This section describes how to integrate SecurID Access with Aha! using a SAML SSO Agent.
Configure SecurID Access Cloud Authentication Service
Perform these steps to configure SecurID Access Cloud Authentication Service(CAS) as an SSO Agent SAML IdP to Aha!.
Sign into the SecurID Access Cloud Administration Console and browse to Applications > Application Catalog.
Search for Aha! then click on Add.
On Basic Information page enter a Name for the application, ie. Aha! Then click on Next Step.
On Connection Profile page.
Choose IDP-Initiated. Note: The following IDP-initiated configuration works for SP-initiated as well.
In Connection URL field leave the defaults.
Note the Identity Provider URL and Issuer Entity ID. These values are automatically generated. They may be needed later for the configuration of Aha!.
Click on Generate Cert Bundle, set a a common name for your company certificate. Then click Generate and Download .
Select Choose File and upload the private key from the generated certificate bundle.
Select Choose File and upload the public cert from the generated certificate bundle. This is the cert.perm file.
Select Include Certificate on Outgoing Assertion.
Scroll down to Service Provider section.
For the Assertion Consumer Service (ACS) enter the SAML consumer URL from Aha! SP information in the SSO setup below. This URL is based on your instance of Aha!. For example, https://mytestinst.aha.io/auth/saml/callback.
For the Audience (Service Provider Issuer ID) enter the SAML entitity ID from Aha! SP information in the SSO setup below. This URL is based on your instance of Aha!. For example, https://mytestinst.aha.io/.
Scroll down to User Identity section.
Ensure Identifier Type = Email Address, set your Identity Source and Property = mail.
Click Show Advanced Configuration.
Ensure the attributes email, firstname and lastname have the correct Property values for your configuration.
Click Next Step.
On User Access page select the Access Policy you require. Allow All Authenticated Users is the least restrictive. Click Next Step.
On Portal Display Page.
Select Display in Portal.
Upload an Application Icon if you wish.
Set an Application Tooltip if you wish.
Click on Save and Finish.
For this new Connector, click on the down arrow next to the Edit button and Export Metadata to save off the IDP metadata information for configuration of .
Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.
Perform these steps to integrate Aha! as an SSO Agent SAML SP to SecurID Access Cloud Authentication Service.
Login into your Aha! account.
Browse to Account > Security and single sign-on.
Select SAML 2.0 from Identity provider list.
Enter a Name for the Identity provider. For example, MySecurID.
For Configure using select Metadata file. Then Choose File and upload the saved metadata file from the SecurID configuration above.
Note the SAML consumer URL and SAML entitity ID. These will be used in the SecurID configuration above.