KOP Integrations - Duo SSO - Rafay Product Documentation

Duo SSO

Follow the steps documented below to integrate access to your Web Console with Duo for Single Sign On (SSO).

Important

Only users with "Organization Admin" privileges can configure SSO in the Web Console.


Step 1: Create IdP

Important

Within an org, the domain of an IdP cannot be used for another IdP. A domain existing in an org can be used in multiple orgs (for one IdP in each org)

Important

Encrypting SAML assertions is optional because privacy is already provided at the transport layer using HTTPS. Encrypted assertions provide an additional layer of security on top ensuring that only the SP (Org) can decrypt the SAML assertion.


Step 2: View SP Details

The IdP configuration wizard will display critical information that you need to copy/paste into your Duo SSO Console. Provide the following information to your Duo administrator.


Step 3: Create App in Duo


Step 4: Configure SAML Settings For App in Duo

In the "Generic Service Provider - Single Sign-On" page, go to "Service Provider" section and:


Step 5: Configure Group Attribute to Send

The "Group" configuration step is critical because it will ensure that Duo will send the groups/roles the user belongs to as part of the SSO process. The controller uses the group information to transparently map users to the correct group/role.

Option 1 Users and groups synced from Active Directory (AD) for your Duo Authentication Source. Follow Step 5.1 below to configuration the Role Attributes

Option 2 Your Duo Authentication Source is from SAML Identity Provider. Follow Step 5.2 to map IdP Attribute for Group Attribute in SAML Response to send to the controller.


Step 5.1: Map Duo Group Synced from AD to Role Attributes


Groups Configuration In Web Console


Step 5.2: Map IdP Attribute to Group Attribute to Send

In the illustrative example below, we are using the attribute name "UserRoles" from IdP source and send to the controller in the SAML Response attribute name


*Groups Configuration In __Web Console


Step 6: Specify IdP Metadata