Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
...
Div | ||
---|---|---|
| ||
...
...
/ Identity Provider Connections / Current: Configuring |
...
Box as an Identity Provider |
...
Configuring LinkedIn as an Identity Provider
...
The EmpowerID SSO framework allows you to configure LinkedIn as an identity provider for the EmpowerID Web application. EmpowerID integrates with LinkedIn using the OAuth protocol to allow your users to log in to EmpowerID using their LinkedIn accounts.
Info | |||||||||
---|---|---|---|---|---|---|---|---|---|
As a prerequisite to creating an SSO Connection for LinkedIn as an Identity Provider, you must have a LinkedIn account and register the EmpowerID web application for your organization under "My Applications" in the LinkedIn Developer Network. This creates a set of values known by theAPI Keyand theAPI Secret(these values are generated by LinkedIn), as well as theOAuth 1.0 Accept Redirect URLs(this value is entered by you to tell LinkedIn where to post the assertion of a user's identity to the EmpowerID Assertion Consumer Service). For specific directions on registering EmpowerID as an application in LinkedIn, see the information provided by LinkedIn athttps://linkedin.com/secure/developer. Once the IDP Connection has been set up for LinkedIn, you can create a link similar to the one below to allow users to login to EmpowerID using LinkedIn.
|
...
This topic describes how to configure an IDP connection for LinkedIn and is divided into the following activities:
- Adding the Consumer Key and Consumer Secret to the LinkedIn OAuth Connection
- Adding MFA Points to the LinkedIn OAuth Connection
- Adding a Login tile for LinkedIn
- Testing the LinkedIn Connection
...
...
To add the API Key and API Secret and to the LinkedIn OAuth Connection
- From the Navigation Sidebar of the EmpowerID Web interface,
...
- expand Admin > SSO
...
- Connections and
...
- click OAuth.
- From the OAuth
...
- page, click
...
- the OAuth Service
...
- Provider tab and then search
...
- for LinkedIn.
- From
...
- the OAuth Service
...
- Provider grid, click
...
- the LinkedIn link.
...
Image Added- In the External OAuth Provider Details page that appears, click
...
- the Edit button for the specific LinkedIn connection you want to edit. By default, EmpowerID includes one connection. However, you can add as many connections for LinkedIn as your organization needs.
...
Image Added- In the OAuth Connection pane that appears, type
...
- the Client
...
- ID LinkIn generated for your application in
...
- the Consumer
...
- Key field and
...
- the Client
...
- Secret in
...
- the Consumer
...
- Secret field.
...
Image Added- Prepend the value of
...
- the Callback
...
- Url with the FQDN of your EmpowerID Web server, using
...
- the https scheme. For example, the FQDN of the EmpowerID Web server in our environment is "sso.empowersso.com" so the full Callback Url for our site is "https://sso.empowersso.com/
...
- webidpforms/oauth/v2".
...
- Click Save to close the OAuth Connection pane.
- Optionally, add any desired MFA points to the LinkedIn application by following the below steps.
...
...
To add MFA points to the LinkedIn application
- From the External OAuth Providers page for LinkedIn, click the Provider Edit link at the top of the page.
...
Image Added- In the MFA Point Value field, type the number of MFA points you want to give to users logging in with LinkedIn.
...
Image Added- Click Save.
Next, add a login tile for LinkedIn to the desired IdP Domains. This allows your users to authenticate to EmpowerID with their LinkedIn credentials. If you have not set up an IdP Domain for your environment, you can do so by following the directions in the below drop-down.
Rw ui expands macro | |||||
---|---|---|---|---|---|
|
...
|
...
|
...
|
...
|
...
...
To add a login tile for LinkedIn
- From the Navigation Sidebar,
...
- expand Admin > Applications and Directories > SSO Connections and
...
- click SSO Components.
- In the IdP Domain Details page that appears, click the External OAuth Providers tab and check the box beside LinkedIn.
Image Added Click Save.
...
Warning To give users the ability to log in using their EmpowerID credentials, be sure to select EmpowerID from the SAML Identity Providers tab of the IdP Domain Details page.
Image Added
Now that the IDP Connection is configured, you can test it by following the below procedure.
To test the LinkedIn IdP Connection
- From the Navigation Sidebar,
...
- expand IT Shop and
...
- click Workflows.
- From the Workflows page, recycle the EmpowerID App Pools by clicking Recycle EmpowerID App Pools.
Image Added - Log out of the EmpowerID Web interface and navigate your browser to the domain name you configured for the LinkedIn IdP connection.
- Click the Login using LinkedIn button.
Image Added In the Authorize page for LinkedIn that appears, enter your LinkedIn credentials (if you are not already signed in) and then click Allow
...
access to allow EmpowerID to retrieve the necessary information to link the LinkedIn account to your EmpowerID identity (Person object).
Image AddedTip The Authorize page only appears the first time you log in to EmpowerID with the third-party account. Subsequent logins simply redirect your browser from the login page for the application to the EmpowerID web application.
Back in the EmpowerID Web interface, click Yes to indicate that you have an EmpowerID login.
Image AddedInfo Users without EmpowerID Persons can request EmpowerID accounts by clicking No. This initiates the Create User Account workflow, which displays a form in the browser to allow the user to fill in the appropriate information. If a user submits the request, EmpowerID routes that request to those individuals in your environment with the ability to approve or deny the request and returns the user to the EmpowerID web login.
- Type your EmpowerID Login or Email in the form and click Submit. The EmpowerID Person must have a valid email address as EmpowerID sends a one-time password to that address.
Image Added - Check your email for the one-time password.
- Back in the EmpowerID Web interface, type the one-time password into the Password field of the One-Time Password Validation form and click Submit.
Image Added
Info | ||
---|---|---|
Upon successful submission of your one-time password, EmpowerID logs the user in and joins the LinkedIn account to their EmpowerID Person account.
|
...
Div |
---|
...
|
...
Administrative Procedures:
- Creating IdP Domains
- Configure AD SF as an Identity Provider
- Configure Azure as an Identity Provider
- Configure Box as an Identity Provider
- Set up the Remote Windows Identity Provider Application
- Configure Facebook as an Identity Provider
- Configure Github as an Identity Provider
- Configure Google as an Identity Provider
- Configure Paypal as an Identity Provider
- Configure Smart Card as an Identity Provider
- Configure Twitter as an Identity Provider
- Configure Windows Auth as an Identity Provider
- Configure Yahoo as an Identity Provider
- Configure Yammer as an Identity Provider
- Creating IP Address Ranges
- Setting MFA Points Granted by SSO Connections
| |||||||
|
Div | ||
---|---|---|
| ||
|