Okta

How to Configure SAML 2.0 for Seculio


Read this before you enable SAML

Enabling SAML will affect all users who use this application, which means that users will not be able to sign in through their regular log in page. They will only be able to access the app through the Okta service.

Backup URL

Seculio does not provide a backup login URL where users can sign in using their normal username and password. You can contact Seculio Support by email (seculio@lrm.jp) or submit this form to turn off SAML, if necessary.

Contents


Supported Features

The Okta/Statusbrew SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Log in to your Seculio account.

  2. Go to Verification > SAML settings:

    go to Verification SAML settings

  3. Select the Identity provider information tab and enter the following:

    • Use a metadata file: Save the following metadata file, then click Select Files to locate and upload it:

      Sign into the Okta Admin dashboard to generate this value.

    • SAML Usage status: Select ON.

    • Click Set:

    upload Metadata File, turn SAML on, click Set

  4. Select the Service provider information tab and enter the following:

    • SP Certificate: Click the download icon.

    • Access Service URL: Make a copy of your Access Service URL: For example if the URL is https://seculio.com/saml/acme, copy acme.

    download SP certificate, copy ACS URL value

  5. In Okta, select the Sign On tab for the Seculio app, then click Edit.

    • Enable Single Logout: Check this.

    • Signature Certificate: Click Browse to locate the certificate you saved earlier in (step 4).

    • Enter the ACS URL value you made a copy of in step 4 into the Tenant ID field.

    • Click Save:

    Upload SP certificate and enter Tenant ID in Okta - Sign On page

  6. Done!


Notes

SP-initiated SSO

  1. Go to: https://seculio.com/login

  2. Enter your Email address, then click next:

  3. go to https://seculio.com/login, enter email, click next