Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How do we block Nosso logins for Saml SingleSignOn?

Syed Ehteshamuddin
March 27, 2018

Is there a way to block Nosso logins for SAML Single Sign-On? I want users always use SSO login to get in confluence but just should be able to access when there is an emergency like AD failure etc..

1 answer

1 accepted

0 votes
Answer accepted
AnnWorley
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 27, 2018

Hi Syed,

If you are using SAML Single Sign On (SSO) for Confluence then this documentation has instructions for disabling the nosso URL: Step 5: Enable login redirection  

The way I read the document, it looks like you would have no way to log in when AD fails if you disable login redirection. Please consider using a proxy, firewall or other network mechanism to block the URL: https://<your-confluence>/login.action?nosso It seems like it would be easier to do that than disable the plugin in the database or otherwise workaround SAML SSO to access Confluence in the event that Confluence somehow can't reach AD.

Thanks,

Ann

Syed Ehteshamuddin
March 27, 2018

Thank you @AnnWorley will try to block it on firewall level.

Christian Reichert (resolution)
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
March 29, 2018

Hi @Syed Ehteshamuddin,

I work for resolution, the company developing the plugin you are using.

Currently there is no way to block the ?nosso from the plugin itself. A couple of customers have requested to be able to globally disable the ?nosso feature. We accepted this as a feature request and it has been selected for development for the next version 2.1.0 which should come out over the next 3 weeks.

However to be explicit once you disables the ?nosso the only Way to get to the old login prompt & login during a failure (i.e. Your ADFS down) is to restart Confluence in safe-mode or to disable the redirection via a REST call and a local admin User.

Thanks @AnnWorley for your collaboration ...


Cheers,
    Christian  

An Dinh
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 12, 2019

I can see 'Enable nosso' checkbox now.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events