02-27-2020 07:46 PM - edited 03-01-2020 07:10 AM
Hi All,
Could someone share the sample configuration template for integration of saml2.0 with asafw
and what certificates are reqd and how to install ?
We're using authentication via LDAP as of now and looking forward to integrate with P'fed'te.
Would like to know whether to select SP initiated or Idp Initiated SSO ?
We're using anyconnectvpn at the moment.
regards
SecIT
03-01-2020 08:31 AM
Hi,
The mode depends on the traffic flow you want, in the end you can have one or both:if the user authenticates agains the IdP, you configure IdP on the ASA, if the user authenticates against the ASA, you configure SP on the ASA. In both cases, you need to import the certificate chain of the IdP on the ASA. If you do it from ASDM, it's pretty intuitive, if you do it form CLI, here's the guideline:
Regards,
Cristian Matei.
03-01-2020 07:30 PM - edited 03-01-2020 07:42 PM
Thanks a lot Cristian.
Would you please give me ASDM procedure.
The user shall be authenticates against Idp.
Whether to import the Idp certificate under Device Mgmt>CA certificate ?
or
Configuration -> Remote Access VPN -> Certificate Management -> Identity certificates ?
03-04-2020 01:21 AM
Hi,
Here's your configuration via ASDM:
As for where to import the certificate, it doesn't matter, just configure a regular trustpoint.
Regards,
Cristian Matei.
03-04-2020 08:40 PM
Thank you Cristian, I shall test and get back to you.
03-04-2020 12:31 AM
Could someone please advise..
03-16-2020 11:44 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide