Search Results :

×

SAML Single Sign On (SSO) into Drupal using SecureAuth as IdP


Drupal SAML SecureAuth SSO setup will allow the user to login to Drupal site using their SecureAuth Credentials. Drupal SAML module gives the ability to enable SAML Single Sign-On for Drupal. This module is compatible with all SAML Identity Providers (IDP). We provide Drupal SAML SP 2.0 Single Sign on (SSO) - SAML Service Provider module which is compatible with Drupal 7, Drupal 8 Drupal 9 as well as Drupal 10. This guide will walk you through the steps to configure SAML SSO between Drupal and SecureAuth IDP.

Installation Steps


  • Download the module:
    Composer require 'drupal/miniorange_saml'
  • Navigate to Extend menu on your Drupal admin console and search for miniOrange SAML Service Provider using the search box.
  • Enable the module by checking the checkbox and click on install button.
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup
  • Install the module:
    drush en drupal/miniorange_saml
  • Clear the cache:
     drush cr
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup
  • Navigate to Extend menu on your Drupal admin console and click on Install new module button.
  • Install the Drupal SAML SP 2.0 Single Sign On (SSO) - SAML Service Provider module either by downloading the zip or from the URL of the package (tar/zip).
  • Click on Enable newly added modules.
  • Enable this module by checking the checkbox and click on install button.
  • Configure the module at
    {BaseURL}/admin/config/people/miniorange_saml/idp_setup

Steps to configure SecureAuth SAML Single Sign-On (SSO) Login into Drupal site

1. Configure SecureAuth as SAML IdP (Identity Provider)

Follow the steps to configure SecureAuth as IDP

  • In the miniOrange SAML SP SSO module, navigate to Service Provider Metadata tab. Here, you can find the SP metadata such as SP Entity ID and ACS (AssertionConsumerService) URL which are required to configure the Identity Provider.
  • Druapl get SP Metadata
  • Log in to your SecureAuth IDP Admin console.
  • Now go to Post Authentication tab.
  • In the Post Authentication section, set Authenticated User Redirect to SAML 2.0 (SP Initiated) Assertion.

    SecureAuth as SAML IdP - SecureAuth Single Sign-On (SSO) Login for Drupal - Post Authentication
  • In the User ID Mapping section, make the following entries:
    User ID Mapping Set to Email 1.
    Name ID Format Set to urn:oasis:names:tc:SAML:2.0:nameid-format-unspecified.
    Encode to Base64 Set to False.
    SecureAuth as SAML IdP - SecureAuth Single Sign-On (SSO) Login for Drupal - User ID Mapping
  • In the SAML Assertion / WS Federation section, make the following entries:

    WSFed Reply To /SAML Target URL Enter ACS (Assertion Consumer Service) URL from Service Provider Metadata tab of the module
    SAML Consumer URL Enter SP Entity ID / Issuer from Service Provider Metadata tab of the module
    WSFed/SAML Issuer Enter unique name that identifies the SecureAuth IDP to the application (as the SAML ID). This value is shared with the application and can be any word, phrase, or URL, but must match exactly in the SecureAuth IDP and Drupal configurations. For example, https://secureauthfqdn/realm12
    SAML Recipient Enter Recipient URL from Service Provider Metadata tab of the module
    Sign SAML Assertion Set Sign SAML Assertion to True.
    Sign SAML Message Set Sign SAML Message to False.
     SecureAuth as SAML IdP - SecureAuth Single Sign-On (SSO) Login for Drupal - SAML Assertion
  • Leave the default value in the Signing Cert Serial Number field
  • Set the Domain to the SecureAuth IDP appliance URL or IP Address to download the metadata file. For example, https://secureauthfqdn

  • SecureAuth as SAML IdP - SecureAuth Single Sign-On (SSO) Login for Drupal - Download Metadata
  • Click on Download link to download the SecureAuth IDP metadata file or note down the given information and keep it handy to configure the Service Provider.

  • You have successfully configured SecureAuth as SAML IDP (Identity Provider) for achieving SecureAuth SSO login into your Drupal Site.

2. Configuring Drupal as Service Provider

  • In miniOrange SAML module, go to Service Provider Setup tab. There are two ways to configure the module:
    • miniOrange image By Uploading SecureAuth IDP Metadata File:

      • Click on Upload IDP Metadata.
      • Enter the Metadata URL and click on Fetch Metadata button.
      • Upload metadata file and click on Upload File button.
      • Upload IDP metadata

      miniOrange image Manual Configuration :

      • Provide the required settings (i.e. Identity Provider Name, IDP Entity ID or Issuer, SAML Login URL, X.509 Certificate) as provided by your Identity Provider and click on the Save button.
      • Once you are done with configuration steps, click on the Test Configuration button.
      • Test Configuration

If the test configuration is successful the module is successfully configured. If you face any issues in test configuration you can reach us at drupalsupport@xecurify.com with the screenshot of the test configuration window.

Additional Features:

Explore the advanced features offered by the module with full-featured trial. You can initiate the trial request using Request 7-day trial button of the module or reach out to us at drupalsupport@xecurify.com for one-on-one assistance from Drupal expert.

 Case Studies
miniOrange has successfully catered to the use cases of 400+ trusted customers with its highly flexible/customizable Drupal solutions. Feel free to check out some of our unique case studies using this link.
 Other Solutions
Feel free to explore other Drupal solutions that we offer here. The popular solutions used by our trusted customers include 2FA, User Provisioning, Website Security. 
  24*7 Active Support
The Drupal developers at miniOrange offer quick and active support for your queries. We can assist you from choosing the best solution for your use case to deploying and maintaining the solution.
Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com