Once the Bitsight SAML app has been configured via PingOne, use the following instructions to set up single sign-on (SSO) in the PingOne application:
- Select the “RSA_SHA256” signing algorithm option or higher.
-
Configure your connection.
The default ACS URL, Entity ID, Single Logout Endpoint, and Single Logout Response Endpoint are preconfigured. They do not need to be changed for the application to work.
- Customize your PingOne dock URL.
-
Map the appropriate user attributes with fields. See the default SAML metadata attributes.
Important: You must individually set the format:uri for the First Name, Last Name, and Email fields.
- Select the “Advanced” option for each field.
- In the pop-up that follows, click in the “NameFormat” box.
- Select the “urn:oasis:names:tc:SAML:2.0:attrname-format:uri” option.
- Assign the “SAML_SUBJECT” option, unless your company has specific mappings. Do not specify any advanced “NameFormat” for it.
- Select Save & Publish.
- Review the setup.
SSO is typically handled directly through the PingOne platform, so you may wish to bookmark the “Initiate Single Sign-On (SSO)” URL.
- Download the SAML Metadata for your configured Bitsight Application.
- Take note of your SAML login URL shown in the SAML page.
- Check the Enable SAML for the account checkbox.
- Log in to Bitsight using SAML from PingOne. You may use the PingOne SSO URL, the PingOne portal, or the Bitsight-provided SAML login URL to initiate your first SAML-based login.
SAML is enabled company-wide for any other Bitsight user accounts after your initial successful log in.
- November 18, 2019: Published.
Feedback
0 comments
Please sign in to leave a comment.