Create a Web logon procedure
- Login to the DualShield Management Administration Console
- In the main menu, select “Authentication | > Logon Procedure”Procedures”
- Click the “Create” “+ CREATE” button on the toolbar, on the right
- Enter a recognisable “Name” and select “Web SSO” as the typeType
Image Removed
Image Added
- Click “Save”“SAVE”
- Click the Context Menu icon of the newly created logon procedureLogon Procedure, select “Logon Steps”
- In the popup windowswindow, click the “Create” “+ ADD” button on the toolbar
- Select the authentication method.
Image RemovedAdd the necessary Authentication methods here
Image Added
Create a Web application
- In the main menu, select “Authentication | Application”> Applications”
- Click the “Create” “+ CREATE” button on the toolbar
- Enter a recognisable “Name”
- Select your internal “Realm”
- Select Add the newly created logon procedure
Image RemovedLogon Procedure (from the previous step)
Image Added
- Click "Save"
- Click the context "..." menu of the newly created applicationApplication, then select "Agent"
- Select the SSO Server
Image Removed"Single Sign-on Server (SSO Server)"
Image Added
- Click "Save"
- Click the context "..." menu of the newly created applicationApplication, select then select "Self Test"
Image Removed
Image Added
- In the main menu, select navigate to " SSO | > SSO Servers"
- Click the context "..." menu of "Download IdP Metadata", and select the application created earlier.
Image Removed
Create a Service Provider
- Single Sign-on Server (SSO Server") then select "Download Idp MetaData" .
Note the Name and location of the XML file, saved locally.
Image Added
service provider , firstly complete Splunk SAML configuration and download the - In the main menu, select navigate to "SSO | Service Providers"
- Click "Create"the "+ CREATE" button in the toolbar
- Select the SSO Server drop-down and select "Single Sign-on Server"
- At the 'Application' drop-down, select the Splunk Application previously created.
- Enter a suitable "Name"
- Set 'Type' Enter "Name", Select Type as "SAML 2.0"
Image Added
- Select the "CREATE METADATA" button.
- At the window that appears, paste in to the large Metadata textbox, the Copy the content of Service Provider Metadata (contained in SPMetadata.xml) into the "Metadata" field.
Image Removed
- Click Edit for Attribute and create a role attribute map to a fix the "Attributes" tab, to create a new custom Attribute, that will be mapped to a fixed value that match the name of the Splunk group, for instance: "admin
Image Removed" - Click the "+ CREATE" button
- Location at the drop-down, set as "HTTP Body"
- Name could be entered as "role"
- Beneath the 'Value' section, select "Fixed Value". Then set the Value in the textbox as "admin"
Image Added
- Click "SAVE" to create the custom attribute.
- Click back to the 'General Settings' tab, of the Service Provider.
- At the 'NameID Format' field, change this field to Select "User Principle Name" on NameID Fromat drop down list.
Image Removed.
Image Added
- Finally select "SAVE", to complete the Service Provider creation process.
{"serverDuration": 74, "requestCorrelationId": "7fd8eb5c2d73628d"}