Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
png
saml1.png 177.8 kB 1 09-Oct-2016 18:14 Ben Spink
png
saml2.png 211.5 kB 1 09-Oct-2016 18:14 Ben Spink

This page (revision-10) was last changed on 25-May-2018 09:47 by Ben Spink

This page was created on 09-Oct-2016 18:14 by Ben Spink

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Difference between version and

At line 1 changed one line
!!The SAMLSSO plugin requires an enterprise license.\\
!!Enterprise Licenses Only\\
SAMLSSO Plugin\\
At line 3 changed one line
This plugin is for advanced users in an organization using SAML.
This plugin is for advanced users in an organization using SAML. While this config is generic in its description for all SAML providers, see the Microsoft ADFS config example for specifics on it. *[SAMLSSO_ADFS]*\\
\\
For configuring through a DMZ, this requires Crush 8.3.0_8+ and for both the DMZ instance and internal instance to have identical configurations. If you are using the groups attribute in SAML to specify group memberships, add them into the LDAP roles area using the same group name SAML returns. Set the cache timeout to be "-1" and it will skip connecting to the LDAP configured server info. (Which is what you want if using SAML groups.)\\
\\
This plugin can be linked together with the WebApplication plugin for a scenario where your LDAP does not apply to your SAML logins. *[SAMLSSO_WebApplication]*\\
!!1)\\
The top half controls the connection parameters to the SAML provider server.\\
We provide an example screenshot for an OKTA account. Both HTTP POST and redirect modes are supported.\\
[attachments|saml1.png]\\
\\
!!2)\\
The lower half controls what to do with the resulting user that is validated once they are redirected back to your CrushFTP server. This mainly contains configuration items related to LDAP. An LDAP server is required for looking of role associations for the user that SAML validated.\\
[attachments|saml2.png]\\
\\
!!3)\\
The final item is using a Url like this to make CrushFTP redirect a user to the SAML provider.\\
{{{
http://domain.com/?u=SSO_SAML&p=redirect
}}}
This could be placed on your login page, or even use javascript to auto redirect the user to that URL.\\
\\
Be certain the Preferences, Misc tab has the remember invalid usernames configured to 0 seconds or your SAML login will get rejected since CrushFTP caches the username as being invalid and doesn't even ask the plugin.\\
\\
Also be sure prefs.XML has "http_redirect_base" set to a blank value, or your actual URL, or else the redirection will be blocked.\\
Version Date Modified Size Author Changes ... Change note
10 25-May-2018 09:47 2.069 kB Ben Spink to previous
9 25-May-2018 09:47 2.069 kB Ben Spink to previous | to last
8 27-Apr-2018 09:34 1.62 kB Ben Spink to previous | to last
7 12-Sep-2017 09:54 1.482 kB Ben Spink to previous | to last
6 15-Aug-2017 07:47 1.49 kB Ben Spink to previous | to last
5 15-Aug-2017 07:47 1.488 kB Ben Spink to previous | to last
4 26-Apr-2017 19:39 1.321 kB Ben Spink to previous | to last
3 09-Oct-2016 18:14 1.171 kB Ben Spink to previous | to last
2 09-Oct-2016 18:14 1.17 kB Ben Spink to previous | to last
1 09-Oct-2016 18:14 0.126 kB Ben Spink to last
« This page (revision-10) was last changed on 25-May-2018 09:47 by Ben Spink
G’day (anonymous guest)

OLD WIKI!!!#

New: CrushFTPv9#

OLD WIKI!!!#


CrushFTP8 | What's New

Referenced by
LeftMenu

JSPWiki