SAML for IQ Server - Sonatype Lifecycle & Repository Firewall - Sonatype Community

SAML for IQ Server

post by jwhitehouse on Sep 3, 2019

SAML support is coming to IQ Server, stay tuned.

post by hugh.byrne on Oct 11, 2019

Release 74 (September 2019)

IQ Server can now be configured to enable single sign-on via SAML during login…

Documentation on SAML integration

post by dwong on Oct 25, 2019

I’m getting this XML validation error when using Azure AD as the IdP -

Identity provider metadata could not be validated: Invalid SAML metadata: cvc-elt.4.2: Cannot resolve ‘fed:SecurityTokenServiceType’ to a type definition for element ‘RoleDescriptor’.

post by jwhitehouse on Oct 25, 2019

Damian, please file a support ticket and we’ll review through that channel.

post by brentbandelgar on Nov 11, 2019

I’m also interested in using IQ Server SAML against Azure AD as an IdP. Perhaps a dedicated Azure AD walkthrough article for SAML is needed.

post by austin on Feb 3, 2020

Hello @jwhitehouse, I started a new thread here:

Essentially, I can work around the IQ error (and another) above by removing two fields in the Azure XML file. However, this causes a problem with the token stored in cookies.

I’m still unable to get the Azure SSO to work though because I can’t get the Reply URL (Assertion Consumer Service URL) setting in Azure correct before generating the XML file. Can you provide any advice? I’ve attached a screen capture of the fields in Azure I need.

post by clankow on Mar 19, 2020

It would be a great feature if we had the option to allow SAML users to derive their role memberships from LDAP groups that are associated with e roles. I will need to abandon SAML for now until this becomes an option. Our authorization infrastructure uses AD LDAP.

post by jwhitehouse on Mar 23, 2020

Christopher, can you use AD LDAP directly? What’s the need for both LDAP and SAML?

post by clankow on Mar 23, 2020

The benefit of SAML is that we have corporately enabled desktop SSO using SAML. SAML would enable our users to authenticate from Windows sessions rather than entering their password again.

post by lubomir.pipiska on Jun 10, 2020

It would be greatly appreciated if we can provision access to SAML groups using UI and do not have to do it via API.

post by jmcpherson on Jan 27, 2021

I was able to correctly configure SAML for use with Azure AD. What I haven’t figured out is how to use claims in the SAML to identify who should have membership to the different roles in IQ Server (specifically Administrator). Does anyone know how to do this?

post by austin on Jan 28, 2021

Hello @jmcpherson - when I was attempting the SAML setup, I was able to get the claims set up to match up to the IQ server groups. Tried to find something explicit in my old notes, but nothing for Nexus. However, this unrelated page may have some useful information to get you started.

post by jmcpherson on Jan 28, 2021

@austin Thanks! That worked great. Have you been able to assign a role in Azure that maps to System Administrator? I would prefer to keep the number of local accounts to a minimum, and we have a policy against sharing passwords.

post by austin on Jan 29, 2021

@jmcpherson at first glance, it seems you should be able to map system administrator like you can the other roles, like owner, developer, application evaluator, etc. That said, I think I remember someone having trouble mapping to the admin role. I don’t know what they tried, though. I can’t remember if I mapped to admin or not.

post by jmcpherson on Jan 29, 2021

@austin The issue I ran into was that Azure AD doesn’t allow spaces in the role names. I can map all of the other roles successfully. However, any role other than System Administrator does not have access at the root level.

post by austin on Jan 29, 2021

@jmcpherson Can you create your own administrator role in IQ (no space in name) and assign it the administrator permissions, then map that in Azure?

post by jmcpherson on Jan 29, 2021

@austin No, unfortunately custom roles aren’t allowed the right degree of access, and only roles with spaces in them have the level of access I would like to delegate to SAML groups.

post by austin on Jan 29, 2021

@jmcpherson Ah, I see. Too bad there’s not a configuration file that IQ pulls the names from, but they seem to be in the .jar file. I wonder if %20 would work instead of space, so system%20administrator in the Azure config. Seems a long shot. I do remember having this issue when I configured Azure SAML for a different application. Fortunately, I’ve been able to ignore those roles so far.

post by jeremy-chua on Jun 9, 2021

I’m able to integrate with Azure AD with some limitations.

1.) The Group ID claim returns the ID and not the name of the group. This is a known limitation of Azure AD. It will be good to have a configuration for translation of the group ID claim to a group name in Nexus IQ server.

2.) Since (1) is not working, I would like to use local users to map SAML users. The username returned from SAML is in email format. However, email format is not supported for local user usernames. It is very common to use email addresses as usernames.

Thanks & regards,

Jeremy