Skip to main content

identity_providers

Creates, updates, deletes, gets or lists an identity_providers resource.

Overview​

Nameidentity_providers
TypeResource
Idsumologic.saml.identity_providers

Fields​

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringUnique identifier of the SAML Identity Provider. (example: 00000000361130F7)
entity_idstringA unique identifier that is the intended audience of the SAML assertion. (example: https:​//service.sumologic.com/sumo/saml/9483922, default: ) (wire: entityId)
configuration_namestringName of the SSO policy or another name used to describe the policy internally. (example: SumoLogic) (wire: configurationName)
assertion_consumer_urlstringThe URL on Sumo Logic where the IdP will redirect to with its authentication response. (example: https:​//service.sumologic.com/sumo/saml/consume/9483922, default: ) (wire: assertionConsumerUrl)
authn_request_urlstringThe URL that the identity provider has assigned for Sumo Logic to submit SAML authentication requests to the identity provider. (example: https:​//www.okta.com/app/sumologic/abxcseyuiwelflkdjh/sso/saml, default: ) (wire: authnRequestUrl)
certificatestringAuthentication Request Signing Certificate for the user.
created_atstring (date-time)Creation timestamp in UTC in [RFC3339](https:​//tools.ietf.org/html/rfc3339) format. (example: 2018-10-16T09:10:00.000Z) (wire: createdAt)
created_bystringIdentifier of the user who created the resource. (example: 0000000006743FDD) (wire: createdBy)
debug_modebooleanTrue if additional details are included when a user fails to sign in. (wire: debugMode)
disable_requested_authn_contextbooleanTrue if Sumo Logic will include the RequestedAuthnContext element of the SAML AuthnRequests it sends to the identity provider. (wire: disableRequestedAuthnContext)
email_attributestringThe email address of the new user account. (example: attribute/subject, default: ) (wire: emailAttribute)
is_redirect_bindingbooleanTrue if the SAML binding is of HTTP Redirect type. (wire: isRedirectBinding)
issuerstringThe unique URL assigned to the organization by the SAML Identity Provider. (example: http:​//www.okta.com/abxcseyuiwelflkdjh)
logout_enabledbooleanTrue if users are redirected to a URL after signing out of Sumo Logic. (wire: logoutEnabled)
logout_urlstringThe URL that users will be redirected to after signing out of Sumo Logic. (example: https:​//www.sumologic.com, default: ) (wire: logoutUrl)
metadata_urlstringThe URL to fetch SAML metadata XML. (example: https:​//api.sumologic.com/api/v1/saml/identityProviders/00000000361130F7/metadata, default: ) (wire: metadataUrl)
modified_atstring (date-time)Last modification timestamp in UTC. (example: 2018-10-16T09:10:00.000Z) (wire: modifiedAt)
modified_bystringIdentifier of the user who last modified the resource. (example: 0000000006743FE8) (wire: modifiedBy)
on_demand_provisioning_enabledobject (wire: onDemandProvisioningEnabled)
roles_attributestringThe role that Sumo Logic will assign to users when they sign in. (example: Sumo_Role, default: ) (wire: rolesAttribute)
sign_authn_requestbooleanTrue if Sumo Logic will send signed Authn requests to the identity provider. (wire: signAuthnRequest)
sp_initiated_login_enabledbooleanTrue if Sumo Logic redirects users to your identity provider with a SAML AuthnRequest when signing in. (wire: spInitiatedLoginEnabled)
sp_initiated_login_pathstringThis property has been deprecated and is no longer used. (example: http:​//www.okta.com/abxcseyuiwelflkdjh, default: ) (wire: spInitiatedLoginPath)
x_509cert_1stringThe certificate is used to verify the signature in SAML assertions. (wire: x509cert1)
x_509cert_2stringThe backup certificate used to verify the signature in SAML assertions when x509cert1 expires. (default: ) (wire: x509cert2)
x_509cert_3stringThe backup certificate used to verify the signature in SAML assertions when x509cert1 expires and x509cert2 is empty. (default: ) (wire: x509cert3)

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectregionGet a list of all SAML configurations in the organization.
createinsertregion, configuration_name, issuer, x_509cert_1Create a new SAML configuration in the organization.
updateupdateid, region, configuration_name, issuer, x_509cert_1Update an existing SAML configuration in the organization.
deletedeleteid, regionDelete a SAML configuration with the given identifier from the organization.

