This article covers the following:
Single Sign-On Administration Page
Single Sign-On (SSO) self-service is available for users with the SSO Admin role. The SSO Admin is a corporate-level role that can be granted by users with the User Admin role. The role is unassigned by default.
SSO Admins can access the Single Sign-On Administration link from the Corporate Profile page.
Accessing the SSO Admin page:
- Under the user's name at the top of the page, click Corporate Profile. The Corporate Profile page displays.
-
In the QuickLinks panel, click Single Sign On Administration.
The Single Sign On Administration page displays.
- Complete each field / section of the SSO Admin page as applicable, including fields marked with an asterisk (*) which indicates a required entry.
Settings
Complete each field under Settings as appropriate:
- Profiles - Web Post Profile (default value).
- Assertion Issuer - Issuer identifier.
-
Domain
The Domain area identifies the domains (domainname.com) a user is routed to once they are signed on.
A Domain must be configured to use the sign-in process when using the Outlook Add-in.
Adding a domain:
- In the Domain field, enter the domain (if entering multiple domains, separate with a comma).
-
Click +Add. The domain is added to the list of available domains.
Up to a maximum of 25 domains are allowed.
- Single Sign Out URL - URL for redirect when session timeout occurs.
- XPath - XPath location for the client’s external ID that is mapped to a CounselLink User.
- SSO ID Identifier - Field Label to be displayed when the SSO ID will be preceded by a special string such as "uid". Blank by default.
- SSO ID Label - Field Label to be displayed on the CounselLink User Profile for SSO ID. The default text setting is "SSO ID".
- Authentication of SSO ID is case sensitive? - Default setting is "No."
- Response Timeout (minutes) - Default setting is 1500.
- IDP Request receiving type - Identity Provider Authentication (AuthN) Request Receiving Type.
- IDP request URL - Identity Provider Authentication (AuthN) Request URL.
Certificate
Up to a maximum of three (3) Certificates can be added. Old Certificates can also be removed.
Under the Certificate section of the SSO Admin page, select the client-provided signing certificate.
SP Metadata
-
In the Certificate section of the SSO Admin page, click the SP Metadata button.
-
Click the Open file link at the bottom of the screen.
The file displays.
- Click Close (X).
Add Certificate
- Click Add Certificate in the Certificate section.
-
Enter the name and contents of the certificate under the X509 Certificate section.
There is a maximum of three (3) x.509 certificates.
- Click Save to add the certificate.
Remove Certificate
- In the Certificate section of the SSO Admin screen, select the certificate to be removed.
- Click Remove Certificate.
- Click Save to remove the certificate.
Delete
- In the Certificate section of the SSO Admin screen, select the certificate to be deleted.
-
Click Delete.
The Are you sure you want to Delete this SSO configuration? screen displays.
- Click Yes, Delete to delete the certificate.
Import Metadata
-
In the Certificate section of the SSO Admin screen, click Import Metadata.
- From the Import Metadata screen, in the Metadata URL field, enter the URL where the contents are stored.
- Click Retrieve.
- From the Import Metadata screen, select the appropriate record, and then click Import.
Assigning Single Sign-on Admin Role
- Under the user's name at the top of the page, click Corporate Profile. The Corporate Profile page displays.
-
In the QuickLinks panel, click the User Roles link. The User Roles page displays.
- Scroll to the far right of the screen and place a check mark in the SSO Admin box for the user being assigned the role.
-
Click Save.
The Corporate Profile screen updates to display the Single Sign On Administration link for the user assigned the role.
Signing in with SSO
-
Click the Sign In With SSO link on the sign in page.
- Enter the Email Address.
- Click Sign In With SSO. The log-in page (as configured by the client on the Single Sign On Administration page) displays.
- Enter your credentials.
- Click Log In.