Enable SAML for SSO
saml (security assertion markup language) is an open standard that facilitates single sign on (sso) by allowing swimlane turbine (the service provider) to rely on external identity providers (idps) to authenticate users by default, swimlane supports a single identity provider per account when the multi sso feature is enabled, administrators can configure multiple saml identity providers within the same account and assign users to the appropriate sso configuration login can start from turbine ( service provider–initiated ) or from your idp ( identity provider–initiated ) feature availability multi sso is controlled by a per account feature flag on the account settings features tab, the flag appears as multi sso by default, swimlane supports a single saml identity provider (idp) per account when multi sso is enabled for the account administrators can configure multiple saml identity providers and assign users to the appropriate sso configuration administrators can also configure multiple directory services configurations see directory services docid\ kygdtejblyxawquk65iza when multi sso is enabled for an account with an existing saml configuration, all existing users are automatically mapped to that configuration so that their current sso login continues without interruption see the automatic migration of existing users section to enable multi sso, contact swimlane support if you are a turbine platform (tp) customer, a super admin can enable the multi sso feature flag for the account prerequisite before enabling the flag if the account already has enabled saml settings without an identity provider signing certificate, turbine blocks enabling multi sso and displays failed to enable multi sso feature flag the existing saml settings do not have a certificate configured add an identity provider certificate to the saml settings before enabling multi sso on the single sso saml settings dialog ( sessions & security ), paste the idp signing certificate into the certificate text area or use upload certificate , then click apply click save on account settings, then enable multi sso again see the idp signing certificate requirements section choose your path goal go to configure saml when multi sso is not enabled configure saml authentication section configure multiple saml idps (multi sso) configure multiple sso identity providers section values to enter in your idp service provider metadata for your idp section test the login flow test sso login section require sso for all users force sso section idp signing certificate requirements (26 3 0) idp signing certificate requirements section provision users automatically provisioning with scim integration docid\ ucyk5mly9erosd2 nvjpu (saml does not create users) benefits of saml authentication when the multi sso feature is enabled, a swimlane account can contain multiple active saml identity providers this allows organizations to authenticate different groups of users through different identity providers while maintaining centralized account management common use cases include managed service providers (msps) supporting multiple customers, organizations undergoing mergers and acquisitions, subsidiaries using separate identity systems, and contractor or partner access scenarios centralized user management user authentication is managed through one or more external identity providers (idps), reducing administrative overhead while supporting multiple authentication sources within a single account when multi sso is enabled scalability supports large enterprises, msps, and multi tenant environments by allowing multiple identity providers to coexist within a single swimlane account when multi sso is enabled prerequisites account admin access to account settings a turbine user account that already exists for each person who will use sso turbine does not support just in time (jit) user creation through saml use provisioning with scim integration docid\ ucyk5mly9erosd2 nvjpu , directory services, or manual user creation to add users first your idp must send the user's email address as the saml name id the name id format in turbine is email address turbine matches the name id to the user's email field only; username based name ids are not supported the email in the saml response must match an existing turbine user matching is case insensitive when multi sso is enabled , users must also be assigned to the appropriate sso configuration before they can authenticate through that identity provider if your account uses a custom domain , use that hostname in the service provider entity id when you configure your idp idp signing certificate required (swimlane 26 3 0) every saml configuration must include an identity provider signing certificate on the single sso saml settings dialog, paste the certificate into the certificate text area or use upload certificate , then click apply and save account settings on multi sso, use certificate / add certificate you cannot enable multi sso while an enabled saml configuration is missing this certificate for full details, see the idp signing certificate requirements section service provider metadata for your idp provide these values to your idp when you register swimlane turbine as a saml application metadata description value service provider entity id unique identifier for turbine as the sp https //{your swimlane hostname}/tenant/api/saml/consume assertion consumer service (acs) url url where the idp posts the saml response same as the service provider entity id name id format format turbine expects in the saml assertion email address single sign on url idp endpoint turbine calls to start login copy from your idp identity provider entity id unique identifier for your idp copy from your idp metadata authnrequest signing whether turbine signs authentication requests optional — sign authnrequest? in general settings (different certificate from the idp signing certificate) idp signature