You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/blog/configuring-sso-for-hpe-greenlake-central-private-cloud-enterprise-and-hpe-greenlake-glcp-using-okta.md
Enterprises looking to use HPE GreenLake for Private Cloud Enterprise can benefit from the use of SSO, as it has been integrated onto the HPE GreenLake edge-to-cloud platform, which supports single sign-on.
18
+
<style>
19
+
li {
20
+
font-size: 27px;
21
+
line-height: 33px;
22
+
max-width: none;
23
+
}
24
+
</style>
25
+
26
+
27
+
Enterprises looking to use HPE GreenLake for Private Cloud Enterprise can benefit from the use of SSO, as it has been integrated onto the HPE GreenLake edge-to-cloud platform (also known as HPE GreenLake platform), which supports single sign-on.
20
28
21
29
In this blog post, I will walk you through the process of configuring Okta Active Directory (AD) to authenticate users into the HPE GreenLake for Private Cloud Enterprise application on the HPE GreenLake platform using SAML Identity Provider (IdP) for single sign-on.
22
30
@@ -31,7 +39,7 @@ Please review the [HPE GreenLake](https://support.hpe.com/hpesc/public/docDispl
31
39
* Step 1: Create an Okta SAML application
32
40
* Step 2: Configure Sign On settings
33
41
* Step 3: Export the SAML 2.0 IdP metadata
34
-
* Step 4: Configure the SAML connection in the HPE GreenLake edge-to-cloud platform
42
+
* Step 4: Configure the SAML connection in the HPE GreenLake platform
35
43
36
44
**Step 1: Create an Okta SAML application**
37
45
@@ -41,7 +49,7 @@ Please review the [HPE GreenLake](https://support.hpe.com/hpesc/public/docDispl
41
49
42
50

43
51
44
-
Provide a name for the SAML application which gets connected to the HPE GreenLake edge-to-cloud platform
52
+
Provide a name for the SAML application which gets connected to the HPE GreenLake platform:
45
53
46
54

47
55
@@ -61,17 +69,17 @@ Provide a name for the SAML application which gets connected to the HPE GreenLak
61
69
62
70
**NameID = user.email**
63
71
64
-
**gl_first_name = user.FirstName**
72
+
**gl\_first\_name = user.FirstName**
65
73
66
-
**gl_last_name = user.LastName**
74
+
**gl\_last\_name = user.LastName**
67
75
68
-
**hpe_ccs_attribute = (See Below)**
76
+
**hpe\_ccs\_attribute = (See Below)**
69
77
70
78
See here for IdP attribute details: [](https://support.hpe.com/hpesc/public/docDisplay?docId=a00120892en_us)<https://support.hpe.com/hpesc/public/docDisplay?docId=a00120892en_us&page=GUID-D7192971-EF71-4304-B51E-548E7954E644.html>
71
79
72
-
A new SAML attribute has been added “hpe_ccs_attribute” which tells HPE GreenLake edge-to-cloud platform and HPE GreenLake for Private Cloud Enterprise application the exact role/permissions for each user. The following describes how to format the attribute.
80
+
A new SAML attribute has been added “hpe\_ccs\_attribute” which tells HPE GreenLake platform and HPE GreenLake for Private Cloud Enterprise application the exact role/permissions for each user. The following describes how to format the attribute.
Note : At present HPE GreenLake for Private Cloud Enterprise application role should be excluded.
77
85
@@ -81,62 +89,69 @@ Provide a name for the SAML application which gets connected to the HPE GreenLak
81
89
82
90

83
91
84
-
The **hpe_ccs_attribute** always starts with version1#. You must first configure the attributes for HPE GreenLake edge-to-cloud platform and To do so, enter the PCID for the account, followed by the HPE GreenLake application ID. This will always be **00000000-0000-0000-0000-000000000000**. Following this, enter the role name and ALL_SCOPES**.**
92
+
The **hpe\_ccs\_attribute** always starts with version1#. You must first configure the attributes for HPE GreenLake platform and to do so, enter the Platform Customer ID (PCID) for the account (this is the identifier assigned to your HPE GreenLake platform Workspace), followed by the HPE GreenLake platform application ID. This will always be **00000000-0000-0000-0000-000000000000**. Following this, enter the role name and ALL\_SCOPES**.**
Click Next and Select “Internal App”, then Finish.
104
+
Click **Next** and select **Internal App**, then **Finish**.
97
105
98
106
**Step 3:****Export the SAML 2.0 IdP metadata**
99
107
100
108
1. Click Next – Configure the single sign-on settings
101
109
102
-
You will find two options are available: **View Setup Instructions** which steps you through the SAML configuration and **Identity Provider metadata**, which will produce an XML file that can be loaded into HPE GreenLake edge-to-cloud platform application
110
+
You will find two options are available: **View Setup Instructions** which steps you through the SAML configuration and **Identity Provider metadata**, which will produce an XML file that can be loaded into HPE GreenLake platform application.
103
111
104
-
Suggestion: Click**Identity Provider metadata** and save the XML data to a file.
112
+
Suggestion: click**Identity Provider metadata** and save the XML data to a file.
105
113
106
114

