Prerequisites
- An IdP that supports automatic updates of a service provider's metadata from a URL, for example: AD FS and Ping Identity.
- Configure your IdP platform to read one of the following Secure Access metadata URLs for encrypted or unencrypted SAML assertions:
- Encrypted:
-
<https://api.sse.cisco.com/admin/v2/samlsp/certificates/Cisco_SSE_SP_Metadata_with_Encryption.xml>
-
- Unencrypted:
-
https://api.sse.cisco.com/admin/v2/samlsp/certificates/Cisco_SSE_SP_Metadata.xml
-
- Encrypted:
- Your IdP platform can read the associated Certificate Authority URLs:
-
http://r3.o.lencr.org
-
http://r3.i.lencr.org
-
- Your IdP platform must support TLS 1.2 in order to connect to the Secure Access metadata URL securely. If the IdP application utilizes .NET framework 4.6.1 or earlier this may require some further configuration. See Microsoft's documentation.
- For information on prerequisites that apply to all SAML IdPs, see Prerequisites for SAML Authentication.