SSO Legacy
    • 04 Dec 2023
    • PDF

    SSO Legacy

    • PDF

    Article Summary

    Use of SSO Legacy is discouraged. Wasabi is no longer provisioning new customers on SSO Legacy.

    As part of the SSO Legacy configuration instructions, you will:

    • Install and configure an Identity Provider (IDP) of a third-party application (such as configure Okta, Auth0, or Shibboleth).
    • Configure SSO Legacy by continuing with the instructions below.

    Configuring SSO Legacy

    1. Click Settings on the Wasabi menu. Or, open the account sign-in drop-down and click Settings.
    2. Open the SSO (Single Sign On) drop-down.
      This option is available only if you have SSO Legacy enabled through Wasabi Customer Support, as noted above.
    3. Click CONFIGURE SSO.

      By default, SSO is disabled for existing and newly created Wasabi accounts. You will see this option only if it is available for your account.

      If you have already configured SSO, refer to Modifying the SSO Configuration to configure a new provider or modify an existing provider.

    4. Click CREATE NEW PROVIDER. (Or, click BACK TO CONSOLE to return to the ACCOUNT SETTINGS panel.)

    5. A panel is displayed on which you can add an authorized provider. Enter a name for the provider. It is best to use a name that will be easily recognized by the users.

    6. Select one of these protocols:
      • SAML2
      • OpenID Connect (OIDC)
    7. Enter the metadata URL that was provided during IDP configuration. For example, enter the URL indicated when configuring SAML2 with Okta.
    8. Optionally, enter an entity ID. For example, a SML2-based IDP can declare more than one “entity” in the meta-data XML (multiple IDP providers each with separate public keys, etc.).
    9. Optionally, enter a Wasabi role prefix. The SSO feature uses this prefix to map to Wasabi roles. By default, the prefix is assumed to be “wasabi-” if you do not enter a different prefix. When Wasabi receives a group/role name from the IDP that starts with this prefix, Wasabi looks for a role with the same name in the Wasabi account. For more information about Wasabi roles, refer to Roles.
    10. Click CREATE. The SSO Provider List is displayed.

      This list shows the serial number, name, ID (which will be used on the enterprise login), and protocol type for each provider.

      If you want to add a provider, click  and return to the instructions above.

      You can click the toggle to enable or disable the provider status.
      When the provider is enabled, the slide option is green
      When the provider is disabled, the option is gray:

      In addition, you can clickto the right of a provider and select:

      • Configure to edit the provider.
      • Support to access Wasabi Technical Support.
      • Delete to delete the provider.
    11. Click BACK TO CONSOLE to return to the ACCOUNT SETTINGS panel.
    12. Set up roles and a policy for the sign in. Refer to Policies and Roles. Begin by reviewing the information in Creating a Role for SSO Legacy.

    Modifying the SSO Configuration

    1. Click CONFIGURE SSO on the ACCOUNT SETTINGS panel.

    2. The SSO Provider List is displayed. Configure a new provider or modify an existing provider, as described above.