Please rate how useful you found this document: 
Average: 2 (1 vote)
Contents: [hide]

Restrictions

The SAML Auth plugin with OneLogin IDP (Identity Provider) cannot connect with the iOS version of PM Mobile.

Set Up

This section discusses how to set up the SAML Auth plugin with OneLogin IDP and how to log on to ProcessMaker.

After Installing and enabling the SAML Auth plugin, follow these steps:

  1. If you do not have a OneLogin account, it is possible to create one.

  2. Log on to your OneLogin account.

  3. After logged on, select Applications from the menu bar and Applications from the drop-down menu.

  4. Click Add App.

  5. On the Find Applications page, type saml in the search... field. Select SAML Test Connector (IdP w/ attr w/ sign response).

  6. Optionally edit the application name and the icon. Then click Save.

  7. Click Configuration.

  8. Copy the following values from ProcessMaker Service Provider section (first image below) to the Configuration section in OneLogin. Click Save:

    • Entity ID to ACS (Consumer) URL Validator.
    • Assertion Consumer Service to ACS (Consumer) URL.
    • Single Logout Service to Single Logout URL.
  9. Click SSO.

  10. Copy the following fields from OneLogin to ProcessMaker in the Identity Provider section:

    • Issuer URL to Entity ID.
    • SAML 2.0 Endpoint (HTTP) to Single Sign-On Service.
    • SLO Endpoint (HTTP) to Single Logout Service.
  11. Click View Details.

  12. Copy Fingerprint to ProcessMaker in the Identity Provider section. Click Update Configuration option.

  13. In the X.509 Certificate section click Download.

  14. In the ProcessMaker SAML Configuration, go to Configurations and then insert the Field Matching attributes.

  15. Leave the Signature Algorithm field filled in by default. Click Upload New Certificate.

  16. In the New Certificate pop-up screen, select IDP as the Certificate Type. Browse and then select the downloaded Certificate file. Click Save.

  17. Click Update Configuration to apply the changes.

To be redirected to OneLogin login page, in your ProcessMaker domain, enter the Workspace name and then click Login.

This redirects you to your OneLogin domain. Once in OneLogin, enter your OneLogin credentials and then click Sign In.



You are now logged on to ProcessMaker via OneLogin.