From e9ccd164b1abaf094f7279d51f79a08671f84d2e Mon Sep 17 00:00:00 2001 From: Sunil Singh Date: Mon, 4 Nov 2024 15:37:05 -0800 Subject: [PATCH] Adding in configuration steps to SAML pages on setting up SAML SLO. Signed-off-by: Sunil Singh --- .../configure-keycloak-saml.md | 13 +++++++++++++ .../configure-okta-saml.md | 12 +++++++----- .../configure-pingidentity.md | 13 +++++++++++++ .../configure-keycloak-saml.md | 15 +++++++++++++++ .../configure-okta-saml.md | 17 ++++++++++++++++- .../configure-pingidentity.md | 15 +++++++++++++++ 6 files changed, 79 insertions(+), 6 deletions(-) diff --git a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md index 0aebd63ad67..1ee8f543015 100644 --- a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md +++ b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md @@ -194,3 +194,16 @@ Try configuring and saving keycloak as your SAML provider and then accessing the * If the log displays `request validation failed: org.keycloak.common.VerificationException: SigAlg was null`, set `Client Signature Required` to `OFF` in your Keycloak client. ## Configuring SAML Single Logout (SLO) + +Rancher supports the ability to configure SAML SLO. Options include logging out of the Rancher application only, logging out of Rancher and registered applications tied to the external authentication provider, or a prompt asking the user to choose between the previous options. The steps below outline configuration from the application GUI: + +1. Sign in to Rancher using a [standard user or an administrator role](../manage-role-based-access-control-rbac/global-permissions.md) to configure SAML SLO. +1. In the top left corner, click **☰ > Users & Authentication**. +1. In the left navigation menu, click **Auth Provider**. +1. Under the section **Log Out behavior**, choose the appropriate SLO setting as described below: + + | Setting | Description | + | ------------------------- | ----------------------------------------------------------------------------- | + | Log out of Rancher and not authentication provider | Choosing this option will only logout the Rancher application and not external authentication providers. | + | Log out of Rancher and authentication provider (includes all other applications registered with authentication provider) | Choosing this option will logout Rancher and all external authentication providers along with any registered applications linked to the provider. | + | Allow the user to choose one of the above in an additional log out step | Choosing this option presents users with a choice of logout method as described above. | diff --git a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md index 2d22a751d2b..6755ce3ebb6 100644 --- a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md +++ b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md @@ -111,13 +111,15 @@ If you experience issues when you test the connection to the OpenLDAP server, en ## Configuring SAML Single Logout (SLO) -1. Sign into Rancher using a local user assigned the [administrator](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/manage-role-based-access-control-rbac/global-permissions) role (i.e., the _local principal_). +Rancher supports the ability to configure SAML SLO. Options include logging out of the Rancher application only, logging out of Rancher and registered applications tied to the external authentication provider, or a prompt asking the user to choose between the previous options. The steps below outline configuration from the application GUI: + +1. Sign in to Rancher using a [standard user or an administrator role](../manage-role-based-access-control-rbac/global-permissions.md) to configure SAML SLO. 1. In the top left corner, click **☰ > Users & Authentication**. 1. In the left navigation menu, click **Auth Provider**. -1. Under the section **Configure Single Logout (SLO)**, choose the appropriate SLO setting as described below: +1. Under the section **Log Out behavior**, choose the appropriate SLO setting as described below: | Setting | Description | | ------------------------- | ----------------------------------------------------------------------------- | - | Only log out of Rancher | Choosing this option will only logout the Rancher application and not external authentication providers. | - | Log out of Okta (including Rancher and all other application registered with the provider) | Choosing this option will logout Rancher and external authentication providers along with any registered application linked to the provider. | - | Allow the user to choose in an extra step | Choosing this option presents users with a choice of logout method as described above. | + | Log out of Rancher and not authentication provider | Choosing this option will only logout the Rancher application and not external authentication providers. | + | Log out of Rancher and authentication provider (includes all other applications registered with authentication provider) | Choosing this option will logout Rancher and all external authentication providers along with any registered applications linked to the provider. | + | Allow the user to choose one of the above in an additional log out step | Choosing this option presents users with a choice of logout method as described above. | diff --git a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md index db418a7f9d7..c3561aefae7 100644 --- a/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md +++ b/docs/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md @@ -66,3 +66,16 @@ Note that these URLs will not return valid data until the authentication configu ::: ## Configuring SAML Single Logout (SLO) + +Rancher supports the ability to configure SAML SLO. Options include logging out of the Rancher application only, logging out of Rancher and registered applications tied to the external authentication provider, or a prompt asking the user to choose between the previous options. The steps below outline configuration from the application GUI: + +1. Sign in to Rancher using a [standard user or an administrator role](../manage-role-based-access-control-rbac/global-permissions.md) to configure SAML SLO. +1. In the top left corner, click **☰ > Users & Authentication**. +1. In the left navigation menu, click **Auth Provider**. +1. Under the section **Log Out behavior**, choose the appropriate SLO setting as described below: + + | Setting | Description | + | ------------------------- | ----------------------------------------------------------------------------- | + | Log out of Rancher and not authentication provider | Choosing this option will only logout the Rancher application and not external authentication providers. | + | Log out of Rancher and authentication provider (includes all other applications registered with authentication provider) | Choosing this option will logout Rancher and all external authentication providers along with any registered applications linked to the provider. | + | Allow the user to choose one of the above in an additional log out step | Choosing this option presents users with a choice of logout method as described above. | diff --git