Redrock tech support and your campus IT contact will need to work together to set up SAML Authentication.
SAML requires some communication between your campus authentication server and the Redrock SAML Proxy server.
1) Your AdvisorTrac/TutorTrac software must be updated to the Feb 2019 version or later.
2) Please provide Redrock with your campus metadata (or the HTTP-POST URL).
3) Here is the Redrock Metadata link:
https://saml2.go-redrock.com/simplesaml/module.php/saml/sp/metadata.php/trac4-saml
- download and install our metadata into your SSO software.
4) We will need a test student account.
5) SAML Attribute:
- Send username, email address, or student ID as an attribute.
- The name of the attribute can be whatever your system uses. (examples: username, student id, email, sAMAccountName, personprincipal, name id, PersonID)
- The attribute needs to be a unique identifier for the student account (preferably the username).
- The attribute must be a value that we can match with the TutorTrac student or instructor account.
6) SAML Response to Redrock:
- can be signed
- can be encrypted
- can be transient or persistent
- Our SAML setup is for SP (Service Provider) initiated with Redrock as the SP.
- We have plans to support IdP (Identity Provider) initiated in the future, rollout date is TBD.
7) Your TutorTrac/AdvisorTrac URL must be reachable (without VPN credentials). Redrock IP must be whitelisted.
- Redrock SAML Proxy IP: saml2.go-redrock.com (63.224.138.136), ports 80 and 443
- Redrock Tech Support IP: go-redrock.com (63.224.138.155), ports 80 and 443
8) Your TutorTrac/AdvisorTrac URL must use SSL (https://TracSystem.campus.edu)
9) After the end user is finished using AdvisorTrac/TutorTrac, we can re-direct to a webpage that you specify. Please provide the exact link address (for example https://mycampus.edu).
10) Please schedule a time to test SAML configuration.
|