simple SAML SP based on simpleSAMLPHP
2.3K
A simple SAML SP Docker container based on the kenchan0130/simplesamlphp image
simpleSAMLPHP documentation store
Part of the GUNet simpleidentity suite (includes a CAS SSO server and several SSO protocol testers)
Exposes port 8080
Default admin username/password: admin/secret
The docker entrypoint makes sure to download the CAS IdP server metadata using the IDP_ENTITYID environment variable. Can be used to test a working setup of the simpleidentity suite or of your own CAS SSO/Shibboleth IdP installation. That means that the container must be started after the CAS server is up and healthy.
Main path: http://<server>:8080/simplesaml
SP Metadata URL: http://<server>:8080/simplesaml/module.php/saml/sp/metadata.php/default-sp
We also include a tool for processing the IdP metadata (it is used by the docker entrypoint of the image) which can be used manually if necessary. One downloads the IdP metadata (say in /var/tmp/idp-metadata.xml) and then runs cd /var/www/simplesamlphp/www/admin; php metadata-converter-command.php -f /var/tmp/idp-metadata.xml 2>/dev/null. The output should be saved in /var/www/simplesamlphp/metadata/saml20-idp-remote.php with a <?php before the output
In a multi-container setup, especially if an actual person (and not a puppeteer script) is accessing the CAS server and/or the SAML SP, the public IP must be used when setting up endpoints, otherwise things will not work as expected.
Main environment variables:
SIMPLESAMLPHP_SP_HOSTNAME: The hostname to use when construcing our own metadata. Default value saml-spSIMPLESAMLPHP_SP_PORT: The port to use when constructing our own metadata. Default value 8080IDP_ENTITYID: The entityId of the IdP. Default value https://host.docker.internal:8443/cas/idpIDP_METADATA_PATH: The path under which the IdP metadata endpoint (or metadata file) is situated. The full metadata endpoint (the concatenation of IDP_ENTITYID and IDP_METADATA_PATH) will be used by the docker entrypoint to download the actual metadata. Default value /metadata (this is the default path for the CAS SSO server)IDP_BASE_URL: In the case of a Shibboleth IdP the EntityID is usually https://<hostname>/idp/shibboleth which cannot be used to download the metadata. For such cases we allow a variable IDP_BASE_URL which will reflect the actual base URL of the IdP (such as https://<hostname>). If the variable is not set then we use IDP_ENTITYID along with IDP_METADATA_PATH. As a result it does not have a default value (it is actually not even set). Checked by the docker entrypoint.SIMPLESAMLPHP_SP_SIGN_AUTHNREQUEST: Sign the AutnNRequest or not (default false, use true for signing)SIMPLESAMLPHP_SP_ENCRYPT_ASSERTION: Require encrypted assertions from the IdP (default false, use true otherwise)SIMPLESAMLPHP_SP_SIGN_LOGOUT: Sign Logout requests (default false, use true otherwise)The above mean that the entityiID of our own SP will be http://${SIMPLESAMLPHP_SP_HOSTNAME}:${SIMPLESAMLPHP_SP_PORT}
The Single Logout and Assertion Consumer Service are set by simpleSAMLPHP itself as:
http://<requested name>:${SIMPLESAMLPHP_SP_PORT}/simplesaml/module.php/saml/sp/saml2-logout.php/default-sphttp://<requested name>:${SIMPLESAMLPHP_SP_PORT}/simplesaml/module.php/saml/sp/saml2-acs.php/default-sp
were <requested name> is the name we use to access the simple SAML SP (so if we access it using http://localhost:8080 and not http://docker.host.internal:8080 then the first URL will be used)Run: docker run --rm --name saml-sp -d -p 8080:8080 [-e <env var>] gunet/simple-saml-sp
How to include in docker-compose.yaml:
saml-sp:
image: gunet/simple-saml-sp
ports:
- ${SAML_SP_PORT:-8080}:8080
environment:
- IDP_ENTITYID=${CAS_SERVER_NAME:-https://host.docker.internal:8443}/cas/idp
- SIMPLESAMLPHP_SP_HOSTNAME=${SIMPLESAMLPHP_SP_HOSTNAME:-host.docker.internal}
- SIMPLESAMLPHP_SP_PORT=${SIMPLESAMLPHP_SP_PORT:-8080}
extra_hosts:
- "host.docker.internal:host-gateway"
depends_on:
ldap:
condition: service_healthy
sso:
condition: service_healthy
config/authsources.php metadata/saml20-idp-remote.phpFederation tab of the web interface.Content type
Image
Digest
sha256:4043e8420…
Size
212.1 MB
Last updated
about 1 year ago
docker pull gunet/simple-saml-sp