Troubleshooting saml bridge for authorization – Google Search Appliance Enabling Windows Integrated Authentication version 7.2 User Manual

Page 19

Advertising
background image

Google Search Appliance: Enabling Windows Integrated Authentication

19

Configuring the Search Appliance to Use SAML Bridge for
Authorization

To configure the search appliance to use SAML Bridge for authorization, add a SAML rule for a URL
pattern that the search appliance can use to send a SAML authorization request to the Policy Decision
Point.

To configure the search appliance to use SAML for authorization:

1.

In the search appliance Admin Console, click Search > Secure Search > Flexible Authorization.

2.

Choose SAML from the pull-down menu, and click Add another rule. The Add Flexible
Authorization Rule page appears.

3.

In the URL Pattern field, type the URL pattern identifying the protected content.

4.

Select an Authentication ID from the pull-down menu or accept the default credential group. By
selecting the Authentication ID, you are instructing the authorization mechanism to use a session
identity from a specific credential group or instance of an authentication mechanism.

5.

If you want to override the default value of 3 seconds for making a network connection, enter the
time in seconds in the Timeout field.

6.

In the Authorization service ID field, enter the Entity ID of the SAML server.

7.

In the Authorization service URL field, enter:

http(s)://saml-hostname:port/saml-bridge/Authz.aspx

8.

Check Use batched SAML AuthZ requests to send multiple URLs for authorization in a single
AuthZ HTTP request for improved serve time performance (recommended).

9.

Click Save.

10. On the Flexible Authorization page, select the added rule and click Move Up to move it ahead of

the HEADREQUEST rule. This causes the SAML rule to take precedence over the HEADREQUEST rule.

11. Click Save Rules Order.

Continue to “Completing the Configuration Process” on page 13.

Troubleshooting SAML Bridge for Authorization

This section contains some troubleshooting tips that apply to authorization. For general tips to narrow
your problem, refer to “Troubleshooting SAML Bridge for Authentication” on page 14. For more
troubleshooting steps, visit the SAML Bridge wiki (

http://code.google.com/p/google-saml-bridge-for-

windows/wiki/SAMLBridgeFAQsTroubleshooting

).

Advertising