---
title: "Configuring SAML 2.0 Application for ForgeRock"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35430556/Configuring%20SAML%202.0%20Application%20for%20ForgeRock"
format: markdown
---
<span style="color: #000000">Before you configure SAML federation for ForgeRock, ensure that you have completed the following:</span>

- [*<span style="color: #0000FF">Selected a domain and a protocol</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397045)
- [*<span style="color: #0000FF">Generated the audience keys</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367311)

<span style="color: #000000">To configure SAML 2.0 application for ForgeRock, complete the following sections:</span>

# <span style="color: #000000">Configuring IdP and Service Provider</span>

<span style="color: #000000">Complete the following steps to configure entity provider in ForgeRock.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Instructions in the following sections are based on ForgeRock Access Management 6.5.2.3 Build 4ed586d624 and ForgeRock Identity Management 6.5.0.3 revision: 204a28f.</span>

## <span style="color: #000000">Creating Hosted Identity Provider</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Access Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">On the </span>*<span style="color: #000000">Access Management</span>*<span style="color: #000000"> page, choose to configure an existing realm or create a new realm.</span>
3. <span style="color: #000000">On the </span>**<span style="color: #000000">Realm Overview</span>**<span style="color: #000000"> dashboard, select </span>**<span style="color: #000000">Configure SAMLv2 Provider</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
4. <span style="color: #000000">On the </span>*<span style="color: #000000">Configure SAML 2.0 Provider</span>*<span style="color: #000000"> page, select </span>**<span style="color: #000000">Create Hosted Identity Provider</span>**<span style="color: #000000">, as follows:</span>  
  
> Macro (inline-media-image)
5. <span style="color: #000000">In the </span>**<span style="color: #000000">metadata</span>**<span style="color: #000000"> section, choose the applicable </span>**<span style="color: #000000">Realm</span>**<span style="color: #000000"> and the </span>**<span style="color: #000000">Signing Key</span>**<span style="color: #000000"> from the drop-down menu. The Signing Key menu lists keys that are available in the keystore. The key you select will be used as a signing key for the assertions. </span>  
  
> Macro (inline-media-image)
6. <span style="color: #000000">Ensure that you choose from the existing Circles of Trust or provide one to be created, so you can include this IdP.</span>
7. <span style="color: #000000">On the </span>*<span style="color: #000000">Create a SAMLv2 Identity Provider on this Server</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Configure</span>**<span style="color: #000000"> on the right upper corner, as follows:</span>  
  
> Macro (inline-media-image)
8. <span style="color: #000000">On the </span>*<span style="color: #000000">Your Identity Provider has been configured</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Finish</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)

## <span style="color: #000000">Configuring Assertions</span>

1. <span style="color: #000000">When you are redirected to the dashboard, click </span>**<span style="color: #000000">Applications</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Federation</span>**<span style="color: #000000"> from the left navigation.</span>
2. <span style="color: #000000">On the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Entity Providers</span>**<span style="color: #000000">.</span>
3. <span style="color: #000000">Check to ensure that the IdP and Circle of Trust were created. Click the newly created IdP in the </span>**<span style="color: #000000">Entity Provider</span>**<span style="color: #000000"> section, and then select the </span>**<span style="color: #000000">Assertion Content</span>**<span style="color: #000000"> tab, as follows:</span>  
> Macro (inline-media-image)
4. <span style="color: #000000">In the </span>**<span style="color: #000000">NameID Format</span>**<span style="color: #000000"> section, complete the following for the </span>**<span style="color: #000000">NameID Value Map</span>**<span style="color: #000000"> section:</span>
  1. **<span style="color: #000000">Current Values</span>**<span style="color: #000000">: Select the following and click </span>**<span style="color: #000000">Remove.</span>**  
**<span style="color: #000000">urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</span>**<span style="color: #000000">=</span>
  2. **<span style="color: #000000">New Value</span>**<span style="color: #000000">: Enter the following value and click </span>**<span style="color: #000000">Add</span>**<span style="color: #000000">.</span>  
**<span style="color: #000000">urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified=mail </span>**
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> and then </span>**<span style="color: #000000">Back</span>**<span style="color: #000000"> to return to the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> Page. </span>
6. <span style="color: #000000">On the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page, select the </span>**<span style="color: #000000">Assertion Processing</span>**<span style="color: #000000"> tab.</span>  
> Macro (inline-media-image)
7. <span style="color: #000000">In the </span>**<span style="color: #000000">Attribute Mapper</span>**<span style="color: #000000"> section, add the following expressions in the </span>**<span style="color: #000000">New Value</span>**<span style="color: #000000"> textbox, and then click </span>**<span style="color: #000000">Add</span>**<span style="color: #000000">. </span>
  - *<span style="color: #000000">email=mail</span>*
  - *<span style="color: #000000">firstName=givenname</span>*
  - *<span style="color: #000000">lastName=sn</span>*
8. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> and then </span>**<span style="color: #000000">Back</span>**<span style="color: #000000"> to return to the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page.</span>

