Is there a way to block Nosso logins for SAML Single Sign-On? I want users always use SSO login to get in confluence but just should be able to access when there is an emergency like AD failure etc..
Hi Syed,
If you are using SAML Single Sign On (SSO) for Confluence then this documentation has instructions for disabling the nosso URL: Step 5: Enable login redirection
The way I read the document, it looks like you would have no way to log in when AD fails if you disable login redirection. Please consider using a proxy, firewall or other network mechanism to block the URL: https://<your-confluence>/login.action?nosso It seems like it would be easier to do that than disable the plugin in the database or otherwise workaround SAML SSO to access Confluence in the event that Confluence somehow can't reach AD.
Thanks,
Ann
Thank you @AnnWorley will try to block it on firewall level.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I work for resolution, the company developing the plugin you are using.
Currently there is no way to block the ?nosso from the plugin itself. A couple of customers have requested to be able to globally disable the ?nosso feature. We accepted this as a feature request and it has been selected for development for the next version 2.1.0 which should come out over the next 3 weeks.
However to be explicit once you disables the ?nosso the only Way to get to the old login prompt & login during a failure (i.e. Your ADFS down) is to restart Confluence in safe-mode or to disable the redirection via a REST call and a local admin User.
Thanks @AnnWorley for your collaboration ...
Cheers,
Christian
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I can see 'Enable nosso' checkbox now.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.