Service Providers (addon federation)

Description

This screen allows you to define the applications that will belong to the federation. These applications are named service providers and must be configured correctly to delegate the user authentication to the identity provider that is responsible for them by configuration.

The main supported standard is SAML. SAML allows to completely detach the identification process from web applications,  known as Service Providers. With SAML, identification is performed by specialized servers known as Identity Providers.  Additionaly, some other, less secure, but some times convenient protocols like OAuth (Open Authorization) and OpenID-Connect protocols are supported. Elder protocols like Openid (do not confuse with OpenID-Connect) are deprecated and no  longer supported.

Remember that after validating the user's login, the identity provider will send a set of attributes to the service provider that will have been previously defined in Soffid in the attribute definition page and shared attribute policy screens.

You can visit the Introduction page to find more information about the federation.

Please note that this screen is available in the federation addon.

Screen overview

image.png

image.png

Standard attributes

SAML

Identification

Service configuration

To publish the federation members' metadata, the main sync server exports the member's metadata at the path /SAML/metadata.xml. Thus, if your sync server is listening at soffid1.your.domain, you can get the whole federation metadata document from:

https://soffid1.your.domain:760/SAML/metadata.xml

After some seconds, up to five minutes, every federation member will notice any change.

Login rules

You can visit the Openid-connect to SAML interoperability page for more detailed information.

SAML API client

Identification

Service configuration

Leave it blank as Soffid IdP will fulfill it for you.

The metadata will be created when the network data and SAML Security data.

Login rules

You can visit the Openid-connect to SAML interoperability page for more detailed information.

Network

SAML Security

OpenID Connect

Identification

Login rules

Image

image.png

You can visit the Openid-connect to SAML interoperability page for more detailed information.

OpenID authorization flow

OpenID Dynamic Register

Identification

Login rules

OpenID authorization flow

Registration token

Radius client

Identification

Login rules

Radius configuration

CAS client

Identification

Login rules

CAS configuration

Tacacs+

Identification

Login rules

Tacacs+ configuration

WS-Federation

Identification

Login rules

WS-Federation

Actions

Federation tree

Add group

Allows you to create a new entity group. You can choose that option by clicking on the "Add group" button in the tree, then Soffid will display a new window with the fields to fullfil. To add a new entity group it will be mandatory to fill in the required fields and save or apply changes.

Add service provider

Allows you to add a new service provider. You must click the "Add service provider" button, under the proper Entity Group and "Identity Provider" label, then Soffid will display a new window with the data to fulfill for new service Provider. To add a new service provider it will be mandatory to fill in the required fields and save or apply changes.

Entity group detail

Apply changes (disk button)

Allows you to save the data of a new entity group or to update the data of a specific entity group. To save the data it will be mandatory to fill in the required fields.

Delete

Allows you to remove the entity group. You can find this option in the "three points" menu by clicking on the "Delete" button. To perform that action, Soffid will ask you for confirmation, you could confirm or cancel the operation.

Undo

Allows you to quit without applying any changes.

Apply changes

Allows you to save the data of a new entity group or to update the data of a specific entity group. Once you apply changes, the plugin details page will be closed.

Service provider detail

Save

Allows you to save the data of a new service provider or to update the data of a specific service provider. To save the data it will be mandatory to fill in the required fields.

Delete service provider

Allows you to delete the service provider. To delete a service provider you can click on the "three points" icon and then click the delete button. Soffid will ask you for confirmation to perform that action, you could confirm or cancel the operation.

Undo

Allows you to quit without applying any changes made.

Apply changes

Allows you to save the data of a new service provider or to update the data of a specific service provider and quit. To save the data it will be mandatory to fill in the required fields.


Revision #13
Created 19 July 2025 12:21:06 by Sion Vives
Updated 22 September 2025 13:01:07 by Sion Vives