Articles avec le tag :
Fermer
Changelog
Fermer
Centre d'aide
Control Panel

How to configure ONLYOFFICE SP and OneLogin IdP

Introduction

Single Sign-on (SSO) is a technology that allows users to sign in only once and then get access to multiple applications/services without re-authentication.

If a web portal includes several large independent sections (forum, chat, blogs etc.), a user can undergo the authentication procedure within one of the services and automatically get access to all other services without entering credentials several times.

SSO is always ensured by the joint operation of two applications: an Identity Provider and a Service Provider (hereinafter referred to as "IdP" and "SP"). ONLYOFFICE SSO implements the SP only. A lot of different providers can act as an IdP, but this article considers the OneLogin implementation.

Preparing ONLYOFFICE Enterprise Edition for the SSO setup

  1. Install ONLYOFFICE Enterprise Edition v9.1.0 for Docker or any later version with the SSO support.
  2. Add a domain name, e.g., myportal-address.com.
  3. On your portal, go to the Control Panel -> HTTPS, create and apply the letsencrypt certificate for the traffic encryption (to enable HTTPS on your portal).
  4. Go to the host computer, copy the private key and public certificate values that you used to enable HTTPS and save them using any text editor, e.g. Notepad (these values will be required later to configure SSO).
It's not necessary to perform Step 4 if you already have valid certificates or want to use self-signed certificates.

Creating an IdP in OneLogin

  1. Sign up for OneLogin, if you have not yet registered.
  2. Sign in to OneLogin as an administrator.
  3. Go to the APPS -> Add Apps menu.
  4. In the Find Application search field, type in the following text: SAML Test Connector (Idp:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  5. Select an appropriate option among the received results, e.g., SAML Test Connector (IdP) w/encrypt.
  6. In a new window that opens, enter any Display Name to distinguish this application from others, replace icons with your own ones and click the Save button.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  7. Go to the Configuration submenu and fill in the fields according to the table below:
    Please specify your own domain name or public IP where your ONLYOFFICE SP is hosted instead of myportal-address.com.
    Application Details
    RelayState https://myportal-address.com
    Audience https://myportal-address.com/sso/
    Recipient https://myportal-address.com/sso/acs
    ACS (Consumer) URL Validator ^https:\/\/myportal-address\.com\/sso\/acs\/$
    ACS (Consumer) URL https://myportal-address.com/sso/acs
    Single Logout URL https://myportal-address.com/sso/slo/callback
    SAML Encryption
    Public key *
    -----BEGIN CERTIFICATE-----
    MIIE9zCCA9+gAwIBAgISA5VHo5m3/9NM1/gv8SDlE7vxMA0GCSqGSIb3DQEBCwUA
    MEoxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MSMwIQYDVQQD
    ExpMZXQncyBFbmNyeXB0IEF1dGhvcml0eSBYMzAeFw0xNzA1MzExNTEzMDBaFw0x
    NzA4MjkxNTEzMDBaMBUxEzARBgNVBAMTCmRvY2tlcjQudGswggEiMA0GCSqGSIb3
    DQEBAQUAA4IBDwAwggEKAoIBAQC/LuH8Hcu0DUz2b8lFiUYHK1l2R55m/3ap9DsA
    /BbOJdbnFm/v5dTgUL4Vx73aX8vl2I5ePh5siNrhEuc7d8VfQ62WqLHM/3jz0wVi
    vFJN4rRVZAOK/S7zfTGf6HUloi0Jg+Rol2zh0IfWUN+UczClJ0b0zewYEF8ZLhNY
    W65X2fx6BahK6zbRotNj3tJy0zib6znqBOPhT999pnk5L0S+CfzNhVHH/V+lPVtX
    Tu9tSILnFQpVAsv3oKo/7n/N/F9t5bI/kMllXQFReq1a+9KTOv0OlZgEd7xMu8ht
    707IdILRBAW3f1iMMT43DpmjkcST7NnNEbsLXSlBIwKz8GENAgMBAAGjggIKMIIC
    BjAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMC
    MAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFOqivMdw2WduQJmO1lXsq9E3zEvmMB8G
    A1UdIwQYMBaAFKhKamMEfd265tE5t6ZFZe/zqOyhMG8GCCsGAQUFBwEBBGMwYTAu
    BggrBgEFBQcwAYYiaHR0cDovL29jc3AuaW50LXgzLmxldHNlbmNyeXB0Lm9yZzAv
    BggrBgEFBQcwAoYjaHR0cDovL2NlcnQuaW50LXgzLmxldHNlbmNyeXB0Lm9yZy8w
    FQYDVR0RBA4wDIIKZG9ja2VyNC50azCB/gYDVR0gBIH2MIHzMAgGBmeBDAECATCB
    5gYLKwYBBAGC3xMBAQEwgdYwJgYIKwYBBQUHAgEWGmh0dHA6Ly9jcHMubGV0c2Vu
    Y3J5cHQub3JnMIGrBggrBgEFBQcCAjCBngyBm1RoaXMgQ2VydGlmaWNhdGUgbWF5
    IG9ubHkgYmUgcmVsaWVkIHVwb24gYnkgUmVseWluZyBQYXJ0aWVzIGFuZCBvbmx5
    IGluIGFjY29yZGFuY2Ugd2l0aCB0aGUgQ2VydGlmaWNhdGUgUG9saWN5IGZvdW5k
    IGF0IGh0dHBzOi8vbGV0c2VuY3J5cHQub3JnL3JlcG9zaXRvcnkvMA0GCSqGSIb3
    DQEBCwUAA4IBAQBItwpwwcQGMvap2hGhBQnZoS8bJ5iuq24KmEl3TrLdtLyklPy2
    oR1HXgfW5fpTCGP744pVBwGXO2A8+2J6/wcNybo/odoB9dSzAMfRtXQR83XN4F8l
    6E5zShBZ1kkzJayk4RytSzBR+uyTR1J7erK1MxlmOgQfLp2JqQsdEO6qpycER5pY
    mK77eWGrEE2+tOwgY4amlnLgBSif+nieUgQiSRboHGSF6nizES2pBKTk595P4pzK
    9W5ax4zjqwQnMQujcjrHm7kbny2gFLH1wl0MY0yRlBytaFOhSWvr2g5JDFjgoFtd
    xEe8PMKA+cfU+0SznX/ynMgrz4MqSRRtQChx
    -----END CERTIFICATE-----
    * This is the example of the HTTPS certificate for the myportal-address.com domain name created using the letsencrypt service.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  8. Click the Save button and go to the Parameters submenu. Use the Add parameter link to create 5 parameters (givenName, sn, mail, title, mobile) checking the Include in SAML assertion option for all of them:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  9. Edit values of each parameter selecting an appropriate value from the list:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  10. Once you fill in all the necessary fields for SAML assertion attributes in the IdP, you should receive nearly the same result as shown in the figure below. Click the Save button.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  11. Go to the SSO submenu:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
    Copy the link from the Issuer URL field (e.g., https://app.onelogin.com/saml/metadata/666179) and go to the ONLYOFFICE portal signing in as an administrator. Open the Control Panel -> SSO page.

