eCase SAML SSO Configuration

Prev Next

Overview

The SAML SSO Configuration page allows system administrators to integrate eCase with an external Identity Provider (IdP) that supports the Security Assertion Markup Language (SAML) 2.0 protocol.

When SAML SSO is enabled, eCase delegates user authentication to the configured IdP, such as Active Directory Federation Services (ADFS), Microsoft Entra ID, Okta, PingFederate, or another SAML 2.0-compliant provider.

eCase has two independent Service Providers (SPs), each requiring its own configuration.

Service Provider

Purpose

User Application

The primary eCase case management web application, used by the end users. The Assertion Consumer Service (ACS) endpoint for this SP is /Saml.aspx on the User Application host.

Admin Application

The eCase Administration console, used exclusively by system administrators to manage platform configuration. The ACS endpoint for this SP is /Saml.aspx on the Admin Application host.

NOTE: When Enable SAML SSO is turned on, both the User Application and Admin Application sections must have all required fields populated. If either section is incomplete, the configuration cannot be saved.

NOTE: Enabling or disabling SAML SSO immediately terminates all active sessions. This includes the session belonging to the administrator who saves the configuration. Plan SAML SSO changes during a scheduled maintenance window or outside peak business hours to minimize disruption.

Prerequisites

The following prerequisites shall be satisfied prior to initiating the SAML SSO configuration in eCase.

Before accessing the SAML SSO Configuration page, the administrator shall obtain the following values from the Identity Provider (IdP) administrator. The table below maps each required value to the corresponding eCase configuration field it populates.

Required Value

Alternate Identifier

eCase Field

SP Entity ID / Issuer

Audience URI; Relying Party Identifier; SP Issuer

Service Provider (User Application and Admin Application sections)

IdP Entity ID / Issuer URL

Federation Service Identifier; Azure AD Identifier; Issuer

Partner Identity Provider

SSO Service URL

SAML Single Sign-On Endpoint; IdP-Initiated SSO URL; Login URL

Partner Service URL

IdP Signing Certificate

Token-signing certificate; Federation certificate (public key)

Partner Certificate File (.cer / .crt / .pem)

SLO / Logout URL

Single Logout Service URL; SAML Logout endpoint

Logout URL

Name ID Format (optional)

NameIDFormat URN — e.g., urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

Name ID Format (leave blank to use IdP default)

NOTE: Two SP registrations are typically required in the IdP; one for the User Application and one for the Admin Application, each with a distinct Entity ID (Issuer). The IdP SSO URL, signing certificate, and logout URL are usually shared across both registrations.

Configuration Checklist

Before proceeding, confirm that the following requirements are complete.

  • The SP Entity ID for the User Application has been determined and registered with the IdP.

  • The SP Entity ID for the Admin Application has been determined and registered with the IdP. This value must be different from the User Application Entity ID.

  • The IdP Entity ID or Issuer URL has been copied exactly from the IdP configuration.

  • The IdP SSO Service URL has been copied and is reachable from the eCase server network.

  • The IdP signing certificate has been exported as a .cer, .crt, or .pem file and does not exceed 5 MB.

  • The IdP Logout or SLO URL has been copied.

  • Both the User Application and Admin Application SP entries have been registered with the IdP, with their respective ACS URLs pointing to the /Saml.aspx endpoint on the correct application host.

  • If request signing is required by the IdP, an SP signing certificate has been exported as a .pfx file and the certificate password is available.

  • A maintenance window has been scheduled because changing the Enable SAML SSO setting terminates all active sessions.

Accessing SAML SSO Configuration

The SAML SSO Configuration page is available in the Admin Web Application.

To access the configuration page, log in to the eCase Admin application and navigate to System Configuration. Select SAML SSO Configuration to manage the SAML SSO Settings. Only users with appropriate administrative permissions can access and manage this page.

Enable SAML SSO

The Enable SAML SSO toggle controls whether eCase uses SAML-based authentication.

When the toggle is enabled, the User Application and Admin Application tabs are available for configuring their respective SAML Service Providers.

At the top of the SAML SSO Configuration page, an Enable SAML SSO toggle is available. By default, the toggle is disabled and field validation is not enforced.

