Understanding Setting Up PeopleSoft-Only Single Signon

The following table list steps for setting up single signon among PeopleSoft systems. Note that additional configuration may be required based on your business and security requirements.

The following table list steps for setting up single signon among PeopleSoft systems. Note that additional configuration may be required based on your business and security requirements.

Step Page/Navigation Description

1. Configure the default local node definition.

1a. Configure Node Definitions page.

Nodes - Node Definitions page.

PeopleTools, and then Portal, and then Portal Node Definitions. Select the default local node and click the Nodes Definition tab.

  • Define the Authentication Option.

    The valid options for single signon are Password or Certificate.

    You must define the same value on the remote PeopleSoft nodes participating in single signon.

  • Generate and define a check token ID.

    Click the CheckTokenID button to create a system-generated ID. The system automatically populates the value in the Check TokenID field on the Node Definition page. As an alternative, create a custom ID, or create a custom ID of up to 256 characters.

    Make a note of the ID before saving the page. You must provide a copy of the ID to your single signon participants, who must in turn define that value on their databases on the Nodes – Node Definitions page for the remote node definition that represents your database.

1b. Configure Portal page.

Nodes - Portal page.

PeopleTools, and then Portal, and then Portal Node Definitions. Select the default local node and click the Portal tab.

  • Define the PeopleTools release.

    In the Tools Release field enter the PeopleTools release running on the local database. For example, 8.56.00

  • Define the Content URI.

    In the Content URI Text field enter the uniform resource identifier (URI) of the pscontent servlet (psc) for the local default node.

  • Define the Portal URI.

    In the Portal URI Text field enter the URI of the portal servlet (psp) for the local default node

2. Configure remote PeopleSoft node for each node participating in single signon.

2a.Configure Node Definitions page.

Nodes - Node Definitions page.

PeopleTools, and then Portal, and then Portal Node Definitions. Select the remote PeopleSoft node and click the Nodes Definition tab.

  • Define the Authentication Option.

    The valid options for single signon are Password or Certificate.

    You must define the same value as defined on the local default node of the single signon participant.

  • Define the check token ID.

    Enter the check token ID as provided by the single signon participant.

2b. Configure Portal page.

Nodes – Portal page.

PeopleTools, and then Portal, and then Portal Node Definitions. Select the remote PeopleSoft node and click the Portal tab.

  • Define the PeopleTools release.

    In the Tools Release field enter the PeopleTools release running on the single signon partner database. For example, 8.56.00

  • Define the Content URI.

    In the Content URI Text field enter the URI of the pscontent servlet (psc) for the single signon participant’s default local node.

  • Define the Portal URI.

    In the Portal URI Text field enter the URI of the portal servlet (psp) for the single signon participant’s default local node.

3. Add nodes/databases participating in single signon to the Single Signon page.

Single Signon page.

PeopleTools, and then Security, and then Security Objects, and then PeopleSoft Single Signon

Add nodes participating in single signon to the Trust Authentication Tokens Issued by These Nodes grid. Click the Lookup button to search for and select nodes to participate in single signon.

The default local node appears in the grid by default.

4. Add sites participating in single signon to the Authorized Sites page.

Authorized Sites page.

PeopleTools, and then Web Profile, and then Authorized Sites.

You can add sites two ways:

  • Allow Domain Compare.

    In the CheckToken section of the page, select the Allow Domain Compare box.

    Selecting this option allows access for all sites within a defined authentication domain, including their sub-domains.

    For example, an authentication domain of example.com will include myserver1.example.com, myserver2.example.com and so on.

  • Allowlist sites to participate in single signon.

    In the Authorized Sites grid, add a row for each site and select the CheckToken box to enable single signon for the site.