Creating a SAML app in Yandex Identity Hub for integration with Time
Time
For your organization's users to be able to authenticate to Time via SAML SSO, create a SAML app in Yandex Identity Hub and configure it both in Yandex Identity Hub and Time.
SAML apps can be managed by users with the organization-manager.samlApplications.admin role or higher.
To provide your organization's with access to Time:
- Generate a key and certificate.
- Create an app.
- Set up the integration.
- Add users.
- Make sure the application works correctly.
Generate a key and certificate
To encrypt and sign SAML responses, Time requires the service provider's (SP) certificate and private key. Generate it using openssl:
openssl req -x509 -newkey rsa:2048 \
-keyout private.key \
-out certificate.crt \
-days 365 -nodes \
-subj "/CN=<instance_name>.time‑messenger.ru"
Where <instance_name> is the name of the Time instance (subdomain on time‑messenger.ru).
This will create two files: private.key and certificate.crt. Save them, as you will need them when setting up SAML in Time.
Create an app
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps. - Click
Create application and do the following in the window that opens:- Select the SAML (Security Assertion Markup Language) single sign-on method.
- In the Name field, specify a name for your new app:
time‑saml‑app. - Optionally, add a description and labels for the app.
- Click Create application.
- On the Overview tab, under Application certificate, click Download certificate and save the
time‑saml‑app.cercertificate you created, as you will need it when setting up SAML in Time.
Set up the integration
To configure Time integration with the SAML app you created in Yandex Identity Hub, complete the configuration both on the Yandex Identity Hub side and in Time.
Configure endpoints and upload the service provider certificate
Provide your Time instance details. To find the endpoint values, go to the Time system console at https://<instance_name>.loop.ru/admin_console/authentication/saml and copy the values of the Entity ID and ACS URL fields from the SAML settings.
- Log in to Yandex Identity Hub
. - In the left-hand panel, click
Apps and selecttime‑saml‑app. - At the top right, click
Edit and in the window that opens:- Under Service provider (SP) configuration:
-
In the **SP EntityID ** field, enter
Entity ID, the unique service provider ID. -
In the ACS URL field, enter
ACS URL, the address to which the service provider will send requests for user authentication. -
Optionally, add more
ACS URLby pressing Add URL if needed. -
Optionally, in the SP Logout URL field, add the address to which the IdP will send the SAML response after the user successfully logs out.
-
In the Signature mode field, select which parts of the SAML response will be signed:
Assertions: Only statements about the user (ID, attributes, authentication time) are signed.Response: The entire SAML response is signed.Assertions and Response: Both the statements and the entire response are signed.
-
- Optionally, to only accept requests signed by one of the added certificates, enable Only accept signed requests and add the certificate using Add certificate.
- To ensure that the SAML response is encrypted using the selected certificate, enable Encrypt assertion in response and add the previously created certificate using Add certificate.
- From the Data encryption algorithm list, select RSA-OAEP-SHA256 (recommended).
- From the Key encryption algorithm list, select RSA-OAEP-SHA1.
- Click Save.
- Under Service provider (SP) configuration:
Configure user attributes
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, click
Apps and selecttime‑saml‑app. -
Navigate to the Attributes tab.
-
Add an attribute to provide the username. At the top right, click Add attribute and in the window that opens:
- In the Attribute name field, enter
username. - In the Value field, select
SubjectClaims.preferred_username.
Note
Use transformations to change the attribute value before sending it to the application, e.g., to convert text to lower case, remove spaces, or extract part of the row. Transformations apply one by one, from top to bottom.
- Click Add transformation and select the
ExtractBeforetransformation type; in the Substring field, enter@. This transformation will extract the part of the email address up to the@char. This value will be used as the username in Time. - Click Add.
- In the Attribute name field, enter
Set up SAML authentication in Time
- Log in to the Time system console at
https://<instance_name>.time‑messenger.ru/admin_console/authentication/saml. - Under Authentication:
-
Enable the Enable SAML 2.0 login option.
-
In the Identity provider metadata URL field, enter the address to which Time sends its request for metadata.
How to find the address of an application's metadata file
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selecttime‑saml‑app. - Under Identity provider (IdP) configuration, copy the Metadata URL field value.
- Log in to Yandex Identity Hub
-
In the SAML SSO URL field, enter the address to which Time sends the SAML request to start the login sequence.
How to find the address for authentication requests
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selecttime‑saml‑app. - Under Identity provider (IdP) configuration, copy the Login URL field value.
- Log in to Yandex Identity Hub
-
In the Identity provider issuer URL field, enter the address used for SAML requests.
How to find the publisher address of an account provider
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selecttime‑saml‑app. - Under Identity provider (IdP) configuration, copy the Issuer / IdP EntityID field value.
- Log in to Yandex Identity Hub
-
Under Certification authority public certificate, upload the
time‑saml‑app.cercertificate file. -
Enable the Signature verification option.
-
In the Login address via service provider field, enter an address in the following format:
https://<instance_name>.time‑messenger.ru/login/sso/saml. Duplicate this address in the Service provider ID field. -
Enable the Enable encryption option.
-
Under Service provider private key, upload the
private.keyfile. -
Under Service provider public certificate, upload the
certificate.crtfile. -
In the Signature algorithm list, select the
RSAwithSHA512algorithm to sign the request. -
In the Canonicalization algorithm list, select
Exclusive XML Canonicalization 1.0 (skip comments). -
In the Email attribute field, enter
emailaddress. -
In the Username attribute field, enter
username. -
Optionally, in the Name attribute field, specify
givenname, the attribute to populate the username in Time. -
Optionally, in the Last name attribute field, specify
surname, the attribute to populate the user last name in Time. -
Optionally, in the Login button text field, enter the text that will appear on the login button on the login page. The default is
Using SAML.
-
- Click Save.
Add users
To authenticate with Time, add the required users and/or user groups to your Yandex Identity Hub SAML application.
Note
Users and groups added to a SAML application can be managed by a user with the organization-manager.samlApplications.userAdmin role or higher.
To add users to a SAML application:
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps and select the required app. - Navigate to the Users and groups tab.
- Click
Add users. - In the window that opens, select the required users.
- Click Add.
Tip
If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.
Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.
Make sure your application works correctly
To ensure your SAML application and integration with Time are working correctly, log in to Time using one of the added users. Proceed as follows:
- In your browser, open the login page of your Time instance:
https://<instance_name>.time‑messenger.ru. - Select Using SAML to sign in.
- Authenticate in Yandex Cloud under a user account from your organization.
- Make sure you have signed in to Time following a successful authentication.