Configuring Ping Identity PingOne as an SAML Identity Provider is done by configuring a Ping Identity PingOne
Authentication server on an SMA appliance.
On the SMA appliance, go to the System Configuration > Authentication Servers page.
In the Authentication servers section, click the + (New) icon. The Add Authentication Server page
Select SAML 2.0 Identity Provider.
Click Continue.... The Edit Authentication Server page displays.
Most of the values for the fields on this page can be obtained from the fields on the PingOne application
The steps that follow explain how to configure the fields in the Configure Authentication Server .
In the Name field, enter PingOne_IDP.
- In the Appliance ID field, enter the entityId from the PingOne application page. For example:
- In the Server ID field, enter the value of the entityID of the EntityDescriptor tag from the downloaded
XML file, for example,
In the Authentication service URL field, enter the Initiate Single Sign-On (SSO) URL from the PingOne application page. For example,
- In the Logout service URL field, enter the value of the Logout Service URL from the Location attribute of SingleLogoutService tag from the downloaded XML file. For example,
From the Trust the following certificate drop-down menu, select the certificate you want. This should be
the Certificate downloaded from the PingOne application page.
You must first download and install the certificate you want before it can appear in this
drop-down menu. See Downloading a Certificate for instructions on how to do this.
(Optional) Select the Sign AuthnRequest message using this certificate if you want it, then select the certificate.