Update Okta SSO image convention
@@ -1,147 +0,0 @@
|
|||||||
---
|
|
||||||
title: "SSO"
|
|
||||||
description: "Log in to Infisical via SSO protocols"
|
|
||||||
---
|
|
||||||
|
|
||||||
<Warning>
|
|
||||||
Infisical currently only supports SAML SSO authentication with [Okta as the
|
|
||||||
identity provider (IdP)](https://www.okta.com/). We're expanding support for
|
|
||||||
other IdPs in the coming months, so stay tuned with this issue
|
|
||||||
[here](https://github.com/Infisical/infisical/issues/442).
|
|
||||||
</Warning>
|
|
||||||
|
|
||||||
You can configure your organization in Infisical to have members authenticate with the platform via protocols like [SAML 2.0](https://en.wikipedia.org/wiki/SAML_2.0).
|
|
||||||
|
|
||||||
To note, configuring SSO retains the end-to-end encrypted architecture of Infisical because we decouple the **authentication** and **decryption** steps. In all login with SSO implementations,
|
|
||||||
your IdP cannot and will not have access to the decryption key needed to decrypt your secrets.
|
|
||||||
|
|
||||||
## Configuration
|
|
||||||
|
|
||||||
Head over to your organization Settings > Authentication > SAML SSO Configuration.
|
|
||||||
|
|
||||||
Next, press "Set up SAML SSO" in the SAML SSO and follow the instructions
|
|
||||||
below to configure SSO for your identity provider:
|
|
||||||
|
|
||||||
<Note>
|
|
||||||
Note that only members with the `owner` or `admin` roles in an organization
|
|
||||||
can configure SSO for it.
|
|
||||||
</Note>
|
|
||||||
|
|
||||||
<AccordionGroup>
|
|
||||||
<Accordion title="Okta SAML">
|
|
||||||
1. In the Okta Admin Portal, select Applications > Applications from the
|
|
||||||
navigation. On the Applications screen, select the Create App Integration
|
|
||||||
button.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
2. In the Create a New Application Integration dialog, select the SAML 2.0 radio button:
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
3. On the General Settings screen, give the application a unique, Infisical-specific name and select Next.
|
|
||||||
|
|
||||||
4. On the Configure SAML screen, configure the following fields:
|
|
||||||
|
|
||||||
- Single sign on URL: `https://app.infisical.com/api/v1/sso/saml2/:identifier`; we'll update the `:identifier` part later in step 6.
|
|
||||||
- Audience URI (SP Entity ID): `https://app.infisical.com`
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
<Note>
|
|
||||||
If you're self-hosting Infisical, then you will want to replace `https://app.infisical.com` with your own domain.
|
|
||||||
</Note>
|
|
||||||
|
|
||||||
4. Also on the Configure SAML screen, configure the Attribute Statements to map:
|
|
||||||
|
|
||||||
- `id -> user.id`,
|
|
||||||
- `email -> user.email`,
|
|
||||||
- `firstName -> user.firstName`
|
|
||||||
- `lastName -> user.lastName`
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Once configured, select the Next button to proceed to the Feedback screen and select Finish.
|
|
||||||
|
|
||||||
5. Get IdP values
|
|
||||||
|
|
||||||
Once your application is created, select the Sign On tab for the app and select the View Setup Instructions button located on the right side of the screen:
|
|
||||||
|
|
||||||
Copy the Identity Provider Single Sign-On URL, the Identity Provider Issuer, and the X.509 Certificate to be pasted into your Infisical SAML SSO configuration details with the following map:
|
|
||||||
|
|
||||||
- `Audience -> Audience URI (SP Entity ID) from Okta`
|
|
||||||
- `Entrypoint -> Identity Provider Single Sign-On URL from Okta`
|
|
||||||
- `Issuer -> Identity Provider Issuer from Okta`
|
|
||||||
- `Certificate -> X.509 Certificate from Okta`
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
6. Create the SSO configuration and copy your SSO identifier in Infisical; update `:identifier` from step 4 earlier to be this value.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
7. Assignments
|
|
||||||
|
|
||||||
Finally, Navigate to the Assignments tab and select the Assign button:
|
|
||||||
|
|
||||||
You can assign access to the application on a user-by-user basis using the Assign to People option, or in-bulk using the Assign to Groups option.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
At this point, you have configured everything you need within the context of the Okta Admin Portal.
