SAML authentication allows users to log in to Coverity on Polaris using an
identity provider's single sign-on (SSO) authentication service. The organization administrator
is responsible for enabling SAML authentication. SAML (Security Assertion Markup Language) is a
standard for messages between service providers (like Coverity on Polaris) and identity
providers like Okta to support user authentication.
Enabling SAML authentication requires the following.
- The service provider gives information about itself to the identity provider.
- The identity provider gives information about itself to the service provider.
In the present case, the service provider is Coverity on Polaris, and the
identity provider is any provider that implements SAML 2.0 authentication. When each party
has valid information about the other, SAML authentication is enabled, and the user can sign
in using whatever password authenticates them in their normal work context, without having
to create a special password for Coverity on Polaris.
Note: Once the Service Provider metadata is updated it takes 10 minutes for the changes to take
effect.
When SAML configuration is complete, users who log in with an email address that has a domain corresponding to the identity provider will be seamlessly passed off to the identity provider to complete logging in. Users do not have to be explicitly created in Coverity on Polaris; they can be managed in the identity provider solution instead.
Note: Users might not be visible on Coverity on Polaris to the Organization
Administrator until the first time they log in. Information related to a user is transmitted
from the IDP after the first sign-in.