Identity providers (addon federation)
Description
SoffidThis Identityscreen Federationallows addon helps administratorsyou to manage an Identity Federation. With Soffid you can managedefine the wholemost federationimportant securitycomponents configuration,of increasinga federation, which are none other than the securityidentity whileproviders. reducingAn identity provider is responsible for performing the federationappropriate managementauthentication costs.for Soffideach canservice alsoprovider actand asuser atype Service Provider, serving identitiesaccording to anytheir SAMLaccounts, capablepermissions, applicationauthorisations, server.and attributes.
The main supported standard is SAML. SAML allows to completely detach the identification process from web applications, known as Service Providers. With SAML, identification is performed by specialized servers known as Identity Providers. Additionaly, some other, less secure, but some times convenient protocols like OAuth (Open Authorization) and OpenID-Connect protocols are supported. Elder protocols like Openid (do not confuse with OpenID-Connect) are deprecated and no longer supported.
Remember that after validating the user's login, the identity provider will send a set of attributes to the service provider that will have been previously defined in Soffid in the attribute definition page and shared attribute policy screens.
You can visit the Introduction page to find more information about the federation members.
Please note that this screen is available in the federation addon.
Screen overview
FederationRelated membersobjects
EntityAttributeGroupdefinition : where the list of possible attributes to be returned in the IdP response is defined- Attribute sharing policies : where policies are defined with the attributes to be sent according to the authenticated service provider
- Identity
Providerproviders : configuration of the identity providers VirtualServiceIdentityprovidersProvider
: configuration of the service providers
Standard attributes
Entity Groupgroup
{{@389}}
Identity Provider
provider
{{@390}}
Virtual Identityidentity Provider
provider
{{@391}}
Actions
Federation Tree view
tree
Add group |
Allows you to create a new To add a new |
Add identity provider |
Allows you to add a new To add a new |
Add virtual identity provider |
Allows you to add a To add a new |
Entity goupgroup
List
detail
|
|
Delete |
Allows you to remove To perform that action, Soffid will ask you for confirmation, you could confirm or cancel the operation. |
Undo |
Allows you to quit without applying any changes. |
Apply changes |
Allows you to save the data of a new entity group or to update the data of a specific entity group. Once you apply changes, the plugin details page will be closed. |
Detail
Identity provider detail
Save
|
Allows you to save the data of a new
|
|
To save the data it will be mandatory to fill in the required fields. |
Delete identity provider |
Allows you to delete the Soffid will ask you for confirmation to perform that action, you could confirm or cancel the operation. |
Undo |
Allows you to quit without applying any changes made. |
Identity Provider
List
|
|
|
|
Detail
|
|
Apply changes |
Allows you to save the data of a new |
Virtual identity provider detail
Save |
Allows you to save the data of a new virtual identity provider or to update the data of a specific virtual identity provider. To save the data it will be mandatory to fill in the required fields. |
Delete identity provider |
Allows you to delete the Soffid will ask you for confirmation to perform that action, you could confirm or cancel the operation. |
Undo |
Allows you to quit without applying any changes made. |
Virtyal Identity Provider
List
|
|
|
|
Detail
|
|
Apply changes |
Allows you to save the data of a new To save the data it will be mandatory to fill in the required fields. |
|
|
|
|
https://en.wikipedia.org/wiki/Federated_identity