Skip to main content

Set up Brightflag as Service Provider (SP) in PingFederate

Sign in as a PingFederate administrator. Navigate to your identity provider configurations by clicking on the IDPConfiguration tab. Under ...

  • Sign in as a PingFederate administrator.

  • Navigate to your identity provider configurations by clicking on the IDP
    Configuration tab.

  • Under SP Connections, click Create New to create your service provider connection (in this
    instance, Brightflag is your service provider).

  • Select the Browser SSO Profiles connection template on the Connection Type tab
    and click Next.

  • Select Browser SSO on the Connection Options tab and click Next.

  • Select None as the method for importing metadata and click Next

  • Enter Brightflag’s Entity ID for the ‘Partner’s Entity ID’ field. Provide a title for the
    Connection Name field, such as ‘Brightflag SP Configuration', and enter Brightflag’s Base URL
    field as described above. Click Next.

  • Note: Please enter the urls described above in the fields found in the image.

  • Click “Configure Browser SSO” on this tab

  • SP Connection > Browser SSO > SAML Profiles

  • Select the “SP-Initiated SSO” and “SP-Initiated SLO” options and click “Next.”

  • Enter your desired assertion validity time from on the “Assertion Lifetime” tab and click
    “Next.” An example of an assertion validity time might be something similar to ~ 5 minutes.

  • SP Connection > Browser SSO > Assertion Creation

  • Click “Configure Assertion Creation” on this tab.

  • SP Connection > Browser SSO > Assertion Creation > Identity Mapping

  • Choose the “PSEUDONYM” option and check “INCLUDE ATTRIBUTE IN ADDITION TO
    PSEUDONYM.” Click “Next.”

  • SP Connection > Browser SSO > Assertion Creation > Attribute Contract

  • We required an attribute mapping of:
    ● username → email-address

  • Please enter under Extend the Contract tab a value of: urn:mace:dir:attribute-def:username
    Please enter under the Attribute Name Format tab a:
    urn:oasis:names:tc:SAML:2.0:attrname-format:emailAddress

  • Note: these values should be part of the same row

  • Click next and finish the remaining steps involved in Assertion Creation

  • SP Connection > Browser SSO > Assertion Creation > Authentication Source Mapping

  • Click “Map New Adapter Instance” on this tab.

  • SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Adapter Instance

  • Select an Adapter Instance such as ‘Adapter’ and ensure in the adapter contract list shown
    there exists a username entry, which should be generated from step 13 above.

  • SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Mapping Method

  • Select the “USE ONLY THE ADAPTER CONTRACT VALUES IN THE SAML ASSERTION” option
    this tab and click “Next.”

  • SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Attribute Contract
    Fulfillment

  • Select your adapter instance in each “Source” drop-down menu and the corresponding
    values as the “Value” for attributes on this tab and click “Next.

  • Note: You should not have a user.email, user.firstname or user.lastname attribute contracts as
    shown in the above image. All we require is:

  • SAML_SUBJECT → Adapter → username

  • Username → Adapter → email-address

  • SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Issuance Criteria

  • (Optional) Select any authorization conditions you would like on this tab and click “Next.”

  • SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Summary

  • Click “Done” on the “Summary” tab.

  • SP Connection > Browser SSO > Assertion Creation > Authentication Source Mapping

  • You will be taken back to the “Authentication Source Mapping” tab. Click “Next.”

  • SP Connection > Browser SSO > Assertion Creation > Summary

  • Review your Assertion Creation Configuration on the “Summary” tab. Click “Done.”

  • Note: Again, you are only expected to have a single attribute shown here, the image above is only
    for clarity as to where you should be in the process.

  • We expect:
    Attribute → urn:mace:dir:attribute-def:username
    Attribute Name Format → urn:oasis:names:tc:SAML:2.0:attrname-format:emailAddress
    (Or any association with an email format)

  • You will be taken back to the Assertion Creation tab. Click “Next.”

  • SP Connection > Browser SSO > Protocol Settings

  • Click “Configure Protocol Settings” on this tab.

  • Ensure the attribute contract is as specified above.

  • SP Connection > Browser SSO > Protocol Settings > Assertion Consumer Service URL

  • The Single Sign-On endpoint URL should be pre-populated in the “Endpoint URL” field on
    this tab. Click “Next.”

  • Note: The image above has a different Endpoint URL, please replace this URL as specified below.
    1. We require an endpoint URL of: https://{region_prefix}.brightflag.com/saml/consumeSaml
    2. We require a Binding of Post.

  • Click Next.

  • SP Connection > Browser SSO > Protocol Settings > Allowable SAML Bindings

  • Select only “POST” on this tab and click “Next.”

  • SP Connection > Browser SSO > Protocol Settings > Signature Policy

  • SP Connection > Browser SSO > Protocol Settings > Encryption Policy

  • SP Connection > Browser SSO > Protocol Settings > Summary

  • Click “Done” on the “Protocol Settings Summary” tab.

  • SP Connection > Browser SSO > Summary

  • Click “Done” on the “Browser SSO Summary” tab.

  • SP Connection > Browser SSO

  • Click “Next” on this tab.

  • SP Connection > Credentials

  • Click “Configure Credentials” on this tab.

  • Select the Signing Certificate to use with the Single Sign-On service and select “INCLUDE THE CERTIFICATE IN THE SIGNATURE ELEMENT.” Click Next.

  • SP Connection > Credentials > Signature Verification Settings > Trust Model

  • Select the desired Trust Model on this tab. Click “Next.”

  • SP Connection > Credentials > Signature Verification Settings > Signature Verification Certificate

  • Select the certificate imported with SP metadata on this tab. Click “Next.”

  • SP Connection > Credentials > Signature Verification Settings > Summary

  • Click “Done” on the Signature Verification Summary tab.

  • SP Connection > Credentials > Signature Verification Settings

  • Click “Done” on this tab.

  • SP Connection > Credentials

  • Click “Next” on this tab.

  • SP Connection > Activation & Summary

  • Select “Active” for the “Connection Status” option and then click “Save” at the bottom of
    this page.

This completes the setup of the ping federate IDP with a Brightflag Service Provider. The
remainder of this guide will demonstrate how to send Brightflag your federation_metadata.xml to
help initialize your SSO profile.

1. First, click on the “IdP Configuration” page listed on the left side of your PingFederate
console. Click “Manage All” under “SP Connections.”

Locate the desired service provider connection and click “Export Metadata.” Select a Signing Certificate from the drop-down menu on the “Metadata Signing” tab. Check the option “CHECK THIS CERTIFICATE’S PUBLIC KEY CERTIFICATE IN THE ELEMENT” option.

Click “Next.”

You will be taken to the “Export & Summary” page. Scroll to the bottom and click “Export.” The .xml
file that contains the required metadata to integrate with Frame will be automatically downloaded.
Please send this downloaded metadata file and send it to brightflag.

Did this answer your question?