(You) 11 Years Ago [...] Liferay 6.1 EE comes with SAML 2.0 Identity Provider and Service Provider support via SAML plugin. If you are not familiar with SAML check out my Introduction to SAML presentation slides. In this... [...] Read More Please sign in to reply. Reply as... Cancel
Alberto Rama 11 Years Ago We got the 6.1 EE SAML plugin working all right, but the default behavior seems to ask the user to set password and security question before provisioning it. Is there a way to prevent this? Also we would like to disable local login and force the app to redirect to the IdP login page when authentication is required, what would be the best way to do it? Please sign in to reply. Reply as... Cancel Armin Cyrus Dahncke Alberto Rama 11 Years Ago Try to set on the SPusers.reminder.queries.enabled=falsein portal ext properties and modify the default password policy so that it requires no password change.You can disable the sign in portlet in plugins configuration and then also add your signurl in portal ext properties like thisauth.login.url= Please sign in to reply. Reply as... Cancel
Armin Cyrus Dahncke Alberto Rama 11 Years Ago Try to set on the SPusers.reminder.queries.enabled=falsein portal ext properties and modify the default password policy so that it requires no password change.You can disable the sign in portlet in plugins configuration and then also add your signurl in portal ext properties like thisauth.login.url= Please sign in to reply. Reply as... Cancel
Amar k 11 Years Ago i dont know how to develop single sign on, please help me? Please sign in to reply. Reply as... Cancel
Al Faller 11 Years Ago HI - in Service Provider mode, is it capable of getting a user's groups from attributes? I am an EE user, and am potentially interested in using this plugin.Thanks,Al Please sign in to reply. Reply as... Cancel
Clint Wilde 10 Years Ago We have a client who needs to implement Liferay as an SP for BOTH user login *and application login. We are already implementing SAML plugin for user login. The Application login will be Liferay(SP) logging in to the IDP as an application user, not as a specific user so we need both. Does the SAML plugin have any support for this out of the box?If not, would we need a BOTH a SAML metadata IDP XML for the user login *AND another SAML metadata IDP XML for the application login?Thanks Please sign in to reply. Reply as... Cancel
Ash Gupta 10 Years Ago Is it important to use the same keystore generated here for the ssl configuration of Tomcat or can this be different ? Please sign in to reply. Reply as... Cancel
Advait Trivedi 9 Years Ago I got Liferay 6.2 EE to work as SAML SP, but after login I was inspecting cookies that get created. I noticed that COMPANY_ID and ID cookies are not created when I login using SAML. But when I login using Liferay's internal login, these cookies gets created. Is there a way for me to get these cookies when I login using SAML ?Thanks,Advait Please sign in to reply. Reply as... Cancel
Denney Liptak 9 Years Ago Perhaps it is obvious (it wasn't to me) but it should be noted that you need to add the IdP certificate to the Liferay SP keystore. I erroneously thought the IdP metadata import/link (the value of parameter: saml.metadata.paths) was sufficient to establish trust but this was not the case.Without importing the IdP certificate, the SAMLResponse signature will be verified but it will be rejected due to lack of 'trust'. I'm not sure if this is required but the alias you give the certificate during import should match the entityID assertion by the IdP.For example: keytool.exe -alias <IdP_entityID> -importcert -file <IdPcert.cer> -keystore keystore.jkswhere keystore.jks is the same SP keystore created at the beginning of this post.If the name/alias didn't match, I'm not sure it'd successfully lookup the certificate. Please sign in to reply. Reply as... Cancel
Eason Chen 9 Years Ago I am using Liferay 6.2 EE. After configuring the same as this blog, my portal is configured with the SP value (http://localhost:8080/group/control_panel/manage/-/server/properties/portal-properties). However, when I browse to the SP Metadata URL, I will be redirected back to portal URL, cannot download SP Metadata, why? Please sign in to reply. Reply as... Cancel
sanjay datta 8 Years Ago Thanks for the great Post, Is it possible to configure SP to connect to Multiple IdP ?.Thanks,Sanjay Please sign in to reply. Reply as... Cancel
(You) 8 Years Ago [...] In this case Liferay was going to be the Service Provider (SP) and Okta was going to be the Identity Provider (IdP). I installed, configured and tested the plugin and everything worked great, but... [...] Read More Please sign in to reply. Reply as... Cancel
Midhun Kumar 7 Years Ago Hi Armin, nice blog seems informative and I want to try it out . But I need to find the Liferay SAML 2.0 portlet compatible with Liferay Portal 6.1 EE GA2. Can you tell mewhich version of Liferay SAML 2.0 would work and where I can download it ?? Please sign in to reply. Reply as... Cancel
(You) 6 Years Ago [...] Liferay Portal 6.2 User Guide - Integrating Existing Users into Liferay - SAML Setting up Liferay Portal 6.1 EE as an IdP Setting up Liferay Portal 6.1 EE as a SP [...] Read More Please sign in to reply. Reply as... Cancel
(You) 6 Years Ago [...] LRDOCS-1531 - Adding SAML configuration as Service Provider in Liferay Portals in Cluster Context Liferay Portal 6.2 User Guide - Setting Up Liferay as a SAML Service Provider in a Clustered... [...] Read More Please sign in to reply. Reply as... Cancel