---
title: How to enable SAML
description: How to enable Single-Sign-On (SSO) using SAML for Hyperglance
---

[Skip to content](https://support.hyperglance.com/knowledge/saml-support-in-hyperglance#main-content)

English

Show submenu for translations

[More support](https://support.hyperglance.com/knowledge/kb-tickets/new?hsLang=en)

![](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=100&height=75&name=hyperglance.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [More support](https://support.hyperglance.com/knowledge/kb-tickets/new)
- [Contact Us](https://www.hyperglance.com/contact/)

[Contact Us](https://www.hyperglance.com/contact/)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Hyperglance Support](https://support.hyperglance.com/knowledge?hsLang=en)
2. [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en)
3. [RBAC & Users](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#rbac-users)

# How to enable SAML

## How to enable Single-Sign-On (SSO) using SAML for Hyperglance

For Azure AD, follow this [step-by-step guide](https://support.hyperglance.com/knowledge/setup-sso-with-saml-for-azure-ad?hsLang=en) instead

If you are deploying our Helm Chart see [this guide](https://github.com/hyperglance/helm-chart/tree/main#single-sign-on-saml).

If you are running on our legacy Docker-based architecture, see [legacy guide](https://support.hyperglance.com/knowledge/saml-support-in-hyperglance-0?hsLang=en).

In this mode, Hyperglance acts as a Service Provider (SP) and will delegate its authentication to an external Identity Provider (IdP).

Internally the Hyperglance SAML feature is provided by an Apache HTTPD reverse-proxy running a SAML module called [mod\_auth\_mellon](https://github.com/latchset/mod_auth_mellon).

### Setup Procedure

#### Step 1: Generate Service Provider (SP) metadata

- Run metadata creation command: sudo hg saml new --entity-id {entity-id-uri} --endpoint-url {saml-endpoint-url} 
    - Example (make sure to adjust the IP address / URL as needed):
    - ```
      sudo hg saml new --entity-id https://18.206.76.67 --endpoint-url https://18.206.76.67/saml
      ```
    - entity-id - Set to the URL of the Hyperglance VM.
    - endpoint-url - Set to: **https://{ip-address-of-your-hyperglance}/saml**
- **The command will generate the sp.cert, sp.key and sp.xml files.**
- If you require the **ACS URL,** this will be: **https://{ip-address-of-your-hyperglance}/saml/postResponse**

Make sure that the IP address or DNS name used for SAML endpoint URL is one that your **browser** will use. SAML works using browser redirects!

#### Step 3: Configure Your Identity Provider

You will need to configure your IdP with the information from the previous step.  
Here is an example configuration for Okta:

![](https://support.hyperglance.com/hs-fs/hubfs/image-png-Aug-20-2020-12-36-35-26-PM.png?width=667&height=956&name=image-png-Aug-20-2020-12-36-35-26-PM.png)

- Some IdP's allow you to upload the **sp.xml** metadata file to simplify setup.
- For Okta use the **ACS URL** (the one ending in /postResponse) while others such as KeyCloak only ask for the endpoint URL (the one ending in /saml).
- For Azure AD we have separate [a step-by-step guide](https://support.hyperglance.com/knowledge/setup-sso-with-saml-for-azure-ad?hsLang=en).

**Add a 'Role' Attribute**

Hyperglance expects a SAML attribute called **Role** to pass a semi-colon-separated list of [Hyperglance roles](https://support.hyperglance.com/knowledge/role-based-access-control-rbac?hsLang=en).

In the screenshot above we grant admin-level access to Hyperglance by setting the role attribute to:  **HyperglanceUser;HyperglanceAdmin**

#### Step 4: Add Identity Provider (IdP) metadata

- Place the acquired **idp.xml** file in the */var/lib/data/hyperglance\_helm\_charts/saml* directory. How you retrieve this XML will vary depending on the exact IdP you use: 
    - **Okta**: There is an option to download the xml metadata. We have found that you may need to [format the XML](https://www.freeformatter.com/xml-formatter.html) for it to work correctly.
    - **Azure AD**: There is an option to download the "[Federation Metadata XML](https://support.hyperglance.com/knowledge/setup-sso-with-saml-for-azure-ad?hsLang=en)".
    - **KeyCloak**: [The metadata can be fetched for a particular realm from a public URL: /auth/realms/{realmName}/protocol/saml/descriptor](https://www.keycloak.org/docs/latest/server_admin/index.html#proc-using-an-entity-descriptors_server_administration_guide)

