This article describes how to integrate RSA Cloud Access Service (CAS) with Okta using a SAML Relying Party.
Configure CAS
-
Sign in to the RSA Cloud Administration Console.
-
Click Authentication Clients > Relying Parties.
-
On the My Relying Parties page, click Add a Relying Party.
-
In the Relying Party Catalog, click Add for Service Provider SAML.
-
On the Basic Information page, enter a name for the application, and then click Next Step.
-
On the Authentication page, configure the following settings, and then click Next Step:
-
Choose RSA manages all authentication.
-
In the 2.0 Access Policy for Authentication drop-down list, select a previously configured access policy.
-
-
On the Connection Profile page, under Data Input Method, click Enter Manually.
Note: The ACS URL and SP Entity ID entered in the next step are temporary. After you configure Okta, import the Okta metadata to replace these values automatically. -
In the Service Provider section, configure the temporary values:
-
For Assertion Consumer Service (ACS) URL, enter any valid URL.
-
For Service Provider Entity ID, keep the default value.
-
-
In the SAML Response Protection section, choose IdP signs SAML assertions, and then click Download Certificate. Save the certificate for the Okta configuration.
-
Expand Advanced Configuration.
-
In the User Identity section, configure the following settings:
-
Identifier Type: Auto Detect
-
Property: Auto Detect
-
-
In the Statement Attributes section, add the following attributes:
-
Attribute Name: firstName
Attribute Source: Identity Source
Property: givenName, or the equivalent first-name attribute in your directory -
Attribute Name: lastName
Attribute Source: Identity Source
Property: sn, or the equivalent last-name attribute in your directory -
Attribute Name: email
Attribute Source: Identity Source
Property: mail, or the equivalent email attribute in your directory
-
-
In the Identity Provider section, make a note of the Entity ID and Identity Provider URL. You need these values when you configure Okta.
-
Click Save and Finish.
-
Click Publish Changes, and wait for the operation to finish.
After publishing, your application is now enabled for SSO.
Configure Okta
Perform these steps to configure Okta.
Procedure
-
Log in to the Okta Admin Console with an administrator account.
-
In the left pane, browse to Security > Identity Providers and click Add Identity Provider.
-
Choose SAML 2.0 IdP from the list of available identity providers and click Next.
-
Enter a name for the RSA Cloud Access Service IdP.
-
Under Authentication Settings, enter the following:
- In the IdP Usage drop-down list, choose SSO only.
- Clear Account matching with Persistent Name ID.
-
Under Account matching with IdP Username, enter the following:
- IdP username: Choose idpuser.subjectNameId in the drop-down list.
- Match against: Choose Email in the drop-down list. This field specifies which attribute of an existing Okta user is compared to the IdP username to determine whether an account link must be established. If an existing account link is found, no comparison is performed.
- If no match is found: Choose the action for authentication responses that do not match an existing user in the Okta organization.
-
Under SAML Protocol Settings, enter the following and click Finish:
- IdP Issuer URI: Enter the Identity Provider URL obtained from the RSA configuration.
- IdP Single Sign-On URL: Enter the Identity Provider URL obtained from the RSA configuration.
- IdP Signature Certificate: Upload the certificate downloaded from RSA.
- Request Binding: Choose HTTP POST.
- Request Signature: If selected, Okta signs its AuthnRequest. CAS must then be configured to validate the Okta signing certificate.
- Request Signature Algorithm: Choose SHA-256.
- Response Signature Verification: Choose Response or Assertion. Okta accepts the required signature when either the response or assertion is signed.
- Response Signature Algorithm: Choose SHA-256.
- Okta Assertion Consumer Service URL: Choose Trust-specific to generate an ACS URL dedicated to the RSA SAML IdP trust.
-
After creating the IdP, under Summary, download the metadata for the Okta service provider.
-
Navigate to Identity Providers > Routing rules and click Add Routing Rule under the Routing Rules tab.
-
Enter the rule name, choose the newly created RSA IdP, and click Create rule.
Routing rules define the conditions for requests that are routed to RSA. Conditions can use network zones, specific applications, or user domains.
-
Return to the RSA Cloud Administration Console and navigate to the Okta application you created.
-
On the Connection Profile page, under Data Input Method, choose Import Metadata and upload the downloaded Okta metadata.
Accept the changes. The imported metadata replaces the temporary values that were entered earlier.
The configuration is complete.
Related Articles
Relying Parties 51Number of Views Manage Relying Parties 38Number of Views Cloud Access Service - Relying Parties 11Number of Views Add a Relying Party 31Number of Views PurelyHR-integration-configuration-relying-party 2Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.9 Setup and Configuration Guide Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle