User Tools

Site Tools


sso_authentication

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
sso_authentication [2019/07/09 11:48] – [Create the Relying Party Trust in AD FS] lucysso_authentication [2019/08/23 15:49] lucy
Line 20: Line 20:
   * ADFS 4.0 (Windows Server 2016)   * ADFS 4.0 (Windows Server 2016)
   * ADFS 5.0 (Windows Server 2019)   * ADFS 5.0 (Windows Server 2019)
 +  * Azure AD (refer to [[sso_azure|this guide]] to have a detailed instructions)
  
 The connection to the AD FS can be configured within the Settings / SSO Configuration:  The connection to the AD FS can be configured within the Settings / SSO Configuration: 
Line 74: Line 75:
   * On your AD FS server, open the **AD FS Management** console, expand **Trust Relationships** and select the **Relying Party Trusts** node. In the Actions pane, click **Add Relying Party Trust**:   * On your AD FS server, open the **AD FS Management** console, expand **Trust Relationships** and select the **Relying Party Trusts** node. In the Actions pane, click **Add Relying Party Trust**:
  
-**Attention** :!: If the Lucy Admin Console is configured on a non-standard port (for example, port 8443, see more [[firewall_security_settings|here]]), then you will need to add two separate entry of Relying Party Trust with the identical parameters, but different Federation metadata address (URL). \\+**Attention** :!: If the Lucy Admin Console is configured on a non-standard port (for example, port 8443, see more [[firewall_security_settings|here]]), then you will need to add **two separate entry of Relying Party Trust** with the identical parameters, but different Federation metadata address (URL): \\ 
 +The first will be: **https://lucydomain.com/service-provider/endpoint/metadata/lucy-sp** \\ 
 +Second: **https://lucydomain.com:8443/service-provider/endpoint/metadata/lucy-sp** \\ 
 +\\
 In case access to the Lucy Admin Console is limited to a range of IP addresses, you must include an ADFS server in this range. In case access to the Lucy Admin Console is limited to a range of IP addresses, you must include an ADFS server in this range.
  
sso_authentication.txt · Last modified: 2021/03/16 14:36 by lucy