Flumotion Smart Multi CDN supports identity providers that use the Security Assertion Markup Language (SAML) protocol.
You can configure your identity provider to enable Single Sign-On (SSO) access to your account.
Configuring SSO #
To configure SSO for your account:
- Navigate to the Account page.
- In the sidebar, select Single Sign-On.
- Copy the provided SSO configuration fields and add them to your identity provider.
- Configure your identity provider. Once completed, download the metadata XML file generated by your identity provider and upload it to the Single Sign-On page.
- Click Enable SSO.
Force SSO #
You can enforce SSO authentication for your account by enabling Force SSO.
Once enabled, users in your account will no longer be able to log in using a username and password and will be required to use SSO.
Important: Make sure to successfully test your SSO access before enabling Force SSO. If SSO is configured incorrectly, you may be locked out of your account without the ability to log in using a username and password.
Configuring SSO in Okta #
If you are using Okta as your identity provider, follow these steps as part of step 4 above:
- Log in to your Okta account as an administrator.
- In the sidebar, select Applications.
- Click Create App Integration.
- Select SAML 2.0 and click Next.
- Enter the App name and click Next.
- In the Single sign-on URL field, paste the value copied from the Assertion Consumer Service URI field on the Flumotion Smart Multi CDN SSO page.
- In the Audience URI field, paste the value copied from the Audience URI field on the Flumotion Smart Multi CDN SSO page.
- Under Name ID format, select EmailAddress.
- Under Application username, select Email.
- Click Next, and then click Finish.
- Once the application is created, access the Metadata URL and save the XML file. Upload the XML file to your Flumotion Smart Multi CDN account as described in step 4 above.
- You can now assign users to the application.
Configuring SSO in Microsoft Entra ID #
If you are using Microsoft Entra ID as your identity provider, follow these steps as part of step 4 above:
- Log in to your Azure account as an administrator. Navigate to Microsoft Entra ID and select Enterprise applications. Click New application, then select Create your own application. Enter an application name, for example, Flumotion Smart Multi CDN, and select Integrate any other application you don’t find in the gallery (Non-gallery). In the newly created application, go to Manage and select Single sign-on. Select SAML as the SSO method. Complete the Basic SAML Configuration:
- Identifier (Entity ID) – Paste the value copied from the Audience URI field on the Flumotion Smart Multi CDN SSO page.
- Reply URL (Assertion Consumer Service URL) – Paste the value copied from the Assertion Consumer Service URI field on the Flumotion Smart Multi CDN SSO page.
- Click Save.
- Under Attributes & Claims, check the Required claim and ensure the following settings are configured:
- Name identifier format – Email address
- Source attribute –
user.mail - Under SAML Certificate, download the Federation Metadata XML. Upload the XML file to your Flumotion Smart Multi CDN account as described in step 4 above. You can now assign users to the application:
- Under the application Properties, make sure the application is visible to users.
- Under Users and groups, assign the appropriate users or groups to the application.
- Users can then log in through Microsoft My Apps. It may take a few minutes for the new application to appear.
Configuring SSO in OneLogin #
If you are using OneLogin as your identity provider, follow these steps as part of step 4 above:
- Log in to your OneLogin account as an administrator.
- In the top navigation bar, select Applications and click Add App.
- In the search box, enter SAML Custom Connector (Advanced) and select the appropriate application.
- In the display name field, enter Flumotion Smart Multi CDN and click Save.
- In the sidebar, select Configuration and complete the following fields:
- Audience (Entity ID) – Paste the value copied from the Audience URI field on the Flumotion Smart Multi CDN SSO page.
- Recipient – Paste the value copied from the Assertion Consumer Service URI field on the Flumotion Smart Multi CDN SSO page.
- ACS (Consumer) URL Validator – Paste the value copied from the Assertion Consumer Service URI field on the Flumotion Smart Multi CDN SSO page.
- ACS (Consumer) URL – Paste the value copied from the Assertion Consumer Service URI field on the Flumotion Smart Multi CDN SSO page.
- Login URL – Paste the value copied from the Assertion Consumer Service URI field on the Flumotion Smart Multi CDN SSO page.
6. In the top-right corner, click More Actions and select SAML Metadata to download the XML metadata file.
7. Upload the XML file to your Flumotion Smart Multi CDN account as described in step 4 above.
8. You can now assign users to the application.