StoryChief - SAML Relying Party Configuration - RSA Ready SecurID Access Implementation Guide
3 years ago
Originally Published: 2021-08-16

StoryChief - SAML Relying Party Configuration - RSA Ready SecurID Access Implementation Guide

This section describes how to integrate RSA SecurID Access with StoryChief using Relying Party. Relying party uses SAML 2.0 to integrate RSA SecurID Access as a SAML Identity Provider (IdP) to StoryChief SAML Service Provider (SP).

Architecture Diagram

kotlad1_0-1629125086410.png

 

Configure RSA Cloud Authentication Service

Perform these steps to configure RSA Cloud Authentication Service as a relying party SAML IdP to StoryChief .

Procedure

  1. Sign into the RSA Cloud Administration Console and browse to Authentication Clients > Relying Parties and click Add a Relying Party.

    kotlad1_1-1629125106271.png

     

    kotlad1_2-1629125130785.png

     

  2. On Basic Information page enter a Name for the application, ie. StoryChief Then click on Next Step.

  3. On Authentication page

    1. select the RSA SecurID Access manages all authentication

    2. Select the desired Primary Authentication Method from the dropdown list.

    3. Select the desired policy from the Access Policy for Additional Authentication.

    4. Click Next Step

      kotlad1_3-1629125619407.png

       

  4. On Connection Profile page

    1. Enter the Assertion Consumer Service (ACS) This is the ACS URL supplied by StoryChief . For example, https://app.storychief.io/sso/rsaready/acs.

    2. Enter the Service Provider Entity ID This is the Metadata URL supplied by StoryChief. For example, https://app.storychief.io/sso/rsaready/meteadata.

    3. Click on Download Certificate

    4. Open Advanced Configuration section and note the Identity Provider Entity ID field . For Example :https://rsaa-blr-pe.auth-demo.securid.com/saml-fe/sso

    5. Click on Save and Finish

      kotlad1_4-1629125644790.png

       

  5. Browse to Authentication Clients > Relying Parties

  6. Scroll down to the your newly created Relying party and click down error next to Edit and choose View or Download IdP MetatData

    kotlad1_5-1629125665340.png

     

  7. Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.

    kotlad1_6-1629125717408.png

     

 

Configure StoryChief

Perform these steps to integrate StoryChief with RSA SecurID Access as a Relying Party SAML SP. This will require interactions with StoryChief support to get and set the required information.

Procedure

  1. Contact Storychief, ie via chat, and request that SSO be enabled. They will respond and provide some basic configuration information used to configure Relying party above. They will also request information needed to complete the configuration in the StoryChief application.

  2. StoryChief will provide the following :

    1. ACS Post: i.e. https://app.storychief.io/sso/rsaready/acs

    2. Login Get: i.e. https://app.storychief.io/sso/rsaready/login

    3. Logout GET: i.e. https://app.storychief.io/sso/rsaready/logout

    4. Metadata GET: i.e. https://app.storychief.io/sso/rsaready/meteadata

    5. Single Logout Service SLS (optional) GET : i.e. https://app.storychief.io/sso/rsaready/sls

  3. StoryChief will request the following. Please send StoryChief the following information.

    1. entityID: This is the Identity Provider Entity ID field obtained above. For Example :https://rsaa-blr-pe.auth-demo.securid.com/saml-fe/sso

    2. Single Sign-ON (SSO) service URL: This is the Identity Provider Entity ID field obtained above. For Example :https://rsaa-blr-pe.auth-demo.securid.com/saml-fe/sso

    3. x509cert : This is the Certificate downloaded above.

  4. Once StoryChief has configured SSO using the requested information, they will notify you when SSO is live.

  5. Once enabled SSO information can be found in Settings > SSO

  6. Users can login by choosing Log In with SSO on the default StoryChief login page or going to the Login URL provided.

Configuration is complete.

See main page for more certification information.