.net core console authenticate to AWS Cognito onpremise AD FS SAML

Viewed 407

Is it possible to authenticate from .NET Core console app (running on premise) to AWS Congnito with AD FS SAML please?

I can authenticate Cognito User Pool with a PASSWORD:

AmazonCognitoIdentityProviderClient provider = new AmazonCognitoIdentityProviderClient();
            CognitoUserPool userPool = new CognitoUserPool("user-pool-id", "client-id", provider);
            CognitoUser user = new CognitoUser("cognito-user1", "client-id", userPool, provider);
            InitiateSrpAuthRequest authRequest = new InitiateSrpAuthRequest()
            {
                Password = "cognito-password1"
            };

            AuthFlowResponse authResponse = await user.StartWithSrpAuthAsync(authRequest);
1 Answers

You will first need to setup your SAML Identity Provider to a User Pool in cognito. Instructions for that from AWS are here. Additional setup instructions located here as well.

For a working example released from AWS that uses cognito with an external IdP (with ADFS specifically used as an example), see here. This example shows in cdk/src/cdk.ts all the resources setup, including roles, policies, and IdP settings. This will likely illuminate if you have missed any part of the required setup to bootstrap this solution. From the page:

This example can be used as a starting point for using Amazon Cognito together with an external IdP (e.g. a SAML 2.0/OIDC provider or a social login provider). It shows how to use triggers in order to map IdP attributes (e.g. LDAP group membership passed on the SAML response as an attribute) to Amazon Cognito User Pools Groups and optionally also to IAM roles.

It contains all that is needed in order to create a serverless web application with Amazon Cognito, Amazon API Gateway, AWS Lambda and Amazon DynamoDB (with optionally an external IdP).

It handles fine-grained role-based access control and demonstrates how to associate users to roles/groups based on mapped attributes from an external IdP or social login provider.

It is using TypeScript for frontend, backend and infrastructure. (Using AWS CDK)

Related