Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Section
bordertrue


Column

Log on to the DualShield Administration Console and go to Authentication>Logon Procedure 


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Click on Image RemovedImage Added on the top right.

Section
bordertrue


Column

In the new Logon Procedure window, please enter the following information:

OptionValue
Name:Enter a friendly name
Type:Web SSO

Click: Save


Column
width50%



Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Add Logon Steps

Section
bordertrue


Column

Select the drop down menu corresponding to the Logon Procedure you will be using and click on Logon Steps.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



In the Logon Steps Dialogue box, click the Image RemovedImage Added button.

Section
bordertrue


Column

Tick the desired authentication method, e.g. Static Password



Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Click Save.


Repeat to add extra steps.

Section
bordertrue


Column
I have added two steps; Static Password and One-Time Password


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

 Image RemovedImage Added




Create an Application

Section
bordertrue


Column

Authentication> Applications


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Click on Image RemovedImage Added on the top right.

...

Section
bordertrue


Column

In the new Application window, please enter the following information:

OptionValue
Name:Enter a friendly name
Realm:Select your Realm
Logon Procedure:

Select the Logon Procedure you had created in the previous step

Click: Save


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Bind the Application to an SSO Server Agent

...

Section
bordertrue


Column

Select the drop down menu corresponding to the Application you will be using and click on Agents.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added




Section
bordertrue


Column

Tick the box of the SSO Server you will be using and click Save below.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Create a Service Provider Profile

...

Section
bordertrue


Column

Go to SSO>Service Providers


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



Click on Image RemovedImage Added on the top right.

...

Section
bordertrue


Column

Fill in the details as per screenshot on right and make sure you select SAML 2.0(Without Metadata) as Type.using the following values

OptionValue
Type:OpenID Connect
SSO Server:Select the SSO server you applied as the aplication agent. (see above)
Application:

Select the name of the Application from the drop down list

Name

Type a frienly name to identify which application this Serrvice Provider will be associated with

NameID Format

Keep as SAM Account Name



Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added





Section
bordertrue


Column

Now fill out Entity ID and ACS URLExpand the BASIC tab and set the values below, leaving the remainining default values.

OptionValue
Entity ID
Redirect URIs:

https://

prefix

x.x.

yourdomainname.comACS URL

x.x:5176/oidcauth

Post Logout Redirect URIs:

https://

prefix

x.x.

yourdomainname

x.

com/ServicesPortal/saml

x:5176/login.html

*Replace the x.x.x.x with the IP of the ConsoleWorks server.

Image Added Scroll down to the next value 


Column
width50%


Image Removed
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Added



Click Save.

Obtain the OIDC Authorization Endpoint URL

Section
bordertrue


Column

Go to SSO>SSO Servers


Column
width50%


Image Added




Section
bordertrue


Column

The completed Service Provider dialogue box will look like this:Select the drop down menu corresponding to the SSO server you will be using and click on Edit


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added

Click Save.





Section
bordertrue

Download the IDP Metadata file.

...

bordertrue


Column

Click on the OpenID Connect tab and copy out the Discovery URL.  

If the URLs are not displaying click on the LOAD DEFAULT button first.



Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Added



Click Save.

Check the endpoint can be discovered on the ConsoleWorks server

Column

Go to SSO>SSO Servers

...

width50%

...

Section
bordertrue


Column

Open a browser on the ConsoleWorks Server and paste in the Discovery URL. You should see something similar to the picture.

If the URL cannot be reached, then you need to fix this first before moving on to the next section

Select the drop down menu corresponding to the SSO server you will be using and click on Download IDP Metadata

.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added