keycloak-scim/server_admin/topics/clients/saml/proc-using-an-entity-descriptor.adoc
2022-07-26 11:50:24 -04:00

38 lines
1.2 KiB
Text

[id="proc-using-an-entity-descriptors_{context}"]
= Using an entity descriptor to create a client
[role="_abstract"]
Instead of registering a SAML 2.0 client manually, you can import the client using a standard SAML Entity Descriptor XML file.
ifeval::[{project_community}==true]
The Client page includes an *Import client* option.
endif::[]
ifeval::[{project_product}==true]
The Add Client page includes an *Import* option.
endif::[]
.Add client
ifeval::[{project_community}==true]
image:{project_images}/import-client-saml.png[Import SAML client]
endif::[]
ifeval::[{project_product}==true]
image:{project_images}/add-client-saml.png[]
endif::[]
.Procedure
ifeval::[{project_community}==true]
. Click *Browse*.
endif::[]
ifeval::[{project_product}==true]
. Click *Select File*.
endif::[]
. Load the file that contains the XML entity descriptor information.
. Review the information to ensure everything is set up correctly.
Some SAML client adapters, such as _mod-auth-mellon_, need the XML Entity Descriptor for the IDP. You can find this descriptor by going to this URL:
[source, subs="attributes"]
----
root{kc_realms_path}/{realm}/protocol/saml/descriptor
----
where _realm_ is the realm of your client.