Skip to main content

Connect Appgate SDP with SAML

This guide explains how to use Casdoor as the SAML identity provider (IdP) of Appgate SDP. Appgate receives the SAMLResponse in an HTTP POST request. The same steps apply to other service providers that use the POST binding.


Learning outcomes​

  • Configure a Casdoor application for the POST binding.
  • Add Casdoor as a SAML identity provider in Appgate.
  • Map the username attribute and allow administrators to sign in.

What you need​

  • An Appgate SDP deployment with administrator access
  • An application in Casdoor

Configure the Casdoor application​

  1. In the Casdoor admin console, open the edit page of the application.

  2. Set the following fields:

    FieldValue
    Redirect URLsThe identifier of the service provider, which Appgate calls the audience
    SAML reply URLThe ACS URL, which receives and verifies the SAML response

    Use the values for your use case:

    Use caseRedirect URLSAML Reply URL
    Administrator authAppGatehttps://mycontroller.your-site-url.com/admin/saml
    User authAppGate Clienthttps://redirectserver.your-site-url.com/saml

    Redirect URLs field with the entity ID

    SAML reply URL field

  3. Download the SAML metadata: copy the metadata URL, open it in a browser, and save the XML file.

    SAML metadata URL of the application

Add the SAML IdP in Appgate​

  1. In the Appgate SDP console, go to System > Identity Providers and create a provider of type SAML.
  2. Enter a Name, for example Casdoor SAML Admin.
  3. Click Choose a file and upload the metadata file. Appgate fills in Single Sign-on URL, Issuer, and Public Certificate.
  4. Set Audience to the value that you entered in Redirect URLs in Casdoor.

Map attributes​

Map the Name attribute to username.

Attribute mapping in Appgate

Allow administrators to sign in​

Update the Builtin Administrator Policy, or your own equivalent policy, so that administrators who sign in through the SAML IdP receive administration rights.

Builtin Administrator Policy in Appgate

Verify the result​

  1. Sign out of the Appgate admin UI.
  2. On the sign-in page, select your Casdoor IdP as the Identity Provider and click Sign in with browser.
  3. Sign in to Casdoor.

If Appgate shows a message such as "You don't have any administration rights", the IdP authenticated you, but the policy doesn't grant you rights yet. Adjust the roles and policies in Appgate.

See also​