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
idstringIdentifier of the SAML configuration to delete.
regionstringSumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT)

SELECT examples​

Get a list of all SAML configurations in the organization.

SELECT
id,
entity_id,
configuration_name,
assertion_consumer_url,
authn_request_url,
certificate,
created_at,
created_by,
debug_mode,
disable_requested_authn_context,
email_attribute,
is_redirect_binding,
issuer,
logout_enabled,
logout_url,
metadata_url,
modified_at,
modified_by,
on_demand_provisioning_enabled,
roles_attribute,
sign_authn_request,
sp_initiated_login_enabled,
sp_initiated_login_path,
x_509cert_1,
x_509cert_2,
x_509cert_3
FROM sumologic.saml.identity_providers
WHERE region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
;

INSERT examples​

Create a new SAML configuration in the organization.

INSERT INTO sumologic.saml.identity_providers (
sp_initiated_login_path,
configuration_name,
issuer,
sp_initiated_login_enabled,
authn_request_url,
x_509cert_1,
x_509cert_2,
x_509cert_3,
on_demand_provisioning_enabled,
roles_attribute,
logout_enabled,
logout_url,
email_attribute,
debug_mode,
sign_authn_request,
disable_requested_authn_context,
is_redirect_binding,
region
)
SELECT
'{{ sp_initiated_login_path }}',
'{{ configuration_name }}' /* required */,
'{{ issuer }}' /* required */,
{{ sp_initiated_login_enabled }},
'{{ authn_request_url }}',
'{{ x_509cert_1 }}' /* required */,
'{{ x_509cert_2 }}',
'{{ x_509cert_3 }}',
'{{ on_demand_provisioning_enabled }}',
'{{ roles_attribute }}',
{{ logout_enabled }},
'{{ logout_url }}',
'{{ email_attribute }}',
{{ debug_mode }},
{{ sign_authn_request }},
{{ disable_requested_authn_context }},
{{ is_redirect_binding }},
'{{ region }}'
RETURNING
id,
entity_id,
configuration_name,
assertion_consumer_url,
authn_request_url,
certificate,
created_at,
created_by,
debug_mode,
disable_requested_authn_context,
email_attribute,
is_redirect_binding,
issuer,
logout_enabled,
logout_url,
metadata_url,
modified_at,
modified_by,
on_demand_provisioning_enabled,
roles_attribute,
sign_authn_request,
sp_initiated_login_enabled,
sp_initiated_login_path,
x_509cert_1,
x_509cert_2,
x_509cert_3
;

UPDATE examples​

Update an existing SAML configuration in the organization.

UPDATE sumologic.saml.identity_providers
SET
sp_initiated_login_path = '{{ sp_initiated_login_path }}',
configuration_name = '{{ configuration_name }}',
issuer = '{{ issuer }}',
sp_initiated_login_enabled = {{ sp_initiated_login_enabled }},
authn_request_url = '{{ authn_request_url }}',
x_509cert_1 = '{{ x_509cert_1 }}',
x_509cert_2 = '{{ x_509cert_2 }}',
x_509cert_3 = '{{ x_509cert_3 }}',
on_demand_provisioning_enabled = '{{ on_demand_provisioning_enabled }}',
roles_attribute = '{{ roles_attribute }}',
logout_enabled = {{ logout_enabled }},
logout_url = '{{ logout_url }}',
email_attribute = '{{ email_attribute }}',
debug_mode = {{ debug_mode }},
sign_authn_request = {{ sign_authn_request }},
disable_requested_authn_context = {{ disable_requested_authn_context }},
is_redirect_binding = {{ is_redirect_binding }}
WHERE
id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND configuration_name = '{{ configuration_name }}' --required
AND issuer = '{{ issuer }}' --required
AND x_509cert_1 = '{{ x_509cert_1 }}' --required
RETURNING
id,
entity_id,
configuration_name,
assertion_consumer_url,
authn_request_url,
certificate,
created_at,
created_by,
debug_mode,
disable_requested_authn_context,
email_attribute,
is_redirect_binding,
issuer,
logout_enabled,
logout_url,
metadata_url,
modified_at,
modified_by,
on_demand_provisioning_enabled,
roles_attribute,
sign_authn_request,
sp_initiated_login_enabled,
sp_initiated_login_path,
x_509cert_1,
x_509cert_2,
x_509cert_3;

DELETE examples​

Delete a SAML configuration with the given identifier from the organization.

DELETE FROM sumologic.saml.identity_providers
WHERE id = '{{ id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;