Cisco Duo
This guide will show you how to integrate GoodAccess with Cisco Duo SSO.
Last updated
This guide will show you how to integrate GoodAccess with Cisco Duo SSO.
Last updated
This feature is available in the Premium plan and higher.
Remember to grant your users access permissions to GoodAccess. Users without them won't be able to log in.
Enabled Duo Single Sign-On
Configured Authentication Source
Log in to the GoodAccess Control Panel, and go to Settings > SSO & Identity.
Click + Add provider, enter the Provider name, choose your Identity Provider, and click Continue.
Log in to the Duo Admin Panel, and go to Applications > Protect an Application.
Search for Generic SAML Service Provider, and click Protect.
Click Download certificate, and open the file in a text editor (e.g. Notepad).
Copy the details to GoodAccess - (3) Identity Provider links.
Sign in URL - Single Sign-On URL
Entity ID - Entity ID
X509 signing certificate - Copy the certificate from the text editor
Copy the details from GoodAccess - (2) GoodAccess links.
Metadata Discovery - None (manual input)
Entity ID - Entity ID
ACS URL - Assertion Consumer Service URL
Service Provider Login URL - Login URL
Default Relay State - Relay State
NameID format - urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
NameID attribute - <Email Address>
Signature algorithm - SHA256
Signing options - Sign response
IdP Attribute | SAML Response Attribute |
---|---|
<Email Address> | |
<Username> | name |
Scroll down to the bottom of the page and click Save.
Return to GoodAccess, skip the next step, and click Submit.
You have now successfully set up your Cisco Duo SSO with GoodAccess.