How to configure SAML SSO in Ronspot
This guide explains how to connect your SAML 2.0 Identity Provider (IdP) to Ronspot, allowing users to sign in to Ronspot using your organisation’s Single Sign-On (SSO) service.
Before you begin
Before configuring SAML in Ronspot:
- Confirm that your Identity Provider supports SAML 2.0 SSO/federation for third-party applications.
- Make sure you have administrator access to your Identity Provider's configuration.
- Have your Identity Provider's SAML configuration details and X.509 signing certificate available.
Once confirmed, you can proceed with the SAML configuration below.
1. Get your SAML details from your Identity Provider
Log in to your Identity Provider's administration portal and locate the SAML configuration details.You will need the following information:
- Entity ID / Issuer: The unique identifier for your Identity Provider.
- Single Sign-On (SSO) URL: The URL that Ronspot will use to redirect users to your Identity Provider for authentication.
- Single Logout (SLO) URL: The URL used when a user signs out. This is optional.
- X.509 signing certificate: The certificate Ronspot will use to verify SAML responses from your Identity Provider.
Note: The names of these fields may vary slightly depending on your Identity Provider.
2. Open 'Login methods' in Ronspot
- Log in to the Ronspot admin portal.
- From the sidebar, go to
Users > Login methods - Locate the domain you want to configure.
Note: If your domain is not listed, click Add domain and add it first.
3. Open the SAML configuration
-
Find your domain and click the icon in the SAML column.
-
This will open the SAML configuration for that domain.
4: Enter your Identity Provider details
-
Set the SAML status to Active, then enter the information obtained from your Identity Provider:
-
Entity ID URL: Enter your Identity Provider's Entity ID or Issuer.
-
Sign-in URI: Enter your Identity Provider's SAML Single Sign-On URL.
- Sign-out URI: Enter your Identity Provider's Single Logout URL, if applicable.
-
X509 Certificate: Paste the contents of your Identity Provider's X.509 signing certificate.
-
When pasting the certificate, include the complete certificate content, including the `BEGIN CERTIFICATE` and `END CERTIFICATE` lines if they are present in the certificate file.
-
-
-
Click
Save.
Step 5: Get the Ronspot URLs for your Identity Provider
-
Once the SAML configuration has been created, Ronspot provides the URLs that need to be added to your Identity Provider.
-
Scroll down to The following URLs must be setup within your Identity Provider configuration. You will see:
-
Single Sign-On URL
-
Recipient URL
-
Destination URI
-
Audience URI
-
-
Copy these values. They are unique to your Ronspot SAML configuration and should be entered into the corresponding fields in your Identity Provider.
Note: Depending on your Identity Provider, the Ronspot Single Sign-On URL may also be referred to as the ACS URL, Assertion Consumer Service URL, Reply URL, or Consumer URL.
6. Configure Ronspot in your Identity Provider
-
Return to your Identity Provider's administration portal and create or update the SAML application for Ronspot.
-
Enter the four values provided by Ronspot:
-
Single Sign-On URL: Use the Single Sign-On URL provided by Ronspot.
-
Recipient URL: Use the Recipient URL provided by Ronspot.
-
Destination URI: Use the Destination URI provided by Ronspot.
-
Audience URI: Use the Audience URI provided by Ronspot.
-
-
Save the configuration in your Identity Provider.
Note: The exact field names may differ depending on your Identity Provider. For example, Audience URI may be called SP Entity ID, Entity ID, or Audience.
7. Test SAML login
-
Once both sides have been configured, test the integration with a user from the configured domain on app.ronspotflexwork.com.
-
The user should be redirected to your Identity Provider to authenticate and, after successful authentication, returned to Ronspot and signed in.
-
We recommend testing with a small number of users before rolling out SAML SSO to your wider organisation.
Troubleshooting
If SAML authentication does not work, check the following:
- The Entity ID, Sign-in URI, and other URLs have been copied exactly, without additional spaces or characters.
- The correct X.509 signing certificate has been added to Ronspot.
- The Ronspot Audience URI and other Ronspot URLs have been correctly configured in your Identity Provider.
- The user's email domain matches the domain configured for SAML in Ronspot.
- The SAML application is active and the user has permission to access it in your Identity Provider.
If you continue to experience issues, please contact Ronspot Support and provide details of the error you are experiencing.