All Products
Search
Document Center

CloudSSO:Example: Shibboleth and CloudSSO single sign-on

Last Updated:Jul 17, 2026

This topic provides an example of how to configure single sign-on (SSO) from Shibboleth to CloudSSO.

Before you begin

Install Shibboleth, Tomcat, and an LDAP server.

Note

The Shibboleth configurations in this topic are provided only to help you understand the end-to-end configuration process. Alibaba Cloud does not provide consulting services for Shibboleth configuration.

Step 1: Get SAML SP metadata from Alibaba Cloud

  1. Log on to the CloudSSO console.

  2. In the left-side navigation pane, click Settings.

  3. In the SSO Logon section, download the service provider (SP) metadata file and save it to /opt/shibboleth-idp/metadata/aliyun-cloudsso-metadata.xml.

    Save the Entity ID of the SP for later use.

Step 2: Register Alibaba Cloud with Shibboleth

Edit the /opt/shibboleth-idp/conf/metadata-providers.xml file to point to the metadata file from Step 1: Get SAML SP metadata from Alibaba Cloud and register Alibaba Cloud as a trusted service provider in Shibboleth.

<!--
    <MetadataProvider id="LocalMetadata"  xsi:type="FilesystemMetadataProvider" metadataFile="PATH_TO_YOUR_METADATA"/>
-->
<!-- Replace the preceding commented code with the following code. -->
<MetadataProvider id="AliyunMetadata"  xsi:type="FilesystemMetadataProvider" metadataFile="%{idp.home}/metadata/aliyun-cloudsso-metadata.xml"/>

Step 3: Configure user attributes from Shibboleth

  1. Modify the /opt/shibboleth/conf/services.xml file.

    The default attribute-resolver.xml file does not include all required attribute definitions. Replace it with attribute-resolver-full.xml to enable the complete configuration.

    <value>%{idp.home}/conf/attribute-resolver.xml</value>
    <!-- Replace the preceding code with the following code. -->
    <value>%{idp.home}/conf/attribute-resolver-full.xml</value>
  2. Modify the /opt/shibboleth/conf/attribute-resolver-full.xml file.

    1. Configure the attributes to return with user information. In this example, the mail attribute is returned.

      <!-- ========================================== -->
      <!--      Attribute Definitions                 -->
      <!-- ========================================== -->
      <!-- Schema: Core schema attributes-->
      <!-- Add the following code after the preceding comments. -->
      <AttributeDefinition xsi:type="Simple" id="mail">
          <InputDataConnector ref="myLDAP" attributeNames="mail" />
          <AttributeEncoder xsi:type="SAML1String" name="urn:mace:dir:attribute-def:mail" encodeType="false" />
          <AttributeEncoder xsi:type="SAML2String" name="urn:oid:0.9.2342.19200300.100.1.3" friendlyName="mail" encodeType="false" />
      </AttributeDefinition>
    2. Configure the LDAP data connector by reading settings from /opt/shibboleth/conf/ldap.properties.

      <!-- Example LDAP Connector -->
      <!--
      	<DataConnector id="myLDAP" xsi:type="LDAPDirectory"
      		ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"
      		baseDN="%{idp.attribute.resolver.LDAP.baseDN}"
      		principal="%{idp.attribute.resolver.LDAP.bindDN}"
      		principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"
      		useStartTLS="%{idp.attribute.resolver.LDAP.useStartTLS:true}"
      		...
      	</DataConnector>
      -->
      <!-- Replace the preceding example code with the following code. -->
      <DataConnector id="myLDAP" xsi:type="LDAPDirectory"
      			   ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"
      			   baseDN="%{idp.attribute.resolver.LDAP.baseDN}"
      			   principal="%{idp.attribute.resolver.LDAP.bindDN}"
      			   principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"
      			   useStartTLS="%{idp.attribute.resolver.LDAP.useStartTLS}"
      			   connectTimeout="%{idp.attribute.resolver.LDAP.connectTimeout}"
      			   responseTimeout="%{idp.attribute.resolver.LDAP.responseTimeout}">
      	<FilterTemplate>
      		<![CDATA[
      				%{idp.attribute.resolver.LDAP.searchFilter}
      			]]>
      	</FilterTemplate>
      </DataConnector>
  3. Modify the /opt/shibboleth/conf/attribute-filter.xml file to add an attribute filter.

    In the PolicyRequirementRule tag, replace the value attribute with the Alibaba Cloud entityID from Step 1: Get SAML SP metadata from Alibaba Cloud.

    <AttributeFilterPolicyGroup id="ShibbolethFilterPolicy"
    							xmlns="urn:mace:shibboleth:2.0:afp"
    							xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    							xsi:schemaLocation="urn:mace:shibboleth:2.0:afp http://shibboleth.net/schema/idp/shibboleth-afp.xsd">
    <!-- Add the following code after the preceding code. -->
    <AttributeFilterPolicy id="aliyun">
    	<PolicyRequirementRule xsi:type="Requester" value="[entityID]" />
    	<AttributeRule attributeID="mail">
    		<PermitValueRule xsi:type="ANY" />
    	</AttributeRule>
    </AttributeFilterPolicy>

Step 4: Configure the SAML NameID

  1. Modify the /opt/shibboleth/conf/relying-party.xml file to configure the NameID for Alibaba Cloud.

    In the bean tag, replace the relyingPartyIds attribute with the Alibaba Cloud entityID from Step 1: Get SAML SP metadata from Alibaba Cloud.

