Users Guide

Table Of Contents
Enabling Application SSO
Enabling application SSO using L2 authentication information requires configuration on the controller and
CPPM. This feature is enabled by completing the following steps:
l Controller:
n Configuring an SSO-IDP Profile
n Applying an SSO Profile to a User Role
n Selecting an IDP Certificate
l CPPM (refer to the ClearPass Policy Manager for configuration of the following procedures):
n Add the controller’s IP address as a network device
n Add the user to the local user DB
n Create an enforcement profile to return the Aruba vendor-specific attribute (VSA) SSO token
n Create an IDP attribute enforcement profile
n Create an enforcement policy binding the Aruba VSA SSO token enforcement profile
n Create an enforcement policy binding the IDP enforcement profile
n Create a service, allowing the respective authentication types and authentication database, and bind the
Aruba VSA SSO token enforcement policy.
n Create a service, allowing the respective authentication types and authentication database, and bind the
IDP enforcement policy.
n Configure SSO for the CPPM.
Configuring SSO IDP-Profiles
Before SSO can be enabled, you must configure an SSO profile by completing the procedure detailed below.
In the WebUI
1. Navigate to Configuration > Advanced Services > All Profiles > Wireless LANs > SSO.
2. Enter the name of the SSO profile and click Add.
3. Click on the name of the IDP profile in the Instance list to edit the profile.
4. Click New.
5. Enter the name of the IDP URL in the URL Name text box.
6. Enter the IDP URL into the URL text box.
7. Click Add.
8. Repeat steps 4 through 7 for each IDP URL you are adding to the SSO profile.
9. Click Apply when all URLs have been added.
In the CLI
sso idp-profile <idp profile name>
idp <urlname> <url>
Applying an SSO Profile to a User Role
The newly created SSO profile must be applied to any applicable user rules that require SSO. Apply the SSO
profile be completing the steps below.
In the WebUI
1. Navigate to Configuration > Security > Access Control.
2. Select the User Roles tab.
Dell Networking W-Series ArubaOS 6.5.x | User Guide 802.1X Authentication | 285