SSO Single Sign On (SAML)
When it comes to making authentication easier, CompleteFTP is right up there with the top file server players. We have added Single Sign On capability to our Top CompleteFTP Enterprise Edition, making it virtually unrivalled when it comes to versatility and the capability for you to flex according to your customers and users requirements. This rigorous authentication method has been added to our product because we realize that many of your users prefer to make life easier. This is especially so when it comes to retaining and storing all those passwords and login credentials which can so easily become a security hazard themselves when users end up writing them down or storing them in an insecure manner.
Delegate Authentication of Users
The great advantage of our Single Sign On addition is that it allows multiple systems to delegate authentication of users to a single authentication server.
This means that accounts for access to many systems may be maintained in a single system. SAML (Security Assertion Markup Language) involves three parties:
- A normal web-browser
- A Service Provider (SP)
- An Identity Provider (IDP)
The SP is the web-server that the person using the browser wants to access, and the IDP is the server on which the person has an account. There is a trust-relationship between the SP and the IDP. In particular, the SP trusts the IDP when the IDP says that the client is allowed to log in. This relationship is established through the exchange of SSL certificates wrapped up in packages referred to as metadata. The SP must almost always have the IDP's metadata installed, before it can accept connections, so that it can verify messages from the IDP. The IDP doesn't always require the SP's metadata as it doesn't itself expose sensitive data. The exchange of metadata must happen before logins are possible.CompleteFTP can be configured as a SAML SP (Service Provider). It can delegate authentication to a IDP but it can't itself act as an IDP. One example of a reliable IDP that works hand in hand with CompleteFTP is OneLogin. Turning your CompleteFTP server into an SP, has many great advantages such as broadening your access potential and allowing 3rd parties to authenticate with you via the IDP authentication process. We are excited about this addition which compliments CompleteFTP’s already amazing feature list!
- Multiprotocol gateway
- Unlimited Windows and non-Windows users in all editions
- Windows domain Active Directory (AD) users
- Authentication via an external database
- SSO Single Sign On (SAML)
- Expiration of user accounts
- Folder tree listings (aka recursive directory listings)
- Authenticators via custom .NET extensions