a/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md b/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md index 4e3d9c2713c..1ee8f543015 100644 --- a/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md +++ b/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-keycloak-saml.md @@ -192,3 +192,18 @@ Try configuring and saving keycloak as your SAML provider and then accessing the * Check your Keycloak log. * If the log displays `request validation failed: org.keycloak.common.VerificationException: SigAlg was null`, set `Client Signature Required` to `OFF` in your Keycloak client. + +## Configuring SAML Single Logout (SLO) + +Rancher supports the ability to configure SAML SLO. Options include logging out of the Rancher application only, logging out of Rancher and registered applications tied to the external authentication provider, or a prompt asking the user to choose between the previous options. The steps below outline configuration from the application GUI: + +1. Sign in to Rancher using a [standard user or an administrator role](../manage-role-based-access-control-rbac/global-permissions.md) to configure SAML SLO. +1. In the top left corner, click **☰ > Users & Authentication**. +1. In the left navigation menu, click **Auth Provider**. +1. Under the section **Log Out behavior**, choose the appropriate SLO setting as described below: + + | Setting | Description | + | ------------------------- | ----------------------------------------------------------------------------- | + | Log out of Rancher and not authentication provider | Choosing this option will only logout the Rancher application and not external authentication providers. | + | Log out of Rancher and authentication provider (includes all other applications registered with authentication provider) | Choosing this option will logout Rancher and all external authentication providers along with any registered applications linked to the provider. | + | Allow the user to choose one of the above in an additional log out step | Choosing this option presents users with a choice of logout method as described above. | diff --git a/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md b/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md index 1f601689bc1..6755ce3ebb6 100644 --- a/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md +++ b/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-okta-saml.md @@ -107,4 +107,19 @@ The OpenLDAP service account is used for all searches. Rancher users will see us 1. Click **Okta** or, if SAML is already configured, **Edit Config** 1. Under **User and Group Search**, check **Configure an OpenLDAP server** -If you experience issues when you test the connection to the OpenLDAP server, ensure that you entered the credentials for the service account and configured the search base correctly. Inspecting the Rancher logs can help pinpoint the root cause. Debug logs may contain more detailed information about the error. Please refer to [How can I enable debug logging](../../../../faq/technical-items.md#how-can-i-enable-debug-logging) for more information. \ No newline at end of file +If you experience issues when you test the connection to the OpenLDAP server, ensure that you entered the credentials for the service account and configured the search base correctly. Inspecting the Rancher logs can help pinpoint the root cause. Debug logs may contain more detailed information about the error. Please refer to [How can I enable debug logging](../../../../faq/technical-items.md#how-can-i-enable-debug-logging) for more information. + +## Configuring SAML Single Logout (SLO) + +Rancher supports the ability to configure SAML SLO. Options include logging out of the Rancher application only, logging out of Rancher and registered applications tied to the external authentication provider, or a prompt asking the user to choose between the previous options. The steps below outline configuration from the application GUI: + +1. Sign in to Rancher using a [standard user or an administrator role](../manage-role-based-access-control-rbac/global-permissions.md) to configure SAML SLO. +1. In the top left corner, click **☰ > Users & Authentication**. +1. In the left navigation menu, click **Auth Provider**. +1. Under the section **Log Out behavior**, choose the appropriate SLO setting as described below: + + | Setting | Description | + | ------------------------- | ----------------------------------------------------------------------------- | + | Log out of Rancher and not authentication provider | Choosing this option will only logout the Rancher application and not external authentication providers. | + | Log out of Rancher and authentication provider (includes all other applications registered with authentication provider) | Choosing this option will logout Rancher and all external authentication providers along with any registered applications linked to the provider. | + | Allow the user to choose one of the above in an additional log out step | Choosing this option presents users with a choice of logout method as described above. | diff --git a/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md b/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md index e45d179881e..c3561aefae7 100644 --- a/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md +++ b/versioned_docs/version-2.10/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/configure-pingidentity.md @@ -64,3 +64,18 @@ Note that these URLs will not return valid data until the authentication configu - The group drop-down shows only the groups that you are a member of. You will not be able to add groups that you are not a member of. ::: + +## Configuring SAML Single Logout (SLO) + +Rancher supports the ability to configure SAML SLO. Options include logging out of the Rancher application only, logging out of Rancher and registered applications tied to the external authentication provider, or a prompt asking the user to choose between the previous options. The steps below outline configuration from the application GUI: + +1. Sign in to Rancher using a [standard user or an administrator role](../manage-role-based-access-control-rbac/global-permissions.md) to configure SAML SLO. +1. In the top left corner, click **☰ > Users & Authentication**. +1. In the left navigation menu, click **Auth Provider**. +1. Under the section **Log Out behavior**, choose the appropriate SLO setting as described below: + + | Setting | Description | + | ------------------------- | ----------------------------------------------------------------------------- | + | Log out of Rancher and not authentication provider | Choosing this option will only logout the Rancher application and not external authentication providers. | + | Log out of Rancher and authentication provider (includes all other applications registered with authentication provider) | Choosing this option will logout Rancher and all external authentication providers along with any registered applications linked to the provider. | + | Allow the user to choose one of the above in an additional log out step | Choosing this option presents users with a choice of logout method as described above. |