https://capriza.github.io/samling/samling.html (https://github.com/capriza/samling) is a great resource for being able to tinker with the SAML options within Synapse without needing to deploy and configure a complicated software stack.
To make Synapse (and therefore Riot) use it:
samling.xml
next to your homeserver.yaml
with
the XML from step 2 as the contents.Edit your homeserver.yaml
to include:
saml2_config:
sp_config:
allow_unknown_attributes: true # Works around a bug with AVA Hashes: https://github.com/IdentityPython/pysaml2/issues/388
metadata:
local: ["samling.xml"]
Run apt-get install xmlsec1
and pip install --upgrade --force 'pysaml2>=4.5.0'
to ensure
the dependencies are installed and ready to go.
Restart Synapse.
Then in Riot:
uid=your_localpart
.
The response must also be signed.If you try and repeat this process, you may be automatically logged in using the information you
gave previously. To fix this, open your developer console (F12
or Ctrl+Shift+I
) while on the
samling page and clear the site data. In Chrome, this will be a button on the Application tab.