Citrix SecurSpaces™

SAML

Citrix SecurSpaces™ acts as a SAML 2.0 service provider. Any conformant identity provider works — Okta, Microsoft Entra ID, Ping, ADFS, and others — because the configuration is an exchange of metadata rather than anything provider-specific.

Setting it up is a two-sided task: the identity provider needs to know about SecurSpaces, and SecurSpaces needs to know about the identity provider.

Configure the identity provider

Create a SAML application in your identity provider with the following values, where <your-sds-hostname> is the domain your platform is deployed on:

Setting Value
Single Sign-On URL (Assertion Consumer Service URL) https://<your-sds-hostname>/saml/acs
Audience URI (Service Provider Metadata URL) https://<your-sds-hostname>/saml/metadata

If your identity provider prefers to import metadata rather than take values by hand, SecurSpaces publishes its own service provider metadata. Use Download metadata on the SAML configuration page.

Attributes

The identity provider must send these attributes in the assertion:

Attribute Type What it does
email Required The email the user is registered with on the platform. Without it the connection does not work.
displayName Recommended The name shown for the user across the platform. When it is empty, firstName and lastName are used instead.
firstName Optional Used only when displayName is empty.
lastName Optional Used only when displayName is empty.
uid Optional A unique identifier, usually supplied so a user’s actions can be traced across systems.

Send displayName if you can. Without it the platform assembles a name from firstName and lastName, and if those are absent too, users are identified by email address throughout the console and the audit log.

Sending uid is worth doing wherever audit data is correlated with other systems, because email addresses change and a stable identifier does not.

Configure SecurSpaces

  1. Sign in as a platform administrator.
  2. Go to System Configuration > SAML Service Provider Configuration, or browse to https://<your-sds-hostname>/platform/system_configuration/saml_sp.
  3. Select Configure.
  4. Provide the identity provider’s metadata, either as an Identity Provider Metadata URL or by uploading its XML metadata file.

SAML

A metadata URL is the better choice where your identity provider offers one, because certificate rotations are picked up automatically rather than needing the file to be uploaded again.

SAML