Topics: |
This section describes how to configure Security Assertion Markup Language (SAML) authentication as a single sign-on (SSO) login between Salesforce.com and WebFOCUS. Doing so prevents you from having to log on to Salesforce.com and WebFOCUS separately.
The My Domain pane opens, as shown in the following image.
The following screen is displayed.
The following screen is displayed, which provides details regarding the Identity Provider, metadata, and the certificate.
Copy the metadata into the following WebFOCUS directory:
\ibi\WebFOCUS82\config\was\saml
This metadata will be used to configure WebFOCUS for the XML file that is used by the Identity Provider.
The specific names of the files are not important, but configuration values in the securitysettings.xml file must reference the correct metadata file.
At a high level, this process consists of the following steps:
To configure WebFOCUS and generate the wfspMetadata.xml file:
The Key Management dialog opens.
The Certificate Alias and Password dialog opens, as shown in the following image.
The password for the Keystore, alias of the certificate, and password for the certificate, are all in the keytool step for generating the key.
The Edit SAML Authentication Settings dialog opens, as shown in the following image.
If this option remains selected, logging out from WebFOCUS will automatically log you out from Salesforce.com.
Note: The same signing and encryption certificates are used in this example, but two different certificates could also be used, if configured originally using the keytool command.
The Service Provider (SP) Metadata Generation dialog opens, as shown in the following image.
Note: If there were any issues with the passwords for the Keystore or certificate, a JSON file is returned and not the wfspMetadata.xml file.
config\was\saml
Provide this file to your ADFS administrator for their use in the configuration of ADFS.
However, do not attempt to sign in until completing the steps described in the next section.
To configure WebFOCUS as a service provider for Salesforce.com:
The New Connected App dialog opens, as shown in the following image.
Note: If you select the Enable SAML check box in the Web App Settings section of this dialog, then the SAML information that must be entered is displayed. You should copy this information from the wfspMetadata.xml file, as Salesforce.com does not provide the ability to upload WebFOCUS metadata as some other Identity Providers.
You can search for entityID within the wfspMetadata.xml file.
The configuration pane for the Connected App (WebFOCUS) is displayed, as shown in the following image.
To allow users to be able to access WebFOCUS as a Service Provider, you must add profiles to this Connected App.
The Application Profile Assignment dialog opens, as shown in the following image.
The profiles you assigned to the Connected App (WebFOCUS) are now listed under the Profiles section, as shown in the following image.
https://server.ibi.com/ibi_apps/
Redirect to your Salesforce.com login page.
You are redirected to WebFOCUS. This is a Service Provider initiated login (login from WebFOCUS).
This is an Identity Provider initiated login.
WebFOCUS | |
Feedback |