|
|
||||||
|
|
||||||
8. Return to Infisical and enable SAML SSO.
|
|
||||||
|
|
||||||
Enabling SAML SSO enforces all members in your organization to only be able to log into Infisical via Okta.
|
|
||||||
|
|
||||||
</Accordion>
|
|
||||||
<Accordion title="Azure SAML">
|
|
||||||
|
|
||||||
1. In the Azure Portal, navigate to the Azure Active Directory and select Enterprise applications. On this screen, select
|
|
||||||
the **+ New application** button.
|
|
||||||
|
|
||||||
TODO: insert image.
|
|
||||||
|
|
||||||
2. On the next screen, press the **+ Create your own application** button.
|
|
||||||
Give the application a unique, Infisical-specific name; choose the "Integrate any other application you don't find in the gallery (Non-gallery)"
|
|
||||||
option and hit the **Create** button.
|
|
||||||
|
|
||||||
TODO: insert image
|
|
||||||
|
|
||||||
3. On the application overview screen, select **Single sign-on** from the left sidebar. From there,
|
|
||||||
select the **SAML** single sign-on method.
|
|
||||||
|
|
||||||
4. Next, press the **Edit** button in the **Basic SAML Configuration** section and configure the following fields:
|
|
||||||
|
|
||||||
- Identifier (Entity ID): https://app.infisical.com
|
|
||||||
- Reply URL (Assertion Consumer Service URL): `https://app.infisical.com/api/v1/sso/saml2/:identifier`
|
|
||||||
|
|
||||||
<Note>
|
|
||||||
If you're self-hosting Infisical, then you will want to replace
|
|
||||||
`https://app.infisical.com` with your own domain.
|
|
||||||
</Note>
|
|
||||||
|
|
||||||
5. Next, press the **Edit** button in the **Attributes & Claims** section.
|
|
||||||
|
|
||||||
In the **Attributes && Claims** section, configure the following claims to map:
|
|
||||||
|
|
||||||
- `email -> user.userprinciplename`
|
|
||||||
- `firstName -> user.firstName`
|
|
||||||
- `lastName -> user.lastName`
|
|
||||||
|
|
||||||
Once you've done that, head back to the **Set up Single Sign-On with SAML** screen.
|
|
||||||
|
|
||||||
6. Get IdP values:
|
|
||||||
|
|
||||||
Back in Infisical > Organization settings > Authentication, select **Set up SAML SSO** and paste your Infisical SAML SSO configuration details
|
|
||||||
with the following map from the **Set up Single Sign-On with SAML** screen in Azure:
|
|
||||||
|
|
||||||
- `Audience -> Azure `
|
|
||||||
- `Entrypoint -> X`
|
|
||||||
- `Issuer -> X`
|
|
||||||
- `Certificate -> X.509 Certificate from Azure`
|
|
||||||
|
|
||||||
</Accordion>
|
|
||||||
</AccordionGroup>
|
|
||||||
@@ -0,0 +1,56 @@
|
|||||||
|
---
|
||||||
|
title: "Azure SAML"
|
||||||
|
description: "Configure Azure SAML for Infisical SSO"
|
||||||
|
---
|
||||||
|
|
||||||
|
1. In the Azure Portal, navigate to the Azure Active Directory and select Enterprise applications. On this screen, select
|
||||||
|
the **+ New application** button.
|
||||||
|
|
||||||
|
TODO: insert image.
|
||||||
|
|
||||||
|
2. On the next screen, press the **+ Create your own application** button.
|
||||||
|
Give the application a unique, Infisical-specific name; choose the "Integrate any other application you don't find in the gallery (Non-gallery)"
|
||||||
|
option and hit the **Create** button.
