SeaLights support SAML 2 SSO integration and the configuration of the Single Sign-On connection requires steps on both the Customer’s IDP and SeaLights sides.
In order to set up the SSO on Sealights side, you’re requested to Contact Sealights Support
The following items walk you through the necessary steps to achieve the SSO integration:
Set up a SAML 2.0 application on your IDP which will be filled with:
The Assertion Consumer Service URL
The Audience URI
A certificate SeaLights will provide
For each user accessing Sealights dashboard, five attributes need to be passed to SeaLights as part of the SAML response:
E-mail address, First Name, Last Name
Role mapped to one of the values
user
,user-admin
,user-devops
Groups: List of groups the user belongs to for assigning apps that user has access to in Sealights
Once this is set up, provide Sealights with one of the options below:
The
metadata.xml
(preferred)The Issuer URI, the SSO URL, the certificate
We will then test that everything is working properly using a dedicated test user and modify the configuration/mapping according to the results of the tests
At this point, we will be ready to assign all your users to work through SSO connection.