Skip to main content

BriefCam Installation Guide

SAML – ADFS Relying Party Setup for BriefCam Requirements

Last Updated: 4 minute read
Version2024r2
LanguageEnglish
  1. To use ADFS to log in to your BriefCam instance, you need the following components:

    • An Active Directory instance.

    • This guide uses screenshots from Server 2012R2, but similar steps should be possible on other versions.

    • An SSL certificate to sign your ADFS login page and the fingerprint for that certificate.

    • After you meet these basic requirements, you need to install ADFS on your server. Configuring and installing ADFS is beyond the scope of this guide, but is detailed in a Microsoft KB article.

    Note

    BriefCam uses the user’s email provided by ADFS as part of the SAML assertions in order to identify the user.

  2. When you have a fully installed ADFS installation, note down the value for the SAML 2.0/W-Federation URL in the ADFS Endpoints section. If you chose the defaults for the installation, this will be '/adfs/ls/'.

Step 1: Adding a Relying Party Trust

  1. At this point you should be ready to set up the ADFS connection with your BriefCam instance. The connection between ADFS and BriefCam is defined using a Relying Party Trust (RPT).

  2. Select the Relying Party Trusts folder from ADFS Management, and add a new Standard Relying Party Trust from the Actions sidebar. This starts the configuration wizard for a new trust.

    SAML welcome.png
  3. In the Select Data Source screen, select the last option, Enter data about the relying party manually.

    SAML select source.png
  4. On the next screen, enter a Display name that you'll recognize in the future, and any notes you want to make.

    SAML display name.png
  5. On the next screen, select the AD FS profile radio button.

    SAML AD FS profile.png
  6. On the next screen, leave the certificate settings with their defaults.

    SAML configure certificate.png
  7. On the next screen, check the box labeled Enable Support for the SAML 2.0 WebSSO protocol. The service URL will be: https://<WebServices>/ProWebApi/AuthenticationApi/AuthenticateSaml

    Replace <WebServices> with your BriefCam WebServices server address. Note that there's no trailing slash at the end of the URL.

    SAML Enable support for protocol.png
  8. On the next screen, add a Relying party trust identifier.

    https://<WebServices>/prowebapi must match the exact prowebapi address in the settings (it is case sensitive).

    Replace <WebServices> with your BriefCam Web Services server address.

    SAML relying identifier.png

    HTTPS is required in the address.

  9. On the next screen, you can configure multi-factor authentication but this is beyond the scope of this guide.

    SAML multi-factor.png
  10. On the next screen, select the Permit all users to access this relying party radio button.

    SAML permit all.png
  11. On the next two screens, the wizard will display an overview of your settings. On the final screen, use the Close button to exit and open the Claim Rules editor.

    SAML claim rules.png

Step 2: Creating Claim Rules

Once the relying party trust has been created, you can create the claim rules.

  1. To create a new rule, click on Add Rule. Create a Send LDAP Attributes as Claims rule.

    SAML claim rule template.png
  2. On the next screen, using Active Directory as your attribute store, do the following:

    • From the LDAP Attribute column, select E-Mail Addresses.

    • From the Outgoing Claim Type, select E-Mail Address.

      SAML configure rule.png
  3. Repeat step for UPN.

  4. Click OK to save the new rule.

Step 3: Configuring BriefCam

  1. After setting up ADFS, you need to configure your BriefCam instance to authenticate using SAML.

  2. You'll use your full ADFS server URL with the SAML endpoint as the SSO URL.

  3. The fingerprint will be the fingerprint of the token signing certificate installed in your ADFS instance. In the Windows certificate utility, this is also referred to as the SHA-1 Thumbprint.

  4. Export the ADFS token signing certificate (on the ADFS server) in PowerShell as admin:

    $certRefs=Get-AdfsCertificate -CertificateType Token-Signing

    $certBytes=$certRefs[0].Certificate.Export([System.Security.Cryptography.X509Certificates.X509ContentType]::Cert)

    [System.IO.File]::WriteAllBytes("c:\foo.cer", $certBytes)

  5. Copy c:\foo.cer to the BriefCam server.

  6. Launch mmc.

  7. File -> add remove snap ins.

  8. Certificates -> add -> computer account -> local computer.

  9. Go to Certificates -> Personal -> Certificates.

  10. Right click on Certificates and select All Tasks -> Importfoo.cer.

    SAML import certificate.png
  11. Double click the new certificate, go to the details tab and copy the certificate thumbprint.

  12. Paste the thumbprint into a text editor, remove the spaces, then copy and paste it into the ProWebAPI section in the web admin > Settings SamlCertificate field.

  13. Configure the following fields in the BriefCam Administrator Console's environment settings:

    • SamlLoginUrl = https:// <ADFS Server address>/adfs/ls/idpinitiatedsignon

    • SamlLogoutUrl = ADFS server logout URL

    • SamlCertificate = <SAML Certificate>

    Note

    Do not change the ProWebApiAddress and ProWebClientAddress environment settings (leave the default values).

  14. In IIS manager on the WebServices computer, go to BriefCam Web Services > Bindings > Add, from the Type drop-down menu, select https and click OK.

    SAML Add binding.png
  15. Restart the IIS Services (by opening the Windows services, right-clicking on the World Wide Web Publishing Service and clicking Restart).

  16. You should now be set up and ready to go. To test, run: https://localhost/authenticationApi/RequestAuthenticationRoute

If you were re-routed to the login page, logged in, and received a valid output (session id and username), congratulations you have successfully survived this guide.

Otherwise, make sure you followed all the steps correctly.