---
title: "EasySSO SAML with G suite"
canonical: "https://www.techtime-initiative.com/space/EasySSO/5308864/EasySSO%20SAML%20with%20G%20suite"
format: markdown
---
Step-by-Step Instructions to configure EasySSO SAML with G Suite as an Identity Provider

> Macro (toc)

> ⚠️ **Unsupported configurations**
> ⚠️ 
> ⚠️ G Suite does not support Single Logout, so the following EasySSO configurations are not supported:
> ⚠️ 
> ⚠️ - Logout Binding (Set the Logout Binding Type to disabled)
> ⚠️ - Sign SP Logout request
> ⚠️ - Sign SP Logout response
> ⚠️ - Verify Logout Request Signature
> ⚠️ - Verify Logout Response Signature

## Add a custom app on the Google side

Sign in into [G Suite admin portal](https://admin.google.com/), navigate to Apps > Web and mobile apps.

![image-20240829-035129.png](media://6119f166-326c-49fa-90df-3cb725313b61)

Click “Add app“ and select “Add custom SAML app” from the dropdown.

![image-20240829-035216.png](media://5efa1780-4f40-4f1f-b0e7-d6f97ce59fc6)

Give your app a name (e.g. "EasySSO Jira") and continue. Optionally you can add a description and icon.


![image-20240829-035233.png](media://320a1b09-7d9d-44a2-878d-98c546e83a35)

We recommend downloading the metadata as the setup will involve fewer steps.

![image-20240829-035247.png](media://4ea34f4c-d930-4003-b2aa-e83f705ccdac)

## Configure the EasySSO side

The following steps are the bare minimum for setting up EasySSO with G Suite. For more complex setups look at [EasySSO with SAML - Configuration](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4948647) after finishing this guide. 

### Load certificate from G Suite app metadata

On EasySSO inside the SAML section, go to the "Certificates" tab.

1. Next to "Load Metadata" select upload, and upload the metadata downloaded from your G Suite app
2. generate an SP Signing Certificate
3. press the save button at the bottom.

![image-20240829-035405.png](media://5ab8d19e-dd7e-4757-9485-2796100a2b25)

On the "General" tab, you should see the "POST Binding URL" and the "Entity ID" have already been filled with the details from your G Suite app.

![image-20240829-035520.png](media://fbb2df03-6f84-4ff4-bea1-54884f9b8d80)

### Enable signed requests

Check the "Sign SP Login Request" box.

![image-20240829-035633.png](media://908e2366-6795-46ee-8e52-3584c6706e54)

## Finish Configuring the Google Side

### Add SP details

On the EasySSO "General" tab, Look under the “Entity ID“ Text Field.

- "Your endpoint URL" corresponds with the "ACS URL" on your G Suite app.
- "Your entityID" corresponds with "Entity ID".

Both should be copied to your G Suite app under "Service provider details". Both should be in the form:

```
https://<YOUR ATLASSIAN APPLICATION HOST>:<YOUR ATLASSIAN APPLICATION PORT>/<YOUR ATLASSIAN APPLICATION CONTEXT>/plugins/servlet/easysso/saml
```

E.g. if you are running Jira on custom port 2990 and context /jira:

```
https://testjira.mydomain.com:2990/jira/plugins/servlet/easysso/samlor
```

if you running on the default HTTPS port 443 and no context:

```
https://testjira.mydomain.com/plugins/servlet/easysso/saml
```

Other settings:

- Leave "Signed Response" unchecked.
- Leave "Name ID" as "Basic Information", "Primary Email".
- Leave "Name ID" Format as "UNSPECIFIED".

Click `Continue` when done

![Where entityId Is-1000.png](media://948a52f5-b432-4c53-8d28-d64a9aa41e16)


![image-20240829-040109.png](media://cb4f320e-733c-43db-9480-b7b1f54490a4)

### Add mappings

From the "Google directory attributes" drop-down list select whatever you use for the user-id in your Atlassian App (Jira, Confluence, etc). Typically it will be "Primary Email". Enter "urn:oid:0.9.2342.19200300.100.1.1" in the corresponding "App attributes" text box.

Add 3 further mappings in the same way and fill them with the following:

1. "Basic Information / Primary Email" → "urn:oid:0.9.2342.19200300.100.1.3"
2. "Basic Information / First Name" → "urn:oid:2.5.4.42"
3. "Basic Information / Last Name" → "urn:oid:2.5.4.4"

Click `Finish`.

![image-20240829-041009.png](media://4bd24ba3-b743-4577-a7d1-91ad1dfbd5ee)

## User access

Click `User access` to go to a menu that will let you enable the app for all users or select groups of users.

![image-20240829-041101.png](media://9b5d2aa1-a2a0-467d-bfa1-99ab5dcc5386)