Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Single Sign-On allows organizations to use their already defined domain authentication and not require users to create a unique username/password for Serviceaide Intelligent Service Management.

...

To enable and configure Single Sign-On, perform the following tasks:

  1. Validate Prerequisites 
  2. Export Identity Provider Certificates
  3. Configure SAML Single Sign-On in CSM
  4. Add CSM As a Trusted Service Provider in the Identity Provider
  5. Configure Identity Provider to Send User Identifier As Name ID 

...

Note: Do not modify any parameters on the application server or database server. Contact Support for assistance in such changes.

Anchor
ExportIdentityProviderCertificate
ExportIdentityProviderCertificate
Export Identity Provider Certificate

Federation servers use Public/Private Key pairs to add digital signature to all security tokens they produce. These keys validate the authenticity of the encrypted security token.

...

If the export is successful, the certificate is saved at the location that you specified. You can open the certificate in any text editor, like Notepad.

Anchor
ConfigureSAMLSingleSign-OninCSM
ConfigureSAMLSingleSign-OninCSM
Configure SAML Single Sign-On in Intelligent Service Management

You can add multiple SAML single sign-on configurations to Intelligent Service Management. This allows a single Intelligent Service Management system to support different organizations that may have a different SSO/SAML setup. To enable Single Sign-On, configure Intelligent Service Management to trust assertions that are sent by the IdP.

...

Note: Contact the support team for the metadata URL applicable to your application instance.

Anchor
AddCSMasTrustedServiceProviderintheIdP
AddCSMasTrustedServiceProviderintheIdP
Add Intelligent Service Management as Trusted Service Provider in the IdP

Add the metadata that is generated from Intelligent Service Management to your IdP to enable the SAML communication between them. For information about generating the metadata, see Configure SAML Single Sign-On in CSM.

Follow these steps on Microsoft ADFS 3.0:

...

Intelligent Service Management is added as a trusted service provider in your IdP.

Anchor
ConfigureIdentityProviderToSendUserIdentifierAsNameID
ConfigureIdentityProviderToSendUserIdentifierAsNameID
Configure Identity Provider to Send User Identifier as Name ID

After configuring your IdP and Intelligent Service Management to trust assertions, set up the attribute statement for SAML assertion. This attribute statement is used to identify a user. You can use a unique identifier to identify each user, like Principle Name, or Email ID.

...