37-12
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 37 Configuring Clientless SSL VPN
Getting Started
Configuring SSO Authentication Using SAML Browser Post Profile
This section describes configuring the security appliance to support Security Assertion Markup
Language (SAML), Version 1.1 POST profile Single Sign-On (SSO) for authorized users. SAML SSO
is supported only for clientless SSL VPN sessions. This section includes:
•
Task Overview: Configuring SSO with SAML Post Profile
•
Detailed Tasks: Configuring SSO with SAML Post Profile
•
SSO Server Configuration
After a session is initiated, the security appliance authenticates the user against a configured AAA
method. Next, the security appliance (the asserting party) generates an assertion to the relying party, the
consumer URL service provided by the SAML server. If the SAML exchange succeeds, the user is
allowed access to the protected resource.
Figure 37-1
shows the communication flow:
Figure 37-1
SAML Communication Flow
Note
The SAML Browser Artifact profile method of exchanging assertions is not supported.
Task Overview: Configuring SSO with SAML Post Profile
This section presents an overview of the tasks necessary to configure SSO with SAML Browser Post
Profile. These tasks are:
•
Specify the SSO server with the
sso-server
command.
•
Specify the URL of the SSO server for authentication requests (the
assertion-consumer-url
command)
•
Specify the security appliance hostname as the component issuing the authentication request (the
issuer
command)
•
Specify the trustpoint certificates use for signing SAML Post Profile assertions (the
trustpoint
command)
Optionally, in addition to these required tasks, you can do the following configuration tasks:
•
Configure the authentication request timeout (the
request-timeout
command)
•
Configure the number of authentication request retries (the
max-retry-attempts
command)
After completing the configuration tasks, you assign an SSO server to a user or group policy.
250105
User
Browser
User Login
Access to
Applications
Security
Applications
SAML SSO
Assertion
Redirection to
Applications
Portal (with
cookie)
SAML
Server
Protected
Resource
URL
(Web Agent)
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......