Setting up the identity provider in Cloudera

In Cloudera, you must create an identity provider to capture the SAML metadata and connection information for your enterprise IdP. To create an identity provider in Cloudera, you must be a Cloudera account administrator or have the PowerUser role.

Required role: Account administrator or PowerUser
  1. Sign in to the Cloudera console.
  2. From the Cloudera home page, click Cloudera Management Console.
  3. In the Cloudera Management Console home page, navigate to Administration and select the Authentication tab.
  4. Configure the following settings for SAML:
    • In IDP Metadata, select File Upload to upload a file that contains the identity provider SAML metadata or select Direct Input to paste the identity provider SAML metadata directly.
    • To synchronize the groups, select the Sync Groups on Login option.
    • If you want to generate workload usernames by email, select its associated option.
  5. If your LDAP is not configured, please ensure you fill in your LDAP configurations as they are required by Cloudera Private Cloud Data Services for workload authorization.
  6. Click Update Authentication Settings.
  7. To set up SAML as the preferred identity provider, go to the Preferred Authentication Type section, select SAML and click Save. If you are switching your preferred authentication type from LDAP to SAML OR SAML to LDAP, ensure you migrate your users. For more information see, Migrating users from another preferred identity provider

Once you update your authentication settings, the Authentication Page will have your new identity provider (IDP) information. It will reflect your previously saved configurations and also provide the Cloudera SAML Service Provider Metadata. This will be used to configure your IDP.

These are the properties for your SAML identity provider:

Property Description
SAML Identity Provider Metadata The identity provider SAML metadata for your enterprise IdP that you provided when you created the Cloudera identity provider.
Sync Groups on Login Indicates whether Cloudera synchronizes a user's group membership in Cloudera with the user's group membership in your enterprise IdP when a user logs in.

For more information about user group synchronization, see Group Membership Synchronization.

Generate workload username by email You can optionally check this if you want the workload username to be generated based on the email instead of the default.
Cloudera SAML Service Provider Metadata The Cloudera SAML service provider metadata to configure your enterprise IdP.