Configuring the LiquidFiles Virtual Appliance in AuthAnvil Single Sign On
- Log in to your AuthAnvil Manager and navigate to the Applications section in Single Sign On.
- Click Add New Application to open a new configuration menu
- Set the Display Name to “LiquidFiles”. You are welcome to download this image to use for the application icon (Right-Click – Save As…):
- Under the Protocol Configuration tab specify the Reply to URL and the Audience URI. The Reply To URL is the SAML endpoint for LiquidFiles and the Audience URI is the SAML Consumer URL. Here are some example values:
- Reply to URL: https://<yourdomain.com>/saml/init
- Audience URI: https://<yourdomain.com>/saml/consume
- Specify the protocol as SP-Init Redirect
- Save the application to save the configuration and create the app
- Re-open the LiquidFiles application by clicking on it
- Create a new Attribute Map with the following name and value:
- Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- Value: {Email}
- Expand the Extended Properties section and enable the advanced properties. Note: Be aware that there are occasions where the Attribute name will revert back to the default value when enabling advanced properties so keep an eye on that.
- After the advanced properties are enabled set the Format tourn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
- Save the changes
- To allow users to access the LiquidFiles Virtual Appliance you will need to add the application to a role in SSO. Navigate to the Roles section of the AuthAnvil Manager and select the role you would like to allow access. Drag the LiquidFiles application into the allowed applications group.
- Users in that role will now be able to view the LiquidFiles application in the portal.
Configure the LiquidFiles Virtual Appliance for Single Sign On
- Log into the LiquidFiles Virtual Appliance with an administrative account.
- Navigate to the Admin section and select Single Sign-On from the left menu.
- Specify the Protocol as SAML 2
- Set the IdP Login URL to the SP-Init endpoint in AuthAnvil Single Sign On. This URL is located at https://<yourdomain.com>/sso/federation/passive/Saml2SPInit where “yourdomain.com” points to your AuthAnvil server
- Set the Logout URL to the AuthAnvil Single Sign On Single Sign Out URL (bit of a tongue twister, eh?). This URL is located at https://<yourdomain.com>/sso/federation/passive/signout. Note: Setting the logout URL to the SSO Log Out URL will cause you to logout of AuthAnvil Single Sign On when you log out of LiquidFiles. If you don’t want that to happen you can specify the SSO Portal as the logout URL, e.g. https://<yourdomain.com>/sso
- Specify the thumbprint from the Signing Certificate in the application configuration in AuthAnvil Single Sign On. You can find this by navigating to the LiquidFiles application in AuthAnvil Manager and opening the Certificate Authority section. The thumbprint can be copied directly into the LiquidFiles configuration.
- Finally, modify the Authentication Context tourn:oasis:names:tc:SAML:2.0:ac:classes:Password . Otherwise, you will be prompted to elevate credentials within AuthAnvil Single Sign On.
Why do we do this?
By default AuthAnvil Single Sign on issues tokens specifying the user was authenticated with a password. This is for compatibility reasons as most federated applications expect it. If you left the value as is, AuthAnvil Single Sign On would issue a token specifying password, LiquidFiles would compare the value in the token and since it’s not what it’s expecting it requests AuthAnvil to reissue a new token. AuthAnvil Single Sign On currently allows authentication via the AuthAnvil Two Factor Auth system so in our case an elevation is simply a re-authentication of a user’s OTP.
If you don’t want to modify the Authn Context in LiquidFiles and do not want to require elevation in AuthAnvil Single Sign On, contact support to reconfigure the authentication type for the LiquidFiles application in AuthAnvil Single Sign On.
- Save the changes and try logging into LiquidFiles from the AuthAnvil Single Sign On portal. You should see the application in the list.
Questions?
If you have any questions or need some help, we would be happy to assist. Open a case at help.scorpionsoft.com or send an email to support@scorpionsoft.com.