Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
This guide is intended to help configure single sign on / SAML 2.0 for Lucidity Software to be able to authenticate against your Google users.
Create a Lucidity app Instance
Log in to https://admin.google.com
NOTE: The account that you use needs to have Super Admin privileges to perform the setup.
Click on the hamburger menu
Image RemovedNavigate to App → SAML apps
Image RemovedClick Create
Image RemovedSelect the "SETUP MY OWN CUSTOM APP"
Image RemovedDownload the IPD Metadata On the left-hand-side menu click Apps > Web and mobile apps
Image AddedIn the centre of the “Web and mobile apps“ screen click Add app > Add custom SAML app
Image AddedThe “Add custom SAML app“ modal will be displayed
Image AddedEnter an appropriate “App name“ such as “Lucidity“ and optionally select a new icon. Click Continue
Image AddedSuggested icon:
Image AddedDownload metadata in Option 1 and send this file to the Lucidity Contact your Lucidity Customer Representative. Click Continue
Image Removed
You can also get this data once the app has been set upClick next
Fill in the Application Nam, Description and logo can be anything you want as long as you remember whats it for, we recommend calling your app “Lucidity Software” and using the Lucidity icon provided:
Image RemovedOnce you have done this click Next
- Enter the following details provided below and leave the rest as the default value:
NOTE: Replace {site-name} with your Lucidity site name.Under the General section:
ACS URL
Image Added In the “Service provider details“ screen enter the following (leave the Name ID format and Name ID values as default):
ACS URL: https://{
clientName}.
{domain}/simplesaml/module.php/saml/sp/saml2-acs.php/{
clientName}
Entity ID
: https://{
clientName}.
{domain}/simplesaml/module.php/saml/sp/metadata.php/{
clientName}
Start URL:
https://{
clientName}.
{domain}/home/login/lucidityintranet/completesso/{
leave the Name ID and Name ID format as the default values
Image RemovedClick next
- Add a new Mapping Under the Attribute Mapping:
Add the following in the following fields:
Enter the application attributeclientName}
NOTE: {clientName} represents your Lucidity instances subdomain and {domain} represents your Lucidity domain (luciditysoftware.com.au or lucidity.io)
Image Added
Click Continue
In the “Attribute mapping“ screen click Add mapping:
Google Directory attributes: Basic Information > Primary email
App attributes: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn
Select category: Basic Information
Select user field: Primary EmailNOTE: The value needs to match the username naming conventions used for users in Lucidity. If an email is used only
the first part is required (eg bob.smith@somewhere.com becomes bob.smith for authentication)
- Image Added
Click Finished Finish
Enable the App
Image Removed. From back in the main SAML app index, select the newly created app
Click User access
Image AddedSelect ON for everyone OR select the required group(s) from the left-hand-side. Click Save
Image AddedIf you have not already sent the metadata.xml to you Lucidity contact Customer Representative please do so now, so that they can finish the set up
In this page:
Table of Contents |
---|
Related pages:
Child pages (Children Display) | ||
---|---|---|
|