verification whether turbine verifies the idp signature required saml responses are always verified; there is no option to disable verification provide the idp signing certificate (single sso certificate text area / upload certificate ; multi sso certificate ) required beginning in swimlane 26 3 0 single logout (slo) federated logout url not supported by turbine encrypted assertions whether assertions are encrypted not supported by turbine important turbine does not create users during saml login the name id email must match an existing user in your account before sso will succeed configure saml authentication use this section when multi sso is not enabled for your account single sso use this procedure when the multi sso feature is not enabled when multi sso is enabled, configure identity providers from the configure multiple sso identity providers section instead navigate to settings > account > account settings open the sessions & security tab expand the authentication section under saml authentication , turn enable on click saml settings to open the saml authentication dialog complete the fields below, then click apply click save on the account settings page to persist your changes identity provider settings field description name id format read only turbine expects email address configure the same format in your idp identity provider entity id globally unique idp identifier from your idp metadata required alias short identifier used at login for alias based sso required, 1–200 characters, unique in your account cannot contain html related characters < , > , " , ' , & , ( , ) , { , } , ; sso url idp single sign on url required idp signing certificate required beginning in swimlane 26 3 0 paste the idp public signing certificate (pem) into the certificate text area under identity provider settings , or use upload certificate supported file extensions txt , cert , crt , pem signature verification is always enforced this is the certificate covered by the idp signing certificate requirements section service provider settings field description service provider entity id enter https //{your swimlane hostname}/tenant/api/saml/consume use the same value in your idp application configuration required general settings setting description sign authnrequest? optional when enabled, upload a separate authnrequest signing certificate in pkcs #12 format ( pfx or p12 ) do not use a password protected file this is not the idp certificate required for 26 3 0 to convert pem key and certificate openssl pkcs12 export out cert pfx in cert pem inkey key pem preserve whitespace in saml response? enable only if your idp includes insignificant whitespace that breaks signature validation force sso is configured at the account level under sessions & security , not in this dialog see the force sso section configure multiple sso identity providers (multi sso) this section applies only when the multi sso feature is enabled for your account administrators can configure one or more saml identity providers (idps) from the sso page under account settings access the sso page navigate to settings > account settings > sso the sso page displays all configured sso providers, including name — the sso configuration name alias — the unique identifier associated with the sso configuration status — indicates whether the configuration is enabled or disabled click + add to create a new sso configuration basic settings in the basic section, configure the following fields field action sso name enter a descriptive name for the sso configuration alias enter a unique alias for the sso configuration the alias can include names, numbers, and special characters, and must be between 1 and 200 characters long the alias serves as a unique identifier for the sso configuration and is used to route users to the appropriate identity provider during authentication alias values must be unique across all accounts in the region while the configuration exists after you delete a configuration, its alias can be reused do not use html related characters < , > , " , ' , & , ( , ) , { , } , ; identity provider settings configure the connection between swimlane and the identity provider configuration select one of the following configuration methods from the configuration dropdown metadata url when you create or edit a multi sso saml configuration, select metadata url under identity provider settings to configure the identity provider using its saml metadata enter the federation metadata url provided by your identity provider swimlane retrieves the saml metadata xml and automatically populates the identity provider entity id, sso url, and signing certificate use this option when your identity provider provides a federation metadata url it simplifies configuration by eliminating the need to enter these values individually if a metadata url is not available, select manual and enter the identity provider details manually after entering the url, click import to automatically populate the following fields identity provider entity id single sign on (sso) url certificates add the identity provider certificate used to validate saml responses from the identity provider when configuration is set to metadata url , the identity provider entity id and sso url fields are read only use import to populate them from the metadata document to enter those values yourself, switch configuration to manual metadata url is available when you configure sso identity providers under multi sso ( settings > account settings > sso ) the single sso saml settings dialog on sessions & security does not include metadata url import; enter idp values manually there this option simplifies configuration by retrieving the identity provider details directly from the metadata document manual configure the identity provider manually by entering the required saml settings when using manual configuration, administrators must provide field description example identity