Skip to content

Configure Watchguard AuthPoint

Chris Gralike edited this page Nov 5, 2025 · 1 revision

These instructions were extracted from the documentation available. The author does not have access to a watchguard environment. Please report any incorrect instructions by creating an issue.

How to Configure samlsso with Watchguard AuthPoint

This guide provides a step-by-step walkthrough for configuring Watchguard AuthPoint as an Identity Provider (IdP) for the samlsso plugin (Service Provider) in GLPI.

This guide assumes you have administrative access to both your GLPI instance and your Watchguard Cloud account.

Overview

The configuration is a four-part process:

  1. Get Service Provider (SP) Info from samlsso - Get your unique GLPI URLs from the plugin.
  2. Configure AuthPoint Resource - Create a new SAML application in Watchguard Cloud.
  3. Finalize samlsso Configuration - Enter the AuthPoint details back into the samlsso plugin.
  4. Add AuthPoint Policy - Allow users to access the new GLPI resource.

Get Service Provider (SP) Info from samlsso (GLPI)

Before you can configure AuthPoint, you need to know what URLs to give it. Your plugin generates unique URLs for each IdP.

  1. In GLPI, navigate to Setup > Plugins > samlsso.
  2. Click the + icon to add a new Identity Provider.
  3. Give it a name (e.g., Watchguard AuthPoint) and click Add.
  4. Find your new "Watchguard AuthPoint" configuration in the list and note its ID (e.g., 1). This ID is part of your unique URLs.
  5. You now have the two critical pieces of information for AuthPoint:
    • SP Entity ID:
      • Go to the Service Provider tab in the plugin's main config.
      • Copy the value from the GLPI URL (Entity ID) field. This is your Service Provider Entity ID.
      • (Example: https://glpi.yourcompany.com)
    • ACS URL:
      • Go back to the configuration page for your "Watchguard AuthPoint" IdP (ID 1).
      • Go to the Identity Provider (IdP) Configuration tab.
      • Copy the Assertion Consumer Service (ACS) URL.
      • (Example: https://glpi.yourcompany.com/plugins/samlsso/front/acs/1)

Keep these two values ready.

Configure AuthPoint resource (Watchguard Cloud)

Now, log in to your Watchguard Cloud account to create the SAML application.

  1. Navigate to Configure > AuthPoint > Resources.
  2. Click Add Resource. From the dropdown, select SAML.
  3. Fill in the configuration fields:
    • Name: GLPI (or any friendly name you prefer).
    • Service Provider Entity ID: Paste the SP Entity ID (your GLPI base URL) from Part 1.
    • Assertion Consumer Service (ACS) URL: Paste the ACS URL (ending in /acs/1) from Part 1.

Configure SAML Attributes This is an important step. You must tell AuthPoint to send attributes with the exact names that the samlsso plugin will look for.

  1. In the SAML Attributes section, click Add Attribute.
  2. Create the following attributes. The Name must be exactly as written below. The Value is the attribute from your identity store (like Active Directory) that you want to send.
    • Attribute 1: Login Name
      • Name: username
      • Value: Select sAMAccountName (or userPrincipalName, whichever your users log in with).
    • Attribute 2: Email
      • Name: email
      • Value: Select mail
    • Attribute 3: Last Name
      • Name: lastname
      • Value: Select sn
    • Attribute 4: First Name
      • Name: firstname
      • Value: Select givenName
  3. Click Save to create the resource.

Finalize samlsso Configuration (GLPI)

AuthPoint has now generated its own metadata. You need to copy this into GLPI.

  1. In your Watchguard AuthPoint dashboard, find the GLPI resource you just created.
  2. Download the Identity Provider metadata file. This is an XML file.
  3. Open the XML file with a text editor and copy the following three values:
    • The entityID (this is the IdP's Entity ID, e.g., https://authpoint.watchguard.com/saml/...).
    • The SingleSignOnService URL (look for the HTTP-Redirect binding).
    • The X509Certificate (the long string of characters).
  4. Go back to your samlsso plugin config in GLPI (Setup > Plugins > samlsso) and edit your "Watchguard AuthPoint" IdP.
  5. Fill in the Identity Provider (IdP) Configuration tab:
    • IdP Entity ID: Paste the entityID from the XML.
    • Single Sign-On Service (SSO) URL: Paste the SingleSignOnService URL from the XML.
    • x.509 Certificate: Paste the X509Certificate from the XML.
  6. Under the General tab, check Enable Identity Provider.
  7. Click Save.

Add AuthPoint policy

Finally, you must give your users permission to use this new application.

  1. In Watchguard Cloud, navigate to Configure > AuthPoint > Authentication Policies.
  2. Click Add Policy.
  3. Select the GLPI resource and the user/groups who should have access.
  4. Click Save.

Your configuration is now complete. Users can test the login by navigating to the GLPI login page and clicking the new "Login with Watchguard AuthPoint" button.

Clone this wiki locally