Working With Your Identity Provider
- You must gather the following information from your identity providerbefore configuring Salesforce for SAML. The version of SAML the identity provider uses (1.1 or 2.0)The entity ID of the identity provider (also known as the issuer)An authentication certificate. Tip Be sure to storethe certificate where you can access it from your browser. This willbe uploaded to Salesforce in a later step.The following SAML assertion parameters, as appropriate:The SAML user ID typeThe SAML user ID locationAttribute NameAttribute URIName ID formatNote Attribute Name, Attribute URI, and Name ID format are only necessary if the SAML User ID Location is in an Attribute element, and not the name identifier element of a Subject statement. Tip To set up single sign-on quickly, you can import SAML 2.0 settings from an XML file (or a URL pointing to the file) on the Single Sign-On Settings page. Obtain the XML from your identity provider.You may also want to share more information about these values with youridentity provider. Tip Enable Salesforce for SAML and take a screenshot of the page for your identity provider. From Setup, enter Single Sign-On Settings in the Quick Find box, then select Single Sign-On Settings, click Edit, then select SAML Enabled.
- The version of SAML the identity provider uses (1.1 or 2.0)
- The entity ID of the identity provider (also known as the issuer)
- An authentication certificate. Tip Be sure to storethe certificate where you can access it from your browser. This willbe uploaded to Salesforce in a later step.
- The following SAML assertion parameters, as appropriate:The SAML user ID typeThe SAML user ID locationAttribute NameAttribute URIName ID formatNote Attribute Name, Attribute URI, and Name ID format are only necessary if the SAML User ID Location is in an Attribute element, and not the name identifier element of a Subject statement. Tip To set up single sign-on quickly, you can import SAML 2.0 settings from an XML file (or a URL pointing to the file) on the Single Sign-On Settings page. Obtain the XML from your identity provider.
- The SAML user ID type
- The SAML user ID location
- Attribute Name
- Attribute URI
- Name ID format
- Work with your identity provider to setup the start, login, and logout pages.
- Share the example SAML assertions with your identity provider so they can determine the format Salesforce requires forsuccessful single sign-on.