Broadcom is standardizing the authentication URL for Broadcom platforms from avagoext.okta.com to login.broadcom.com. The primary goal for enabling custom URL in the avagoext.okta.com tenant is to provide the ability to customize the Okta hosted login page and change to a Broadcom branding. Broadcom is working to ensure that the migration is as seamless as possible. There are a few simple actions that will be required from our customers due to this standardization. Below you will find instructions on how to update your configuration with the new URL (login.broadcom.com) and the impact if you do not take the appropriate action.
This knowledge article provides generic guidelines on changing the Assertion Consumer Service (ACS) URL. Please consult your Identity Provider (IdP) vendor documentation or Single-Sign On (SS)/IT team for detailed steps needed to modify the ACS URL.
The change is required on or after Sunday March 14th 2021.
The change can be performed in a sandbox environment (your DEV or TEST environment) first before promoting to Production.
Failure to test and make any required configuration changes in response to the Federated SSO user authentication may result in some or all of your Clarity SaaS users from being able to access the service. Any such interruptions to service access will not be considered for your uptime SLA
Customers that do not make the change to their ACS URL will notice the following:
Your end users will continue to be able to access the Clarity SaaS service till 60 days since March 13, 2021 after which they can experience service disruption. Access to other services and Broadcom resources, such as Broadcom Support, will be disrupted after March 13, 2021 until the change is made.
Customers can always continue to contact Broadcom support
The only change needed on customer IDP is to add a new Assertion Consumer Service (ACS) URL to the existing ACS list or update the Assertion Consumer Service (ACS) URL. ACS is the Broadcom OKTA Clarity service provider's endpoint (URL) that is responsible for receiving and parsing a SAML assertion from customer IDP. Depending on the IDP vendor customer is using, the ACS URL field could be labeled as Single Sign On URL, or Reply URL.
The following steps need to be performed by SSO Administrators.
https://avagoext.okta.com/sso/saml2/0oa1dqivx15iBsjgp1d8
After change the updated field should look like following for this example SP ID. Your IDP screen might differ but the two ACS URLs should be displayed in the list. Please note that only hostname is the only difference in these two ACS URLs.
Note: Do not delete existing ACS URL
b. If IDP does not permit adding multiple ACS URLs, Replace https://avagoext.okta.com with https://login.broadcom.com in the ACS URL field.
After change the updated field should look like following for this example SP ID: https://login.broadcom.com/sso/saml2/0oa1dqivx15iBsjgp1d8
All Broadcom GCP SaaS Customers using Federation Single Sign On
This informational is intended to provide a generic, non-exhaustive guideline on changing ACS URL for your specific IDP vendor. Please consult your IDP vendor documentation for detailed steps needs to add or modify the ACS URL.
Vendors:
Note: Do not delete existing ACS URL
Note: Do not delete existing ACS URL
3. Open the "End Points" tab. Copy the existing SAML ACS URL that starts with https://avagoext.okta.com/sso/saml..
6. Press “OK” to see the list of ACS URLs. There should be two ACS URLs listed
7. Save the Configuration and validate end user access to Clarity
8. If there is a problem accessing Clarity after the change, reverse the change and contact Broadcom Support
Note: Do not delete existing ACS URL
Note: The new ACS URL will be same as existing one other than the host name part should be changed from https://avagoext.okta.com to https://login.broadcom.com
If login to Broadcom support site prompts a user for credentials after the user is logged to Clarity PPM via federated authentication, following steps can be taken to access support site.