    <!--
    	Override example that identifies a single RP by name and configures it
    	for SAML 2 SSO without encryption. This is a common "vendor" scenario.
    -->
    <!--
    <bean parent="RelyingPartyByName" c:relyingPartyIds="https://sp.example.org">
    	<property name="profileConfigurations">
    		<list>
    			<bean parent="SAML2.SSO" p:encryptAssertions="false" />
    		</list>
    	</property>
    </bean>
    -->
    <!-- Replace the preceding commented code with the following code. -->
    <bean parent="RelyingPartyByName" c:relyingPartyIds="[entityID]">
        <property name="profileConfigurations">
            <list>
                <bean parent="SAML2.SSO" p:encryptAssertions="false" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" />
            </list>
        </property>
    </bean>
  2. Modify the /opt/shibboleth/conf/saml-nameid.xml file to configure NameID generation.

    <!-- Uncomment the following two beans to enable them. -->
    <bean parent="shibboleth.SAML2AttributeSourcedGenerator"
        p:omitQualifiers="true"
        p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
        p:attributeSourceIds="#{ {'mail'} }" />
    <bean parent="shibboleth.SAML1AttributeSourcedGenerator"
        p:omitQualifiers="true"
        p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
        p:attributeSourceIds="#{ {'mail'} }" />
  3. Modify the /opt/shibboleth/conf/saml-nameid.properties file to configure NameID properties.

    idp.nameid.saml2.default = urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
    idp.persistentId.useUnfilteredAttributes = true
    idp.persistentId.encoding = BASE32

Step 5: Get SAML IdP metadata from Shibboleth

  1. Restart Tomcat to apply your changes.

  2. Access https://<your_server_address>/idp/shibboleth and save the metadata file to your local computer.

Step 6: Enable SSO in CloudSSO

  1. In the left-side navigation pane of the CloudSSO console, click Settings.

  2. In the SSO Logon section, click Configure IdP.

  3. In the Configure IdP dialog box, select Upload Metadata File.

  4. Click Upload File and upload the IdP metadata file from Step 5: Get SAML IdP metadata from Shibboleth.

  5. Turn on the SSO switch to enable SSO.

    Note

    After you enable SSO logon, username and password logon is disabled. This means CloudSSO users can no longer sign in with their platform credentials. Once enabled, all users must sign in through your identity provider.

Step 7: Create a user in CloudSSO

Create a CloudSSO user whose username matches the corresponding Shibboleth user.

  1. In the left-side navigation pane of the CloudSSO console, choose User Management > User.

  2. On the User page, click Create User.

  3. In the Create User panel, enter a Username.

    In this example, the username is testUser@testdomain.alicloud.com.

  4. Set the user status to Enabled.

  5. Click Close.

(Optional) Step 8: Assign permissions to the user

To let users access resources in specific Resource Directory member accounts after SSO, create a permission set and grant the user access to those accounts.

  1. Create a permission set in CloudSSO to define policies.

    For more information, see Create a permission set.

  2. Grant the user access to the member accounts.

    For more information, see Grant access to a member account.

Verify the result

You can initiate SSO from either Alibaba Cloud or Shibboleth.

  • Initiate SSO from Alibaba Cloud

    1. On the Overview page of the CloudSSO console, copy the user logon URL.

    2. Open the URL in a new browser.

    3. Click Go. You are redirected to the Shibboleth login page. The SSO Login page appears with the Enterprise Account Login URL field pre-filled. Click Go to proceed to the identity provider login page.

    4. On the Shibboleth logon page, enter the username (testUser) and password, and then click Log On.

      After successful authentication, you are redirected to the CloudSSO user portal.

    5. Access the resources in the member accounts to which you have permissions.

  • Initiate SSO from Shibboleth

    1. Access https://<your_server_address>/idp/profile/SAML2/Unsolicited/SSO?providerId=<entityID>.

      Replace <entityID> in the URL with the Alibaba Cloud entityID from Step 1: Get SAML SP metadata from Alibaba Cloud.

    2. On the Shibboleth logon page, enter the username (testUser) and password, and then click Log On.

      After successful authentication, you are redirected to the CloudSSO user portal.

    3. Access the resources in the member accounts to which you have permissions.

FAQ

If you encounter issues during verification, check /opt/shibboleth-idp/logs/idp-process.log. The following are common issues and solutions:

Error after successful Shibboleth logon

Check the error message in /opt/shibboleth-idp/logs/idp-process.log. If the error is related to ValidateUsernamePassword, verify your LDAP connection settings and deployment. Make sure that you have uncommented the required sections and that there are no extra spaces.

Logon fails with "unable to connect to the ldap" error

Check the LDAP connection settings in the ldap.properties and attribute-resolver-full.xml files.

Redirect error: "The NameID is missing"

Verify that you correctly mapped the mail attribute from the user information in Step 3: Configure user attributes from Shibboleth. Also, verify that the NameID is configured correctly in Step 4: Configure the SAML NameID.

Access error: "Unsupported Request" on https://<your_server_address>/idp/profile/SAML2/Unsolicited/SSO?providerId=<entityID>

Make sure the entityId is consistent across three locations: the metadata file in the metadata folder, the attribute-filter.xml file, and the relying-party.xml file.

Redirect error: "The response signature is invalid"

Upload the Shibboleth metadata file to Alibaba Cloud again.