provider entity id the globally unique identifier for the idp that turbine will use to verify the identity provider during authentication it serves as the official name of the idp in saml transactions https //\<identity provider domain> tld sso url the entry point for authentication requests from swimlane turbine to the idp it is where turbine sends authentication requests to initiate the sso process https //identity provider domain tld/saml2/turbinecloud identity provider certificate upload the identity provider's public signing certificate an identity provider signing certificate is required for saml authentication swimlane uses this certificate to verify signed saml responses from the identity provider saml response signature verification is always enforced and cannot be disabled supported certificate formats are pem and cert ensure that the certificate is accurate and matches the configuration in your idp incorrect or expired certificates can cause saml authentication failures service provider settings configure the swimlane service provider settings required by the identity provider swimlane pre populates the service provider settings required by your identity provider copy these values from turbine and use them when configuring swimlane as a service provider in your idp field description example service provider entity id the unique identifier for swimlane turbine as a service provider this value is pre populated in turbine copy it and provide it to your idp when configuring the saml connection it must be provided to the idp to allow the idp to trust and authenticate requests from turbine this id is critical in establishing a secure saml connection and must be configured accurately on both the idp and turbine sides https //{swimlane hostname here}/tenant/api/saml/consume general settings the following optional settings are available sign authnrequest signs authentication requests sent from swimlane to the identity provider select whether the saml authentication request should be signed by turbine by toggling the sign authnrequest? option if enabled, upload the private key and public certificate in pkcs #12 format ( pfx or p12 ) you can convert a pem formatted public certificate and key into pkcs #12 using the following command openssl pkcs12 export out cert pfx in pem public certificate crt inkey pem private key key do not enter a password for the pkcs #12 certificate turbine does not support password protected certificates preserve whitespace in saml response if your sso provider includes insignificant whitespace in the saml response signature, enable the preserve whitespace in saml response? toggle force sso is not configured per sso identity provider configure it at the account level under sessions & security see the force sso section user mapping user mapping is available only when multi sso is enabled users cannot authenticate through an sso identity provider until they are mapped to the corresponding sso configuration creating a new sso configuration does not automatically assign users to it after creating an sso configuration, administrators must manually assign users through user mapping , or assign the configuration from the user's authentication settings or during user creation each user can be associated with only one sso configuration at a time a user already assigned to an sso configuration cannot be assigned to another sso configuration until they are removed from the existing configuration to assign the user to a different sso configuration, first unmap the user from the current sso configuration, and then map the user to the new sso configuration administrators can assign users using either of the following methods assign individual users use the search users field to locate and select individual users the user list displays name email address selection checkbox assign users by group use the filter by group option to filter the user list by one or more groups the user list is updated to display users who belong to the selected groups, making it easier to locate and select multiple users after selecting the required users, save the sso configuration to assign them to remove assigned users, select clear selection to clear the current user selection, and then click save to apply the changes filtering by group is used only to locate and select users for bulk assignment to an sso configuration it does not create an ongoing association between the group and the sso configuration users added to the group later are not automatically assigned to that sso configuration and must be assigned separately users can be assigned to an sso configuration from either of the following locations settings > account settings > sso > user mapping user profile > authentication > saml configuration both interfaces manage the same user to sso relationship changes made in one location are automatically reflected in the other for assignment during user creation, see users docid\ iuzidcollvgz3x8qj4ywj and customize your user profile docid\ prwh3nd3y3c7jl5ohbvh1 after completing the configuration, enable or disable it using the enabled toggle, then click save manage existing sso configurations the sso page displays all configured sso providers for each configuration, administrators can open the actions menu ( ⋮ ) and select edit — modify the sso configuration delete — remove the sso configuration enable / disable — activate or deactivate the sso configuration the status column indicates whether the configuration is currently active automatic migration of existing users when the multi sso feature flag is enabled, turbine runs an upgrade that links existing users (and related directory data) only when a single configuration of each type exists single saml configuration existing non system users are automatically mapped to that sso configuration so current sso login continues without interruption single directory services configuration existing directory provisioned