Setting Up Mist Global SSO
Mist admins who are responsible for multiple users and regional clouds can create a global login.
Once you have a global Mist account, setting it up for global single sign-on (SSO) starts by building out a Mist workspace. That is where you can associate the global account with a domain, Identity Provider (IdP), and Mist users so that multiple users from that domain can all login using the same method and security standards.
As a part of setting up the workspace, you'll need to verify the domain you're going to use. Do this using a DNS record from your domain provider, which can take anywhere from a few minutes to a few hours (and maybe as long as 72 hours, depending on the provider). You'll also be prompted to provide a copy of the security certificate your IdP uses to encrypt web traffic, and to specify the URL that authenticated users will be redirected to.
To create a workspace for setting up global SSO,
Open the Mist login page and click the Workspaces link that appears below the list of organizations.
In the page that opens, click Create New Workspace, and give your workspace a name.
- Open the workspace you just created.
Select "+ Add Domain" to add the domain to the Mist workspace and follow the on-screen instructions for verification. We use DNS records to verify that you are the owner of the domain.
The workspace will show the domain as pending until verification is complete.
After your DNS provider has confirmed the domain, click the three vertical dots next to the domain parameters (as shown in Figure 1) and select Verify Domain from the pop-up menu.
Click + Add Provider to configure your IdP and set up a security certificate:
Name: IdP service provider
Scope: Specify your Mist account type, Organization or MSP
Type: Specify the type of IdP, for example Security Assertion Markup Language (SAML).
Issuer: For the IdP security certificate, specify who issued it.
NameID format: Default is Email.
Signing algorithm: The default is SHA-256, or you can select a different value from the drop-down.
Certificate: Paste the X.509 certificate (that is, the
.pemor.certcode copied from the IdP). The certificate is to verify the authenticity of sign-on responses.SSO URL: Specify the IdP redirect page where you want to send Mist users.
Custom Logout URL: Specify the redirect page you want users to land on after signing out from the Mist portal.
ACS URL (Assertion Consumer Service URL): Specify the IdP location where Mist will send its SAML assertion.
Single Logout URL:
After adding the IdP, link it to the Mist account by selecting the three vertical dots at the end of the IdP parameters row. To add a Mist account, you need to have administrator, or super user privileges for that account.
To subsequently edit or delete your IdP settings, click the three dots to reopen the page.
Only Mist super users can link or unlink an MSP account, and that is only for accounts where they have super user privileges.
(Optional) If other users need to be added to the workspace, click the User tab and then the + Add User button to invite additional users.
Only workspace admins can add, update, or delete workspace users.
Each workspace must have at least one admin, but multiple admins are allowed.
Linking an organization to the IdP requires a Mist admin account for the organization.
Only users with a global SSO account can be invited.
After configuring the workspace and verifying the domain, Mist users within the domain will be redirected to the global SSO page to sign in using the configured IdP. If the global SSO option is unavailable, users can sign in using their regional account.