Salesforce Integration
Steps in Skillmine Authenticator
- Create the client with basic information like client_name, client_type, scopes, redirect_url and logout url. 
- After client creation go to the advance settings of this client and enabled the SAML and save the settings. 
- Now the IDP metadata is generated, click the view SAML button.It will redirect into the metadata. Save this metadata with xml extension. 
- Map this client in any one of the flow settings. 
Steps in Salesforce
- Log in to Salesforce. 
- Navigate to Setup -> SETTINGS -> Identity ->Single-Sign-On Settings. 
- Enable SAML by clicking the Edit button, then checking the box for SAML Enabled and clicking the Save button. 
- Click the New button to create a new SAML Single Sign-On Setting. 
- Enter the following settings: (If we create the config via metadata it will most of the information automatically) 

Other settings
- Request Signing Certificate: Generate self-signed certificate 
- Request Signature Method: RSA-SHA256 
- Assertion Decryption Certificate: Leave default 
- SAML Identity Type: - Assertion contains the User's Salesforce username: Authenticator will send by default the unique id (email) of the user as NameIdentifier (the default) and Salesforce will match that with the Username field. 
 
- SAML Identity Location: Identity is in the NameIdentifier element of the Subject statement 
- Server Provided Initiated Request Binding: HTTP POST 
- Custom Error URL: Leave default 
- Single Logout Enabled: Enable this to set the Identity Provider Single Logout URL. 
- API Name: Leave default 
- User Provisioning Enabled: If checked, users will be just-in-time provisioned the first time they log in. 
- After saving the configuration, download the metadata from the below screen. 

If you have issues while logging in, you can use the SAML Assertion Validator tool. You will find it on Salesforce Single Sign-On settings page.
Last updated