This topic describes how to configure Alibaba Cloud as a trusted SAML service provider (SP) of your identity provider (IdP) for user-based single sign-on (SSO).
- Obtain the SAML SP metadata URL from the Resource Access Management (RAM) console.
- Log on to the RAM console by using your Alibaba Cloud account.
- In the left-side navigation pane, click SSO.
- On the SSO page, click the User-based SSO tab.
- In the SSO Settings section, copy the value of the SAML Service Provider Metadata URL parameter.
- Create a SAML SP in your IdP and configure Alibaba Cloud as the relying party by using
one of the following methods:
- Use the SAML SP metadata URL of Alibaba Cloud that you copied in Step 1.
- If your IdP does not support the URL-based configuration of the relying party, download the metadata file from the URL that you copied in Step 1 and upload the metadata file.
- If your IdP does not allow you to upload the metadata file, configure the following
Entity ID: the value of the
entityIDattribute in the
md:EntityDescriptorelement of the metadata file.
ACS URL: the value of the
Locationattribute in the
md:AssertionConsumerServiceelement of the metadata file.
RelayState: This parameter is optional. If your IdP requires the
RelayStateparameter, set the value of the parameter to a URL. Users will be redirected to the URL after SSO succeeds. If you do not configure this parameter, users are redirected to the homepage of the Alibaba Cloud Management Console after SSO succeeds.Note For security purposes, you must enter a URL that points to an Alibaba website for the
RelayStateparameter. For example, the domain name in the URL can be *.aliyun.com, *.hichina.com, *.yunos.com, *.taobao.com, *.tmall.com, *.alibabacloud.com, or *.alipay.com.
What to do next
After you configure Alibaba Cloud as a trusted SAML SP, you must configure SAML assertions for your IdP. For more information, see SAML response for user-based SSO.