---
title: Configure PingFederate for SSO
description: To configure a connection for single sign-on (SSO) to Evernote, follow the instructions in this section. Outbound provisioning details are managed within a service provider (SP) connection and can be added to an existing SP connection.
component: evernote
page_id: evernote:setup:pf_evernote_connector_configure_pf_for_sso
canonical_url: https://docs.pingidentity.com/integrations/evernote/setup/pf_evernote_connector_configure_pf_for_sso.html
revdate: June 11, 2024
section_ids:
  about-this-task: About this task
  steps: Steps
---

# Configure PingFederate for SSO

## About this task

To configure a connection for single sign-on (SSO) to Evernote, follow the instructions in this section. Outbound provisioning details are managed within a service provider (SP) connection and can be added to an existing SP connection.

|   |                                                                                                                                                                                                                                                                                                               |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | SSO is required for SCIM provisioning with Evernote. SCIM is available only in Evernote Teams accounts created on or after September 15, 2017. Learn more in [How to determine when an Evernote Teams account was created](https://help.evernote.com/hc/articles/115011455527) in the Evernote documentation. |

## Steps

1. Create a new SP connection or select an existing SP connection from the **SP Configuration** menu.

2. On the **Connection Template** screen, select **Use a template for this connection** and choose **Evernote Connector** in the **Connection Template** list. When asked during the connection configuration steps, import the `evernote-saml-metadata.xml` packaged with this connector.

   ![An image of the Connection Template screen.](_images/meb1563995310023.png)

   |   |                                                                                                 |
   | - | ----------------------------------------------------------------------------------------------- |
   |   | If this selection is not available, verify the connector installation and restart PingFederate. |

3. On the **Connection Type** screen, ensure that the **Browser SSO Profiles** checkbox is selected and the **Outbound Provisioning** checkbox is cleared.

   ![An image of the Connection Type screen.](_images/ueu1563995310996.png)

4. On the **General Info** screen, the default values are taken from the metadata file you selected in an earlier step. We recommend using the metadata default values.

   ![An image of the General Info screen.](_images/vnb1563995311687.png)

5. Click **Next** to continue the Browser SSO configuration.

   Learn more in the following sections under [Identity provider SSO configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_ident_provid_sso_config.html) in the PingFederate documentation:

   * [Managing IdP adapters](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_managing_idp_adapters.html)

   * [Configure IdP Browser SSO](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_spbrowserssostate.html)

   * [Configuring credentials](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_spconnectionconfigtasklet_credentialsstate.html)

6. On the **Attribute Contract** screen, set the **Subject Name Format** for SAML\_SUBJECT to the below value:

   * urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

7. On the authentication adapter's **Attribute Contract Fulfillment** screen, map SAML\_SUBJECT to email address. Evernote requires SAML\_SUBJECT to contain the user's email address, which must match the Evernote user's business email address.

8. On the **Credentials > Digital Signature Settings** screen, select the signing certificate.

9. On the **Activation & Summary** screen, set **Connection Status** to **ACTIVE**, then click **Save**.

   |   |                                                                                                                                                                                                                                                 |
   | - | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   |   | If you are not ready to complete the SSO configuration, you can click **Save** and return to the configuration page later. To return to the configuration page, select the connection from **Identity Provider > SP Connections > Manage All**. |
