Configuring PingFederate (SAML) SSO for Vantage

Modified on Thu, 8 Oct at 10:28 AM

Configuring PingFederate (SAML) SSO for Vantage



Environment: Production Purpose: Configure PingFederate as a SAML 2.0 Identity Provider (IdP) for federated Single Sign-On into Vantage through NPI's Auth0 tenant.

Overview

PingFederate connects to Vantage over SAML 2.0, not OIDC: your PingFederate server is the IdP, and NPI's Auth0 tenant (auth.npi-digital.com) is the Service Provider (SP). You create one SP connection in PingFederate, then send NPI your IdP metadata and signing certificate.


The sign-in flow works like this:

  1. A user opens Vantage at https://www.npi-digital.com and enters their work email.
  2. Auth0 recognizes your email domain and sends a SAML authentication request to your PingFederate server.
  3. PingFederate authenticates the user against your directory and posts a signed SAML assertion back to Auth0.
  4. Auth0 validates the signature with your certificate and signs the user into Vantage.


1. Prerequisites

Before starting, verify:

  • You have Administrator access to the PingFederate administrative console.
  • PingFederate has an IdP adapter or authentication policy that authenticates your users (most installations already have one).
  • You have a signing certificate in PingFederate under Security → Signing & Decryption Keys & Certificates.
  • You have received the Auth0 connection name from your Vantage implementation engineer. It is unique to your organization and appears in the values below as <CONNECTION_NAME>.

Values NPI provides

The fastest path is to import NPI's SP metadata file, which carries all of these values. Use the table to verify the import or to enter them by hand.


Setting

Value

SP metadata URL

https://auth.npi-digital.com/samlp/metadata?connection=<CONNECTION_NAME>

Partner's Entity ID

urn:auth0:npi-prod:<CONNECTION_NAME>

Assertion Consumer Service (ACS) URL

https://auth.npi-digital.com/login/callback?connection=<CONNECTION_NAME>

ACS binding

HTTP-POST

Single Logout URL (optional)

https://auth.npi-digital.com/logout

Auth0 request-signing certificate

https://auth.npi-digital.com/pem

Auth0 identifies the SP by the Entity ID above, so it must match exactly, including case.


2. Create the SP Connection

  1. Sign in to the PingFederate administrative console.
  2. Navigate to Applications → Integration → SP Connections and click Create Connection.
  3. Connection Template: select Do not use a template for this connection. Click Next.
  4. Connection Type: check Browser SSO Profiles and choose SAML 2.0 as the protocol. Click Next.
  5. Connection Options: leave Browser SSO selected. Click Next.
  6. Import Metadata: select URL and enter the SP metadata URL from Section 1, or select File and upload the metadata file NPI sent you. Click Next.
  7. General Info: confirm Partner's Entity ID reads urn:auth0:npi-prod:<CONNECTION_NAME>. Set Connection Name, for example NPI Vantage (Auth0) - Prod. Click Next.

2.1 Browser SSO

On the Browser SSO tab, click Configure Browser SSO.

  1. SAML Profiles: select SP-Initiated SSO. Add IdP-Initiated SSO if you want a Vantage tile in your user portal, and SP-Initiated SLO if you want single logout.
  2. Assertion Lifetime: keep the defaults (5 minutes before and after).
  3. Assertion Creation: click Configure Assertion Creation and complete Section 3 below.

2.2 Protocol Settings

Click Configure Protocol Settings.

  1. Assertion Consumer Service URL: confirm one entry with binding POST and endpoint https://auth.npi-digital.com/login/callback?connection=<CONNECTION_NAME>. Add it manually if the import did not.
  2. Allowable SAML Bindings: check POST and Redirect. Auth0 sends requests by Redirect and receives assertions by POST.
  3. Signature Policy: select Always sign the SAML Assertion.
  4. Encryption Policy: select None, unless your security policy requires encrypted assertions. If so, tell NPI before go-live.
  5. Review the summary and click Done.

2.3 Credentials

Click Configure Credentials.

