Set Up Fusion Applications Identity Domain as the Identity Provider in Customer Cloud Service Identity Domain
Your system administrator completes this task.
-
Log in to your Customer Cloud Service identity domain in your Oracle Cloud Infrastructure account. You can get this link from your welcome email. If you have questions about which tenancy and domain to log in to, contact your Oracle Support team.
-
In the navigation pane, select Security, and then select Identity providers.
-
Click the Add IdP dropdown button and select Add SAML IdP.
-
On the Add SAML identity provider screen, complete these fields, and then click Next:
-
Name
-
Description (optional)
-
Icon (optional)
-
-
Choose Import Metadata and upload the metadata file from the previous task.
-
In the Configure IdP section, select the Import identity provider metadata button, and then select the file you downloaded in the previous task.
-
Click Next.
-
Under Map attributes, complete the following fields as described:
-
In the Identity provider user attribute area, select Name ID.
-
In the Identity domain user attribute field, select Username.
-
In the Requested NameID format field, select Unspecified.
-
-
Click the Create IdP button.
-
In the Export screen, click the Download button next to Service provider signing certificate, and save the file.
-
Click Next and do not click anything else before completing the next steps. You will return to this screen later in the process.
-
In a new browser window, log in to your Fusion application identity domain in the Oracle Cloud Infrastructure Console.
-
In the navigation pane, click Applications.
-
In the Applications screen, click the hyperlink for the Customer Cloud Service application (as service provider) you created previously.
-
Under the SSO configuration section, click the Edit SSO Configuration button.
-
On the Edit SSO configuration screen, scroll down to the Signing Certificate field and upload the signing certificate you downloaded in the previous task.
-
Click Save changes.
-
Click the Users link in the navigation panel under Resources.
-
In the Users section of the screen, click the Assign users button.
-
Select the users you want to assign, and then click the Assign button.
-
Scroll to the top of the screen and verify that the application is active. If it is not, click the Activate button.
-
Return to the browser window with your Customer Cloud Service identity domain.
-
On the Test IdP screen, click the Test login button. You will receive a message indicating whether your test is successful. If there is an error, contact My Oracle Support for assistance. If it is successful, click Next.
-
On the Activate IdP screen, click Activate.
-
Click Finish. You will see a list of identity providers.
-
In the navigation pane, select IdP policies.
-
Click the hyperlink for the default identity provider policy.
-
In the Identity provider rules section, click the action menu (3 dots) on the record, and select Edit IdP rule.
-
On the Edit identity provider rule screen, in the Assign identity providers field, click inside the field and select the provider you just created. It will appear in the field next to Username-Password.
-
Click the Save changes button.
Later, you will test your SSO and verify that it is working as expected. Once you are satisfied with your test, you will return to this screen and remove Username-Password from the Assign identity providers field. This removes the ability to log in with your local username and password.
Parent topic: Configure Single Sign On