Okta

How to Configure SAML 2.0 for Ustream Align

Contents


Supported Features

The Okta/Ustream Align SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Sign into Ustream Align as an Administrator.

  2. Navigate to ACCOUNT > SSO Settings.

  3. Enter the following information (screen shot at end of step for reference):

    • Select Identity Provider Initiated SSO.

    • Entity ID: Copy and paste the following into this field:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Certificate: Copy and paste the following into this field:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Login URL: Copy and paste the following into this field:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Logout URL: Copy and paste the following into this field:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Click Save changes.

    UstreamAlign1.png

  4. Select CHANNELS, then select the following (screen shot at end of step for reference):

    • Select the channel for which you want SAML to be activated.

    • Click Security.

    • Locate the Content is secured with single sign-on (SSO) and click Change settings.

    UstreamAlign2.png

  5. For How do you want to secure your content?, select With single sign-on (SSO), then click Save:

    UstreamAlign3.png

  6. From the Security page, make note of your Channel ID. This is the last part (the digits) of your channel URL, as shown below:

    UstreamAlign4.png

  7. In Okta, select the Sign On tab for the Ustream Align app, then click Edit.

    • For Default Relay State, enter the Channel ID you saved in step 6.

    • Click Save:

    UstreamAlign5.png

  8. Done!


Notes

Make sure that you selected the correct value in the Base URL field under the Sign On tab in Okta. Using the wrong value will prevent you from authenticating via SAML to Ustream Align.


SP-initiated SSO

Use the Channel URL, for example: http://www.ustream.tv/internal/123456789:

UstreamAlign6.png