Configuring SAML in OpManager

Configuring SAML in OpManager

There are two ways to configure SAML in OpManager. You can either do it manually by providing the necessary credentials or you can upload the metadata file directly, if available.

Service provider details

If you opt to configure SAML manually, you will be provided with the following details: the Entity ID, Assertion Consumer URL, SSO Logout URL, and a link to download the SP certificate file. This information, available in the OpManager UI, can be used to add OpManager as a supported application in your IdP.

You can also download the SP metadata file directly from OpManager and import it on the IdP side. This metadata file will have all the above-mentioned details in XML format.

SAML authentication in OpManager 

Identity provider details

Similar to the SP details configuration, you can either configure the IdP details manually or upload the metadata file fetched from the IdP side.

Uploading the IdP metadata file:

If you have a metadata file from your IdP, upload it directly in OpManager.

  1. Under Settings -> General Settings -> Authentication, navigate to the SAML Authentication tab.
  2. Under the 'Configure Identity Provider Details' section, choose Upload IdP metadata file and enter the IdP Name.
  3. Find the metadata file acquired from the IdP and click Upload.

SAML authentication in OpManager 

Configuring IdP information manually:

You can also enter the IdP details manually in OpManager. For this, you will need the following details:

  1. IdP name
  2. IdP login URL
  3. IdP logout URL
  4. IdP certificate

Enter the above details in the 'Configure IdP information manually' section under Settings -> General Settings -> Authentication.

To see the steps to configure SAML between OpManager and that IdP, click the corresponding IdP name.

SAML authentication in OpManager 

Note

  1. OpManager also offers an option called Single Logout. Similar to SSO, users will be able to log out of OpManager and the configured IdP at once from the OpManager UI by clicking the logout URL provided.
  2. As of now, Email address, transient and persistent name identifiers can be used for SAML configuration.
  3. To authenticate AD users of OpManager through SAML authentication, the name ID value from the IdP should be in the format - <domainname>\<username>.
  4. If more than one user have provided the same Email address while configuring the Email Address Name Identifier, they cannot login using SAML authentication.
  5. The Username/Email address configured in the IdP should match the same Username/Email address provided in OpManager for successful authentication.

                  New to ADSelfService Plus?