Search Results :

×

Enterprise organizations frequently operate not one Joomla website, but an entire network of them. Separate brand sites, regional portals, department hubs, and franchise locations, each running as an independent Joomla instance with its own database, its own settings, and its own administrative overhead. At scale, this architecture introduces a fundamental configuration management problem that standard plugin setups are not built to handle.

The miniOrange SAML SP plugin addresses this through a custom file-based configuration architecture. Rather than storing SSO settings individually across every site in the network, a single master configuration is maintained in one centralized JSON file. Every site in the network reads its SAML settings from this shared source, meaning one update propagates everywhere instantly. What would otherwise require touching 100 separate databases becomes a single change in a single file.

To enable SAML SSO for centralized multisite configuration, this use case uses the following miniOrange plugin. You will need to install it on your Joomla instance:

usecase card logo

SAML Single Sign-On (SP) Plugin

Download Extension

Managing SAML SSO through Joomla's default database-driven configuration model works reasonably well for a single site. Stretched across a network of 100 or more interconnected Joomla instances, the same approach becomes operationally unsustainable:

  • Database bloat at scale: Every Joomla site in the network stores its own copy of the SAML plugin configuration in its own database. Across 100+ sites, this creates significant and entirely redundant data duplication with no functional benefit.
  • Configuration drift: When settings are managed independently across dozens or hundreds of databases, small inconsistencies inevitably accumulate, mismatched certificate versions, outdated IdP metadata, or varying attribute mappings that cause silent authentication failures on specific sites.
  • Update propagation risk: Any IdP change to a new certificate, a modified SSO endpoint, or an updated Entity ID requires the same update to be manually applied across every site individually. At scale, this is not just time-consuming; it is a near-certain source of human error.
  • No single point of governance: Without a centralized configuration layer, there is no reliable way for an IT team to audit, verify, or enforce a consistent SSO standard across the entire network at any given moment.
  • Disproportionate setup time: Onboarding a new site into the network means configuring the SAML plugin from scratch in yet another database, a process that should take seconds but instead takes the same effort as the very first deployment.

The implementation replaces per-database SAML configuration with a centralised, file-based architecture. One master site is configured, one JSON file is created, and all remaining sites in the network are pointed to it.


Step 1: Configure the master site. A single Joomla instance is designated as the master configuration site. The miniOrange SAML SP plugin is fully configured on this site in the usual way, IdP metadata is entered, attribute mappings are defined, and SSO behaviour is set according to the organisation's requirements. This master configuration serves as the single authoritative source of truth for the entire network.


Step 2: Export settings to a centralised JSON file. Once the master site is configured, the plugin exports all SAML settings to a structured JSON file stored at a designated, secure file path that is accessible to all Joomla instances in the network. This file contains the complete plugin configuration: IdP metadata, SP entity ID, certificate details, attribute mappings, login and logout behaviour, and any advanced customisations.


Step 3: Connect satellite sites to the master configuration. On each remaining Joomla site in the network, the miniOrange SAML SP plugin is installed and pointed to the centralised JSON file path rather than storing its own local configuration. The plugin reads all SSO settings directly from this shared file at runtime. No per-site configuration is required beyond specifying the file path; every site in the network is immediately operating with an identical, consistent SAML setup.


Step 4: Propagate updates across the entire network. When any configuration change is required, a certificate renewal, an IdP metadata update, or a change in attribute mapping is made once on the master configuration file. All sites in the network pick up the change automatically on the next authentication request, with no additional steps and no risk of partial or inconsistent updates across the network.

For enterprise organisations managing large-scale Joomla site networks, the default approach of configuring and maintaining SAML SSO independently across every database is neither practical nor secure at scale. Configuration drift, update errors, and database redundancy are not occasional inconveniences; they are structural certainties when the same settings are managed in 100 different places simultaneously.

The file-based centralised configuration architecture available through the miniOrange SAML SP plugin eliminates this problem at its root. One configuration file governs the entire network, updates propagate instantly, and every site operates from the same verified, consistent SSO setup regardless of how large the network grows.

  1. SAML Single Sign-On (SP) Plugin for Joomla
  2. Check out our documentation

We'll Reach Out to You at the Earliest

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Table of Contents

Hello there!

Need Help? We are right here!

support