How to configure Google as a relying party manually for TozID or Keycloak
Following this tutorial will show you how to complete the integration between TozID and GSuite. This will allow your organization to sign into all of their Google products using TozID. Additionally these configuration settings can be useful in any Keycloak based deployment. Note that with TozID your passwords never leave the client devices to add another layer of protection. Learn more at TozID.
TozID allows for instant configuration of GSuite. Simply select "Google SAML" from the drop down menu when creating a client.
- Admin access to GSuite
- Admin access to your TozID Realm
- 30 minutes
Start by logging into your realm through the Tozny dashboard. Select clients from the left hand menu and then the create button on the top right. Enter the following values:
- Client ID: google.com/a/<your_gsuite_domain> (eg google.com/a/tozny.com)
- Client Protocol: saml
- Client SAML Endpoint: empty
Client creation step
Once you've created the client application we can configure the details of our SAML integration. Below are the settings:
SAML Signature Key Name
Force POST Binding
Front Channel Logout
Force Name ID Format
Name ID Format
IDP Initiated SSO URL Name
IDP Initiated SSO Relay State
Assertion Consumer Service POST Binding URL
Configure the mapper which maps an email address to the SAML attribute of emailAddress. Navigate to the mappers tab of the client.
Gsuite Mapper Configuration
Extract your X509 certificate for upload to Google. To do this navigate to the Installation tab of the client application and select SAML Metadata IDPSSODescriptor from the drop down. You need to select only the text between the tag <dsig:X509Certificate>. Save that to a new text file called cert.pem.
Navigate to the GSuite Admin portal. Once logged in go to the security section of the portal.
Expand the section labeled Set up single sign-on (SSO) and enter the following values with your realm where applicable.
Setup SSO with third party identity provider
Sign-in Page URL
Sign-out Page URL
Change Password URL
Upload your cert.pem file
User a domain specific issuer
You're all set! Save those settings and when you navigate to your gsuite gmail domain you'll be able to login with your TozID account.