Configuring FortiPAM as an SP
To configure FortiPAM as an SP:
- Go to User Management > Saml Single Sign-On.
- In the Configure Service Provider tab, keep the default values.
Ensure that the FortiAuthenticator IdP uses the same configuration as in Configure Service Provider tab in SP Metadata when Configuring FortiAuthenticator as a SAML IdP:
FortiPAM
FortiAuthenticator
Entity ID
SP entity ID
Single Logout Service (SLS) URL
SP SLS (logout) URL
Portal (Sign On) URL
SP ACS (login) URL
- Click Next.
- In the Configure Identity Provider tab:
- In Type, select Custom.
- In IdP entity ID, enter the FortiAuthenticator IdP entity ID.
- In IdP single sign-on URL, enter the FortiAuthenticator IdP login URL.
- In IdP single logout URL, enter the FortiAuthenticator IdP logout URL.
IdP entity ID, IdP single sign-on URL, and IdP single logout URL were initially configured in Configuring FortiAuthenticator as a SAML IdP.
- In the IdP Certificate dropdown, select the remote certificate imported in Importing FortiAuthenticator certificate to FortiPAM.
- Click Next.
- In the Additional Saml Attributes tab:
- In Attribute used to identify users, enter username.
- In Attribute used to identify groups, enter group.
These attributes are the same as those configured in the Assertion Attributes pane when Configuring FortiAuthenticator as a SAML IdP.
- Click Next.
- In the Review tab, verify the information you entered and click Submit.