Introduction
Springboard supports authentication with any SAML 2.0 compliant service. This documentation has been written on the assumption that you are using Okta. If you are using a different authentication provider, please request the required documentation from PeopleScout.
The steps required to configure Springboard to authenticate against your Okta tenancy are outlined below;
Assumptions
The following documentation assumes that you have the following in place;
• Access to your Okta Admin Console,
• Ability to add and modify applications within your Okta Console.
Prerequisites
Before commencing the steps below please ensure you have;
• Provided PeopleScout with your careers site URL e.g https://careers.mycompany.com,
• Configuration text file provided by PeopleScout.
Dependencies
At the completion of this document you will have;
• Set up Springboard as a SAML 2.0 application within Okta
• Configured Springboard Attribute Statements within Okta
• Generated a Token Signing Certificate (Exported from Okta)
Create Okta Application
- Log into your Okta Admin Console E.g. https://mycompany.okta.com/admin
- Navigate to Applications within Okta
- Select Add Application
- Select Create New App
- Platform = Web
- Sign on method = SAML 2.0
- Select Create
- App Name = Springboard
- If desired, upload the Springboard Logo (Provided by PeopleScout)
- Set your App visibility as desired (Springboard is mobile optimised)
Configuring SAML Integration
- Enter the URL provided by PeopleScout in your configuration text file for;
a. Single sign on URL
b. Audience URI (SP Entity ID) - You will need two Attribute Statements;
a. Name = RASP_ORG_ID, Value = XXXXX (Provided by PeopleScout)
b. Name = Role, Value = SpringboardUser - Leave Group Attribute Statements Blank
- Select Next then Finish
Configuring Sign-On and Assignments
- The next step is to provide the configured information to PeopleScout to complete setting up the trust.
- Navigate to Sign-On Tab within the Springboard Application in Okta
- Select View Setup Instructions
- Provide the following to PeopleScout; Once PeopleScout have this information we will load it into our Systems and advise when the system is ready for testing.
a. Identity Provider Single Sign-On URL
b. Identity Provider Isuser
c. X.509 Certificate (Select Download)
- Configure your Sign-On Policy as desired. For further information refer to the Okta Help Centre - https://help.okta.com
- Select Assignments Tab, assign users as desired