SSO technical details and glossary

Technical details

Federated sign-on is implemented through the Oracle Construction and Engineering Lobby, which is an application written on top of Oracle Identity Cloud Service. A user navigates to the Lobby to sign in and this request is forwarded to IDCS to authenticate the user. If SSO federation is configured, the authentication request is forwarded to the Customer’s Identity Provider. Once authentication is successful, the user is redirected back to the Lobby with the relevant claims in place to meet the SAML 2.0 protocol. Any protocols supported by IDCS will be usable with the Lobby for authentication with Aconex.


Oracle Identity Cloud Service SAML integration currently supports:

  • SP initiated Web SSO
  • IdP initiated Web SSO
  • SP initiated Single Logout
  • IDP initiated Single Logout

You can find more information about SAML support in the Oracle Identity Cloud Service Documentation.

Download the datasheet and configuration checklist (PDF)

Also see:
Configure Identity Cloud Service (IDCS) for Single Sign-On
Create an Identity Provider Policy in IDCS

 

Glossary

Single Sign-On (SSO) -  An authentication scheme that allows a user to securely sign in to several related systems with a single username and password.

SAML - The protocol by which SSO authentication is negotiated between different identity providers

Identity Provider (IdP) - A service that stores and manages digital identities for users of systems. Examples are Oracle Identity Cloud Service and Microsoft’s Azure Active Directory and Active Directory Federation Services.