In "Identity Provider Login URL", enter the Login URL of your DualShield SSO, e.g. “https://dualshield.opensid.net:8074/appsso/login”
If your DualShield's version is 5.9.4 or earlier, then you need to append the application name to the end of the Login URL, e.g. https://dualshield.opensid.net:8074/appsso/login?DASApplicationName=SalesForceSAML The value of the DASApplicationName is the name of the web application that created on DualShield Management Console for SalesForce SAML |
In "Identity Provider Logout URL" enter the Logout URL of your DualShield SSO, e.g. “https://dualshield.deepnetid.com:8074/appsso/logout”
In "Service Provider Initiated Request Binding", select "HTTP Redirect"
Click "Save"
Click "Download Metadata" and save it to a local file, e.g. Salesforce.xml
In "Authenticatrion Service", turn on the newly created single sign-on service, i.e. “DualShield”
The "Login Form" service is the SalesForce's original login form. Once you have fully tested the new SSO logon service with 2FA enabled, e.g. "DualShield" you will want to turn off the "Login Form" option. |
Click "Save"