Version Affected: All
Overview
This article explains how to configure SAML single sign-on (SSO) between SecureAuth Identity Provider (IdP) and Invicti (formerly Netsparker). Invicti requires the SAML assertion to be signed, but not the SAML message itself.
Configure SAML SSO with Invicti
- On the SecureAuth side, create the application and set the Connection Type to SP Initiated by Redirect.
- Set the User ID Profile Field to the profile field that maps to the email address you want to use in Invicti (for example, Email1).
- In the Invicti admin console, copy the SAML 2.0 Service URL value and enter it in the Assertion Consumer Service (ACS) field of the application you are creating in SecureAuth.
- On the SecureAuth side, set an IdP Issuer value, and copy that same value into the IdP Identifier field in the Invicti console.
- On the SecureAuth side, set the Audience value to match the Identifier shown in the Invicti console.
- On the SecureAuth side, enable Sign SAML Assertion.
- In the Invicti console, set the SAML 2.0 Endpoint to match your SecureAuth URL and realm number — for example, https://idp.example.com/SecureAuth123/.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.