Single Sign-On (SSO) Support for SafeNet App Gateway
Single Sign-On (SSO) support for SafeNet App Gateway signifies its capability to facilitate seamless SSO operations while accessing non-standard web applications (that do not support SAML 2.0 or OIDC protocol) that are protected by SafeNet Trusted Access (STA). Users are authenticated once and gain access to multiple applications without the necessity of repeated logins for each application.
The following table shows the SSO behavior when two applications with the same or different authentication schemes are hosted on the same web or application server.
Similar behavior, as enlisted below, is also expected if more than two applications are hosted on the same (single) web or application server and protected by a single SafeNet App Gateway instance.
Use Case | Application | Authentication Scheme | Workflow | Conclusion |
---|---|---|---|---|
1 | Application 1 Application 2 |
Custom Custom |
|
Reauthentication is not required for application 2. |
2 | Application 1 Application 2 |
Basic Custom |
|
Reauthentication is not required for application 2. |
3 | Application 1 Application 2 |
Custom Basic |
|
Reauthentication is required for application 2 using the application credentials only and not for the STA IdP as it maintains a STA IdP session. |
4 | Application 1 Application 2 |
Basic Basic |
|
Reauthentication is not required for application 2. |
5 | Application 1 Application 2 |
Custom Form-based |
|
Reauthentication is required for application 2 using the application credentials only and not for the STA IdP as it maintains a STA IdP session. |
6 | Application 1 Application 2 |
Form-based Custom |
|
Reauthentication is not required for application 2. |
7 | Application 1 Application 2 |
Form-based Basic |
|
Reauthentication is not required for application 2. |
8 | Application 1 Application 2 |
Basic Form-based |
|
Reauthentication is not required for application 2. | 9 | Application 1 Application 2 |
Form-based Form-based |
|
Reauthentication is not required for application 2. |
Access to multiple applications without re-authentication depends on the active SSO session, which lasts for eight hours in STA. For more information, refer to the Single sign-on session timeout section.