Ad Widget

Collapse

Zabbix SAML with Azure AD

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • joostdeheer
    Junior Member
    • Feb 2022
    • 7

    #16
    I've created a howto where all the steps are explained in detail:

    Comment

    • LenR
      Senior Member
      • Sep 2009
      • 1005

      #17
      Just when you get it working.... https://www.bleepingcomputer.com/new...abbix-servers/

      Comment

      • Ngk
        Junior Member
        • Aug 2022
        • 10

        #18
        We have users in Azure AD and while we tried to sign using SSO asking to create user in Zabbix.

        How to synch the users between Azure AD and Zabbix?

        Comment

        • cyber
          Senior Member
          Zabbix Certified SpecialistZabbix Certified Professional
          • Dec 2006
          • 4806

          #19
          Probably over API.
          Automatic user creation is mentioned in roadmap for v6.4
          JIT user provisioning In design
          Support automatic user creation after successful AD, LDAP, or SAML authentication. It will allow remote management of users and their permissions

          Comment

          • Ngk
            Junior Member
            • Aug 2022
            • 10

            #20
            How to get roadmap v6.4? When i click on Download it shows v6.2 only.

            Please share the reference link.
            Click image for larger version  Name:	image.png Views:	0 Size:	44.1 KB ID:	450847

            https://www.zabbix.com/roadmap

            Comment

            • bbs2web
              Junior Member
              • Apr 2016
              • 22

              #21
              Hope this helps someone else, we previously configured Apache to use Kerberos authentication from domain joined workstations and had our users defined as the Active Directory SamAccountName (eg davidh):
              Click image for larger version

Name:	image.png
Views:	1873
Size:	2.8 KB
ID:	454587




              We subsequently configured SAML in the Azure AD Enterprise Application registration to add an additional claim called 'username' where we then use the SamAccountName field from the account sync'd to Azure AD from our on-premises AD:
              Click image for larger version

Name:	image.png
Views:	1808
Size:	31.7 KB
ID:	454588



              Zabbix SAML integration was configured to use the custom claim field 'username':
              Click image for larger version

Name:	image.png
Views:	1803
Size:	33.0 KB
ID:	454589



              Lastly download the Azure AD application certificate and store it as 'idp.crt' whilst creating a certificate for Zabbix:
              Click image for larger version

Name:	image.png
Views:	1811
Size:	5.6 KB
ID:	454590

              Created 'sp.crt' and 'sp.key' with the following command:
              openssl req -x509 -newkey rsa:4096 -keyout /usr/share/zabbix/conf/certs/sp.key -out /usr/share/zabbix/conf/certs/sp.crt -sha256 -days 1825 -nodes

              Comment

              • Akash Malviya
                Junior Member
                • Mar 2023
                • 1

                #22
                I Have tried the steps mentioned in the post to do the setup but it's not working . Getting error-
                • Invalid array settings: idp_cert_or_fingerprint_not_found_and_required
                ​I have added the idp.crt in ~/conf/certs . Can someone please help ?​


                Click image for larger version

Name:	Screenshot from 2023-03-03 13-39-37.png
Views:	1458
Size:	47.2 KB
ID:	460398

                Click image for larger version

Name:	Screenshot from 2023-03-03 13-43-33.png
Views:	1407
Size:	83.3 KB
ID:	460399


                Comment

                Working...