## <span style="color: #000000">Importing IdP Metadata</span>

1. <span style="color: #000000">In the </span>**<span style="color: #000000">Entity Provider</span>**<span style="color: #000000"> section, select the IdP and click </span>**<span style="color: #000000">Import Identity</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
2. <span style="color: #000000">On the</span>*<span style="color: #000000"> Import Entity Provider</span>*<span style="color: #000000"> page, complete the following:</span>
  - **<span style="color: #000000">Realm Name</span>**<span style="color: #000000">: Select the correct realm name from the drop-down list.</span>
  - **<span style="color: #000000">Where does the metadata file reside?</span>**<span style="color: #000000">: Select </span>**<span style="color: #000000">File</span>**<span style="color: #000000">.</span>
  - **<span style="color: #000000">URL where metadata is located</span>**<span style="color: #000000">: Click </span>**<span style="color: #000000">Upload</span>**<span style="color: #000000"> and navigate to the metadata file that you have previously downloaded from the SSO Portal. </span>
3. <span style="color: #000000">Click </span>**<span style="color: #000000">Upload File</span>**<span style="color: #000000">, and then click </span>**<span style="color: #000000">OK</span>**<span style="color: #000000"> after you have uploaded the file. See the following as an example:</span>  
> Macro (inline-media-image)

## <span style="color: #000000">Configuring Service Provider</span>

1. <span style="color: #000000">Select the service provider you just created using the imported IdP metadata, and ensure that the following fields are chosen and associated with your desired realm:</span>
  - **<span style="color: #000000">Authentication Requests Signed</span>**
  - **<span style="color: #000000">Assertions Signed</span>**  
> Macro (inline-media-image)
2. <span style="color: #000000">Scroll down to the </span>**<span style="color: #000000">NameID Format</span>**<span style="color: #000000"> section and select the </span>**<span style="color: #000000">Disable NameID persistence</span>**<span style="color: #000000"> checkbox, as follows:</span>  
> Macro (inline-media-image)
3. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> and then </span>**<span style="color: #000000">Back</span>**<span style="color: #000000"> to return to the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page.</span>

## <span style="color: #000000">Configuring Circle of Trust</span>

1. <span style="color: #000000">On the </span>*<span style="color: #000000">Federatio</span>*<span style="color: #000000">n page, click the name of the Circle of Trust and ensure that both the IdP and the service provider are selected, as follows:</span>  
> Macro (inline-media-image)
2. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">.</span>

# <span style="color: #000000">Configuring LDAP User Attributes</span>

<span style="color: #000000">After you have set up your identity provider, you can configure the LDAP user attributes.</span>

<span style="color: #000000">To configure LDAP user attributes in ForgeRock, complete the following:</span>

