[Yandex Cloud documentation](../../../../index.md) > [Yandex Identity Hub](../../../index.md) > [Tutorials](../../index.md) > [Setting up single sign-on (SSO) for apps](../index.md) > Time > SAML

# Creating a SAML app in Yandex Identity Hub for integration with Time

[Time](https://time-messenger.ru/) is a corporate messenger with single sign-on support based on the [SAML](https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language) standard.

For your [organization's](../../../concepts/organization.md) users to be able to authenticate to Time via SAML SSO, create a [SAML app](../../../concepts/applications/saml.md) in Yandex Identity Hub and configure it both in Yandex Identity Hub and Time.

SAML apps can be managed by users with the `organization-manager.samlApplications.admin` [role](../../../security/index.md#organization-manager-samlApplications-admin) or higher.

To provide your organization's with access to Time:

1. [Generate a key and certificate](#generate-key-cert).
1. [Create an app](#create-app).
1. [Set up the integration](#setup-integration).
1. [Add users](#add-users).
1. [Make sure the application works correctly](#validate).

## Generate a key and certificate {#generate-key-cert}

To encrypt and sign SAML responses, Time requires the service provider's (SP) certificate and private key. Generate it using `openssl`:

```bash
openssl req -x509 -newkey rsa:2048 \
  -keyout private.key \
  -out certificate.crt \
  -days 365 -nodes \
  -subj "/CN=<instance_name>.time‑messenger.ru"
```

Where `<instance_name>` is the name of the Time instance (subdomain on `time‑messenger.ru`).

This will create two files: `private.key` and `certificate.crt`. Save them, as you will need them when setting up SAML in Time.

## Create an app {#create-app}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, select ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps**.
    1. Click ![Circles3Plus](../../../../_assets/console-icons/circles-3-plus.svg) **Create application** and do the following in the window that opens:
        1. Select the **SAML (Security Assertion Markup Language)** single sign-on method.
        1. In the **Name** field, specify a name for your new app: `time‑saml‑app`.
        1. Optionally, add a description and [labels](../../../../resource-manager/concepts/labels.md) for the app.
        1. Click **Create application**.
    1. On the **Overview** tab, under **Application certificate**, click **Download certificate** and save the `time‑saml‑app.cer` certificate you created, as you will need it when setting up SAML in Time.

{% endlist %}

## Set up the integration {#setup-integration}

To configure Time integration with the SAML app you created in Yandex Identity Hub, complete the configuration both on the Yandex Identity Hub side and in Time.

### Configure endpoints and upload the service provider certificate {#sp-endpoints}

Provide your Time instance details. To find the endpoint values, go to the Time system console at `https://<instance_name>.loop.ru/admin_console/authentication/saml` and copy the values ​​of the `Entity ID` and `ACS URL` fields from the SAML settings.

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, click ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `time‑saml‑app`.
    1. At the top right, click ![pencil](../../../../_assets/console-icons/pencil.svg) **Edit** and in the window that opens:
        1. Under **Service provider (SP) configuration**:
            1. In the **SP EntityID ** field, enter `Entity ID`, the unique service provider ID.
            1. In the **ACS URL** field, enter `ACS URL`, the address to which the service provider will send requests for user authentication.
            1. Optionally, add more `ACS URL` by pressing **Add URL** if needed.
            1. Optionally, in the **SP Logout URL** field, add the address to which the IdP will send the SAML response after the user successfully logs out.
            1. In the **Signature mode** field, select which parts of the SAML response will be signed:

                * `Assertions`: Only statements about the user (ID, attributes, authentication time) are signed.
                * `Response`: The entire SAML response is signed.
                * `Assertions and Response`: Both the statements and the entire response are signed.
        1. Optionally, to only accept requests signed by one of the added certificates, enable **Only accept signed requests** and add the certificate using **Add certificate**.
        1. To ensure that the SAML response is encrypted using the selected certificate, enable **Encrypt assertion in response** and add the previously created certificate using **Add certificate**.
        1. From the **Data encryption algorithm** list, select **RSA-OAEP-SHA256 (recommended)**.
        1. From the **Key encryption algorithm** list, select **RSA-OAEP-SHA1**.
        1. Click **Save**.

{% endlist %}

### Configure user attributes {#user-attributes}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, click ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `time‑saml‑app`.
    1. Navigate to the **Attributes** tab.
    1. Add an attribute to provide the username. At the top right, click **Add attribute** and in the window that opens:
        * In the **Attribute name** field, enter `username`.
        * In the **Value** field, select `SubjectClaims.preferred_username`.

