Reetro Single Sign On Configurations

In this article we will explain you How to Register your Company in Reetro How to Create Team How to add team members in Team How to upgrade/downgrade registered users right

 

OKTA SSO INTEGRATION

 

In order to configure OKTA integration with Reetro follow the steps below.

 

Requirements

You must be an admin in your Reetro Organization account

You must be an admin in Okta

 

STEP_1: Getting Data From Reetro

 

- Logon to Reetro and on the left menu go to “Admin Controls”

 

- On the “Admin Controls” click on the Single sign on tab

 

- Leave this window open for the moment - we'll need this information to complete configuration of the reetro app in OKTA.

Reetro okta integration  

STEP_2: Configure Single Sign On in OKTA

 

-In your OKTA admin dashboard, select Add Application

 

-Click the Create New App button.

 

-In the "Create a New Application Integration" dialog:

 

Select "Platform": Web  

Select "Sign on method": SAML 2.0

okta integration  
 

-Click Create

-Following window will open

 
okta integration  
 

-On the Create SAML Integration, General Settings screen

  Enter "App name": Reetro

  Upload the Reetro logo (you can download the one below)

-Click Next

-Following screen will open

 
okta integration  
 

In the above from, you need to add following details

1- Single sign on URL: [copy the Login URL from SSO tab from the Reetro app]

for example : https://www.reetro.app/xxxxxxxxxxxxxx/api/saml/login/callback

Remember to add the /callback at the end of URL

2-Audience URI (SP EntityID):[copy the SPIDENTITYID URL from SSO tab from the Reetro]

3- Select "Name ID format": EmailAddress

4- Select "Application username": Email

5- In the "Attribute Statements (Optional)" section, add the following entries firstName [Unspecified] user.firstName

lastName [Unspecified] user.lastName

email [Unspecified] user.email

 
okta integration  
 

6- Press Finish

 

Now you need to download the certificate from OKTA and copy the values needed for configuration in Reetro.

1- Click on the Credentials Details

2- Copy the values from “Identity Provider Single Sign On URL”

3- Copy the value from “Identity Provider Issuer”

4- Click on “Download certificate”

 
okta integration  
 

STEP_3: Configuring Single Sign On in Reetro

 

1 :In Reetro Go to left menu and click on “Admin Controls”

2 : Click on “Single Sign On” tab

3 : Add a friendly name

4 : Add IDP Entity URL from above step

5 : Add “Login SSO URL” from the above step

6 : Add “Logont SSO URL”

7 : Copy the contents for Certificate in “Signing Certificate” text box

8 : Click Save

okta integration  
 

How to test

- Go to the login page and click SSO Login

-Type email in SSO login page.

-Fill out credential on OKTA login page. If it is correct, you will be logged in the website automatically.

 
 

ONELOGIN SSO INTEGRATION

 

In order to configure OneLogin integration with Reetro follow the steps below.

 

Requirements

 

You must be an admin in your Reetro Organization account

You must be an admin in OneLogin

 

STEP_1:Open Single Sign on Settings in Reetro

 

- Logon to Reetro and on the left menu go to “Admin Controls”

 

- On the “Admin Controls” click on the Single sign on tab

 

- Leave this window open for the moment - we'll need this information to complete configuration of the reetro app in OKTA.

okta integration  

STEP_2: Configure Single Sign On in OneLogin

 

- Open OneLogin dashboard in new tab or window

- In your OneLogin admin dashboard, Click on applications

-Create app and provide name details

 
okta integration  
 

-Click on Add app

 
okta integration  
 

- Search the SAML app

 
okta integration  
 

-SAML Test Connector (Advanced)

-Create app and provide name details

 
okta integration  
 

Now go to configurations

Now copy paste the urls from Reetro configuration page to onelogin on following fields

 
okta integration  
 
 

Add the /callback after each url

Now go to the Parameters

And add following parameters

Nameid ,email, firstName, lastName

 
okta integration  
 

While adding parameters remember to check mark the (add SAML insertion check box ) for each parameter

For name id

 
okta integration  

For field email

 
okta integration  

For firstName

 
okta integration  

For firstName

 
okta integration  

Click SAVE

Download the IdP metadata file - MORE ACTIONS > SAML Metadta soon you will need this.

okta integration  

STEP_3: Configuring Single Sign On in Reetro

 

1 :In Reetro Go to left menu and click on “Admin Controls”

2 : Click on “Single Sign On” tab

3 : Add a friendly name

4 : Add IDP Entity URL from above step

5 : Add “Login SSO URL” from the above step

6 : Add “Logont SSO URL”

7 : Copy the contents for Certificate in “Signing Certificate” text box

8 : Click Save

okta integration  
 

How to test

- Go to the login page and click SSO Login

-Type email in SSO login page.

