PingFederate
Follow these steps to configure SSO
Single Sign-On (SSO) - A session/user authentication process that permits a user to enter one name and password in order to access multiple applications. authentication with PingFederate.
Prerequisite
-
Permissions to your company's DNS server if you select login-based domain verification as the integration type.
-
In the Check Point Portal, go to
> Identity & Access and click the plus icon. -
Enter a name for the Integration Title and select PingFederate.
-
To continue, click Next.
In this step of the IdP Integration Wizard, you can configure SSO authentication for Check Point Portal administrators and for end users of Check Point services.
-
Select Enable Administrators to log in to the portal using this IdP.
-
Select one of these options:
-
Login based on domain verification - Check Point Portal Administrators can log in to this Check Point Portal account with SSO from the Identity Provider
A system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network. Acronym: IdP or IDP.. Administrators log in through the Check Point Portal login page. -
Login with a unique URL - Check Point Portal Administrators can log in to multiple Check Point Portal accounts with SSO from the Identity Provider. Administrators log in using the URL that appears at the bottom of the Login with a unique URL section. Copy this URL and keep it in a safe place.
-
-
In the Service(s) Integration section, select one of these options:
-
No Services - End users of Check Point Portal services cannot authenticate with SSO from the Identity Provider. This is the default configuration.
-
All Services - End users can log in with SSO from the Identity Provider to all Check Point services that support SSO.
-
Specific Service(s) - From the list of services, select service(s) to allow end users to log in with SSO from the Identity Provider. Available services:
-
Connect
-
Quantum Gateways
-
-
-
Click Next (or, if you are editing a configuration, Apply) to complete the Integration Type configuration.
|
|
Note - If you selected Login with a unique URL for Integration Type, the Verify Domain step is not necessary. |
-
Connect to your DNS server.
-
Copy the DNS Value from the Check Point Portal IdP Integration wizard > Verify Domain step.
-
On your DNS server, enter the Value as a TXT record.
-
In the Check Point Portal > Domain(s) section, enter a public DNS domain server name and click the plus icon.
Check Point makes a DNS query to verify your domain's configuration.
-
Optional - add more DNS domain servers.
-
Click Next.
Note - Wait until the DNS record propagates and becomes resolvable.
-
In the PingFederate portal, create a SAML
Security Assertion Markup Language. An XML-based, open-standard data format for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. application for the Check Point Portal. For more information, see PingFederate documentation. -
Copy the Entity ID from the Check Point Portal and paste it in the relevant field in the SAML application in the PingFederate portal.
-
Optional - Select Enable IDP initiated flow to allow users of the PingFederate SAML application to access the Check Point Portal directly from the PingFederate portal.
-
Copy the Reply URL from the Check Point Portal and paste it in the relevant field in the SAML application you created in the PingFederate portal.
-
In the SAML application you created in the PingFederate portal, add the attributes and claims shown in the Check Point Portal > Mandatory User Attributes & Claims section.
-
Click Next.
|
|
Important - Before you can test the connectivity between Ping Identity and Check Point Portal, you must complete all of the IdP integration steps in Check Point Portal. |
In this step, you upload the federation metadata XML file.
-
On the Check Point Portal, Identity Provider Wizard > Configure Metadata page, upload the Federation Metadata XML that you downloaded from the PingFederate Portal.
Note - Check Point uses the service URL and the name of your Certificate to identify your users behind the site.
-
Click Next. Check Point verifies the metadata of your Identity Provider.
Review the details of the SSO configuration and click Submit.
|
|
Important - Create a user group with the applicable roles and assign it to the related IdP group name or ID. This depends on the applicable identity provider before you log out. For more information, see User Groups. |