8. WWW.LIFERAY.COM WWW.FACEBOOK.COOM/LIFERAY @LIFERAY
eHerkenning
Insert User Group
Logo (please resize)
een gestandaardiseerd inlogsysteem,
waarmee ondernemers met één sleutel
kunnen inloggen bij diverse overheden,
instellingen of andere organisaties.
ontwikkeld door het
bedrijfsleven in samenwerking
met de overheid
19. WWW.LIFERAY.COM WWW.FACEBOOK.COOM/LIFERAY @LIFERAY
Liferay en SAML
Insert User Group
Logo (please resize)
# keystore type
saml.keystore.type=jks
# location of the keystore
saml.keystore.path=/export/www/portal/data/keystore.jks
# pwd for accessing the keystore
saml.keystore.password=bigsecret
# pwd for accessing the certificate of the entity in the keystore
saml.keystore.credential.password[urn:nl:eherkenning:DV:00000003507204570000:en
# Service Provider SAML entity id
saml.sp.default.idp.entity.id=urn:nl:eherkenning:HM:00000003273226310000:entities:30
portal-ext.properties
23. WWW.LIFERAY.COM WWW.FACEBOOK.COOM/LIFERAY @LIFERAY
After login - then what?
Insert User Group
Logo (please resize)
• end result of authentication:
information about identity of user
• proceed with authorization (roles,
groups, organisation)
• important: we need a persistent
Liferay User object
24. WWW.LIFERAY.COM WWW.FACEBOOK.COOM/LIFERAY @LIFERAY
Limitations of Liferay SAML Plugin
Insert User Group
Logo (please resize)
• poor customisation possibilities
• no support for multiple IdPs =>
cannot connect both Digid and
eHerkenning
• no support for Artifact binding
25. WWW.LIFERAY.COM WWW.FACEBOOK.COOM/LIFERAY @LIFERAY
Our status
Insert User Group
Logo (please resize)
• still in testing phase
• need to address plugin limitations -
cooperation with Liferay
• more complicated scenarios such as
‘machtigingen’?
• what will happen when live?