Single Sign-On For Owncloud As SP And Joomla As IDP



About Owncloud

OwnCloud is an open-source file hosting application provides services for business and personal use. It is a flexible tool which manages file and data synchronization. It helps users to store files, folders, contacts, photo galleries, calendars and more on a server of your choice. It is a self-hosted file sync and share server that is all under your control. Content can be shared by defining granular read/write permissions between users and groups. To use the application effectively you can be logged in into Owncloud using SSO. Single sign-on helps employees save time, prevents lost or forgotten passwords, and reduces the risk of password theft.

Challenge

To achieving Single Sign-On between Identity Provider(Joomla) and Service Provider (Owncloud) both need to supports SAML. Owncloud supports SAML connection but it is supported in the Owncloud enterprise version. Single Sign-On user can log in into IdP based site and gain access to Owncloud services. Identity Provider can manage the identity details of users and give the authorization to use the resources of the service provider.

Solution

The SAML IDP plugin makes SAML connection between Joomla and Owncloud. miniOrange SAML IDP Plugin is an authentication component that serves identity details to the service provider for on-premise, cloud, and mobile. SAML single sign-on (SSO) compliance makes it possible for users to authenticate through identity provider when they login to Owncloud applications. SAML SSO module acts as an Identity Provider which can be configured to build the trust between the module and Owncloud Service Provider. SAML exchanges security and identity-related information such as authorization and authentication. The user can easily log in to Owncloud using their Joomla credentials.

How miniOrange SAML plugin can work for Owncloud?

Owncloud sso

Steps to configure Owncloud as SP:

    Step 1:

  • Go to Service Provider tab in the plugin and enter the following values:
    Service Provider NameOwncloud(You can enter any name)
    SP Entity ID or Issuer Owncloud Entity ID
    ACS URLOwncloud ACS URL
    Single Logout URLSingle Logout URL of the Owncloud.
    X.509 Certificate (optional)[For Signed Request]Paste X.509 Certificate from STEP 1 for Signed Request.
    NameID FormatSelect NameID format for Owncloud
    Assertion SignedOwncloud signed Assertion.
  • Click on Save to save your settings.

Step 2:

There are two ways to setup the Owncloud. You can either import the metadata url of the IdP or provide individual values required by the Owncloud from Joomla Identity Provider (plugin). You can find both under IDP METADATA tab in the plugin.

Here is an example of setting up Owncloud as a Service Provider.


  • Log in to your Owncloud’s Admin Console.
  • Go to Security Settings.
  • Under Security Settings go to Setup up single sign-on (SSO) settings.
  • You will need to provide the following information in Owncloud from the plugin’s IDP METADATA Tab under the Setup SSO with Third party Identity Provider Section:
  • Sign-in page URL SAML Login URL from the IDP METADATA Tab.
    Sign-out page URL SAML Logout URL from the IDP METADATA Tab.
    Verification Certificate Upload the certificate from the IDP METADATA Tab

Step 3:

If your Service Provider needs an extra user attributes or custom attributes to be sent in the SAML response then you can configure this under the Attribute/Role Mapping Tab.

Free Trial

If you don't find what you are looking for, please contact us at info@xecurify.com or call us at +1 978 658 9387 to find an answer to your question about Owncloud Single Sign On (SSO).