This sample is a demonstration on how to configure SAML2 SSO using a sample service provider.
When running this sample on AS
Both this SSOAgentSample application and WSO2 Application Server contain different versions of the same slf4j jar. As a solution you can select ONE of the following approaches.
- Remove log4j-over-slf4j-1.6.1.jar file from travelocity.com.war/WEB-INF/lib directory and deploy.
<AS_HOME>/repository/conf/tomcat/webapp-classloading-environments.xmlto resolve the
slf4jconflict and restart the WSO2 Application Server. This change is done so as not to expose the
org.slf4j.*package from WSO2 Carbon.
Configuring the web app
Check out the source from the repository location which contains the samples.
Remove the parent entry in the pom.xml file that comes along with the sample. The contents of the pom.xml file will look similar to the following.
<HOME>/sso/SSOAgentSamplein the checked out folder and build the sample with following command.
- After successfully building the sample, a .war file named
travelocity.comcan be found inside the
Deploy this sample web app on a web container. To do this, use the Apache Tomcat server.
Since this sample is written based on Servlet 3.0 it needs to be deployed on Tomcat 7.x.
Use the following steps to deploy the web app in the web container:
- Stop the Apache Tomcat server if it is already running.
- Copy the
travelocity.warfile to the
- Start the Apache Tomcat server.
travelocity.properties file, which is found inside the
travelocity.com/WEB-INF/classes folder, can be used to change the properties like
consumer url and
IdP url. This sample uses default values.
- A unique identifier for this SAML 2.0 Service Provider application:
- The URL of the SAML 2.0 Assertion Consumer:
- The URL of the SAML 2.0 Identity Provider:
Now that the web app is successfully deployed on a web container; the next step is to configure WSO2 Identity Server as the identity provider.
Configuring WSO2 Identity Server as an identity provider
- Start the Identity Server and access the management console using https://localhost:9443/carbon/
- Log in to the Identity Server using default administrator credentials (the username and password are both "admin").
- In the management console found on the left of your screen, navigate to the Main menu and click add under Service Provider.
- Expand the Inbound Authentication Configuration section and then expand SAML2 Web SSO Configuration.
- Click Configure. A form appears. Register the new service provider by providing the following values.
This value should be same as the
SAML.IssuerIDvalue specified inside the
Assertion Consumer URL:
This value should be same as the
SAML.ConsumerUrlvalue mentioned inside the
- NameID format: Enter the default value here (i.e.,
- Use fully qualified username in the NameID: Set this as true by selecting the checkbox
- Enable Response Signing: Set this as true by selecting the checkbox
- Enable Assertion Signing: Set this as true by selecting the checkbox
- Enable Signature Validation in Authentication Requests and Logout Requests: Set this as true (Certificate alias = wso2carbon)
- Enable Single Logout: Set this as true by selecting the checkbox
- After providing above values click Register.
After successfully registering the service provider, log out from management console. You have now configuring Identity Server as the identity provider. The next step is to run the sample.
Running the sample
. You are directed to the following page:
- Since you need to use SAML2 for this sample, click the first link, i.e., Click here to login with SAML from Identity Server. You are redirected to the Identity Server for authentication.
- Enter the default admin credentials (admin/admin).
- Now you are logged in and you can see the home page of the travelocity.com app.
If you need to view the SAML request and response, please add the following debug log to the
log4j.propertiesfile found inside
- Since single log out is enabled, if you click the logout button in the travelocity.com home page, you will successfully log out.