Field

Description

Enable SAML SSO

Activates or deactivates SAML SSO for the entire eCase platform. When ON, all user authentication is delegated to the configured Identity Provider and eCase's built-in credential-based login is suspended. When OFF, eCase reverts to its standard username-and-password login mechanism. Changing the state of this toggle triggers immediate termination of all active user sessions on save.

When the toggle is ON, SAML SSO is enabled, and all the configuration fields become mandatory.

Configure the User Application

Select the User Application tab to configure SAML SSO for the primary eCase case management application.

Step 1: Service Provider

The Service Provider step contains the information that identifies the eCase User Application to the Identity Provider.

Field

Description

Issuer / Entity ID

Enter the Entity ID (Issuer) that uniquely identifies the eCase User Application as a Service Provider within the IdP.

This value must exactly match the Audience URI, Relying Party Identifier, or equivalent value configured for the User Application in the IdP. The value is case-sensitive.

Assertion Service URL

The Assertion Service URL identifies the ACS endpoint where the IdP sends the SAML response after authentication.

For the User Application, the endpoint is the /Saml.aspx endpoint on the User Application host.

Select Download XML MetaData to download the Service Provider metadata.

Select Download Certificate to download the applicable Service Provider certificate.

Advance Settings

Select Advance Settings to display additional Service Provider options.

Field  

Description

SP Single Logout Service (SLO) URL

Enter the Single Logout Service URL for the User Application. This endpoint is used when users sign out and the IdP session also needs to be terminated.

Sign Authentication Request

Enable this option when the IdP requires eCase to digitally sign outbound SAML authentication requests.

Want Assertion Encrypted

Enable this option when the IdP is configured to send encrypted SAML assertions.

Certificate

The Certificate field determines the type of Service Provider certificate used by eCase.

The configuration supports a Serial Number option, as shown in the User Application configuration, and certificate-based configuration options such as PFX Certificate.

When Serial Number is selected, enter the Certificate Serial Number and specify the Certificate Expiration Date.

When a PFX certificate is used, provide the SP signing certificate and the required password.

Field

Description

Signature Certificate

Provide the eCase SP signing certificate in .pfx format when the IdP requires eCase to sign outbound SAML authentication or Single Logout requests.

Signature Certificate Password

Enter the password that protects the PFX certificate.

Signature Certificate Expiration Date

Specify the expiration date of the configured signature certificate.

Use same certificate for encryption

Select this option when the same certificate should be used for encryption.

Field

Description

Encryption Certificate

Provide the certificate used to encrypt SAML assertions when a separate encryption certificate is required.

Encryption Certificate Password

Enter the password associated with the encryption certificate.

Encryption Certificate Expiration Date

Specify the expiration date of the encryption certificate. Select Next to proceed to the Identity Provider step.

Step 2: Configure the User Application Identity Provider

The Identity Provider step contains the information required to connect the eCase User Application to the external IdP.

Field

Description

Upload Metadata XML Here

Select the Metadata XML that you wish to upload.  

Identity Provider Entity ID

Enter the Entity ID or Issuer URL provided by your Identity Provider. This value must match the Issuer value contained in the SAML responses sent by the IdP. Any mismatch can cause eCase to reject the SAML assertion.

Single Sign ON Service(SSO) URL

Enter the IdP's SAML Single Sign-On Service URL. This is the endpoint to which eCase redirects the user's browser when authentication is initiated.  

 

The URL must begin with https:// or http://.

Select Test Connection next to the Partner Service URL to verify that the eCase server can reach the IdP endpoint over the network.

The connection test verifies HTTP reachability only. It does not validate the complete SAML authentication exchange.

NOTE: If the connection test fails, review the IdP URL, firewall rules, proxy configuration, and DNS resolution from the eCase server. The configuration should not be saved until the connectivity test completes successfully.

Advance Settings

Select Advance Settings to display additional Identity Provider settings.

Field

Description

SAML SSO URL Binding Type

Specify the binding type required by the IdP for the SSO service.

Single Logout Service (SLO) URL

Enter the IdP's Single Logout Service URL when applicable.

