Single Sign-On Requirements
The requirements for Single Sign-On with Access Control are as follows.
HENNGE Access Control (SAML Authentication)
- Supports SAML 2.0
- The SAML authentication Name ID (user account information) matches one of the user information fields in HENNGE Access Control
- Supports either or both SP-Initiated SSO and IdP-Initiated SSO
- Can handle the following NameIDFormats: "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress", "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent", or "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
- Supports SAML signature certificates using SHA-256 (SHA-2)
HENNGE Access Control (OpenID Connect)
- Acts as a Relying Party that supports Authorization Code Flow
- Is a confidential client
- Client authentication is either client_secret_post or client_secret_basic
- Scopes include one or more of openid, profile, email, or offline_access
- The ID token claims can include aud, iss, sub, iat, exp, hd, name, given_name, family_name, preferred_username, email, email_verified, zoneinfo, locale, updated_at, auth_time, nonce, and custom attributes
- The redirect URI must be an HTTPS URL or localhost (including 127.0.0.1 or [::1])
Services with Single Sign-On Integrations
Currently, services with Single Sign-On integrations with HENNGE Access Control can be found at the following link under [External Services Integrated with HENNGE Access Control].
External Services Integrated with HENNGE One
Single Sign-On Manuals
For some services, Single Sign-On manuals are available.
You can check the Single Sign-On manuals for each service from the link below.
The Single Sign-On manuals describe the configuration steps on the service side as well as the values to be set in HENNGE Access Control (such as ACS URL, SP Issuer, Name ID, Name ID Format, Login URL, signature method, etc.).
Please note that the Single Sign-On manuals published by our company are based on the verification results at the time of testing and do not guarantee current operation.
Single Sign-On Manuals
Verification Support for Services without Integrations
For services that do not have existing integrations with Access Control, we offer free verification support for Single Sign-On integration.
If you would like verification support for Single Sign-On integration, please refer to the following article.
HENNGE Access Control Single Sign-On Integration Verification Support