Configure: Secure Access with Shibboleth IdP authentication
Virtu Authentication
Configure: Secure Access with Shibboleth IdP authentication
Virtu Authentication
In this article is described instructions for configuring Secure Access component to be able to authenticate Customers end-users to Matrix42 Pro and IGA solutions by using SAML2 and Shibboleth. This process involves authenticating users via cookies and SAML.

How to Configure Authentication for Shibboleth IdP?
Step-By-Step instructions
Prerequisites
- Install Shibboleth root ca certificate to Secure Access. Contact Matrix42 for certificate installation.
Step-by-step instructions for Secure Access configuration
- Login with Secure Access Admin user (main.admin) to URL e.g. https://domain.com/auth/admin
- Open Identity Provider settings from the left side panel and choose
Add provider, typeSAML v2.0
- Set information for new SAML provider
Set alias, displayname and display order (where to show button on login screen)
SetSAML entity descriptorurl you got from Shibboleth environment

ClickShow metadatato validate metadata was correctly fetched from Shibboleth
- Click
Addto save Identity provider



5. Click Save
6. After above configuration is done, a new login button appears on the Secure Access login page
7. Copy and send Redirect URI to Shibboleth admin (they need that on Shibboleth side configurations)

8. Add mappers to Identity Provider
Open Identity provider and go to Mappers tab
Add at least username_mapper, email_mapper, firstname_mapper and lastname_mapper. You need to add also groups_mapper if you want to us Shibboleth groups for Matrix42 Pro and IGA permissions. Mappers attribute names and name formats might not be same as in example screenshots, that depends how Shibboleth is configured to send claims (consult Shibboleth admin for correct values for mappers).
Username mapper

email mapper

firstname mapper

lastname mapper

groups mapper

9. Finalize Shibboleth side configurations
10. Test login and logout use cases
Customer Instructions
We do not provide customer instructions for Shibboleth side configurations as Shibboleth can be configured multiple different ways, depending on environment needs.
Table of Contents