
Product Announcements — Tim J (Veracode PM) (Veracode) asked a question.
Hi! We have an update coming that will improve our Single Sign On and Just-In-Time Provisioning support. This is an update that will be scheduled on a customer-by-customer basis as it requires some work by your IT organization to update your SAML settings for Veracode. Read on for more information about what’s changing and what you need to do.
Why we’re updating
We wanted to bring a more modern single sign on capability to customers that improves compatibility with industry single sign on providers and makes maintaining and supporting single sign on more straightforward. We also wanted to unify the experience for single sign on and non-SSO users, and address some common requests for Just in Time provisioning. Last, we wanted to lay the groundwork for future enhancements to our SSO capabilities.
What’s changing
The following changes will happen as part of this work:
For end users
- End users will see the new Veracode home page when they log in
For administrators
- Administrators will see separate tabs for SAML Settings and Just-in-Time (JIT) Provisioning settings
- The SAML settings tab will show all configuration values required for your identity provider (target URL, relaystate URL, audience URL).
- The SAML settings tab will clearly show the expiration date of your SAML certificate
- The JIT Settings tab will allow setting the Security Labs User role as a JIT default
- The JIT Settings tab no longer allows setting the Activation Required option. If you use this option, we recommend defining a default team that is not associated with any applications in the JIT settings, then reviewing the membership of that team periodically to assign users to the appropriate settings.
For IT administrators
- Veracode will now provide three settings (target, relaystate, audience) instead of the two currently provided
- The target URL is changing and will be unique for each customer
For automation developers
- Customers using the new SAML and JIT workflow can no longer use the XML Admin API to update users and teams. See the recent announcement about XML Admin API Deprecation for more information.
- Customers using the “Prefer Organization Identity Provider Data” setting can no longer use the Identity API to update user information as this is controlled by the values in the SAML assertion.
What future updates are planned for single sign on?
Veracode will support a Service Provider Initiated (SP Initiated) single sign on workflow for customers that migrate to the new SAML workflow. With SP Initiated single sign on, a user visiting the login page of the Veracode Platform can enter their email address and be redirected to their identity provider to complete the sign-on process. We expect this capability to be available this summer for customers who migrate to the new SAML workflow.
When will this change be available?
The new workflows will be available for customers starting in early July. We will roll out this changes in phases. Your customer success manager will notify you when Veracode is ready for you to make changes on your identity provider to take advantage of the new features.
Do I have to migrate on a certain timeline?
Migration to the new workflow can be driven by your timeline. However, you will be unable to take advantage of new features like SP initiated single sign on until you migrate.
What must a customer do to take advantage of the new workflow?
Follow the following process to take advantage of the new workflow:
- Notify your identity provider administrator (usually your IT team) of the upcoming change.
- Update any automation using the Admin APIs to use the Veracode Identity APIs instead.
- Contact Veracode support to activate the new SAML and JIT Provisioning tabs.
- Make any updates desired to the JIT Provisioning settings (e.g. define a default team if you are currently using the Activation Required workflow; add the Security Labs User role to default role settings; etc.)
- Copy the Target URL, Audience URL and Relay State URL settings from the SAML tab and share these with your identity provider administrator.
- Recommended: Within your identity provider, create a new connection to Veracode using the settings from Step 5 and test that the new single sign on workflow works correctly.
- Update your production Veracode identity provider tile to use the new settings.
I have questions!
You can ask them here! You can also reach out to Veracode customer support or your customer success manager.
.png)
hi,
we have 2 tenants in our company and we want to connect both issuers and certificates to veracode platform.
please let me know how we can do that?
i see in "Organization SAML Settings" section only one field for one issuer and a single certificate .