users and matching groups are linked to that directory services configuration zero or multiple saml configurations automatic saml user mapping is skipped administrators must assign users through user mapping , the user authentication tab, or during user creation zero or multiple directory services configurations automatic directory linking is skipped after multi sso is enabled, creating additional sso configurations does not automatically assign users map users to each new configuration as needed a successful saml login requires a user account that already exists in swimlane and is assigned to the appropriate identity provider configuration the name id value returned by the identity provider must match an existing swimlane user's email address swimlane does not support just in time (jit) user provisioning through saml correct incorrect user mapping if users are automatically mapped to the default sso configuration navigate to settings > account settings > sso edit the default sso configuration remove the incorrectly mapped users open the appropriate sso configuration map the users to the correct sso configuration using user mapping alternatively, update the user's saml configuration from the authentication tab in the user's profile see customize your user profile docid\ prwh3nd3y3c7jl5ohbvh1 test sso login service provider–initiated login go to the turbine login page click login via sso enter your alias or email address input behavior email address turbine looks up your account and starts saml authentication using the sso configuration assigned to that user alias turbine routes login using the alias configured for the matching sso configuration some accounts show alias only (alias only login mode) with multi sso, each sso configuration has its own alias; enter the alias that corresponds to the identity provider you intend to use complete authentication at your idp turbine validates the response and signs you in identity provider–initiated login open the turbine application from your idp portal (for example, an okta app tile) the idp sends a saml response to turbine turbine validates the response and matches the name id email to an existing user who is mapped to that sso configuration idp signing certificate requirements this section describes the swimlane 26 3 0 identity provider signing certificate requirement in detail complete certificate setup before or while you configure saml (see the configure saml authentication and configure multiple sso identity providers sections) overview to strengthen the security of swimlane's single sign on (sso) capabilities and support upcoming identity management enhancements, swimlane is making the identity provider (idp) signing certificate a required part of all saml sso configurations on the single sso saml settings dialog, paste the idp signing certificate into the certificate text area under identity provider settings , or use upload certificate on multi sso configurations, use certificate / add certificate (the ui shows certificate is configured when a certificate is stored) it is not the optional certificate used with sign authnrequest? in general settings this change improves the security posture of saml authentication by ensuring that saml assertions can be cryptographically validated and lays the foundation for future identity capabilities, including support for multiple saml identity providers (multi sso) which certificate is required? on the single sso saml authentication dialog ( sessions & security > saml settings ), two certificate controls appear only the idp signing certificate is required for this change the same dialog is shown in the general settings section under configure saml authentication setting location required for 26 3 0? purpose idp signing certificate (certificate text area / upload certificate ) identity provider settings yes the idp public signing certificate (pem) swimlane uses it to validate that saml responses come from your trusted idp signature verification is always enforced; there is no toggle to disable it sign authnrequest? general settings no (optional) a separate pkcs #12 ( pfx / p12 ) certificate that swimlane uses to sign authentication requests it sends to the idp this is not the certificate covered by this notice see general settings under configure saml authentication single sso paste the idp signing certificate into the certificate text area under identity provider settings , or use upload certificate do not confuse it with sign authnrequest? under general settings — that is a different, optional certificate multi sso use certificate / add certificate on each sso configuration (the ui shows certificate is configured when a certificate is stored) see the configure multiple sso identity providers section why is this change being made? idp signing certificates are an industry standard for establishing trust between an identity provider (idp) and a service provider (sp) requiring the idp signing certificate allows swimlane to verify that saml responses and assertions originate from a trusted identity provider protect against identity spoofing and unauthorized authentication attempts align with security best practices and modern saml implementations enable future multi sso capabilities, allowing organizations to securely configure and manage multiple saml identity providers within a single swimlane account how does this relate to multi sso? multi sso is available in turbine 26 3 0 when the feature flag is enabled for your account as part of this enhancement, every saml configuration must have an associated idp signing certificate so each identity provider can be independently validated and trusted you cannot enable multi sso while an existing enabled saml configuration is missing an idp signing certificate turbine shows failed to enable multi sso feature flag — the existing saml settings do not have a certificate configured add an identity provider certificate to the saml