How can I configure an asp.net Service Provider (Web Application) to use Sustainsys.Saml2 with OKTA as the identity Provider

Viewed 199

Looking at the documentation at https://saml2.sustainsys.com/en/stable/getting-started.html#asp-net-web-forms

It appears that Sustainsys.Saml2.HttpModule would be the way to go.

"In many cases it should just be configured in the web.config file and work without any code written in the application at all"

So, I have created a simple test asp.net web application and referenced Sustainsys.Saml2 (2.8.0) and Sustainsys.Saml2.HttpModule (2.8.0) in my Visual Studio project

The Web Site that I ultimately want to add SAML SSO to is an asp.net web application with thousands of pages inheriting from a master page. I want it to use the OKTA login pages as the Identity Provider, but if I get that working I would try it on other Identity Providers too.

Unfortunately, I am finding the configuration settings bewildering.

Does anyone have a really basic (minimal) example web.config for Single Sign On for a basic SAML 2 application setup in OKTA (using mostly defaults)?

I can do stuff like downloaded the X509 .cert from the OKTA App Integration

Identity Provider Single Sign-On URL: https://#######.okta.com/app/#######_sustainsyssamlexample_1/####################/sso/saml

Identity Provider Issuer: http://www.okta.com/####################

Single Sign On URL: https://localhost:44334/Saml2/Acs

Recipient URL: https://localhost:44334/Saml2/Acs

Destination URL: https://localhost:44334/Saml2/Acs

Audience Restriction: https://localhost:44334/Saml2

Name ID Format: x509SubjectName

I am assuming that the /Saml2/Acs and /Saml2 are requirements that are built into Sustainsys.Saml2.HttpModule

I just need to get something working and then I can play around with the rest. Any help on this would be brilliant.

0 Answers
Related