  1. Digital Signature Settings: choose the PingFederate signing certificate that will sign assertions for Vantage.
  2. Signature Verification Settings: Auth0 signs its SAML requests by default. Import the Auth0 certificate from https://auth.npi-digital.com/pem and mark it Unanchored.
  3. Click Done.

2.4 Activate

On Activation & Summary, set Connection Status to Active and click Save.


3. Configure Assertion Creation (Attributes)

Auth0 requires only the NameID (SAML_SUBJECT), but Vantage needs the user's email to match their account, so send the user's email address as the NameID and include the attributes below.

  1. Identity Mapping: select Standard. Click Next.
  2. Attribute Contract: set the SAML_SUBJECT format to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress, then click Extend the Contract to add the attributes in the table.
  3. Authentication Source Mapping: click Map New Adapter Instance (or Map New Authentication Policy) and select the adapter or policy contract that authenticates your users.
  4. Attribute Contract Fulfillment: map each attribute to its source, as in the table. Click Next through Issuance Criteria, then Done.

Attribute

Required

Typical source (LDAP / Active Directory)

SAML_SUBJECT (NameID)

Yes

mail

email

Yes

mail

given_name

Recommended

givenName

family_name

Recommended

sn

name

Optional

displayName

Use the attribute names exactly as shown, all lowercase. The email in the assertion must match the email the user is invited to Vantage with.


4. Export Metadata and Share Details with the Vantage Team

After saving, go to Applications → Integration → SP Connections, open the Action menu for the new connection, and select Export Metadata. Choose your signing certificate and download the XML file.


Then export the signing certificate itself: Security → Signing & Decryption Keys & Certificates, select the certificate, and choose Export → Certificate only (PEM/CER).


Provide the following to your Vantage implementation engineer:

Value

Example

PingFederate IdP metadata (XML file)

NPI_Vantage_metadata.xml

PingFederate Server URL (base URL)

https://sso.yourcompany.com

SSO endpoint

https://sso.yourcompany.com/idp/SSO.saml2

X.509 signing certificate (PEM/CER, public key only)

pingfed-signing.crt

Email domains to route to PingFederate

yourcompany.com, subsidiary.com

Assertion encryption in use?

No

IdP-initiated SSO wanted?

Yes / No

Test user email

jane.doe@yourcompany.com

The metadata and certificate contain only public keys, so email is fine. Never send a private key or a .p12 / .pfx file.


5. Test the Connection

Once NPI confirms the Auth0 connection is live, test with the user you named in Section 4.

  1. Open a private or incognito browser window.
  2. Go to https://www.npi-digital.com and enter the test user's work email.
  3. Confirm you are redirected to your PingFederate sign-in page, not the Vantage password prompt.
  4. Sign in. You should land in Vantage, signed in as the test user.
  5. If you enabled IdP-initiated SSO, also launch Vantage from your user portal and confirm it signs in.

If a step fails, note the time and the error text, and send them to NPI along with your PingFederate server log entry for that sign-in.


6. Common Errors to Avoid

Issue

Resolution

PingFederate rejects the request: unknown partner

Partner's Entity ID must be exactly urn:auth0:npi-prod:<CONNECTION_NAME>, including case

Auth0 shows an invalid signature error

Confirm Always sign the SAML Assertion is set and NPI has your current signing certificate

User is sent to the Vantage password prompt

Email domain is not registered with NPI; send the missing domain

Signed in but missing email or name

Check the attribute contract and fulfillment mapping in Section 3

IdP-initiated sign-in fails

ACS URL must include ?connection=<CONNECTION_NAME>

Sign-in breaks after a certificate rotation

Send NPI the new certificate before the old one expires


7. Quick Checklist

  • Received the Auth0 connection name from NPI
  • Created a SAML 2.0 SP connection from NPI's metadata
  • Entity ID and ACS URL verified
  • SP-initiated SSO enabled (IdP-initiated optional)
  • Assertion always signed
  • NameID set to email; email, given_name, family_name mapped
  • Auth0 request-signing certificate imported
  • Connection activated
  • Metadata, signing certificate, domains, and test user sent to NPI
  • Test sign-in completed


Need Help?

If you encounter issues or need assistance, contact your Vantage implementation engineer or reach us at support@npi-digital.com.


Sources

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article