---
title: "EasySSO SAML with PingOne"
canonical: "https://www.techtime-initiative.com/space/EasySSO/5865476/EasySSO%20SAML%20with%20PingOne"
format: markdown
---
Step-by-Step Instructions to configure EasySSO SAML with PingOne as an Identity Provider

## Step 1: Create an EasySSO SAML application in PingOne

Sign in to the [PingOne Admin portal](https://admin.pingone.com/) and navigate to the "Applications" tab.

![image-20240829-225108.png](media://35028d8b-1858-43f4-ab5a-7e4dbf8de902)

Click "Add Application" > "New SAML Application."

![image-20240829-225128.png](media://0ee1d2b3-14e9-4bed-9130-7bcb09168eb3)

Give your application a name, like "EasySSO Jira," a description, and a category. Optionally you can also add an icon for the app. When you're done, click `Continue to Next Step`.

![image-20240829-225219.png](media://5310123c-e24a-4b5b-93c9-7f13d598a6b0)

## Step 2: Save SAML metadata from PingOne

Click on `Download` to download the metadata from PingOne. We will use this later for the EasySSO configuration.

![image-20240829-225256.png](media://2f026561-934b-4fa2-a297-56e487edf37a)


## Step 3: Configure the EasySSO Side

On EasySSO, check the "Enable SAML" box, go to the "Certificates" tab, upload the metadata, and click `Save`.

![image-20240829-225442.png](media://d5dc898e-c0a9-436f-9ddd-c98903044f5e)

Go to the "General" tab. The required fields should now be filled out with the metadata you just uploaded. See [EasySSO SAML Configuration](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4948647) for configuration options, but note that PingOne does not support signed log in so checking the "Sign SP Login request" box will have no effect.

Once you're done, make sure to click `Save` at the bottom of the page.

## Step 4: Upload EasySSO Metadata to PingOne

Save the EasySSO metadata to a file. (Click on the metadata URL, right click below the text, and select the save option).

![image-20240829-230043.png](media://5d25beed-db9a-44b3-9629-0fafe01d3877)

Upload that metadata to the PingOne application you are creating by clicking on "Select File."

![image-20240829-230517.png](media://5c1f13ae-9755-489f-86ff-e9f21c602552)

Click the `Continue to Next Step` button.

![image-20240829-230532.png](media://51d3d81d-34c1-4bb2-84a4-4bc7db5c2b5b)

## Step 5: Mapping attributes

You should now be on the SSO Attribute Mapping screen. Click on `Add new attribute` to add a new attribute. You'll need to add 4 attributes in total and fill them in with the following:

1. urn:oid:0.9.2342.19200300.100.1.3 → Email (Work)
2. urn:oid:2.5.4.42 → First Name
3. urn:oid:0.9.2342.19200300.100.1.1 → SAML_SUBJECT
4. urn:oid:2.5.4.4 → Last Name
5. urn:oid:0.9.2342.19200300.100.1.1 → SAML_SUBJECT

Note that the image below has some of the attribute ids cut off. Make sure to select check all the boxes in the "Required" column.

![image-20240829-231001.png](media://5fb71801-b003-42dd-b976-58319bc04c10)

![image-20240829-231016.png](media://4bc4340b-554e-41d5-9653-1ff778770920)

 Click `Continue to Next Step`.

## Step 6: Final steps

You should find yourself on “Group Access”. The defaults are fine here, so you can click `Continue to Next Step` again. Once you’re happy with your configuration, click `Finish`.

![image-20240829-231303.png](media://325bd05b-ffac-493e-93a3-8f2c92ac58e5)

Finally, for users to successfully log in, they must also have permission to access the application. Depending on your user and user directory configuration, this can be either via: default groups, groups synced from G Suite or manually assigned groups.

You should be set up and ready to log in!

# Encrypted Assertions (Optional)

## EasySSO Side

1. Follow the details given on [EasySSO with SAML - Configuration](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/4948647)
2. Download the certificate from EasySSO
3. Check the Encrypt Assertions checkbox on EasySSO
4. Save the settings

## PingOne Configuration

1. Open your SAML Administration page
2. Open the SAML Client configuration
3. Check the encrypt assertions box

![image-20240829-231621.png](media://d739934d-d1f8-482e-8871-5904fb78b2ac)

![image-20240829-231630.png](media://33432709-0d96-40cd-99d5-208eda48a7b9)