Login as Administrator
Setup (under your username) -> Security Controls (Left Nav under Administrative Setup) -> Single Sign-on Settings
Click the edit button, then check the SAML enabled box.
Enter the following information (but change "auth" to "auth-test" or "auth-dev" if linking a test or development application to Shibboleth's test or development instance):
Option |
Value |
---|---|
SAML Version |
2.0 |
Identity Provider Certificate |
get it here: |
Identity Provider Login URL |
|
Custom Error URL |
leave empty |
SAML User ID Type |
Assertion contains the Federation ID from the User object |
SAML User ID Location |
User ID is in the NameIdentifier element of the Subject statement |
Entity Id |
|
Issuer |
|
Identity Provider Logout URL |
leave blank |
It should look like this..
SAVE!
Please email your entire "Salesforce.com Login URL" to idp.yale@panlists.yale.edu, ITS needs this url to add to the IdP for SSO to work. This will take a short amount of time to push to the production IdP so please request this a few days before the site go live date.
Thats it... almost... check out how to manage access to the site to select netids, here.