Slack - SAML IDR SSO Configuration - RSA Ready Implementation Guide
2 years ago
This article describes how to integrate Slack with RSA Cloud Authentication Service using SAML IDR SSO.

Configure RSA Cloud Authentication Service

Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to Slack.
Procedure
  1. Sign in to RSA Cloud Administration Console and browse to Applications > Application Catalog.                                                  
  2. Search for Slack and click Add to add the connector.                                                                                                                                         image.png
  3. On the Basic Information page, choose Identity Router.                                                                                                                            image.png
  4. Enter the name for the application in the Name field and click Next Step.
  5. Navigate to the Initiate SAML Workflow section and verify the default setting in the Connection URL field.
  6. Choose IdP-initiated.                                                                                                                                                                                image.png
  7. Scroll down to the Identity Provider section. The values in this section are required while configuring Slack.                                      image.png
    • Identity Provider URL and Identity Provider Entity ID are automatically generated. 
  8. Import a private/public key pair to sign and validate SAML assertions. If a key is unavailable, use the following sub-steps to generate a certificate bundle. Otherwise, continue to the next step.
    1. Click Generate Certificate Bundle in the SAML Response Signature section.
    2. Enter a common name for your Identity Router domain in the Common Name (CN) field.
    3. Click Generate and Download, save the certificate bundle zip file to a secure location, and extract its contents. The zip file contains a private key, a public certificate, and a certificate signing request.                                                                             image.png
  9. In the Service Provider section, provide the details in the following format: 
    1. ACS URL: https://<workspace>.slack.com/sso/saml. Replace <workspace> with your workspace name value.
    2. Audience (Service Provider Entity ID): https:// <workspace>.slack.com. Replace <workspace> with your workspace name value.image.png
  10. Scroll down to the User Identity section and select the following:
    1. Identifier Type - Email Address
    2. Identity Source - Select your user identity source
    3. Property - mail                                                                                                                                                                                   image.png
  11. Include email address in the Statement Attributes section.
    1. Select Identity Source in the Attribute Source drop-down list, enter User.Email in the Attribute Name text box, select your Identity Source in the Identity Source drop-down list, and select mail in the Property drop-down list.                                          image.png
  12. Click Next Step.
  13. On the User Access page, select the access policy that the identity router will use to determine which users can access the application.  image.png
  14. Click Next Step.
  15. On the Portal Display page, configure the portal display and other settings.
  16. Click Save and Finish
  17. Click Publish Changes.                                                                                                                                                                           image.png

Configure Slack

Perform these steps to configure Slack.
Procedure
  1. Sign in to Slack admin console - https://<workspace>.slack.com/admin.
  2. Click the Menu in the upper-left corner and click Settings & permissions.                                                                                               image.png
  3. Click the Authentication tab. 
  4. If you are configuring SAML Authentication for the first time, click Configure. If SAML Authentication was configured previously, click Change Settings in the SAML Authentication Settings section.                                                                                                               image.png                                          image.png
  5. In the Configure SAML Authentication section, enable the Configure toggle switch.                                                                            image.png
  6. Enter your Identity Provider URL in the SAML 2.0 Endpoint (HTTP) field and your Issuer Entity ID in the Identity Provider Issuer field.                                                                                                                                                                                                            image.png
  7. Copy the RSA public certificate extracted from the zip file during configuration and paste it into the Public Certificate field.                       image.png
  8. Scroll down to the Advanced Options section and click expand.                                                                                                                 image.png
  9. Enter your Service Provider URL in the Service Provider Issuer field. 
    (Default value is: https://slack.com)                                                                                                                                                          image.png
  10. Choose how the SAML response from your IDP is signed. You must choose at least one option.                                                              image.png
  11. Click Save Configuration.                                                                                                                                                          image.png 
Your users will receive an e-mail with directions to bind their current profile for single sign-on.

The configuration is complete.
Return to Slack - RSA Ready Implementation Guide .