|
||||||
|
|
||||||
|
TODO: insert image
|
||||||
|
|
||||||
|
3. On the application overview screen, select **Single sign-on** from the left sidebar. From there,
|
||||||
|
select the **SAML** single sign-on method.
|
||||||
|
|
||||||
|
4. Next, press the **Edit** button in the **Basic SAML Configuration** section and configure the following fields:
|
||||||
|
|
||||||
|
- Identifier (Entity ID): https://app.infisical.com
|
||||||
|
- Reply URL (Assertion Consumer Service URL): `https://app.infisical.com/api/v1/sso/saml2/:identifier`
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
If you're self-hosting Infisical, then you will want to replace
|
||||||
|
`https://app.infisical.com` with your own domain.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
5. Next, press the **Edit** button in the **Attributes & Claims** section.
|
||||||
|
|
||||||
|
In the **Attributes && Claims** section, configure the following claims to map:
|
||||||
|
|
||||||
|
- `email -> user.userprinciplename`
|
||||||
|
- `firstName -> user.firstName`
|
||||||
|
- `lastName -> user.lastName`
|
||||||
|
|
||||||
|
Once you've done that, head back to the **Set up Single Sign-On with SAML** screen.
|
||||||
|
|
||||||
|
6. Get IdP values:
|
||||||
|
|
||||||
|
Back in Infisical > Organization settings > Authentication, select **Set up SAML SSO** and paste your Infisical SAML SSO configuration details
|
||||||
|
with the following map from the **Set up Single Sign-On with SAML** screen in Azure:
|
||||||
|
|
||||||
|
- `Audience -> Azure `
|
||||||
|
- `Entrypoint -> X`
|
||||||
|
- `Issuer -> X`
|
||||||
|
- `Certificate -> X.509 Certificate from Azure`
|
||||||
|
|
||||||
|
7. Assignments
|
||||||
|
|
||||||
|
Finally, navigate to the **Users and groups** tab and select the + button to assign access to the login with SSO application on a user or group-level.
|
||||||
|
|
||||||
|
8. Return to Infisical and enable SAML SSO.
|
||||||
|
|
||||||
|
Enabling SAML SSO enforces all members in your organization to only be able to log into Infisical via Azure.
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "JumpCloud SAML"
|
||||||
|
description: "Configure JumpCloud SAML for Infisical SSO"
|
||||||
|
---
|
||||||
@@ -0,0 +1,72 @@
|
|||||||
|
---
|
||||||
|
title: "Okta SAML"
|
||||||
|
description: "Configure Okta SAML for Infisical SSO"
|
||||||
|
---
|
||||||
|
|
||||||
|
1. In the Okta Admin Portal, select Applications > Applications from the
|
||||||
|
navigation. On the Applications screen, select the Create App Integration
|
||||||
|
button.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2. In the Create a New Application Integration dialog, select the SAML 2.0 radio button:
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
3. On the General Settings screen, give the application a unique, Infisical-specific name and select Next.
|
||||||
|
|
||||||
|
4. On the Configure SAML screen, configure the following fields:
|
||||||
|
|
||||||
|
- Single sign on URL: `https://app.infisical.com/api/v1/sso/saml2/:identifier`; we'll update the `:identifier` part later in step 6.
|
||||||
|
- Audience URI (SP Entity ID): `https://app.infisical.com`
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
<Note>
|
||||||
|
If you're self-hosting Infisical, then you will want to replace
|
||||||
|
`https://app.infisical.com` with your own domain.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
4. Also on the Configure SAML screen, configure the Attribute Statements to map:
|
||||||
|
|
||||||
|
- `id -> user.id`,
|
||||||
|
- `email -> user.email`,
|
||||||
|
- `firstName -> user.firstName`
|
||||||
|
- `lastName -> user.lastName`
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Once configured, select the Next button to proceed to the Feedback screen and select Finish.
