Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FtW64
Contributor
Jump to solution

Modify 'Return URL' in Identity Provider object for SmartConsole SAML SSO

I have successfully setup SmartConsole SAML SSO, using an Identity Provider object in SmartConsole.

When creating this Identity Provider object, the IdP "Return URL" is automatically populated like: "https://192.168.100.241/...", where 192.168.100.241 is the IP address of the management server. You cannot edit this value.

I'd like to replace the IP address with the FQDN of the management server, like "https://sms.mydomain.com/...".

Is this possible? If so, how?

Thanks in advance!

-Frank

0 Kudos
1 Solution

Accepted Solutions
FtW64
Contributor

SOLVED

It is in the "R81.20 Quantum Security Management Administration Guide", as explained by CP TAC, although a bit hidden: search for "SAML_IP_OR_NAME".

  1. Edit $CPDIR/tmp/.CPprofile.sh
  2. Add this line to the file:

    SAML_IP_OR_NAME=example.com; export SAML_IP_OR_NAME

  3. Restart the management server (cpstop;cpstart will do)

NOTE:

When creating an Identity Provider object for SmartConsole ("Managing Administrator Access"), the Return URL still shows the IP address. However, when SmartConsole performs the SAML request, it uses the FQDN in the Return URL silently. So, you MUST manually change the IP address for the FQDN when configuring the Return URL on the IdP (EntraID or similar).

 

 

View solution in original post

7 Replies
the_rock
Legend
Legend

I could be mistaken, but the only way I know of possibly be able to do that is if you change what I attached and install policy.

Andy

0 Kudos
Nüüül
Advisor
Advisor

if this would work, it only works on standalone installation. management server objects don´t have VPN Portal settings 🙂

i believe, you will have to change simple-saml config files or something like that. would suggest having TAC involved.

 

0 Kudos
the_rock
Legend
Legend

Funny enough, that lab is standalone : - )

0 Kudos
FtW64
Contributor

Note that I'm using the SmartCenter Server as a SAML service provider. I'm not authenticating agains the gateway (or gateways) for Client VPN. Or are you referring to a management server cluster (management HA)?

0 Kudos
FtW64
Contributor

This is for IA (or Remote Access VPN) IdP. I don't think these settings apply to the management server as a SAML SP.

I have submitted a TAC case and will update when (if) I get a solution.

0 Kudos
FtW64
Contributor

SOLVED

It is in the "R81.20 Quantum Security Management Administration Guide", as explained by CP TAC, although a bit hidden: search for "SAML_IP_OR_NAME".

  1. Edit $CPDIR/tmp/.CPprofile.sh
  2. Add this line to the file:

    SAML_IP_OR_NAME=example.com; export SAML_IP_OR_NAME

  3. Restart the management server (cpstop;cpstart will do)

NOTE:

When creating an Identity Provider object for SmartConsole ("Managing Administrator Access"), the Return URL still shows the IP address. However, when SmartConsole performs the SAML request, it uses the FQDN in the Return URL silently. So, you MUST manually change the IP address for the FQDN when configuring the Return URL on the IdP (EntraID or similar).

 

 

the_rock
Legend
Legend
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events