How to enroll Flex Appliance as a service provider for PingFederate

Article: 100054128
Last Published: 2022-12-21
Ratings: 0 0
Product(s): Appliances

To enroll a Flex appliance as a service provider for PingFederate

  1. Download the Flex Appliance service provider metadata.xml from the Flex Appliance Console or with the following Flex API: https://<flex appliance>/api/v1/single-signon/metadata.
  2. Log in to your PingFederate account.
  3. If you already have an Environment with the SSO solution, use that environment and skip to step 5.
  4. If you do not have an environment, click Add Environment. On the screen that appears, do the following:
    • Select Build your own solution.
    • Select PingOne SSO.
      Finish the Environment setup and open the environment.
  5. Click Connections in the navigation bar on the left.
  6. Click the plus icon next to Applications.
  7. Enter a name for the application. Under Choose Application Type, select SAML Application and click Configure.
  8. Configuration the application with one of the following methods:
    • Import Metadata: Choose Import metadata and click Select a file. Upload the metadata file that you downloaded in step 1. Once the metadata file uploads successfully, the correct ACS URL and the Entity ID are shown. Click Save. 
    • Import From URL: Enter the following Flex Appliance service provider URL: https://<flex appliance>/api/v1/single-signon/metadata. Click Import. Once the metadata file uploads successfully, the correct ACS URL and the Entity ID are shown. Click Save.
    • Manually Enter: Enter the ACS URL and the Entity ID, which you can get from the following service provider URL : https://<flex appliance>/api/v1/single-signon/metadata. In general, the ACS URL is https://<flex appliance>/api/v1/single-signon/acs, and the Entity ID is https://<flex appliance>/api/v1/single-signon/metadata.
  9. If you used the Manually Enter option in the previous step, click Edit Configuration and add the URL's for the SLO Endpoint and the SLO Response Endpoint as https://<flex appliance>/api/v1/logout. Click Save.
  10. Select the newly created app and click Attributes.
  11. Change the attribute mappings as shown in the following screen and click Save.
  12. (Optional) Veritas recommends that you enable encryption for assertions. To do so, perform the following steps:
    1. Refer to www.veritas.com/support/en_US/article.100054258 to obtain the Flex Appliance authservice certificate.
    2. Click Edit Configuration and select Enable Encryption.
    3. Upload the Flex Appliance certificate.
  13. Select the application and move the slider on the top bar to enable it.
  14. Click Configuration and then click Download Metadata. Use this file when you add the PingFederate IDP on your appliance.

References

JIRA : FLEX-664

Was this content helpful?