This guide walks you through setting up Cisco Duo single sign-on (SSO) for logging into Sastrify.


To set up Cisco Duo SSO as your login method in Sastrify, follow these steps:

  1. Select "Login with Cisco Duo" in your Sastrify platform.
  2. Create a generic SAML service provider application in Duo and generate your credentials: Single Sign-On URL and IdP Certificate.
  3. Send the credentials to Sastrify.
  4. Complete the configuration by entering values provided by Sastrify into Duo.
  5. Confirm the setup and request a test if needed.


Each step is outlined below.


IN THIS ARTICLE


Step 1: Select the login method in Sastrify



  1. Go to: Settings > User & Company Data > Authentication Settings
  2. Click "Edit".
  3. Select "Login with Cisco Duo".
  4. Click "Enable SSO".


After you click Enable SSO, you'll see a confirmation message. This also triggers an email from Sastrify with instructions to provide your Cisco Duo credentials, which you’ll need to complete the setup in Step 3.


Step 2: Create a Generic SAML Service Provider application in Duo


  1. Sign in to your Duo Admin Portal using your admin account.
  2. Navigate to Applications > Application Catalog.


  3. Locate the entry for Generic SAML Service Provider with the "SSO" label in the catalog
  4. Click the + Add button to start configuring Generic SAML Service Provider.


  5. Go to the Metadata section, where you can get SAML identity provider information about Duo Single Sign-On to provide to Sastrify.
  6. Cisco Duo will automatically generate a single sign-on URL and idP certificate. 
  7. Copy the URL, download the certificate, and proceed to the next step.


The certificate will be used by Sastrify to validate the signature on the SAML response sent by Duo Single Sign-On. Click the Download Certificate button to download a crt file.

Step 3: Send credentials to Sastrify


Reply to the email from Step 1 and include:

  • Single Sign-On URL

  • IdP Certificate


Once received, Sastrify will send back the following configuration values needed to complete the setup. 

  1. Entity ID, e.g., urn:auth0:sastrix:<company_name>-CISCODUO-SSO-PROD
  2. ACS URL, e.g., https://login.sastrify.com/login/callback?connection=<company_name>-CISCODUO-SSO-PROD
  3. Single Logout URL, e.g., https://login.sastrify.com/logout

Step 4: Update your application and complete configuration in Duo


Once you receive the final configuration values from Sastrify:

  1. Return to the application page in your Duo Admin Panel.

  2. Leave the drop-down set to None (manual import) to populate the fields by copying information from Sastrify and pasting it into the Duo Admin Panel.

  3. Enter the IdP Entity ID, SP Entity ID, and ACS URL as provided into the Service Provider section.


  4. Under the SAML Response section, set the following values:
    • NameID Format: nameid::format::emailAddress
    • NameID Attribute: <Email Address>
    • Signature Algorithm: SHA256
  5. Map the required SAML attributes according to your organization's identity setup.

  6. Scroll down to the bottom of the page and click Save.


Once saved, your Cisco Duo SSO integration will be complete.


Step 5: Confirm setup and testing


To finalize, reply to the same email thread and confirm that you’ve completed the SSO configuration in Cisco Duo. 


Our support team can run a quick test on your behalf to ensure that authentication is working as expected.