Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


In order to configure Ctera for SAML2 authentication, you will need details of the Single Sign-on and Single Logout URL.

Section
bordertrue
Column

From the ConsoleWorks Navigation Window, select SECURITY > Authentication > OpenID Connect >
Add.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Modified





Section
bordertrue


Column

Go back to the DualShield Admin Console and go to SSO>Service providers. View or edit your OIDC service provider created in DualShield Configuration for ConsoleWorks

Expand the BASIC tab and copy out the Client ID and Client SecretSelect the drop down menu corresponding to the SSO server you will be using and click on View.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added





Section
bordertrue


Column

Add the following into ConsoleWorks.

OptionValue
Name:Enter a friendly name such as 'DualShield'
Title:Enter a friendly name such as 'DualShield'
Type:General
URL:Paste in the Discovery URL you had Copied from SSO>SSO Servers (refer to DualShield Configuration for ConsoleWorks)
Client ID:Paste in the Client ID you had copied from SSO>Service Providers (see above)
Client SecretPaste in the Client Secret you had copied from SSO>Service Providers (see above) 
In the view screen scroll down and click on Display Metadata



Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added





Section
bordertrue


Column

Scroll down to where you can see the SingleSignOnService and  SingleLogoutService URL.  You may want to copy and past this somewhere, ready for the next section.Expand Display Options and set the order to 1


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added



You will also need to download the IdP Certificate from the DualShield Administration Console

Section
bordertrue


Column

Select the drop down menu corresponding to the SSO server you will be using and click on Download IdP Certificate


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px




Section
bordertrue


Column

In ConsoleWorks navigate to Security>Certificates>Import and follow the prompts to import the idp cert

Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Added



Adding Users for OIDC authentication.

Please refer to ConsoleWorks' own documentation for creating Users, templates and rules, however there are two ways this can be set up:

Section
bordertrue


Column

1) New User Template is created, so that users are automatically created when they first logon. 


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Added




Section
bordertrue


Column

2) If users already exist on ConsoleWorks then connection rules need to be setup so the users are authorized DualShield as the OIDC provider,  (Please refer the ConsoleWorks support guides)

The exisiting users will then be added here:


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Added