Configuring the SAML Inbound Setup

The SAML Inbound Setup page creates an inbound web service in the producer site that maps the one PeopleSoft user ID to one SAML assertion subject and links the subject with the sender's digital certificate (public key). The SAML administrator sets up a web service for each external user who accesses the PeopleSoft system and who is using the SAML security option. This information should be configured by the SAML administrator—someone who understands the external requirements and how these requirements map to the component permissions that are necessary for the user to accomplish the business task.

Access the Security Assertion Markup Language [SAML] Inbound Setup page (PeopleTools, and then Security, and then SAML Administration Setup, and then Inbound SAML Setup).

This example illustrates the fields and controls on the Security Assertion MarkUp Language [SAML] Inbound Setup page. You can find definitions for the fields and controls later on this page.

Security Assertion MarkUp Language [SAML] Inbound Setup page
Field or Control Description

Active Flag

Select Active or Inactive.

Certificate Alias

Enter the sender's public key, which you imported in the previous step (Importing Digital Certificates).

Note: The key must be base-64 encoded.

Issuer

Enter the domain name of the issuing entity.

SubjectName

Enter a user ID or email address.

QualifierName

Enter the domain name of the issuing entity.

Mapping PeopleSoft UserID

Enter the user ID to map to the SubjectName. This field sets the PeopleSoft internal permissions for the external user and prevents cross-site vulnerability.

Note: This user ID does not have to be the user ID of the sender, but must be a valid PeopleSoft user in the PSOPRDEFN table.

Note: This field is internal to the PeopleSoft application and is hidden from all consumer sites and third-party systems.