Configuring single sign-on
You can use Security Assertion Markup Language (SAML) for single sign-on (SSO) to the IBM® Software Hub web client.
- Configuring single sign-on using SAML
- Configuring single sign-on using OpenID Connect
For information about which version of IBM Cloud Pak foundational services is installed on your cluster, see Operator and operand versions.
- Who needs to complete this task?
- To complete this task, you must have one of the following roles:
- Cluster administrator
- Instance administrator
- When do you need to complete this task?
- Complete this task if you want to use SAML for SSO to the web client.
It is strongly recommended that you complete this task before you add users to IBM Software Hub. If you add users to IBM Software Hub before you configure SSO, you must re-add the users with their SAML ID to enable them to use SSO.
Before you begin
Ensure that you source the environment variables before you run the commands in this task.
You must have an existing SAML SSO identity provider (IdP).
Work with your IdP administrator to review this task and gather the information required to connect to your IdP.
Procedure
What to do next
Wait for the usermgmt pods to restart before you attempt to log in to the web
client. If the pods are not running, you will not be able to log in.
- Go directly to the web client log in page by appending the following path to your IBM Software
Hub URL:
/auth/login/zen-login.html. - Log in to the web client as an administrator with the Manage users permission.
- Add users with their SAML IDs. For details, see Managing users.
Disabling SAML
Procedure
To disable SAML: