How to configure Okta SSO for Condeco
Required: Admin permissions to your Okta organization’s account.
- Sign in to Okta with your admin account and open the Okta admin interface.
- In the Applications menu on the left, select Applications then click Create App Integration.
- On the Create a new app integration pop-up, select SAML 2.0 and click Next.
The SAML Integration page is displayed.
- In 1. General Settings enter a name for your app and click Next.
- In 2. Configure SAML, complete the fields as follows:
- Single sign-on URL: Enter
https://sso.condecosoftware.com/sp/ACS.saml2
(or other value provided to you by Condeco) and tick Use this for Recipient URL and Destination URL. - Audience URI (SP Entity ID): Enter
PING-CONDECO
(or other value provided to you by Condeco). - Default RelayState: Enter your Condeco URL e.g.
[yourcompany].condecosoftware.com
- Name ID format: Click the drop-down and select Transient.
- Application username: Click the drop-down and select Okta Username (or other value as defined by your organization policy).
- Update application username on: Click the drop-down and select Create and update.
- Single sign-on URL: Enter
- Click Show Advanced Settings and check the settings are as follows:
- Response: Signed.
- Assertion Signature: Signed.
- Digest Algorithm: RSA-SHA256.
- Assertion Encrytion: Unencrypted.
- Enable Single Logout: Not checked.
- Assertion Inline Hook: None (disabled).
- Authentication context class: PasswordProtectedTransport.
- Honor Force Authentication: Yes.
- SAML Issuer ID: http://www.okta.com/${org.externalKey}
- No further changes to this section are required. Scroll down the page and click Next at the bottom.
- In 3. Feedback click Finish. Your new application is displayed.
- In the application you just created, click the Sign On tab and scroll down to SAML Signing Certificates.
- Under SAML Signing Certificates click the Actions drop-down and select View IdP metadata.
- The metadata opens in a new tab. Right-click the tab and select Save As to save the metadata XML file.
Now send the Metadata XML to Condeco:
- Existing customers: Create a support ticket in the Condeco Support portal and either attach the XML file in a secure zip file or request another secure way to send the data – via secured email or shared drive, for example.
- New Condeco installations: Your Condeco project manager or technical consultant will advise how to securely send the XML file.
See also
- SSO Configuration Learn more about SSO and Condeco.
- SCIM provisioning for Okta
Post your comment on this topic.