Search Results :

×

Drupal SAML Single Sign On using OneLogin as Identity Provider


The Drupal SAML integration using the miniOrange SAML SP module establishes seamless SSO between Onelogin and the Drupal site. The users will be able to log in to the Drupal site using their Onelogin credentials. This document will walk you through the steps to configure Single Sign-On - SSO between Drupal as a Service Provider (SP) and Onelogin as an Identity Provider (IdP). The module is compatible with Drupal 7, Drupal 8, Drupal 9, and Drupal 10.

Installation Steps


  • Download the module:
    Composer require 'drupal/miniorange_saml'
  • Navigate to Extend menu on your Drupal admin console and search for miniOrange SAML Service Provider using the search box.
  • Enable the module by checking the checkbox and click on install button.
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup
  • Install the module:
    drush en drupal/miniorange_saml
  • Clear the cache:
     drush cr
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup
  • Navigate to Extend menu on your Drupal admin console and click on Install new module button.
  • Install the Drupal SAML SP 2.0 Single Sign On (SSO) - SAML Service Provider module either by downloading the zip or from the URL of the package (tar/zip).
  • Click on Enable newly added modules.
  • Enable this module by checking the checkbox and click on install button.
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup

Drupal SAML SP Metadata

  • After installing the module on the Drupal site, in the Administration menu, navigate to Configuration → People → miniOrange SAML Login Configuration. (/admin/config/people/miniorange_saml/idp_setup)
  • Drupal SAML Single Sign-On - Select miniOrange SAML Login Configuration
  • Copy the SP Entity ID/Issuer and the SP ACS URL in the Service Provider Metadata tab. Keep it handy. (This is required to configure OneLogin as Identity Provider (IdP)).
  • Drupal SAML Single Sign-On - Copy SP information which is required to configure Google as IdP

Configure SAML Single Sign-On Application in OneLogin:

  • Log into OneLogin as Administrator console.
  • Navigate to the Applications and select Applications from the dropdown.
  • Onelogin saml Single Sign On login - click on applications
  • Click on the Add App button.
  • Onelogin saml Single Sign On login - click on add apps
  • Under the Find Applications, search for SAML Custom and click on the SAML Custom Connector (Advanced).
  • Onelogin saml Single Sign On login - under the find application search for the saml test connector (advanced)
  • On the Configuration tab, enter the app name in the Display Name text field. Click on Save.
  • Onelogin saml Single Sign On login - enter display name
  • In the Application details section of the Configuration tab, enter the information from the module's Service Provider Metadata tab referring below.
    OneLogin SAML Field Service Provider Information (Drupal)
    Audience (EntityID) SP Entity ID/Issuer
    ACS (Consumer) URL SP ACS URL
    ACS (Consumer) URL Validator SP ACS URL
  • Onelogin saml Single Sign On login - go to configuration tab and paste the required sp information
  • Click on the Save
  • Navigate to the Info of the created application from the left panel. From the More Actions dropdown on the top right corner, select SAML Metadata. Keep the downloaded file handy. (This will be required to configure Drupal as SAML Service Provider.)
  • Onelogin saml Single Sign On login -  select saml metadata from more actions

Configure Drupal as SAML Service Provider:

  • Go to your Drupal website. Navigate to the Service Provider Setup tab of the module and click on the Upload IdP Metadata.
  • In the Upload Metadata File field, choose the SAML metadata file that you downloaded from OneLogin and click on the Upload File button.
  • Drupal SAML Service Provider - upload idp metadata

    Note: To alter your Identity Provider Name, follow these steps:

    • Under Action, select the Edit.
    • Enter Okta in the Identity Provider Name text field.
    • Scroll down and click on the Save Configuration button.

  • After successfully saving the configurations, click on the Test link
  • Drupal SAML Service Provider - Check connection between Drupal and Onelogin
  • On a Test Configuration popup sign in using OneLogincredentials (if an active session is not present). After successful authentication, a list of attributes that are received from OneLogin will be displayed. Click on the Done.
  • Drupal SAML Service Provider - Test configuartion

Congratulations! you have successfully configured OneLogin as SAML Identity Provider and Drupal as SAML Service Provider.

How does SAML SSO login work?

  • Open a new browser/private window and navigate to the Drupal site login page.
  • Click the Login using Identity Provider (Onelogin) link.
  • You will be redirected to the Onelogin login page. Enter the Onelogin credentials. After successful authentication, the user will be redirected back to the Drupal site.

Additional Features:

Explore the advanced features offered by the module with full-featured trial. You can initiate the trial request using Request 7-day trial button of the module or reach out to us at drupalsupport@xecurify.com for one-on-one assistance from Drupal expert.

 Case Studies
miniOrange has successfully catered to the use cases of 400+ trusted customers with its highly flexible/customizable Drupal solutions. Feel free to check out some of our unique case studies using this link.
 Other Solutions
Feel free to explore other Drupal solutions that we offer here. The popular solutions used by our trusted customers include 2FA, User Provisioning, Website Security. 
  24*7 Active Support
The Drupal developers at miniOrange offer quick and active support for your queries. We can assist you from choosing the best solution for your use case to deploying and maintaining the solution.
Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com