diff --git a/content/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/_index.md b/content/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/_index.md index 700ec9fda08..e7722028540 100644 --- a/content/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/_index.md +++ b/content/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/_index.md @@ -6,11 +6,87 @@ _Available as of v2.0.7_ If your organization uses Microsoft Active Directory Federation Services (AD FS) for user authentication, you can configure Rancher to allow your users to log in using their AD FS credentials. +### Setup Outline + +Setting up Microsoft AD FS with Rancher Server requires configuring AD FS on your Active Directory server, and configuring Rancher to expect AD FS queries. + +- [Microsoft AD FS Setup]({{< baseurl >}}/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/#microsoft-ad-fs-setup) + + Set up Microsoft AD FS to expect Rancher for authentication + +- [Rancher AD FS Setup]({{< baseurl >}}/rancher/v2.x/en/admin-settings/authentication/microsoft-adfs/#rancher-setup) + + Configure Rancher Server to use Microsoft AD FS for authentication + + >**Prerequisites:** > >- You must have a [Microsoft AD FS Server](https://docs.microsoft.com/en-us/windows-server/identity/active-directory-federation-services) configured. >- Export a `federationmetadata.xml` file from your AD FS Server. For more information, see the [PingIdentity video](https://docs.pingidentity.com/bundle/ping_sm_videoLibrary/page/p1_IdentityBridgeADFS.html). +## Microsoft AD FS Setup + +1. Open the `AD FS Management Console` + ![AD FS Management Console Screenshot]({{< baseurl >}}/img/rancher/adfs/adfs-overview.png) + +1. Select `Add Relying Party Trust...` in the right actions menu. + ![ADFS Add RPT Wizard Step 1]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-1.png) + +1. Select `Enter data about the relying party manually` as the option for obtaining data about the relying party + ![ADFS Add RPT Wizard Step 2]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-2.png) + +1. Enter a `Display name` for your Relying Party Trust + ![ADFS Add RPT Wizard Step 3]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-3.png) + +1. Select `AD FS profile` as the configuration profile for your relying party trust + ![ADFS Add RPT Wizard Step 4]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-4.png) + +1. Leave the `optional token encryption certificate` empty, as Rancher ADFS will not be using one. + ![ADFS Add RPT Wizard Step 5]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-5.png) + +1. Select `Enable support for the SAML 2.0 WebSSO protocol` + and enter `https:///v1-saml/adfs/saml/acs` for the service URL + ![ADFS Add RPT Wizard Step 6]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-6.png) + +1. Add `https:///v1-saml/adfs/saml/metadata` as the Relying party trust identifier + ![ADFS Add RPT Wizard Step 7]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-7.png) + +1. This tutorial will not cover multi-factor authentication; please refer to the Microsoft documentation if you would like to configure mutli-factor authentication. + ![ADFS Add RPT Wizard Step 8]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-8.png) + +1. Select `Permit all users to access this relying party` + ![ADFS Add RPT Wizard Step 9]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-9.png) + +1. After reviewing your settings, select `Next` to add the relying party trust + ![ADFS Add RPT Wizard Step 10]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-10.png) + +1. Select `Open the Edit Claim Rules...` and click `Close` + ![ADFS Add RPT Wizard Step 11]({{< baseurl >}}/img/rancher/adfs/adfs-add-rpt-11.png) + +1. Click `Add Rule...` + ![ADFS Edit Claim Rules]({{< baseurl >}}/img/rancher/adfs/adfs-edit-cr.png) + +1. Select `Send LDAP Attributes as Claims` as the Claim rule template + ![ADFS Add Transform Claim Rule Step 1]({{< baseurl >}}/img/rancher/adfs/adfs-add-tcr-1.png) + +1. Set the `Claim rule name` to your desired name, and select `Active Directory` as the Attribute store. Create the following mapping to reflect the table below + + | LDAP Attribute | Outgoing Claim Type | + | -------------------------------------------- | ------------------- | + | Given-Name | Given Name | + | User-Principal-Name | UPN | + | Token-Groups - Qualified by Long Domain Name | Group | + | SAM-Account-Name | Name | + ![ADFS Add Transform Claim Rule Step 2]({{< baseurl >}}/img/rancher/adfs/adfs-add-tcr-2.png) + +1. Download the `federationmetadata.xml` from your AD server at: +``` +https:///federationmetadata/2007-06/federationmetadata.xml +``` + + +## Rancher Setup + 1. From the **Global** view, select **Security > Authentication** from the main menu. 1. Select **Microsoft Active Directory Federation Services**. @@ -49,4 +125,4 @@ If your organization uses Microsoft Active Directory Federation Services (AD FS) > >- AD FS does not support search or lookup. When adding users to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), the exact IDs must be entered correctly. >- When adding users to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), group IDs are not supported unless the admin who turned on access control is a member of the group. ->- When adding a group that includes an admin to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), add it from the drop-down rather than the search bar. If you add the group using the search bar, the group will not get added. \ No newline at end of file +>- When adding a group that includes an admin to [clusters]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/editing-clusters/) or [projects]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/projects-and-namespaces/editing-projects/), add it from the drop-down rather than the search bar. If you add the group using the search bar, the group will not get added. diff --git a/src/img/rancher/adfs/adfs-add-rpt-1.png b/src/img/rancher/adfs/adfs-add-rpt-1.png new file mode 100644 index 00000000000..4da63c44f00 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-1.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-10.png b/src/img/rancher/adfs/adfs-add-rpt-10.png new file mode 100644 index 00000000000..8ea35096194 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-10.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-11.png b/src/img/rancher/adfs/adfs-add-rpt-11.png new file mode 100644 index 00000000000..b99dcc615d3 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-11.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-2.png b/src/img/rancher/adfs/adfs-add-rpt-2.png new file mode 100644 index 00000000000..a70e1be7a38 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-2.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-3.png b/src/img/rancher/adfs/adfs-add-rpt-3.png new file mode 100644 index 00000000000..d12e690558d Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-3.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-4.png b/src/img/rancher/adfs/adfs-add-rpt-4.png new file mode 100644 index 00000000000..34344ad8b81 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-4.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-5.png b/src/img/rancher/adfs/adfs-add-rpt-5.png new file mode 100644 index 00000000000..8bc1e4dc9ec Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-5.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-6.png b/src/img/rancher/adfs/adfs-add-rpt-6.png new file mode 100644 index 00000000000..a25c63f101a Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-6.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-7.png b/src/img/rancher/adfs/adfs-add-rpt-7.png new file mode 100644 index 00000000000..d3362d67093 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-7.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-8.png b/src/img/rancher/adfs/adfs-add-rpt-8.png new file mode 100644 index 00000000000..150457aae14 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-8.png differ diff --git a/src/img/rancher/adfs/adfs-add-rpt-9.png b/src/img/rancher/adfs/adfs-add-rpt-9.png new file mode 100644 index 00000000000..cbf5f9055c2 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-rpt-9.png differ diff --git a/src/img/rancher/adfs/adfs-add-tcr-1.png b/src/img/rancher/adfs/adfs-add-tcr-1.png new file mode 100644 index 00000000000..628f31cb522 Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-tcr-1.png differ diff --git a/src/img/rancher/adfs/adfs-add-tcr-2.png b/src/img/rancher/adfs/adfs-add-tcr-2.png new file mode 100644 index 00000000000..1b317b378ba Binary files /dev/null and b/src/img/rancher/adfs/adfs-add-tcr-2.png differ diff --git a/src/img/rancher/adfs/adfs-edit-cr.png b/src/img/rancher/adfs/adfs-edit-cr.png new file mode 100644 index 00000000000..f1d92df3525 Binary files /dev/null and b/src/img/rancher/adfs/adfs-edit-cr.png differ diff --git a/src/img/rancher/adfs/adfs-overview.png b/src/img/rancher/adfs/adfs-overview.png new file mode 100644 index 00000000000..8def480fdff Binary files /dev/null and b/src/img/rancher/adfs/adfs-overview.png differ