PurelyHR-integration-configuration-relying-party
2 years ago
Originally Published: 2021-11-03

PurelyHR - SAML Relying Party Configuration - SecurID Access Implementation Guide

This section describes how to integrate SecurID Access with PurelyHR using Relying Party. Relying party uses SAML 2.0 to integrate SecurID Access as a SAML Identity Provider (IdP) to PurelyHR SAML Service Provider (SP).

Architecture Diagram

gmoison_7-1635952199910.png

 

Configure SecurID Access Cloud Authentication Service

Perform these steps to configure SecurID Access Cloud Authentication Service(CAS) as a relying party SAML IdP to PurelyHR .

Procedure

  1. Sign into the Cloud Administration Console and browse to Authentication Clients > Relying Parties and click Add a Relying Party.

    gmoison_5-1635952182387.png

     

    gmoison_6-1635952191066.png

     

  2. On Basic Information page enter a Name for the application, ie. PurelyHR Then click on Next Step.

  3. On Authentication page.

    1. select the RSA SecurID Access manages all authentication.

    2. Select the desired Primary Authentication Method from the dropdown list.

    3. Select the desired policy from the Access Policy for Additional Authentication.

    4. Click Next Step.

      gmoison_4-1635952160651.png

       

  4. On Connection Profile page.

    1. Under the Service Provider Metada section.

      gmoison_3-1635952139272.png

       

    2. Enter the Assertion Consumer Service (ACS) . This is based on your specific domain of your PurelyHR instance. The URL is https://<domain>.purelyhr.com/sso-consume. For example https://myrsademo.purelyhr.com/sso-consume.

    3. Enter the Service Provider Entity ID. This is based on your specific domain of your PurelyHR instance. The URL is https://<domain>.purelyhr.com. For example https://myrsademo.purelyhr.com.

    4. Click on Download Certificate. This will be used below in the PurelyHR configuration.

    5. Click on Choose File and upload the certificate just downloaded.  This same certificate may be used in the PurelyHR configuration below.

    6. Open Advanced Configuration section.

      gmoison_2-1635952123149.png

       

    7. For Identifier Type Email Address choose mail for the Property.

    8. Click on Add.

    9. Set Attribute Name to Email and Property to mail.

    10. Click on Add.

    11. Set Attribute Name to Lastname and Property to sn.

    12. Click on Add.

    13. Set Attribute Name to Firstname and Property to givenName.

    14. Note Property values may be different based on your SecurID CAS configuration.

    15. Note the Identity Provider Entity ID field . For Example :https://rsa-blr-per.auth-demo.securid.com/saml-fe/sso.

    16. Click on Save and Finish.

  5. Browse to Authentication Clients > Relying Parties

  6. Scroll down to the your newly created Relying party and click down arrow to Edit and choose View or Download IdP MetatData and save off the metadata information.

    gmoison_1-1635952105257.png

     

  7. Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.

    gmoison_0-1635952063741.png

     

 

Configure PurelyHR

Perform these steps to integrate PurelyHR with SecurID Access as a Relying Party SAML SP.

Procedure

  1. Sign into PurelyHR and browse to SSO SETTINGS.

  2. From the Connector dropdown choose Generic SAML.

  3. For the X.509 Certificate copy and paste the contents of the downloaded Certificate from the SecurID Access CAS configuration.

  4. For IDP Issuer URL provide the value of the Identity Provider Entity ID from the SecurID Access CAS configuration. For example, https://rsa-test.auth-demo.securid.com/saml-fe/sso.

  5. For IDP Endpoint URL provide the value of the Identity Provider Entity ID from the SecurID Access CAS configuration. For example, https://rsa-test.auth-demo.securid.com/saml-fe/sso.

  6. Keep Force SSO option unselected, to allow non-SAML based authentications to continue to work.

  7. Keep Auto-create Users option the default.

  8. Save changes.

Configuration is complete.

Next Step: See main page for more certification information.