"java.security.UnrecoverableKeyException: requested entry requires a password" after creating SAML keystore
When using OpenJDK 11, you may find that the method for creating a SAML keystore described in Set up a SAML2 keystore does not work because the key being generated is not protected by a password - trying to log in via SAML will give you an unspecified error, and the server.log file will contain the error message "java.security.UnrecoverableKeyException: requested entry requires a password".
ADFS — SAML setup with iGrafx Identity
Configure Microsoft ADFS as the SAML identity provider for the iGrafx Identity Solution: add a relying party trust from the iGrafx metadata, add the NameID claim rule, and send iGrafx your IdP metadata.
ADFS auto-creation of authenticated users
Configure the platform to create authenticated SAML users automatically on first sign-in by mapping the ADFS first name, last name, and email claims.
Auto-create users on first sign-in
Turn on just-in-time provisioning so SSO users get an account on first sign-in. Whether you can do it yourself depends on whether your platform shows a SAML or an OAuth authentication tab.
Legacy SAML setup guide
Set up SAML SSO on the classic iGrafx login (not the iGrafx Identity Solution): configure Microsoft Azure AD, ADFS, Okta, or another SAML 2.0 provider, then test and disable form-based login.
Microsoft Entra ID / Azure AD — SAML setup with iGrafx Identity
Configure Microsoft Entra ID (Azure AD) as the SAML identity provider for the iGrafx Identity Solution: create an enterprise application, set the region-specific identifier and reply URL, and send iGrafx the metadata URL.
Okta — SAML setup with iGrafx Identity
Configure Okta as the SAML identity provider for the iGrafx Identity Solution: create the app integration, set the SSO URL and entity ID for your region, map the attributes, and send iGrafx the metadata URL.
SAML setup guide for the iGrafx Identity Solution
How SAML SSO works with the iGrafx Identity Solution as the service provider, the requirements, and links to the per-vendor setup guides for Microsoft Entra ID, Okta, and ADFS.
SAML2 authentication (ADFS, Okta, Centrify)
Set up SAML2 single sign-on for the iGrafx platform: create the SAML keystore, then configure Azure AD, ADFS, Okta, or Centrify as the identity provider, with user mapping and debugging options.
Setting up single sign-on
How single sign-on works with iGrafx Process360 Live, the SAML 2.0 identity providers it supports, and how to tell whether you're on the iGrafx Identity Solution or the classic login before you start.
Setting up SSO via an Azure AD enterprise application
Configure SAML SSO for an on-premises iGrafx platform using an Azure AD enterprise application: register the app, set the SAML URLs, and point the platform at the metadata.
Troubleshooting SAML configuration via Azure Active Directory
Fix two common Azure AD SAML SSO failures on the classic iGrafx login: a misconfigured Basic SAML Configuration, and a user or group not in scope for the enterprise application.
Update your SAML SSO configuration after upgrading to 20.x
Check and update your identity provider configuration after upgrading to 20.x: re-import the service provider metadata, verify bindings and endpoint URLs, and troubleshoot SAML sign-in failures.