Creating a single sign-on connection
To allow PingFederate to handle single sign-on (SSO) to Zscaler Internet Access, create a service provider (SP) connection.
About this task
You can follow these steps to create a new SP connection, or you can modify your provisioning connection. |
Steps
-
In the PingFederate administrator console, configure the data store that PingFederate will use as the source of user data. For instructions, see Datastores in the PingFederate documentation.
-
On the Identity Provider tab, in the SP Connections area, open an existing connection or create a new one as follows:
-
Click Create new.
-
On the Connection Template tab, select Use a template for this connection.
-
In the Connection Template list, select Zscaler ZIA Provisioner.
-
Click Choose File, select the
zscaler-metadata.xml
file that you downloaded in Enabling provisioning and single sign-on in Zscaler, and then click Open. Click Next.
-
-
On the Connection Type tab, select Browser SSO Profiles and clear any unwanted types. Click Next.
-
On the General Info tab, the basic connection information is populated by the metadata XML file. Click Next.
-
On the Browser SSO tab, configure browser SSO.
For a complete guide, see Configuring IdP Browser SSO in the PingFederate documentation.
-
On the Browser SSO → SAML Profiles tab, select only IdP-Initiated SSO and SP-Initiated SSO.
-
On the Browser SSO → Protocol Settings → Allowable SAML Bindings tab, select only POST.
-
On the Browser SSO → Protocol Settings → Signature Policy tab, select Always sign assertion.
-
-
On the Credentials tab, configure the connection credentials. Click Next.
For a complete guide, see Configuring credentials in the PingFederate documentation.
-
On the Credentials → Signature Verification Settings → Signature Verification Certificate tab, click Manage Certificates and import the certificate that you downloaded in Enabling provisioning and single sign-on in Zscaler.
-
-
On the Activation and Summary tab, above the Summary section, turn on the connection. Click Save.