Single Sign-On (SSO) to OnlyOffice#
Follow these instructions to configure the Gluu Server and OnlyOffice for SSO.
Configure OnlyOffice#
Note
Review the docs for configuring OnlyOffice SSO.
- 
Sign in to the OnlyOffice portal with an administrative account
 - 
Navigate to the Control Panel

 - 
Click SSO (on the left menu), and select
Enable Single Sign-on Authentication
 - 
Load metadata to fill the required fields automatically. Shibboleth provides the IdP metadata file at
https://{shibboleth-idp-domain}/idp/shibboleth. Store theshibboleth.xmlfilein the local machine and upload it with theSELECT FILEbutton. - 
The Name ID format must be
Transient
 - 
In the Public Certificates section, check the box for both
Verify Authentication Response SignatureandVerify Logout Request Signature
 - 
Inside the SP Certificates section, keep the default values for Attribute Mapping

 - 
Click the
Savebutton - 
Click
DOWNLOAD SP METADATA XML 
Configure Gluu Server#
Now, follow the instructions below to create a SAML Trust Relationship (TR) for OnlyOffice in the Gluu Server.
Note
Review the docs for creating SAML TRs.
Trust Relationship#
- Create a TR by clicking 
Saml, thenAdd Trust Relationship. Use the following fields:Display Name: Name the TR (e.g. OnlyOffice SSO)Description: Provide a description for the TR (e.g. SAML SSO TR for OnlyOffice)Metadata Type: Select File
 - Upload the OnlyOffice metadata (downloaded during OnlyOffice configuration)
 - Release the following attributes: 
TransientIDandEmail - Add the TR
 - Select 
Configure Relying Party - Add the following configurations: 
- Select 
SAML2SSO includeAttributeStatement: EnabledassertionLifetime: keep the defaultassertionProxyCount: keep the defaultsignResponses: conditionalsignAssertions: neversignRequests: conditionalencryptAssertions: conditionalencryptNameIds: never- Save
 
 - Select 
 - Click 
Update - 
Click
Activate
 
NameID#
Now, configure the NameID:
- Navigate to 
Configure custom NameID - 
Click
Add NameID Configuration- Check 
Enabled - For Source Attribute, select 
Emailfor the Source Attribute - For NameId Type, select 
emailAddress 

 - Check 
 - 
Click
Update 
Testing#
- Attempt to access the Only Office dashboard.
 - Click the button 
Single Sign-On - Enter your credentials in Gluu and login
 - You will be redirected back to the OnlyOffice dashboard with an active session