Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Integrate Salesforce.com

Introduction

These instructions describe the steps necessary to integrate the Application Portal with SFDC (Salesforce.com)

Prerequisites

SALESFORCE.COM

This document assumes that your SFDC environment is already available and that it simply needs additional configuration to integrate with the Application Portal. It is important to note that the Application Portal only supports SP-Initiated single sign-on. When setting up SSO in Salesforce, you use a unique attribute to identify each user. This attribute is the link that associates the Salesforce user with the third-party identity provider. You can use a username, user ID, or a Federation ID. Typically, you assign a Federation ID at the time of setting up a user account in Salesforce.

USER PERMISSIONS NEEDED

The integration procedure requires the involvement of authorized user within your SFDC organization who has the necessary permissions to configure Connected Apps with SAML.

REALM URL PROVIDED BY APPLICATION PORTAL

The remainder of these instructions will refer to the Application Portal URLs from the table below. Use the values for the appropriate realm.

CONGA CLOUD REALMAPPLICATION PORTAL URL
US REALM 1https://login.us1s1.congacloud.com
US Previewhttps://login.us0s1.congacloud.com
EU1https://login.eu1s1.congacloud.com
EU Previewhttps://login.eu0s1.congacloud.com
AU REALM 1https://login.au1s1.congacloud.com
E1 EU1https://login.eu1s2.congacloud.com
US REALM 2https://login.us1s2.congacloud.com

SFDC Configuration

WHAT INFORMATION DO YOU NEED FROM US WHEN A CONNECTED APP IS BEING CREATED?

  1. When a Connected App is being created, some SAML Service Provider Settings fields are required from the Application Portal.

    CONGA CLOUD REALM US 1

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.us1s1.congacloud.com
    ACS URLhttps://login.us1s1.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.us1s1.congacloud.com/x/sfdc-saml2/logout

    CONGA CLOUD REALM US 1-Preview

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.us0s1.congacloud.com
    ACS URLhttps://login.us0s1.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.us0s1.congacloud.com/x/sfdc-saml2/logout

    CONGA CLOUD REALM EU 1

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.eu1s1.congacloud.com
    ACS URLhttps://login.eu1s1.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.eu1s1.congacloud.com/x/sfdc-saml2/logout

    CONGA CLOUD REALM EU 1-Preview

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.eu0s1.congacloud.com
    ACS URLhttps://login.eu0s1.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.eu0s1.congacloud.com/x/sfdc-saml2/logout

    CONGA CLOUD REALM AU 1

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.au1s1.congacloud.com
    ACS URLhttps://login.au1s1.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.au1s1.congacloud.com/x/sfdc-saml2/logout

    CONGA CLOUD REALM E1 EU 1

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.eu1s2.congacloud.com
    ACS URLhttps://login.eu1s2.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.eu1s2.congacloud.com/x/sfdc-saml2/logout

    CONGA CLOUD REALM L1 US 1

    FIELD NAMEFIELD VALUE
    Entity Idhttps://login.us1s2.congacloud.com
    ACS URLhttps://login.us1s2.congacloud.com/x/sfdc-saml2/assertion
    Single Logout URLhttps://login.us1s2.congacloud.com/x/sfdc-saml2/logout
  2. You can obtain them by downloading the XML metadata file from https://login.<realm>.congacloud.com/x/sfdc-saml2/metadata.

ENABLE SALESFORCE AS AN IDENTITY PROVIDER

If not done yet, you need to enable Salesforce as an Identity Provider. From Setup, enter Identity Provider in the Quick Find box, select Identity Provider, and click Enable Identity Provider. See Salesforce documentation for more details.

Note that the Application Portal requires signing certificate with the SHA-256 algorithm which is the default from Salesforce Identity Provider.

After you enable Salesforce as an Identity Provider, you can create connected apps to provide access to the Application Portal.

CREATE A CONNECTED APP FOR APPLICATION PORTAL

Available in both Salesforce Classic and Lightning Experience Connected Apps can be created in: Group, Professional, Enterprise, Performance, Unlimited, and Developer Editions.

Connected Apps can be installed in All Editions.