SAML SLO URL Binding Type

Specify the binding type used by the IdP's Single Logout Service.

Name ID Format

Enter the SAML NameIDFormat value to request from the IdP. If you leave this field blank, eCase does not specify a format preference and the IdP applies its default.

If a specific format is required, enter the complete URN.

Common values include:

urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

urn:oasis:names:tc:SAML:2.0:nameid-format:persistent

urn:oasis:names:tc:SAML:2.0:nameid-format:transient

Signing Algorithm

Select the signing algorithm used for SAML signing. The configuration shown in the provided interface uses SHA-256.

Authentication Context

Enter the authentication context required by the IdP, when applicable.

Authentication Context Comparison

Select the applicable comparison value for the authentication context.

Identity Provider Certificate

The Identity Provider Certificate section contains the certificate information used by eCase to validate SAML responses and assertions received from the IdP.

Field

Description

Signature Certificate Text

Enter or provide the IdP signature certificate information.

Signature Certificate Text Expiration Date

Displays the expiration date associated with the signature certificate.

Encryption Certificate Text

Enter the encryption certificate information when encryption is configured.

Encryption Certificate Text Expiration Date

Displays the expiration date associated with the encryption certificate.

IDP Public Certificate (Upload)

Upload the IdP public certificate used by eCase to verify digital signatures applied to SAML assertions and responses. The accepted file formats are .cer, .crt, and .pem. The maximum file size is 5 MB.

IDP Certificate Expiration Date

Displays the expiration date of the uploaded IdP certificate.

Advance Settings

Select Advance Settings to display the available SAML security options.

Field

Description

Want Assertion Signed

Requires the SAML assertion to be signed.

Want SAML Response Signed

Requires the SAML response to be signed.

Encrypt Logout Name ID

Encrypts the Name ID used during logout.

Force Authentication

Requires authentication to be performed again instead of relying on an existing authentication session.

Sign Logout Request

Sign out from the SAML Single Logout request.

Sign Logout Response

Sign out from the SAML Single Logout response.

Disable In Response To Check

Controls validation of the response correlation value during the SAML response validation process.

Select Next to proceed to Review & Save.

Step 3: Review & Save

The Review & Save step displays a read-only overview of the configured SAML SSO settings before you commit the configuration.

The review displays the configured information for:

Service Provider

The Service Provider section includes the Issuer / Entity ID, Assertion Service URL, Advanced Settings, SP Single Logout Service URL, signing and encryption options, certificate information, passwords, and certificate expiration dates.

Identity Provider

The Identity Provider section includes the uploaded metadata, Identity Provider Entity ID, Single Sign-On Service URL, Advanced Settings, SAML SSO URL Binding Type, SLO settings, Name ID Format, Signing Algorithm, Authentication Context, and Authentication Context Comparison.

Identity Provider Certificate

The Identity Provider Certificate section includes the Signature Certificate Text, certificate expiration information, Encryption Certificate Text, IDP Public Certificate, IDP Certificate Expiration Date, and applicable SAML security settings.

Review the displayed values and select Previous if you need to return to an earlier step and make changes.

NOTE: The Review & Save page displays the configuration for verification. The provided interface indicates that the review must be completed before selecting Save at the top of the page to commit the configuration.

Configure the Admin Application

Select the Admin Application tab to configure SAML SSO for the eCase administration console.

The Admin Application follows the same configuration flow:

Service Provider → Identity Provider → Review & Save

The fields in the Admin Application have the same names, purposes, and validation behavior as the corresponding User Application fields.

Key Differences from the User Application

The Issuer / Entity ID for the Admin Application must be different from the User Application Entity ID.

The Identity Provider treats each Entity ID as a separate registered Service Provider. Using the same Entity ID for both applications prevents the IdP from distinguishing between the two applications and can result in authentication or attribute-mapping failures.

The IdP SSO URL, signing certificate, and logout URL can typically be shared between the User Application and Admin Application when both applications authenticate against the same IdP.

The Admin Application must have its own ACS URL registered with the IdP. The ACS URL must point to the /Saml.aspx endpoint on the Admin Application host.

NOTE: Register the Admin Application as a separate Service Provider in the IdP. If the Admin Application SP registration is missing, administrators may be locked out of the eCase Admin Application after SAML SSO is enabled. Verify that both the User Application and Admin Application SP registrations are complete and functional before activating SSO.

Configure No-PIV / Two-Factor Authentication

Select the Two-Factor Authentication tab to configure a secondary authentication factor for users who cannot authenticate using a PIV or CAC card.

When SAML SSO is enabled, this section is labeled No-PIV Configuration. When SAML SSO is disabled, it is labeled Two-Factor Authentication Configuration.

The configuration operates independently of the SAML SSO toggle. The secondary authentication factor can therefore be enabled regardless of whether SAML SSO is active.

Configure Two-Factor Authentication

Select the Two-Factor Authentication tab to configure an additional authentication factor for users.

Two-Factor Authentication Configuration

Select Enable Two-Factor Authentication to enable two-factor authentication for the eCase application.

When enabled, the Verification Mode field is available for selecting the authentication method. The available option shown in the configuration is Client Certificate (PIV/CAC).

Verification Mode

When two-factor authentication is enabled, select the verification mode that determines how the secondary authentication is performed. Select Client Certificate (PIV/CAC) to configure client certificate-based authentication using a Personal Identity Verification (PIV) or Common Access Card (CAC).

Client Certificate Subject Fields

Enter the X.509 certificate subject field names that eCase uses to match the presented client certificate to a registered eCase user account.

Enter each field name as it appears in the certificate's Subject Distinguished Name. Common values include CN for Common Name and E for Email Address.

Separate multiple field names with a comma.

For example: CN,E

Save and Activate SAML SSO

Complete the configuration and validation steps before activating SAML SSO.

  • Complete all required fields in both the User Application and Admin Application sections.

  • Set the Enable SAML SSO toggle to the ON position.

  • Select Save.

  • Review the confirmation dialog indicating that active sessions will be terminated.

  • Select OK to confirm the change.

eCase saves the configuration and immediately invalidates all active sessions, including the administrator session used to save the configuration. After saving, verify the authentication flow for both applications.

For the User Application, navigate to the eCase User Application login page and confirm that the browser is redirected to the configured IdP. Authenticate with valid IdP credentials and verify that you are redirected to the eCase home page.

For the Admin Application, repeat the authentication process using IdP credentials mapped to a System Administrator account in eCase. Confirm that the administration console is accessible.

NOTE: Before enabling SAML SSO, make sure that at least one local eCase System Administrator account with a known password is available and documented securely.

SAML SSO Configuration Behavior

The effect of saving the configuration depends on the current and new state of the Enable SAML SSO toggle.

Scenario

System Behavior

SAML SSO is turned ON when it was previously OFF

All active sessions are immediately terminated. Users are redirected to the IdP on their next request, and the SAML SSO configuration takes effect immediately.

SAML SSO is turned OFF when it was previously ON

All active sessions are immediately terminated. Users are redirected to the standard eCase credential-based login page on their next request, and the IdP integration is suspended.

SAML SSO remains ON

All active sessions are immediately terminated. The updated IdP configuration takes effect for subsequent login attempts, and users must re-authenticate through the IdP.

SAML SSO remains OFF

No session termination occurs. The administrator remains on the configuration page and receives a success message. The saved values are retained for future use when SAML SSO is enabled.

Frequently Asked Questions

Q. Why does the Test /ion button return “Service URL is not Valid”?

A. This indicates that the eCase server cannot reach the IdP SSO URL over the network.

The connectivity test checks HTTP reachability only; it does not validate the complete SAML protocol exchange.

Verify that the IdP SSO URL is correct, and check firewall rules, proxy configurations, and DNS resolution for the IdP hostname from the eCase server. Also confirm that the correct URL scheme and port are accessible.

Q. Why can users authenticate successfully at the IdP but still cannot access eCase?

A. This can occur when eCase cannot map the IdP identity to the corresponding eCase user account because the Username or Email values do not match.

Verify that the user's Username or Email in eCase exactly matches the identity information sent by the IdP.