Prerequisite
Server
The SAML identity provider supports the HTTP POST binding as specified by the SAML 2.0 specification.
SSO must be configured for the servers.
You only have access to the metadata XML file if SAML is enabled.
ARIS must be registered as a trusted service provider at the SAML identity provider.
Client
Your web browser supports JavaScript.
Enable SSO (SAML)
Procedure
Open ARIS Advanced.
Click Application launcher >
Administration.
Click Configuration management.
Click Single sign-on.
Under General, enable Enable single sign-on.
Enter the ID of the identity provider in the Identity provider ID field.
Enter the ID of the service provider in the Service provider ID field, for example UMC@<server name>.
Enter the end point of the identity provider that is used for single sign-on in the Single sign-on URL field.
Enter the end point of the identity provider that is used for single log-out in in the Single logout URL field.
Click Save.
Optional SAML settings
Under Signature, enable the options you want to set:
Enforce signing of assertions
Enforce signing of requests
Enforce signing of responses
Enforce signing of metadata
Select signature algorithm
Click Save.
You have enabled the signing. If you have enabled this option, you must configure the truststore.
Optional: Configure the keystore
Under Keystore, click Upload.
Click Upload. The dialog opens. Select the keystore file on your file system and click Upload.
Configure your keystore.
Click Save.
You have configured the keystore.
Share the service provider (SP) metadata
You can find the service provider metadata under General. Send the service provider ID to your identity provider (IDP).
Configure SAML using identity provider (IDP) metadata
Under General, enter the identity provider ID.
Click Save.
Optional: Configure the truststore
Under Truststore, click Upload. The dialog opens. Select the truststore file on your file system and click Upload.
Configure your truststore.
Click Save.
You have configured the truststore.
Configure the user attributes
Under User attributes, specify the attribute fields, for example, the first name, the last name, or the e-mail.
Click Save.
You have configured the user attributes.
Optional: Advanced settings
Under Advanced settings, configure:
Authentication context classes
Authentication content comparison
NamedID format
Clock skew (in seconds)
Assertion lifetime (in seconds)
Click Save.
You have configured the advanced settings.