Okta SAML Single sign-on (SSO) is an authentication method that enables Okta
users to access multiple Joomla applications with one login and one set of credentials.
Our plugin is compatible with Joomla 4 as well as with all the SAML 2.0 compliant Identity Providers.
Here we will go through a step-by-step guide to configure SAML SSO login between Joomla site and Okta by considering
Okta as IdP (Identity Provider) and Joomla as SP (Service Provider).
What is SSO ?
Single sign-on (SSO) is an authentication method that enables users to
access multiple applications with one-click login and one set of credentials. For example,
after users log in to your org, they can automatically access all apps from the App Launcher. When you set up
SSO, you configure one system to trust another to authenticate users , eliminating users' need
to log in to each system separately. The system that authenticates users is called an Identity
provider. The system that trusts the identity provider for authentication is called the
Service provider.
SAML allows exchanging of information between Service Provider and Identity provider, SAML is
integration between SP and IDP. When a user tries to log in, your identity provider sends SAML
assertions containing facts about the user to Identity Provider. Identity Provider receives the assertion,
validates it against your Identity Provider configuration, and allows the user to access your org.
Okta Single Sign On (SSO) for Joomla miniOrange provides a ready to use solution for Joomla.
This solution ensures that you are ready to roll out secure access to your Joomla site using Okta within
minutes.
Joomla SAML app gives the ability to enable SAML Single Sign-On for Joomla Site. Joomla site is
compatible with all SAML Identity Providers. Here we will go through a guide to configure SAML SSO between Joomla
and your Identity Provider. By the end of this guide, users from your Identity Provider should be able to login and
register to Joomla site.
Pre-requisites : Download And Installation
Configuration Support and Free Trial
If you want support in configuring the plugin, or to integrate Okta with Joomla, click on Free
Configuration Setup button.
We provide a 7 day full feature trial wherein you can fully test out all the features of the plugin, click on
Free Business Trial button.
Steps to
Integrate Okta Single Sign-On (SSO) with Joomla SAML SP
1. Download and setup
Joomla SAML SP Plugin
- Download the zip file for the miniOrange SAML SP plugin for Joomla from the link here.
- Login into your Joomla site’s Administrator console.
- From left toggle menu, click on System, then under Install section click on
Extensions.
- Here click on Browse for file button to locate and install the plugin file downloaded earlier.
- Installation of plugin is successful. Now click on Start Using miniOrange SAML SP plugin.
- Then go to the Service Provider Metadata Tab, scroll down and copy the
SP-EntityID and the ACS URL.
2. Configure Okta as
Identity Provider
- Login into your Okta Admin
dashboard.
- Then click on the Appictions tab from the side-panel and then select
Applications.
- You will get the following screen. Click on Create App Integration button.
- Select SAML 2.0 as Sign-On method and Click on Next button.
- In General Settings tab, enter App Name and click on Next
button.
- In Configure SAML tab, enter the required details:
Single Sign On URL |
ACS (AssertionConsumerService) URL from the Service Provider Metadata tab of the Plugin |
Audience URL (SP Entity ID) |
SP Entity ID / Issuer from the Service Provider Metadata tab of the Plugin |
Default Relay State |
Relay State from the Service Provider Metadata tab of the Plugin |
Name ID Format |
Select E-Mail Address as a Name Id from dropdown list |
Application Username |
Okta username |
- Configure Attribute Statements and Group Attribute Statements (Optional),then click on
Next button.
- Navigate to the application you created and click on the Assignments Tab. Then click on
Assign button to Assign People and Assign Groups.
- Once you Assign the user, click on Done button.
- Navigate to Sign On tab and navigate to the the SAML Signing Certifiacte
section.
- Click on Action dropdown for the Active certificate and then click on the
View
IdP Metadata
option to get
IdP Metadata which will be required for configuring your Service Provider.
- You have successfully configured Okta as SAML Identity Provider, ensuring secure Okta Login
into Joomla
Site.
3.
