Shibboleth
Discover step-by-step instructions on configuring a connection with Shibboleth Identity Provider. Learn how to integrate your application with Shibboleth to secure and streamlined SSO authentication.
How to startβ

- Connect to the server hosting your Shibboleth Identity Provider.
- Open a shell in your installation directory, usually
/opt/shibboleth-idp.
XML Metadata fileβ

- Your IdP publishes its metadata at
https://your-idp.example.org/idp/shibboleth - Open that URL and check the
entityIDmatches the one inconf/idp.properties - Copy the URL, or download the file if your IdP is not reachable from the internet

Paste your Metadata URL and click on "Submit".
Register Cryptr as a Service Providerβ

Copy the "SP Metadata URL" shown in the right sidebar π β this is the URL your Identity Provider will fetch Cryptr's metadata from.

- On your IdP server, edit
conf/metadata-providers.xml - Add a
FileBackedHTTPMetadataProviderwhosemetadataURLis the SP Metadata URL you just copied - Give it a
backingFilesuch as%\{idp.home\}/metadata/cryptr-sp.xml, so the IdP keeps working if Cryptr is briefly unreachable

Place it just before the final closing tag of the file, so it sits inside the chaining provider. Added inside one of the commented examples it is silently ignored, and logins fail with "the application you have accessed is not registered".
Attributes Mappingβ

Cryptr needs two attributes, and Shibboleth already knows both of them under their standard names.
uidbecomes the stable user identifiermailbecomes the user email address

- Open
conf/attribute-resolver.xmland make sureuidandmailresolve for your users - The stock configuration already defines both, so most deployments have nothing to change here

- Open
conf/attribute-filter.xmland add a policy releasinguidandmailto Cryptr - Scope it with a
Requesterrule set to the SP Entity ID shown in the right sidebar π
Signatureβ

Shibboleth signs the assertion and leaves the response envelope unsigned by default, which is exactly what Cryptr expects. You have nothing to change in conf/relying-party.xml.

The default Name ID format is "Transient", which Cryptr supports. The stable identifier comes from the uid attribute, not from the Name ID.
Restart your Identity Providerβ

- Restart your servlet container so the new configuration is picked up
- In
logs/idp-process.log, look for a line readingNew metadata successfully loadedforcryptr-sp.xml
Test SSO loginβ
Test SSO login