Sign in as a PingFederate administrator.
Navigate to your identity provider configurations by clicking on the IDP
Configuration tab.Under SP Connections, click Create New to create your service provider connection (in this
instance, Brightflag is your service provider).
Select the Browser SSO Profiles connection template on the Connection Type tab
and click Next.
Select Browser SSO on the Connection Options tab and click Next.
Select None as the method for importing metadata and click Next
Brightflag’s EntityID: https://{region_prefix}.brightflag.com
Brightflag’s Base URL: https://{region_prefix}.brightflag.com
Enter Brightflag’s Entity ID for the ‘Partner’s Entity ID’ field. Provide a title for the
Connection Name field, such as ‘Brightflag SP Configuration', and enter Brightflag’s Base URL
field as described above. Click Next.
Note: Please enter the urls described above in the fields found in the image.
Click “Configure Browser SSO” on this tab
SP Connection > Browser SSO > SAML Profiles
Select the “SP-Initiated SSO” and “SP-Initiated SLO” options and click “Next.”
Enter your desired assertion validity time from on the “Assertion Lifetime” tab and click
“Next.” An example of an assertion validity time might be something similar to ~ 5 minutes.SP Connection > Browser SSO > Assertion Creation
Click “Configure Assertion Creation” on this tab.
SP Connection > Browser SSO > Assertion Creation > Identity Mapping
Choose the “PSEUDONYM” option and check “INCLUDE ATTRIBUTE IN ADDITION TO
PSEUDONYM.” Click “Next.”
SP Connection > Browser SSO > Assertion Creation > Attribute Contract
We required an attribute mapping of:
● username → email-addressPlease enter under Extend the Contract tab a value of: urn:mace:dir:attribute-def:username
Please enter under the Attribute Name Format tab a:
urn:oasis:names:tc:SAML:2.0:attrname-format:emailAddressNote: these values should be part of the same row
Click next and finish the remaining steps involved in Assertion Creation
SP Connection > Browser SSO > Assertion Creation > Authentication Source Mapping
Click “Map New Adapter Instance” on this tab.
SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Adapter Instance
Select an Adapter Instance such as ‘Adapter’ and ensure in the adapter contract list shown
there exists a username entry, which should be generated from step 13 above.SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Mapping Method
Select the “USE ONLY THE ADAPTER CONTRACT VALUES IN THE SAML ASSERTION” option
this tab and click “Next.”SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Attribute Contract
FulfillmentSelect your adapter instance in each “Source” drop-down menu and the corresponding
values as the “Value” for attributes on this tab and click “Next.
Note: You should not have a user.email, user.firstname or user.lastname attribute contracts as
shown in the above image. All we require is:SAML_SUBJECT → Adapter → username
Username → Adapter → email-address
SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Issuance Criteria
(Optional) Select any authorization conditions you would like on this tab and click “Next.”
SP Connection > Browser SSO > Assertion Creation > IdP Adapter Mapping > Summary
Click “Done” on the “Summary” tab.
SP Connection > Browser SSO > Assertion Creation > Authentication Source Mapping
You will be taken back to the “Authentication Source Mapping” tab. Click “Next.”
SP Connection > Browser SSO > Assertion Creation > Summary
Review your Assertion Creation Configuration on the “Summary” tab. Click “Done.”
Note: Again, you are only expected to have a single attribute shown here, the image above is only
for clarity as to where you should be in the process.We expect:
Attribute → urn:mace:dir:attribute-def:username
Attribute Name Format → urn:oasis:names:tc:SAML:2.0:attrname-format:emailAddress
(Or any association with an email format)You will be taken back to the Assertion Creation tab. Click “Next.”
SP Connection > Browser SSO > Protocol Settings
Click “Configure Protocol Settings” on this tab.
Ensure the attribute contract is as specified above.
SP Connection > Browser SSO > Protocol Settings > Assertion Consumer Service URL
The Single Sign-On endpoint URL should be pre-populated in the “Endpoint URL” field on
this tab. Click “Next.”
Note: The image above has a different Endpoint URL, please replace this URL as specified below.
1. We require an endpoint URL of: https://{region_prefix}.brightflag.com/saml/consumeSaml
2. We require a Binding of Post.Click Next.
SP Connection > Browser SSO > Protocol Settings > Allowable SAML Bindings
Select only “POST” on this tab and click “Next.”
SP Connection > Browser SSO > Protocol Settings > Signature Policy
SP Connection > Browser SSO > Protocol Settings > Encryption Policy
SP Connection > Browser SSO > Protocol Settings > Summary
Click “Done” on the “Protocol Settings Summary” tab.
SP Connection > Browser SSO > Summary
Click “Done” on the “Browser SSO Summary” tab.
SP Connection > Browser SSO
Click “Next” on this tab.
SP Connection > Credentials
Click “Configure Credentials” on this tab.
Select the Signing Certificate to use with the Single Sign-On service and select “INCLUDE THE CERTIFICATE IN THE SIGNATURE ELEMENT.” Click Next.
SP Connection > Credentials > Signature Verification Settings > Trust Model
Select the desired Trust Model on this tab. Click “Next.”
SP Connection > Credentials > Signature Verification Settings > Signature Verification Certificate
Select the certificate imported with SP metadata on this tab. Click “Next.”
SP Connection > Credentials > Signature Verification Settings > Summary
Click “Done” on the Signature Verification Summary tab.
SP Connection > Credentials > Signature Verification Settings
Click “Done” on this tab.
SP Connection > Credentials
Click “Next” on this tab.
SP Connection > Activation & Summary
Select “Active” for the “Connection Status” option and then click “Save” at the bottom of
this page.
This completes the setup of the ping federate IDP with a Brightflag Service Provider. The
remainder of this guide will demonstrate how to send Brightflag your federation_metadata.xml to
help initialize your SSO profile.
1. First, click on the “IdP Configuration” page listed on the left side of your PingFederate
console. Click “Manage All” under “SP Connections.”
Locate the desired service provider connection and click “Export Metadata.” Select a Signing Certificate from the drop-down menu on the “Metadata Signing” tab. Check the option “CHECK THIS CERTIFICATE’S PUBLIC KEY CERTIFICATE IN THE ELEMENT” option.
Click “Next.”
You will be taken to the “Export & Summary” page. Scroll to the bottom and click “Export.” The .xml
file that contains the required metadata to integrate with Frame will be automatically downloaded.
Please send this downloaded metadata file and send it to brightflag.
