Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Change example1SamlAttributeMap to reflect the id of the attribute map created in the previous section.

Metadata Generation

After completing this initial setup. It's time to generate the metadata. To do this setup the login configuration form to have a log in with SAML button and click it. You should be redirected to your identity provider and rejected, but your metadata will be generated by this step. Next log in as a local user then go to <<yourhost>>/Phixflow/saml/metdata in order to download an XML file of your metadata.This will need to be given to your identity provider to log in. In order to simplify configuration it is recommended to save this as metadata/sp-metadata.xml

At this point please refer to  the Phixflow Active Directory Setup section for more information on how to connect your identity provider provided groups to PhixFlow groups. The "default domain" section is not needed.

Logging in as a SAML user

Image Removed

...

Configure External Groups

System Configuration defines an external login group, which grants the right to login to that PhixFlow instance. If this group is not configured, or the user is not a member of that external group, she will not be allowed to login, even if she provides a valid username and password for the identity provider.

Each PhixFlow User Group defines external group names which grant access rights (the rights to view, activate, change, delete objects) conferred by membership of those user groups. A user who successfully logs in using SAML / Single Sign-on will only have the access rights for which she is a member of the corresponding external groups.

See here for how to configure external groups.

Troubleshooting

Enhanced diagnostics can be generated by adding the lines

...