Configuring SAML Single Sign-On : Using SAML 2.0 For Single Sign-On : Introduction
  
Introduction
To configure SAML SSO, you need an SAML identity provider. CTERA Portal SAML single sign-on has been certified with the following identity providers:
Okta
OneLogin
Microsoft Active Directory Federation Services 2.0 (ADFS) on Windows 2008 and Windows 2012
Before setting up SAML in the CTERA Portal, you have to define an endpoint on the identity provider side. Although each identity provider can have a different procedure for setting up the endpoint, the SAML protocol requires the following information:
Entity ID – A globally unique name for a SAML entity. This entity is defined at the identity provider, IdP, side.
Sign-in page URL – The location where the SAML assertion is sent with HTTP POST. This is often referred to as the SAML Assertion Consumer Service (ACS) URL for the SAML endpoint at the IdP side.
Log-out page URL – The location where the logout response will be sent.
Identity Provider Certificate – The authentication certificate issued by the provider.
The terms used for this information can vary between the different identity providers.
Note: If you want to use a different identity provider, contact CTERA to validate the provider.
You need to enable SSO on the portal and specify the identity provider's parameters. Once configured, the provider handles the sign-in process for all portal users, including access from mobile devices. The provider is also responsible for authentication credentials for the users.