SAML 2.0 Authentication Using PHP - php

We have a website create in PHP and MySQL where users can register and login. Recently my client gave me some 3rd party service/website which also required users to login to access their services. Now, my client wants that if users is already logged-in to our site and when we redirect user to other/3rd party site it should not ask for the password or login again. When I talked to 3rd party site to provide solution for this, they ask me to implement/use SAML 2.0 SSO option to achieve this feature. Though, I heard about auth0 and SAML but I have no idea from where should I start from.
Do I have to add something on our website? Like auth0 service?
Do I have to ask something from them to implement this? What changes do I need to make ?
What will be the steps involve in this, When we redirect user to 3rd party site it will be auto logged-in or something?

Some confusion here.
Auth0 is an Identity as a Service product, not part of SAML. You've tagged OAuth but that has nothing to do with SAML either. It's a completely different protocol.
What you need is a SAML client-side stack. As you are using PHP, use simpleSAMLphp.
As you are the client, you need to implement the SP mode.
If you were intending to use Auth0, use this sample.
Then use Auth0 to do the SAML connection to the SAML IDP.
So the path is:
PHP application --> Auth0 --> SAML protocol --> SAML IDP
Just to be clear, use either simpleSAMLphp or Auth0.

It seems that your customer want you to be a "Identity Provider", so that when the users are loggued to your website, they will autolog to the other 3rs party customer's website.
Technical Solution : MiniOrange
I recently did this, connecting my PHP/MySQL app to external customer's intranets with "MiniOrange" SAML Solution.
more informations here : https://www.miniorange.com/ and https://idp.miniorange.com/
support : I had many free hours of Skype Support, they are very good, they helped me until it worked !
installating/pricing : I paid for having an onsite licence (they installed this on my server at zero cost), but you can use the Cloud version (start from 10$/month), and they have Wordpress and other CMS plugins...
Answers to your questions :
1) Do I have to add something on our website? Like auth0 service? :
yes, your website must be a identity provider...
2) Do I have to ask something from them to implement this? What changes do I need to make ?
Yes, they have to install and configure a "Service Provider" connector, that will automatically connect to the Identity Provider (your website) with JSON Web Tokens (JWT) for example, check if the user is already connected to your website (if yes, your website return a token, and then the user autologs to the 3rd party website, if not, he's redirected to the SAML login form for instance)...all this process will be invisible for the user.
3) What will be the steps involve in this, When we redirect user to 3rd party site it will be auto logged-in or something?
The process will be like this :
the user goes to the 3rd party site
the "service provider" connector installed in this 3rd party site checks if the user is connected to this 3rd party site.
If yes, nothing to do, the user is already connected.
If not connected, then the user is redirected to your website's login form.
The user types his login/password, then is redirected to the 3rd party website.
the 3rd party website (in which the user isn't yet loggued) ask to his "service provider" module to call the "Identity Provider" (ie your website) with JWT Json Web Tokens for example (the communication between the IDP identity provider and the SP Service Provider is invisible for the user in the browser, but if you install "SAML DevTools extension" Chrome extension, you'll see the tokens exchanged between the Identity Provider and the Service Provider)
As you are connected to your website (being the "identity provider"), then the Identity Provider returns a SAML Response token, that allows the user to automatically connect to the 3rd party website...And that's done, the user is auto-loggued !

Related

Login into php website and automatically get logged in into Drupal website running on different server?

My comapny has a web portal written in php and mysql and there is another website running in Drupal-7 so they want me to integreate SSO i:e; once someone login into portal he/she should be automatically logged into drupal website by clicking the website link(drupal website) from the portal. is there any way to do it?
Note: I don't have any idea about Drupal system.
If you have a the code that handles the user login post it here.
Basically you need to act on user login somewhere in the code, and make a curl request to the drupal site api to login there too.
A good starting point is to learn about the Services module.
Also read Making authenticated requests to REST Server
Best way to make Drupal 7 Users table common for both the sites.
For this you need to do migration of users as well as change the code in PHP site at registration and login to use Drupal 7 Rest API to get login and resister into the portal.
SimpleSAMLphp (SSP) is a very good solution for you to look at. It provides a SAML 2.0 service provider (SP) and identity provider (IdP) in one package.
You would need to set up SSP as an Identity Provider first, for which you could use a simple MySQL database for the users. Then, you can connect both the portal, and Drupal with the Identity Provider via SAML integration, where here the portal and the Drupal site will be "service providers".
If you install SSP on the site with the portal, I don't think that it can function as both the IdP and SP, fair warning. You would need to either use an alternative SAML service provider (like Shibboleth), or better yet, second instance of under a different hostname. (Otherwise the cookies will conflict.) You will also need to integrate Drupal, which could be easily done with a module.
If you wanted to go the other way, where to Drupal site's user's table is used as an authentication source, that's doable as well using SimpleSAMLphp along with drupalauth4ssp Drupal module in conjunction with the drupalauth SSP module.

