Source record · tier 2 current vendor documentation
SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration
- Publisher
- Cisco
- URL
- https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/SAML_SSO_deployment_guide/15/cucm_b_saml-sso-deployment-guide-release-15/cucm_m_saml-sso-configuration-1251.html
- Published
- 2025-05-26
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- Cisco documentation; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Cisco strongly recommends CA-signed server certificates for SAML SSO and multiserver certificates where the product supports them. in context
- When exporting metadata the administrator chooses either a system-generated self-signed certificate or the Cisco Tomcat certificate. in context
- The certificate Common Name or Subject Alternative Name must match the FQDN the browser requests. in context
- The browser must be able to resolve both the service provider hostname and the IdP, including the service provider ACS URL the IdP redirects to. in context
- The enable procedure is: System > SAML Single Sign On, Enable SAML SSO, Continue, Next, browse to the IdP metadata file, Import IdP Metadata, Next, select a test user, Run SSO Test, sign in, then Finish. in context
- After selecting SSO mode and certificate, the administrator clicks Export All Metadata and saves the file to a secure location. in context
- If FIPS or Enhanced Security Mode is enabled, set the SSO signing algorithm to SHA256 with 'utils sso set signing-algorithm sha256' on the admin CLI of all Unified CM nodes. in context
- After a server domain or hostname change SAML SSO does not work until new metadata is exported via the recovery URL, uploaded to the IdP and the SSO test is run. in context
- With an IM and Presence Centralized Deployment, metadata is exported and the SSO configuration steps are repeated separately on the standalone IM and Presence publisher node. in context
- With an IM and Presence Standard Deployment, IM and Presence metadata is included in the Unified CM metadata export. in context
- The SSO Login Behavior for iOS enterprise parameter defaults to Use Embedded Browser, and Cisco does not recommend Use Native Browser except in a controlled MDM deployment. in context
- LDAP directory synchronisation is mandatory for SAML SSO: users must be synchronised between the Unified Communications applications and the LDAP directory. in context
- SAML SSO is configured in Cisco Unified CM Administration under System > SAML Single Sign On. in context
- Switching between self-signed and Tomcat certificates, regenerating the Tomcat certificate, or changing cluster configuration regenerates SP metadata, which must be re-uploaded to the IdP. in context
- Cluster wide SSO mode produces a single metadata file that represents the entire cluster. in context
- Per Node SSO mode produces a separate metadata XML file for each cluster node, each needing its own agreement at the IdP. in context
- For cluster wide agreements only, the enable wizard includes a Test for Multi-server tomcat certificates step. in context
- SAML SSO for Unified CM requires NTP synchronisation, and the maximum allowed time difference between the IdP and the Unified Communications applications is 3 seconds. in context
- With per node agreements, the enable process is repeated on each Unified CM node. in context
- Only application users with administrative privileges can use the recovery URL. in context
- The recovery URL is enabled or disabled from the CLI with 'utils sso recovery-url enable' and 'utils sso recovery-url disable'. in context
- The SAML SSO recovery URL is https://<hostname>:8443/ssosp/local/login and bypasses SSO for troubleshooting and administrative tasks such as updating metadata. in context
- The recovery URL does not work for end users, LDAP or local, signing in to the Self Care portal. in context
- Cisco instructs restarting the Cisco Tomcat service before enabling SAML SSO. in context
- The SSO test user must be an LDAP-synchronised user with Standard CCM Super User permissions. in context
- Before and after enabling or disabling SAML SSO, restart Cisco Tomcat with 'utils service restart Cisco Tomcat' on all Unified CM and IM and Presence cluster nodes where SSO runs. in context
- When IdP metadata changes, sign in through the recovery URL, choose System > SAML Single Sign On, click Update IdP Metadata File, import the new file, run the SSO test with a Standard CCM Super User and click Finish. in context
- Updating IdP metadata in cluster-wide mode restarts the Cisco Tomcat, Cisco SSOSP Tomcat and Cisco UDS Tomcat services on all cluster nodes. in context
Cite this source record
APA
WarmTransfer. (2025, May 26). SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cucm-saml-sso-dg-15-configuration
BibTeX
@misc{warmtransfer-cisco-cucm-saml-sso-dg-15-configuration,
title = {SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration},
author = {{WarmTransfer}},
year = {2025},
url = {https://warmtransfer.net/knowledge/sources/cisco-cucm-saml-sso-dg-15-configuration},
note = {Cisco, accessed 2026-09-25}
}