Sign inSign up

gunet/simple-saml-sp

By gunet

•Updated about 1 year ago

simple SAML SP based on simpleSAMLPHP

Buildkit cache
Image
0

2.3K

gunet/simple-saml-sp repository overview

A simple SAML SP Docker container based on the kenchan0130/simplesamlphp⁠ image

simpleSAMLPHP documentation store⁠

Part of the GUNet simpleidentity suite (includes a CAS SSO server and several SSO protocol testers)

Exposes port 8080

Default admin username/password: admin/secret

The docker entrypoint makes sure to download the CAS IdP server metadata using the IDP_ENTITYID environment variable. Can be used to test a working setup of the simpleidentity suite or of your own CAS SSO/Shibboleth IdP installation. That means that the container must be started after the CAS server is up and healthy.

Main path: http://<server>:8080/simplesaml

SP Metadata URL: http://<server>:8080/simplesaml/module.php/saml/sp/metadata.php/default-sp

We also include a tool for processing the IdP metadata (it is used by the docker entrypoint of the image) which can be used manually if necessary. One downloads the IdP metadata (say in /var/tmp/idp-metadata.xml) and then runs cd /var/www/simplesamlphp/www/admin; php metadata-converter-command.php -f /var/tmp/idp-metadata.xml 2>/dev/null. The output should be saved in /var/www/simplesamlphp/metadata/saml20-idp-remote.php with a <?php before the output

In a multi-container setup, especially if an actual person (and not a puppeteer script) is accessing the CAS server and/or the SAML SP, the public IP must be used when setting up endpoints, otherwise things will not work as expected.

Main environment variables:

  • SIMPLESAMLPHP_SP_HOSTNAME: The hostname to use when construcing our own metadata. Default value saml-sp
  • SIMPLESAMLPHP_SP_PORT: The port to use when constructing our own metadata. Default value 8080
  • IDP_ENTITYID: The entityId of the IdP. Default value https://host.docker.internal:8443/cas/idp
  • IDP_METADATA_PATH: The path under which the IdP metadata endpoint (or metadata file) is situated. The full metadata endpoint (the concatenation of IDP_ENTITYID and IDP_METADATA_PATH) will be used by the docker entrypoint to download the actual metadata. Default value /metadata (this is the default path for the CAS SSO server)
  • IDP_BASE_URL: In the case of a Shibboleth IdP the EntityID is usually https://<hostname>/idp/shibboleth which cannot be used to download the metadata. For such cases we allow a variable IDP_BASE_URL which will reflect the actual base URL of the IdP (such as https://<hostname>). If the variable is not set then we use IDP_ENTITYID along with IDP_METADATA_PATH. As a result it does not have a default value (it is actually not even set). Checked by the docker entrypoint.
  • Protocol specific variables:
    • SIMPLESAMLPHP_SP_SIGN_AUTHNREQUEST: Sign the AutnNRequest or not (default false, use true for signing)
    • SIMPLESAMLPHP_SP_ENCRYPT_ASSERTION: Require encrypted assertions from the IdP (default false, use true otherwise)
    • SIMPLESAMLPHP_SP_SIGN_LOGOUT: Sign Logout requests (default false, use true otherwise)

The above mean that the entityiID of our own SP will be http://${SIMPLESAMLPHP_SP_HOSTNAME}:${SIMPLESAMLPHP_SP_PORT}

The Single Logout and Assertion Consumer Service are set by simpleSAMLPHP itself as:

  • http://<requested name>:${SIMPLESAMLPHP_SP_PORT}/simplesaml/module.php/saml/sp/saml2-logout.php/default-sp
  • http://<requested name>:${SIMPLESAMLPHP_SP_PORT}/simplesaml/module.php/saml/sp/saml2-acs.php/default-sp were <requested name> is the name we use to access the simple SAML SP (so if we access it using http://localhost:8080 and not http://docker.host.internal:8080 then the first URL will be used)

Run: docker run --rm --name saml-sp -d -p 8080:8080 [-e <env var>] gunet/simple-saml-sp

How to include in docker-compose.yaml:

  saml-sp:
    image: gunet/simple-saml-sp
    ports:
      - ${SAML_SP_PORT:-8080}:8080
    environment:
      - IDP_ENTITYID=${CAS_SERVER_NAME:-https://host.docker.internal:8443}/cas/idp
      - SIMPLESAMLPHP_SP_HOSTNAME=${SIMPLESAMLPHP_SP_HOSTNAME:-host.docker.internal}
      - SIMPLESAMLPHP_SP_PORT=${SIMPLESAMLPHP_SP_PORT:-8080}
    extra_hosts:
      - "host.docker.internal:host-gateway"
    depends_on:
      ldap:
        condition: service_healthy
      sso:
        condition: service_healthy

⁠Extra Documentation

  • SP setup: config/authsources.php
  • Remote IdP setup: metadata/saml20-idp-remote.php
  • The metadata of your SP can be found in the Federation tab of the web interface.

Tag summary

Content type

Image

Digest

sha256:4043e8420…

Size

212.1 MB

Last updated

about 1 year ago

docker pull gunet/simple-saml-sp