Manage federations
To perform any actions with your user federation:
-
Go to the console.
-
In the upper-left corner of the page, click your organization name → Manage organizations.
-
Select Members from the panel on the left, open the Federations tab and click the name of the federation you want to manage.
Edit a federation
To edit a federation:
-
In the upper-right corner of your federation's information page, click Edit.
-
On the Edit Federation page:
-
Specify the Name of your federation.
-
Specify the Cookie lifetime in minutes.
DoubleCloud federations support cookie lifetime from
10
to720
minutes (12 hours). -
Specify the IdP issuer.
-
From the dropdown menu, select the SSO method:
-
POST
- send your token from the SSO server using the HTTP POST -
REDIRECT
- send your token from the SSO server using an HTTP redirect
-
-
Provide a link to the IdP login page.
-
Under Advanced:
-
Select the state of the Automatically create users checkbox:
Enabled
Users will be added to the federation automatically at the first SSO login. They'll also automatically become members of the organization to which their federation belongs.
Disabled
Users need to be invited to the federation individually.
-
Choose the state of the Sign authentication requests checkbox:
Enabled
Enable the SAML
Disabled
Disable the SAML Request signature verification.
-
Select the state of the Case-insensitive user names checkbox:
Enabled
NewUser@company.com
,newuser@company.com
, andnewuser@Company.com
are the same user.Disabled
NewUser@company.com
,newuser@company.com
, andnewuser@Company.com
are different users.
-
-
-
Click Submit.
Add a certificate
When the identity provider (IdP) confirms to the DoubleCloud service that a user has been authenticated, they sign the message with their certificate. To enable your organization to verify this certificate, add it to your federation:
-
On your federation's information page, under Certificates, click Add certificate.
-
In the File upload dialog:
-
Specify a Name for your IdP certificate.
-
Select an upload Method:
UploadText-
Click Choose a file.
-
Find your
.pem
certificate and click Open.
-
Open your
.pem
certificate in a text editor. -
Copy all the text from the opened file and paste it into the Content field.
- Click Submit.
-
Delete a certificate
To delete a certificate:
-
To the right of the certificate's name, click
-
In the dialog window, confirm deletion and click Delete.
Delete a federation
To delete a federation:
-
In the upper-right corner of your federation's information page, click Delete.
-
In the dialog window, confirm deletion and click Delete.