Support

Configure Single Sign-on (SSO) with Duo Security

Set up Stack Internal Community for SAML SSO authentication with Duo Security.

ADMIN PRIVILEGES REQUIRED

Applies to:
Free
Basic
Business
Enterprise

Overview

Stack Internal Community integrates with Duo Security for SAML 2.0 authentication. You can learn more about SAML in our SAML 2.0 Overview document.

To configure Duo Security authentication, you'll first need to have configured a SAML Identity Provider to provide primary authentication for Duo Single Sign-On. Learn more about configuring the SAML Identity Provider with Duo Single Sign-On.

When setting up SAML authentication, you'll configure your Stack Internal Community site and Duo Security in a back-and-forth process. We recommend having a browser tab or window open to each site.

Protect an application in Duo Security

  1. Sign in to your Duo Security administration panel.

  2. On the left-hand side of the screen, click Applications then Protect an Application.

  3. Enter "generic SAML" in the search bar. Locate the "Generic SAML Service Provider" option and click Protect.

The main SAML configuration screen will appear. It includes the Entity ID and Single Sign-On URL fields you'll enter later into Stack Internal Community.

Configure settings in Stack Internal Community

In a separate browser tab or window, log into Stack Internal Community as an admin. Click Admin settings in the left-hand menu, then Authentication. Click Use SAML 2.0 (if not already enabled).

SAML 2.0 settings

On the SAML 2.0 settings page, enter the following information.

  • Assertion consumer service URL Enter the SAML 2.0 post URL of your Stack Internal Community site (https://[your_site].stackenterprise.co/auth/saml2/post).
  • Single sign-on service URL Copy the Single Sign-On URL value from Duo Security and paste it here.
  • Issuer Copy the Entity ID value from Duo Security and paste it here.
  • Audience restriction Enter any value (we suggest StackOverflowEnterprise). You'll enter this into Duo Security in a later step.
  • Use Subject/NameID as user identifier Leave this option checked.

Configure settings in Duo Security

Service provider

Next, you'll configure settings in the Service Provider section in Duo Security.

  • Metadata Discovery Leave set to None.
  • Entity ID Copy the Stack Internal Community Audience Restriction value you created earlier (for example: StackOverflowEnterprise) and paste it here.
  • Assertion Consumer Service (ACS) URL Enter the SAML 2.0 post URL of your Stack Internal Community site (https://[your_site].stackenterprise.co/auth/saml2/post).

Leave the remaining fields from this section blank.

SAML response

In the SAML Response section of the page, set the following values.

  • NameID format Set this to the option that ends in :persistent (for example: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent).

  • NameID attribute Enter a user identifier that will never change (for example: login or user ID).

  • Signature algorithm Select SHA256.

  • Signing options Select Sign response and Sign assertion.

  • Assertion encryption Leave this unselected.

It's important to select a NameID attribute that is both unique and unchanging. A user's email address, for example, is unique but not unchanging (an updated email address would result in Stack Internal Community creating a new, duplicated account for that user).

SAML attributes

In SAML 2.0, attributes (also called "assertions") are the fields that carry user information. Stack Internal Community requires one attribute for the user's email address and another for display name.

  1. Use the green (+) button to add <Display Name> and <Email Address> attributes in the IdP Attribute column.

  2. In the corresponding SAML Response Attribute fields, enter displayname and email.

    You can also add the following optional SAML attributes:

    • Job title (as jobtitle)
    • Department (as department)

    When Duo Security includes jobtitle and department in the SAML response, Stack Internal Community automatically updates these user data fields on login. Including these attributes also allows you to use Stack Internal Community's Connectivity reporting feature.

  3. To make the login process clearer to your users, assign a name to the application (for example: Stack Internal Community). Users with Duo Push two-factor authentication will see the application name.

  4. Click Save at the bottom of the page to complete the Duo Security configuration.

Finalize Stack Internal Community setup

SAML attributes

In Stack Internal Community, copy and paste the SAML response attributes from Duo into the corresponding Display name assertion and Email address assertion fields. If you added the optional job title and department assertions, enter those here as well.

Certificate

  1. From the Downloads section in Duo Security, click Download certificate. Your browser will download a .crt file.

  2. Open the .crt with a text editor (such as Notepad).

  3. Copy the entire text of the certificate, including "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----".

  4. In Stack Internal Community, click Add certificate and paste the copied text into the text box.

  5. Click Validate certificate to check that the certificate is valid. You should see a green box with a success message.

  6. Click Save Settings to save the SAML configuration.

When saving settings, Stack Internal Community will first perform an authentication test. If the test succeeds, Stack Internal Community will apply your new authentication settings. Logged-in users stay logged in, as all active user sessions remain valid.

If the test fails, Stack Internal Community will not apply the authentication settings. You'll stay on the SAML settings page so you can troubleshoot and correct problems.

This test acts as a safety net to keep invalid authentication settings from locking users (yourself included) out of your site. If you do find your users locked out of your site, reach out to Stack Overflow product support for help.

You can also click Test currently saved SAML configuration to display technical details about your SAML authentication. You'll find these helpful for understanding what information your IdP and Stack Internal Community exchange. This is also useful when troubleshooting.

Users should now be able to log in to your Stack Internal Community site with their SSO credentials.

Troubleshooting

Properly configuring SAML authentication can be tricky. For more information on troubleshooting, see the SAML Authentication Troubleshooting article.

https://doc-automation.netlify.app/pdfs/docs/community/enterprise/for_admins/single_sign-on_sso/configure_SAML_duo.pdf

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article