← Back to plugin index

SAML 2.0 Config

Description
Configures the SAML 2.0 Identity Provider (IdP) and Service Providers (SP) of the login application.
Type name
Saml
Class
com.airlock.iam.saml2.application.configuration.SamlConfig
May be used by
License-Tags
SamlIdp,SamlSp
Properties
SAML 2.0 Identity Provider (samlFlowIdpSettings)
Description
Configures the SAML Identity Provider (IdP) and the associated service providers (SPs) that rely on this IdP to authenticate a user.
Attributes
Plugin-Link
Optional
License-Tags
SamlIdp
Assignable plugins
SAML 2.0 Service Providers (samlFlowSpSettings)
Description
Enables and configures the local SAML Service Providers (SPs).
Attributes
Plugin-List
Optional
License-Tags
SamlSp
Assignable plugins
Use Single-Logout (SLO) Behaviour (enableSingleLogoutOnSps)
Description
When enabled, IAM (as Service Provider) will automatically initiate a Single-Logout with the Identity Provider when the logout endpoint is called. If this flag is disabled, only a local logout will take place.
Attributes
Boolean
Optional
License-Tags
SamlSp
Default value
true
Flow SSO Initialization URI (customSpSsoInitializationUri)
Description

The URI to start or continue the correct authentication flow after receiving an assertion from the Identity Provider (either using IdP- or SP-initiated SSO).

Must only be configured when using a custom SPA.

Relative URIs not starting with a slash are resolved against the current context path.

When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.

Attributes
String
Optional
License-Tags
SamlSp
Example
https://example.com/custom-ui/saml2/sp/sso/init
Example
/custom-ui/sp/sso/init
Logout URI (customLogoutUri)
Description

The URI to start the logout process in the UI.

This is used during IdP-initiated Single-Logout (the logout is started by an Identity Provider). In this case, the browser must first be redirected to the UI in order to start the regular logout before being able to finish the SAML 2.0 Single-Logout.

Must only be configured when using a custom SPA.

Relative URIs not starting with a slash are resolved against the current context path.

When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.

Attributes
String
Optional
License-Tags
SamlSp
Example
https://example.com/custom-ui/logout
Example
/custom-ui/logout
Logout Resume URI Pattern (customLogoutResumeUriPattern)
Description

During SP-Initiated Single-Logout (SLO), the SPA has to send the location where to resume the logout process after SAML 2.0 Single-Logout has been finished using a "Location" URL parameter.

If not configured, the standard URL for logout resume in the Loginapp UI (ui/app/auth/logout/resume) will be used.

That absolute location will be validated against this pattern.

Must only be configured when using a custom SPA.

If behind an Airlock Gateway (WAF), a "URL Encryption Exception" must also be configured for this URL.

Attributes
RegEx
Optional
License-Tags
SamlSp
SAML Federation Settings (samlFederationConfig)
Description
Federation settings used for all SAML 2.0 use-cases.
Attributes
Plugin-Link
Optional
License-Tags
SamlIdp,SamlSp
Assignable plugins
YAML Template (with default values)

type: Saml
id: Saml-xxxxxx
displayName: 
comment: 
properties:
  customLogoutResumeUriPattern:
  customLogoutUri:
  customSpSsoInitializationUri:
  enableSingleLogoutOnSps: true
  samlFederationConfig:
  samlFlowIdpSettings:
  samlFlowSpSettings: