Single Sign-On with OneLogin Using SAML 2.0

This article explains how to configure SAML 2.0 authentication integration between OneLogin and Questetra.

In this configuration, OneLogin acts as the SAML Identity Provider (IdP), while Questetra BPM Suite acts as the Service Provider (SP).

For an overview of SAML SSO in Questetra BPM Suite, refer to:

M310: Enable Login Function using External Authentication Service (SAML)

1. [Questetra BPM Suite] Check the SP Information

First, check the SP information in Questetra. These values will be used when configuring OneLogin.

Navigate to System Settings → SSO (SAML), then open the Single Sign-On (SAML) settings page and select Enable Single Sign-On. At this stage, you only need to view the values, so there is no need to save the settings.

Record the following two values:

  • Entity ID
  • ACS URL

After noting these values, proceed to the OneLogin configuration.

2. [OneLogin] Add an Application

Log in to the OneLogin Administration console.

Navigate to [Applications] → [Applications], then click Add App in the upper-right corner.

Search for SAML Custom Connector (Advanced) and select it from the search results.

Enter a name of your choice in Display Name (for example, Questetra BPM Suite), then click Save.

3. [OneLogin] Configure the Configuration Tab

Open the application’s Configuration tab and configure the following settings:

  • RelayState ― Leave blank
  • Audience (EntityID) ― Copy the Entity ID from Questetra’s SP Information
  • Recipient ― Copy the ACS URL from Questetra’s SP Information
  • ACS (Consumer) URL Validator ― .* (a regular expression that allows any URL)
  • ACS (Consumer) URL ― Copy the ACS URL from Questetra’s SP Information
  • Single Logout URL ― (Optional) Copy the SLO URL from Questetra’s SP Information

We recommend leaving SAML initiator set to Service Provider and SAML signature element set to Both.

When you have finished configuring these settings, click Save.

4. [OneLogin] Verify the Parameters Tab

Open the Parameters tab and verify that NameID value is set to Email.

Questetra identifies users by their email address, so each user’s email address in OneLogin must match the corresponding user’s email address in Questetra.

5. [OneLogin] Retrieve the SSO Information

Next, open the SSO tab and record the following information, which will be required for the Questetra configuration:

  • Issuer URL ― Configure this as the Entity ID in Questetra.
  • SAML 2.0 Endpoint (HTTP) ― Configure this as the Login Page URL in Questetra.
  • SLO Endpoint (HTTP) ― Configure this as the Logout Page URL in Questetra (optional).
  • X.509 Certificate ― Click View Details to display the certificate.

When pasting the certificate into Questetra, ensure that the alphanumeric string between —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—– is entered as a single continuous line with no line breaks.

6. [OneLogin] Assign Users

Assign the users who should be able to use the OneLogin application.

You can either add users from the application’s Users tab, or open individual user pages via Users → Users and add the application under Applications. Only assigned users will be able to sign in to Questetra BPM Suite using Single Sign-On.

7. [Questetra BPM Suite] Configure the Identity Provider

Finally, configure the Identity Provider settings in Questetra.

Navigate to System Settings → SSO (SAML), then select Enable Single Sign-On. Enter the OneLogin information obtained in Step 5 as follows:

  • Entity ID ― OneLogin Issuer URL
  • Login Page URL ― OneLogin SAML 2.0 Endpoint (HTTP)
  • Logout Page URL ― OneLogin SLO Endpoint (HTTP) (optional)
  • Certificate ― Contents of the OneLogin X.509 Certificate (without line breaks)

When you have finished entering the information, click Save.

This completes the Single Sign-On configuration. Users can now sign in to Questetra BPM Suite using Single Sign-On from the login page. If the user is already signed in to OneLogin, they will be taken directly to the requested page within Questetra BPM Suite. If they are not yet signed in to OneLogin, they will first be prompted to log in to OneLogin before being redirected to Questetra BPM Suite.

Troubleshooting

If the configuration does not work as expected, review your settings. The following items are the most common causes of configuration errors:

  • Verify that Audience (EntityID) in OneLogin matches the Entity ID in Questetra.
  • Verify that ACS (Consumer) URL in OneLogin matches the ACS URL in Questetra.
  • Verify that the certificate has been pasted without any line breaks.
  • Verify that the user’s email address in OneLogin matches the user’s email address in Questetra.

If all settings appear to be correct but authentication still fails, check the login failure records under Administration → System Log. The log contains detailed error information.

  • SAML Error: Invalidated Session ― This indicates a temporary session issue. Close and reopen your browser, then try again.
  • SAML Error: AuthnStatement/@AuthnInstant is invalid ― Too much time has elapsed since the user authenticated with the IdP. Sign in to the IdP again, or increase the Authentication lifetime setting in Questetra.
  • No SAML Error is recorded ― Questetra could not find a user whose email address matches the one sent by the IdP. Review Step 4.

If a different error message is recorded, review the configuration checklist above once more. If the issue persists, contact Questetra Support and include the relevant error message from the system log.

Discover more from Questetra Support

Subscribe now to keep reading and get access to the full archive.

Continue reading