SAML Identity Provider

LL::NG can act as an SAML 2.0 Identity Provider, that can allow to federate LL::NG with:

  • Another LL::NG system configured with SAML authentication
  • Any SAML Service Provider, for example:

See SAML service configuration chapter.

Go in General Parameters » Issuer modules » SAML and configure:

  • Activation: set to On.
  • Path: keep ^/saml/ unless you have change SAML end points suffix in SAML service configuration.
  • Use rule: a rule to allow user to use this module, set to 1 to always allow.
For example, to allow only users with a strong authentication level:
$authenticationLevel > 2

After configuring SAML Service, you can export metadata to your partner Service Provider.

They are available at the EntityID URL, by default:

In the Manager, select node SAML service providers and click on New service provider:

The SP name is asked, enter it and click OK.

Now you have access to the SP parameters list.


You must register SP metadata here. You can do it either by uploading the file, or get it from SP metadata URL (this require a network link between your server and the SP).

You can also copy/paste the metadata: just click on the Edit button. When the text is pasted, click on the Apply button to keep the value.

Exported attributes

For each attribute, you can set:

  • Key name: name of the key in LemonLDAP::NG session
  • Mandatory: if set to "On", then this attribute will be sent in authentication response. Else it just will be sent trough an attribute response, if explicitly requested in an attribute request.
  • Name: SAML attribute name.
  • Friendly Name: optional, SAML attribute friendly name.
  • Format: optional, SAML attribute format.


Authentication response
  • Default NameID format: if no NameID format is requested, or the NameID format undefined, this NameID format will be used. If no value, the default NameID format is Email.
  • One Time Use: set the OneTimeUse flag in authentication response.

These options override service signature options (see SAML service configuration).

  • Sign SSO message: sign SSO message
  • Check SSO message signature: check SSO message signature
  • Sign SLO message: sign SLO message
  • Check SLO message signature: check SLO message signature
  • Encryption mode: set the encryption mode for this IDP (None, NameID or Assertion).