Configure SSO for Multiple Institutions
A single Pressbooks network can be integrated with multiple institution’s single sign on services using our Open ID Connect (OIDC) plugin. This plugin enables users from multiple institutions to create accounts and log into a single shared Pressbooks network with their institutional credentials. If your Pressbooks network is used by a single school, our SAML2 SSO plugin will be the better option for your institution.
Setting this up may require assistance from the people who manage Identity and Access Management at each institution, since we will need to exchange metadata between our Service Provider (SP) and their Identity Provider (IdP). Details about the metadata exchange and required claims are included at the bottom of this guide chapter.
OIDC Log In Flow
When correctly configured, the login flow for this plugin is as follows:
- From the login page the user selects ‘Institutional Login’ (this step can be bypassed, using a configuration setting)
- The user is brought to a “Where Are You From” (WAYF) wayfinder tool which allows them to select their institution. They should select the institution for which they have login credentials.
- Once they have entered their institution, they will be redirected to their institution’s login page, and will be prompted to enter their NetID and password.
- Their institution’s IdP authenticates the user and sends the Pressbooks service provider a set of claims about the authenticated user.
- Pressbooks checks the security domain from this claim against a lise of approved security domains for this particular network. If a match is found, Pressbooks then checks to see whether a matching user exists. If a matching user is found, the user is logged in as this person.
- If no matching user is found, Pressbooks either creates a new account for this user or refuses access, depending on the configuration setting.
The video below shows this login flow for a test user using the SAMLtest service as the IdP.
Configuration Settings
High-level configuration of the OIDC SSO plugin will be handled by the Pressbooks support team. However, Network Managers can configure a few additional settings as they prefer after the integration has been completed. To navigate to the OIDC settings page, go to the Network Admin dashboard. Then, select Integrations > OIDC from the left sidebar menu. The OIDC settings page can be found at located at https://[YOURNETWORKURL]/wp-admin/network/admin.php?page=pb_oidc_admin
If the OIDC User does not have a Pressbooks account
This setting controls what happens if Pressbooks receives an authenticated user from an authorized institution. If you would like all users from your institution(s) to have accounts created in Pressbooks the first time they login with their institutional credentials, select Add New User from the dropdown menu. This option allows your institution to use SSO as a method of self-registration.
If you would like only pre-existing users to be a