Creating a SAML app in Yandex Identity Hub for integration with Loop
Loop
For the users of your organization to be able to authenticate to Loop via SAML SSO, create a SAML app in Yandex Identity Hub and configure it both in Yandex Identity Hub and Loop.
SAML apps can be managed by users with the organization-manager.samlApplications.admin role or higher.
To give access to Loop to the users of your organization:
- Generate a key and certificate.
- Create an app.
- Set up the integration.
- Add users.
- Make sure the application works correctly.
Generate a key and certificate
To encrypt and sign SAML responses, Loop requires a service provider (SP) certificate and private key. To generate it, use openssl:
openssl req -x509 -newkey rsa:2048 \
-keyout private.key \
-out certificate.crt \
-days 365 -nodes \
-subj "/CN=<instance_name>.loop.ru"
Where <instance_name> is your Loop instance name (subdomain on loop.ru).
This command will create two files, private.key and certificate.crt. Save them, as you will need them to configure SAML in Loop.
Create an app
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps. - Click
Create application and in the window that opens:- Select the SAML (Security Assertion Markup Language) single sign-on method.
- In the Name field, specify a name for your new app:
loop-saml-app. - Optionally, add a description and labels for the app.
- Click Create application.
- On the Overview tab, under Application certificate, click Download certificate and save the new app’s certificate,
loop-saml-app.cer; you will need it to configure SAML in Loop.
Set up the integration
To configure Loop integration with the SAML app you created in Yandex Identity Hub, complete the configuration on both the Yandex Identity Hub side and in Loop.
Configure endpoints and upload the service provider certificate
Specify the details of your Loop instance. To find out endpoint values, go to the Loop system console at https://<instance_name>.loop.ru/admin_console/authentication/saml and copy the Entity ID and ACS URL values from the SAML settings.
- Log in to Yandex Identity Hub
. - In the left-hand panel, click
Apps and selectloop-saml-app. - At the top right, click
Edit and in the window that opens:- Under Service provider (SP) configuration:
-
In the **SP EntityID ** field, enter
Entity ID, the unique service provider ID. -
In the ACS URL field, enter
ACS URL, the address to which the service provider will send requests for user authentication. -
Optionally, add more
ACS URLaddresses by pressing Add URL. -
Optionally, in the SP Logout URL field, add the address to which the IdP will send the SAML response after the user successfully logs out.
-
In the Signature mode field, select which parts of the SAML response will be signed:
Assertions: Sign only user data payloads (ID, attributes, and authentication timestamp).Response: Sign the entire SAML response.Assertions and Response: Sign both the user payloads and the entire response.
-
- Optionally, to only accept requests signed by one of the added certificates, enable Only accept signed requests and add the certificate by clicking Add certificate.
- To ensure SAML response encryption using the selected certificate, enable Encrypt assertion in response and add the previously created certificate by clicking Add certificate.
- From the Data encryption algorithm list, select RSA-OAEP-SHA256 (recommended).
- From the Key encryption algorithm list, select RSA-OAEP-SHA1.
- Click Save.
- Under Service provider (SP) configuration:
Configure user attributes
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, click
Apps and selectloop-saml-app. -
Navigate to the Attributes tab.
-
Add an attribute for providing the username. At the top right, click Add attribute and in the window that opens:
- In the Attribute name field, enter
username. - In the Value field, select
SubjectClaims.preferred_username.
Note
Use transformations to change the attribute value before sending it to the application, e.g., to convert text to lower case, remove spaces, or extract part of the row. Transformations apply one by one, from top to bottom.
- Click Add transformation, and select the
ExtractBeforetransformation type. In the Substring field, enter@. This will extract the part of email address up to the@symbol to serve as the username in the Loop. - Click Add.
- In the Attribute name field, enter
Set up SAML authentication in Loop
- Log in to the Loop system console at
https://<instance_name>.loop.ru/admin_console/authentication/saml. - Under Authentication:
-
Activate the Enable SAML 2.0 login option.
-
In the IdP metadata URL field, enter the address to which Loop sends its metadata request.
How to find out the address of the app metadata file
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selectloop-saml-app. - Under Identity provider (IdP) configuration, copy the Metadata URL field value.
- Log in to Yandex Identity Hub
-
In the SAML SSO URL field, enter the address to which Loop sends the SAML request to initiate the login flow.
How to find out the authentication request address
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selectloop-saml-app. - Under Identity provider (IdP) configuration, copy the Login URL field value.
- Log in to Yandex Identity Hub
-
In the IdP issuer URL field, enter the address used for SAML requests.
How to find out the IdP issuer URL
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selectloop-saml-app. - Under Identity provider (IdP) configuration, copy the Issuer / IdP EntityID field value.
- Log in to Yandex Identity Hub
-
Under CA public certificate, upload the
loop-saml-app.cercertificate file. -
Enable Signature verification.
-
In the Service provider sign-in URL field, enter
https://<instance_name>.loop.ru/login/sso/saml. Also specify this address in the Service provider ID field. -
Activate the Enable encryption option.
-
Under Service provider private key, upload the
private.keyfile. -
Under Service provider public certificate, upload the
certificate.crtfile. -
In the Signature algorithm list, select the
RSAwithSHA512request signature algorithm. -
In the Canonicalization algorithm list, select
Exclusive XML Canonicalization 1.0 (skip comments). -
In the Email attribute field, specify
emailaddress. -
In the Username attribute field, specify
username. -
Optionally, in the Name attribute field, specify the
givennameattribute to populate the user’s first name in Loop. -
Optionally, in the Last name attribute field, specify the
surnameattribute to populate the user’s last name in Loop. -
Optionally, in the Login button text field, enter the sign-in button text to display on the login page. The default text is
Sign in with SAML.
-
- Click Save.
Add users
To enable user authentication in Loop, add the required users and/or user groups to your Yandex Identity Hub SAML application.
Note
Users and groups added to a SAML application can be managed by a user with the organization-manager.samlApplications.userAdmin role or higher.
To add users to a SAML application:
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps and select the required app. - Navigate to the Users and groups tab.
- Click
Add users. - In the window that opens, select the required users.
- Click Add.
Tip
If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.
Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.
Make sure your application works correctly
To make sure both your SAML app and integration with Loop work correctly, log in to Loop as one of the users you added to the app. Proceed as follows:
- In your browser, open the login page of your Loop instance:
https://<instance_name>.loop.ru. - Select Sing in with SAML.
- Authenticate in Yandex Cloud under a user account from your organization.
- Make sure you have signed in to Loop following a successful authentication.