1. <span style="color: #000000">On the </span>**<span style="color: #000000">Realm Overview</span>**<span style="color: #000000"> dashboard, select </span>**<span style="color: #000000">Identity Stores</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">OpenDJ</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
2. <span style="color: #000000">On the </span>*<span style="color: #000000">OpenDJ</span>*<span style="color: #000000"> page, click the </span>**<span style="color: #000000">User Configuration</span>**<span style="color: #000000"> tab. </span>
3. <span style="color: #000000">on the </span>*<span style="color: #000000">User Configuration</span>*<span style="color: #000000"> page, check to see if </span>**<span style="color: #000000">isMemberOf</span>**<span style="color: #000000"> is in the </span>**<span style="color: #000000">LDAP User Attributes</span>**<span style="color: #000000"> list. If not, add </span>**<span style="color: #000000">isMemberOf</span>**<span style="color: #000000">. </span>  
> Macro (inline-media-image)
4. <span style="color: #000000">Click </span>**<span style="color: #000000">Save Change</span>*****<span style="color: #000000">s. </span>***
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Applications</span>**<span style="color: #000000"> on the left navigation, and then click the </span>**<span style="color: #000000">Federation</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Entity Providers</span>**<span style="color: #000000">. </span>
6. <span style="color: #000000">Select the IdP and click the </span>**<span style="color: #000000">Assertion Processing</span>**<span style="color: #000000"> tab. </span>
7. <span style="color: #000000">Add </span>**<span style="color: #000000">groups=isMemberOf</span>**<span style="color: #000000"> to the attribute map, as follows:</span>  
> Macro (inline-media-image)
8. <span style="color: #000000">Click </span>***<span style="color: #000000">Save</span>***<span style="color: #000000">.</span>

# <span style="color: #000000">Configuring Users and Groups</span>

<span style="color: #000000">You must set up users and groups in ForgeRock before you can map them to Infoblox Platform user groups.</span>

## <span style="color: #000000">Adding New Users</span>

<span style="color: #000000">To add new users, complete the following:</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Identity Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">Manage Users</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
3. <span style="color: #000000">On the </span>*<span style="color: #000000">User List </span>*<span style="color: #000000">page, click </span>**<span style="color: #000000">+ New User</span>**<span style="color: #000000">.</span>
4. <span style="color: #000000">On the </span>*<span style="color: #000000">New User</span>*<span style="color: #000000"> page, complete all applicable information for the new user, as follows:</span>  
> Macro (inline-media-image)
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">.</span>
6. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> again on the summary page.</span>

## <span style="color: #000000">Adding User Groups</span>

<span style="color: #000000">To add new user groups, complete the following:</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Access Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">On the realm tab, click </span>**<span style="color: #000000">Identities</span>**<span style="color: #000000">, and select the</span>**<span style="color: #000000"> Groups </span>**<span style="color: #000000">tab -></span>**<span style="color: #000000"> Add Group</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
3. <span style="color: #000000">On the </span>*<span style="color: #000000">New Identity Group</span>*<span style="color: #000000"> page, enter the </span>**<span style="color: #000000">Group ID</span>**<span style="color: #000000"> and click </span>**<span style="color: #000000">Create</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)

## <span style="color: #000000">Adding Users to User Groups</span>

<span style="color: #000000">After you have added users and created a user group, you can add users to the user group.</span>

<span style="color: #000000">To add users to the user group, complete the following:</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Access Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">On the realm tab, click </span>**<span style="color: #000000">Identities</span>**<span style="color: #000000">, and select the</span>**<span style="color: #000000"> Groups </span>**<span style="color: #000000">tab.</span>
3. <span style="color: #000000">Choose the user group to which you want to add users.</span>
4. <span style="color: #000000">On the </span>*<span style="color: #000000">User</span>*<span style="color: #000000"> page, select the </span>**<span style="color: #000000">Members</span>**<span style="color: #000000"> tab and add the required users to the group using their usernames, as follows:</span>  
> Macro (inline-media-image)
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Save changes</span>**<span style="color: #000000">.</span>

# <span style="color: #000000">Configuring SAML on Infoblox SSO Portal</span>

<span style="color: #000000">After you have successfully set up the entity provider in ForgeRock, you can configure SAML on the Infoblox SSO Portal to complete the federation.</span>

<span style="color: #000000">To configure SAML on Infoblox SSO Portal, complete the following:</span>

