# discourse-samlプラグインとOktaでのSSO設定に問題あり

**URL:** https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002
**Category:** SSO
**Created:** [2018 年 4 月 10 日午後 6:09 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002 "2018-04-10T18:09:04Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![sjforman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sjforman/32/120003_2.png) [@sjforman](https://meta.discourse.org/u/sjforman)
#### Post date: [2018 年 4 月 10 日午後 6:09 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/1 "2018-04-10T18:09:04Z")

</div>

I’m trying to configure a self-hosted Docker instance of Discourse to authenticate users with SAML, using Okta as the IdP. At first my setup looked identical to what @runofthemill posted here: [Discourse-saml + Okta endless redirect](https://meta.discourse.org/t/discourse-saml-okta-endless-redirect/55525). But then, thanks @skoota, I re-set all the native SSO configs to the defaults, since I understand want to be relying just on the plugin.

So now plugin is successfully installed, and SAML appears as a login option, but I get this error when I try to use it:

 ![24](https://global.discourse-cdn.com/meta/original/3X/5/1/519422891aeb79a807945065dc338c2f047f3e2a.png)

I took a look at the [library this error seems to orginate from](https://github.com/onelogin/ruby-saml/blob/master/lib/onelogin/ruby-saml/authrequest.rb#L38), and it’s not obvious to me what’s going wrong. But I’m not a rubyist, so maybe (hopefully!) I’m missing something obvious.

Suggestions? Thanks in advance.

---

<div class="post-metadata">

### Author: ![Scott\_Morgan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/scott_morgan/32/120023_2.png) [@Scott\_Morgan](https://meta.discourse.org/u/Scott_Morgan)
#### Post date: [2018 年 5 月 2 日午後 10:30 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/2 "2018-05-02T22:30:45Z")

</div>

Did you end up getting Okta working? Configuring Discourse + Okta is on my todo list. Thanks.

---

<div class="post-metadata">

### Author: ![sjforman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sjforman/32/120003_2.png) [@sjforman](https://meta.discourse.org/u/sjforman)
#### Post date: [2018 年 5 月 7 日午後 8:03 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/3 "2018-05-07T20:03:45Z")

</div>

Nope, couldn’t figure it! Thanks for asking though. If you do wind up figuring out how to make them work nicely together, I’d be interested to know what you discover.

---

<div class="post-metadata">

### Author: ![Chris\_Reilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chris_reilly/32/154383_2.png) [@Chris\_Reilly](https://meta.discourse.org/u/Chris_Reilly)
#### Post date: [2019 年 2 月 8 日午前 6:31 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/4 "2019-02-08T06:31:58Z")

</div>

I was able to get Okta and Discourse working together nicely via OpenID Connect. I couldn’t figure out Okta via SAML, but it seems like that should be possible.

---

<div class="post-metadata">

### Author: ![galligan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/galligan/32/224839_2.png) [@galligan](https://meta.discourse.org/u/galligan)
#### Post date: [2020 年 8 月 3 日午後 1:47 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/5 "2020-08-03T13:47:26Z")

</div>

@Chris_Reilly、Okta を介してグループをプッシュする方法は見つかりましたか？

これが機能するかどうか疑問に思っています：

 ![CleanShot 2020-08-03 at 09.47.03@2x](https://global.discourse-cdn.com/meta/original/3X/4/0/40d535ec3882372f4bc3793db7a74f159da51c9b.png)

---

<div class="post-metadata">

### Author: ![Chris\_Reilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chris_reilly/32/154383_2.png) [@Chris\_Reilly](https://meta.discourse.org/u/Chris_Reilly)
#### Post date: [2020 年 8 月 3 日午後 2:23 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/6 "2020-08-03T14:23:27Z")

</div>

グループ同期には SAML が必要です。OpenID ではグループ同期はサポートされていません。Okta は SAML をサポートしていますが、別途統合と SAML プラグイン/エンタープライズプランが必要です。

---

<div class="post-metadata">

### Author: ![raufis27](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/raufis27/32/202096_2.png) [@raufis27](https://meta.discourse.org/u/raufis27)
#### Post date: [2020 年 12 月 3 日午後 2:19 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/7 "2020-12-03T14:19:01Z")

</div>

Okta 側の設定情報を共有いただけますでしょうか？アプリの作成と割り当てはどのように行いましたか？Discourse では OpenID オプションでログインできるのですが、Okta から Discourse への認証開始ができません。

---

<div class="post-metadata">

### Author: ![Chris\_Reilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chris_reilly/32/154383_2.png) [@Chris\_Reilly](https://meta.discourse.org/u/Chris_Reilly)
#### Post date: [2020 年 12 月 7 日午前 3:56 UTC](https://meta.discourse.org/t/trouble-configuring-sso-with-discourse-saml-plugin-okta/85002/8 "2020-12-07T03:56:43Z")

</div>

最終的に Auth0 を採用しましたが、ユーザーに直接「ブックマーク」アプリ以外の形でランチャーリンクを提供することができませんでした。Discourse のセッションが存在しない状態で保護された URL にアクセスした場合、新しいセッションが作成されるはずです。Discourse では他のすべてのログインオプションを無効化していたため、ユーザーはログインモーダルを表示することさえありませんでした。POC としてはスムーズな設定でしたが、シングルログアウトのシナリオについては結局解決に至りませんでした。
