14.3 Configuring the Single Sign-on Connector

After importing a single sign-on connector, you must configure the connector to work with the application. For more information about how to import connectors, see Section 4.1, Importing Connectors.

To configure the connector:

  1. Log in as an administrator to the CloudAccess administration console:

    https://appliance_dns_name/appliance/index.html
    
  2. Drag the appropriate connector from the Applications palette to the Applications panel.

  3. On the Configuration tab, follow the on-screen prompts to configure the connector.

    Use the information you obtained in the requirements section to configure the connector. For more information, see Section 14.2, Requirements for the Single Sign-on Connectors.

  4. Map the SAML Assertion attributes to the corresponding attributes in your identity source.

  5. Expand the Federation Instructions, then copy and paste the instructions into a text editor. You will use this information to configure the federated connection for the CloudAccess appliance in the administration console.

    NOTE:You must use a text editor that does not introduce hard returns or additional white space. For example, use Notepad instead of Wordpad.

  6. Add an appmark for the connector to enhance the user experience. For more information, see Section 5.0, Configuring Appmarks for Connectors.

  7. Click OK, then click Apply to save the configuration.

  8. Log in to your application account and use the Federation Instructions from Step 5 to configure the federated connection.

    NOTE:Ensure that you include the beginning and end tags when you create the certificate from the Federation Instructions.

  9. Perform policy mapping to specify entitlements for identity source groups. For more information, see Mapping Authorizations in the NetIQ CloudAccess and MobileAccess Installation and Configuration Guide.