Follow the Salesforce documentation on how to create a connected app for the Application Portal using the following information.

Basic Information

This section will specify basic information about your app, including the app name, logo, and contact information.

  1. Enter the connected app’s name. This name is displayed in the App Manager and on its App Launcher tile.
  2. Enter the API name used when referring to your app from a program.

Web App Settings

This section controls your app’s web settings.

  1. Select Enable SAML.
  2. Enter the following data that you can obtain from xml file the Application Portal metadata
    1. Enter manually Start URL = https://login.us1s1.congacloud.com
    2. Enter manually Entity ID = https://login.us1s1.congacloud.com
    3. Enter manually ACS URL = https://login.us1s1.congacloud.com/x/sfdc-saml2/assertion
    4. Enable Single Logout = check
    5. Enter manually Single Logout

      URL = https://login.us1s1.congacloud.com/x/sfdc-saml2/logout

    6. Select Single Logout Binding = HTTP POST
    7. Select Subject type = User ID
      Note: For Salesforce users, the User ID corresponds with the Federation ID that was assigned when you initially created your Salesforce account.
  3. Select Name ID Format = urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
    1. Issuer = keep it by default
    2. Select proper IdP Certificate to use.
  4. Select Verify Request Signatures. Browse your system for the Application Portal certificate and upload it.
  5. Copy the <X509Certificate> value extracted from xml file (the Application Portal metadata) to a new .crt file adding "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE". Then you can upload .crt file


  6. Optionally, you can choose Encrypt SAML Response. Browse your system for the Application Portal certificate and upload it.
  7. Select the method you want to use for Block Encryption Algorithm: AES128, AES256 and TRIPLE DES

  8. Save the new Connected App.

The Connected App will be created and displayed, now click on Manage button to add Custom Attributes and set who can access this app.

Add Custom Attributes

Add the following Custom Attributes using the New button under the Custom Attributes section

  1. Scroll to Custom Attributes and click New.
  2. Set the Attribute key to one specified in the table below.
  3. Click Insert Field.
  4. Click $User, $Profile or $UserRole and find the Label specified in the table below.
  5. Click Insert.
ATTRIBUTE KEYATTRIBUTE VALUE
FirstName$User.FirstName
LastName$User.LastName
ProfileId$Profile.Id
ProfileName$Profile.Name
UserRoleId$UserRole.Id
UserRoleName$UserRole.Name

Alternative to User Profiles

Salesforce previously announced plans to retire permissions in profiles.

Permission sets are an authorization mechanism for internal use in Salesforce and are not exposed for external consumption by third-party applications. Therefore, we recommend using a custom attribute for managing authorization to Conga applications.

As an example, you could create a custom field in the User object (e.g., Conga_Role c) and match it with a dedicated custom attribute to be linked with the ProfileId and ProfileName attributes.

ATTRIBUTE KEYATTRIBUTE VALUE
FirstName$User.FirstName
LastName$User.LastName
ProfileId$User.Conga_Role c
ProfileName$User.Conga_Role c
UserRoleId$UserRole.Id
UserRoleName$UserRole.Name

Access permissions

Use profiles and/or permission sets to control who can access this app.

Follow Salesforce documentation Profile or Permission Sets to control who can access this app.

WHAT INFORMATION DOES APPLICATION PORTAL NEED FROM YOUR CONNECTED APP?

The Application Portal will need the metadata information; it can be downloaded from your Connected App under SAML Login Information using the Download Metadata button.



Configure the Application Portal

The next step is to set up the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.

If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.

If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.

Test Integration

Please follow the steps documented in the following guide: Test IdP Integration

Request a Service Account for SFDC IdP

HOW TO GENERATE A SELF-SIGNED CERTIFICATE ON SFDC

Follow Salesforce's documentation on how to generate a self-signed certificate.

Using the self-signed certificate, generate the public key using the following commands

openssl x509 -pubkey -noout -in mycert.crt > mypubkey.pub

WARNING

Do not share or send the private key, even with Conga Customer Success or Conga Customer Support.

Include [mypubkey].pub when requesting your Service Account