Canvas supports a SAML-based single sign-on (SSO) service for its web-based
application that you can configure in your RapidIdentity portal. These
configuration settings are an example and may vary for individual
configurations.
Requirements
- Canvas administrator credentials
- Access to your RapidIdentity administrator portal
- In Canvas, navigate to and select Authentication from the
navigation menu.
- Configure the following SAML settings:
| Setting | Value |
|---|
| IdP Entity ID | RapidIdentity Entity ID |
| Log On URL | RapidIdentity Base URL |
| Log Out URL | RapidIdentity Logout URL |
| Certificate Fingerprint | RapidIdentity Certificate Fingerprint |
| Login Attribute | NameID |
| Strip Domain From Login Attribute Value | true |
| Identifier Format | urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
| Authentication Context | No Value |
| Message Signing | RSA-SHA256 |
- Record the Canvas SAML Entity ID URL and Direct Login URL for your
RapidIdentity configuration.
- Navigate to your RapidIdentity administrator portal.
- From the module selector, choose Configuration.
- Select .
- Click , then click Create SAML Relying Party.
- In the General section, set the following:
- Name: Canvas SAML SSO
- Description: SAML configuration for Canvas LMS
- Metadata: Paste the Canvas metadata.
- In the Attribute Mapping section, click Add New Attribute
+ and set the following options:
- Select New Attribute Type: Name ID
- LDAP Attribute:
mail - Name Format Friendly Name: Email Address
- Click Create, then click
Save.
- Click Trigger Service Reload.
RapidIdentity and Canvas are now integrated, allowing users to authenticate to
Canvas with their RapidIdentity credentials.