Skip to main content

Using SAML for JIT provisioning

You can use Just-In-Time (JIT) provisioning to provision new users or update existing user records.

By using JIT provisioning, you can use a SAML assertion to provision a new user in the Veracode Platform. JIT provisioning allows you to create Veracode users automatically the first time they attempt to access the Veracode Platform. If JIT provisioning is available, you can sign in to the Veracode Platform using SAML and have a login automatically created with default roles and privileges.

JIT provisioning also allows you to update existing user records with fresh information from your identity provider. If there are changes to the first or last name of a user, phone number, or email address, your identity provider automatically propagates these values to Veracode without requiring administrator intervention.

JIT provisioning takes advantage of the SAML specification support for optional attributes in the SAML XML document. Veracode requires specific attributes for using JIT provisioning. You can add other attributes to populate additional data for new or existing records.

Required and optional SAML attributes​

Veracode recognizes these SAML attributes as containing information for SAML self-registration. You provide these attributes to supply additional information about the user to Veracode. Veracode requires that you either specify the default Veracode user role in the SAML attributes, or you choose to use SAML assertion data, in which you must specify the Veracode user role.

AttributeDescription
firstname
Required
First name of the user.
lastname
Required
Last name of the user.
email
Required
Email address of the user.
rolesComma-separated list of valid UI user roles. If not provided here, you must specify the default user roles using SAML assertion data.
teamsComma-separated list of teams to which the newly registered users are assigned. If you do not provide this information using the teams attribute, you must specify the default teams using SAML assertion data.
teamsmanagedComma-separated list of teams managed by the team administrator.
hasiprestrictionSet to TRUE if the user is restricted to a certain IP range. Requires that you enter a value for ipaddresslist.
ipaddresslistThe IP range to which the user is restricted for login.
customoneCustom field one.
customtwoCustom field two.
customthreeCustom field three.
customfourCustom field four.
customfiveCustom field five.

Set the assertion recipient​

In your SAML assertion, ensure that SubjectConfirmationData has the Recipient attribute set to the Target URL.

For example:

<Subject>
<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">...</NameID>
<SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<SubjectConfirmationData InResponseTo="..."
NotOnOrAfter="..."
Recipient="https://login.analysiscenter.veracode.com/sso/saml2/..."/>
</SubjectConfirmation>
</Subject>

SAML format settings​

Veracode accepts SAML assertions in two formats: multivalued attributes and comma-separated values (CSV).

Important

The CSV format is limited to 20,000 characters per field.

Multivalued attribute example:

<saml2:Attribute Name="roles" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">Submitter</saml2:AttributeValue>
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">Reviewer</saml2:AttributeValue>
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">Security Lead</saml2:AttributeValue>
</saml2:Attribute>

CSV example:

<saml2:Attribute Name="roles" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
<saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">Submitter,Reviewer,Security Lead</saml2:AttributeValue>
</saml2:Attribute>

The SAML Format Settings selections in your JIT provisioning configuration must match the format of the assertion data you provide.

Configure JIT provisioning​

Before you begin:

To complete this task:

  1. In the Veracode Platform, select the gear icon in the top menu and select Admin.

  2. Select JIT Provisioning.

    note

    You cannot make changes to this tab unless you have provided the settings on the SAML tab.

  3. In Organization Settings, set Configure default settings for Just-In-Time user provisioning to On.

  4. In User Data Updates, choose how the Veracode Platform handles conflicts between data in the SAML assertion and data in the Veracode Platform with these options:

    • Prefer Organization Identity Provider Data: the IdP of the organization controls the configuration of the user. The Veracode Platform is updated with the data that is in the SAML assertion. This setting allows the IdP to automatically update fields that may change, such as email address, phone number, last name, roles, and team assignments.

      note

      After you set this option, you cannot update the authentication type for existing users or update users with the Identity APIs because the identity provider controls all user information.

    • Prefer Veracode User Data: the Veracode Platform ignores any changed data in the SAML assertion.

  5. Choose which default attributes to set on individual users. Veracode requires that you either specify the default Veracode user role in the SAML attributes or the SAML assertion data. If you do not set a default user role, the user cannot log in.

  6. In SAML Format Settings, select the SAML attributes that you provide in the comma-separated value (CSV) format, which has a character limit of 20,000 characters per field. For the unselected values, you must provide the SAML data in the multi-valued attribute format, which has no character limit. See example values for each format.

  7. Select Save.

If you disable JIT provisioning, you must manually add and update users in the Veracode Platform. Additionally, Veracode deletes your existing JIT settings, which you must re-configure if you reactivate JIT. Disabling JIT provisioning does not prevent existing users from logging in.