Skip to main content

Configure SAML SSO between DigiCert and Google Workspace

This guide walks you through setting up Single Sign-On (SSO) between your DigiCert​​®​​ account and Google Workspace using SAML 2.0.

You will switch between DigiCert and Google Workspace tabs to exchange metadata and URLs. Once setup is complete, users in your account can sign in to DigiCert using their Google Workspace credentials, either from the Google Workspace dashboard or the DigiCert sign-in page.

For more details about Google Workspace configuration, refer to Google Workspace.

Before you begin

To complete this setup, you need administrative access in both DigiCert and Google Workspace:

  • Account admin user group required in DigiCert account.

    How do I check my user group?

  • Application Administrator or equivalent role required in Google Workspace.

Step 1: Access DigiCert SSO settings

Access DigiCert's SAML configuration page:

  1. In the DigiCert​​®​​ account menu, select the Accounts icon > Sign-in methods.

  2. Select Single sign-on with SAML.

  3. Leave this window open.

Step 2: Create SAML application in Google Workspace

In another tab, create a SAML application for your DigiCert account in Google Workspace:

  1. Sign in to the Google Admin console.

  2. In the left-hand navigation menu, navigate to Apps > Web and mobile apps.

  3. In the App name field, enter DigiCert account.

  4. In the Description field, enter a custom description.

    Example: DigiCert's single login experience

  5. In the App icon field, upload the DigiCert icon.

    Need a DigiCert logo?

  6. Select Continue.

  7. In the Download IdP metadata section, select Download metadata.

  8. Select Continue.

  9. Leave this window open.

Step 3: Upload Google Workspace metadata to DigiCert

Back in your DigiCert​​®​​ account tab:

  • Upload the Google Workspace metadata that you downloaded in Step 2.

  • Copy the SSO URL, you'll need to provide it to Google Workspace in Step 4.

  • Enable SSO.

  1. In the Connect your IdP to DigiCert section, select Upload IdP metadata.

  2. In the Connect DigiCert to your IdP section, copy the SSO URL.

  3. In the Enable/Disable SSO with SAML section, toggle to enable SSO.

  4. Select Save configuration.

Step 4: Back in Google Workspace

  1. Paste the SSO URL in both of these fields:

    1. ACS URL

    2. Entity ID

  2. In the Name ID format field, select Email.

  3. In the Name ID field, keep the default Basic information > Primary email.

  4. Select Continue.

  5. In the Attributes section, select Add mapping.

    1. Below the Google Directory attributes field, select Primary email.

    2. Below the App attributes field, type email.

  6. Select Finish.

In Google Admin console:

  1. Go to Apps > Web and mobile apps.

  2. Select the DigiCert app you just created.

  3. In the User access section, select View details.

  4. In the Organizational units section, select the group you want to assign.

  5. In the Service status field, select the radio button next to On.

  6. Select Save.

In Google Admin console:

  1. Go to Apps > Web and mobile apps.

  2. Select the DigiCert app you just created.

  3. On the DigiCert app overview, select TEST SAML LOGIN.

  4. In the Can't test SAML login modal, select Allow access.

  5. In the Service status field, select the radio button next to ON for everyone.

  6. Select Save.

  7. Return to the DigiCert app overview, select TEST SAML LOGIN.

    Tip

    • Your SAML app is configured correctly if you are redirected to DigiCert account and asked to complete two-factor authentication (2FA).

    • If you are not redirected to the 2FA page in DigiCert account, please compare your app settings to the instructions above or contact DigiCert support for assistance.

DigiCert logos

Use of DigiCert's logo must at all times comply with DigiCert brand guidelines, including the DigiCert Trademark Usage Guidelines available at https://www.digicert.com/legal-repository/ (as updated from time to time).

DigiCert_White_on_Blue_Logo.png
DigiCert_Blue_on_White_Logo.png

DigiCert logo's for SSO configuration.