Adding MS ADFS Setup Documentation Enhancements
@@ -6,11 +6,87 @@ _Available as of v2.0.7_
|
||||
|
||||
If your organization uses Microsoft Active Directory Federation Services (AD FS) for user authentication, you can configure Rancher to allow your users to log in using their AD FS credentials.
|
||||
|
||||
### Setup Outline
|
||||
|
||||
Setting up Microsoft AD FS with Rancher Server requires configuring AD FS on your Active Directory server, and configuring Rancher to expect AD FS queries.
|
||||
|
||||
- [Microsoft AD FS Setup]({{< baseurl >}}/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/#microsoft-ad-fs-setup)
|
||||
|
||||
Set up Microsoft AD FS to expect Rancher for authentication
|
||||
|
||||
- [Rancher AD FS Setup]({{< baseurl >}}/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/#rancher-setup)
|
||||
|
||||
Configure Rancher Server to use Microsoft AD FS for authentication
|
||||
|
||||
|
||||
>**Prerequisites:**
|
||||
>
|
||||
>- You must have a [Microsoft AD FS Server](https://docs.microsoft.com/en-us/windows-server/identity/active-directory-federation-services) configured.
|
||||
>- Export a `federationmetadata.xml` file from your AD FS Server. For more information, see the [PingIdentity video](https://docs.pingidentity.com/bundle/ping_sm_videoLibrary/page/p1_IdentityBridgeADFS.html).
|
||||
|
||||
## Microsoft AD FS Setup
|
||||
|
||||
1. Open the `AD FS Management Console`
|
||||

|
||||
|
||||
1. Select `Add Relying Party Trust...` in the right actions menu.
|
||||

|
||||
|
||||
1. Select `Enter data about the relying party manually` as the option for obtaining data about the relying party
|
||||

|
||||
|
||||
1. Enter a `Display name` for your Relying Party Trust
|
||||

|
||||
|
||||
1. Select `AD FS profile` as the configuration profile for your relying party trust
|
||||

|
||||
|
||||
1. Leave the `optional token encryption certificate` empty, as Rancher ADFS will not be using one.
|
||||

|
||||
|
||||
1. Select `Enable support for the SAML 2.0 WebSSO protocol`
|
||||
and enter `https://<rancher-server>/v1-saml/adfs/saml/acs` for the service URL
|
||||

|
||||
|
||||
1. Add `https://<rancher-server>/v1-saml/adfs/saml/metadata` as the Relying party trust identifier
|
||||

|
||||
|
||||
1. This tutorial will not cover multi-factor authentication; please refer to the Microsoft documentation if you would like to configure mutli-factor authentication.
|
||||

|
||||
|
||||
1. Select `Permit all users to access this relying party`
|
||||

|
||||
|
||||
1. After reviewing your settings, select `Next` to add the relying party trust
|
||||

|
||||
|
||||
1. Select `Open the Edit Claim Rules...` and click `Close`
|
||||

|
||||
|
||||
1. Click `Add Rule...`
|
||||

|
||||
|
||||
1. Select `Send LDAP Attributes as Claims` as the Claim rule template
|
||||

|
||||
|
||||
1. Set the `Claim rule name` to your desired name, and select `Active Directory` as the Attribute store. Create the following mapping to reflect the table below
|
||||
|
||||
| LDAP Attribute | Outgoing Claim Type |
|
||||
| -------------------------------------------- | ------------------- |
|
||||
| Given-Name | Given Name |
|
||||
| User-Principal-Name | UPN |
|
||||
| Token-Groups - Qualified by Long Domain Name | Group |
|
||||
| SAM-Account-Name | Name |
|
||||

|
||||
|
||||
1. Download the `federationmetadata.xml` from your AD server at:
|
||||
```
|
||||
https://<ad-server>/federationmetadata/2007-06/federationmetadata.xml
|
||||
```
|
||||
|
||||
|
||||
## Rancher Setup
|
||||
|
||||
1. From the **Global** view, select **Security > Authentication** from the main menu.
|
||||
|
||||
1. Select **Microsoft Active Directory Federation Services**.
|
||||
@@ -49,4 +125,4 @@ If your organization uses Microsoft Active Directory Federation Services (AD FS)
|
||||
>
|
||||
>- AD FS does not support search or lookup. When adding users to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), the exact IDs must be entered correctly.
|
||||
>- When adding users to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), group IDs are not supported unless the admin who turned on access control is a member of the group.
|
||||
>- When adding a group that includes an admin to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), add it from the drop-down rather than the search bar. If you add the group using the search bar, the group will not get added.
|
||||
>- When adding a group that includes an admin to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), add it from the drop-down rather than the search bar. If you add the group using the search bar, the group will not get added.
|
||||
|
||||
|
After Width: | Height: | Size: 205 KiB |
|
After Width: | Height: | Size: 260 KiB |
|
After Width: | Height: | Size: 192 KiB |
|
After Width: | Height: | Size: 300 KiB |
|
After Width: | Height: | Size: 177 KiB |
|
After Width: | Height: | Size: 231 KiB |
|
After Width: | Height: | Size: 222 KiB |
|
After Width: | Height: | Size: 333 KiB |
|
After Width: | Height: | Size: 222 KiB |
|
After Width: | Height: | Size: 262 KiB |
|
After Width: | Height: | Size: 277 KiB |
|
After Width: | Height: | Size: 237 KiB |
|
After Width: | Height: | Size: 226 KiB |
|
After Width: | Height: | Size: 105 KiB |
|
After Width: | Height: | Size: 305 KiB |