Add support and docs for Google SAML
@@ -27,6 +27,7 @@ type TSAMLConfig = {
|
|||||||
cert: string;
|
cert: string;
|
||||||
audience: string;
|
audience: string;
|
||||||
wantAuthnResponseSigned?: boolean;
|
wantAuthnResponseSigned?: boolean;
|
||||||
|
wantAssertionsSigned?: boolean;
|
||||||
disableRequestedAuthnContext?: boolean;
|
disableRequestedAuthnContext?: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -82,6 +83,10 @@ export const registerSamlRouter = async (server: FastifyZodProvider) => {
|
|||||||
samlConfig.audience = `spn:${ssoConfig.issuer}`;
|
samlConfig.audience = `spn:${ssoConfig.issuer}`;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (ssoConfig.authProvider === SamlProviders.GOOGLE_SAML) {
|
||||||
|
samlConfig.wantAssertionsSigned = false;
|
||||||
|
}
|
||||||
|
|
||||||
(req as unknown as FastifyRequest).ssoConfig = ssoConfig;
|
(req as unknown as FastifyRequest).ssoConfig = ssoConfig;
|
||||||
done(null, samlConfig);
|
done(null, samlConfig);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
@@ -4,7 +4,8 @@ import { ActorType } from "@app/services/auth/auth-type";
|
|||||||
export enum SamlProviders {
|
export enum SamlProviders {
|
||||||
OKTA_SAML = "okta-saml",
|
OKTA_SAML = "okta-saml",
|
||||||
AZURE_SAML = "azure-saml",
|
AZURE_SAML = "azure-saml",
|
||||||
JUMPCLOUD_SAML = "jumpcloud-saml"
|
JUMPCLOUD_SAML = "jumpcloud-saml",
|
||||||
|
GOOGLE_SAML = "google-saml"
|
||||||
}
|
}
|
||||||
|
|
||||||
export type TCreateSamlCfgDTO = {
|
export type TCreateSamlCfgDTO = {
|
||||||
|
|||||||
@@ -0,0 +1,95 @@
|
|||||||
|
---
|
||||||
|
title: "Google SAML"
|
||||||
|
description: "Configure Google SAML for Infisical SSO"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
Google SAML SSO feature is a paid feature.
|
||||||
|
|
||||||
|
If you're using Infisical Cloud, then it is available under the **Pro Tier**. If you're self-hosting Infisical,
|
||||||
|
then you should contact [email protected] to purchase an enterprise license to use it.
|
||||||
|
</Info>
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Prepare the SAML SSO configuration in Infisical">
|
||||||
|
In Infisical, head to your Organization Settings > Authentication > SAML SSO Configuration and select **Set up SAML SSO**.
|
||||||
|
|
||||||
|
Next, note the **ACS URL** and **SP Entity ID** to use when configuring the Google SAML application.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Create a SAML application in Google">
|
||||||
|
2.1. In your [Google Admin console](https://support.google.com/a/answer/182076), head to Menu > Apps > Web and mobile apps and
|
||||||
|
create a **custom SAML app**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2.2. In the **App details** tab, give the application a unique name like Infisical.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2.3. In the **Google Identity Provider details** tab, copy the **SSO URL**, **Entity ID** and **Certificate**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2.4. Back in Infisical, set **SSO URL**, **IdP Entity ID**, and **Certificate** to the corresponding items from step 2.3.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2.5. Back in the Google Admin console, in the **Service provider details** tab, set the **ACS URL** and **Entity ID** to the corresponding items from step 1.
|
||||||
|
|
||||||
|
Also, check the **Signed response** checkbox.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
2.6. In the **Attribute mapping** tab, configure the following map:
|
||||||
|
|
||||||
|
- **First name** -> **firstName**
|
||||||
|
- **Last name** -> **lastName**
|
||||||
|
- **Primary email** -> **email**
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Click **Finish**.
|
||||||
|
</Step>
|
||||||
|
<Step title="Assign users in Google Workspace to the application">
|
||||||
|
Back in your [Google Admin console](https://support.google.com/a/answer/182076), head to Menu > Apps > Web and mobile apps > your SAML app
|
||||||
|
and press on **User access**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
To assign everyone in your organization to the application, click **On for everyone** or **Off for everyone** and then click **Save**.
|
||||||
|
|
||||||
|
You can also assign an organizational unit or set of users to an application; you can learn more about that [here](https://support.google.com/a/answer/6087519?hl=en#add_custom_saml&turn_on&verify_sso&&zippy=%2Cstep-add-the-custom-saml-app%2Cstep-turn-on-your-saml-app%2Cstep-verify-that-sso-is-working-with-your-custom-app).
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Enable SAML SSO in Infisical">
|
||||||
|
Enabling SAML SSO allows members in your organization to log into Infisical via Google Workspace.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Enforce SAML SSO in Infisical">
|
||||||
|
Enforcing SAML SSO ensures that members in your organization can only access Infisical
|
||||||
|
by logging into the organization via Google.
|
||||||
|
|
||||||
|
To enforce SAML SSO, you're required to test out the SAML connection by successfully authenticating at least one Google user with Infisical;
|
||||||
|
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
||||||
|
|
||||||
|
<Warning>
|
||||||
|
We recommend ensuring that your account is provisioned the application in Google
|
||||||
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
|
</Warning>
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
If you're configuring SAML SSO on a self-hosted instance of Infisical, make sure to
|
||||||
|
set the `AUTH_SECRET` and `SITE_URL` environment variable for it to work:
|
||||||
|
|
||||||
|
- `AUTH_SECRET`: A secret key used for signing and verifying JWT. This can be a random 32-byte base64 string generated with `openssl rand -base64 32`.
|
||||||
|
- `SITE_URL`: The URL of your self-hosted instance of Infisical - should be an absolute URL including the protocol (e.g. https://app.infisical.com)
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
References:
|
||||||
|
- Google's guide to [set up your own custom SAML app](https://support.google.com/a/answer/6087519?hl=en#add_custom_saml&turn_on&verify_sso&&zippy=%2Cstep-add-the-custom-saml-app%2Cstep-turn-on-your-saml-app%2Cstep-verify-that-sso-is-working-with-your-custom-app).
|
||||||
@@ -22,3 +22,4 @@ your IdP cannot and will not have access to the decryption key needed to decrypt
|
|||||||
- [Okta SAML](/documentation/platform/sso/okta)
|
- [Okta SAML](/documentation/platform/sso/okta)
|
||||||
- [Azure SAML](/documentation/platform/sso/azure)
|
- [Azure SAML](/documentation/platform/sso/azure)
|
||||||
- [JumpCloud SAML](/documentation/platform/sso/jumpcloud)
|
- [JumpCloud SAML](/documentation/platform/sso/jumpcloud)
|
||||||
|
- [Google SAML](/documentation/platform/sso/google-saml)
|
||||||
|
|||||||
|
After Width: | Height: | Size: 236 KiB |
|
After Width: | Height: | Size: 258 KiB |
|
After Width: | Height: | Size: 221 KiB |
|
After Width: | Height: | Size: 279 KiB |
|
After Width: | Height: | Size: 584 KiB |
|
After Width: | Height: | Size: 605 KiB |
|
After Width: | Height: | Size: 524 KiB |
|
After Width: | Height: | Size: 205 KiB |
|
After Width: | Height: | Size: 324 KiB |
|
After Width: | Height: | Size: 371 KiB |
@@ -146,7 +146,8 @@
|
|||||||
"documentation/platform/sso/gitlab",
|
"documentation/platform/sso/gitlab",
|
||||||
"documentation/platform/sso/okta",
|
"documentation/platform/sso/okta",
|
||||||
"documentation/platform/sso/azure",
|
"documentation/platform/sso/azure",
|
||||||
"documentation/platform/sso/jumpcloud"
|
"documentation/platform/sso/jumpcloud",
|
||||||
|
"documentation/platform/sso/google-saml"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -19,7 +19,8 @@ import { SSOModal } from "./SSOModal";
|
|||||||
const ssoAuthProviderMap: { [key: string]: string } = {
|
const ssoAuthProviderMap: { [key: string]: string } = {
|
||||||
"okta-saml": "Okta SAML",
|
"okta-saml": "Okta SAML",
|
||||||
"azure-saml": "Azure SAML",
|
"azure-saml": "Azure SAML",
|
||||||
"jumpcloud-saml": "JumpCloud SAML"
|
"jumpcloud-saml": "JumpCloud SAML",
|
||||||
|
"google-saml": "Google SAML"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const OrgSSOSection = (): JSX.Element => {
|
export const OrgSSOSection = (): JSX.Element => {
|
||||||
|
|||||||
@@ -21,13 +21,15 @@ import { UsePopUpState } from "@app/hooks/usePopUp";
|
|||||||
enum AuthProvider {
|
enum AuthProvider {
|
||||||
OKTA_SAML = "okta-saml",
|
OKTA_SAML = "okta-saml",
|
||||||
AZURE_SAML = "azure-saml",
|
AZURE_SAML = "azure-saml",
|
||||||
JUMPCLOUD_SAML = "jumpcloud-saml"
|
JUMPCLOUD_SAML = "jumpcloud-saml",
|
||||||
|
GOOGLE_SAML = "google-saml"
|
||||||
}
|
}
|
||||||
|
|
||||||
const ssoAuthProviders = [
|
const ssoAuthProviders = [
|
||||||
{ label: "Okta SAML", value: AuthProvider.OKTA_SAML },
|
{ label: "Okta SAML", value: AuthProvider.OKTA_SAML },
|
||||||
{ label: "Azure SAML", value: AuthProvider.AZURE_SAML },
|
{ label: "Azure SAML", value: AuthProvider.AZURE_SAML },
|
||||||
{ label: "JumpCloud SAML", value: AuthProvider.JUMPCLOUD_SAML }
|
{ label: "JumpCloud SAML", value: AuthProvider.JUMPCLOUD_SAML },
|
||||||
|
{ label: "Google SAML", value: AuthProvider.GOOGLE_SAML }
|
||||||
];
|
];
|
||||||
|
|
||||||
const schema = yup
|
const schema = yup
|
||||||
@@ -140,7 +142,15 @@ export const SSOModal = ({ popUp, handlePopUpClose, handlePopUpToggle }: Props)
|
|||||||
issuer: "IdP Entity ID",
|
issuer: "IdP Entity ID",
|
||||||
issuerPlaceholder: "xxx"
|
issuerPlaceholder: "xxx"
|
||||||
};
|
};
|
||||||
|
case AuthProvider.GOOGLE_SAML:
|
||||||
|
return {
|
||||||
|
acsUrl: "ACS URL",
|
||||||
|
entityId: "SP Entity ID",
|
||||||
|
entryPoint: "SSO URL",
|
||||||
|
entryPointPlaceholder: "https://accounts.google.com/o/saml2/idp?idpid=xxx",
|
||||||
|
issuer: "IdP Entity ID",
|
||||||
|
issuerPlaceholder: "https://accounts.google.com/o/saml2/idp?idpid=xxx"
|
||||||
|
};
|
||||||
default:
|
default:
|
||||||
return {
|
return {
|
||||||
acsUrl: "ACS URL",
|
acsUrl: "ACS URL",
|
||||||
|
|||||||