1. <span style="color: #000000">Open a browser window and enter the following URL to retrieve the ForgeRock metadata:</span>
  *<span style="color: #000000">http://<ServerUrl>/saml2/jsp/exportmetadata.jsp?entityid=<</span>**<span style="color: #000000">SPentityID</span>**<span style="color: #000000">>&realm=<realm_name></span>*  
<span style="color: #000000">where</span>
  1. <span style="color: #000000">[</span>*<span style="color: #000000">ServerURL</span>*<span style="color: #000000">] is the full AM/OpenAM server URL. Example: </span><span style="color: #000000">http://host1.example.com:8080/am.</span>
  2. <span style="color: #000000">[</span>*<span style="color: #000000">SPentityID</span>*<span style="color: #000000">] is the name of the SP entity provider you created in the Entity Provider configuration in ForgeRock.</span>
  3. *<span style="color: #000000">Realmname</span>*<span style="color: #000000"> is the name of the realm in which the SP entity provider is configured. If the SP entity is configured at the top level realm (/), you can exclude the </span>*<span style="color: #000000">&realm</span>*<span style="color: #000000"> parameter from the URL.</span>
  <span style="color: #000000">The following is a sample ForgeRock metadata and the values you need to copy for the SAML configuration on the SSO Portal:</span>  
  
> Macro (inline-media-image)
2. <span style="color: #000000">From the ForgeRock metadata, copy the following:</span>
  - **<span style="color: #000000">Single Sign-On URL</span>**<span style="color: #000000">, which is located at SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST".</span>
  - **<span style="color: #000000">Entity ID</span>**<span style="color: #000000">, which is the entityID. </span>
  - **<span style="color: #000000">Signature Certificate </span>**<span style="color: #000000">(minimum digital signature of SHA-256 is required)</span>
3. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
4. <span style="color: #000000">Go to </span>**<span style="color: #000000">Authentication</span>**<span style="color: #000000"> -></span>**<span style="color: #000000"> </span>****<span style="color: #000000">3rd Party IdP</span>**<span style="color: #000000">, and then click </span>**<span style="color: #000000">Configure SAML</span>**<span style="color: #000000">.</span>
5. <span style="color: #000000">Enter the following values that you have copied from the ForgeRock metadata:</span>
  - **<span style="color: #000000">IDP Single Sign-On URL</span>**<span style="color: #000000">:  Paste the Single Sign-On URL here.</span>
  - **<span style="color: #000000">IDP Issuer URI</span>**<span style="color: #000000">: Paste the Entity ID here.</span>
  - **<span style="color: #000000">Signature Certificate</span>**<span style="color: #000000">: Paste only the X.509 Certificate key, which is the value between "BEGIN CERTIFICATE" and "END CERTIFICATE" or between the XML entries such as <ds:x509Certificate> & </ds:x509Certificate >, depending on your data format). The SSO Portal also supports Base64 certificates with the following file extensions: </span>*<span style="color: #000000">.crt</span>*<span style="color: #000000">, </span>*<span style="color: #000000">.pem</span>*<span style="color: #000000">, and </span>*<span style="color: #000000">.ca-bundle</span>*<span style="color: #000000">. Minimum </span><span style="color: #000000">digital signature of SHA-256 is required</span><span style="color: #000000">.</span>
6. <span style="color: #000000">Click </span>**<span style="color: #000000">Save & Close</span>**<span style="color: #000000">.</span>
7. <span style="color: #000000">After you have configured the SAML application, you can complete the following configuration in the SSO Portal:</span>
  1. [*<span style="color: #000000">Mapping User Groups</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463665)
  2. [*<span style="color: #0000FF">Testing 3rd Party IdP Authentication</span>*](https://docs.infoblox.com/display/BloxOneCloud/Testing+3rd+Party+IdP+Authentication)
  3. [*<span style="color: #0000FF">Activating 3rd Party IdP Authentication</span>*](https://docs.infoblox.com/display/BloxOneCloud/Activating+3rd+Party+IdP+Authentication)
  <span style="color: #000000">You can also perform the following after you set up 3rd party IdP authentication:</span>
  - [*<span style="color: #0000FF">Deactivating 3rd Party IdP Authentication</span>*](https://docs.infoblox.com/display/BloxOneCloud/Deactivating+3rd+Party+IdP+Authentication)
  - [*<span style="color: #0000FF">Resetting 3rd Party IdP</span>*](https://docs.infoblox.com/display/BloxOneCloud/Resetting+3rd+Party+IdP)
  - [*<span style="color: #0000FF">Adding a Chiclet for IdP-initiated SSO (OKTA)</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35431099)
  - [*<span style="color: #0000FF">Adding an IdP Application to Microsoft Azure</span>*](https://docs.infoblox.com/display/BloxOneCloud/Adding+an+IdP+Application+to+Microsoft+Azure)

