identity_providers
Creates, updates, deletes, gets or lists an identity_providers resource.
Overview​
| Name | identity_providers |
| Type | Resource |
| Id | sumologic.saml.identity_providers |
Fields​
The following fields are returned by SELECT queries:
- list
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier of the SAML Identity Provider. (example: 00000000361130F7) |
entity_id | string | A unique identifier that is the intended audience of the SAML assertion. (example: https:​//service.sumologic.com/sumo/saml/9483922, default: ) (wire: entityId) |
configuration_name | string | Name of the SSO policy or another name used to describe the policy internally. (example: SumoLogic) (wire: configurationName) |
assertion_consumer_url | string | The URL on Sumo Logic where the IdP will redirect to with its authentication response. (example: https:​//service.sumologic.com/sumo/saml/consume/9483922, default: ) (wire: assertionConsumerUrl) |
authn_request_url | string | The URL that the identity provider has assigned for Sumo Logic to submit SAML authentication requests to the identity provider. (example: https:​//www.okta.com/app/sumologic/abxcseyuiwelflkdjh/sso/saml, default: ) (wire: authnRequestUrl) |
certificate | string | Authentication Request Signing Certificate for the user. |
created_at | string (date-time) | Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt) |
created_by | string | Identifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy) |
debug_mode | boolean | True if additional details are included when a user fails to sign in. (wire: debugMode) |
disable_requested_authn_context | boolean | True if Sumo Logic will include the RequestedAuthnContext element of the SAML AuthnRequests it sends to the identity provider. (wire: disableRequestedAuthnContext) |
email_attribute | string | The email address of the new user account. (example: attribute/subject, default: ) (wire: emailAttribute) |
is_redirect_binding | boolean | True if the SAML binding is of HTTP Redirect type. (wire: isRedirectBinding) |
issuer | string | The unique URL assigned to the organization by the SAML Identity Provider. (example: http:​//www.okta.com/abxcseyuiwelflkdjh) |
logout_enabled | boolean | True if users are redirected to a URL after signing out of Sumo Logic. (wire: logoutEnabled) |
logout_url | string | The URL that users will be redirected to after signing out of Sumo Logic. (example: https:​//www.sumologic.com, default: ) (wire: logoutUrl) |
metadata_url | string | The URL to fetch SAML metadata XML. (example: https:​//api.sumologic.com/api/v1/saml/identityProviders/00000000361130F7/metadata, default: ) (wire: metadataUrl) |
modified_at | string (date-time) | Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt) |
modified_by | string | Identifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy) |
on_demand_provisioning_enabled | object | (wire: onDemandProvisioningEnabled) |
roles_attribute | string | The role that Sumo Logic will assign to users when they sign in. (example: Sumo_Role, default: ) (wire: rolesAttribute) |
sign_authn_request | boolean | True if Sumo Logic will send signed Authn requests to the identity provider. (wire: signAuthnRequest) |
sp_initiated_login_enabled | boolean | True if Sumo Logic redirects users to your identity provider with a SAML AuthnRequest when signing in. (wire: spInitiatedLoginEnabled) |
sp_initiated_login_path | string | This property has been deprecated and is no longer used. (example: http:​//www.okta.com/abxcseyuiwelflkdjh, default: ) (wire: spInitiatedLoginPath) |
x_509cert_1 | string | The certificate is used to verify the signature in SAML assertions. (wire: x509cert1) |
x_509cert_2 | string | The backup certificate used to verify the signature in SAML assertions when x509cert1 expires. (default: ) (wire: x509cert2) |
x_509cert_3 | string | The backup certificate used to verify the signature in SAML assertions when x509cert1 expires and x509cert2 is empty. (default: ) (wire: x509cert3) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | region | Get a list of all SAML configurations in the organization. | |
create | insert | region, configuration_name, issuer, x_509cert_1 | Create a new SAML configuration in the organization. | |
update | update | id, region, configuration_name, issuer, x_509cert_1 | Update an existing SAML configuration in the organization. | |
delete | delete | id, region | Delete a SAML configuration with the given identifier from the organization. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
id | string | Identifier of the SAML configuration to delete. |
region | string | Sumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT) |
SELECT examples​
- list
Get a list of all SAML configurations in the organization.
SELECT
id,
entity_id,
configuration_name,
assertion_consumer_url,
authn_request_url,
certificate,
created_at,
created_by,
debug_mode,
disable_requested_authn_context,
email_attribute,
is_redirect_binding,
issuer,
logout_enabled,
logout_url,
metadata_url,
modified_at,
modified_by,
on_demand_provisioning_enabled,
roles_attribute,
sign_authn_request,
sp_initiated_login_enabled,
sp_initiated_login_path,
x_509cert_1,
x_509cert_2,
x_509cert_3
FROM sumologic.saml.identity_providers
WHERE region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;
INSERT examples​
- create
- Manifest
Create a new SAML configuration in the organization.
