SAML & Azure

Hi,

I have a 9.0.1 FP9 Domino server with a browser based application - the server is dedicated to host only this application. The task
is to have SAML with Azure AD. (or any other SSO with Azure) Yes, I know its not supported…

  • server is set to use internet sites
  • home url is set to the application’s main db
  • domcfg has a sign in form mapping

I’ve tried to use the ADFS cookbook:

Redirection Azure works. Authenticated myself there then the result was a loop. At this time the reply URL specified there was
the server’s root. Next try was to modify the reply URL in Azure to https://DOMAIN/names.nsf?SAMLLogin https://DOMAIN/names.nsf?SAMLLogin the result is an error message:
HTTP Web Server: Bad SAML Request [/names.nsf?SAMLLogin] Anonymous
At least its not a loop now but still not the desired result… The returned package has my email address (NameID) but it seems Domino ignores it. What did I miss? ReplyURL should be different? Any advices? Thanks in advance.

Subject: FP9 Bad SAML request

interesting topic. I’m about to do exact same thing.Not started yet.

There is an issue with FP9 and SAML - was discovered using TFIM so maybe its also for ADFS.

Suggest trying FP 8 to see if that solves the BAD SAML. Also you can add the saml settings in Notes.ini.

I have been working w. okta so heres an article about Domino and Okta but also Saml config in Domino

Opus Neo http://www.opusneo.com/#!federated-login-okta

Interested to follow this.

Subject: Checkpoint MOBA now

Finally we’ve solved it using Checkpoint Mobile Access, but it should be a temporary solution only as it requires a separate user account/pwd but at least we have MFA now. Now we’re configuring F5 and we’ll try to use it as IdP. I’ll keep you posted.

Subject: SAML - idp

Good to hear its working. How did you solve the Bad SAML issue? Using FP9?

We are using F5 as idp with a client. Works fine once its configured. Biggest challenge was the SSL.

idpconf doc. set as ADFS.

Not using MFA.