settings before enabling multi sso under multi sso, idp signing certificates are required , and saml response signature verification is always enforced — there is no option to disable verification for accounts that use the single sso path on sessions & security , open saml settings and paste the idp signing certificate into the certificate text area or use upload certificate , then apply and save that certificate is required beginning in swimlane 26 3 0 for new configurations and for any edit or save of an existing configuration you are not required to enable multi sso; the idp certificate requirement applies to both paths release timeline swimlane 26 3 0 starting with version 26 3 0 existing saml configurations existing saml configurations without an idp signing certificate will continue to authenticate users however, administrators will not be able to edit or save changes to those configurations until a valid idp signing certificate has been uploaded (single sso certificate text area / upload certificate ; multi sso certificate ) new saml configurations all newly created saml configurations must include a valid idp signing certificate before they can be saved this approach allows customers to continue normal authentication while providing time to update existing configurations before making future administrative changes will certificate less saml be deprecated? yes support for saml configurations without idp signing certificates will be phased out over time as swimlane completes the transition to the new security model the 26 3 0 release is the first step in this migration a future release will fully deprecate configurations that do not include an idp signing certificate swimlane will provide advance notice and migration guidance before this occurs what do customers need to do? we recommend completing the following as soon as possible review all existing saml sso configurations identify any configurations that do not have an idp signing certificate obtain the idp signing certificate (public certificate / pem) from your identity provider (such as microsoft entra id, okta, ping identity, google workspace, jumpcloud, or other saml providers) in turbine, open saml settings (single sso) or the sso configuration (multi sso), paste the idp certificate into the certificate text area or use upload certificate (single sso), or use certificate / add certificate (multi sso) then apply / save as required by that screen supported file extensions include txt , cert , crt , and pem see the configure saml authentication section updating your configurations now ensures you can continue to administer your saml settings without interruption and prepares your environment for future multi sso enhancements frequently asked questions which certificate do i need to upload? the idp public signing certificate under identity provider settings (single sso certificate text area / upload certificate ; multi sso certificate ) it is not the sign authnrequest? certificate under general settings will my users be able to continue logging in after upgrading to 26 3 0? yes existing saml configurations without an idp certificate will continue to authenticate users the restriction only applies when an administrator attempts to modify that saml configuration what happens if i create a new saml configuration? new saml configurations require a valid idp signing certificate before they can be saved do i need to migrate immediately? authentication will continue to work for existing configurations, but we strongly recommend uploading the idp certificate before you need to make any changes to your saml settings do i also need a sign authnrequest certificate? no sign authnrequest? remains optional this notice applies only to the required idp signing certificate under identity provider settings does this mean i must use multi sso? no multi sso is an optional capability the idp certificate requirement is part of the underlying security improvements and applies regardless of whether you choose to use multi sso need help? if you need assistance obtaining or uploading your idp signing certificate, contact swimlane support or your customer success representative force sso force sso requires users to sign in through sso instead of a turbine password in turbine 26 3 0, force sso is an account level setting on settings > account settings > sessions & security it is not configured per sso identity provider (including multi sso configurations) to allow specific users to sign in with a password while force sso is enabled open the user under settings > users turn on exempt force sso when creating a user, use the exempt force sso toggle on the create user form when editing an existing user, open the authentication tab and turn on exempt force sso save the user limitations topic supported? notes just in time user provisioning no create users with scim, directory services, or manually before sso username as name id no use email address name id format in your idp multiple idp configurations feature flag supported only when multi sso is enabled; otherwise one saml config per account enabling the flag requires an idp signing certificate on any existing enabled saml configuration single logout (slo) no — encrypted saml assertions no — role assignment via saml no assign roles and groups in turbine after the user exists next steps provision and deprovision users automatically provisioning with scim integration docid\ ucyk5mly9erosd2 nvjpu configure session timeout and password policies sessions and security docid 9r 4c5noilguupeph0pd4 understand login options turbine login and authentication methods docid\ mhla1 pgcebnhsfrjwdzb review authentication fields on a user profile customize your user profile docid\ prwh3nd3y3c7jl5ohbvh1 configure directory services directory services docid\ kygdtejblyxawquk65iza create and manage users users docid\ iuzidcollvgz3x8qj4ywj groups provisioning columns groups docid\ qdacionbffcjiqj6cdn