Skip to main content

Configure SAML SSO between DigiCert and Google Workspace

Use this procedure to configure single sign-on (SSO) between your DigiCert​​®​​ account and Google Workspace using Security Assertion Markup Language (SAML) 2.0.

To set up this sign in method, you need to switch between two tabs, DigiCert and Google Workspace, to exchange metadata.

For more details about Google Workspace configuration, refer to Google Workspace.

Before you begin

To finish this setup, you need administrative access in both DigiCert and Google Workspace:

  • Account admin user group required in DigiCert account.

    How do I check my user group?

  • Application Administrator or equivalent role required in Google Workspace.

Access DigiCert's SAML configuration page:

  1. In DigiCert​​®​​ account, select the Accounts icon > sign in methods.

  2. Select Single sign-on with SAML.

  3. Leave this tab open.

In another tab, create a SAML application for your DigiCert account:

  1. Sign in to the Google Admin console.

  2. In the left pane, navigate to Apps > Web and mobile apps.

  3. In the App name field, enter DigiCert account.

  4. In the Description field, enter a custom description.

    Example: DigiCert's single login experience

  5. In the App icon field, upload the DigiCert icon.

    Need a DigiCert logo?

  6. Select Continue.

  7. In the Download IdP metadata section, select Download metadata.

  8. Select Continue.

  9. Leave this tab open.

Back in your DigiCert​​®​​ account tab, upload the metadata file that you downloaded in Step 2 and copy the SSO URL.

  1. In the Connect your IdP to DigiCert section, select Upload IdP metadata.

  2. In the Connect DigiCert to your IdP section, copy the SSO URL.

  3. In the Enable/Disable SSO with SAML section, switch to enable SSO.

  4. Select Save configuration.

Back in your Google Workspace tab, enter the SSO URL that you copied from DigiCert​​®​​ account in Step 3, and finish the remaining fields.

  1. Enter the SSO URL in both of these fields:

    1. ACS URL

    2. Entity ID

  2. In the Name ID format field, select Email.

  3. In the Name ID field, keep the default Basic information > Primary email.

  4. Select Continue.

  5. In the Attributes section, select Add mapping.

    1. Below the Google Directory attributes field, select Primary email.

    2. Below the App attributes field, type email.

  6. Select Finish.

Ensure that all users in your DigiCert​​®​​ account are assigned to the SAML application in Google Admin console:

  1. Go to Apps > Web and mobile apps.

  2. Select the DigiCert app you created.

  3. In the User access section, select View details.

  4. In the Organizational units section, select the group you want to assign.

  5. In the Service status field, select the radio button next to On.

  6. Select Save.

Verify that you’re able to sign in using your SAML application from Google Admin console:

  1. Go to Apps > Web and mobile apps.

  2. Select the DigiCert app you created.

  3. On the DigiCert app overview, select TEST SAML LOGIN.

  4. In the Can't test SAML login modal, select Allow access.

  5. In the Service status field, select the radio button next to ON for everyone.

  6. Select Save.

  7. Return to the DigiCert app overview, select TEST SAML LOGIN.

    Tip

    • Your SAML app is configured correctly if you’re redirected to your DigiCert account and asked to finish two-factor authentication (2FA).

    • Not redirected to the 2FA page in your DigiCert account? Compare your SAML app settings to these instructions or contact DigiCert Support for assistance.

DigiCert logos

Use of DigiCert's logo must at all times comply with DigiCert brand guidelines, including the DigiCert Trademark Usage Guidelines available at https://www.digicert.com/legal-repository/ (as updated from time to time).

DigiCert_White_on_Blue_Logo.png
DigiCert_Blue_on_White_Logo.png

DigiCert logos for SSO configuration.