plugin:adfs
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
plugin:adfs [2016-12-09 13:11] – doc for customizable attributes and autoprovisioning option 2001:a18:1:8::136 | plugin:adfs [2024-03-12 14:27] (current) – question added asheenlevrai | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== | + | ====== |
---- plugin ---- | ---- plugin ---- | ||
Line 6: | Line 6: | ||
email : andi@splitbrain.org | email : andi@splitbrain.org | ||
type : auth | type : auth | ||
- | lastupdate : 2016-12-09 | + | lastupdate : 2020-10-22 |
- | compatible : hrun | + | compatible : Hrun, Greebo, Hogfather |
depends | depends | ||
conflicts | conflicts | ||
Line 15: | Line 15: | ||
downloadurl: | downloadurl: | ||
bugtracker : https:// | bugtracker : https:// | ||
- | sourcerepo : https:// | + | sourcerepo : https:// |
donationurl: | donationurl: | ||
screenshot_img : | screenshot_img : | ||
---- | ---- | ||
+ | |||
+ | The plugin was tested with Active Directory Federation Services on Windows Server 2008 and 2010. It might work with other SAML2 based Identity Providers, too. Users have reported it to work with SimpleSAMLphp and Okta. | ||
+ | |||
+ | The plugin makes use of the [[https:// | ||
===== Installation ===== | ===== Installation ===== | ||
- | [[http:// | + | [[https:// |
- | Install | + | Search and install |
==== Setup ADFS with SAML 2.0 ==== | ==== Setup ADFS with SAML 2.0 ==== | ||
- | The plugin was tested with Windows Server 2008. Please note that there is an updated version of the Federation | + | Before you start, make sure you have a SSL certificate for the Federation Server |
- | Run the installer | + | **Windows Server 2008**: [[http:// |
- | Your wiki has to be SSL secured as well! ADFS will refuse to work without SSL! A browser accepted certificate is highly recommended. | + | **Windows Server 2010**: Open the Server Manager, select "Add roles and Features" |
- | Once the services are set up, add a new **Relying Party Trust** in the ADFS snap-in. | + | Once the services are set up, add a new **Relying Party Trust** in the ADFS snap-in |
For configuration use the following **Federation metadata address**: '' | For configuration use the following **Federation metadata address**: '' | ||
Line 53: | Line 57: | ||
==== Configure the Plugin ==== | ==== Configure the Plugin ==== | ||
- | There are two settings to configure in the [[plugin: | + | There are multiple |
- | * '' | + | | '' |
- | | + | | '' |
+ | | '' | ||
+ | | '' | ||
+ | | '' | ||
+ | | '' | ||
- | You can find the certificate in an XML file that is usually found under %%'' | + | Please make sure your users have valid email addresses set in the Active Directory! Otherwise certain DokuWiki features may not work for them. |
- | + | ||
- | The attribute names above (login, | + | |
- | + | ||
- | Once everything is set up you can switch the [[config: | + | |
+ | Once everything is set up, you can switch the [[config: | ||
+ | Be sure to configure a [[config: | ||
+ | Important: make sure your Wiki and ADFS Server have the correct time! They may only drift apart by three minutes maximum or login will not work. | ||
===== Usage ===== | ===== Usage ===== | ||
- | Clicking the login button will bring up the ADFS login form. Users can login with their Active Directory user name there and will be redirected to the wiki. If setup correctly, the ADFS form will use Single-Sign-On | + | Clicking the login button will redirect users to your ADFS server. The server might automatically log in users using Single-Sign-On |
- | The login will be remembered by the wiki. Unless they log out explicitly subsequent visits will trigger the login process automatically. | ||
- | Please make sure your users have valid email addresses set in the Active Directory! Otherwise certain DokuWiki features may not work for them. | + | ===== Questions ===== |
+ | |||
+ | 2024-03-12 : Is this plugin still currently maintained? | ||
- | By default, new accounts are created during the first time login. | ||
- | If you prefer to reject unknown users and want to manually manage the user accounts you can untick the option " |
plugin/adfs.1481285506.txt.gz · Last modified: 2016-12-09 13:11 by 2001:a18:1:8::136