The following configurations must be done in order to successfully set up Radancy Hiring Events as a service provider in your identity provider.
1) Point to Radancy's Metadata
Radancy's SAML metadata is found at https://app.brazenconnect.com/sso/saml/metadata.
2) Specify the correct attribute name and format.
Radancy requires all SAML attributes to have the Object Identifier (OID) as the name and uri as the name format.
<saml:Attribute Name="urn:oid:0.9.2342.19200300.100.1.3"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>user@example.com</saml:AttributeValue>
</saml:Attribute>Required fields
| Friendly Attribute Name | OID Attribute Name | Definition |
|---|---|---|
| urn:oid:0.9.2342.19200300.100.1.3 | The preferred or primary email address for the user. Radancy will use the first value it finds in a claim. | |
| givenName | urn:oid:2.5.4.42 | Name strings that are the part of a person's name that is not their surname. |
| surname | urn:oid:2.5.4.4 | The surname or last name of the user. |
Optional fields
Radancy has an OID repository (1.3.6.1.4.1.47993) that defines fields specific to Radancy's system. These are optional fields that do not need to be provided in order to successfully provision a user in Radancy.
To send a value as one of these fields to Radancy, simply make the attribute name the corresponding OID value.
| Friendly Attribute Name | OID Attribute Name | When to use | Definition |
|---|---|---|---|
| userId | urn:oid:1.3.6.1.4.1.47993.1.1.2 | This is needed if the system cannot guarantee that a user's email address will remain the same. | The identifier for this user in the external system. Radancy will use the first value it finds in a claim. |
| ianaTimeZone | urn:oid:1.3.6.1.4.1.47993.1.1.3 | To set the timezone for the user other than the default. | The user's preferred time zone such as "America/New_York". Radancy uses IANA Olson time zone names. If one is not provided, the user's time zone is set to "US/Eastern". Users will have the ability to set a timezone within Radancy. |
See the example below for a valid AttributeStatement in the SAML response.
<saml:AttributeStatement>
<saml:Attribute Name="urn:oid:0.9.2342.19200300.100.1.3"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>user@example.com</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="urn:oid:2.5.4.4"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>Test Last Name</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="urn:oid:2.5.4.42"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>Test First Name</saml:AttributeValue>
</saml:Attribute>
<!-- Optional fields -->
<saml:Attribute Name="urn:oid:1.3.6.1.4.1.47993.1.1.2"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>Test External ID</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="urn:oid:1.3.6.1.4.1.47993.1.1.3"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>America/New_York</saml:AttributeValue>
</saml:Attribute>
</saml:AttributeStatement>3) The NameId format must be persistent
Radancy's SSO configuration requires the NameId format to be persistent. This is a requirement of Radancy's system and cannot be changed.
The NameId can be found within the Subject element in the SAML response.
<saml:Subject>
<saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">
NameId
</saml:NameID>
</saml:Subject>Resources on how to specify a persistent NameId
-
ADFS: ADFS: Sending NameID with Specific Format
- For Outgoing NameId Format, select
persistent(step 15 in the instructions).
- For Outgoing NameId Format, select
-
Okta: How to create a basic custom SAML application using an SP metadata file
- This is shown in step 9. The Name ID format needs to be
persistent.
- This is shown in step 9. The Name ID format needs to be
- Ping: SAML Name ID: persistent format
- Shibboleth: Relying Party Configuration