Pega Platform - SAML SSO Agent Configuration - RSA Ready SecurID Access Implementation Guide
2 years ago
Originally Published: 2021-12-01

This section describes how to integrate RSA SecurID Access with Pega Platform using a SAML SSO Agent.

Architecture Diagram

jaink9_0-1638360236479.png

 

Configure RSA Cloud Authentication Service

Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to Pega Platform. During configuration of the IdP you will need some information from the SP. This information includes (but is not limited to) Assertion Consumer Service URL and Service Provider Entity ID.

Procedure

    1. Sign into RSA Cloud Administration Console and browse to Applications > Application Catalog, click Create From Template and select SAML Direct.

      jaink9_1-1638360273624.png

       

    2. Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.

      jaink9_2-1638360311665.png

       

    3. Navigate to Initiate SAML Workflow section.

        1. In the Connection URL field, enter the Assertion Consumer Service (ACS) location, which is available in Step 7 of Configure SAML in Pega Platform section.

        2. Choose SP-Initiated.

      jaink9_3-1638360352094.png

       

    4. Scroll down to SAML Identity Provider (Issuer) section.

      jaink9_4-1638360385809.png

       

  1. Identity Provider URL - <Automatically generated>

  2. Issuer Entity ID - <Automatically generated>

  3. Select Choose File and upload the private key.

  4. Select Choose File to import the public signing certificate.

    1. Scroll down to the Service Provider section.

      jaink9_5-1638360421562.png

       

      1. Assertion Consumer Service (ACS) - Enter the Assertion Consumer Service (ACS) location, which is available in Step 7 of Configure SAML in PegaPlatform section.

      2. Audience (Service Provider Entity ID) - Enter the Entity Identification, which is available in Step 7 of Configure SAML in PegaPlatform section.

    2. Scroll to the User Identity section, select the following values.

      jaink9_6-1638360537833.png

       

      • Identifier Type – Email Address
      • Identity Source – name of your user identity source

      • Property – mail

    3. Click Next Step.

    4. On the User Access page, select Allow All Authenticated Users radio button.

                  jaink9_7-1638360603412.png

    1. Click Next Step.

    2. On the Portal Display page, select Display in Portal.

    3. Click Save and Finish.

    4. Click Publish Changes.

                  jaink9_8-1638360669227.png

  1. Navigate to Applications > My Applications and locate Pega in the list and from the Edit option, select Export Metadata.

 

Configure SAML in Pega Platform

Perform these steps to configure PegaPlatform as an SSO Agent SAML SP to RSA Cloud Authentication Service.

Procedure

  1. Log onto the Pega Platform Dev Studio.

  2. Navigate to Configure > Org &Security > Authentication > Create Authentication Service.

    jaink9_9-1638360728184.png

     

  3. Enter the following details:

    jaink9_10-1638360761529.png

     

    • Authentication Type: SAML 2.0

    • Name: Any name for this service

    • Short description: Any short description for this service.

  4. Click Create and open.

  5. On the Authentication Service form enter a Authentication service alias. This becomes part of the URL of SSO login.

    jaink9_11-1638360788201.png

     

  6. Click the Import IDP metadata link and select via file and choose the idp metadata downloaded in Step 13 of Configure RSA Cloud Authentication Service section.

    • After the idp metadata import the Identity Provider (IdP) information should look like this:

      jaink9_12-1638360827096.png

       

  7. On the Service Provider (SP) settings section, copy the Entity Identification url and Assertion Consumer Service (ACS) location url. These urls are needed in Step 3 and Step 5 of Configure RSA Cloud Authentication Service section.

    • Select Disable request signing checkbox.

      jaink9_13-1638360861297.png

       

  8. Click Save.

 

Return to the main page for more certification related information.