Bug 48473 - The SAML IdP should be available on UCS member server
The SAML IdP should be available on UCS member server
Status: NEW
Product: UCS
Classification: Unclassified
Component: SAML
UCS 5.0
Other Linux
: P5 enhancement (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
: 47908 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-01-15 15:14 CET by Nico Gulden
Modified: 2020-07-06 16:37 CEST (History)
6 users (show)

See Also:
What kind of report is it?: Feature Request
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?: Yes
ISV affected?: Yes
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): External feedback, Security
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nico Gulden univentionstaff 2019-01-15 15:14:54 CET
Feedback from an app provider: Currently, the SAML identity provider runs on a UCS domain controller. For access from the Internet, it is required that the domain controller is exposed to the Internet. This regularly causes frowning from customers.

It should be possible to make the IdP available on a member server.
Comment 2 Florian Best univentionstaff 2019-03-07 14:59:23 CET
Doing this requires the DC Slave or whatever to simply proxy all requests to the DC Master. For security reasons the IDP must not be installed on other systems than a DC Master.
Comment 3 Florian Best univentionstaff 2019-03-18 09:21:01 CET
*** Bug 47908 has been marked as a duplicate of this bug. ***
Comment 4 Florian Best univentionstaff 2019-03-18 09:24:20 CET
I suggest as a solution that we provide a debian package univention-saml-idp-proxy which then can act as the IDP and forwards all requests to /simplesamlphp/ to the DC Master.

@Profession services:
You already have such a configuration for customer projects, could you paste the essentials part of it?