To configure SSO for your ePO - On-prem server:
Configure the IdP application.
Input your Security Assertion Markup Language (SAML) configuration information in ePO - On-prem.
Update your IdP configuration with the information from ePO - On-prem server.
Configuring the IdP application
Configure a new IdP application in your SSO solution to get the IdP Entity Id (Issuer URL), IdP SSO URL, and X 509 certificate to input in your SAML configuration information.
For instructions on how to configure your IdP application, see your identity provider's documentation.
Note
You might need to use placeholder information for the ACS URL and the Audience URI (Service Provider Entity ID) when you configure your third-party IdP. Enter the details when you Update your IdP application SAML settings with the information from ePO - On-prem server.
Input your SAML configuration information in ePO - On-prem
Configure the settings in the IDP SAML Settings page under Server Settings to enable SSO using your IdP application.
Enter the information in the IdP Settings section.
Import IDP Metadata xml file — Download the metadata from your IdP, and then click Import to upload the metadata to ePO - On-prem.
Note
Some IdP’s do not support the download of the metadata extension. You need to input data manually, after collecting the necessary details from your IdP application.
SSO Identity provider name — Enter the name of the Identity Provider.
Service Provider (ePO) Entity Id — Enter a unique identifier for the Service Provider application configured in IdP.
Service Provider Assertion Consumer Service Url — Url used to recognize the SAML request. For example: https://<EPO_SERVER_URL>/core/orionNavigationExtLogin.do.
Identity Provider Entity Id — Unique identity of the Identity Provider.
Identity Provider SSO Url — Single Sign-On Url of the Identity provider.
Identity Provider X 509 Certificate — Certificate from the Identity Provider used in the Single Sign-On process.
Logout redirect URL — The link where you navigate after logging out from ePO - On-prem. You can give the home page address of your identity provider.
After entering the above details, Click Save.
Once you log off from the ePO application, you will see the Log On with IDP option on the main screen.
Update your IdP configuration with the information from ePO - On-prem Server
After saving the IdP configuration in your ePO - On-prem server, go to your IdP application and edit the SAML settings with the information from ePO - On-prem.
Audience URI (Service Provider Entity ID) — Enter the Service Provider (ePO) Entity Id from ePO - On-prem.
Single Sign On URL — Enter the Service Provider Assertion Consumer Service URL from ePO - On-prem.
Assigning the user locale for the identity provider application
When logging in using an identity provider, the user locale is assigned in the following manner:
From the user_locale attribute — It is configured in the IdP application to inform the Service Provider application about the locale of a particular user. For example: Fr-fr or, FR_fr.
Using the drop-down option — It is present on the logon screen of the ePO - On-prem application.
Available as the default locale of the tenant.