Configuring ONLYOFFICE SP

  1. Make sure that you are signed in as an Administrator to your ONLYOFFICE Control Panel and click the SSO tab.
    You can only register one enterprise Identity Provider for your organization on the ONLYOFFICE portal.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  2. Enable SSO using the Enable Single Sign-on Authentication switcher and paste the link copied from the OneLogin issuer URL into the URL to Idp Metadata XML field.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP

    Press the button with the upward arrow to load the IdP metadata. The ONLYOFFICE SP Settings form will be automatically filled in with your data from the OneLogin IdP.

  3. Now you need to add certificates to the SP Certificates section. You can add the certificates used earlier when enabling HTTPS or any other certificates.
    the public certificate in OneLogin must be the same that you upload in the SP Certificates section and the private key must correspond to it.

    You should get nearly the same result:

    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
    It is not necessary to adjust the Attribute Mapping form, since we specified the same parameters when creating OneLogin IdP.
  4. Click the Save button. The ONLYOFFICE SP Metadata section should be opened. Verify that our settings are publicly available by clicking the Download SP Metadata XML button. The XML file contents should be displayed.

Creating users in OneLogin and giving them access to ONLYOFFICE

To create users in OneLogin and provide them access to our ONLYOFFICE SP, perform the following steps:

  1. go to the OneLogin All Users page signing in as an administrator,
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  2. create a new user or edit an existing one,
  3. go to the Applications submenu,
  4. select our newly created application from the list and click CONTINUE,
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  5. in a new window that opens add the missing data if necessary or just close the window,
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  6. click the SAVE USER button,
  7. now the user is able to work in ONLYOFFICE SP.

Checking the work of the ONLYOFFICE SP with the OneLogin IdP

Logging in to ONLYOFFICE on the SP side
  1. Go to the ONLYOFFICE Authentication page (e.g., https://myportal-address.com/auth.aspx).
  2. Click the Single sign-on link below the Sign In button (if the link is missing, this means that SSO is not enabled).
  3. If all the SP and IdP parameters are set correctly, we will be redirected to the OneLogin IdP login form:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  4. Enter the login and password of the user who has been granted access to the ONLYOFFICE SP and click the LOG IN button.
  5. If you get the following page, this means that the user has not been granted access to ONLYOFFICE SP:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP

    In this case you will need to log out from OneLogin and repeat steps 1-4, but using another user credentials.

  6. If the credentials are correct, we will be redirected to the main page of the portal (the user will be created automatically if missing, or the data will be updated if changed in the IDP).
Profiles for users added with SSO authentication

The possibility to edit user profiles created using the SSO authentication is restricted. The user profile fields received from the IdP are disabled for editing (i.e. First Name, Last Name, Email, Title and Location). You can edit these fields from your IdP account only.

The figure below shows the Actions menu for an SSO user:

How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP

The following figure shows an SSO user profile opened for editing:

How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP

The users created using the SSO authentication are marked with the SSO icon in the user list for the portal administrators:

How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
Logging out from ONLYOFFICE SP
  1. Logout can be made from the portal using the Sign Out menu. The user should also be automatically logged out from the OneLogin IdP in case he/she is logged out from all other applications that he/she has been granted access to in OneLogin and that he/she previously signed in to.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  2. If you signed out successfully, you will be redirected to the portal authentication page.
  3. If you go to the application page (e.g., https://companypage.onelogin.com/login), you will see the login form:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
Logging in to ONLYOFFICE on the Onlogin IdP side
  1. Go to your company page in OneLogin (e.g. https://companypage.onelogin.com/login).
  2. Sign in using your OnleLogin credentials.
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  3. If the credentials are correct, you will be redirected to the page of the applications that you have been granted access to by your company administrator in OneLogin. Click on the necessary application (e.g., SAML Test Connector (IdP) w/encrypt).
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  4. If all the settings are correct, you will be redirected to the myportal-address.com portal.
Logging out from OneLogin IdP
  1. Go to your company page in OneLogin (e.g. https://companypage.onelogin.com/) and click the Log Out option:
    How to configure ONLYOFFICE SP and OneLogin IdP How to configure ONLYOFFICE SP and OneLogin IdP
  2. If everything is correct, you will be signed out from the portal and redirected to the OneLogin login page.
Download Host on your own server Available for Docker,
Windows, Linux and virtual machines
Cela peut vous aider aussi :
Fermer