Managing SAML Single Sign-on (SSO) users

Once you’ve finished configuring your CertCentral account for SAML SSO, you can begin adding your SSO Users (e.g., Administrators, Managers, etc.). Before you begin, it is important to note that there are two types of SSO users: SAML SSO-only and account.

"Only Allow This User to Log in Through SAML SSO" permission

This permission allows you to control how users (Administrators, Managers, Finance Managers, and Users) sign in to their CertCentral accounts: SAML SSO login only or SAML SSO and direct CertCentral logins.

The Only allow this user to log in through SAML SSO permission also removes the ability for SAML SSO-only type users to modify their username or email address. Only an administrator or manager can change the username or email address for SAML SSO-only accounts. Account users who can sign in using CertCentral credential or SAML SSO can change the username and email address for their account themselves, although this is not recommended.

Add a SAML SSO-only account user or an account user

To add a SAML SSO-only type user, you simply check Only allow this user to log in through SAML SSO when creating the user account. To add an account user, you simply uncheck Only allow this user to log in through SAML SSO when creating the user account.

  • A SAML SSO-only user can only log into their CertCentral account via the custom SSO login URL (e.g., https://www.digicert.com/account/sso/"federation-name"/login) or the IdP initiate login URL that you provide them.
  • An account user can sign in to their CertCentral account directly via the DigiCert URL (e.g., https://www.digicert.com/account/login.php) or via the custom SSO login URL or the IdP initiate login URL that you provide them.

Both user types—SAML SSO-only and account—can be assigned to a division or have access to all divisions, can be assigned to one of the four roles (Administrator, User, Finance Manager, and Manager), and can be added as a verified contact to approve EV SSL, EV Code Signing, and Code Signing requests.