The SAMLSSO plugin requires an enterprise license.

This plugin is for advanced users in an organization using SAML.


The top half controls the connection parameters to the SAML provider server.
We provide an example screenshot for an OKTA account. Both HTTP POST and redirect modes are supported.


The lower half controls what to do with the resulting user that is validated once they are redirected back to your CrushFTP server. This mainly contains configuration items related to LDAP. An LDAP server is required for looking of role associations for the user that SAML validated.


The final item is using a Url like this to make CrushFTP redirect a user to the SAML provider.
This could be placed on your login page, or even use javascript to auto redirect the user to that URL.

Be certain the Preferences, Misc tab has the remember invalid usernames configured to 0 seconds or your SAML login will get rejected since CrushFTP caches the username as being invalid and doesn't even ask the plugin.

Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
saml1.png 177.8 kB 1 02-Nov-2015 16:20 Ben Spink
saml2.png 211.5 kB 1 02-Nov-2015 16:20 Ben Spink
« This page (revision-3) was last changed on 02-Nov-2015 16:26 by Ben Spink
G’day (anonymous guest)


New: CrushFTPv9#


CrushFTP7 | What's New

Referenced by

JSPWiki v2.8.2
View PDF