← Back to plugin index

SAML 2.0 Flow SP

Description

Configures a local SAML Service Provider (SP).

The SAML SP receives assertions from other SAML Identity Providers (IdPs). The Airlock IAM Loginapp can also act as identity provider, i.e. issue SAML assertions for other SPs. See separate configuration section for further details.

Type name
Saml2FlowSp
Class
com.airlock.iam.saml2.application.configuration.sp.Saml2FlowSpConfig
May be used by
License-Tags
SamlSp
Properties
SP Entity Settings (spEntityConfig)
Description
Configures the Service Provider (SP) entity.
Attributes
Plugin-Link
Mandatory
Assignable plugins
IdP Entity Settings (remoteIdpEntitySettings)
Description
Configures the remote identity provider (IdP) entity.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Username Transformation (usernameTransformers)
Description
Transforms the username provided by the IdP. The transformation precedes the flow's Username Transformation. If one of the transformers configured here interrupts the transformation chain, username transformations in the authentication flow's configuration will be skipped.
Attributes
Plugin-List
Optional
Assignable plugins
Authn Request Binding (authnRequestBinding)
Description

The binding to be used for the authentication request in SP-Initiated SSO.

Important: if an explicit binding type is configured, the same binding must also be enabled in the IdP's standard metadata.

  • Automatic: Automatically selects the first enabled binding in the IdP standard metadata.
  • HTTP Redirect Binding: The authentication request is carried directly in the URL query string of an HTTP GET request. Since the length of URLs is limited in practice, the HTTP Redirect binding is only suitable for short messages. Longer messages (e.g. signed requests or if large extensions are added) should be transmitted via the POST binding.
  • HTTP POST Binding: The authentication request is sent by the user's browser as a POST parameter via a self-posting form using JavaScript. This binding is recommended for long authentication requests or when there is no direct communication between the IdP and the SP. It requires that JavaScript is enabled in the user's browser.
Attributes
Enum
Optional
Default value
AUTOMATIC
Custom Authn Request Extensions (customAuthnRequestExtensions)
Description

With this property any custom extensions can be added to the AuthnRequest. This can e.g. be used to request additional attributes from the IdP. The extensions must be given as valid XML string, without the surrounding <Extension> tag.

Attributes
String
Optional
Multi-line-text
Example
<tag>custom-extension</tag>
Default Flow Application ID (defaultFlowApplicationId)
Description
Defines the application ID of the authentication flow to start in case an Authentication Request received by this Service Provider (IdP-initiated SSO) does not have any relay state or the one provided is not valid.

If this property is not configured, the "Default Application" defined in "Authentication Flows" will be used.

Attributes
Plugin-Link
Optional
Assignable plugins
Attribute to Import as User ID (attributeToImportAsUserId)
Description
Set this property to the name of an attribute to use as user ID instead of the NameID. The obtained user ID completely replaces the Name ID sent by the IdP. It can then be subject to further "Username Transformers" (depending on the selected authentication flow).
Attributes
String
Optional
Example
surname
Example
email
Attribute to Import as Language (attributeToImportAsLanguage)
Description
Set this property to the name of an assertion attribute to use as display language.

Valid language values from the IdP should conform to the format specified by ISO 639-1 (two characters).

Attributes
String
Optional
Example
language
Attribute to Import as Audit Token (attributeToImportAsAuditToken)
Description
Set this property to the name of an assertion attribute to use as audit token. This allows the SAML SP (service provider) to use the same Audit Token as the SAML IdP (identity provider) which makes it easy to correlate SP and IdP sessions.

Note that the audit token cannot be overwritten. This means if it was previously already set (e.g. upon successful completion of a previous authentication flow), the value imported here will be ignored.

Attributes
String
Optional
Example
auditTokenAttr
Attribute to Import as Auth Token ID (attributeToImportAsAuthTokenId)
Description
Set this property to the name of an assertion attribute to use as Auth Token ID.
Attributes
String
Optional
Example
authTokenAttr
Attributes to Import as Tags (attributeNameToTagMappingConfigs)
Description
Import attributes from a SAML 2.0 assertion as flow tags.
Attributes
Plugin-List
Optional
Assignable plugins
Attributes to Import in Flow (attributesToImport)
Description
Import additional attributes from a SAML 2.0 assertion into the user's flow session. The imported attributes can for example be used during the identity propagation to be propagated to a back-end.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: Saml2FlowSp
id: Saml2FlowSp-xxxxxx
displayName: 
comment: 
properties:
  attributeNameToTagMappingConfigs:
  attributeToImportAsAuditToken:
  attributeToImportAsAuthTokenId:
  attributeToImportAsLanguage:
  attributeToImportAsUserId:
  attributesToImport:
  authnRequestBinding: AUTOMATIC
  customAuthnRequestExtensions:
  defaultFlowApplicationId:
  remoteIdpEntitySettings:
  spEntityConfig:
  usernameTransformers: