Перейти до основного вмісту

Add Alibaba Cloud IDaaS as a SAML provider

This guide explains how to let the users of Alibaba Cloud IDaaS (EIAM) sign in to Casdoor through SAML.


Learning outcomes​

  • Create a SAML application in IDaaS and associate its accounts with Casdoor users.
  • Add Alibaba Cloud IDaaS as a SAML provider in Casdoor.

What you need​

  • An Alibaba Cloud account
  • Administrator access to the Casdoor admin console

Create a SAML application in IDaaS​

  1. In the Alibaba Cloud console, open IDaaS (Identity as a Service).

    IDaaS in the console

  2. Натисніть Список екземплярів EIAM та відкрийте безкоштовну версію. Alibaba Cloud creates and starts an instance.

    EIAM instances

  3. Click the name of the instance, or Manage, to open the IDaaS console.

    EIAM instance list

  4. Click Add Application, search for SAML, and click Add Application.

    SAML application template

  5. Click Add SigningKey, fill in the form, and submit. Then select the new signing key.

    Add SigningKey

    SigningKey form

    SigningKey selection

  6. Fill in the application and submit:

    FieldValue
    IDP IdentityIdThe same value as Issuer URL in Casdoor
    SP Entity ID, SP ACS URL (SSO Location)Placeholders for now. You replace them after configuring Casdoor
    Assertion Attributeusername
    Account Association ModeAccount Association

    Application settings

Associate accounts​

After the application is added, IDaaS asks you to authorize it. Don't authorize it yet.

  1. Go to Organizations and Groups, click New Account, fill in the form, and submit.

    New Account

    Account form

  2. Go to Application Authorization, select the accounts to authorize, and click Save.

    Application Authorization

  3. Go to the Application List, click View application sub-accounts, and then Add account association.

    Sub-accounts of the application

    Add account association

  4. Enter the primary account, which exists in IDaaS, and the sub-account, which is the ID of the user in Casdoor. Click Save.

    Account association form

Export the metadata​

In the Application List, click View Application Details and Export IDaaS SAML Metadata.

Export IDaaS SAML Metadata

Add the provider in Casdoor​

  1. In the Casdoor admin console, go to Identity > Providers and add a provider.

  2. Set Category to SAML and Type to Aliyun IDaaS.

  3. Paste the metadata into Metadata and click Parse. Casdoor fills in Endpoint, IdP, and Issuer URL.

    Alibaba Cloud IDaaS provider in Casdoor

  4. Copy the SP ACS URL and the SP Entity ID, and save the provider.

  5. Open the edit page of your application, add the provider on the Providers tab, and save.

    Provider in the application

Complete the IDaaS application​

  1. In IDaaS, disable the application and click Modify Application.

    Modify Application

  2. Enter the SP Entity ID and the SP ACS URL (SSO Location) that you copied from Casdoor. The ACS URL accepts only POST.

    SP values in IDaaS

  3. Submit and enable the application.

Verify the result​

Open the sign-in page of the application and click the IDaaS button. After you sign in at IDaaS, you are signed in to Casdoor.

Recording of the sign-in through IDaaS

See also​