Forum Replies Created
-
sohamj
Participant# 2 years, 2 months agoHi there,
Thank you for reaching out to us.
As I understand it, if users try to log in through the SAML SSO plugin via the SSO button, they are not being redirected to the same page from where the SSO is initiated; instead, they are being redirected to the site’s homepage. Please correct me if I am wrong.
If my understanding is correct, then can you please share the following details on our support email (samlsupport@xecurify.com) so that we can look into the issue at the earliest –
– Share the SAML Tracer Logs while reproducing the issue.
– Share the plugin configuration file. You can export the file by navigating to the Service Provider Setup tab and clicking the Export Configuration button.In the meantime, please do not hesitate to contact us if you have any further questions or concerns.
Awaiting your response.Thanks,
in reply to: Redirect back to gated page after loginsohamj
Participant# 2 years, 2 months agoHi there,
I hope you are doing well.
As I understand it, you have an array of memberships that you pass in one of the SAML attributes, and you have a few memberships to which you want to assign subscriber roles, while some memberships you want to deny access to your site and assign a Non-Subscriber role. Please correct me if I am wrong.
Would I enable regex on the role mapping fields? What would that look like?
>> Yes, you can enable regex for role mapping in the premium version of our plugin. Please follow the steps below to enable regex for role mapping-
– Navigate to the Advanced Settings section of the Attribute/Role Mapping tab within the plugin and enable the “Enable Regex for Role Mapping” toggle.
– Now, navigate to the Role mapping section of the Attribute/Role Mapping tab and here you can use the following pattern to assign the role from the SAML attribute (INTL|NMI|NRS|OTHCP|PHA|PSR|PHYS|PA|RET|RNNRS|TR).Further, I would like to inform you that for users whom you want to deny access to your WP site and assign the Non-Subscriber role, you need to define capabilities for the Non-Subscriber role in WordPress such that users with the Non-Subscriber role are not able to access your site. Then, map semicolon-separated memberships in front of your Non-Subscriber custom role. Moreover, if you don’t have capabilities defined for your custom role, you can use the ‘Create/Update the user but assign a ‘None’ role’ option in our plugin. This way, users whose memberships are not mapped with the subscriber role get the none role and cannot access your site.
Drop us an email at samlsupport@xecurify.com if you would like to see a demo.
I hope this helps.
Thanks,
Nutanin reply to: Attribute with Arraysohamj
Participant# 2 years, 4 months agoHi there,
Thank you for bringing this to our attention.
We have identified the issue you mentioned, the plugin is currently not handling JSON based state parameters correctly and our team is working on a fix for this. We will release this fix in our next release which will be available on the WordPress plugin repository on Friday or early next week.
If you want you can also reach out to us using the support from in the plugin and we can provide you with a quick patch before the release.
Thanks,
Team miniOrangein reply to: Backslahes in URI componentsohamj
Participant# 2 years, 11 months agoHi There,
Thank you for getting in touch with us. I understand that you’re looking to implement restrictions for specific users on your WordPress site so that these users cannot perform SSO instead they can use the WordPress login form to log into the website.
Our OAuth Client plugin allows you to restrict SSO access based on attributes returned by the identity provider. Please let us know which attributes you would like to use to restrict SSO access. You can find a comprehensive overview of all premium features here: [LINK]
Feel free to reach out to us at oauthsupport@xecurify.com for further discussions.
in reply to: How do I exclude a user by username or email?sohamj
Participant# 3 years, 8 months agoHi There,
Thanks for reaching out to us.
As per my understanding, you want to login into your WordPress site using the credentials of your CRM, Also, you want to enable registration on the CRM itself and new users should be able to authenticate themselves using the credentials of the CRM. Please correct me if I’m wrong.
Can you please let me know which CRM you are using? So that I can guide you accordingly.
Thanks,
Prashant Khuranain reply to: Authentication by CRMsohamj
Participant# 5 years agoThe feature you are looking for is not in our free plugin, You can upgrade to our premium version.
Some of which popular features are shown below:1. Custom Role Mapping based on groups in AD.
2. Custom Attribute Mapping.
3. Custom Search Filter with Group Restriction
4. Multiple Search Bases
5. WP to LDAP profile update
6. Authenticate users from both LDAP and WordPress
7. Redirect to custom URL after authentication
8. Support for LDAPS Connectionin reply to: logging in with both LDAP user account and WordPresssohamj
Participant# 5 years, 1 month agoHi there,
Welcome to the miniOrange forum.
Looking at the logs, it seems the plugin is unable to identify the SSO user, and as a result, it is unable to assign any groups and create a user session. This problem usually occurs when the username and email mapping in the “User Profile” tab is wrong.
