Add and manage custom SAML resources

Path to function: Resources > Catalogue > Custom

Custom resources, once created, can be allocated to permission sets like any other resource. This page is about custom SAML resources rather than basic custom resources.

Custom SAML resources were developed for single sign-on to systems like your VLE, G Suite or Adobe Creative Cloud. They can also provide peer-to-peer access to SAML resources that lack enough subscribers to benefit from membership of a federation (which makes things much easier for all parties). In both situations, they should work for any SAML target that adheres to the SAML 2 core specification.

Because SAML requires a resource to have a unique identifier (entityID), custom resources can only be added at the domain level by users with the owner role. You will also need to supply the resource with your OpenAthens details. See How to access your login.openathens.net metadata.

Custom SAML resources appear in the Custom tab of the resource catalogue and are identified by a 'SAML' tag.

Example of a custom SAML resource called 'Google Apps'. Beside the title and description of the resource is the label 'saml'.

They appear in reports alongside regular and proxy resources.  

Add a custom SAML resource

  1. Log in to OpenAthens Compass as an administrator with the owner role.

  2. Go to Resources > Catalogue and select the Custom tab.

    Custom tab of the resource catalogue. The main content area currently displays the message 'No resources found'. There are buttons labeled 'Create' and 'Allocate resources'.
  3. Press the Create button. A pop-up window opens.

    Pop-up window titled 'Select resource type'. It has two options - 'Custom resource. Add a custom resource by manually entering the details' and 'SAML. Connect to a service provider using SAML 2.0'. At the bottom of the window are 'Configure' and 'Cancel' buttons.
  4. Select the SAML option and press Configure. You can then provide the details of the resource.

    Pop-up window titled 'Add a SAML resource'. Advisory text reads, 'Upload SAML 2 metadata via URL or file'. There is a text field labeled 'Metadata URL', followed by a file upload field. At the bottom of the window are buttons labeled 'Create resource' and 'Cancel'.
  5. Either:

    1. Enter the URL of the resource’s metadata in the Metadata URL field, or

    2. Press Choose File and upload the metadata file from your computer. The file must be in .xml format.

  6. Press Create resource. The new resource appears in your catalogue.

  7. Open the resource to customise details such as its title (which, by default, is pulled from the entityID in the metadata), its description and its logo.

    Details of a custom SAML resource called 'Acme'. The left sidebar displays a default logo, a status selector (set to 'Allocated'), the type of the resource ('SAML') and the entityID. The main content area has four tabs - 'Resource details' (currently open), 'Visibility', 'Certificates' and 'SAML'. The 'Resource details' tab contains the fields 'Title', 'Description', 'Information URL', 'Access URL' and 'Categories', and a checkbox labeled 'Hidden from users'. At the top right is a 'Save changes' button.
  8. Save your changes.

You will almost always need to tell the other application about your own metadata or endpoints before it will work. Typically, you must add a custom release policy so that the target receives the attributes it is expecting. There are examples of setting up a custom release policy for Google Workspace and Adobe Creative Cloud.

After submitting, it can take a few minutes for the resource to go live.

SAML 1.x is not supported for this type of connection.

Manage an existing custom SAML resource

You can edit the title, description and other details of an existing resource, view certificate details and update the metadata. You might need to update the metadata if, for example, the resource changes its certificates or endpoints.

Update metadata only if necessary. Updating metadata will overwrite other custom settings.

If you delete and recreate a resource, you will need to reassign the resource to any permission sets that were previously allocated.

Delete a custom SAML resource

  1. Go to Resources > Catalogue and select the Custom tab.

    custom-resouces-main-full.png
  2. Click the name of the resource to go to its editing screen.

    'Modify resource' screen of a custom resource. At the top of the page are buttons labeled 'Delete custom resource', which is highlighted, and 'Save changes'.
  3. Press the Delete custom resource button. You are asked to confirm this action before the resource is deleted.

    Pop-up dialog titled 'Delete custom resource'. A message reads, 'Please confirm you wish to delete this custom resource. Deleted resource are removed from all permission sets that contain them including those of sub-administrators. This operation cannot be undone.' Following this are 'Delete' and 'Cancel' buttons.
  4. Press Delete to confirm.

Allocate a custom SAML resource

You can allocate custom SAML resources to permission sets in the same way that you allocate other resources.

Anything to watch out for?

Every few years, we have to update a security certificate which will affect these connections and require an update at the resource end. Since that end is both variable and unknown to us, we recommend you make and keep notes on how the resource end is configured. It could be as long as nine years before you need to refer to those notes, so local retention policies might be relevant.

If a SAML resource does not adhere to the SAML 2 core specification, it might not be able to work with OpenAthens this way. Our service desk will be happy to put the publisher in touch with someone who can talk to them about the benefits of federation membership.