This guide is for an older version of Kantega SSO Enterprise and is no longer maintained. New guides are here: https://kantega-sso.atlassian.net/l/c/rNTaTonz .

In Kantega Single Sign-on, add a new identity provider and select "Ping Federate" from the dropdown:

In the Prepare step, copy the Metadata URL if your Atlassian server is available to Ping Federate, or download the file if it's not.

Open the Ping Federate admin console in a separate browser tab. Press Create New in IdpConfiguration

Select Connection Template: Browser SSO Profiles PROTOCOL SAML 2.0. Press Next.

Select Browser SSO. Press Next.

Select the desired metadata import option. Press Next.

Review the metadata summary. Press Next.

Under General Info:

Select Configure Browser SSO. Press Next.

Select whether you want IDP-initiated SSO, SP-Initiated SSO, or both. Press Next.

Accept the default assertion lifetime. Press Next.

Select "Configure Assertion Creation"

Select Standard Identity Mapping. Press Next.

Configure Attribute Contract. This step may be skipped if you don't intend to use Just-in-time provisioning to create user accounts when users log into the Atlassian application.

"Extend the contract" with the additional fields from the table below.

Extend the tract:

Attribute Name Format

email

urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified

givenName

urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified

surname

urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified

Press Next.

Authentication Source Mapping. Select Map New Adapter Instance.

Adapter Instance:

Press Next.


Mapping Method:

Select Use Only The Adapter Contract Values In The SAML Assertion. Press Next.

Attribute Contract Fulfillment:

Press Next.

Issuance Criteria:

Press Next.

IDP Adapter Mapping Summary:

Press Done.

Assertion Creation

Authentication Policy Contract

Manage Contracts

Contract Info

Contract Attributes

Extend the contract with the following attributes:

After adding the attributes, press Next.

Authentication Policy Contract Summary

Authentication Policy Contracts

Selecting an Authentication Policy Contract

Mapping Method


Attribute Contract Fulfillment

Issuance Criteria

Authentication Policy Mapping Summary

Authentication Source Mapping 

Assertion Creation Summary

Assertion Creation

Protocol Settings

Assertion Consumer Service URL

Allowable SAML Bindings

Signature Policy

Encryption Policy

Protocol Settings Summary

Protocol Settings

Browser SSO

Credentials

Digital Signature Settings

Manage Digital Signing Certificates

Create Certificate

Create Certificate Summary

Manage Digital Signing Certificates

Digital Signature Settings

Credentials

Activation and Summary

Metadata Export


Metadata Mode

Connection Metadata

Metadata Signing

Export & Summary

Configuring Kantega Single Sign-on

Finally, go back to the Kantega SSO tab. Still on the Prepare step, press Next.

Metadata import

Location

Signature

Users

You should now be able to test SAML login through Ping Federate.