To fix this issue, please follow the steps below.
1. Navigate to the “Configure OAuth” Tab and click on the “Test Configuration” button. You will see all the user information here.
2. Keep the Test Configuration window open and navigate to the “User Profile” tab of the plugin.
3. Copy the Attribute name that contains the Confluence username and email of the user and map that attribute with the respective username and email field. In case if you do not find the Confluence username then select the “Login/Create User Account by” option to “Email”.In case if you still face this issue, please raise a Support request to miniOrange Helpdesk and the technical team will help you out with the configuration. You can raise a support request from the link below.
https://miniorange.atlassian.net/servicedesk/customer/portal/2
sohamj
Participant# 5 years, 5 months agoHi There,
miniOrange Captive portal supports login with social login apps like Facebook, Linked-in, Instagram, etc. to connect with captive WIFI/network.
You can choose the social login apps you want to show to your users and on the login page of your captive portal, they will see the option for login with those social login apps.
Your users can choose the application by which they want to log in if there are multiple applications are available to them. Once they click on the application ( like Facebook, linked in, etc) They will be forwarded to the site and based on the response they will be logged in to the captive WIFI.You can send us a query at info@xecurify.com / 2fasupport@xecurify.com we are happy to help you.
in reply to: Captive portal with Facebook login ?sohamj
Participant# 5 years, 5 months agoHi There,
miniOrange supports Radius authentication to verify the users when they connect to the captive wifi/Network. The users will be prompted with the login page of the Captive portal when they connect to the wifi. They need to enter their username and password of the Active Directory.
Captive portal will send a request to the radius server and based on the response it will allow and disallow their connection request.
You can also enable the two-factor authentication with OTP Over SMS, OTP Over Email, and many more authentication methods on top of radius authentication.You can send us a query at info@xecurify.com / 2fasupport@xecurify.com we are happy to help you.
sohamj
Participant# 5 years, 5 months agoHi There,
miniOrange supports Radius authentication to verify the users when they connect to the captive wifi/Network. The users will be prompted with the login page of the Captive portal when they connect to the wifi. They need to enter their username and password of the Active Directory.
Captive portal will send a request to the radius server and based on the response it will allow and disallow their connection request.
You can also enable the two-factor authentication with OTP Over SMS, OTP Over Email, and many more authentication methods on top of radius authentication.You can send us a query at info@xecurify.com / 2fasupport@xecurify.com we are happy to help you.
sohamj
Participant# 5 years, 5 months agoHi There,
You can easily set-up Two Factor Authentication(TFA) / 2FA for users connecting to companies WIFI portal by using Captive Portal login. We do provide 2-Factor Authentication(2FA) on connection to WIFI. Your users need to enter their username and password which can be in any IDP/AD/Database.
After this they will be prompted with the configured second Factor Authentication(2FA) method.It will allow you to block Internet access for all users until they complete their authentication. This helps you in securing your network, protecting your users and collecting customer data simultaneously.
We do provide 15+ authentication methods including OTP Over SMS, OTP Over Email, Google authenticator, etc.
Please send us a query at info@xecurify.com / 2fasupport@xecurify.com so that we can help you in setting up 2FA for your WIFI.
sohamj
Participant# 5 years, 5 months agoHi There,
Captive portal can be enabled and disabled by using the scheduler. With this captive portal scheduler, you can :
1. Either disable the captive portal so during that time period nobody needs to verify themselves using the captive portal WIFI.
2. Or you can disable the user login so for that period of time your users will not be able to login into the captive portal.Benefits:
This will protect your WIFI when the workplace is closed.
This would ensure secure access at all times, as you can enable captive WIFI anytime.You can send us a query at info@xecurify.com / 2fasupport@xecurify.com so that we can help you in setting up enabling/disabling of Captive portal.
sohamj
Participant# 5 years, 6 months agoHi There,
You can restrict the maximum number of users connecting to WiFi by using the Captive portal.
Captive portal will count the active connection to WiFi and based on that it will restrict the new connection to that captive WiFi.
Captive portal will help you to restrict the number of devices that can use your WiFi.The captive portal is presented to the client and is stored either at the gateway or on a web server hosting the web page. After authentication the clients MAC address is stored, as a form of verification.
To upgrade the security of an account an admin can apply a limit to the number of current sessions a user may have open to between 1 and n. When a user attempts to login and open a new login session beyond the defined limit, the user will be logged out of their previous inactive session.
You can send us a query at info@xecurify.com or 2fasupport@xecurify.com we are happy to help you
sohamj
Participant# 5 years, 10 months agoYeah, it’s possible but there’s a lot of things you would have to change. Specially in the HTML file of the captive portal login page.
in reply to: How do you add advertisements in a captive portal