Configuring SSO authentication

Introduction to SSO authentication in ConSol CM

SSO is an authentication method which can be used to verify the identity of users in the Web Client and CM/Track. It is based on OpenID Connect and can be set up using Microsoft Active Directory Federation Services or Azure AD.

Concepts, terms and definitions

Concept

Other terms

Definition

SSO

 

Abbreviation of single sign-on. Authentication mechanism which allows users to access several applications after logging in once

OpenID Connect

 

Authentication mechanism based on the OpenID protocol, which allows clients to obtain information about authenticated user sessions

Basic tasks

Setting up SSO for the Web Client

The SSO configuration on the ConSol CM side is done using system properties from the module cmas-core-security. Set the following system properties in the Web Admin Suite, see System properties:

Setting up SSO for CM/Track

The SSO configuration on the ConSol CM side is done using system properties from the module cmas-core-security.

If there are several instances of CM/Track, for example, one for internal customers and one for external customers, you can provide separate configurations for each instance. The mapping of the CM/Track instance to a configuration is done using the following property:

The following system properties are used as a default configuration. You can copy them and replace “default” in the property name by the name of the instance to create a separate configuration for the instance. The default values are used whenever no configuration-specific property is set.

Set the following system properties in the Web Admin Suite, see System properties:

The logins for the contacts are saved in contact fields with the user name setting in the Web Client.