Configure Okta Identity Provider with Joomla SAML Service Provider
- In Joomla SAML plugin, go to Service Provider Setup Tab, then click on Upload IdP
metadata.
- Enter Metadata URL (Copied from Okta app) and click on Fetch Metadata.
- Or, Click on choose metadata file and click on Upload.
- Then Click on Save, and then Click on Test Configuration.
- Congratulaions we have successfully configured Joomla SAML Service Provider with Okta as Identity Provider.
4. Attribute Mapping - Premium
Feature (Included with Business
Trial)
- Attributes are user details that are stored in your Identity Provider.
- Attribute Mapping helps you to get user attributes from your Identity Provider (IdP) and map them to Joomla user
attributes like firstname, lastname etc.
- While auto registering the users in your Joomla site these attributes will automatically get mapped to your
Joomla user details.
- In Joomla SAML plugin, go to Attribute Mapping tab and fill in all the fields.
Username: |
Name of the username attribute from IdP (Keep NameID by default) |
Email: |
Name of the email attribute from IdP (Keep NameID by default) |
Group/Role: |
Name of the Role attribute from Identity Provider(IdP) |
- You can check the Test Configuration Results under Service Provider Setup tab
to get a better idea of which values to map here.
5. Group Mapping - Premium
Feature (Included with Business
Trial)
- Role mapping helps you to assign specific roles to users of a certain group in your Identity Provider (IdP).
- While auto registering, the users are assigned roles based on the group they are mapped to.
6. Redirection & SSO
Links
- Go to Login Settings tab. There are multiple features availabe in this tab like Auto redirect the user
to Identity Provider and Enable Backed Login for Super Users. To use these features, click on the
respective checkboxes.
You have successfully completed your miniOrange SAML 2.0 SP configurations. Still, if you are
facing any difficulty please mail us on
joomlasupport@xecurify.com .
Recommended Add-Ons
User Sync SCIM Provisioning
Synchronize users, groups & directory with SCIM & REST APIs for Server.
Know More
Page Restriction
Page Restriction plugin restricts Joomla pages (Articles) based on User
Roles and User's Login Status.
Know More
Integrate with Community Builder Customer
Using this Add-on you would be mapping the user details into the CB's
comprofilers fields table which contains the values.
Know More
How miniorange Joomla SAML SSO plugin works?
SAML 2.0 SP Single Sign On ( SAML SSO) - Service Provider Plugin acts as a SAML
2.0
Service Provider which can be configured to establish the trust between the Joomla site and
various SAML 2.0 supported Identity Providers to securely authenticate (Secure
Login)
the user to the Joomla site.
SAML 2.0 SP Single Sign On (SSO) - Service Provider plugin also provides Cross-Domain / Sub-domain login
sharing
with other Joomla websites.
We also provide a separate plugin that enables Joomla to act as an Identity Provider. It
supports authentication with Joomla, user management, session management, change password,
etc. You can configure any service provider with your Joomla site with the help of this
plugin.
What is the use of the configuration or integration with SAML SSO?
Miniorange Provides best SAML Single Sign-On (SSO) solution to Okta.
SSO reduces the number of attack surfaces because users only log in once each day and only use one set of
credentials. Reducing login to one set of credentials improves enterprise
security. When employees have to use separate passwords for each app, they usually
don't.
Okta [SAML] Single Sign-On (SSO) login for Joomla can be achieved by using our
Joomla SAML SP Single Sign-On(SSO) plugin. Our plugin is compatible with all the SAML
compliant
Identity providers. Here we will go through a step-by-step guide to configure SAML SSO login between the
Joomla
site and Okta.
Additional
Resources.
Miniorange Joomla SAML Single sign-on(web SSO) supports multiple known IDPs like ADFS,
Azure
AD, Okta,
Shibboleth, Okta, Okta,
SimpleSamlPhp, Google apps, Bitium, OpenAM, miniorange IDP, Centrify and many more.
Business
Trial
If you want Business Trial for FREE Click Here
If you don't find what you are looking for, please contact us at joomlasupport@xecurify.com or call us at
+1
978 658 9387.