Reftab - SAML SSO Agent Configuration - SecurID Access Implementation Guide
This section describes how to integrate SecurID Access with Reftab using a SAML SSO Agent.
Architecture Diagram
Configure SecurID Access Cloud Authentication Service
Perform these steps to configure SecurID Access Cloud Authentication Service as an SSO Agent SAML IdP to Reftab.
Procedure
-
Sign into the Cloud Administration Console and browse to Applications > Application Catalog.
-
Click on Create from Template and select SAML Direct.
-
On Basic Information page enter a Name for the application, ie. Reftab Then click on Next Step.
-
On Connection Profile page.
-
In Connection URL field, verify the default setting
-
Choose IDP-Initiated or SP-Initiated. SP-Initiated requires POST as a binding method.
-
Scroll down to SAML Identity Provider (Issuer) section.
-
Note the Identity Provider URL . This value is automatically generated. They may be needed later for the configuration of Reftab
-
For Issuer Entity ID select Override and set the value to the same as the Identity Provider URL. For example, https://portal.sso.pi.rsa.net/IdPServlet?idp_id=rhb1bbwu7un6
-
Click on Generate Cert Bundle, set a a common name for your company certificate. Then click Generate and Download
-
Select Choose File and upload the private key from the generated certificate bundle
-
Select Choose File and upload the cert from the generated certificate bundle
-
Select Include Certificate on Outgoing Assertion
-
Scroll down to Service Provider section.
-
Enter the Assertion Consumer Service (ACS) from the Entity Id in the Reftabconfiguration below. For example, https://www.reftab.com/api/sso.
-
Enter the Audience (Service Provider Entity ID) from the ACS URL in the Reftab configuration. For example, https://www.reftab.com/.
-
Scroll down to User Identity section
-
Ensure Identifier Type = Email Address, set your Identity Source and Property = mail
-
Expand Show Advanced Configuration.
-
In Attribute Extension section click +ADD.
-
Add Attribute Name = email and Property = mail.
-
Click Next Step
-
-
On User Access page select the Access Policy you require. Allow All Authenticated Users is the least restrictive. Click Next Step
-
On Portal Display Page
-
Select Display in Portal
-
Upload an Application Icon if you wish
-
Set an Application Tooltip if you wish.
-
Click on Save and Finish
-
-
Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.
-
Browse to Application > My Applications
-
Locate newly create application for Reftab
-
Click on Down Arrow next to Edit button
-
Select Export Metadata data. This will be used below for Reftab configuration.
Configure Reftab
Perform these steps to integrate Reftab with SecurID Access as a SAML SSO Agent.
Procedure
-
Sign into Reftab your administration console .
-
Browse to Settings > SAML Settings.
- Note the Entity Id and ACS URL values. They are used above in the RSA Cloud Authentication Service configuration.
-
Click on +Add New Domain.
-
For Domain, enter your domain. For example, mycompany.com.
-
For Email Attribute enter email. This is the attribute configured above in the RSA Cloud Authentication Service configuration.
-
For both the IDP Entity ID and the URI Endpoint enter the value for the Identity Provider URL noted above. For example, https://portal.sso.pi.rsa.net/IdPServlet?idp_id=rhb1bbwu7un6
-
For Bind Method select HTTP-Post.
-
For Certificate copy the contents of the cert.pem file generated from the certificate bundle above in SecurID Access Cloud Authentication Service configuration above.
-
Click on Save SAML Settings.
Configuration is complete.
Next Step: See main page for more certification information.
Related Articles
Telemetry TV - SAML SSO Agent Configuration - SecurID Access Implementation Guide 3Number of Views ScreenSteps - SAML SSO Agent Configuration - SecurID Access Implementation Guide 3Number of Views RSA Governance and Lifecycle - SAML SSO Agent Configuration - RSA Ready SecurID Access Implementation Guide 36Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Cisco Umbrella - SAML SSO Agent Configuration - SecurID Access Implementation Guide 16Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide