# Authentication with unsupported SAML provider

**URL:** <https://forums.suse.com/t/authentication-with-unsupported-saml-provider/13145>\
**Category:** General\
**Created:** [January 29, 2019, 10:54am UTC](https://forums.suse.com/t/authentication-with-unsupported-saml-provider/13145 "2019-01-29T10:54:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kklemon](https://avatars.discourse-cdn.com/v4/letter/k/a88e57/32.png) [@kklemon](https://forums.suse.com/u/kklemon)\
**Post date:** [January 29, 2019, 10:54am UTC](https://forums.suse.com/t/authentication-with-unsupported-saml-provider/13145/1 "2019-01-29T10:54:48Z")

</div>

Is it possible to use a SAML provider for authentication that is not officially supported? Rancher seems to support PingIdentity and KeyCloak on this side, but shouldn’t in theory this work for any other provider that implements the SAML protocol?

---

<div class="post-metadata">

**Author:** ![superseb](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/superseb/32/2424_2.png) [@superseb](https://forums.suse.com/u/superseb)\
**Post date:** [January 29, 2019, 1:22pm UTC](https://forums.suse.com/t/authentication-with-unsupported-saml-provider/13145/2 "2019-01-29T13:22:55Z")

</div>

Yes, it’s just not tested/validated/supported. See [https://mattslifebytes.com/2018/08/15/using-okta-and-other-saml-idps-with-rancher-2-0/](https://mattslifebytes.com/2018/08/15/using-okta-and-other-saml-idps-with-rancher-2-0/) for a reference.

---

<div class="post-metadata">

**Author:** ![masmith](https://avatars.discourse-cdn.com/v4/letter/m/eb9ed0/32.png) [@masmith](https://forums.suse.com/u/masmith)\
**Post date:** [February 21, 2019, 5:21pm UTC](https://forums.suse.com/t/authentication-with-unsupported-saml-provider/13145/3 "2019-02-21T17:21:15Z")

</div>

Hi, our enterprise use openam as SAML provider, and I am trying to follow this link ( [https://mattslifebytes.com/2018/08/15/using-okta-and-other-saml-idps-with-rancher-2-0/](https://mattslifebytes.com/2018/08/15/using-okta-and-other-saml-idps-with-rancher-2-0/)) to configure.  
However it is not successful. How rancher pass unique identifier? I received all claim rancher site is asking as well as metadata. I kept getting http 500 error and saml is not valid.  
After we parsed SAML link, it seems like valid SAML data is passed. We believe somewhere rancher is not handshaking well with our SAML provider.

Any suggestion?
