Configuring Service Provider Metadata in PingFederate IdP
This procedure describes the steps required for configuring service provider metadata in PingFederate.
This topic provides a basic set of guidelines required for service provider metadata on the PingFederate server. The images and attributes may change with PingFederate software updates.
Before you Begin
Go through the SAML SSO feature description to understand how SAMLSecurity Assertion Markup Language. SAML is an XML-based framework for communicating user authentication, entitlement, and attribute information. SAML enables single sign-on by allowing users to authenticate at an identity provider and then access service providers without additional authentication. framework works in the context of Aruba Central.
Steps to Configure Service Provider Metadata in PingFederate
To configure service provider metadata in PingFederate, complete the following steps:

- Log in to the PingFederate administration console.
- Click
- In the
- Click the tab.
- Verify the Entity ID and select the logging mode.
- Click SSOSingle Sign-On. SSO is an access-control property that allows the users to log in once to access multiple related, but independent applications or systems to which they have privileges. The process authenticates the user across all allowed resources during their session, eliminating additional login prompts. Settings. . Configure the Browser

- On the
- Click .
- Select the following SAML profiles:
- Select IDP-INITITATED SSO
- Select SP-INITITATED SSO
- Click . The tab opens.
- Click
- Click
- Click . The page opens.
- Add the SAML attributes in the SAML assertion. The IdP will send these attributes in the SAML Assertion.
- Click
- Click
- Complete the following configuration steps:
- Click
- Click
- To add a data source, click
- Click .
. The page opens. - Click
- On the URLsUniform Resource Locator. URL is a global address used for locating web resources on the Internet., and SAML bindings.
- Click
- Verify the
and complete the following steps: - Verify the
- Click . The tab opens.
- Select
- Click . The tab opens.
- Select
- Click . Review the protocol setting.
- Click .

- On the SP Connections page in the PingFederate administrative console, click
- Click .
- Click .
- Select the certificate to use for digital signature in SAML messages.

To review the configuration, click the
tab.
For information on how to configure a SAML authorization profile, see Configuring SAML Authorization Profiles in Aruba Central.