SSO Agent - SAML Configuration - Teem RSA Ready SecurID Access Implementation Guide

Document created by RSA Information Design and Development on Jan 22, 2019Last modified by RSA Information Design and Development on Jan 22, 2019
Version 2Show Document
  • View in full screen mode

This section contains instructions on how to integrate RSA SecurID Access with Teem Teem using a SAML SSO Agent.

Architecture Diagram

RSA Cloud Authentication Service

Follow the steps in this section to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to Teem.

Procedure

1. Logon to the RSA Cloud Administration Console and browse to Applications > Application Catalog, search for Teem and click +Add to add the connector.

2. Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.

3. Navigate to Initiate SAML Workflow section.

a. In the Connection URL field, enter Uuid string from the Teem SAML app page.

b. Choose IDP-initiated.

Note: The following IDP-initiated configuration works for SP-initiated Teem connections as well.

4. Scroll down to SAML Identity Provider (Issuer) section.

a. Take note of the Identity Provider URL.

b. Take note of the Issuer Entity ID.

b. Select Choose File and upload the private key.

c. Select Choose File to import the public signing certificate.

5. Scroll down to the Service Provider section.

6. Verify the Assertion Consumer Service (ACS) URL.

7. Verify the Audience (Service Provider Entity ID).

8. Scroll down to the User Identity section. Verify the settings are correct for your environment. In this example the NameID is set to format Email Address with the value of mail.

9. Click Show Advanced Configuration.

10. Under Attribute Extension enter the following attributes:

urn:oid:0.9.2342.19200300.100.1.1 set to property mail

urn:oid:0.9.2342.19200300.100.1.3 set to property mail

urn:oid:2.5.4.4 set to property last name, sn

urn:oid:2.5.4.42 set to property first name, givenName

11. Click Next Step.

12. On the User Access page, select Allow All Authenticated Users user policy from the available options.

13. Click Next Step.

14. On the Portal Display page, select Display in Portal.

15. Click Save and Finish.

16. Click Publish Changes. Your application is now enabled for SSO.

 

Teem

Follow the steps in this section to configure Teem as an SSO Agent SAML SP to RSA Cloud Authentication Service.

Procedure

1. Login into the Teem administration console. https://app.teem.com.

2. Create your Teem SSO sub-domain. Navigate to Manage > Teen Account >Company Details.

3. Scroll down to Teem SSO Sub-Domain and enter a custom subdomain.

4. Navigate to Manage > Apps & Integrations > 3rd Party Apps.

5. Scroll down to User Management. Click ACTIVATE for the SAML app.

6. The configuration page will open.

7. Enter the name for your SAML Provider.

8. Enter the Issuer Entity ID in the Entity Id.

9. Enter the Identity Provider URL in the Signin Url field.

10. Paste the public certificate in the x509 field. Do not include the ---BEGIN and ---END CERTIFICATE markers.

11. Select Allow Just-In-Time provisioning.

12. Click Save.

13. Copy the Uuid string from the Details window. Paste the Uuid into the RSA Connection URL field.

 

Configuration is complete.

Return to the main page for more certification related information.

 

Attachments

    Outcomes