Integrate OpenID Connect-Based Identity Provider
Introduction
These instructions describe the steps necessary to integrate the Application Portal with your Identify Provider (IdP) compatible with the OpenID Connect protocol.
Prerequisites
OPENID CONNECT COMPATIBLE IDP
This document assumes that your Provider is already generally available, supports OpenID Connect integration, is able to service logins for your users, and that it simply needs additional configuration to integrate with the Application Portal.
IDP ADMINISTRATOR ACCESS
IdP administrators with working knowledge of OpenID Connect SSO scenarios, with the assistance of the Application Portal team support if necessary.
CONGA LOGIN ADMINISTRATOR SECURITY GROUP
As a part of setting up the Application Portal to integrate with your Provider, the Application Portal requires at least one security group to represent those users who shall be granted administrative rights to the Application Portal. The selected security group(s) may already exist and need not be specific to Conga, if for instance you have an existing group that represents its security/domain administrators; however, some organizations may wish to create a separate security group specific to the Conga integration. This document does not cover how to create a new group or how to add a user to such a group.
To ensure that the user performing the initial configuration has and retains access to administrative functions within the Application Portal, the user must select the administrative group(s) from one or more of his/her own group memberships. This means that the initial configuration user must already be an existing member of at least one of the desired administrator security groups.
Identity Provider Configuration
This section describes the information you will need from the Application Portal in order to configure your Provider.
| CONGA CLOUD REALM | APPLICATION PORTAL URL |
|---|---|
| US REALM 1 | https://login.us1s1.congacloud.com/ |
| US Preview | https://login.us0s1.congacloud.com/ |
| EU1 | https://login.eu1s1.congacloud.com/ |
| EU Preview | https://login.eu0s1.congacloud.com/ |
| AU REALM 1 | https://login.au1s1.congacloud.com/ |
| E1 EU1 | https://login.eu1s2.congacloud.com/ |
| US REALM 2 | https://login.us1s2.congacloud.com/ |
Register the following URLs within your Identity Provider Settings (substitute realm with the correct Conga Cloud Realm):
Redirect/Reply URL
| CONGA CLOUD REALM | APPLICATION PORTAL OIDC REPLY URL |
|---|---|
| US REALM 1 | https://login.us1s1.congacloud.com/x/oidc/reply |
| US Preview | https://login.us0s1.congacloud.com/x/oidc/reply |
| EU1 | https://login.eu1s1.congacloud.com/x/oidc/reply |
| EU Preview | https://login.eu0s1.congacloud.com/x/oidc/reply |
| AU REALM 1 | https://login.au1s1.congacloud.com/x/oidc/reply |
| E1 EU1 | https://login.eu1s2.congacloud.com/x/oidc/reply |
| US REALM 2 | https://login.us1s2.congacloud.com/x/oidc/reply |
Single Logout (SLO) URL
| CONGA CLOUD REALM | APPLICATION PORTAL OIDC SIGNOUT URL |
|---|---|
| US REALM 1 | https://login.us1s1.congacloud.com/x/oidc/signout |
| US Preview | https://login.us0s1.congacloud.com/x/oidc/signout |
| EU1 | https://login.eu1s1.congacloud.com/x/oidc/signout |
| EU Preview | https://login.eu0s1.congacloud.com/x/oidc/signout |
| AU REALM 1 | https://login.au1s1.congacloud.com/x/oidc/signout |
| E1 EU1 | https://login.eu1s2.congacloud.com/x/oidc/signout |
| US REALM 2 | https://login.us1s2.congacloud.com/x/oidc/signout |
If your Identity Provider does not support Single Logout, you may ignore registering the Application Portal logout URL.
Required Information for the Application Portal Configuration
Once you have completed the registration in your Identity Provider, the Application Portal will need to following information in order to integrate with your IdP:
OpenID Connect Provider Metadata
- Issuer: the Application Portal will only accept token responses from this issuer.
- Authorization URL: URL of your Provider's OAuth 2.0 Authorization Endpoint
- Token URL: URL of your Provider's OAuth 2.0 Token Endpoint
- Client ID: The OAuth 2.0 Client Identifier
- Client Secret: Assigned by you or your Provider, it should be protected and known only to the Application Portal and your Identity Provider's authorization server.
- Single Logout URL (Optional): URL of your Provider's SLO endpoint. If you choose not to use Single Logout, you can instead provide a URL where users will be redirected after log out.
- Response Mode: The method used by your Provider to respond to the Application Portal from the Authorization Endpoint. The allowed Response Modes are:
- form_post (preferred)
- query
- Scopes: the Application Portal will request these OAuth 2.0 scopes when initiating a request to your Identity Provider's authorization server. Multiple values are allowed, separated by space. Minimum requirement: openid
Recommended: openid profile email
- ID Token Claim Names:
- preferred_username
The username that represents the user. If you are unable to provide the "preferred_username" claim name from your IdP, you can use a different claim name instead.
The email that represents the user. If you are unable to provide the "email" claim name from your IdP, you can use a different claim name instead. This will be used by certain Conga applications for email alerts and notifications.
- locale
The user's preferred locale. If you are unable to provide the "locale" claim name from your IdP, you can use a different claim name instead. This will be utilized by certain Conga applications for datetime, numerical and currency formatting.
- groups
Contains a list of the groups for which the user is a member. When a user logs in, the Application Portal recognizes those groups and they become available to use for access control. If you are unable to provide the "groups" claim name from your IdP, you can use a different claim name instead.
- ID Token Signature Verification Details:
- Signature Algorithm: select an algorithm from the HS* (HMAC-SHA) or RS* (RSA-SHA) families.
- JSON Web Key Set (JWKS) URL: Required when using an RSA algorithm, this URL is used to retrieve the keys which verify the digital signature. For HMAC-based signatures, the client secret is used instead. Signature verification is recommended; however, you may
configure the Application Portal to ignore it based on preference or if your provider does not sign ID Tokens.
Configure the Application Portal
The next step is to setup the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.
If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.
If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.
Test Integration
Please follow the steps documented in the following guide: Test IdP Integration.
