Okta

How to Configure SAML 2.0 for Chatter

Contents


Supported Features

The Okta/Chatter SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to your Chatter account as an administrator.

  2. Navigate to Setup > Security Controls > Single Sign-On Settings:

    chatter_new1.png

  3. On the Single Sign-On Settings page, click Edit:

    chatter_new2.png

  4. Check the SAML Enabled box to enable the use of SAML Single-Sign On, then click Save:

    chatter_new3.png

  5. Click New:

    chatter_new4.png

  6. Enter the following:

    • Name: Enter a preferred name.

    • Issuer: Copy and paste the following:

      Sign into the Okta Admin dashboard to generate this value

    • Identity Provider Certificate: Download, then upload the following certificate:

      Sign into the Okta Admin dashboard to generate this value

    • Request Signing Certificate: Select SelfSignedCert.

    • Request Signing Method: Select RSA-SHA256.

    • Assertion Decryption Certificate: Select Assertion not encrypted.

    • SAML Identity Type: Select Assertion contains the User's Salesforce username.

    • SAML Identity Location: Select Identity is in the Nameidentifier element of the Subject statement.

    • Service Provider Initiated Request Binding: Select HTTP POST.

    • Identity Provider Login URL: Copy the following:

      Sign into the Okta Admin dashboard to generate this value

    • Custom Logout URL: Copy and paste the following:

      Sign into the Okta Admin dashboard to generate this value

    • Entity ID:

      • If you have a custom domain setup, enter https://[customDomain].my.salesforce.com

      • If you do not have a custom domain setup, enter https://saml.salesforce.com

    • Click Save.

    chatter_new5.png

  7. Make a copy of your Login URL value:

    chatter_new6.png

  8. In Okta, select the Sign On tab for the Chatter app, then click Edit.

    • Enter the Login URL value you made a copy of in step 7 above into the corresponding field.

    • If you are using a custom domain, then enter that value into the Custom Domain field (for example, if your domain is acme.my.salesforce.com, enter acme, otherwise leave it blank.

    • Click Save:

    chatter_new7.png

  9. Done!

Notes

SP-initiated SSO

Navigate to your Salesforce Domain URL. You should see an option to login using your Identity Provider:

chatter_new8.png