You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

异构环境下SAP与Web应用SAML+OpenID单点登录方案咨询

Great question! Let's break this down clearly since you're dealing with two different authentication protocols and want seamless SSO across them.

1. Optimal SSO Between SAML-based SAP Web Apps and OIDC-based Web Apps

The best approach here is to use a unified identity provider (IdP) that natively supports both SAML 2.0 and OpenID Connect. Microsoft ADFS (2016 or later) is a perfect fit for this scenario—it’s designed to act as a bridge between different protocol ecosystems, which aligns exactly with your use case. Here’s how it works:

  • Centralize authentication with ADFS: Configure ADFS as the single source of truth for user identity. Your SAP app will trust ADFS as its SAML IdP, and your OIDC apps will trust ADFS as their OIDC authorization server.
  • Set up trust relationships:
    • For SAP: Register your SAP web app as a SAML Service Provider (SP) in ADFS. You can either import SAP’s metadata file (if SAP supports exporting it) or manually configure the ACS (Assertion Consumer Service) URL and entity ID. On the SAP side, configure ADFS as the trusted SAML IdP by importing ADFS’s metadata.
    • For OIDC apps: Register each OIDC app as a client in ADFS. Define the redirect URI(s) for the app, set a client secret (for confidential clients), and enable the appropriate OAuth 2.0 flow (authorization code flow is recommended for most web apps). Then configure the OIDC app to point to ADFS’s OIDC endpoints (authorization, token, user info).
  • Unify user directory: Ensure ADFS is connected to a user store (like Active Directory) that’s already used by both SAP and your OIDC apps. This eliminates identity silos and ensures consistent user attributes across all systems.
2. Using ADFS to Issue SAML Tokens for SAP and JWTs for OIDC Apps Without Re-authentication

Absolutely—this is exactly what ADFS is built to do, thanks to its single session management system. Here’s the breakdown:

  • ADFS Session Cookie: When a user first authenticates (either via triggering SAML flow from SAP or OIDC flow from another app), ADFS sets a persistent session cookie (like MSISAuth or MSISAuthenticated) in the user’s browser. This cookie is tied to the user’s authenticated session with ADFS.
  • Seamless token issuance:
    • If the user starts with SAP: SAP sends a SAML AuthnRequest to ADFS. ADFS checks for the existing session cookie—if it’s valid and unexpired, ADFS immediately generates a signed SAML assertion and sends it back to SAP, no re-login needed.
    • When switching to an OIDC app: The OIDC app redirects the user to ADFS’s authorization endpoint. ADFS detects the existing session cookie, skips the login prompt, and redirects back to the OIDC app with an authorization code. The app then exchanges this code for a JWT (ID Token + Access Token) without any user interaction.
  • Key configuration tips:
    • Adjust session lifecycle: In the ADFS Management Console, go to Service > Sessions to set the session timeout (default is 8 hours) and sliding session expiration to balance security and usability.
    • Cross-domain cookie handling: If your SAP and OIDC apps are on different domains, ensure ADFS’s cookie is configured to be accessible across those domains. You can set the cookie domain in ADFS to a parent domain that covers both apps, or use ADFS’s federation service URL as the cookie domain.
    • Attribute mapping: Configure ADFS to map the correct user attributes from your directory to both SAML assertions (e.g., NameID for SAP) and JWT claims (e.g., sub, email for OIDC apps). This ensures consistent user identity across all systems.

A quick note: Always test the end-to-end flow in a non-production environment first—verify that SAML assertions are correctly parsed by SAP, JWTs are valid for OIDC apps, and session persistence works across app switches.

内容的提问来源于stack exchange,提问作者Daniel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:27:52