This is an old revision of the document!


Guideline for Service Owners

Connecting to our Identity Providers (IdPs)

We provide you with the flexibility to connect your services to our IdP solutions through two protocols: SAML and OIDC. These protocols ensure a secure and smooth integration, allowing for seamless authentication and authorization processes for your applications.

1: Security Assertion Markup Language (SAML):

SAML allows for secure single sign-on (SSO) and federation across different applications and platforms. It enables the exchange of user authentication and authorization information in a standardized way, ensuring smooth communication between your services and our IdPs.

GWDG Academic ID SAML Solutions:

SimpleSAMLphp:

SimpleSAMLphp (https://simplesamlphp.org) is an open-source software package for providing IAM functionalities and features. It is written in PHP and supports straightforward integration of new customizable modules. SimpleSAMLphp is often used to provide authentication and authorization services for web-based applications; however, it also supports native mobile apps and APIs using different protocols, including SAML, OIDC, and OAuth. It is designed to be easy to install and configure and can be used as a standalone application or as a module within other applications.

Shibboleth:

Shibboleth (https://www.shibboleth.net) is a type of open-source SAML implementation developed by the Shibboleth Consortium. It provides content personalization, secure authentication, and authorization and enables SSO functionality for accessing services in multiple domains. Shibboleth has been designed to be compatible with many organizational domains' infrastructures to support general FIM requirements.

Information We Need from You:

To connect your services to our SAML SSO solution, we request the following information from you:

  • SP Metadata (Mandatory): Provide us with the metadata of your service, which typically includes information about your organization, entity ID, and SAML endpoints.
  • Authorization Policies (Optional): Provide us with the information and conditions on whom and how they can access your services. Example: Only students from the University “ABC” are authorized to access our resources.

Once you have collected this information, please submit it to our support team at sso-support@gwdg.de.

Hosting IdPs

Setting up your Service Provider (SP)

This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.More information about cookies