SAML 2.0 Flow SP
Configures a local SAML Service Provider (SP).
The SAML SP receives assertions from other SAML Identity Providers (IdPs). The Airlock IAM Loginapp can also act as identity provider, i.e. issue SAML assertions for other SPs. See separate configuration section for further details.
spEntityConfig) remoteIdpEntitySettings) usernameTransformers) authnRequestBinding) The binding to be used for the authentication request in SP-Initiated SSO.
Important: if an explicit binding type is configured, the same binding must also be enabled in the IdP's standard metadata.
- Automatic: Automatically selects the first enabled binding in the IdP standard metadata.
- HTTP Redirect Binding: The authentication request is carried directly in the URL query string of an HTTP GET request. Since the length of URLs is limited in practice, the HTTP Redirect binding is only suitable for short messages. Longer messages (e.g. signed requests or if large extensions are added) should be transmitted via the POST binding.
- HTTP POST Binding: The authentication request is sent by the user's browser as a POST parameter via a self-posting form using JavaScript. This binding is recommended for long authentication requests or when there is no direct communication between the IdP and the SP. It requires that JavaScript is enabled in the user's browser.
customAuthnRequestExtensions) With this property any custom extensions can be added to the AuthnRequest. This can e.g. be used to request additional attributes from the IdP. The extensions must be given as valid XML string, without the surrounding <Extension> tag.
defaultFlowApplicationId) If this property is not configured, the "Default Application" defined in "Authentication Flows" will be used.
attributeToImportAsUserId) attributeToImportAsLanguage) Valid language values from the IdP should conform to the format specified by ISO 639-1 (two characters).
attributeToImportAsAuditToken) Note that the audit token cannot be overwritten. This means if it was previously already set (e.g. upon successful completion of a previous authentication flow), the value imported here will be ignored.
attributeToImportAsAuthTokenId) attributeNameToTagMappingConfigs) attributesToImport)
type: Saml2FlowSp
id: Saml2FlowSp-xxxxxx
displayName:
comment:
properties:
attributeNameToTagMappingConfigs:
attributeToImportAsAuditToken:
attributeToImportAsAuthTokenId:
attributeToImportAsLanguage:
attributeToImportAsUserId:
attributesToImport:
authnRequestBinding: AUTOMATIC
customAuthnRequestExtensions:
defaultFlowApplicationId:
remoteIdpEntitySettings:
spEntityConfig:
usernameTransformers: