This guide provides step-by-step instructions to configure SAML Single Sign-On (SSO) with OneLogin using the SAML Test Connector (Advanced). This configuration lets you create a secure and streamlined authentication for your users.
Configure the SSO connection
- In the Opti ID Admin Center, go to Settings to configure a new SAML SSO connection.
- Assertion Consumer Service URL (ACS URL)
- Audience URI
-
In your OneLogin admin dashboard, go to Applications and click Add App.
-
In the Search field, enter saml test and select SAML Test Connector (Advanced) from the results list.
-
Enter the desired app name and click Save.
- Go to the SSO tab.
-
Copy the Issuer URL.
-
Copy the SAML 2.0 Endpoint (HTTP).
-
Click View Details in the X.509 Certificate section.
-
Click Download and save the PEM file.
-
- Go to the Opti ID Admin Center > Settings and configure a new SAML SSO connection.
- For the Issuer URL, paste the Issuer URL you copied in step five.
- For the SSO URL, paste the SAML 2.0 Endpoint URL you copied in step five.
- For the Signature Certificate, select the certificate file you downloaded in step five.
- When you submit the form to create an SSO connection, the page displays the Audience URL and the Assertion Consumer Service URL. Copy both values to be used later to complete the configuration of the OneLogin application.
- Go to the Configuration tab and paste the Audience URL into the field Audience (Entity ID).
- Paste the Assertion Consumer Service URL into the fields Recipient, ACS (Consumer) URL Validator, and ACS (Consumer) URL.
- Go to the Configuration tab and paste the Audience URL into the field Audience (Entity ID).
- Go to the SSO tab, change the SAML Signature Algorithm dropdown to SHA-256 and click Save.
For information about SAML tracing, see OneLogin's documentation on External SAML Tools.
Test the SSO connection
One of the users you assigned in the SAML application should test the setup. They need to be a user in the Opti ID Admin Center but logged out.
- Open an incognito window and go to https://login.optimizely.com.
- When you enter your email and click Next, it should redirect you to your organization's IdP.
- Double-check your settings if there are any issues with signing in with your incognito window.
If it does not work correctly, see the Opti ID troubleshooting articles. If you cannot resolve the issue, contact Optimizely Support.
Please sign in to leave a comment.