Ping Identityの設定
Ping IdentityとのKeeperオンプレミスSSOコネクト連携設定
Ping Identity
Ping Identityポータルにログインします。

Ping Identityのメニューから、 [Applications] を選択します。

次に、 [Add Application] を選択し、 [New SAML Application] を選択します。

Application Detailsページで、以下のデータを追加します。
Application Name: Keeper Password Manager Application Detail: Password Manager and Digital Vault Category: Compliance (またはその他) Graphic: Keeperの画像をアップロード http://s3.amazonaws.com/keeper-email-images/common/keeper256x256.png
続いて、 [Continue to Next Step] を選択します。

以下の手順で、Ping IdentityからSAMLメタデータをダウンロードします。 [SAML Metadata] の隣の [Download] リンクを選択します。

saml2-metadata-idp.xmlファイルがブラウザにダウンロードされます。このファイルをKeeper SSOコネクトサーバーにコピーし、ファイルを以下の設定画面にドラッグアンドドロップして、Keeper SSOコネクトインターフェースにアップロードします。 [保存] を選択します。

Keeper SSOコネクトサーバーに関する残りの手順は、KeeperSsoMetadata.xmlファイルをダウンロードして、Pingアプリケーションの設定にアップロードすることです。 Keeper SSOコネクトの [メタデータをエクスポート] を選択します。

Ping Identityアプリケーションの設定に戻って、 [Select File] ボタンを選択し、KeeperSsoMetadata.xmlファイルを選択します。

[Continue to Next Step] を選択します。

以下の手順で、属性をマッピングします。 [Add new attribute] ボタンを選択します。

属性1では、Application Attribute列にFirstと入力し、Identity Bridge Attribute or Literal Value列でFirst Nameを選択して、Requiredをチェックします。 [Add new attribute] ボタンを選択します。
属性2では、Application Attribute列にLastと入力し、Identity Bridge Attribute or Literal Value列でLast Nameを選択して、Requiredをチェックします。 [Add new attribute] ボタンを選択します。
属性3では、Application Attribute列にEmailと入力し、Identity Bridge Attribute or Literal Value列でEmailを選択して、Requiredをチェックします。 Application Attributes: First、Last、Emailは大文字で始まる必要があります。

[Save & Publish] ボタンを選択します。 設定内容を確認してから、 [Finish] ボタンを選択します。

Keeperアプリケーションが追加されて、有効になっているはずです。

Ping Identity設定の [Application Configuration] セクションで、 [Signing] セクションの [Sign Response] が選択され、署名アルゴリズムに [RSA_SHA256] が設定されていることを確認してください。
これでKeeper SSOコネクトの設定は完了です。
最終更新

