Skip to Content

Integrate OneLogin SSO with jumpserver

Note: SAML is an authentication mechanism for web applications. It's based on web protocols and it cannot be used for user authentication over SSH.

 

1. Login to OneLogin and Add Application.

 

 

2. Search for SAML TEST and select SAML Test Connector (Advanced)

 

3. Change the Display name and save 

4. Select the configuration tab from the right panel and fill in the Application details

 

      Audience (EntityID)Entity ID ( you can find it from ezeelogin GU > Settings > SAML)     

     Recipient  - Assertion Consumer Service URL ( you can find it from ezeelogin GU > Settings > SAML)

     ACS (Consumer) URL Validator - Entity ID ( you can find it from ezeelogin GU > Settings > SAML)

     ACS (Consumer) URL

     Single Logout URL - Single Logout Service URL  ( you can find it from ezeelogin GU > Settings > SAML)   

5. Select the SSO tab from the right panel & Copy the Issuer URL and paste it  to Metadata URL  on Ezeelogin GUI > Settings > SAML Metadata URL 

 

6.Click on the fetch button, it will be auto-fill the SAML setting and SAVE it

7.  Select users tab from left panel and click on new user then provide first name, last name and email to save the user.

8.  Select applications from left panel and click on add icon to map application to user.

9.  Select application from drop down and then save application.

10.  Change Web panel Authentication to SAML from Ezeelogin GUI > Settings > General >Authentication

11. Enable Auto Create User from Ezeelogin GUI -> Settings -> General -> Security -> Enable Auto Create User

You need reset the password and security code after login to the Ezeelogin GUI in order to login to the SSH.
We would recommend you to use the webssh shell when you are using SAML authentication. Using webssh shell is a lot more convenient as you would not have to worry about the SSH password or the security code for the users.
 

You need to add different email address for each users. By default ezeelogin uses email address for creating users. 

If you want to add an existing user in ezeelogin to SSO, Add the user with exact username, email address  as follows. (Ezeelogin will verify with the email address of the users by default). Make sure to add the email address for the Ezeelogin Administrator user.

Saml authentication is not supported for slave  if the URL is IP based.If you want to authenticate  slave using saml you have to use domain name