Google Workspace - SAML IDR SSO Configuration - RSA Ready Implementation Guide
2 years ago
Originally Published: 2021-10-30

This article describes how to integrate RSA Cloud Authentication Service with Google Workspace (formerly G Suite) using SAML IDR SSO.

Configure RSA Cloud Authentication Service

Perform these steps to configure RSA Cloud Authentication Service as IDR SSO to Google Workspace.
Procedure

  1. Sign in to RSA Cloud Administration Console and browse to Applications > Application Catalog
  2. Search for G Suite and click Add to add the connector.                                                                                                                                     image.png
  3. On the Basic Information page, choose Identity Router.
  4. Enter the name for the application in the Name field and click Next Step.                                                                                                       image.png
  5. On the Connection Profile page, choose IdP-initiated and enter Connection URL in the following format: https://mail.google.com/a/%DOMAIN% - replace %DOMAIN% with the domain name of your Workspace connected domain.                image.png
  6. In the Identity Provider section, perform the following sub-steps:
    1. Make a note of the Identity Provider URL that is required in the Workspace configuration.                                                      image.png
    2. Under Identity Provider Entity ID, click the Override option and enter https://www.opensaml.org/IDP in the text field.                image.png
    3. Import a private/public key pair to sign and validate SAML assertions. If a key is unavailable, follow the sub-steps to generate a certificate bundle. Otherwise, continue to the next step.
      1. Click Generate Certificate Bundle in the SAML Response Signature section.
      2. Enter a common name for your Identity Router domain in the Common Name (CN) field.
      3. Click Generate and Download, save the certificate bundle zip file to a secure location, and extract its contents. The zip file contains a private key, a public certificate, and a certificate signing request.                                                                             image.png
  7. Fill in the Service Provider section details in the following format:
    1. In the Assertion Consumer Service (ACS) URL and Audience (Service Provider Entity ID) fields, enter the URL in this format:  https://www.google.com/a/%DOMAIN%/acs - replace %DOMAIN% with the domain name of your Workspace connected domain.   image.png
  8. In the User Identity section, select Email Address in the Identifier Type drop-down list, select the name of your user Identity Source, and select the Property value as mail.                                                                                                                                                     image.png
  9. On the User Access page, select the access policy that the identity router will use to determine which users can access the Workspace service provider.
  10. Click Next Step.                                                                                                                                                                                              image.png
  11. On the Portal Display page, configure the portal display and other settings.                                                                                              image.png
  12. Click Save and Finish
  13. Click Publish Changes and wait for the operation to complete.

Configure Google Workspace

Perform these steps to configure Google Workspace.
Procedure
  1. Sign in to the Workspace administrator console at https://admin.google.com.
  2. Go to Security Authentication SSO with third-party IdP.
  3. On the SSO with third-party IdP page, do the following:
    1. Select the Set up SSO with third-party identity provider check box.                                                                                      image.png
    2. In the Sign-in page URL field, enter the Identity Provider URL obtained from of RSA Cloud Authentication Service configuration. image.png
    3. In the Sign-out page URL field, enter https://google.com.                                                                                                              image.png
    4. Verification certificate: Upload the public certificate extracted from RSA Cloud Authentication Service configuration.                    image.png
  4. Click Save.
Note: The domain connected to your Workspace account must be verified before using third-party SAML IdP. If the domain is not verified, follow https://support.google.com/a/answer/60216?hl=en&ref_topic=29190 to get your domain verified before proceeding.

The configuration is complete.
Return to Google Workspace - RSA Ready Implementation Guide.