Steps to implement SSO for php application

I am a newbie in SSO implementation. We are looking at implementing SSO for a client that uses a php application (supported by us), for their employees to login to the application. We are in the process of setting up Simple SAML for this .. I have been reading articles on SSO, many of which are helpful. Pardon me for asking this, I know it is dumb. In this scenario, who is the IDP and who will be the service provider. The client apparently uses SSO for other applications as well. Can someone throw some light on what all I need to setup from our end.. I will research on how to do each of them..could someone please help by mentioning the things that need to be implemented.
who is the IDP and who will be the service provider.
IDP (Identity Provider) is the one who creates, stores, maintains and authenticates the identity of the user or principal in saml terms. So in your case it is the clients application.
SP (Service Provider) is the one who provides the service or resource to a user (authenticated by IDP) so in your case it is your application.
could someone please help by mentioning the things that need to be implemented.
As you can see in the above diagram when user will try to access a resource on your site you will have to redirect them to IDP to confirm whether this user is authenticated and if you should return them the resource/response they are looking for. The SSO url and other details are exchanged between IDP and SP through Metadata.
Once IDP has authenticated the user it will POST a response on your application url. This response contains an assertion through which you will know user details and whether user is authenticated or not. You will have to parse this response (xml). Also, these assertions are generally signed with certificate and are encoded base 64.
You will also have to think about SLO so when a user clicks on logout in your site you might have to clear their session from your application and redirect them to the IDP so they get logged out from there as well.
As suggested by smartin you can use some library which will make it easier to implement SAML. I am also learning about SAML as we are working on converting our current application into IDP :)
I found this SAML official documentation and some of the diagrams very helpful. http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0-cd-02.html
Your app is the SP, and the customer will provide to you the IdP metadata to register on your SP.
In order to add SAML support to a PHP application, you have 2 alternatives:
simpleSAMLphp
php-saml
LightSAML
All of them are well documented, you will need to spend some time reading/learning.

Central login with SAML and making site to work as identity provider

So my scenario goes like :
I have two sites a.com and site b.com and one authentication server cauth.com.
what client wants is ...
When user lands on a.com or b.com user fills in the login form on respective site , but the action of form will be on cauth.com (cauth.com/authenticate). when user is authenticated on cauth he is loggined on the both sites.
I am thinking to implement SAML to achieve the same and flow is like
after authentication iDP(cauth.com) will send SAML response to the both the service providers and user will be given access to both the sites .
I am novice in SAML and unable to get proper documentation and comprehension for the same.
What I want to know is :
Is my solution to the problem worth implementation ?
Is it possible to make site (cauth.com) as identity provider.I have looked at thread Making your PHP website into SAML Identity Provider but not able to get proper solution.
SimpleSamlPHP should be pretty easy to set up. You'll want to make a copy of the folder modules/exampleauth/ and then alter the file modules/<yournewmodule>/lib/Auth/Source/External.php to work for your site. The documentation is good though and it's definitely the easiest thing for your need, and the right one.
I should add that following the instructions to set up SimpleSamlPHP should give you a basic understanding of which metadata files are most important and where they live and how things interact.
I am not sure which technology you are using for your application. If you are free to switch to JAVA then I can suggest you Spring-Saml because its very easy to implement and fulfill your requirement. Spring-Saml has good documentation and online support as well being it as open-source project.
You can refer this link for Spring-saml and for code-repo use this link
You can integrate spring-saml in your abc.com and xyz.com application to make it Service provider(SP) and you can deploy it on different domain as well. Then you need to have one IDP (identity provider server) for your SPs. So you can use either ADFS with Active directory or LDAP to act as IDP.
We had similar requirement for our customer. I recently integrated spring-saml in my project.
Please let me know for any help
A federated Single Sign On (SSO) mechanism like SAML or OpenID Connect will give you what you want.
This comes with the important distinction that the login form would not be presented on a.com or b.com but those sites would rather redirect to cauth.com and the user would authenticate there. cauth.com would then send a verifiable "assertion" to a.com and b.com that the user has authenticated successfully. This constitutes one of the major goals of federated SSO, namely that the user credentials should not be presented/stored-by foreign websites and makes the means of authentication independent from the target websites ("Relying Parties").
So what you should be looking for is a suitable implementation of SAML or OpenID Connect for your platform (don't write it yourself!) and leverage that.
Shibboleth is open source and one of the most popular SSO solutions. It includes a SAML Identity Provider which you can download here: https://shibboleth.net/downloads/identity-provider/latest/ .
If your client is willing, one approach would be to use a cloud SSO provider like Okta which has a developer program and could make things easier.
I think there is a subtle misunderstanding in your description. For SAML authentication, if a user at site a.com either clicks a login link/button or tries to access a secure page, that user will receive an http 305 redirect to cauth.com. There the user will enter their credentials, and the user will be redirected back to a.com. If that user then goes to site b.com and tries to access secure content, b.com sends the user to cauth.com with the same http 305 redirect. This time, as there is an active session for the user's browser at cauth.com, the user does NOT see the credential form. Instead, the IDP returns the user with a successful authentication to b.com. It appears to the user that they are automatically logged on to site b, but in truth a SAML authentication flow has occurred.
Hans Z's answer elides the fact the that IDP only sends the assertions on the request of a or b (the Relying parties or RPs, also known as Service Providers or SPs). It is not a broadcast to all RPs.
I'll reinforce that SAML does NOT support a.com receiving the credentials from the user and then passing them to the authentication engine. This is a pattern one may be familiar with from LDAP.
Take a look at the sequence diagram in the wikipedia entry on SAML.
Follow below instruction to get SAML implimentation with PHP.
SAML login setup is very easy in php.
First register on onelogin server
https://www.onelogin.com/signup and create demo app on it. After
it follow all instruction to set Idp (Identity provider setting ) and
sp (service provider setting) to settings.php
https://developers.onelogin.com/saml/php
It worked perfect for me with CI and and php

