How to integrate Blackberry mobile zero sign on into android and iOS apps

Viewed 144

We are trying to implement SSO on Android and iOS applications using Blackberry mobile ZSO (Zero Sign On) feature.

We have followed the Blackberry's official document and created a BlackBerry Authentication policy and a service in the BlackBerry Enterprise Identity. But couldn't proceed further. Not sure how to integrate this in Android and iOS apps.

Is it possible to integrate BlackBerry mobile zero sign on into native mobile apps ?

If possible can someone please help us in providing steps to implement it ? Or any tutorial to follow ?

Thanks in advance.

1 Answers

If you are using a zero sign on certificate, in iOS you'll use either safariviewcontroller or ASWebAuthenticationSession. For android, use Chrome CustomTabs.

The following links explain how this is configured in BlackBerry UEM. NOTE: devices must be managed to deliver the zso cert.

https://docs.blackberry.com/en/id-comm-collab/blackberry-enterprise-id/latest/blackberry-enterprise-identity-administration-html/lfj1478021944976/ftp1502891582419/nxa1502891731577

https://docs.blackberry.com/en/development-tools/blackberry-dynamics-sdk-ios/7_1/blackberry-dynamics-sdk-ios-devguide/Integrating-optional-features/Using-ZSO-for-SaaS-services-through-BlackBerry-Enterprise-Identity

Once you have configured EID with SAML, configured their app server to use EID an sp-initiated flow would look like the following.

  1. Your app should reach out to your app server’s login endpoint (URL).
  2. This app server should locate the EID related metadata (linked from within the SAML service created in EID settings, within BlackBerry UEM).
  3. Your app sever redirects the ASWebAuthenticationSession to the HTTP:POST binding from the metadata.
  4. ASWebAuthenticationSession should hit the endpoint in EID.
  5. EID will lookup the service provider entity ID (entered in EID for this SAML service too). a. This should have mobile zso enabled.
  6. User should be enabled for the custom service in the EID service bubble in their user account.
  7. EID will lookup the auth policy for the user a. The Mobile ZSO auth level should be associated with this app override.
  8. EID will initiate a flow for cert auth.
  9. The ASWebAuthenticationSession should handle the cert auth.
  10. EID will redirect the ASWebAuthenticationSession back to the Assertion consumer service POST URL (configured in EID, to match with their service) with a signed SAML assertion (signed with the IdP signing key).
  11. Your app server will verify the SAML assertion using the public key (from the metadata)
  12. Your app server will authorize the authenticated user
  13. Your app server will send ASWebAuthenticationSession a redirect back to their app with whatever your app should use as a token.
Related