Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| en:2.0:single_sign_on:saml_joomla [2025/04/27 10:24] – kainhofer | en:2.0:single_sign_on:saml_joomla [2026/09/04 18:49] (current) – [Setting up the Client (SP) in Admidio] kainhofer | ||
|---|---|---|---|
| Line 7: | Line 7: | ||
| Throughout the document we will assume you have both Admidio and Joomla already set up properly at https:// | Throughout the document we will assume you have both Admidio and Joomla already set up properly at https:// | ||
| - | As a first step, one needs to **configure Admidio to act as an SAML 2.0 Identity Provider** (IdP). This has to be done once and is not specific to any client. Please | + | As a first step, one needs to **configure Admidio to act as an SAML 2.0 Identity Provider** (IdP). This has to be done once and is not specific to any client. Please |
| {{ : | {{ : | ||
| - | Basically, one (1) needs to **create a cryptographic key** to sign message | + | Basically, one needs to enable SAML 2.0 and **choose a unique EntityID**. |
| - | The page preferences | + | |
| + | The page https:// | ||
| - | ===== TL;DR; - Quick Overview ===== | + | ===== Quick Overview ===== |
| - | Setting up a client (SAML " | + | Setting up a client (SAML " |
| * At the **Service Provider (SP)** - Joomla in our case - **install the extension** to support SAML login. | * At the **Service Provider (SP)** - Joomla in our case - **install the extension** to support SAML login. | ||
| Line 21: | Line 23: | ||
| * Choose whether sent messages **should be signed and/or encrypted** (these features require an additional private key and certificate for the SP!), and whether received messages are checked for signatures or encryption is expected. | * Choose whether sent messages **should be signed and/or encrypted** (these features require an additional private key and certificate for the SP!), and whether received messages are checked for signatures or encryption is expected. | ||
| * In **Admidio**, | * In **Admidio**, | ||
| - | * Choose an easily understood **label for the client** (only used in Admidio' | + | * Choose an easily understood **label for the client** (only used in Admidio' |
| * Enter the **ClientID from the SP**, as well as the ACS URL and the SLO response URL. These values must be provided by the client. | * Enter the **ClientID from the SP**, as well as the ACS URL and the SLO response URL. These values must be provided by the client. | ||
| * In Admidio, also choose whether sent messages should be **signed or encrypted**. The crypto key generated in the general SAML setup will be used. | * In Admidio, also choose whether sent messages should be **signed or encrypted**. The crypto key generated in the general SAML setup will be used. | ||
| Line 58: | Line 60: | ||
| Paste the metadata URL copied from Joomla into the corresponding input field at the top and click "Load Client Metadata" | Paste the metadata URL copied from Joomla into the corresponding input field at the top and click "Load Client Metadata" | ||
| {{ : | {{ : | ||
| + | {{ : | ||
| The only other setting that is relevant for the limited features of the free Joomla plugin is the User ID field. The Joomla plugin insists on matching only E-Mail Addresses, so make sure to select it: | The only other setting that is relevant for the limited features of the free Joomla plugin is the User ID field. The Joomla plugin insists on matching only E-Mail Addresses, so make sure to select it: | ||
| Line 77: | Line 80: | ||
| ==== Caveats and Things to Consider ==== | ==== Caveats and Things to Consider ==== | ||
| - | * The miniOrange Joomla plugin requires the email address to be used as the user ID, so only users with a valid email in Admidio can log in! Oone also has to make sure the Admidio SAML client is configured to use the email as the user ID. | + | * The miniOrange Joomla plugin requires the email address to be used as the user ID, so only users with a valid email in Admidio can log in! One also has to make sure the Admidio SAML client is configured to use the email as the user ID. |
| + | * The miniOrange SAML plugin for Joomla does not support single-log-out in its free version (and the paid version is several hundreds of Euros for every installation, | ||