# <span style="color: #000000">Configuring IdP and Service Provider</span>

<span style="color: #000000">Complete the following steps to configure entity provider in ForgeRock.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Instructions in the following sections are based on ForgeRock Access Management 6.5.2.3 Build 4ed586d624 and ForgeRock Identity Management 6.5.0.3 revision: 204a28f.</span>

## <span style="color: #000000">Creating Hosted Identity Provider</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Access Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">On the </span>*<span style="color: #000000">Access Management</span>*<span style="color: #000000"> page, choose to configure an existing realm or create a new realm.</span>
3. <span style="color: #000000">On the </span>**<span style="color: #000000">Realm Overview</span>**<span style="color: #000000"> dashboard, select </span>**<span style="color: #000000">Configure SAMLv2 Provider</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
4. <span style="color: #000000">On the </span>*<span style="color: #000000">Configure SAML 2.0 Provider</span>*<span style="color: #000000"> page, select </span>**<span style="color: #000000">Create Hosted Identity Provider</span>**<span style="color: #000000">, as follows:</span>  
  
> Macro (inline-media-image)
5. <span style="color: #000000">In the </span>**<span style="color: #000000">metadata</span>**<span style="color: #000000"> section, choose the applicable </span>**<span style="color: #000000">Realm</span>**<span style="color: #000000"> and the </span>**<span style="color: #000000">Signing Key</span>**<span style="color: #000000"> from the drop-down menu. The Signing Key menu lists keys that are available in the keystore. The key you select will be used as a signing key for the assertions. </span>  
  
> Macro (inline-media-image)
6. <span style="color: #000000">Ensure that you choose from the existing Circles of Trust or provide one to be created, so you can include this IdP.</span>
7. <span style="color: #000000">On the </span>*<span style="color: #000000">Create a SAMLv2 Identity Provider on this Server</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Configure</span>**<span style="color: #000000"> on the right upper corner, as follows:</span>  
  
> Macro (inline-media-image)
8. <span style="color: #000000">On the </span>*<span style="color: #000000">Your Identity Provider has been configured</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Finish</span>**<span style="color: #000000">, as follows</span>

## <span style="color: #000000">Configuring Assertions</span>

1. <span style="color: #000000">When you are redirected to the dashboard, click </span>**<span style="color: #000000">Applications</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Federation</span>**<span style="color: #000000"> from the left navigation.</span>
2. <span style="color: #000000">On the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Entity Providers</span>**<span style="color: #000000">.</span>
3. <span style="color: #000000">Check to ensure that the IdP and Circle of Trust were created. Click the newly created IdP in the </span>**<span style="color: #000000">Entity Provider</span>**<span style="color: #000000"> section, and then select the </span>**<span style="color: #000000">Assertion Content</span>**<span style="color: #000000"> tab, as follows:</span>  
> Macro (inline-media-image)
4. <span style="color: #000000">In the </span>**<span style="color: #000000">NameID Format</span>**<span style="color: #000000"> section, complete the following for the </span>**<span style="color: #000000">NameID Value Map</span>**<span style="color: #000000"> section:</span>
  1. **<span style="color: #000000">Current Values</span>**<span style="color: #000000">: Select the following and click </span>**<span style="color: #000000">Remove.</span>**  
**<span style="color: #000000">urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</span>**<span style="color: #000000">=</span>
  2. **<span style="color: #000000">New Value</span>**<span style="color: #000000">: Enter the following value and click </span>**<span style="color: #000000">Add</span>**<span style="color: #000000">.</span>  
**<span style="color: #000000">urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified=mail </span>**
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> and then </span>**<span style="color: #000000">Back</span>**<span style="color: #000000"> to return to the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> Page. </span>
6. <span style="color: #000000">On the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page, select the </span>**<span style="color: #000000">Assertion Processing</span>**<span style="color: #000000"> tab.</span>  
> Macro (inline-media-image)
7. <span style="color: #000000">In the </span>**<span style="color: #000000">Attribute Mapper</span>**<span style="color: #000000"> section, add the following expressions in the </span>**<span style="color: #000000">New Value</span>**<span style="color: #000000"> textbox, and then click </span>**<span style="color: #000000">Add</span>**<span style="color: #000000">. </span>
  - *<span style="color: #000000">email=mail</span>*
  - *<span style="color: #000000">firstName=givenname</span>*
  - *<span style="color: #000000">lastName=sn</span>*
8. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> and then </span>**<span style="color: #000000">Back</span>**<span style="color: #000000"> to return to the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page.</span>

## <span style="color: #000000">Importing IdP Metadata</span>

1. <span style="color: #000000">In the </span>**<span style="color: #000000">Entity Provider</span>**<span style="color: #000000"> section, select the IdP and click </span>**<span style="color: #000000">Import Identity</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
2. <span style="color: #000000">On the</span>*<span style="color: #000000"> Import Entity Provider</span>*<span style="color: #000000"> page, complete the following:</span>
  - **<span style="color: #000000">Realm Name</span>**<span style="color: #000000">: Select the correct realm name from the drop-down list.</span>
  - **<span style="color: #000000">Where does the metadata file reside?</span>**<span style="color: #000000">: Select </span>**<span style="color: #000000">File</span>**<span style="color: #000000">.</span>
  - **<span style="color: #000000">URL where metadata is located</span>**<span style="color: #000000">: Click </span>**<span style="color: #000000">Upload</span>**<span style="color: #000000"> and navigate to the metadata file that you have previously downloaded from the SSO Portal. </span>
3. <span style="color: #000000">Click </span>**<span style="color: #000000">Upload File</span>**<span style="color: #000000">, and then click </span>**<span style="color: #000000">OK</span>**<span style="color: #000000"> after you have uploaded the file. See the following as an example:</span>  
  
> Macro (inline-media-image)

## <span style="color: #000000">Configuring Service Provider</span>

1. <span style="color: #000000">Select the service provider you just created using the imported IdP metadata, and ensure that the following fields are chosen and associated with your desired realm:</span>
  - **<span style="color: #000000">Authentication Requests Signed</span>**
  - **<span style="color: #000000">Assertions Signed</span>**  
> Macro (inline-media-image)
2. <span style="color: #000000">Scroll down to the </span>**<span style="color: #000000">NameID Format</span>**<span style="color: #000000"> section and select the </span>**<span style="color: #000000">Disable NameID persistence</span>**<span style="color: #000000"> checkbox, as follows:</span>  
> Macro (inline-media-image)
3. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> and then </span>**<span style="color: #000000">Back</span>**<span style="color: #000000"> to return to the </span>*<span style="color: #000000">Federation</span>*<span style="color: #000000"> page.</span>

## <span style="color: #000000">Configuring Circle of Trust</span>

1. <span style="color: #000000">On the </span>*<span style="color: #000000">Federatio</span>*<span style="color: #000000">n page, click the name of the Circle of Trust and ensure that both the IdP and the service provider are selected, as follows:</span>  
> Macro (inline-media-image)
2. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">.</span>

# <span style="color: #000000">Configuring LDAP User Attributes</span>

<span style="color: #000000">After you have set up your identity provider, you can configure the LDAP user attributes.</span>

<span style="color: #000000">To configure LDAP user attributes in ForgeRock, complete the following:</span>

1. <span style="color: #000000">On the </span>**<span style="color: #000000">Realm Overview</span>**<span style="color: #000000"> dashboard, select </span>**<span style="color: #000000">Identity Stores</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">OpenDJ</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
2. <span style="color: #000000">On the </span>*<span style="color: #000000">OpenDJ</span>*<span style="color: #000000"> page, click the </span>**<span style="color: #000000">User Configuration</span>**<span style="color: #000000"> tab. </span>
3. <span style="color: #000000">on the </span>*<span style="color: #000000">User Configuration</span>*<span style="color: #000000"> page, check to see if </span>**<span style="color: #000000">isMemberOf</span>**<span style="color: #000000"> is in the </span>**<span style="color: #000000">LDAP User Attributes</span>**<span style="color: #000000"> list. If not, add </span>**<span style="color: #000000">isMemberOf</span>**<span style="color: #000000">. </span>  
> Macro (inline-media-image)
4. <span style="color: #000000">Click </span>**<span style="color: #000000">Save Change</span>*****<span style="color: #000000">s. </span>***
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Applications</span>**<span style="color: #000000"> on the left navigation, and then click the </span>**<span style="color: #000000">Federation</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Entity Providers</span>**<span style="color: #000000">. </span>
6. <span style="color: #000000">Select the IdP and click the </span>**<span style="color: #000000">Assertion Processing</span>**<span style="color: #000000"> tab. </span>
7. <span style="color: #000000">Add </span>**<span style="color: #000000">groups=isMemberOf</span>**<span style="color: #000000"> to the attribute map, as follows:</span>  
> Macro (inline-media-image)
8. <span style="color: #000000">Click </span>***<span style="color: #000000">Save</span>***<span style="color: #000000">.</span>

# <span style="color: #000000">Configuring Users and Groups</span>

<span style="color: #000000">You must set up users and groups in ForgeRock before you can map them to Infoblox Platform user groups.</span>

## <span style="color: #000000">Adding New Users</span>

<span style="color: #000000">To add new users, complete the following:</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Identity Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">Manage Users</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
3. <span style="color: #000000">On the </span>*<span style="color: #000000">User List </span>*<span style="color: #000000">page, click </span>**<span style="color: #000000">+ New User</span>**<span style="color: #000000">.</span>
4. <span style="color: #000000">On the </span>*<span style="color: #000000">New User</span>*<span style="color: #000000"> page, complete all applicable information for the new user, as follows:</span>  
> Macro (inline-media-image)
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">.</span>
6. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000"> again on the summary page.</span>

## <span style="color: #000000">Adding User Groups</span>

<span style="color: #000000">To add new user groups, complete the following:</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Access Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">On the realm tab, click </span>**<span style="color: #000000">Identities</span>**<span style="color: #000000">, and select the</span>**<span style="color: #000000"> Groups </span>**<span style="color: #000000">tab -></span>**<span style="color: #000000"> Add Group</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)
3. <span style="color: #000000">On the </span>*<span style="color: #000000">New Identity Group</span>*<span style="color: #000000"> page, enter the </span>**<span style="color: #000000">Group ID</span>**<span style="color: #000000"> and click </span>**<span style="color: #000000">Create</span>**<span style="color: #000000">, as follows:</span>  
> Macro (inline-media-image)

## <span style="color: #000000">Adding Users to User Groups</span>

<span style="color: #000000">After you have added users and created a user group, you can add users to the user group.</span>

<span style="color: #000000">To add users to the user group, complete the following:</span>

1. <span style="color: #000000">Log in to the ForgeRock </span>**<span style="color: #000000">Access Management</span>**<span style="color: #000000"> console.</span>
2. <span style="color: #000000">On the realm tab, click </span>**<span style="color: #000000">Identities</span>**<span style="color: #000000">, and select the</span>**<span style="color: #000000"> Groups </span>**<span style="color: #000000">tab.</span>
3. <span style="color: #000000">Choose the user group to which you want to add users.</span>
4. <span style="color: #000000">On the </span>*<span style="color: #000000">User</span>*<span style="color: #000000"> page, select the </span>**<span style="color: #000000">Members</span>**<span style="color: #000000"> tab and add the required users to the group using their usernames, as follows:</span>  
> Macro (inline-media-image)
5. <span style="color: #000000">Click </span>**<span style="color: #000000">Save changes</span>**<span style="color: #000000">.</span>

# <span style="color: #000000">Configuring SAML on Infoblox SSO Portal</span>

<span style="color: #000000">After you have successfully set up the entity provider in ForgeRock, you can configure SAML on the Infoblox SSO Portal to complete the federation.</span>

<span style="color: #000000">To configure SAML on Infoblox SSO Portal, complete the following:</span>

