How to enable Single-Sign-On (SSO) with Cisco DUO and OpenID Connect
To enable Single Sign-On (SSO) with Cisco DUO you will need to configure Crewmojo using the generic OpenID Connect integration and Cisco DUO with the "Generic OIDC Relying Party - Single Sign-On"
This guide assumes you already have a configured Cisco DUO account with an Authentication Source for Single Sign-On and users to test with.
The users from Cisco DUO must have accounts in Crewmojo. This is usually synced from your HRIS or Payroll system. Please ensure this is set up before turning on SSO.
Cisco DUO Set Up
In the admin portal for DUO. Navigate to Applications > Protect an Application. Find "Generic OIDC Relying Party" from the list and click "Protect".
If you don't see "Protect" it is because your DUO authentication source is not properly configured.
The Metadata section is generated by DUO. You will need this later for the Crewmojo side of the set up.