You can delete or modify an identity provider in Carbon Black App Control.

You might decide not to use an identity provider at all, or to change to a different provider. Only one identity provider per server is allowed. To change providers, you must first delete the old identity provider and then add the new identity provider.

Delete an Identity Provider

To delete the identity provider for a Carbon Black App Control Server, perform the following procedure.

Procedure

  1. In the console menu, click on the Configuration (gear) icon and click System Configuration.
  2. Click the SAML Login tab.
  3. In the Identity Provider panel, click Delete. Click OK in the confirmation dialog box.

Results

The identity provider is removed and SAML logins are disabled. Logins are handled locally by using the user names and passwords configured in Carbon Black App Control.

Edit an Identity Provider

To edit an identity provider for a Carbon Black App Control Server, perform the following procedure.

Procedure

  1. In the console menu, click on the Configuration (gear) icon and click System Configuration.
  2. Click the SAML Login tab.
  3. In the Identity Provider panel, click Edit.
    The Edit Identity Provider dialog box
  4. Edit the settings and then click the Save button at the bottom of the dialog box.

Identify Provider Settings

The following table describes the fields available in the Edit Identity Provider dialog box.

Field

Description

Configuration Type

This field has two radio buttons that determine editing mode: XML and Manual. When you edit an IdP, the default choice is Manual.

Identity Provider Name

This field shows the current IdP name that appears on the Login button in Carbon Black App Control. Changing this value changes the button name, but does not affect anything else about the IdP configuration.

Identity Provider Entity ID

This field is the base URL for the IdP. For example: https://idp.socentral.com.

Sign-on Location

This field is the URL for signing on to your IdP. For example: https://idp.socentral.com:443/sso/SSORedirect/metaAlias/publicidp.

Logout Location

This field is the URL for logging out of the IdP. For example: https://idp.socentral.com:443/sso/IdPSloRedirect/metaAlias/publicidp.

Signing Certificate

The identity provider’s signing certificate.

Encryption Certificate

The identity provider’s encryption certificate.