Reference: OneLogin SSO Configuration
This topic provides additional information about configuring OneLogin as your identity provider (IdP) for Single Sign-On (SSO). For general SSO configuration steps, see Steps: Configure Single Sign-On (SSO) for Contract Management and Document Intelligence.
Considerations for OneLogin Configuration
- Application type: When adding a new app in OneLogin, search for custom SAML and selectSAML Custom Connector (Advanced).
- ACS Reply / Recipient URLin Contract Management and Document Intelligence is the same as theOneLogin ACS (Consumer) URL. TheIdentifier URLin Contract Management and Document Intelligence is the same asACS (Consumer) URL Validator.
- When completing the configuration in OneLogin, select:OptionDescriptionSAML InitiatorService ProviderSAML name IDTransientSAML Issuer TypeSpecificSAML signature elementBothSAML encryption methodAES-256-CBC
- Attribute mappings: In OneLogin, you must add and configure parameters for each attribute, such as first name, last name, and email. SelectInclude in SAML assertioncheck box for each parameter. The names you provide for these parameters are the keys, not the user's personal information, and you must use them exactly as typed in the Contract Management and Document Intelligence SSO configuration..
- Signature algorithm: Ensure that the signature algorithm is set toSHA-256in both OneLogin and Workday.