This topic describes how to enable SSO in Cisco Crosswork Planning so you can access the integrated service provider applications using a single set of credentials, streamlining authentication and simplifying navigation between service providers.
Single sign-on (SSO) is an authentication method that lets users log in once and access multiple independent systems without reentering credentials. Cisco Crosswork Planning acts as an Identity Provider (IdP) and supports SSO integration for service provider applications. You can enable SSO for users authenticated via TACACS+, LDAP, and RADIUS. When SSO is configured, users benefit from seamless access and improved security management.
-
When Cisco Crosswork Planning’s CAS pod is restarting or not running, the login page is not available.
-
The SSO URL from the Identity Provider (IdP) is https://<IP>:30603/crosswork/sso/idp/profile/SAML2/Redirect/SSO, where <IP> represents the Cisco Crosswork Planning's IP address or hostname.
Before you begin
-
Check the Enable source IP for auditing check box on the page.
-
Ensure you have the latest service provider metadata to integrate with Cisco Crosswork Planning SSO.
-
Confirm that network connectivity exists between Cisco Crosswork Planning (IdP) and each service provider application.
-
Verify the CAS pod is running and stable.
Procedure
|
1. |
From the main menu, choose .
The Identity Provider page opens. On this page, you can add service providers, edit their settings, or delete them.
|
|
2. |
To add a new service provider:
-
Click .
-
On the Service Provider page, enter the values in these fields:
-
Name: Enter the name of the service provider entity.
Note
If you provide a URL, the Service name entry in the Identity Provider page becomes a hyperlink.
-
Evaluation order: Enter a unique number indicating the order in which the service definition should be considered.
-
Metadata: Click the field or click Browse to navigate to the metadata XML document that describes a SAML client deployment. You can also enter the service provider URL here for cross-launch.
-
Click Add to finish adding the service provider.
|
|
3. |
Click Save all changes. When prompted, confirm by clicking Save changes.
After you save the settings and log in to the integrated service provider application for the first time, the application redirects to the Cisco Crosswork server. After providing the Crosswork credentials, the service provider application logs in automatically. For all the subsequent application logins, you do not have to enter any authentication details.
|
|
4. |
To edit a service provider:
-
Select the service provider and click .
-
Update the Evaluation order or Metadata as required.
-
Click Update to apply the changes.
|
|
5. |
To delete a service provider:
-
Select the check box next to the service provider and click .
-
Click Delete to confirm.
|
Single sign-on is enabled for selected service provider applications. Users can authenticate once via Cisco Crosswork Planning and seamlessly access associated applications without reentering authentication factors.
What to do next
-
If Cisco Crosswork Planning is reinstalled or migrated, update the Identity Provider (IdP) metadata in all service provider applications to avoid authentication errors due to metadata mismatch.
-
For first-time users, ensure password change is completed before attempting to log in with a different username. To reset an incomplete session, an administrator must terminate it.