Configuring SAML Authorization in Your Atlassian Application Based on Confluence 6 Data Center

To configure SAML in Confluence:

  1. Go to

     >  General Configuration

    > SAMl authorization (SAML Authentication) .

  2. Select SAML single sign-on .
    Configure the following settings:

 

  • Single sign-on issuer

    This value is provided by your IdP as part of setting up SAML. Sometimes this is called 'Entity ID'

    The publisher is the IdP application that will accept the authorization request form.

    Identity provider single sign-on URL

    This value is provided by your IdP as part of setting up SAML

    This defines the URL your user will be redirected to when logged in.

    X.509 Certificate

    This value is provided by your IdP as part of setting up SAML. Sometimes this is called ''Signing certificate'. This key usually starts with '-----BEGIN CERTIFICATE-----'.

    This contains the public key, which we will use to verify authorization requests from your IdP.

    Login mode

    This defines that your users can use SSO, the usual options are:

    • Use SAML as secondary authentication - By default, the app will use the funds login form to log into the system. You can log in by using SAML if you go to your IdP and select your application, or log in using the following URL: BASE-URL/plugins/servlet/external-login . We recommend you use this method because you can test all configurations and make sure users can log in using SSO.
    • Use SAML as primary authentication - In this mode, all browser-based users will be redirected from the application login screen to the IdP screen to log in to the system. Possible authorizations are as follows:
      • Basic Auth
      • Form-based auth via dedicated REST endpoint
      • Existing Remember Me tokens

        You need to make sure your SAMl authorization is properly configured to enable this mode.

    Remember user logins

    When you select this, users who have successfully logged in will be remembered by the browser. When accessing other browsers, the user will be automatically logged in without the need for a second login using SAMl.

    (warning)Confluence datacenter uses 'remember me' to enable login in 2 nodes. Setting Existing Remember Me tokens to Disable on this page can override Confluence's behavior and will prompt the user to log in again when moving to another node. We recommend setting  Remember user logins to enabled.

  • The following configuration information is provided in the authorization interface and will be asked to configure your IdP:

 

  1. Assertion Consumer Service URL This is the address to which the IdP will return SAML authorization requests.
    Audience URL (Entity ID) This is the address where the IdP prepares the SAML authorization request.
  2. Click Save configuration .

Once you have successfully configured your application and your IdP, you can start using SSO.

 

https://www.cwiki.us/display/CONFLUENCEWIKI/SAML+SSO+for+Confluence+Data+Center

Guess you like

Origin http://43.154.161.224:23101/article/api/json?id=324842172&siteId=291194637