Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| en:2.0:single_sign_on:saml_gitlab [2026/09/05 20:14] – [Prerequisites] kainhofer | en:2.0:single_sign_on:saml_gitlab [2026/09/05 23:42] (current) – [Configuring the Service Provider (Gitlab)] kainhofer | ||
|---|---|---|---|
| Line 15: | Line 15: | ||
| The page https:// | The page https:// | ||
| - | ===== TL;DR; - Quick Overview ===== | + | ===== Quick Overview ===== |
| - | Setting up a client (SAML " | + | Setting up a client (SAML " |
| * At the **Service Provider (SP)** - Gitlab in our case - **install the extension** to support SAML login. | * At the **Service Provider (SP)** - Gitlab in our case - **install the extension** to support SAML login. | ||
| Line 23: | Line 23: | ||
| * Choose whether sent messages **should be signed and/or encrypted** (these features require an additional private key and certificate for the SP!), and whether received messages are checked for signatures or encryption is expected. | * Choose whether sent messages **should be signed and/or encrypted** (these features require an additional private key and certificate for the SP!), and whether received messages are checked for signatures or encryption is expected. | ||
| * In **Admidio**, | * In **Admidio**, | ||
| - | * Choose an easily understood **label for the client** (only used in Admidio' | + | * Choose an easily understood **label for the client** (only used in Admidio' |
| * Enter the **ClientID from the SP**, as well as the ACS URL and the SLO response URL. These values must be provided by the client. | * Enter the **ClientID from the SP**, as well as the ACS URL and the SLO response URL. These values must be provided by the client. | ||
| * In Admidio, also choose whether sent messages should be **signed or encrypted**. The crypto key generated in the general SAML setup will be used. | * In Admidio, also choose whether sent messages should be **signed or encrypted**. The crypto key generated in the general SAML setup will be used. | ||
| Line 34: | Line 34: | ||
| Gitlab does not provide a graphic config interface to set up SAML. However, it is easy to set up SAML in the config file (gitlab.rb) as described in https:// | Gitlab does not provide a graphic config interface to set up SAML. However, it is easy to set up SAML in the config file (gitlab.rb) as described in https:// | ||
| - | An example would be as follows. The URLs and the certificate can again be copied from Admidios SSO preferences page. | + | {{ : |
| < | < | ||
| gitlab_rails[' | gitlab_rails[' | ||