SAML 2.0 Flow IdP
Enables and configures the SAML 2.0 Identity Provider (IdP) for use in the flow-based authentication.
The IdP provides assertions to receiving applications called "SAML Service Providers".
idpEntitySettings) serviceProviders) authnContextMappings) Assertions contain an 'Authentication Context Class Reference' referencing the type or strength of the performed authentication of the user. This can be used by a Service Provider (SP) in order to assess the level of confidence it can put in the assertion.
If configured, the first fulfilled condition defines the final 'Authentication Context Class Reference'. If left empty (or no condition is fulfilled), the logic of the "Default Authentication Context" takes place. (See property description)
defaultAuthnContextUri) Assertions contain an 'Authentication Context Class Reference' referencing the type or strength of the performed authentication of the user. This can be used by a Service Provider (SP) in order to assess the level of confidence it can put in the assertion.
This property defines the default 'Authentication Context Class Reference' used if no URI can be determined based on the 'Authentication Context Mappings'.
If left empty, the SAML default resolution is used which also honors the requested URI of an SP in the SP-initiated SSO scenario. For IdP-initiated SSO or if no requested 'Authentication Context Class Reference' can be met in SP-initiated SSO, the first URI defined in the IdP extended metadata file is used (see the "Extended Metadata File" property in the IdP entity settings).
The available context classes are configured in the IdP extended metadata attribute "idpAuthncontextClassrefMapping". Only URIs defined by the attribute are valid to be set here.
customAuthenticationUri) The URI to start authentication in case of SP-Initiated SSO.
Must only be configured when using a custom SPA.
Relative URIs not starting with a slash are resolved against the current context path.
When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.
customLogoutUri) The URI to start the logout process in the UI.
This is mainly used in SP-initiated Single-Logout (the logout is started by a Service Provider). In this case, the browser must first be redirected to the UI in order to start the regular logout before being able to finish the SAML 2.0 Single-Logout (SLO).
It is also used in certain error cases where a logout must be performed.
Must only be configured when using a custom SPA.
Relative URIs not starting with a slash are resolved against the current context path.
When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.
customLogoutResumeUriPattern) During IdP-Initiated Single-Logout (SLO), the SPA has to send the location where to resume the logout process after SAML 2.0 Single-Logout has been finished using a "Location" URL parameter.
If not configured, the standard URL for logout resume in the Loginapp UI (ui/app/auth/logout/resume) is used.
That absolute location will be validated against this pattern.Must only be configured when using a custom SPA.
If behind an Airlock Gateway (WAF), a "URL Encryption Exception" must also be configured for this URL.
temporarySloCredentialProvider) The Airlock Gateway (WAF) role granted to a user on IdP logout before performing the SP logout requests.
Allows requests to temporarily access protected logout endpoints during single-logout if the SP is protected by the same Airlock Gateway (WAF). If this is left empty, the current gateway credentials are still deleted but no new ones are set. This does not pose a security risk, but the logout might not work properly on the SP.
Security notes:- The temporary credential should only be used to protect the logout URLs of the SPs in their corresponding mapping configuration in Airlock Gateway (WAF).
- It is recommended to set an Idle Timeout and a Lifetime as low as possible. These values can be defined inside the plugin configured in this property. In order to guarantee that the SLO flow terminates even with slow connections (e.g. mobile connections), a value of 60 seconds is recommended for both properties.
clearGatewaySessionOnSlo) - SPs which are behind the same Airlock Gateway (WAF) as Airlock IAM to which the logout is propagated, will not recognize the session because the session-cookie has already been deleted at that point.
- Logout propagation configured on the Airlock Gateway (WAF) does not work, because the session cookie of the corresponding backend will have been deleted at this point.
Regardless of this setting, the Airlock Gateway (WAF) session will be terminated at the end of a single-logout, which means that all cookies and credentials will be deleted.
protocol) (see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
host) (see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
port) (see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
contextPath) (see the "Metadata File" and "Extended Metadata File" properties in the IdP entity settings. Together with the other values, this must match one of the entries in 'Server List'.
serverList) For load balancing, specify all participating servers in the form "<protocol>://<hostname>:<port>/<path>".
This list must be specified on ALL participating load balanced servers for all servers identically.
This setting is only used if more than one server is involved.
type: Saml2FlowIdp
id: Saml2FlowIdp-xxxxxx
displayName:
comment:
properties:
authnContextMappings:
clearGatewaySessionOnSlo: true
contextPath:
customAuthenticationUri:
customLogoutResumeUriPattern:
customLogoutUri:
defaultAuthnContextUri:
host:
idpEntitySettings:
port:
protocol: https
serverList:
serviceProviders:
temporarySloCredentialProvider: