Enterprise Licenses Only
#


Prerequisits: on the Preferences panel Misc page need to set the Remember invalid usernames parameter value to 0 and clear the HTTP Redirect Base field value. This is a must with any plugin integration scenario.#



Amazon supports custom SAML 2.0 applications. See https://docs.aws.amazon.com/singlesignon/latest/userguide/samlapps.html
Restriction!!!: Redirect of CrushFTP user to the SAML provider is not supported.
https://domain.com/?u=SSO_SAML&p=redirect


1. Amazon SSO SAML 2.0 Configurations:#


Open the IAM Identity Center Console https://console.aws.amazon.com/singlesignon and create a new custom application.

custom_app.png

Configure the name, Application ACS URL, and SAML Audience, then submit the application.
Application ACS URL example:
https://your.crushftp.com/?u=SSO_SAML&p=none

SAML Audience example:
https://your.crushftp.com/


custom_app_settings.png

Configure the attribute mappings of your application.

custom_app_attribute_mappings_edit.png

Add new attribute mapping.
Maps to this string value or user attribute in IAM Identity Center:
${user:subject}

csutom_app_new_attribute.png

Warning: Assign users/groups to the created application!

custom_app_assign_users.png

2. SAMLSSO plugin configuration
#


Download the IAM Identity Center SAML metadata file.
[Amazon SSO SAML 2.0 Configuration]                                    [CrushFTP settings] 

entityID value of IAM Identity Center SAML metadata XML file        -> SAML Provider URL (EntityID)

Application SAML audience                                           -> SAML Audience

SingleSignOnService SAML:2.0:bindings:HTTP-POST Location value 
of IAM Identity Center SAML metadata XML file                       -> IDP Redirect URL (HTTP-POST)

IAM Identity Center SAML issuer URL                                 -> SAML Issuer

X509Certificate value of IAM Identity Center SAML metadata XML file -> Base64 encoded PEM Signing certificate

On CrushFTP SAMLSSO plugin for "Authentication type:" set "urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport".

urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport


custom_app_crushftp_settings.png

Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
png
csutom_app_new_attribute.png 55.0 kB 2 27-Mar-2023 10:28 krivacsz
png
custom_app.png 105.1 kB 1 27-Mar-2023 09:34 krivacsz
png
custom_app_assign_users.png 64.1 kB 1 27-Mar-2023 10:41 krivacsz
png
custom_app_attribute_mappings_... 43.2 kB 1 27-Mar-2023 10:21 krivacsz
png
custom_app_crushftp_settings.p... 217.3 kB 1 29-Mar-2023 03:46 krivacsz
png
custom_app_settings.png 149.6 kB 1 27-Mar-2023 10:13 krivacsz
« This page (revision-46) was last changed on 28-Feb-2024 16:26 by Ada Csaba
G’day (anonymous guest)
CrushFTP10 | What's New

Referenced by
LeftMenu

JSPWiki