107
-
2. Click **Next**.
115
+
116
+
2. Click **Next**.
117
+
108
118
3. Select **Internal app**, and click **Finish**.
109
119
110
-
##### **Step 3.1 : Access to the SAML application and HPE GreenLake edge-to-cloud platform is determined by assigning only those members or group to the SAML application.**
120
+
##### **Step 3.1 : Access to the SAML application and HPE GreenLake platform is determined by assigning only those members or group to the SAML application.**
111
121
112
122

113
123
114
124
115
125
116
-
**Step 4:****Configure the SAML connection in the HPE GreenLake edge-to-cloud platform**
126
+
**Step 4:****Configure the SAML connection in the HPE GreenLake platform**
117
127
118
-
1. Log into HPE GreenLake edge-to-cloud platform and click Menu > Manage > Authentication and Click Set Up SAML Connection.
128
+
1. Log into HPE GreenLake platform and click **Menu** > **Manage** > **Authentication** and click **Set Up SAML Connection**.
119
129
120
-
*Before you can add a new SAML configuration, you must have at least **one** user account with that **domain** already enabled in HPE GreenLake edge-to-cloud platform. Also, you must be logged into HPE GreenLake edge-to-cloud platform with an account from that domain in order to enable SSO for it.*
130
+
_Before you can add a new SAML configuration, you must have at least **one** user account with that **domain** already enabled in HPE GreenLake platform. Also, you must be logged into HPE GreenLake platform with an account from that domain in order to enable SSO for it._
121
131
122
132

133
+
123
134
2. Type in the domain you want to enable SSO on:
124
135
125
136

137
+
126
138
3. Input the metadata from the step above.
127
139
128
-
While HPE GreenLake edge-to-cloud platform does support entering this information manually, it's recommended that you simply upload the XML metadata that was downloaded in the previous step. To do so, Select Metadata File, selecting the XML file. Then, click Next.
140
+
While HPE GreenLake platform does support entering this information manually, it's recommended that you simply upload the XML metadata that was downloaded in the previous step. To do so, select **Metadata File**, selecting the XML file. Then, click **Next**.
129
141
130
142

143
+
131
144
4. Enter the SAML attributes to match what was entered in Okta. Set the idle timeout value as well.
132
145
133
146

134
-
5. Then click **Next**.
135
-
6. Create a recovery user so that, in the event SSO fails, an admin will still be able to access the HPE GreenLake edge-to-cloud platform.
147
+
148
+
5. Then click **Next**.
149
+
150
+
6. Create a recovery user so that, in the event SSO fails, an admin will still be able to access the HPE GreenLake platform.
136
151
137
152

138
153
139
-
Congratulations! SSO will now be enabled for HPE GreenLake edge-to-cloud platform as well as the HPE GreenLake for Private Cloud Enterprise application. Log out and on the HPE GreenLake edge-to-cloud platform home page, click **Sign in with SSO**.
154
+
Congratulations! SSO will now be enabled for HPE GreenLake platform as well as the HPE GreenLake for Private Cloud Enterprise application. Log out and on the HPE GreenLake platform home page, click **Sign in with SSO**.
140
155
141
156
**Testing and troubleshooting:**
142
157
@@ -146,7 +161,7 @@ On the HPE GreenLake edge-to-cloud platform home page, click **Sign In with SSO*
146
161
147
162

148
163
149
-
Enter the SSO credentials. You will be redirected to Okta to authenticate. Once you successfully authenticate, you will be redirected back to HPE GreenLake edge-to-cloud platform. You can then click on the HPE GreenLake for Private Cloud Enterprise application and be given access based on the configured role/permissions.
164
+
Enter the SSO credentials. You will be redirected to Okta to authenticate. Once you successfully authenticate, you will be redirected back to HPE GreenLake platform. You can then click on the HPE GreenLake for Private Cloud Enterprise application and be given access based on the configured role/permissions.
150
165
151
166
**Additional notes:**
152
167
@@ -157,4 +172,4 @@ Enter the SSO credentials. You will be redirected to Okta to authenticate. Once
157
172
* Customer users should be given access to SAML application.
158
173
* After authentication when clicking the HPE GreenLake for Private Cloud Enterprise application**,** if it leads to the below error, it will take 1 hr to sync. If it does not do so within that time period, the customer should contact their HPE administrator.
159
174
160
-
I hope this blog post answers any questions you may have had in regards to how to configure single sign-on for HPE GreenLake for Private Cloud Enterprise on the HPE GreenLake edge-to-cloud platform using Okta Active Directory. Please return back to the [HPE Developer blog](https://developer.hpe.com/blog) for more tips and tricks on working with the HPE GreenLake edge-to-cloud platform.
175
+
I hope this blog post answers any questions you may have had in regards to how to configure single sign-on for HPE GreenLake for Private Cloud Enterprise on the HPE GreenLake platform using Okta Active Directory. Please return back to the [HPE Developer Community blog](https://developer.hpe.com/blog) for more tips and tricks on working with the HPE GreenLake platform.
0 commit comments