16.2 Configuring the Connector

After you import the connector, you must configure the connector settings in CloudAccess.

  1. Log in as an administrator to the CloudAccess administration console:

    https://appliance_dns_name/appliance/index.html
    
  2. Drag and drop the connector for Box from the Applications palette to the Applications panel.

    The Configuration window opens automatically for the initial configuration. To view or reconfigure the settings later, click the connector icon, then click Configure.

  3. On the Configuration page, specify the configuration properties.

    The signing certificate from Box is optional.

  4. Under Assertion Attribute Mappings, map the SAML Assertion attributes to the appropriate attributes in your identity source.

  5. Expand the Federation Instructions, then copy and paste the instructions into a text file to use during the Box configuration for single sign-on.

    NOTE:You must use a text editor that does not introduce hard returns or additional white space. For example, use Notepad instead of Wordpad.

  6. Click the Appmarks tab, then review and edit the default settings for the appmark.

    For more information, see Section 2.5, Configuring Appmarks for Connectors.

  7. Click OK to save the configuration.

  8. On the Admin page, click Apply to commit the changes to the appliance.

  9. Wait until the configuration changes have been applied on each node of the CloudAccess cluster.

  10. Contact your Box account representative and provide the information they need to configure the SAML 2.0 federation for CloudAccess.

    Use the information from the Federation Instructions in Step 5 to complete the setup.

    NOTE:When you copy the appliance’s signing certificate, ensure that you include all leading and trailing hyphens in the certificate’s Begin and End tags.

  11. Click Policy in the toolbar, then perform policy mapping to specify entitlements for identity source roles (groups).

    For more information, see Mapping Authorizations in the NetIQ® CloudAccess and MobileAccess Installation and Configuration Guide.

  12. After you complete the configuration, users can log in through CloudAccess to single sign-on to the Box system. The CloudAccess login page URL is:

    https://appliance_dns_name