Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generic SAML2 integration vs ISAM, multiple IdPs #62

Closed
micsafi opened this issue Mar 6, 2021 · 2 comments
Closed

Generic SAML2 integration vs ISAM, multiple IdPs #62

micsafi opened this issue Mar 6, 2021 · 2 comments

Comments

@micsafi
Copy link

micsafi commented Mar 6, 2021

Regarding the ISAM integration functionality, which seems to be based on generic SAML2 integration feature (samlWeb-2.0) from Websphere Liberty:

  • Do you see any reason why the ISAM config would not work with other SAML2 IdPs? Have you tested with other IdP solutions?
  • Is there a way to configure multiple SAML2 based IdPs, in a scenario where users are managed in different IAM solutions?
@inalasai
Copy link

Do you see any reason why the ISAM config would not work with other SAML2 IdPs? Have you tested with other IdP solutions?

ISAM specific config may not work straightaway with other IdPs as endpoints may differ between IdPs from different vendors. We haven’t tested with other IdP solutions but one of our customers has recently configured SPM successfully with Oracle Access manager. We are currently working with them to support SP flow SSO with SPM Universal Access web app on Weblogic using OAM.

Is there a way to configure multiple SAML2 based IdPs, in a scenario where users are managed in different IAM solutions?

Almost every application server supports configuration of multiple IdPs. SPM which is based on SAML2 supports it as well when deployed on an application server that is configured to interact with multiple IdPs. Again we have not tried this in-house but we don’t see a reason why it would fail. We have a plan to try this in future. SPM Universal Access web app (React based application) does not support multiple IdPs OOTB as we don’t see a need for supporting mutliple IdPs for single instance of UA web app. UA web app supports pluggable authentication functionality where customers can customise the OOTB SSO authentication module to support multiple IdPs.

@wwwild
Copy link

wwwild commented Nov 23, 2022

Closing as the questions have been answered.

@wwwild wwwild closed this as completed Nov 23, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants