CloudAMQP - SAML Relying Party Configuration - SecurID Access Implementation Guide
2 years ago
Originally Published: 2021-08-18

CloudAMQP - SAML Relying Party Configuration - SecurID Access Implementation Guide

This section describes how to integrate SecurID Access with CloudAMQP using Relying Party. Relying party uses SAML 2.0 to integrate SecurID Access as a SAML Identity Provider (IdP) to CloudAMQP SAML Service Provider (SP).

Architecture Diagram

kotlad1_0-1629321948265.png

 

Configure SecurID Cloud Authentication Service

Perform these steps to configure SecurID Cloud Authentication Service as a relying party SAML IdP to CloudAMQP .

Procedure

    1. Sign into the Cloud Administration Console and browse to Authentication Clients > Relying Parties and click Add a Relying Party.

kotlad1_1-1629321975146.png

 

kotlad1_2-1629322009890.png

 

    1. On Basic Information page enter a Name for the application, ie. CloudAMQP Then click on Next Step.

    2. On Authentication page

        1. select the SecurID Access manages all authentication

        2. Select the desired Primary Authentication Method from the dropdown list.

        3. Select the desired policy from the Access Policy for Additional Authentication.

        4. Click Next Step

      kotlad1_3-1629322043630.png
    3. On Connection Profile page

        1. Enter the Assertion Consumer Service (ACS) From the ACS URL CloudAMQP configuration below. For example: https://customer.cloudamqp.com/login/saml.

        2. Enter the Service Provider Entity ID From the SAML Audience URL in theCloudAMQP configuration below. For example: https://customer.cloudamqp.com/saml/metadata/ee8269ae-d46a-473e-ba33-d5f7ed15afe2.

        3. In the Message Protection section, check the idP Signs: Entire SAML response.

        4. Open Advanced Configuration section.

        5. For Name ID set Identifier type = EmailAddress and Property = mail
        6. Click on Save and Finish

      kotlad1_4-1629322075233.png
    4. Browse to Authentication Clients > Relying Parties

    5. Scroll down to the your newly created Relying party and click down error next to Edit and choose View or Download IdP MetatData and download the Metadata File.
      kotlad1_5-1629322105923.png

 

  1. Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.
    kotlad1_6-1629322127422.png

 

Configure CloudAMQP

Perform these steps to integrate CloudAMQP with SecurID Access as a Relying Party SAML SP.

Procedure

  1. Sign into CloudAMQP and browse to Team Settings > SAML.

  2. Note the ACS URL and SAML Audience URL these are used above in the SecurID Cloud Authenitcation Service (CAS) configuration above.

  3. For the Issuer/Entity ID enter the Issuer Entity ID from the SecurID Cloud Authenitcation Service (CAS) configuration above. For example, 2kshvydovyh.

  4. Save changes.

Configuration is complete.

See main page for more certification information.