-Fill out credential on OKTA login page. If it is correct, you will be logged in the website automatically.

 
 

GOOGLE GSUITE SSO INTEGRATION

 

In order to configure Google GSuite integration with Reetro follow the steps below.

 

STEP_1: Configure Single Sign On in Gsuite

 

- Login to your G-suite as admin

- This menu is shown select the Admin

 
glogin integration  
 

-Select -> apps -> SAML apps

 
gsuite integration  
 

-Click on Add apps

 
reetro sso integration  
 

-Click on add custom SAML app

 
SAMP app  
 

Create app

 
create app  
 
 

Use these credentials to copy into reetro.io

 
reetro copy credentials  
 

SSO URL and entity id into reetro

 
reetro sso url  

Now copy these urls into G-suite

 
gsuite reetro  

Paste it here

reetro glogin integration  

Add NAME ID AS EMAIL

glogin sso name integration  

Now add attributes

reetro sso attributes   
email sso attribute  

Now enable the app for available to all domain users

glogin sso domain  
sso domain  

Now test the app if the connection works

reetro glogin sso integration  
 

AZUREAD SSO INTEGRATION

 

In order to configure AzureAd integration with Reetro follow the steps below.

 

STEP_1: Configure Single Sign On in AzureAd

 

- Go to AzureAD Account -> Go to All Services-> Select Enterprise Applications-> Browse Azure AD Gallery (ppreview) -> Select Add and application

 
AzureAd integration  
 

Create the as defined in above step now after creating the app go to right menu of option list of that app Overview as shown in below screenshoot

 
gsuite integration  
 

Now from the Overview screen select the option as shown in above screen Select ( Set up single sign on )

 
reetro sso integration  
 

Now from above screen select the ( SAML ) The saml will open the all the settings as shown in below screen

 
SAMP app  
 

Here in above screenshot fill up the required fields as shown as red color marked click on it and fill these fields from the Reetroapp -> SSO tab-> the urls of “SP Identity ID” and login URL and logout URL

Copy Reetro field of ( SP Identity ID ) and Paste it in AzureAD field: Identifier (Entity ID)

Copy Reetro field of ( login URL) and Paste it in AzureAD field: Identifier (Reply URL)

Copy Reetro field of ( logout URL) and Paste it in AzureAD field: Identifier (logout url)

While copying login url and logout url field from reetro to Azure AD, Please also add /callback to the end of url

E.g

Reetro Login URL: https://www.reetro.app/60270bexxxxxxxxxxxxxx/api/saml/login

Add ( /callback ) when pasting it in Azure AD

Check the following screenshot

 
create app  
 
 

Now successfully copy/pasting urls correctly now check the next step

 
reetro copy credentials  
 

It will look like this when Basic SAML configuration is filled in above screen.

Now set the attributes by going to (User Attributes and Claims) option as shown in

Above screen click the (Edit button)

After opening the edit screen the below screen will be shown

 
reetro sso url  

Now Click on the (Add new claim) and fill it as it is shown in (Additional Claims and value)

Claim name: Email Value: user.mail

Claim name: firstName Value:user.givenname

Clain name lastName Value:user.surname

Put all these new claims and remove all others make sure it looks like as in screen above

After this step now copy/download the Certificate and paste it in Reetroapp -> SSO page -> Signing certificate field

Download the certificate as (Certificate (Base64)) then open it -> copy it-> paste it at Reetroapp -> SSO page -> Signing certificate field

reetro glogin integration  

Now follow the Step 4 from the above screen

Copy AzureAD field: Login URL and paste it Reetro field of ( Login SSO URL)

Copy AzureAD field: Azure AD identified and paste it Reetro field of (IDP Entity URL)

Copy AzureAD field: Azure AD identified and paste it Reetro field of ( Logout SSO URL )

And successfully copy pasting it press save changes in Reetro app as in below screen

glogin sso name integration  

Now add the users for this app

reetro sso attributes   

Once users are added -> Now go again to Signle sign on-> and test the connection

glogin sso domain