Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Integrate SAML-Based Identity Provider

Overview

These instructions describe the steps necessary to integrate the Application Portal with your Identity Provider (IdP) compatible with SAML 2.0.

Prerequisites

SAML 2.0 COMPATIBLE IDP

This document assumes that your IdP instance is already generally available, supports SAML 2.0 integration, is able to service logins for your users, and that it simply needs additional configuration to integrate with the Application Portal. It is important to note that the Application Portal only supports SP-Initiated single sign-on, IdP-initiated SSO is not supported.

IDP ADMINISTRATOR ACCESS

IdP administrators with working knowledge of SAML SSO scenarios, with the assistance of the Application Portal team support if necessary.

CONGA LOGIN ADMINISTRATOR SECURITY GROUP

As a part of setting up the Application Portal to integrate with your IdP, the Application Portal requires at least one security group to represent those users who shall be granted administrative rights to the Application Portal. The selected security group(s) may already exist and need not be specific to Conga, if for instance you have an existing group that represents its security/domain administrators; however, some organizations may wish to create a separate security group specific to the Conga integration. This document does not cover how to create a new group or how to add a user to such a group. To ensure that the user performing the initial configuration has and retains access to administrative functions within the Application Portal, the user must select the administrative group(s) from one or more of his/her own group memberships. This means that the initial configuration user must already be an existing member of at least one of the desired administrator security groups.

Identity Provider Configuration

This section describes the information you will need from the Application Portal in order to configure your IdP. Substitute or adjust the values for the appropriate URL that correspond with your Conga Cloud Realm (eu1s1, au1s1, us0s1, etc).

CONGA CLOUD REALMAPPLICATION PORTAL URL
US REALM 1https://login.us1s1.congacloud.com
US REALM 2https://login.us1s2.congacloud.com
US Previewhttps://login.us0s1.congacloud.com
EU1https://login.eu1s1.congacloud.com
EU REALM 2https://login.eu1s2.congacloud.com
EU Previewhttps://login.eu0s1.congacloud.com
AU REALM 1https://login.au1s1.congacloud.com

APPLICATION PORTAL METADATA

You can obtain the Application Portal metadata by combining your realm's Application Portal URL with the following URI: /x/saml2/metadata.

CONGA CLOUD REALMAPPLICATION PORTAL URL
US REALM 1https://login.us1s1.congacloud.com/x/saml2/metadata
US REALM 2https://login.us1s2.congacloud.com/x/saml2/metadata
US Previewhttps://login.us0s1.congacloud.com/x/saml2/metadata
EU1https://login.eu1s1.congacloud.com/x/saml2/metadata
EU REALM 2https://login.eu1s2.congacloud.com/x/saml2/metadata
EU Previewhttps://login.eu0s1.congacloud.com/x/saml2/metadata
AU REALM 1https://login.au1s1.congacloud.com/x/saml2/metadata

You can import our metadata file directly if your Identity Provider supports it. Alternatively, you can specify all settings manually using the information provided in the Application Portal metadata file. the Application Portal requires that all assertions from the Identity Provider are signed with the SHA256 hashing algorithm. (Signing the assertion allows the Application Portal to validate the assertion's signature against your IdP's public X.509 certificate.) the Application Portal signs outgoing messages to the IdP with the SHA256 hashing algorithm. the Application Portal does make an allowance of two minutes (configurable) for clock skew. It is important that your server clock stays synced.

Required Information for the Application Portal

the Application Portal will need to following information in order to integrate with your IdP.

IDP METADATA

Conga will need the metadata about your IdP including the following information:

  1. Entity ID: The unique identifier for your IdP. the Application Portal will only accept SAML assertions from an entity with this ID.
  2. Single Sign On Service: The SSO POST endpoint that the Application Portal will send authentication requests to.
  3. Single Logout Service (OPTIONAL): The SLO POST endpoint to which the Application Portal will send logout requests. If you choose not to use Single Logout, you must instead provide us a URL to which we can redirect users after they log out.
  4. Public X.509 Certificate (signing): the Application Portal will use this to establish trust with your IdP. the Application Portal will validate incoming SAML assertions from the IdP with this certificate.
  5. NameID Format: The allowed NameID formats are:
  6. urn:oasis:names:tc:SAML:2.0:nameid - format:persistent (preferred)
  7. urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
  8. Custom Attributes - Reference the table below for the custom attributes.
    Important: If these attributes are not configured correctly, login or access control may not work!
ATTRIBUTE NAMEDESCRIPTION
FirstNameFirst name of the user (recommended).
LastNameLast name of the user (recommended).
EmailThe email of the user (recommended). This will be used by certain Conga applications to send out email alerts and notifications.
DisplayNameDisplay name of the user (optional). If the display name is not provided, the Application Portal will use the concatenation of first name and last name as the display name.
LocaleThe desired local of the user (optional). This will be utilized by certain Conga applications for datetime, numerical and currency formatting.
usernameUsers login user name (required). This should uniquely identify a given user.
GroupThis attribute should contain a list of the groups for which the user is a member (required). When a user logs in, we recognize those groups and they become available to use for access control. If this attribute is missing or empty, it will not be possible to grant a user access to any Conga products! Example values for Group attribute: group1 group2 group3

Troubleshooting

If you get an error in the form of "errorID":"AUTH-001004","errorMessage":"Failed to verify SAML assertion." when attempting to log in, follow the steps below.

Open a SAML tracer of your choice (i.e SAML Tracer Chrome Extension) to debug SAML if you run into any errors. Ensure that the values for all of the fields match what you'd expect based on the claims assignments above. You should contain an attribute statement like the one below; verify that the Group attribute is populated as expected and is not empty.

If everything appears correct with the claims, check both that both the certificate uploaded to the Application Portal and the Conga SAML certificate (if applicable) are uploaded correctly.

If you get an error in the form of "errorID":"AUTH-001008","errorMessage":"IdP initiated SSO is not supported." , your Identity Provider needs to be configured to use SP-initiated SAML authentication instead.

Configure the Application Portal

The next step is to setup the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.

If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.

If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.

Test Integration

Please follow the steps documented in the following guide: Test IdP Integration