Search Results :

×

SAML Single Sign-On (SSO) into Drupal using OpenAM as IdP


The Drupal SAML integration using the miniOrange SAML SP module establishes seamless SSO between OpenAM and the Drupal site. The users will be able to log in to the Drupal site using their OpenAM credentials. This document will walk you through the steps to configure Single Sign-On - SSO between Drupal as a Service Provider (SP) and OpenAM as an Identity Provider (IdP). The module is compatible with Drupal 7, Drupal 8, Drupal 9, and Drupal 10.

Installation Steps


  • Download the module:
    Composer require 'drupal/miniorange_saml'
  • Navigate to Extend menu on your Drupal admin console and search for miniOrange SAML Service Provider using the search box.
  • Enable the module by checking the checkbox and click on install button.
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup
  • Install the module:
    drush en drupal/miniorange_saml
  • Clear the cache:
     drush cr
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup
  • Navigate to Extend menu on your Drupal admin console and click on Install new module button.
  • Install the Drupal SAML SP 2.0 Single Sign On (SSO) - SAML Service Provider module either by downloading the zip or from the URL of the package (tar/zip).
  • Click on Enable newly added modules.
  • Enable this module by checking the checkbox and click on install button.
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup

Drupal SAML SP Metadata

  • After installing the module on the Drupal site, in the Administration menu, navigate to Configuration → People → miniOrange SAML Login Configuration. (/admin/config/people/miniorange_saml/idp_setup)
  • Drupal SAML Single Sign-On - Select miniOrange SAML Login Configuration
  • Navigate to the Service Provider Metadata and copy the Metadata URL. (This is required in configuring the OpenAM as a SAML IdP)
  • Drupal SAML Single Sign-On - Copy SP information which is required to configure OpenAM as IdP

Configure SAML Single Sign-On Application

Create OpenAM as a Hosted Identity Provider:

    Note: If you've already set up OpenAM-hosted IDP, move on to Configure Remote Service Provider and skip this step.

  • Login into your OpenAM instance as an administrator.
  • Select the realm you want to use you will be redirected to the Realm Overview page.
  • Click on Create SAMLv2 Providers.
  • Drupal-SAML-SP-Configure-Remote-SP
  • Click on Create Hosted Identity Provider.
  • Drupal-SAML-SP-Configure-Remote-SP
  • Enter the Identity Provider’s Name, then select a Singing Key. Choose a Circle of Trust that already exists or start a new one by giving it a name. In the Attribute Mapping section, provide the user profile attributes to send to the Service Provider.
  • Drupal-SAML-SP-Configure-SAML-IDP
  • In the top right corner, click on the Configure button.
  • Check the configuration in OpenAM's Federation tab.

Configure Remote Service Provider

  • Login into your OpenAM instance as an administrator.
  • Select the realm you want to use you will be redirected to the Realm Overview page.
  • Click on Create SAMLv2 Providers.
  • Drupal-SAML-SP-Configure-Remote-SP
  • Click on Register Remote Service Provider.
  • Drupal-SAML-SP-Register-Remote-SP
  • Enter the metadata URL of the Drupal site. Select an existing Circle of Trust or create a new one by giving it a name. Provide the user profile attributes to send to the service provider in the Attribute Mapping section.
  • Drupal-SAML-SP-Configure-SAML-SP
  • In the top right corner, click on the Configure button.
  • Check the configuration in OpenAM's Federation tab.
  • Download the OpenAM metadata using the URL given below.

    [OpenAM ServerURL] /saml2/jsp/exportmetadata.jsp (This will be required for further configuration of Drupal)

    OR

    If you have multiple realms and a hosted identity Provider configured then use the URL given below.

    [OpenAM ServerURL] /saml2/jsp/exportmetadata.jsp?entityid=[IdPentityID]&realm=/realmname

Configure Drupal as SAML Service Provider:

  • Open your Drupal site. Go to the Service Provider Setup tab of the module.
  • Click on Upload IDP Metadata Section
  • Drupal-SAML-IDP-Select-Upload-Metadata
  • Now paste the metadata URL from the OpenAM IdP.
  • Drupal-SAML-Paste-the-Federation-Metadata-URL-into-the-Upload-Metadata-URL
  • Click the Test link to verify the connection between Drupal and OpenAM.
  • Drupal SAML Service Provider - Check connection between Drupal and Simple-SAML
  • In the test configuration window, a success message with SAML response attributes will appear if the configurations are correct; otherwise, error messages with additional troubleshooting instructions will appear. Click on Done
  • Drupal SAML Service Provider - Test configuartion

Congratulations! You have successfully configured OpenAM as an Identity Provider and Drupal as a Service Provider.

How does SAML SSO login work?

  • Open a new browser/private window and navigate to the Drupal site login page.
  • Click the Login using Identity Provider (OpenAM) link.
  • You will be redirected to the OpenAM login page. Enter the OpenAM credentials. After successful authentication, the user will be redirected back to the Drupal site.

Additional Features:

Explore the advanced features offered by the module with full-featured trial. You can initiate the trial request using Request 7-day trial button of the module or reach out to us at drupalsupport@xecurify.com for one-on-one assistance from Drupal expert.

 Case Studies
miniOrange has successfully catered to the use cases of 400+ trusted customers with its highly flexible/customizable Drupal solutions. Feel free to check out some of our unique case studies using this link.
 Other Solutions
Feel free to explore other Drupal solutions that we offer here. The popular solutions used by our trusted customers include 2FA, User Provisioning, Website Security. 
  24*7 Active Support
The Drupal developers at miniOrange offer quick and active support for your queries. We can assist you from choosing the best solution for your use case to deploying and maintaining the solution.
Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com