PHP SAML IdP First

I'm trying to make a Client portal (IdP) in PHP.
That portal links to several SP's (like Magento, Google Analytics and Wordpress)
Seeing how this needs to works my IdP needs to initiate authentication. when clicked on a link to an SP the authentication needs to start.
So it needs an IdP first application. I try to set it up with SimpleSAML, the only problem is the initial explanation on the simpleSAML website isn't clear enough for me (https://simplesamlphp.org/docs/stable/simplesamlphp-idp) can someone give me some better or in depth explanation about IdP first?
this is a new client portal but the clients already have accounts with the mentioned sites and other sites, sometimes more than 1 account. Is it possible to connect those accounts without doing it myself but let the clients connect them?
If there are better solutions than SAML to this problem please don't hesitate to mention them
4.5 IdP initiated login
If you use a simpleSAMLphp IdP, and you want users to be able to bookmark the login page, you need to test IdP initiated login. To test IdP initiated login from a simpleSAMLphp IdP, you can access:
https://.../simplesaml/saml2/idp/SSOService.php?spentityid=<entity ID of your SP>&RelayState=<URL the user should be sent to after login>
Note that the RelayState parameter is only supported if the IdP runs version 1.5 of simpleSAMLphp. If it isn't supported by the IdP, you need to configure the RelayStateoption in the authentication source configuration.
As for account linking, it's my understanding that simple doesn't do this (it's getting out of the simple realm). To use it, you'll have to clean up accounts.
[edit]Actually, I suppose you could - though you'd have to build a structure to do it. You would need to somehow build a mapping of accounts from the corporate ID to the SP accounts at Wordpress, Google, etc.

Can a webservice written in Symfony2 regognize if the user who is calling the webservice is logged in?

I have a B2C application coded in Symfony2. Users arrives on my homepage and then signup. Once signup, my application authenticate this user, using the Authentication of Symfony 2. The authentication is persistent, so after the signup the user will be loggedin "forever".
But my users can interact with my application not only directly under my domain: there are websites, partners of my application, that allows their users to interact with my application. During this, the user remains inside the pages of the third party website.
In order to make this possible I've created, in Symfony, a set of API that allows third party websites to interact with my application. The API calls are made by Jquery.
Here comes my question: would my Symfony Controller who replies to API Calls, be able to recognize if the user who is on the third party website which is doing the API call is loggedin on my application or not?
I tried to check this:
if($this->get('security.context')->isGranted('ROLE_USER')){
But it always replies me with false.
If the API Call would have been made by PHP, I know it would be impossible. But it is made in JavaScript, so from the client (the user). That's why I think I would be able to recognize if the client who is calling my API from a third party website, is already loggedin on my application.
Thanks
I think you are looking for a SSO Solution. I've just implemented SSO in one of my projects using SamlSPBundle and SimpleSamlPhp. You would have to setup SimpleSamlPhp as an Identity Provider and all the participating Websites who want to use SSO as Service providers.

Categories