Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,644,485
Community Members
 
Community Events
196
Community Groups

How to generate XML metadata file for SAML SSO 2.0 configuration ?

Trying to implement SAML SSO 2.0 on Jira DC 8.5 / Confluence DC 7.4, my IDP asks me for a XML metadata file that contains a X509 certificate used to decrypt or confirm the signing, they can't register Jira/Confluence in their tool without this metadata file.

The only information I have for them are the 2 URLs "Assertion Consumer Service URL" and "Audience URL (Entity ID)" shown in SSO 2.0 configuration panel.

How do I generate such a metadata file ?

1 answer

1 vote
Christian Reichert _resolution_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Sep 24, 2020

Hi Eddy,

 

this Question is slightly word in the Atlassian Access area (since that is a Cloud Service).

However, going to your Question about metadata on SAML for DC - the SAML that Atlassian Datacenter supports out of the box does not generate any metadata. 
So you would have to do this setup manually on your IdP and not via metadata

Just for reference here are the Atlassian Docs about configuring SAML: https://confluence.atlassian.com/enterprise/saml-single-sign-on-for-atlassian-data-center-applications-857050705.html

However to my knowledge Authentication request, signing/encryption is also not supported by Atlassian. So if this is a requirement, then you can't use the basic SAML integration form DC.

In that case (or if you need a setup via metadata), you'll have to consider a 3rd Party Plugin like ours: https://marketplace.atlassian.com/search?query=saml%20resolution%20gmbh 
Our plugins are the most installed & best rated one's in the Atlassian Marketplace - beside many other additional features we also fully support:

- Setup via metadata (both ways)
- Signed authentication requests.
- Encrypted authentication requests.

If that's a consideration then let me know which Identity Provider you are trying to integrate with - for many we do have step-by-step guide on our documentation (https://wiki.resolution.de/doc/saml-sso/latest/jira/setup-guides-for-saml-sso). Or you just book a free Screenshare with us & we help you do the setup via https://resolution.de/go/calendly

Cheers,
Chris

P.S. Full disclosure, I work for resolution, a marketplace vendor.

Thanks Chris for your answer.

Finally, my IDP accepted my homemade xml metadata file (built with an online tool available at https://www.samltool.com/sp_metadata.php), just containing both URLs provided by Jira, the X509 certificate was optional.

So no need for an additional plugin on my side, sorry for your company and good news for mine :)

Regards 

Like # people like this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events