Creating SSO configurations - User Guide - BlueCat Horizon

BlueCat Horizon User Guide

ft:locale
en-US
Product name
BlueCat Horizon

To create an SSO configuration and use an external identity provider to authenticate, navigate to Administration > Single sign-on and follow these instructions:

Note: For some of the values needed to create an SSO configuration, you will need to enter placeholder values. These values are required to generate the metadata file that you will need to configure SSO with your identity provider. After you configure the SSO connection with your identity provider, you will need to update the SSO connection in BlueCat Horizon with the true values.
  1. Select New.
  2. In the Create SSO configuration dialog, enter the following information:
    • Name: Enter a name for the SSO configuration.
    • Sign in URL: URL of the location where users are directed to sign in, provided by your identity provider. Enter a placeholder value, which you will later update after you've configured the SSO connection with your identity provider.
    • Signing certificate: Drag and drop a placeholder signing certificate file into the provided field. Or select the field, which opens your file finder window, in which you can select the signing certificate file. You will later upload the real file after you've configured the SSO connection with your identity provider. Only PEM file types are supported.
    • User ID attribute: (Optional) Enter the SAML attribute name that uniquely identifies the user. This is needed if you want to map a specific field as the ID taken from the identity provider. If no attribute is added, it will resolve automatically.
  3. Select Create.
  4. When the SSO configuration populates the Single sign-on page, select Download under Metadata to download the service provider metadata. The data will be downloaded to your local machine as an XML file, approximately 1 kB in size. You will need this metadata when configuring the SSO with your identity provider.

The new SSO configuration will be added to the Single sign-on page. Next, you need to configure groups and roles for the users who will authenticate through SSO. Afterwards, you can configure the SSO connection with your identity provider.