INSERT INTO sumologic.saml.identity_providers (
sp_initiated_login_path,
configuration_name,
issuer,
sp_initiated_login_enabled,
authn_request_url,
x_509cert_1,
x_509cert_2,
x_509cert_3,
on_demand_provisioning_enabled,
roles_attribute,
logout_enabled,
logout_url,
email_attribute,
debug_mode,
sign_authn_request,
disable_requested_authn_context,
is_redirect_binding,
region
)
SELECT
'{{ sp_initiated_login_path }}',
'{{ configuration_name }}' /* required */,
'{{ issuer }}' /* required */,
{{ sp_initiated_login_enabled }},
'{{ authn_request_url }}',
'{{ x_509cert_1 }}' /* required */,
'{{ x_509cert_2 }}',
'{{ x_509cert_3 }}',
'{{ on_demand_provisioning_enabled }}',
'{{ roles_attribute }}',
{{ logout_enabled }},
'{{ logout_url }}',
'{{ email_attribute }}',
{{ debug_mode }},
{{ sign_authn_request }},
{{ disable_requested_authn_context }},
{{ is_redirect_binding }},
'{{ region }}'
RETURNING
id,
entity_id,
configuration_name,
assertion_consumer_url,
authn_request_url,
certificate,
created_at,
created_by,
debug_mode,
disable_requested_authn_context,
email_attribute,
is_redirect_binding,
issuer,
logout_enabled,
logout_url,
metadata_url,
modified_at,
modified_by,
on_demand_provisioning_enabled,
roles_attribute,
sign_authn_request,
sp_initiated_login_enabled,
sp_initiated_login_path,
x_509cert_1,
x_509cert_2,
x_509cert_3
;
# Description fields are for documentation purposes
- name: identity_providers
props:
- name: region
value: "{{ region }}"
description: Required parameter for the identity_providers resource.
- name: sp_initiated_login_path
value: "{{ sp_initiated_login_path }}"
description: |
This property has been deprecated and is no longer used.
default:
- name: configuration_name
value: "{{ configuration_name }}"
description: |
Name of the SSO policy or another name used to describe the policy internally.
- name: issuer
value: "{{ issuer }}"
description: |
The unique URL assigned to the organization by the SAML Identity Provider.
- name: sp_initiated_login_enabled
value: {{ sp_initiated_login_enabled }}
description: |
True if Sumo Logic redirects users to your identity provider with a SAML AuthnRequest when signing in.
default: false
- name: authn_request_url
value: "{{ authn_request_url }}"
description: |
The URL that the identity provider has assigned for Sumo Logic to submit SAML authentication requests to the identity provider.
default:
- name: x_509cert_1
value: "{{ x_509cert_1 }}"
description: |
The certificate is used to verify the signature in SAML assertions.
- name: x_509cert_2
value: "{{ x_509cert_2 }}"
description: |
The backup certificate used to verify the signature in SAML assertions when x509cert1 expires.
default:
- name: x_509cert_3
value: "{{ x_509cert_3 }}"
description: |
The backup certificate used to verify the signature in SAML assertions when x509cert1 expires and x509cert2 is empty.
default:
- name: on_demand_provisioning_enabled
value:
firstNameAttribute: "{{ firstNameAttribute }}"
lastNameAttribute: "{{ lastNameAttribute }}"
onDemandProvisioningRoles:
- "{{ onDemandProvisioningRoles }}"
- name: roles_attribute
value: "{{ roles_attribute }}"
description: |
The role that Sumo Logic will assign to users when they sign in.
default:
- name: logout_enabled
value: {{ logout_enabled }}
description: |
True if users are redirected to a URL after signing out of Sumo Logic.
default: false
- name: logout_url
value: "{{ logout_url }}"
description: |
The URL that users will be redirected to after signing out of Sumo Logic.
default:
- name: email_attribute
value: "{{ email_attribute }}"
description: |
The email address of the new user account.
default:
- name: debug_mode
value: {{ debug_mode }}
description: |
True if additional details are included when a user fails to sign in.
default: false
- name: sign_authn_request
value: {{ sign_authn_request }}
description: |
True if Sumo Logic will send signed Authn requests to the identity provider.
default: false
- name: disable_requested_authn_context
value: {{ disable_requested_authn_context }}
description: |
True if Sumo Logic will include the RequestedAuthnContext element of the SAML AuthnRequests it sends to the identity provider.
default: false
- name: is_redirect_binding
value: {{ is_redirect_binding }}
description: |
True if the SAML binding is of HTTP Redirect type.
default: false
UPDATE examples​
- update
Update an existing SAML configuration in the organization.
UPDATE sumologic.saml.identity_providers
SET
sp_initiated_login_path = '{{ sp_initiated_login_path }}',
configuration_name = '{{ configuration_name }}',
issuer = '{{ issuer }}',
sp_initiated_login_enabled = {{ sp_initiated_login_enabled }},
authn_request_url = '{{ authn_request_url }}',
x_509cert_1 = '{{ x_509cert_1 }}',
x_509cert_2 = '{{ x_509cert_2 }}',
x_509cert_3 = '{{ x_509cert_3 }}',
on_demand_provisioning_enabled = '{{ on_demand_provisioning_enabled }}',
roles_attribute = '{{ roles_attribute }}',
logout_enabled = {{ logout_enabled }},
logout_url = '{{ logout_url }}',
email_attribute = '{{ email_attribute }}',
debug_mode = {{ debug_mode }},
sign_authn_request = {{ sign_authn_request }},
disable_requested_authn_context = {{ disable_requested_authn_context }},
is_redirect_binding = {{ is_redirect_binding }}
WHERE
id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND configuration_name = '{{ configuration_name }}' --required
AND issuer = '{{ issuer }}' --required
AND x_509cert_1 = '{{ x_509cert_1 }}' --required
RETURNING
id,
entity_id,
configuration_name,
assertion_consumer_url,
authn_request_url,
certificate,
created_at,
created_by,
debug_mode,
disable_requested_authn_context,
email_attribute,
is_redirect_binding,
issuer,
logout_enabled,
logout_url,
metadata_url,
modified_at,
modified_by,
on_demand_provisioning_enabled,
roles_attribute,
sign_authn_request,
sp_initiated_login_enabled,
sp_initiated_login_path,
x_509cert_1,
x_509cert_2,
x_509cert_3;
DELETE examples​
- delete
Delete a SAML configuration with the given identifier from the organization.
DELETE FROM sumologic.saml.identity_providers
WHERE id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;