER
Use this information about ASM as a Service Provider to set up your Identity Provider.
Service Provider Entity ID
Use this URL to identify ASM to your IdP uniquely and get the Service Provider’s (Apica’s) Metadata.
Assertation Consumer Service URL
Set your IdP to post SAML responses to this URL.
SAML ATTRIBUTE STATEMENTS MAPPING
ASM requires several attributes to be presented in SAML assertion. Note that attribute names may include namespaces.
User Name (A UNIQUE SAML attribute statement name for user name.)
Full Name (SAML attribute statement name for user's full name.)
Email (SAML attribute statement name for user's full name.)
Identity Provider Roles (SAML attribute statement name for user's roles list provided by your IdP.)
Set Default (Apply default settings for Centrify.)
Reset (Clear the settings.)
ROLES MAPPING
The Identity Provider User roles/groups must map to User Roles and Monitor Groups to access Apica Synthetic Monitoring.
Make sure that SAML roles you use already exist in Centrify.
Identity Provider Roles Mapping (Associate roles used in the IdP with User Roles and Monitor Groups in ASM)
IdP Role / Group (Name of user role (or group) in the IdP.)
User Roles (List of User Roles in ASM to associate with the IdP role.)
Monitor Groups (List of Monitor Groups in ASM to associate with the IdP role.)
Co-Owned Monitor Groups (List of Monitor Groups for the Customer Power User Role to associate as co-owner with the IdP role.)
Comment (Additional information about the mapping.)
Overwrite Access Settings for Monitor Groups (Access settings for Monitor Groups will be overwritten every time the user logs in.)
Check = Yes to Override with each login.
Uncheck (default) = Accept default Access permissions
Loggin into ASM using Centrify’s SSO
You can log in with a user existing in Centrify and be granted access to the application (it's described above). After successful login, you will be redirected back to ASM. If you were already logged in to Centrify, then you will be redirected automatically to ASM. If you want to use another test user, go to the Centrify user SSO page (https://12345.my.centrify.com/my and press log out).
Step
Screenshot
With the setup used in the examples above, go to http://alpha.foo.com, log out.
On the log in page, choose "Sign in using SSO"
Insert customer name SSOTestA, and press "Continue."
You will be redirected to the Centrify log-in page.
You can log in with a user existing in Centrify and granted access to the application, as described above.
After successful login, you will be redirected back to ASM.
If you were already logged in to Centrify, then you will be redirected automatically to ASM.
If you want to use another test user, go to the Centrify user SSO page and press log out.
Was this helpful?