Configure PingOne for Coveo SSO
Configure PingOne for Coveo SSO
This is for:
System AdministratorPingOne is a service providing single sign-on (SSO) for web and mobile applications.
As a Coveo administrator, you can implement Security Assertion Markup Language (SAML) 2.0 SSO when your company uses PingOne. Users can then log in to Coveo without having to provide their authentication credentials since their identity has previously been validated when logging in to their PingOne session.
To allow users to log in via SAML SSO, Coveo must be able to trust and rely on PingOne to authenticate users wanting to log in. To establish this trust relationship, you must configure PingOne and Coveo so that both parties can exchange authentication information. This page explains how to proceed.
To configure SSO in more than one Coveo organization, for example in a production organization and a sandbox organization, configure one of these organizations, and then follow the instructions at the end of this page.
|
|
Note
If you’re not the PingOne administrator at your company, contact them so they configure PingOne using the following steps. |
Configure PingOne
Both PingOne and Coveo must be configured to work together and provide a SAML SSO service to your Coveo users.
First configure PingOne so that it can provide Coveo with user authentication data.
-
Log in to your PingOne Administrator account.
-
Select the Applications tab.
-
Click the Add Application dropdown menu, and then New SAML Application.
-
Under 1. Application Details:
-
In the Application Name box, enter an application name to display in your Applications page.
-
In the Application Description box, enter a short application description.
-
In the Category dropdown menu, select a category to label the application.
-
Click Continue to Next Step.
-
-
Under 2. Application Configuration:
NoteYou might need to scroll up on this page to see all options.
-
Next to Upload Metadata, click Or use URL, and then enter one of the following addresses. Alternatively, you can download the XML file from the URL, and then click Select File to upload it.
-
For a regular (non-HIPAA) organization:
https://platform.cloud.coveo.com/saml/metadata. -
For a HIPAA organization:
https://platformhipaa.cloud.coveo.com/saml/metadata. -
For an organization with data residency outside the US:
https://platform-<REGION_ABBREVIATION>.cloud.coveo.com/saml/metadata.
-
-
The Assertion Consumer Service (ACS) and Entity ID boxes are automatically filled, and a Primary Verification Certificate is loaded. Click Continue to Next Step.
-
-
Under 3. SSO Attribute Mapping:
-
Click Add new attribute, and then fill the boxes using the following table values.
Application attribute Identity bridge attribute or literal value Required user.emailEmail
-
To import your PingOne groups in Coveo, click Add new attribute again, and then fill the boxes using the following table values.
NoteImporting your PingOne groups into Coveo allows you to create several Coveo organization members at once. If you don’t import your PingOne groups, you must add your PingOne users to your Coveo organization one by one.
Application attribute Identity bridge attribute or literal value Required user.groupsmemberOf
-
Optionally, to add additional attributes, click Add new attribute again, and then fill the boxes.
ExampleYou could choose to add the following attributes:
Application attribute Identity bridge attribute or literal value user.firstNameFirst Name
user.lastNameLast Name
-
Click Save & Publish.
-
-
Under 4. Review Setup, review your configuration. You’ll use the information displayed on this page to configure Coveo.
-
Click Finish.
Prepare to configure Coveo
Once you’ve configured PingOne so that it passes the right information about user authentication to Coveo, you must configure Coveo to enable federation between Coveo and PingOne. To do so, retrieve data to later import into Coveo:
-
In the My Applications PingOne page, click the application you just created to display your application configuration.
-
Next to Signing Certificate, click Download.
-
Once you have downloaded the file, open it with a text editor such as Notepad++. This is the public certificate you’ll enter in the Coveo configuration panel.
-
Next to SAML Metadata, click Download.
-
Once you have downloaded the file, open it with a text editor such as Notepad++.
-
The
entityIDdisplayed at the top of the document must be entered in the Coveo configuration panel. -
The
SingleSignOnServicePOST binding address displayed towards the bottom of the file must be entered in the Coveo configuration panel, in the Single sign-on URL box.
-
Configure Coveo
Once you’ve configured your identity provider to provide Coveo with user authentication data, you must configure Coveo to trust your identity provider and accept to rely on it for user authentication.
-
With the data required to fill the Coveo configuration form in hand, access the Settings page:
-
Log in to Coveo (platform-ca | platform-eu | platform-au) as a member of a group with the required privileges to manage settings in the target Coveo organization.
-
On the Settings page, select the Organization tab, and then select the Single sign-on (platform-ca | platform-eu | platform-au) subtab.
-
-
In the Single sign-on subtab, in the Identity provider name box, enter the identity provider name as you want it to appear on your Coveo organization login page.
-
In the Single sign-on URL box, enter the URL where Coveo must send an authentication request. The SSO URL may also be called Assertion Consumer Service (ACS).