|
||||||
|
|
||||||
|
5. Get IdP values
|
||||||
|
|
||||||
|
Once your application is created, select the Sign On tab for the app and select the View Setup Instructions button located on the right side of the screen:
|
||||||
|
|
||||||
|
Copy the Identity Provider Single Sign-On URL, the Identity Provider Issuer, and the X.509 Certificate to be pasted into your Infisical SAML SSO configuration details with the following map:
|
||||||
|
|
||||||
|
- `Audience -> Audience URI (SP Entity ID) from Okta`
|
||||||
|
- `Entrypoint -> Identity Provider Single Sign-On URL from Okta`
|
||||||
|
- `Issuer -> Identity Provider Issuer from Okta`
|
||||||
|
- `Certificate -> X.509 Certificate from Okta`
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
6. Create the SSO configuration and copy your SSO identifier in Infisical; update `:identifier` from step 4 earlier to be this value.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
7. Assignments
|
||||||
|
|
||||||
|
Finally, navigate to the Assignments tab and select the Assign button:
|
||||||
|
|
||||||
|
You can assign access to the application on a user-by-user basis using the Assign to People option, or in-bulk using the Assign to Groups option.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
At this point, you have configured everything you need within the context of the Okta Admin Portal.
|
||||||
|
|
||||||
|
8. Return to Infisical and enable SAML SSO.
|
||||||
|
|
||||||
|
Enabling SAML SSO enforces all members in your organization to only be able to log into Infisical via Okta.
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
title: "SSO Overview"
|
||||||
|
description: "Log in to Infisical via SSO protocols"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Warning>
|
||||||
|
Infisical currently only supports SAML SSO authentication with [Okta as the
|
||||||
|
identity provider (IdP)](https://www.okta.com/). We're expanding support for
|
||||||
|
other IdPs in the coming months, so stay tuned with this issue
|
||||||
|
[here](https://github.com/Infisical/infisical/issues/442).
|
||||||
|
</Warning>
|
||||||
|
|
||||||
|
You can configure your organization in Infisical to have members authenticate with the platform via protocols like [SAML 2.0](https://en.wikipedia.org/wiki/SAML_2.0).
|
||||||
|
|
||||||
|
To note, configuring SSO retains the end-to-end encrypted architecture of Infisical because we decouple the **authentication** and **decryption** steps. In all login with SSO implementations,
|
||||||
|
your IdP cannot and will not have access to the decryption key needed to decrypt your secrets.
|
||||||
|
|
||||||
|
## Configuration
|
||||||
|
|
||||||
|
Head over to your organization Settings > Authentication > SAML SSO Configuration.
|
||||||
|
|
||||||
|
Next, press "Set up SAML SSO" in the SAML SSO and follow the instructions
|
||||||
|
below to configure SSO for your identity provider.
|
||||||
|
Before Width: | Height: | Size: 264 KiB After Width: | Height: | Size: 264 KiB |
|
Before Width: | Height: | Size: 381 KiB After Width: | Height: | Size: 381 KiB |
|
Before Width: | Height: | Size: 423 KiB After Width: | Height: | Size: 423 KiB |
|
Before Width: | Height: | Size: 316 KiB After Width: | Height: | Size: 316 KiB |
|
Before Width: | Height: | Size: 598 KiB After Width: | Height: | Size: 598 KiB |
|
Before Width: | Height: | Size: 443 KiB After Width: | Height: | Size: 443 KiB |
|
Before Width: | Height: | Size: 563 KiB After Width: | Height: | Size: 563 KiB |
|
Before Width: | Height: | Size: 386 KiB After Width: | Height: | Size: 386 KiB |
@@ -121,7 +121,15 @@
|
|||||||
"documentation/platform/token",
|
"documentation/platform/token",
|
||||||
"documentation/platform/ip-allowlisting",
|
"documentation/platform/ip-allowlisting",
|
||||||
"documentation/platform/mfa",
|
"documentation/platform/mfa",
|
||||||
"documentation/platform/saml"
|
{
|
||||||
|
"group": "SSO",
|
||||||
|
"pages": [
|
||||||
|
"documentation/platform/sso/overview",
|
||||||
|
"documentation/platform/sso/okta",
|
||||||
|
"documentation/platform/sso/azure",
|
||||||
|
"documentation/platform/sso/jumpcloud"
|
||||||
|
]
|
||||||
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||