External Identity Provider | Getting Started
Customers subscribing to Cirrus External Identity Provider will have an instance provisioned during customer on-boarding.
Customers will often subscribe to one or more additional Cirrus Identity modules to support desired implementations. In addition to provisioning the External Identity Provider, some initial setup for Cirrus Gateway, Cirrus Identity Provider Proxy, Cirrus Account Linking, and/or Cirrus Invitation will also take place.
The following are the steps needed to get started using Cirrus External Identity Provider:
Customers should take a moment and think about their External IdP deployment. Cirrus Identity can offer generally accepted practices, customer stories, and professional services to help. Reviewing the questions covered by the Cirrus External Identity Provider | Planning Steps is a good first step:
Who is the target audience?
What is/are the Service Providers that will be accessed?
How will password reset be handled?
How will this identity provider be branded?
Depending on the customer, Cirrus will provision other modules based on the customer’s subscription (or trial/PoC agreement). Modules such as Cirrus Gateway, Cirrus Identity Provider Proxy, and Cirrus Invitation each have associated setup. See the “Getting Started” for each module as appropriate:
If there is a service provider (SP) that will use the External IdP, but the metadata for the SP is not published to federation metadata (for example InCommon or eduGAIN), the metadata needs to be sent to Cirrus Identity Support (email@example.com) for configuration. Additionally, if there is an SP with special attribute requirements, regardless where the metadata is published, that also needs to be communicated to Cirrus Identity Support.
A member of the organization needs to have access to the Cirrus Console and to be granted the “Organization Administrator” (org admin) role for your organization. (See Cirrus Console Getting Started)
Before the External IdP can be completely setup, an “Organization Administrator” must complete the setup of the customer organization’s user interface.
Cirrus Identity will provide a URL so that customers can download the metadata for the External IdP. This will need to be added to any service providers (other than Cirrus Identity Provider Proxies) that need to leverage the External IdP.
Once these steps are complete, you are ready to add the External IdP to the configurations of other Cirrus Modules.