Single Sign-on
You are viewing documentation for a legacy Rasa product. If you want to get started building assistants with Rasa please check out our latest documentation here.
Configuring SAML SSO for Rasa Enterprise
Rasa Enterprise acts as a service provider (SP) which initiates the SSO request to an external SAML authority, called the identity provider (IdP). This section describes how to configure the Rasa Enterprise SAML SP to work with your enterprise IdP.
Rasa Enterprise mounts SAML certificates, keys and a settings file from your project directory. Create a directory for the authentication information and a directory for storing the configuration file with
cd ${RASA_HOME} mkdir -pv auth/certs mkdir -pv auth/samlThe Rasa Enterprise SAML SP requires a X.509 certificate to sign the authentication request. You’ll need to create a certificate and the corresponding private key in
${RASA_HOME}/auth/certs. To do this, run:cd ${RASA_HOME}/auth/certs openssl req -new -x509 -days 3652 -nodes -out sp.crt -keyout saml.keyThe SAML SP has to be configured using a
jsonfile. Create a file calledsettings.jsonin${RASA_HOME}/auth/samlwith the following content:{ "strict": true, "debug": true, "sp": { "entityId": "http://<RASA_ENT_HOST>/api/auth/saml/metadata", "assertionConsumerService": { "url": "http://<RASA_ENT_HOST>/api/auth/saml/acs", "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" }, "NameIDFormat": "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" }, "idp": { "entityId": "<ENTITY_ID>", "singleSignOnService": { "url": "<SSO_URL>", "binding": "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" }, "x509cert": "<X509_CERT>" } }
Replace the following placeholder variables with values specific to your SAML IdP:
RASA_ENT_HOST: The host endpoint that the IdP (provider) will use to connect to Rasa Enterprise.ENTITY_ID: Identifier of the IdP identity.SSO_URL: Target URL to which the SSO requests are sent.X509_CERT: Public X.509 certificate of the IdP.
- Re-start Rasa Enterprise so that it will read the updated
settings.json.
Once the rasa-x service has been (re-)started after modifying the SAML settings, you can retrieve the SAML endpoint metadata by issuing this GET command:
curl http://<Rasa Enterprise server host>/api/auth/saml/metadata
You can specify additional details about your IdP in settings.json, as well as in an additional file called advanced_settings.json. Have a look at onelogin’s documentation on python3-saml for more details.