Integrate Salesforce.com
Introduction
These instructions describe the steps necessary to integrate the Application Portal with SFDC (Salesforce.com)
Prerequisites
SALESFORCE.COM
This document assumes that your SFDC environment is already available and that it simply needs additional configuration to integrate with the Application Portal. It is important to note that the Application Portal only supports SP-Initiated single sign-on. When setting up SSO in Salesforce, you use a unique attribute to identify each user. This attribute is the link that associates the Salesforce user with the third-party identity provider. You can use a username, user ID, or a Federation ID. Typically, you assign a Federation ID at the time of setting up a user account in Salesforce.
USER PERMISSIONS NEEDED
The integration procedure requires the involvement of authorized user within your SFDC organization who has the necessary permissions to configure Connected Apps with SAML.
REALM URL PROVIDED BY APPLICATION PORTAL
The remainder of these instructions will refer to the Application Portal URLs from the table below. Use the values for the appropriate realm.
| CONGA CLOUD REALM | APPLICATION PORTAL URL |
|---|---|
| US REALM 1 | https://login.us1s1.congacloud.com |
| US Preview | https://login.us0s1.congacloud.com |
| EU1 | https://login.eu1s1.congacloud.com |
| EU Preview | https://login.eu0s1.congacloud.com |
| AU REALM 1 | https://login.au1s1.congacloud.com |
| E1 EU1 | https://login.eu1s2.congacloud.com |
| US REALM 2 | https://login.us1s2.congacloud.com |
SFDC Configuration
WHAT INFORMATION DO YOU NEED FROM US WHEN A CONNECTED APP IS BEING CREATED?
- When a Connected App is being created, some SAML Service Provider Settings fields are required from the Application Portal.
CONGA CLOUD REALM US 1
FIELD NAME FIELD VALUE Entity Id https://login.us1s1.congacloud.com ACS URL https://login.us1s1.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.us1s1.congacloud.com/x/sfdc-saml2/logout CONGA CLOUD REALM US 1-Preview
FIELD NAME FIELD VALUE Entity Id https://login.us0s1.congacloud.com ACS URL https://login.us0s1.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.us0s1.congacloud.com/x/sfdc-saml2/logout CONGA CLOUD REALM EU 1
FIELD NAME FIELD VALUE Entity Id https://login.eu1s1.congacloud.com ACS URL https://login.eu1s1.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.eu1s1.congacloud.com/x/sfdc-saml2/logout CONGA CLOUD REALM EU 1-Preview
FIELD NAME FIELD VALUE Entity Id https://login.eu0s1.congacloud.com ACS URL https://login.eu0s1.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.eu0s1.congacloud.com/x/sfdc-saml2/logout CONGA CLOUD REALM AU 1
FIELD NAME FIELD VALUE Entity Id https://login.au1s1.congacloud.com ACS URL https://login.au1s1.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.au1s1.congacloud.com/x/sfdc-saml2/logout CONGA CLOUD REALM E1 EU 1
FIELD NAME FIELD VALUE Entity Id https://login.eu1s2.congacloud.com ACS URL https://login.eu1s2.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.eu1s2.congacloud.com/x/sfdc-saml2/logout CONGA CLOUD REALM L1 US 1
FIELD NAME FIELD VALUE Entity Id https://login.us1s2.congacloud.com ACS URL https://login.us1s2.congacloud.com/x/sfdc-saml2/assertion Single Logout URL https://login.us1s2.congacloud.com/x/sfdc-saml2/logout - You can obtain them by downloading the XML metadata file from https://login.<realm>.congacloud.com/x/sfdc-saml2/metadata.
ENABLE SALESFORCE AS AN IDENTITY PROVIDER
If not done yet, you need to enable Salesforce as an Identity Provider. From Setup, enter Identity Provider in the Quick Find box, select Identity Provider, and click Enable Identity Provider. See Salesforce documentation for more details.
Note that the Application Portal requires signing certificate with the SHA-256 algorithm which is the default from Salesforce Identity Provider.
After you enable Salesforce as an Identity Provider, you can create connected apps to provide access to the Application Portal.
CREATE A CONNECTED APP FOR APPLICATION PORTAL
Available in both Salesforce Classic and Lightning Experience Connected Apps can be created in: Group, Professional, Enterprise, Performance, Unlimited, and Developer Editions.
Connected Apps can be installed in All Editions.
Follow the Salesforce documentation on how to create a connected app for the Application Portal using the following information.
Basic Information
This section will specify basic information about your app, including the app name, logo, and contact information.
- Enter the connected app’s name. This name is displayed in the App Manager and on its App Launcher tile.
- Enter the API name used when referring to your app from a program.
Web App Settings
This section controls your app’s web settings.
- Select Enable SAML.
- Enter the following data that you can obtain from xml file the Application Portal metadata
- Enter manually Start URL = https://login.us1s1.congacloud.com
- Enter manually Entity ID = https://login.us1s1.congacloud.com
- Enter manually ACS URL = https://login.us1s1.congacloud.com/x/sfdc-saml2/assertion
- Enable Single Logout = check
- Enter manually Single Logout
URL = https://login.us1s1.congacloud.com/x/sfdc-saml2/logout
- Select Single Logout Binding = HTTP POST
- Select Subject type = User IDNote: For Salesforce users, the User ID corresponds with the Federation ID that was assigned when you initially created your Salesforce account.
- Select Name ID Format = urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
- Issuer = keep it by default
- Select proper IdP Certificate to use.
- Select Verify Request Signatures. Browse your system for the Application Portal certificate and upload it.
- Copy the <X509Certificate> value extracted from xml file (the Application Portal metadata) to a new .crt file adding "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE". Then you can upload .crt file
- Optionally, you can choose Encrypt SAML Response. Browse your system for the Application Portal certificate and upload it.
- Select the method you want to use for Block Encryption Algorithm: AES128, AES256 and TRIPLE DES
- Save the new Connected App.
The Connected App will be created and displayed, now click on Manage button to add Custom Attributes and set who can access this app.
Add Custom Attributes
Add the following Custom Attributes using the New button under the Custom Attributes section
- Scroll to Custom Attributes and click New.
- Set the Attribute key to one specified in the table below.
- Click Insert Field.
- Click $User, $Profile or $UserRole and find the Label specified in the table below.
- Click Insert.
| ATTRIBUTE KEY | ATTRIBUTE VALUE |
|---|---|
| FirstName | $User.FirstName |
| LastName | $User.LastName |
| ProfileId | $Profile.Id |
| ProfileName | $Profile.Name |
| UserRoleId | $UserRole.Id |
| UserRoleName | $UserRole.Name |
Alternative to User Profiles
Salesforce previously announced plans to retire permissions in profiles.
Permission sets are an authorization mechanism for internal use in Salesforce and are not exposed for external consumption by third-party applications. Therefore, we recommend using a custom attribute for managing authorization to Conga applications.
As an example, you could create a custom field in the User object (e.g., Conga_Role c) and match it with a dedicated custom attribute to be linked with the ProfileId and ProfileName attributes.
| ATTRIBUTE KEY | ATTRIBUTE VALUE |
|---|---|
| FirstName | $User.FirstName |
| LastName | $User.LastName |
| ProfileId | $User.Conga_Role c |
| ProfileName | $User.Conga_Role c |
| UserRoleId | $UserRole.Id |
| UserRoleName | $UserRole.Name |
Access permissions
Use profiles and/or permission sets to control who can access this app.
Follow Salesforce documentation Profile or Permission Sets to control who can access this app.
WHAT INFORMATION DOES APPLICATION PORTAL NEED FROM YOUR CONNECTED APP?
The Application Portal will need the metadata information; it can be downloaded from your Connected App under SAML Login Information using the Download Metadata button.
Configure the Application Portal
The next step is to set up the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.
If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.
If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.
Test Integration
Please follow the steps documented in the following guide: Test IdP Integration
Request a Service Account for SFDC IdP
HOW TO GENERATE A SELF-SIGNED CERTIFICATE ON SFDC
Follow Salesforce's documentation on how to generate a self-signed certificate.
Using the self-signed certificate, generate the public key using the following commands
openssl x509 -pubkey -noout -in mycert.crt > mypubkey.pub
WARNING
Do not share or send the private key, even with Conga Customer Success or Conga Customer Support.
Include [mypubkey].pub when requesting your Service Account
