How to integrate IDaaS applications using SAML

更新时间:
复制 MD 格式

This topic describes how to integrate Alibaba Cloud IDaaS applications with a SAML 2.0 identity source on the Mobi platform.

Create an IDaaS application

  1. In Alibaba Cloud IDaaS EIAM, create an application that uses the SAML 2.0 protocol and name it mobi-saml-example.

  2. Open the IDaaS IdP metadata URL in a browser to view the SAML IdP information. Then, copy the IDaaS IdP metadata.

    image

  3. Configure the assertion attributes that IDaaS returns.

Create a SAML identity source in the Mobi platform

  1. Enter the basic information for the identity source.

  2. Paste the IDaaS IdP metadata that you copied from the IDaaS application into Mobi to complete the import.

  3. Configure other advanced properties.

    Note

    The configurations for properties such as Post Binding Request, Post Binding Response, Post Binding Logout, and Name ID Policy Format must match the assertion attributes returned by IDaaS.

  4. Configure identity attribute mappings.

    Note

    Configure the identity attribute mappings based on the SAML assertion attributes that you set in the IDaaS application.

    • Configure the Username mapping.

    • Configure the Email mapping.

    • Configure the Phone Number mapping.

    • Configure the Nickname mapping.

  5. Configure permission group mappings.

    By default, all users who log on from the IDaaS identity source are mapped to the END_USER permission group. Users with a status of `enabled` are mapped to the HR1 permission group. You can change the permission groups as needed.

  6. View and copy the metadata URL of the Mobi SAML 2.0 identity source.

IDaaS application configuration

  1. Paste the metadata URL from the previous step into the metadata configuration section of the IDaaS application.

  2. Add an account in IDaaS.

Verify the logon in Mobi

  1. Create an application and select SAML 2.0 as the default logon method for PCs.

  2. After you publish and access the application, the IDaaS logon interface is displayed.

  3. After a successful logon, the corresponding user information is displayed in the Mobi user management interface.