This section describes how to integrate RSA SecurID Access with MyWorkDrive using relying party. Relying party uses SAML 2.0 to integrate RSA SecurID Access as a SAML Identity Provider (IdP) to MyWorkDrive SAML Service Provider (SP).
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as a relying party SAML IdP to MyWorkDrive .
Sign into the RSA Cloud Administration Console and browse to Authentication Clients > Relying Parties and click Add a Relying Party.
Click the Add a Relying Party button on the My Relying Parties page.
From the Relying Party Catalog select the +Add button for Service Provider SAML.
Enter a Name for the Service Provider in the Name field on the Basic Information page.
Click the Next Step button.
On the Authentication page, select RSA SecurID Access manages all authentication.
Select your access policy from the Access Policy for Additional Authentication drop-down menu.
Select Next Step.
For Connection Profile page's Service Provider Metadata section, enter the following information:
Select Default Service Provider Entity ID in Audience for SAML Response section.
Copy the MyWorkDrive certificate from MyWorkDrive Server location C:\Wanpath\WanPath.Data\Settings\Certificates and click Choose File and attach it.
Click Download Certificate. This certificate is required for Step 2 of Configure SAML in MyWorkDrive.
Click Show Advanced Configuration and configure User Identity with the following values:
Identity Type – Email Address
Property - mail
Click Save and Finish.
Click Publish Changes.
Navigate to Authentication Clients > Relying Parties and locate MyWorkDrive in the list and from the Edit option, select View or Download IdP Metadata. Locate the entityID from the metadata and copy it as it will be needed in Step 3 Configure SAML in MyWorkDrive.
Configure SAML in MyWorkDrive
Perform these steps to configure MyWorkDrive as a Relying Party SAML SP to RSA Cloud Authentication Service.
Please Note: Before proceeding, please ensure that the users are available in Active Directory with matching username UPN with users logging into RSA Cloud Authentication Service.
Log into MyWorkDrive Server as administrator.
Navigate to C:\Wanpath\WanPath.Data\Settings\Certificates and place the RSA Cloud Authentication Service certificate downloaded in Step 11-a of Configure RSA Cloud Authentication Service section.
Update the SAML config located at C:\Wanpath\WanPath.Data\Settings to add <PartnerIdentityProvider> entry. In this case we used below: