Adding and Managing a SAML Identity Provider Profile

You can associate a SAML Identity Provider (IdP) with Captive Portal settings, providing secure authentication for Wi-Fi users and administrators while ensuring seamless user access.

Complete the following steps to create a SAML Identity Provider profile:
  1. Add the SAML Identity Provider service to your tenant account. From the navigation bar, select Network Control > Service Catalog.
  2. Find the Identity Provider tile and click Add.
    The Add Identity Provider page is displayed.
  3. Select SAML IdP from the Identity Provider Type drop-down list, and then click Next.
    The Add SAML Identity Provider page is displayed.
  4. Enter a Profile Name.
  5. In the Identity Provider (IdP) Metadata field, perform one of the following actions:
    • Enter the metadata URL provided by the identity provider.
    • Paste the metadata XML provided by the identity provider.
    • Click Import via XML.

      The Import via XML sidebar is displayed. Drag and drop the XML file into the upload area, or click Browse to select an XML file. You can replace the file by clicking the Change File button, which allows you to browse and upload a new file. The file format must be XML, and the size must not exceed 512 KB.

    Click Clear to remove the imported metadata and enter new metadata information.

    Note: Importing overwrites any existing information.
  6. (Optional) Toggle the Enable SAML Request Signature switch on to digitally sign and validate SAML authentication requests sent from RUCKUS One to an external IdP.
    • Select a certificate from the resulting Select Signing Certificate drop-down list.
      Note: Only certificates with the Digital Signature key usage option selected appear in the Select Signing Certificate drop-down list.

      If a signing certificate does not exist, click Generate a signing certificate, complete the fields in the Generate Certificate sidebar, and then click Add. You can then select the newly created certificate from the Signing Certificate drop-down list. Refer to Managing Server and Client Certificates for more details.

  7. (Optional) Toggle the Enable SAML Response Encryption switch on to encrypt SAML responses received from the Identity Provider (IdP).
    • Select a certificate from the resulting Select Encryption Certificate drop-down list.
      Note: Only certificates with the Key Encipherment key usage option selected appear in the Select Encryption Certificate drop-down list.

      If an encryption certificate does not exist, click Generate an encryption certificate, complete the fields in the Generate Certificate sidebar, and then click Add. You can then select the newly created certificate from the Select Encryption Certificate drop-down list. Refer to Managing Server and Client Certificates for more details.

  8. (Optional) Enter values in the following fields in the Identity Attributes & Claims Mapping section:
    • Identity Display Name
    • Identity Email
    • Identity Phone

    The claim names are available from the IdP console.

  9. (Optional) Click Add custom field.
    The Identity Attribute Mapping section is displayed.
    • Select an Attribute Type from the drop-down list. The following attribute types are available: First Name, Last Name, User Principal Name, Title, Groups, Roles, Department, Organization, and Address.
    • Enter a value in the Claim Name field.

    To add additional mappings, click Add custom field again.

  10. Click Add.
    The SAML IdP profile is added and displayed in the SAML tab.
    Note: A maximum of 64 SAML IdP profiles can be created per tenant.

    The page displays the following information:

    • Name: Displays the name of the SAML Identity Provider profile.
    • IdP Metadata: Displays the IdP metadata provided by the identity provider. Click the icon to view the IdP metadata.
    • SAML Request Signature: Displays whether the SAML request signature option is on or off. If enabled, click the hyperlink to view more details.
    • SAML Response Encryption: Displays whether the SAML response encryption is on or off. If enabled, click the hyperlink to view more details.
    • Networks: Displays the number of networks associated with a SAML IdP profile. Hover your cursor over the network number to view more details.
    You can use the Search option to display only the table entries matching the specified name; enter a minimum of two characters. Additionally, you can filter the list by selecting an option from the Networks drop-down menu.
  11. Select the checkbox alongside the profile name to display the management options:
    • Edit: Allows you to edit the SAML IdP profile.
    • Download SAML Metadata: Allows you to download the SAML metadata file and provide it to the external Identity Provider (IdP) when configuring SAML authentication.

      The downloaded metadata contains the service provider entity ID, signing certificate, and assertion consumer service URL.

    • Delete: Allows you to delete the SAML IdP profile.
      Note: You cannot delete a profile that is associated with a network.