        {% note info %}
        
        Use transformations to change the attribute value before sending it to the application, e.g., to convert text to lower case, remove spaces, or extract part of the row. Transformations apply one by one, from top to bottom.
        
        {% endnote %}

        * Click **Add transformation** and select the `ExtractBefore` transformation type; in the **Substring** field, enter `@`. This transformation will extract the part of the email address up to the `@` char. This value will be used as the username in Time.
        * Click **Add**.

{% endlist %}

### Set up SAML authentication in Time {#setup-sp}

1. Log in to the Time system console at `https://<instance_name>.time‑messenger.ru/admin_console/authentication/saml`.
1. Under **Authentication**:
   1. Enable the **Enable SAML 2.0 login** option.
   1. In the **Identity provider metadata URL** field, enter the address to which Time sends its request for metadata.

      {% cut "How to find the address of an application's metadata file" %}

      1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
      1. In the left-hand panel, navigate to ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `time‑saml‑app`.
      1. Under **Identity provider (IdP) configuration**, copy the **Metadata URL** field value.

      {% endcut %}

   1. In the **SAML SSO URL** field, enter the address to which Time sends the SAML request to start the login sequence.

      {% cut "How to find the address for authentication requests" %}

      1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
      1. In the left-hand panel, navigate to ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `time‑saml‑app`.
      1. Under **Identity provider (IdP) configuration**, copy the **Login URL** field value.

      {% endcut %}

   1. In the **Identity provider issuer URL** field, enter the address used for SAML requests.

      {% cut "How to find the publisher address of an account provider" %}

      1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
      1. In the left-hand panel, navigate to ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `time‑saml‑app`.
      1. Under **Identity provider (IdP) configuration**, copy the **Issuer / IdP EntityID** field value.

      {% endcut %}

   1. Under **Certification authority public certificate**, upload the `time‑saml‑app.cer` certificate file.
   1. Enable the **Signature verification** option.
   1. In the **Login address via service provider** field, enter an address in the following format: `https://<instance_name>.time‑messenger.ru/login/sso/saml`. Duplicate this address in the **Service provider ID** field.
   1. Enable the **Enable encryption** option.
   1. Under **Service provider private key**, upload the `private.key` file.
   1. Under **Service provider public certificate**, upload the `certificate.crt` file.
   1. In the **Signature algorithm** list, select the `RSAwithSHA512` algorithm to sign the request.
   1. In the **Canonicalization algorithm** list, select `Exclusive XML Canonicalization 1.0 (skip comments)`.
   1. In the **Email attribute** field, enter `emailaddress`.
   1. In the **Username attribute** field, enter `username`.
   1. Optionally, in the **Name attribute** field, specify `givenname`, the attribute to populate the username in Time.
   1. Optionally, in the **Last name attribute** field, specify `surname`, the attribute to populate the user last name in Time.
   1. Optionally, in the **Login button text** field, enter the text that will appear on the login button on the login page. The default is `Using SAML`.
1. Click **Save**.

## Add users {#add-users}

To authenticate with Time, add the required users and/or [user groups](../../../concepts/groups.md) to your Yandex Identity Hub SAML application.

{% note info %}

Users and groups added to a SAML application can be managed by a user with the `organization-manager.samlApplications.userAdmin` [role](../../../security/index.md#organization-manager-samlApplications-userAdmin) or higher.

{% endnote %}

To add users to a SAML application:

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, select ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select the required app.
    1. Navigate to the **Users and groups** tab.
    1. Click ![person-plus](../../../../_assets/console-icons/person-plus.svg) **Add users**.
    1. In the window that opens, select the required users.
    1. Click **Add**.

{% endlist %}

{% note tip %}

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use [authentication policies](*authentication_policies).

{% endnote %}

[*authentication_policies]: Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see [Authentication policies in Yandex Identity Hub](../../../concepts/authentication-policy.md).

## Make sure your application works correctly {#validate}

To ensure your SAML application and integration with Time are working correctly, log in to Time using one of the added users. Proceed as follows:

1. In your browser, open the login page of your Time instance: `https://<instance_name>.time‑messenger.ru`.
1. Select **Using SAML** to sign in.
1. Authenticate in Yandex Cloud under a user account from your organization.
1. Make sure you have signed in to Time following a successful authentication.