Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| en:2.0:single_sign_on:saml_gitlab [2025/04/26 00:39] – created kainhofer | en:2.0:single_sign_on:saml_gitlab [2026/09/05 23:42] (current) – [Configuring the Service Provider (Gitlab)] kainhofer | ||
|---|---|---|---|
| Line 7: | Line 7: | ||
| Throughout the document we will assume you have both Admidio and Gitlab already set up properly at https:// | Throughout the document we will assume you have both Admidio and Gitlab already set up properly at https:// | ||
| - | As a first step, one needs to **configure Admidio to act as an SAML 2.0 Identity Provider** (IdP). This has to be done once and is not specific to any client. Please | + | As a first step, one needs to **configure Admidio to act as an SAML 2.0 Identity Provider** (IdP). This has to be done once and is not specific to Gitlab. Please |
| {{ : | {{ : | ||
| - | Basically, one (1) needs to **create a cryptographic key** to sign message | + | Basically, one needs to enable SAML 2.0 and **choose a unique EntityID**. |
| - | The page preferences | + | |
| + | The page https:// | ||
| - | ===== TL;DR; - Quick Overview ===== | + | ===== Quick Overview ===== |
| - | Setting up a client (SAML " | + | Setting up a client (SAML " |
| * At the **Service Provider (SP)** - Gitlab in our case - **install the extension** to support SAML login. | * At the **Service Provider (SP)** - Gitlab in our case - **install the extension** to support SAML login. | ||
| Line 21: | Line 23: | ||
| * Choose whether sent messages **should be signed and/or encrypted** (these features require an additional private key and certificate for the SP!), and whether received messages are checked for signatures or encryption is expected. | * Choose whether sent messages **should be signed and/or encrypted** (these features require an additional private key and certificate for the SP!), and whether received messages are checked for signatures or encryption is expected. | ||
| * In **Admidio**, | * In **Admidio**, | ||
| - | * Choose an easily understood **label for the client** (only used in Admidio' | + | * Choose an easily understood **label for the client** (only used in Admidio' |
| * Enter the **ClientID from the SP**, as well as the ACS URL and the SLO response URL. These values must be provided by the client. | * Enter the **ClientID from the SP**, as well as the ACS URL and the SLO response URL. These values must be provided by the client. | ||
| * In Admidio, also choose whether sent messages should be **signed or encrypted**. The crypto key generated in the general SAML setup will be used. | * In Admidio, also choose whether sent messages should be **signed or encrypted**. The crypto key generated in the general SAML setup will be used. | ||
| Line 32: | Line 34: | ||
| Gitlab does not provide a graphic config interface to set up SAML. However, it is easy to set up SAML in the config file (gitlab.rb) as described in https:// | Gitlab does not provide a graphic config interface to set up SAML. However, it is easy to set up SAML in the config file (gitlab.rb) as described in https:// | ||
| - | An example would be as follows. The URLs and the certificate can again be copied from Admidios SSO preferences page. | + | {{ : |
| < | < | ||
| gitlab_rails[' | gitlab_rails[' | ||