Efecte Secure Access - Customer instructions for Virtu Authentication
Virtu
Efecte Secure Access - Customer instructions for Virtu Authentication
Virtu
In this article is described instructions for Customer to be able to configure Virtu Authentication to Efecte solutions. This configuration is usually implemented by Customer's Authentication specialist.
Instructions are the same for all Efecte solutions, build on top of Efecte Service Management platform (like for example ITSM, IGA, HR etc.) and which are using Efecte Secure Access component for authentication.
How to Configure Virtu Authentication
Resource Registration
This chapter explains how to add a new Service Provider (SP) service to the Virtu trust network using the Resource Register. The procedure is the same for both test and production servers. The difference is that for production services, the operator will seek Valtor's approval to add the service to the Virtu metadata.
NOTE! This guide contains example images. Use your own company information when registering.
-
Go to https://virtus.csc.fi and select link Add a new Service Provider

- Select right Organization from the dropdown list and Apply changes and return.

- Select SP Basic Information and fill in the information. (Remember that Entity Id must be provided to Efecte for ESA configuration). The Entity Id must be a URI, either a URL or a URN, for example https://domain.com/service. Apply changes and return.
- Select SP SAML Endpoints and fill the information. Apply changes and return.

- Select Certificates and fill the information. Apply changes and return.

- Select Required attributes and fill the information. Apply changes and return.

- Select Contact information and fill the information. Apply changes and return.
- Select Submit SP Description button. The information then goes to the trust network operator and the Valtori for verification. You will receive email when registration is checked.
Certificate requirements
Test
Using self signed certificates is allowed on Virtu test environment.
Production
Certificates for services connecting to production Virtu must be signed by the Finnish Digital and Population Data Services Agency (DVV). The requirement applies to SAML2 certificates, not to TLS certificates.
https://dvv.fi/en/service-certificates-for-organisations
We recommend choosing "system signature certificate" in exchange for "normal server certificate" because the first one is valid for two years as the second only for one year.
The CN of the certificate should indicate for what service it is meant to be used. So please add your service name on it.
We strongly recommend to document how to change saml-certificate on the service side. The certificate must be changed once a year or two depending which type of certificate has been chosen.
DeleteTable of Contents