# Support for SAML via Shibboleth?

**URL:** <https://forums.suse.com/t/support-for-saml-via-shibboleth/14045>\
**Category:** SUSE Rancher Prime\
**Created:** [April 23, 2019, 1:24am UTC](https://forums.suse.com/t/support-for-saml-via-shibboleth/14045 "2019-04-23T01:24:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [April 23, 2019, 1:24am UTC](https://forums.suse.com/t/support-for-saml-via-shibboleth/14045/1 "2019-04-23T01:24:38Z")

</div>

Hi folks,

Shibboleth is widely used at universities & government research institutions to implement identity management via SAML.

Does Rancher 2.x support Shibboleth as a SAML provider? The documentation mentions [Keycloak & PingIdentity, but not Shibboleth](https://rancher.com/docs/rancher/v2.x/en/admin-settings/authentication/).

Does anyone have a guide to configure Rancher to work with Shibboleth or a generic SAML provider?

-= Stefan

---

<div class="post-metadata">

**Author:** ![amtsai](https://avatars.discourse-cdn.com/v4/letter/a/e0b2c6/32.png) [@amtsai](https://forums.suse.com/u/amtsai)\
**Post date:** [July 30, 2019, 4:42pm UTC](https://forums.suse.com/t/support-for-saml-via-shibboleth/14045/2 "2019-07-30T16:42:10Z")

</div>

@Stefan_Lasiewski I am looking for the same support and have came to the same roadblock as you.

Currently our work around is to set up SSO with GitHub Enterprise then enable GitHub authentication on Rancher.

There is an enhancement ticket on their GitHub page. [https://github.com/rancher/rancher/issues/19776](https://github.com/rancher/rancher/issues/19776)

---

<div class="post-metadata">

**Author:** ![Stefan\_Lasiewski](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/stefan_lasiewski/32/1801_2.png) [@Stefan\_Lasiewski](https://forums.suse.com/u/Stefan_Lasiewski)\
**Post date:** [July 30, 2019, 5:18pm UTC](https://forums.suse.com/t/support-for-saml-via-shibboleth/14045/3 "2019-07-30T17:18:28Z")

</div>

Hi @amtsai,

We are still pursuing this as well. If you have a support contract, please contact Rancher Support and ask for this feature. It will help them to prioritize the feature appropriately.

-= Stefan

---

<div class="post-metadata">

**Author:** ![catherineluse](https://avatars.discourse-cdn.com/v4/letter/c/cc9497/32.png) [@catherineluse](https://forums.suse.com/u/catherineluse)\
**Post date:** [July 31, 2019, 9:39pm UTC](https://forums.suse.com/t/support-for-saml-via-shibboleth/14045/4 "2019-07-31T21:39:26Z")

</div>

Rancher supports several SAML providers:

> In Rancher v1.6, we encouraged our SAML users to use Shibboleth, as it was the only SAML authentication option we offered. However, to better support their minor differences, we’ve added more fully tested SAML providers for v2.x: Ping Identity, Microsoft ADFS, and FreeIPA.

> **[1. Get Started | Rancher](https://rancher.com/docs/rancher/v2.x/en/v1.6-migration/get-started/)**
>
> Get started with your migration to Rancher v2.x by installing Rancher and configuring your new Rancher environment.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [August 1, 2019, 4:37pm UTC](https://forums.suse.com/t/support-for-saml-via-shibboleth/14045/5 "2019-08-01T16:37:43Z")

</div>

@catherineluse They know that, but Shibboleth is not one of them (in 2.x).
