KB No. 17: Configuring LemonLDAP::NG as an Identity Provider (IdP) with Olfeo SaaS

Background

This document covers the implementation of the LemonLDAP::NG solution as an identity provider (IDP) for the Olfeo SaaS product.

LemonLDAP::NG is a French open source solution initially developed and used by the French National Gendarmerie. It offers access control and identity federation features. Compatible with SAML, OpenID Connect, and CAS protocols, it supports various authentication modes (LDAP, Kerberos, SQL) and integrates two-factor authentication (MFA) management. To learn more about the features of this solution, visit: LemonLDAP::NG.

You will also find LemonLDAP::NG documentation for configuring an application with Olfeo SaaS.

 

Prerequisites

Synchronize your company directory with Olfeo SaaS. For this part, refer to the Olfeo SaaS technical documentation: Configure and manage directories.

Ensuring that the endpoints required for authentication are publicly exposed on the internet.

Have selected the SAML authentication method in your Olfeo directory.

 

Configuration steps:

  • In the LemonLDAP console, declare a new SAML service provider.
  • In the Olfeo SaaS console, go to Configuration, Directories, Directory editing, Authentication, and complete the "Provider metadata" section with your LemonLDAP metadata.
  • Next, in the LemonLDAP console, enter the Olfeo metadata.

  • Please note that the identifier property defined when synchronizing your directory with Olfeo Saas must be used in the NameID attribute sent in the SAML assertion by LemonLDAP. In the LemonLDAP console, you can adjust this setting in the Option section, Authentication response, then fill in the "Force NameID session key" field.

  • Verify that the signature options are correctly entered as follows:

  • At this stage, all you have to do is perform an authentication test with a user.