Configure SSO: Use a Token Signing Certificate
EnterWorks obtains the signing certificate in the following manner:
EnterWorks will look for the file:
<drive>:\Enterworks\certs\token_cert.pemIf it finds the file, it will pull the certificate out of it.
-
EnterWorks will then look at the metadata. If a signing certificate is provided in the metadata, it will pull the certificate from the metadata and use it. If EnterWorks already has pulled a certificate from
token_certs.pemfile, EnterWorks will use the certificate it found in the metadata.
To configure EnterWorks to use the signing certificate:
-
Open the
create-enable-web-server-service.cmdscript in an editor. -
Uncomment out the setting:
samlSigningSPKeysPath. -
To tell EnterWorks to look for the
token_cert.pemfile, set thesamlSigningSPKeysPathparameter to indicate the location of thetoken_cert.pemcertificate file:-samlSigningSPKeysPath=<drive>:\Enterworks\certs\saml -
Save the
create-enable-web-server-service.cmdscript. -
Use the
create-enable-web-server-service.cmdscript.