Entra ID
Last updated
Last updated
Linux Control Center = 2.12.X or higher
Pre-configured Single Sign-On (SSO) Provider
Linux Control Center allows you to configure a Single Sign-On (SSO) provider for the Console, offering secure and convenient access. LCC supports authentication via LDAP and SAML.
See the image representing the authentication flow.
The objective of this document is to provide a step-by-step guide to configure an access provider to the LCC Console using a SAML provider.
Access the Entra ID platform in your environment and go to Applications. Select App Registrations and click New Registration.
Define a name for the application and choose the type of Microsoft Entra ID account that will have permission to access LCC.
Define the scope of access to the application as desired.
Click Register.
Click Config in the left menu of LCC.
Click Provider.
Click SAML.
Click Create.
Fill in the required fields as follows:
Name: This will be the name of the provider button on the LCC login screen.
Entity ID: Enter the ID of the application created in Microsoft Entra ID.
IDP Metadata URL: Enter the Authority URL from the Entra ID application.
IDP Metadata Data: Enter the metadata URL from your Identity Provider.
To obtain the IDP URL information from Microsoft Entra ID, go to the Overview page of the application and click Endpoints.
Copy the SAML-P Sign-on Endpoint and paste it into the IDP Metadata URL field.
Click Select an Icon and choose the login button icon for the provider that will appear on the LCC Console login screen. You can also upload a custom icon using a Base64 string.
Click Next.
Fill in the User Identifier Attribute field. This defines the user from the Identity Provider responsible for validating authentication. You can define a key to validate the IDP response.
Click Next again and select the options as needed.
Click Save to create the provider in the LCC Console.
Important: This step is crucial in configuring the identity provider. You must register the LCC endpoint in your Identity Provider so that LCC has permission to perform queries.
Click on the Identity Provider you created and copy the Assertion Consumer Service URL. Paste it into the Redirect URL field in the Microsoft Entra ID application.
Field configuration in Microsoft Entra ID.
Click Config in the left menu.
Click Authentication.
Click the Providers tab, select the provider, and move it to the table on the right.
Click Save to set the provider (e.g., Cisco Duo) as a valid authentication method.
Log out from the current user and click the Identity Provider button you created. LCC will perform the query and read the SAML response to validate access to the Console.