Configuring Workfront Proof Single Sign-On

If you are a Workfront Proof administrator, you can configure Single Sign-On on the Workfront Proof side. For more information, see Single Sign-On in Workfront Proof.

  1. Click Settings > Account Settings, then open the Single sign-on tab.

  2. In the SSO URL box, paste your Entity ID.
    The following is an example of an Entity ID:
    http://<adfs.your-company.com>/adfs/services/trust
    Your Entity ID can be found in your Federation Metadata XML file.
    ProofHQ_configuration_02.png

  3. Federation Metadata is found in the AD FS 2.0 snap-in > Service > Endpoints folder. In the Metadata section, locate the one with the Federation Metadata type. To view metadata, paste this endpoint in your browser. You can also go to this link directly: https://<adfs.your-company.com>/FederationMetadata/2007-06/FederationMetadata.xml after replacing the {adfs.your-company.com} with your own details.

  4. In the Login URL box, paste your SSO login.

  5. The following is an example of an SSO login:

  6. http://<adfs.your-company.com>/adfs/ls.

  7. This link can be located in the Federation Metadata XML file.
    ProofHQ_configuration_03.png

  8. In the Logout URL box, enter the link and save.
    The following is an example of a Logout URL:
    https://<adfs.your-company.com>/adfs/ls/?wa=wsignout1.0

    1. Go to your AD FS manager > Trust Relationships > Relying Party Trusts - ProofHQ properties.

    2. Under the Endpoints, click Add and entry with the following details:

      • Endpoint Type = SAML Logout
      • Binding = POST
      • URL = https://<adfs.your-company.com>/adfs/ls/?wa=wsignout1.0
      • This step can be completed after configuring the Relying Party Trust (see below) in your AD FS.
    3. In the Certificate fingerprint box, enter the data from your certificate.

    4. Go to your ADFS 2.0 snap-in navigate to Service > Certificates > Token-signing.

    5. Right-click on this entry to view the certificate.

    6. From the Certificate Details tab copy the Thumbprint, and paste it in the Workfront Proof Single Sign-On configuration tab.

    7. The fingerprint characters can be separated with colons or spaces, but we do recommend removing these. If you have any troubles with your Single Sign-On configuration, please contact the Customer Support team.