This article explains how to configure SafeNet Trusted Access as the Single Sign-On (SSO) provider for users to authenticate to the Cato Client.
SSO relies on an encrypted token from Cato and your IdP to validate that the user is authenticated and allowed to connect to the network. For more details, see SSO Authentication for Users with Cato.
Configuring SafeNet Trusted Access as your SSO provider simplifies authentication and enhances the user experience. With SSO configured for your account, users can log in to the Client by authenticating with their SSO credentials and do not need a different set of dedicated credentials. For more information, see the SafeNet Trusted Access documentation.
Follow these steps to configure SafeNet Trusted Access as an SSO provider:
-
Add Cato as an application in your STA Access Management console
-
Enter the details of your SafeNet Trusted Access Host in the Cato Management Application
-
Configure the token validity
In your STA Access Management console, add Cato as an application.
To add Cato as an application:
-
In the STA Access Management console, on the Applications page, click Add Application.
-
Select Generic Template.
-
Choose OCID as the Integration Protocol.
-
(Optional) Change the display name of the application.
-
Click Next.
-
On the Configure tab, in the STA Setup section, enter this URL as the Service Login URL:
https://sso.via.catonetworks.com/login
-
Enter these URLs in as Valid Redirect URLs:
https://sso.via.catonetworks.com/auth_results
https://sso.ias.catonetworks.com/auth_results
https://sso.proxy.catonetworks.com/auth_results
-
On the Assign tab, choose the users that will use SafeNet SSO.
-
Click Save.
In the Cato Management Application, enter the unique details for your SafeNet Trusted Access account.
To configure SafeNet Trusted Access as your SSO provider:
-
In the Cato Management Application, from the Navigation menu, click Access > Single Sign On.
-
Click New.
-
From the Identity Provider drop-down menu, select SafeNet.
-
Enter a Name.
-
Select your Zone and enter your Client ID, Tenant ID, and Client Secret.
The Client ID and Client Secret information is available from the Configure tab in your STA Access Management console.
-
If you are configuring one Single Sign-On provider, enable the Default toggle. If you are configuring multiple Single Sign-On providers, see Configuring Multiple Identity Providers.
-
Click Apply.
You can configure how long the Cato authentication token is valid for. The Token validity settings define in Days or Hours the amount of time that users remain authenticated. Users that are logged in must re-authenticate when the duration you define in Days or Hours (since they last logged in) has been reached.
The Always Prompt options means that users must always authenticate to the Client.
0 comments
Article is closed for comments.