Okta is a popular identity management product that can be integrated with Wavefront to enable single sign-on.
After setting up the Okta integration, users can authenticate to Wavefront through Okta instead of using a password. New users who did not exist in Wavefront are auto-created on the Wavefront side when they authenticate for the first time.
Step 1. Create the Wavefront Application in Okta
Note: Steps 1 - 12 are only required if the Wavefront application is not present in Okta. Otherwise, proceed to step 13 to copy and paste the metadata.
- In Okta, click Add Applications.
- Click Create New App.
- In the Create a New Application dialog, select SAML 2.0 and click Create.
- In the App name field, type Wavefront.
Right-click and save the Wavefront logo:
- In the App logo field, browse to the logo file and click Upload Logo.
- Click Next.
- Enter the following SAML settings:
- Single sign on URL - https://YOUR_CLUSTER.wavefront.com/api/saml/login
- Use this for Recipient URL and Destination URL - Checked
- Audience URI (SP Entity ID) - https://YOUR_CLUSTER.wavefront.com
- Default RelayState - <LEAVE BLANK>
- Name ID Format - EmailAddress
- Application username - Email
- Click Next.
- In the Are you customer or partner? field, select I’m an Okta customer adding an internal app.
- In the App type field, select This is an internal app that we have created.
- Click Finish.
In the application Sign On tab, click View Setup Instructions and click the Identity Provider metadata link to copy and paste the metadata.
Step 2. Send the Identity Provider Metadata to Wavefront and Complete the Setup
- Log in to your Wavefront instance as a user with
SAML IdP Adminpermissions.
- From the gear icon in the top right corner, select Self Service SAML.
- From the Identity Provider drop-down menu, select Okta.
- Paste the downloaded metadata from Step 1 into the Configure Connection text box.
- To validate the metadata, click Test. The Okta login page opens in a new browser window.
- Log in to Okta.
After the login is successful, click the Save button.
Note: The Save button is disabled until you’ve completed a test successfully.