IBM Aspera Shares supports Security Assertion Markup Language (SAML) 2.0, an open, XML-based standard that allows secure web domains to exchange user authentication and authorization data. With the SAML model, you can configure the Shares web application as a SAML "online service provider" (SP) that contacts a separate online "identity provider" (IdP) to authenticate users who will use Shares to access secure content.
With SAML enabled and configured, a user logging into Shares is redirected to the IdP sign-on URL. If the user has already signed in with the IdP, the IdP sends a SAML assertion back to Shares. The user is now logged into Shares.
When SAML is enabled, Shares creates a user account based on the information provided by a SAML response, and therefore the Shares user account does not need to be created manually. However, any changes to the account that are made on the DS server are not picked up by SAML.
These instructions assume you are already familiar with SAML and already have an identity provider (IdP) -- either third-party or internal -- that meets the following requirements:
Please refer to Configuring Your Identity Provider (IdP) for information on setting up an identity provider for Shares.
Please refer to Configuring SAML for instructions on how to enable SAML authentication in Shares.
Please refer to Creating SAML Groups for instructions on how to set up SAML groups in Shares.
Please refer to Adding a SAML User to a Local Groups for instructions on how to add individual SAML users to a local group.
Please refer to User Accounts Being Provisioned by SAML Just-In-Time (JIT) Provisioning for information on SAML Just-In-Time (JIT) Provisioning for Shares.