← Back to plugin index

SAML 2.0 Flow IdP

Description

Enables and configures the SAML 2.0 Identity Provider (IdP) for use in the flow-based authentication.

The IdP provides assertions to receiving applications called "SAML Service Providers".

Type name
Saml2FlowIdp
Class
com.airlock.iam.saml2.application.configuration.Saml2FlowIdpConfig
May be used by
License-Tags
SamlIdp
Properties
IdP Entity Settings (idpEntitySettings)
Description
Configures the identity provider (IdP) entity.
Attributes
Plugin-Link
Optional
Assignable plugins
Service Providers (serviceProviders)
Description
The list of supported Service Providers.
Attributes
Plugin-List
Mandatory
Assignable plugins
Authentication Context Mappings (authnContextMappings)
Description

Assertions contain an 'Authentication Context Class Reference' referencing the type or strength of the performed authentication of the user. This can be used by a Service Provider (SP) in order to assess the level of confidence it can put in the assertion.

If configured, the first fulfilled condition defines the final 'Authentication Context Class Reference'. If left empty (or no condition is fulfilled), the logic of the "Default Authentication Context" takes place. (See property description)

Attributes
Plugin-List
Optional
Assignable plugins
Default Authentication Context (defaultAuthnContextUri)
Description

Assertions contain an 'Authentication Context Class Reference' referencing the type or strength of the performed authentication of the user. This can be used by a Service Provider (SP) in order to assess the level of confidence it can put in the assertion.

This property defines the default 'Authentication Context Class Reference' used if no URI can be determined based on the 'Authentication Context Mappings'.

If left empty, the SAML default resolution is used which also honors the requested URI of an SP in the SP-initiated SSO scenario. For IdP-initiated SSO or if no requested 'Authentication Context Class Reference' can be met in SP-initiated SSO, the first URI defined in the IdP extended metadata file is used (see the "Extended Metadata File" property in the IdP entity settings).

The available context classes are configured in the IdP extended metadata attribute "idpAuthncontextClassrefMapping". Only URIs defined by the attribute are valid to be set here.

Attributes
String
Optional
Suggested values
urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol, urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocolPassword, urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorUnregistered, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorUnregistered, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorContract, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract, urn:oasis:names:tc:SAML:2.0:ac:classes:Password, urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport, urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession, urn:oasis:names:tc:SAML:2.0:ac:classes:X509, urn:oasis:names:tc:SAML:2.0:ac:classes:PGP, urn:oasis:names:tc:SAML:2.0:ac:classes:SPKI, urn:oasis:names:tc:SAML:2.0:ac:classes:XMLDSig, urn:oasis:names:tc:SAML:2.0:ac:classes:Smartcard, urn:oasis:names:tc:SAML:2.0:ac:classes:SmartcardPKI, urn:oasis:names:tc:SAML:2.0:ac:classes:SoftwarePKI, urn:oasis:names:tc:SAML:2.0:ac:classes:Telephony, urn:oasis:names:tc:SAML:2.0:ac:classes:NomadTelephony, urn:oasis:names:tc:SAML:2.0:ac:classes:PersonalTelephony, urn:oasis:names:tc:SAML:2.0:ac:classes:AuthenticatedTelephony, urn:oasis:names:tc:SAML:2.0:ac:classes:SecureRemotePassword, urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient, urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken, urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
Authentication URI (customAuthenticationUri)
Description

The URI to start authentication in case of SP-Initiated SSO.

Must only be configured when using a custom SPA.

Relative URIs not starting with a slash are resolved against the current context path.

When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.

Attributes
String
Optional
Example
https://example.com/custom-ui/saml2/init
Example
/custom-ui/saml2/init
Logout URI (customLogoutUri)
Description

The URI to start the logout process in the UI.

This is mainly used in SP-initiated Single-Logout (the logout is started by a Service Provider). In this case, the browser must first be redirected to the UI in order to start the regular logout before being able to finish the SAML 2.0 Single-Logout (SLO).
It is also used in certain error cases where a logout must be performed.

Must only be configured when using a custom SPA.

Relative URIs not starting with a slash are resolved against the current context path.

When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.

