मुख्य सामग्री पर जाएँ

SaaS SSO setup: SAML और OpenID Connect integration checklist

SAML या OpenID Connect से enterprise single sign-on बनाएँ—tenant mapping, सुरक्षित account linking, certificate tests और recovery सहित।

इस मार्गदर्शिका में

SaaS के लिए single sign-on क्या है?

Single sign-on (SSO) में कोई organisation अपने identity provider (IdP) से लोगों को SaaS service में authenticate करती है। SAML 2.0 और OpenID Connect (OIDC) federation के आम विकल्प हैं: OIDC, OAuth 2.0 पर identity layer जोड़ता है, जबकि SAML XML-based protocol में signed assertions भेजता है। SSO identity claim verify करता है; product अब भी तय करता है कि उस identity को कौन-सा tenant, role और resource access मिले।

Customer के identity provider के अनुसार protocol चुनें

पूछें कि customer का IdP कौन-सा protocol support करता है और integration से क्या चाहिए। OIDC में आम तौर पर redirect flow के साथ ID token आता है; SAML में signed assertion, assertion consumer endpoint पर भेजी जाती है। Protocol का implementation vetted library और संबंधित specification के अनुसार करें; cryptography या XML signature handling खुद से न लिखें।

Authentication और authorization अलग रखें

Verified external identity को account और tenant से जोड़ें, फिर अपना authorization policy लागू करें। IdP group या claim को product role तभी बनाएँ जब tenant administrator ने mapping सेट की और मंजूर की हो। SSO server-side role checks या tenant isolation का विकल्प नहीं है।

ऐसे identifiers तय करें जो नाम या email बदलने पर भी स्थिर रहें

OIDC के लिए issuer-plus-subject और SAML के लिए configured persistent identifier को प्राथमिकता दें। Email बदल सकता है, दोबारा किसी और को दिया जा सकता है या verify न हुआ हो। केवल email text match होने पर SSO identity को पुराने password account से स्वतः न जोड़ें; account linking को explicit और verified प्रक्रिया बनाएँ।

Enterprise SSO configuration worksheet
Tenant / IdPProtocol और issuerRedirect या ACS endpointIdentity और role mappingCertificate / recovery owner

SAML या OIDC को सुरक्षित तरीके से कैसे configure करें?

Exact redirect और assertion endpoints register करें

OIDC में configured issuer, client, redirect URI, state और nonce को चुने हुए flow तथा library के नियम से validate करें। SAML में entity identifiers, assertion consumer service URL, audience और expected signing keys configure करें। सुविधा के लिए broad wildcard callback न रखें; unexpected destination या issuer reject करें।

Signature, audience, issuer और validity समय जाँचें

केवल tenant के configured IdP से जारी, आपकी service के लिए intended और वैध समय-सीमा वाली assertion या token स्वीकारें। Trusted metadata या configuration से keys manage करें, vetted library से signature जाँचें और malformed या unsigned response पर access deny करें। Decode किए token को cryptographic तथा claim checks से पहले trusted न मानें।

हर IdP configuration को एक verified customer tenant से बाँधें

Setup पूरा करने के लिए authorised tenant administrator की जरूरत रखें और organisation के domain या IdP configuration का control verify करें। केवल unverified email suffix से sign-in को किसी tenant पर न भेजें। Issuer, tenant ID, signing key और allowed identity domains को review योग्य record में रखें।

Team SSO कैसे launch और support करे?

Enforcement से पहले failures और key rotation test करें

गलत issuer, expired assertion, बदला certificate, replayed response, clock skew, duplicate email और IdP outage test करें। Customer को सुरक्षित test mode और समझ आने वाला configuration error दें। Protocol तथा IdP support करें तो signing-key rotation को overlap keys के साथ rehearse करें, फिर पुरानी key हटाएँ।

ऐसी emergency recovery रखें जो छिपा bypass न बने

SSO unavailable या misconfigured हो तो तय करें कि tenant access कौन बहाल कर सकता है और उसकी identity कैसे verify होगी। सीमित, audited recovery account या administrator-approved temporary route रखें। Undocumented shared password या स्थायी bypass न छोड़ें जो organisation की SSO policy को निष्फल करे।

Sign-out और session के व्यवहार की जानकारी दें

Product से sign-out करने पर user IdP में signed-in रह सकता है; IdP logout से product के सभी sessions अपने-आप revoke भी नहीं हो सकते। Supported behavior, session lifetime और admin controls बताएँ। Membership हटने या incident पर रोकथाम जरूरी होने पर product का अपना session और refresh credential revoke करें।

SaaS SSO से जुड़े सवाल

नए SaaS product को SAML या OIDC में से क्या चुनना चाहिए?

Target customers और उनके identity providers से पूछें। OIDC आधुनिक OAuth-based identity protocol है; enterprise SSO में SAML अभी भी आम है। Maintained, security-reviewed implementation चुनें और केवल ग्राहक की वास्तविक जरूरत वाले features बनाएँ।

क्या SSO user accounts खुद बनाता और हटाता है?

जरूरी नहीं। SSO sign-in authenticate करता है; account lifecycle provisioning अलग काम है, जो SCIM या administrator workflow से हो सकता है। तय करें कि कौन शामिल हो सकता है और organisation छोड़ने पर access कब खत्म होगा।

इस बिंदु के स्रोत: IETF RFC 7644: SCIM Protocol

क्या existing account से SSO email match करना सुरक्षित है?

अपने-आप नहीं। Email बदल सकता है या दोबारा किसी और को दिया जा सकता है। IdP issuer और stable subject verify करें; identities या privileges जोड़ने से पहले deliberate, verified account-linking प्रक्रिया अपनाएँ।

इस बिंदु के स्रोत: OpenID Connect Core 1.0, specification version 36

क्या SSO administrator role दे सकता है?

वह group या attribute claim भेज सकता है, लेकिन product को उस value को customer-approved policy से map करके tenant scope verify करना चाहिए। Authentication claim से चुपचाप privileged application role न दें।

इस बिंदु के स्रोत: OWASP Cheat Sheet: authorization