SAML 2 : ForgeRock as Service Provider, authenticating with external IDP

Hello,

You can follow the instructions in the SAML2 docs: Configure IDPs, SPs, and CoTs :: AM 7.3.0

In a nutshell, you need to:

  1. Create a Hosted SP

  2. Obtain and import the metadata of the external IDP to create a remote IDP

  3. Create a circle of trust and add both entities to it

  4. Provide the metadata of your hosted AM SP to your external IDP

The assertion consumer URL is part of the metadata and can be accessed at https://openam.example.com:8443/openam/saml2/jsp/exportmetadata.jsp?entityid=myHostedProvider&realm=/mySubRealm (adapting the URL to your environment).

4 Likes