-
In the Identity provider issuer URI box, enter the identity provider issuer unique URI. The identity provider issuer URI may also be called entity ID or federation service identifier.
-
Using one of the following methods, provide Coveo with the identity provider’s Base64 public certificate to validate the identity provider signature:
-
Paste the certificate in the X.509 public certificate box.
-
If you saved the certificate on your computer, click Upload to browse your files and upload the certificate.
-
-
Click Add.
Encrypt PingOne assertions
Assertion encryption is optional. To encrypt PingOne assertions, retrieve the Coveo public certificate and import it into your PingOne configuration:
-
On the Settings page, on the Single sign-on (platform-ca | platform-eu | platform-au) tab, download Coveo’s certificate.
-
Access your PingOne application configuration:
-
Log in to your PingOne Administrator account.
-
Select the Applications tab.
-
On the My Application page, click your Coveo application.
-
-
Under the application configuration, click Edit.
-
Under 1. Application Details, click Continue to Next Step.
-
Under 2. Application Configuration:
-
Check the Encrypt Assertion box.
-
Next to Encryption Certificate, click Select file, and then select the Coveo public certificate you downloaded.
-
Next to Signing, select Sign Response.
-
Click Continue to Next Step.
-
-
Under 3. SSO Attribute Mapping, click Save & Publish.
Test your configuration
Once you’ve completed the SSO configuration, test the login process to ensure it works as expected. To do so, you’ll need to add your SSO identity as a member of your Coveo organization. You can’t use the account you’ve used to configure SSO, as it’s associated with a different identity provider. See Login options and Multiple accounts for details.
-
Add your email address as an organization member. In the Add a Member dialog, under Provider, ensure to select Single sign-on.
-
Log out of the Coveo Administration Console, and then log back in using the SSO option and your identity provider account. By doing so, you ensure Coveo and your identity provider work together properly.
We strongly recommend that you don’t delete the account with which you first logged in to the Administration Console and implemented SAML SSO. This original account is a "backdoor" that prevents you from being locked out if the SAML SSO doesn’t work as expected. At any time, you can log in with your original, non-SSO identity provider, and then edit the Coveo configuration. For details on how accounts belonging to the same individual are separated, see Multiple Accounts.
Alternatively, if you must delete your original account, you can also create another non-SSO administrator account with the required privileges beforehand. Logging in via email is also an alternative.
Invite SSO users
Once you’ve verified that your SSO configuration works, invite SSO users to join your Coveo organization.
|
|
Once your SSO is active, promptly add your users to the organization as SSO users so they can log in successfully. When an organization has an SSO configured, users accessing a hosted search page of this organization are directed by default to the SSO login page. If a user hasn’t been added to Coveo as an SSO user, they can authenticate with their identity provider, but they won’t be able to access the hosted search page because no corresponding Coveo SSO user exists. |
Add users to your Coveo organization by using either or both of these methods:
-
Adding them one by one through the Members (platform-ca | platform-eu | platform-au) page.
-
If you’ve decided to import SSO groups into Coveo, you can add a group of SSO users to a Coveo group.
Configure SSO in another organization
If you have multiple Coveo organizations, such as a production organization and a sandbox organization, you must use the same SSO settings for all organizations. Users will then use the same SSO credentials to log in, regardless of the organization they are accessing.
Follow these steps to configure SSO in additional organizations:
-
Ensure that the user identity you’ll use to configure SSO:
-
Is a member of all organizations where the SSO configuration will be used, including the original organization where SSO is already configured. If it’s not already a member, this user identity must be invited to the organizations and accept the invitations.
-
Has the privilege to edit SSO settings (Edit on the Single sign-on identity provider domain) in each of these organizations.
-
-
Using this identity, log in to the organization where you want to configure SSO.
-
In the Single sign-on (platform-ca | platform-eu | platform-au) tab of the Settings page, delete any existing SSO configuration. Save your change. This will also permanently delete the associated SSO members from your Coveo organization.
-
Copy the SSO settings from the first organization to the other. The SSO settings provided to Coveo must be identical across all organizations, including the identity provider name.
Open the organization where SSO was originally configured in a private browser window. This will let you copy and paste from one organization to the other without logging in and out to switch between them.
-
Follow the remainder of the deployment process above, starting at the assertion encryption step, for each organization where you copied the SSO settings.
Required privileges
The following table indicates the privileges required to configure SSO on the Single sign-on (platform-ca | platform-eu | platform-au) page (see Manage privileges and Privilege reference).
| Action | Service | Domain | Required access level |
|---|---|---|---|
View SSO configuration |
Organization |
Organization |
View |
Single sign-on identity provider |
View |
||
Edit SSO configuration |
Organization |
Organization |
View |
Single sign-on identity provider |
Edit |
|
|
Note
Granting the Edit access level on a domain also implicitly grants View on that domain. |