This article describes how to integrate Amazon Web Services (AWS) IAM with RSA Cloud Access Service (CAS) using My Page SSO.
Configure CAS
Perform these steps to configure RSA Cloud Authentication Service as an Identity provider to AWS IAM.
Procedure
- Sign in to the RSA Cloud Administration Console.
- Navigate to Applications > Application Catalog and search for Amazon Web Services.
- Click Add to add the connector or click Create from Template. The latter option is used in this guide.
- Click Select for SAML Direct and choose Cloud.
- On the Basic Information page, enter the name for the application in the Name field and click Next Step.
- On the Connection Profile page, configure the values shown in the following table. Retain the default values for all other settings.
Field Value Initiate SAML Workflow IdP-initiated Data Input Method Enter Manually Service Provider > Assertion Consumer Service (ACS) URL https://signin.aws.amazon.com/saml Service Provider > Audience (Service Provider Entity ID) urn:amazon:webservices Identity Provider > IdP Advanced Configuration Default: Identity Provider Entity ID Message Protection > SAML Response Protection IdP signs assertion within response Message Protection > Override default signing key and certificate Signature Algorithm:RSA-SHA256,Digest Algorithm:SHA256 Message Protection > Connection Profile Advanced Configuration User Identity
Name ID Format: persistent
User Attribute for SAML Response Subject: mailStatement Attributes
Attribute Name: https://aws.amazon.com/SAML/Attributes/RoleSessionName
Attribute Source: Identity Source
Property: mailAttribute Name: https://aws.amazon.com/SAML/Attributes/Role
Attribute Source: Constant
Property: arn:aws:iam::492411261048:role/RSAIAMRole,arn:aws:iam::492411261048:saml-provider/RSAarn:aws:iam::492411261048:role/ReadbillingRole,arn:aws:iam::492411261048:saml-provider/RSA
(<ARN of the role assigned to provider in AWS>,<ARN of the provider created in AWS>)
Note on Role Attribute Mapping
In this example, two different Role ARN/Provider ARN combinations are mapped to a single https://aws.amazon.com/SAML/Attributes/Role attribute.
- You can map either a single Role ARN/Provider ARN value or multiple values to this attribute.
- When a federated user signs in to the AWS console and multiple role mappings are available, AWS presents the user with a role selection option.
- Access is granted only if the user satisfies the AWS trust policy criteria for the selected AWS role. AWS evaluates and enforces this trust policy.
- Click Next Step.
- On the User Access page, select the configured access policy and click Next Step.
- On the Portal Display page, configure the portal display settings.
- In the Application Tooltip field, enter a descriptive text about the application. The portal will display this text when a user hovers over the application’s icon.
- On the Fulfillment page, make the required changes and click Save and Finish.
- Click Publish Changes, then wait for the operation to complete.
- Locate the newly created application in the applications list.
- In the Edit drop-down list, select Export Metadata to download an XML file containing IdP metadata. This is required for AWS side configurations.
Notes
- If the values for Role ARN and Provider ARN are not known, enter placeholder values <RoleARN>, <ProviderARN> in the Property field to continue with the configuration. The actual value will be entered after completing the configuration of AWS IAM as the Service Provider.
- The selected attribute source is constant for testing purposes. These values can be sourced from the identity source.
Configure AWS IAM
Perform these steps to configure AWS IAM as a SAML service provider for CAS.
Procedure
- Log in to the Identity and Access Management (IAM) console with an appropriate admin role or as a root user.
- Select IAM.
- In the left pane, click Identity Providers.
- Click Add provider.
- Choose SAML as Provider type.
- Enter a name of your choice in the Provider Name field. In this example, the provider name is set to RSA.
- In the Metadata Document field, select the IdP metadata file that you downloaded from RSA during the CAS configuration process.
- Click Add provider.
- Click the provider name you created, and then copy the Provider ARN displayed in the upper-right corner. Use this value for the attribute https://aws.amazon.com/SAML/Attributes/Role in your IdP settings.
- Click Assign role.
- Choose the Create a new role option.
- In the Select Trusted Entity section, choose SAML 2.0 federation as the Trusted entity type.
- In the SAML 2.0 federation section, choose the SAML provider created before in the SAML 2.0-based provider drop-down list.
- Click Next.
- In the Permissions policies section, select the permission policies you want for this role.
- Click Next.
- Enter role names, then click Create role. We have created two roles, namely RSAIAMRole and ReadBillingRole.
- Click your created Role Name and copy the ARN, which you must use as one of the values of the attribute https://aws.amazon.com/SAML/Attributes/Role in your IDP settings. Perform this step for every role created.
The configuration is complete.
Related Articles
AWS IAM Identity Center S3 - SAML Relying Party Configuration - RSA Ready Implementation Guide 4Number of Views AWS Workspaces - SAML My Page SSO Configuration - RSA Ready Implementation Guide 30Number of Views Anomalix idGenius - RSA Administration API (REST) - RSA Ready Implementation Guide 4Number of Views Amazon Web Services - SAML IDR SSO Configuration - RSA Ready Implementation Guide 67Number of Views AWS IAM Identity Center S3 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 25Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Authentication Manager Upgrade Process RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Governance & Lifecycle 8.0.0 Platform Datasheet and Support Matrix Guide