SAML SP installation - SSO
Requirements
System Requirements
- Java 2 Platform Standard Edition Runtime Environment 6, 7 or 85.0
- Java Servlet 2.33.0, 2.4 or 2.53.1 compliant application server
- System time synchronized with the time of the IDP
- Ubisecure Server 4.1.3 or Ubisecure ServerGlobalSign SSO 5.x, 6.x, 7.x
Unpacking the software
Required Files
- ubispservlet-<version>.zip
The Service Provider software package
Extract the contents of the package into a folder of your choice.
Package contents
- ubispservlet/doc/api/index.html
Java API documentation in HTML format - ubispservlet/webapp/
- ubispservlet/webapp/WEB-INF/web.xml
A deployment descriptor example with SAML SP integration entries. - ubispservlet/webapp/WEB-INF/lib/.jar*
SAML SP binary libraries to be copied to the WEB-INF/lib directory of the web application.
Things to Consider About Your Environment
There are a number of environment specific issues that might affect configuration and installation of the SAML SP.
- Is the server clock synchronized automatically?
The SAML assertions have a very strict time window of validity and there can be virtually no time skew between the IDP and the SAML SP. Using automatic time synchronization is a requirement. - Does the server network use HTTP proxies?
HTTP proxies affect how Java services (such as the configuration tool) can access external network resources, the way browser IP addresses are seen by application servers and so on. Contact your local network administrator to check how HTTP proxies affect your environment. - Do the IDP and your application server see the same client browser IP address?
The default configuration of the SAML SP expects that both IDP and the SAML SP see the same client browser IP address. This would not be the case if for an example the SAML SP is installed behind a NAT, while the IDP is in public internet. See Network address tolerance to change the way client IP addresses are checked.