Last updated on February 15, 2024
Overview
The purpose of this document is to introduce Rublon Authentication (Rublon Access Gateway) into the G Suite authentication process and enable the Two-Factor authentication process for G Suite users. To be able to achieve that, it is required to create a Rublon Access Gateway application as well as configure several SSO settings on the G Suite administration panel site. All needed steps will be described within this document.
Supported Authentication Methods
Installation
Required Components:
- Rublon Access Gateway
- G Suite account with access to the administrator panel
Download the Rublon Access Gateway certificate
- Sign in to Rublon Access Gateway
- Go to Applications → All applications
- Click the Download Certificate button
- Go into your G Suite SSO settings and add the app to Rublon Access Gateway
Configure G Suite SSO settings
- Login as super admin to G Suite admin console.
- Select Security.
- Choose the Single Sign On tab:
- Fill the required component data from Rublon Access Gateway metadata.
- Check the Setup SSO with third party identity provider checkbox – this will enable and force Single Sign on.
- Copy the SSO URL from Rublon Access Gateway to Sign-in page URL
- Copy the Logout URL from Rublon Access Gateway to Sign-out URL
- In the Verification certificate field, select the Rublon Access Gateway certificate you have downloaded before and upload it.
- Check the Use a domain specific issuer checkbox.
- Save your configuration.
Create a new application in Rublon Access Gateway
- Login into your Rublon Access Gateway instance.
- Open the Applications tab.
- Select the Add application subtab.
- Fill the form with data:
- Application name – will be displayed in the Rublon Admin Console
- Entity ID – google.com/a/your_domain
- Assertion Consumer Service – https://www.google.com/a/your_domain/acs
- Single Logout Service – https://google.com/a/out/tld/?logout
- NameID Format – urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
- NameID attribute– “mail”
- Check Sign response
- Add the previously downloaded certificate from Rublon Access Gateway in the Certificate for singing field
- Click the SAVE button to save the changes.
Check the integration with G Suite
Go to Google account login page
Provide your email, e.g. “username@your_domain” and / or password.
NOTE: You can not use the account with super admin privileges.
Provide your login and password
Choose one of the available methods to complete Rublon second factor authentication
Get access to your Google account
Troubleshooting
If you encounter any issues with your Rublon integration, please contact Rublon Support.