1. <span style="color: #000000">Open a browser window and enter the following URL to retrieve the ForgeRock metadata:</span>
  *<span style="color: #000000">http://<ServerUrl>/saml2/jsp/exportmetadata.jsp?entityid=<</span>**<span style="color: #000000">SPentityID</span>**<span style="color: #000000">>&realm=<realm_name></span>*  
<span style="color: #000000">where</span>
  1. <span style="color: #000000">[</span>*<span style="color: #000000">ServerURL</span>*<span style="color: #000000">] is the full AM/OpenAM server URL. Example: </span><span style="color: #000000">http://host1.example.com:8080/am.</span>
  2. <span style="color: #000000">[</span>*<span style="color: #000000">SPentityID</span>*<span style="color: #000000">] is the name of the SP entity provider you created in the Entity Provider configuration in ForgeRock.</span>
  3. *<span style="color: #000000">Realmname</span>*<span style="color: #000000"> is the name of the realm in which the SP entity provider is configured. If the SP entity is configured at the top level realm (/), you can exclude the </span>*<span style="color: #000000">&realm</span>*<span style="color: #000000"> parameter from the URL.</span>
  <span style="color: #000000">The following is a sample ForgeRock metadata and the values you need to copy for the SAML configuration on the SSO Portal:</span>  
  
> Macro (inline-media-image)
2. <span style="color: #000000">From the ForgeRock metadata, copy the following:</span>
  - **<span style="color: #000000">Single Sign-On URL</span>**<span style="color: #000000">, which is located at SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST".</span>
  - **<span style="color: #000000">Entity ID</span>**<span style="color: #000000">, which is the entityID. </span>
  - **<span style="color: #000000">Signature Certificate</span>**
3. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
4. <span style="color: #000000">Go to </span>**<span style="color: #000000">Authentication</span>**<span style="color: #000000"> -></span>**<span style="color: #000000"> </span>****<span style="color: #000000">3rd Party IdP</span>**<span style="color: #000000">, and then click </span>**<span style="color: #000000">Configure SAML</span>**<span style="color: #000000">.</span>
5. <span style="color: #000000">Enter the following values that you have copied from the ForgeRock metadata:</span>
  - **<span style="color: #000000">IDP Single Sign-On URL</span>**<span style="color: #000000">:  Paste the Single Sign-On URL here.</span>
  - **<span style="color: #000000">IDP Issuer URI</span>**<span style="color: #000000">: Paste the Entity ID here.</span>
  - **<span style="color: #000000">Signature Certificate</span>**<span style="color: #000000">: Paste only the X.509 Certificate key, which is the value between "BEGIN CERTIFICATE" and "END CERTIFICATE" or between the XML entries such as <ds:x509Certificate> & </ds:x509Certificate >, depending on your data format). The SSO Portal also supports Base64 certificates with the following file extensions: </span>*<span style="color: #000000">.crt</span>*<span style="color: #000000">, </span>*<span style="color: #000000">.pem</span>*<span style="color: #000000">, and </span>*<span style="color: #000000">.ca-bundle</span>*<span style="color: #000000">.</span>
6. <span style="color: #000000">Click </span>**<span style="color: #000000">Save & Close</span>**<span style="color: #000000">.</span>
7. <span style="color: #000000">After you have configured the SAML application, you can complete the following configuration in the SSO Portal:</span>
  1. [*<span style="color: #000000">Mapping User Groups</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463665)
  2. [*<span style="color: #0000FF">Testing 3rd Party IdP Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367251)
  3. [*<span style="color: #0000FF">Activating 3rd Party IdP Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463635)
  <span style="color: #000000">You can also perform the following after you set up 3rd party IdP authentication:</span>
  - [*<span style="color: #0000FF">Deactivating 3rd Party IdP Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005)
  - [*<span style="color: #0000FF">Resetting 3rd Party IdP</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367439)
  - [*<span style="color: #0000FF">Adding a Chiclet for IdP-initiated SSO (OKTA)</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35369713/Adding+a+Chiclet+for+IdP-initiated+SSO+OKTA)
  - [*<span style="color: #0000FF">Adding an IdP Application to Microsoft Azure</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367488)