#### Step 5: Restart services

- Run the following command to generate an updated values.yaml with your saml configuration files. A backup of your previous values.yaml will be stored in */var/lib/data/hyperglance\_helm\_charts/values\_yaml\_backups*
  
  `sudo hg saml generate-values`
- To activate your new SAML configuration, apply the updated values.yaml by running the following command:  
  `sudo hg apply-config`

#### Step 6: Testing it

1. Using Incognito/InPrivate mode visit your Hyperglance URL in a web browser: **https://{ip-address}**
2. You should be redirected to the IdP login screen.
3. Login via your IdP
4. You should now be redirected back to Hyperglance.

---

### Troubleshooting Tips

Problems may be due to misconfiguration, either on the Hyperglance appliance (SP) or at the IdP.

Here are some helpful things to check that may help you track down an issue:

- Re-trace these instructions carefully.
- Manually inspect the sp.xml and the idp.xml files and ensure that all URLs,  IP addresses and ports are correct from the point-of-view of the user's browser (NOT necessarily from the point-of-view of the Hyperglance appliance box!). If any of these files are changed, re-run the command `sudo hg saml generate-values`
- Check the logs: 
    - General httpd logs can be accessed via running 
          - `hg logs httpd` For general access logs
          - `hg logs httpd -e` For error logs

- - - `hg logs httpd -a` For SSL Access logs
          - `hg logs httpd -s` For SSL Error logs

- Check the logs on your id provider.
- Ensure that you have configured your IdP correctly against the sp.xml file and that it expects to redirect to the /saml/postResponse endpoint.
- It may help to (temporarily) disable any checks that your IdP does for signed responses.
- See if your issue is documented by mod\_auth\_mellon: 
    - [In their readme](https://github.com/latchset/mod_auth_mellon)
    - [In their user-guide](https://github.com/latchset/mod_auth_mellon/blob/master/doc/user_guide/mellon_user_guide.adoc)
    - On their issues tracking page: [Here](https://github.com/latchset/mod_auth_mellon/issues) or [Here](https://github.com/Uninett/mod_auth_mellon/issues?q=is%3Aissue+is%3Aclosed).
- Search online any dedicated guides on how to configure your IdP with **mod\_auth\_mellon**. Such instructions would be highly applicable to Hyperglance since that is what we use internally.

![](https://support.hyperglance.com/hs-fs/hubfs/Knowledge%20Base%20Import/support.hyperglance.comsupportsolutionsarticles11000049094-single-sign-on-with-samlhit.gif?width=1&height=1&name=support.hyperglance.comsupportsolutionsarticles11000049094-single-sign-on-with-samlhit.gif)

- [Before You Start](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#main-content)

    - [Kubernetes](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#gcp)
    - [AWS](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#azure)
- [Using Hyperglance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#main-content)

    - [Automations](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#automations)
    - [Inventory & Diagrams](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#inventory-diagrams)
    - [Rules](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#rules)
    - [Cost Management](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#cost-management)
    - [Dashboards](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#dashboards)
    - [Security & Compliance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#security-compliance)
- [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#main-content)

    - [Updating & Migrating](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#updating-migrating)
    - [General](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#general)
    - [RBAC & Users](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#rbac-users)
    - [STIGS & FIPS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#stigs-fips)
    - [AWS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#azure)
    - [Kubernetes](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#gcp)
    - [API](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#api)
    - [Legacy Docker-based deployments](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#legacy-docker-based-deployments)
    - [AI](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#ai)

[![Chill listening crop-3](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=134&height=24&name=hyperglance.png "Chill listening crop-3")](https://www.hyperglance.com/)

2880 Zanker Road, Suite 203, San Jose, CA 95134

<https://www.linkedin.com/company/hyperglance/>

Copyright © 2025 Hyperglance. All rights reserved.