Attributes
String
Optional
Example
https://example.com/custom-ui/logout
Example
/custom-ui/logout
Logout Resume URI Pattern (customLogoutResumeUriPattern)
Description

During IdP-Initiated Single-Logout (SLO), the SPA has to send the location where to resume the logout process after SAML 2.0 Single-Logout has been finished using a "Location" URL parameter.

If not configured, the standard URL for logout resume in the Loginapp UI (ui/app/auth/logout/resume) is used.

That absolute location will be validated against this pattern.

Must only be configured when using a custom SPA.

If behind an Airlock Gateway (WAF), a "URL Encryption Exception" must also be configured for this URL.

Attributes
RegEx
Optional
Temporary Single-Logout Gateway Credential (temporarySloCredentialProvider)
Description

The Airlock Gateway (WAF) role granted to a user on IdP logout before performing the SP logout requests.

Allows requests to temporarily access protected logout endpoints during single-logout if the SP is protected by the same Airlock Gateway (WAF). If this is left empty, the current gateway credentials are still deleted but no new ones are set. This does not pose a security risk, but the logout might not work properly on the SP.

Security notes:
  • The temporary credential should only be used to protect the logout URLs of the SPs in their corresponding mapping configuration in Airlock Gateway (WAF).
  • It is recommended to set an Idle Timeout and a Lifetime as low as possible. These values can be defined inside the plugin configured in this property. In order to guarantee that the SLO flow terminates even with slow connections (e.g. mobile connections), a value of 60 seconds is recommended for both properties.
Attributes
Plugin-Link
Optional
Assignable plugins
Clear Gateway Session on Single-Logout (clearGatewaySessionOnSlo)
Description
If enabled, the Airlock Gateway (WAF) session will be cleared at the beginning of a Single-Logout. The Cookies and Credentials stored at the Airlock Gateway (WAF) for backend services will be deleted already at the beginning of a Single-Logout, before the logout has been propagated to the backend services. This means that:
  • SPs which are behind the same Airlock Gateway (WAF) as Airlock IAM to which the logout is propagated, will not recognize the session because the session-cookie has already been deleted at that point.
  • Logout propagation configured on the Airlock Gateway (WAF) does not work, because the session cookie of the corresponding backend will have been deleted at this point.
If disabled, no cookies on the Airlock Gateway (WAF) will be deleted. Credentials will still be cleared or overriden by the "Temporary Single-Logout Gateway Credential" in case it is set. A temporary credential is usually necessary to properly log out an SP which is behind the same Airlock Gateway (WAF). Consider the security aspects mentioned in the documentation of the "Temporary Single-Logout Gateway Credential".

Regardless of this setting, the Airlock Gateway (WAF) session will be terminated at the end of a single-logout, which means that all cookies and credentials will be deleted.

Attributes
Boolean
Optional
Default value
true
Protocol (protocol)
Description
If load balancing is used, specify the IdP's protocol. Make sure it matches the URLs in the IdP metadata files.
(see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
Attributes
String
Optional
Default value
https
Allowed values
https, http
Host (host)
Description
If load balancing is used, specify the IdP's host name. Make sure it matches the URLs in the IdP metadata files.
(see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
Attributes
String
Optional
Example
localhost
Example
idp
Port (port)
Description
If load balancing is used, specify the IdP's port. Make sure it matches the URLs in the IdP metadata files.
(see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
Attributes
Integer
Optional
Context Path (contextPath)
Description
If load balancing is used, specify the IdP's context path with leading but no trailing slash. Make sure it matches the URLs in the IdP metadata files.
(see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
Attributes
String
Optional
Example
/auth
Example
/saml-login
Server List (serverList)
Description

For load balancing, specify all participating servers in the form "<protocol>://<hostname>:<port>/<path>".

This list must be specified on ALL participating load balanced servers for all servers identically.

This setting is only used if more than one server is involved.

Attributes
String-List
Optional
YAML Template (with default values)

type: Saml2FlowIdp
id: Saml2FlowIdp-xxxxxx
displayName: 
comment: 
properties:
  authnContextMappings:
  clearGatewaySessionOnSlo: true
  contextPath:
  customAuthenticationUri:
  customLogoutResumeUriPattern:
  customLogoutUri:
  defaultAuthnContextUri:
  host:
  idpEntitySettings:
  port:
  protocol: https
  serverList:
  serviceProviders:
  temporarySloCredentialProvider: