# SAML SSO with G Suite

**URL:** <https://forum.mautic.org/t/saml-sso-with-g-suite/12746>\
**Category:** Product Support\
**Created:** [February 13, 2020, 1:30pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746 "2020-02-13T13:30:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![acremonezi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/acremonezi/32/1681_2.png) [@acremonezi](https://forum.mautic.org/u/acremonezi)\
**Post date:** [February 13, 2020, 1:30pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/1 "2020-02-13T13:30:58Z")

</div>

My Mautic version is: 2.15.3  
My PHP version is: 7.0.33-0+deb9u6

**I am not able setup Mautic SAML SSO with G Suite.**

I have setup SAML on G Suite and it provides to me two files as following.

1 - GoogleIDPMetadata.xml  
2 - GoogleIDPCertificate.pem

These two files above I can load with no problem on Mautic. But Mautic asked me more two information such as:

3 - Private key  
4 - Private key encryption password

To better clarify it, I have taken a screenshot, please have a look at: [https://pasteboard.co/IUuIrXK.png](https://pasteboard.co/IUuIrXK.png)

**My doubt is: What should I load on item 3 and 4 above?**

Thanks in advanced.

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [February 13, 2020, 2:08pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/2 "2020-02-13T14:08:05Z")

</div>

Hello @acremonezi, welcome to the Mautic Community Forums!

Does the documentation here: [Authentication | Mautic](https://www.mautic.org/docs/en/authentication/saml.html) help at all?

See particularly:

> 1. `Verify request signatures` or a SSL certificate - **If the IDP supports encrypting and validating request signatures from Mautic to the IDP** , generate a self signed SSL certificate. Upload the certificate and private key through Mautic’s Configuration → User/Authentication Settings under the `Use a custom X.509 certificate and private key to secure communication between Mautic and the IDP.` section. Then upload the certificate to the IDP.

So it seems this part is not mandatory, but if they support encryption then you need to generate the self-signed certificate and upload the private key in those parts.

---

<div class="post-metadata">

**Author:** ![acremonezi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/acremonezi/32/1681_2.png) [@acremonezi](https://forum.mautic.org/u/acremonezi)\
**Post date:** [February 13, 2020, 3:29pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/3 "2020-02-13T15:29:50Z")

</div>

hi! @silavapi, thanks for your prompt repply.

I have read this documentation and follow it, I have used that to set it up, this item 5 you mension specially, was not enough to me, I suspected this may not be necessary, but even though its caused me doubts specially with usuing G Suite.

Assuming that the (3 - Private key and 4 - Private key encryption password) are not necessary the problem may be on G Suite setup.

I have done this screenshot of my G Suite setup, please access it here: [https://pasteboard.co/IUvxQ8O.png](https://pasteboard.co/IUvxQ8O.png)

**Could you please tell me if you are able to clarify my doubts on this setup?**

Thanks so much in advanced.

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [February 13, 2020, 4:00pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/4 "2020-02-13T16:00:43Z")

</div>

Based on your screenshot, I believe the ACS field needs to be:

> [https://your-mautic.com/s/saml/login\_check](https://your-mautic.com/s/saml/login_check)

(according to point 3 on the Mautic docs)

The check box is whether or not to use the signing, which we are at this point not using (if you’re not providing the private key etc)

I believe the Name ID type should be Email, based on what you have chosen.

The mapping looks correct per this from the documentation:

> 1. `Custom attributes` - Mautic requires 3 custom attributes that must be included in the IDP responses for the user email, first name and last name.

So maybe if you fix the URL in the ACS field and give it a go? I don’t know about the start URL but it seems to be optional so maybe leave it blank?

---

<div class="post-metadata">

**Author:** ![acremonezi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/acremonezi/32/1681_2.png) [@acremonezi](https://forum.mautic.org/u/acremonezi)\
**Post date:** [February 13, 2020, 5:38pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/5 "2020-02-13T17:38:31Z")

</div>

Hi! @silavapi, again thanks for your support, your guidance was very important to me.

**Thanks a lot, with you help, I could solved it.**

In order to help other people that may need it, I have made the screenshot bellow to clarify what was the steps done on G Site and Mautic in order to have it working.

Please, access it here: [https://pasteboard.co/IUwnGjm.png](https://pasteboard.co/IUwnGjm.png)

Thanks again and best regards,

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [February 13, 2020, 8:09pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/6 "2020-02-13T20:09:51Z")

</div>

Glad to hear you got it solved! You can add an image to your forum post just by dragging it into the editor, FYI 🙂

Thanks for reporting back with the solution!

---

<div class="post-metadata">

**Author:** ![acremonezi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/acremonezi/32/1681_2.png) [@acremonezi](https://forum.mautic.org/u/acremonezi)\
**Post date:** [February 14, 2020, 7:52pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/7 "2020-02-14T19:52:53Z")

</div>

hi! @silavapi, thanks for the information.  
I did not know this, on the next post I will apply this advice.  
Best regards,

---

<div class="post-metadata">

**Author:** ![monkeymon](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/monkeymon/32/692_2.png) [@monkeymon](https://forum.mautic.org/u/monkeymon)\
**Post date:** [December 5, 2020, 3:56am UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/8 "2020-12-05T03:56:39Z")

</div>

Hi,

I have follow all the steps but I’m still getting the following errors.  
**Invalid inbound message destination "[https://xxxxxx.com/s/saml/login\_check](https://xxxxxx.com/s/saml/login_check)"**

[2020-12-05 11:54:43] app.EMERGENCY: Invalid inbound message destination “[https://xxxxxx.com/s/saml/login\_check](https://xxxxxx.com/s/saml/login_check)” {“profile\_id”:“sso\_sp\_receive\_response”,“own\_role”:“sp”,“action”:“LightSaml\Action\Profile\Inbound\Message\DestinationValidatorResponseAction”,“top\_context\_id”:“00000000412d51f5000000005b9dd7af”,“top\_context”:"[object] (LightSaml\Context\Profile\ProfileContext: {\n “root”: “LightSaml\\Context\\Profile\\ProfileContext”,\n “root\_\_children”: {\n “http\_request”: “LightSaml\\Context\\Profile\\HttpRequestContext”,\n “own\_entity”: “LightSaml\\Context\\Profile\\EntityContext”,\n “inbound\_message”: “LightSaml\\Context\\Profile\\MessageContext”,\n “inbound\_message\_\_children”: {\n “deserialization”: “LightSaml\\Model\\Context\\DeserializationContext”,\n “request\_state”: “LightSaml\\Context\\Profile\\RequestStateContext”\n },\n “party\_entity”: “LightSaml\\Context\\Profile\\EntityContext”\n }\n})"}

I’m using the docker version of Mautic, do i need to do anything extra?

---

<div class="post-metadata">

**Author:** ![ilo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ilo/32/1181_2.png) [@ilo](https://forum.mautic.org/u/ilo)\
**Post date:** [April 8, 2022, 2:11pm UTC](https://forum.mautic.org/t/saml-sso-with-g-suite/12746/9 "2022-04-08T14:11:12Z")

</div>

Hi @ [monkeymon](https://forum.mautic.org/u/monkeymon), did you find a solution for this? I am having the same issue. Thanks
