Hootsuite Enterprise SAML Configuration

system

Introduction

This article outlines the information and steps you need to take in order to configure Hootsuite Enterpise to use the LogonBox SAML Identity Provider. Once configured your users will be redirected to your LogonBox Server to authenticate. 

 

Step 1 - Create the Resource from the Template

Log into your server as admin and navigate to Identity Services->SAMLSelect Search Templates and select the Hootsuite Enterprise SAML template and click Next.

 

You will be asked for your Hootsuite return URL, this is provided by the hootsuite support team, if you do not know this currently, enter returnURL.

 

Click Next. At this point click close the templates window so that you can return to the list of SAML resources where your Hootsuite SAML resource should now be present.

 

Edit the resource and in the Assignment tab, add users, groups or roles who will have permission to use this resource.

You can add the Everyone role to add all users and click Update.

 

 

Step 2 - Download SAML metadata

You will need a couple of things from your server in order to configure Hootsuite. First you will need to download the SAML metadata.

In the table of SAML resources locate the Lynda SAML resource, and click the options icon to activate the dropdown. Select Download Metadata; this is an XML file that contains information about the Identity Provider and its access points.

 

Open the XML file containing the metadata and locate the logon service URL. This islocated towards the end of the document and will look like

https://demo.logonbox.com/app/api/sso/logon/123456

Copy the entire URL we will need this in the next step.

Next, navigate to Certificates and locate the SAML RSA certificate. Again using the options icon to activate the dropdown, select Download Certificate

 

Step 3 - Establishing Federation with Hootsuite

Once you have setup the SAML resource on your server you will now need to contact Hootsuite support and request they enable SAML for your organization. You will need to provide your metadata, certificate and sign on URL as taken in the previous step. They will then enable SSO on your account and provide you with a return URL.

Edit the Hootsuite template, select Advanced and locate all references to returnURL  and replace with the actual return URL provided by Hootsuite.

Click Update when done.

 

Step 4 - Final Checks

Each user's email address must match their SAML logon email as this is the primary link between accounts.

Once access is assigned log out of Hootsuite and then access LogonBox as a user with the rights to use the new resource. In BMy Resources->Browser Resources click the launch icon to access Hootsuite.

You can also login from Hootsuite by clicking the single sign-on button.