ShareFile - SSO Configuration

ShareFile - SSO Configuration

Idea
This documentation has been tested and approved by Kelvin Zero's Team. 
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for ShareFile using Multi-Pass. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with ShareFile, ensure you meet the following requirements:
- ShareFile admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in ShareFile are registered in your IdP and have the necessary permissions to access ShareFile.
Important: Custom elements in URLs (like tenant names) are case sensitive. Make sure to match the exact casing from your environment.





ShareFile - SSO configuration





Step 1 - Configure ShareFile as the Service Provider (SP)

  • Log into ShareFile as an Administrator
  • Navigate to Settings > Admin Settings > Security > Login & Security Policy
  • Scroll down the page to Single sign-on/SAML 2.0 Configuration
  • Select Yes on Enable SAML

Step 2 - Configure Multi-Pass as the Identity Provider (IdP)

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations, click on Applications.
  • Select SAML in the custom integration section.

  • Complete the SAML setup with the following information:
FieldValue
Client ID (=SP Entity ID)https://<SHAREFILE-SUBDOMAIN>.sharefile.com
NameShareFile
DescriptionShareFile SSO integration
Assertion Consumer Service URLhttps://<SHAREFILE-SUBDOMAIN>.sharefile.com/saml/acs
NameID Policy Formatemail
  • Under Tenant Certificate toggle the first box to Text and click Copy contents.
  • Copy and paste the certificate into a Notepad file.

  • Click Add integration.
  • Click Advanced Console.

  • Click Clients and search for ShareFile.
General settings
FieldValue
Client IDhttps://<SHAREFILE-SUBDOMAIN>.sharefile.com
NameShareFile
DescriptionShareFile SSO integration
Always display in UION
Access settings
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIs (ACS)https://<SHAREFILE_SUBDOMAIN>.sharefile.com/saml/acs?idpentityid=https://ca.auth.kzero.com/realms/<TENANT>
IDP-Initiated SSO URL Name<APP_NAME>
Valid post logout redirect URIshttps://<SHAREFILE-SUBDOMAIN>.sharefile.com/saml/acs
SAML Capabilities
SettingValue
Name ID Formatemail
Force Name ID FormatON
Force POST BindingON
Include AuthnStatementON
Signature & Encryption
SettingValue
Sign DocumentsOFF
Sign AssertionsON
  1. Now that you have checked the different parameters, change to the tab called “Keys”.
    1. Make sure that both parameters are switched to OFF.

  1. Now go to the “Advanced” tab.
    1. The field “Assertion Consumer Service POST Binding URL” must equal the Valid Redirect URIs (ACS).

Step 3 — Complete configuration of ShareFile as a Service Provider (SP)

  • Log into ShareFile as an Administrator
  • Navigate to Settings > Admin Settings > Security > Login & Security Policy
  • Scroll down the page to Single sign-on/SAML 2.0 Configuration
FieldValue
ShareFile Issuer/Entity IDhttps://<SHAREFILE_SUBDOMAIN>.sharefile.com
Your IDP Issuer/Entity IDhttps://ca.auth.kzero.com/realms/<YOUR_TENANT>/
Login URLhttps://ca.auth.kzero.com/realms/<YOUR_TENANT>/protocol/saml

  1. Under X.509 Certificate copy and paste the certificate you stored in the Notepad.
    1. Ensure you include the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----.
  2. Under Optional Settings select the below values
FieldValue
Require SSO LoginYes
SP-Initiated SSO certificateHTTP Redirect with no signature
Enable Web AuthenticationYes
SP-Initiated Auth ContextUser Name and Password + Exact

  1. Click Save
    • Related Articles

    • Mulesoft - SSO Integration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Mulesoft using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • D2L Brightspace - SSO Integration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • Miro - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Miro using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Pipedrive – SSO configuration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Pipedrive using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • Checkpoint - SSO Configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Checkpoint using MPAS. SSO simplifies user authentication by allowing access to multiple ...