Integrate SAML-Based Identity Provider
Overview
These instructions describe the steps necessary to integrate the Application Portal with your Identity Provider (IdP) compatible with SAML 2.0.
Prerequisites
SAML 2.0 COMPATIBLE IDP
This document assumes that your IdP instance is already generally available, supports SAML 2.0 integration, is able to service logins for your users, and that it simply needs additional configuration to integrate with the Application Portal. It is important to note that the Application Portal only supports SP-Initiated single sign-on, IdP-initiated SSO is not supported.
IDP ADMINISTRATOR ACCESS
IdP administrators with working knowledge of SAML SSO scenarios, with the assistance of the Application Portal team support if necessary.
CONGA LOGIN ADMINISTRATOR SECURITY GROUP
As a part of setting up the Application Portal to integrate with your IdP, the Application Portal requires at least one security group to represent those users who shall be granted administrative rights to the Application Portal. The selected security group(s) may already exist and need not be specific to Conga, if for instance you have an existing group that represents its security/domain administrators; however, some organizations may wish to create a separate security group specific to the Conga integration. This document does not cover how to create a new group or how to add a user to such a group. To ensure that the user performing the initial configuration has and retains access to administrative functions within the Application Portal, the user must select the administrative group(s) from one or more of his/her own group memberships. This means that the initial configuration user must already be an existing member of at least one of the desired administrator security groups.
Identity Provider Configuration
This section describes the information you will need from the Application Portal in order to configure your IdP. Substitute or adjust the values for the appropriate URL that correspond with your Conga Cloud Realm (eu1s1, au1s1, us0s1, etc).
| CONGA CLOUD REALM | APPLICATION PORTAL URL |
|---|---|
| US REALM 1 | https://login.us1s1.congacloud.com |
| US REALM 2 | https://login.us1s2.congacloud.com |
| US Preview | https://login.us0s1.congacloud.com |
| EU1 | https://login.eu1s1.congacloud.com |
| EU REALM 2 | https://login.eu1s2.congacloud.com |
| EU Preview | https://login.eu0s1.congacloud.com |
| AU REALM 1 | https://login.au1s1.congacloud.com |
APPLICATION PORTAL METADATA
You can obtain the Application Portal metadata by combining your realm's Application Portal URL with the following URI: /x/saml2/metadata.
| CONGA CLOUD REALM | APPLICATION PORTAL URL |
|---|---|
| US REALM 1 | https://login.us1s1.congacloud.com/x/saml2/metadata |
| US REALM 2 | https://login.us1s2.congacloud.com/x/saml2/metadata |
| US Preview | https://login.us0s1.congacloud.com/x/saml2/metadata |
| EU1 | https://login.eu1s1.congacloud.com/x/saml2/metadata |
| EU REALM 2 | https://login.eu1s2.congacloud.com/x/saml2/metadata |
| EU Preview | https://login.eu0s1.congacloud.com/x/saml2/metadata |
| AU REALM 1 | https://login.au1s1.congacloud.com/x/saml2/metadata |
You can import our metadata file directly if your Identity Provider supports it. Alternatively, you can specify all settings manually using the information provided in the Application Portal metadata file. the Application Portal requires that all assertions from the Identity Provider are signed with the SHA256 hashing algorithm. (Signing the assertion allows the Application Portal to validate the assertion's signature against your IdP's public X.509 certificate.) the Application Portal signs outgoing messages to the IdP with the SHA256 hashing algorithm. the Application Portal does make an allowance of two minutes (configurable) for clock skew. It is important that your server clock stays synced.
Required Information for the Application Portal
the Application Portal will need to following information in order to integrate with your IdP.
IDP METADATA
Conga will need the metadata about your IdP including the following information:
- Entity ID: The unique identifier for your IdP. the Application Portal will only accept SAML assertions from an entity with this ID.
- Single Sign On Service: The SSO POST endpoint that the Application Portal will send authentication requests to.
- Single Logout Service (OPTIONAL): The SLO POST endpoint to which the Application Portal will send logout requests. If you choose not to use Single Logout, you must instead provide us a URL to which we can redirect users after they log out.
- Public X.509 Certificate (signing): the Application Portal will use this to establish trust with your IdP. the Application Portal will validate incoming SAML assertions from the IdP with this certificate.
- NameID Format: The allowed NameID formats are:
urn:oasis:names:tc:SAML:2.0:nameid - format:persistent(preferred)urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress- Custom Attributes - Reference the table below for the custom attributes.Important: If these attributes are not configured correctly, login or access control may not work!
| ATTRIBUTE NAME | DESCRIPTION |
|---|---|
FirstName | First name of the user (recommended). |
LastName | Last name of the user (recommended). |
Email | The email of the user (recommended). This will be used by certain Conga applications to send out email alerts and notifications. |
DisplayName | Display name of the user (optional). If the display name is not provided, the Application Portal will use the concatenation of first name and last name as the display name. |
Locale | The desired local of the user (optional). This will be utilized by certain Conga applications for datetime, numerical and currency formatting. |
username | Users login user name (required). This should uniquely identify a given user. |
Group | This attribute should contain a list of the groups for which the user is a member (required). When a user logs in, we recognize those groups and they become available to use for access control. If this attribute is missing or empty, it will not be possible to grant a user access to any Conga products! Example values for Group attribute: group1 group2 group3 |
Troubleshooting
If you get an error in the form of "errorID":"AUTH-001004","errorMessage":"Failed to verify SAML assertion." when attempting to log in, follow the steps below.
If everything appears correct with the claims, check both that both the certificate uploaded to the Application Portal and the Conga SAML certificate (if applicable) are uploaded correctly.
If you get an error in the form of "errorID":"AUTH-001008","errorMessage":"IdP initiated SSO is not supported." , your Identity Provider needs to be configured to use SP-initiated SAML authentication instead.
Configure the Application Portal
The next step is to setup the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.
If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.
If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.
Test Integration
Please follow the steps documented in the following guide: Test IdP Integration
