Skip to main content

Shibboleth

Discover step-by-step instructions on configuring a connection with Shibboleth Identity Provider. Learn how to integrate your application with Shibboleth to secure and streamlined SSO authentication.

How to start​

SSO Shibboleth integration with Cryptr
  1. Connect to the server hosting your Shibboleth Identity Provider.
  2. Open a shell in your installation directory, usually /opt/shibboleth-idp.

XML Metadata file​

SSO Shibboleth integration with Cryptr
  • Your IdP publishes its metadata at https://your-idp.example.org/idp/shibboleth
  • Open that URL and check the entityID matches the one in conf/idp.properties
  • Copy the URL, or download the file if your IdP is not reachable from the internet

SSO Shibboleth integration with Cryptr

Paste your Metadata URL and click on "Submit".

Register Cryptr as a Service Provider​

SSO Shibboleth integration with Cryptr

Copy the "SP Metadata URL" shown in the right sidebar πŸ‘‰ β€” this is the URL your Identity Provider will fetch Cryptr's metadata from.


SSO Shibboleth integration with Cryptr
  • On your IdP server, edit conf/metadata-providers.xml
  • Add a FileBackedHTTPMetadataProvider whose metadataURL is the SP Metadata URL you just copied
  • Give it a backingFile such as %\{idp.home\}/metadata/cryptr-sp.xml, so the IdP keeps working if Cryptr is briefly unreachable

SSO Shibboleth integration with Cryptr

Place it just before the final closing tag of the file, so it sits inside the chaining provider. Added inside one of the commented examples it is silently ignored, and logins fail with "the application you have accessed is not registered".

Attributes Mapping​

SSO Shibboleth integration with Cryptr

Cryptr needs two attributes, and Shibboleth already knows both of them under their standard names.

  • uid becomes the stable user identifier
  • mail becomes the user email address

SSO Shibboleth integration with Cryptr
  • Open conf/attribute-resolver.xml and make sure uid and mail resolve for your users
  • The stock configuration already defines both, so most deployments have nothing to change here

SSO Shibboleth integration with Cryptr
  • Open conf/attribute-filter.xml and add a policy releasing uid and mail to Cryptr
  • Scope it with a Requester rule set to the SP Entity ID shown in the right sidebar πŸ‘‰

Signature​

SSO Shibboleth integration with Cryptr

Shibboleth signs the assertion and leaves the response envelope unsigned by default, which is exactly what Cryptr expects. You have nothing to change in conf/relying-party.xml.


SSO Shibboleth integration with Cryptr

The default Name ID format is "Transient", which Cryptr supports. The stable identifier comes from the uid attribute, not from the Name ID.

Restart your Identity Provider​

SSO Shibboleth integration with Cryptr
  • Restart your servlet container so the new configuration is picked up
  • In logs/idp-process.log, look for a line reading New metadata successfully loaded for cryptr-sp.xml

Test SSO login​

Test SSO login