Integrations

/

CAS SAML2 SSO with Flexopus: Secure single sign-on for your organization

With the CAS SAML2 SSO integration, you can seamlessly connect Flexopus to your central identity provider. Users log in with their usual company login details – without additional passwords, without extra effort.

No items found.
No items found.

What is the CAS SAML2 SSO integration?

CAS (Central Authentication Service) is a widely used single sign-on protocol, primarily employed in educational and corporate environments. It centralizes authentication and allows users to log in to multiple applications with a single login.

Flexopus supports the open SAML2 standard (Security Assertion Markup Language 2.0) and acts as a service provider. This means that any Identity Provider that complies with the SAML2 standard – including CAS-based systems like Shibboleth – can be connected to Flexopus.

During registration, the user is redirected to the central identity provider, authenticated there, and then securely logged into Flexopus. User attributes such as name, email address, department or cost center can be automatically transferred and synchronized.

What is the purpose of integration?

CAS SAML2 SSO integration makes access to Flexopus easier, more secure and more uniform – for users and IT departments alike.

Instead of managing separate accounts and passwords for Flexopus, employees simply log in with their existing company login credentials. Authentication is handled entirely through your organization's central identity provider.

Typical use cases:

  • Universities and educational institutions that use CAS or Shibboleth for identity management can integrate Flexopus directly.
  • Companies with a central identity provider control precisely which employees have access to Flexopus via groups and permissions.
  • New users are automatically created in Flexopus upon their first login – without any manual administrative effort.
  • User attributes such as name, email, department or cost center are taken directly from the Identity Provider and kept up to date.

How easy is the integration?

Setting up the CAS SAML2 SSO integration is done via the Flexopus administrator interface and does not require in-depth technical knowledge. Essentially, two steps are necessary: registering Flexopus as a service provider in your identity provider and storing your identity provider's metadata in Flexopus.

Flexopus provides all the necessary configuration parameters, including Entity ID, Callback URL (ACS) and Metadata URL. Once both sides are configured, you can enable access for your users and test it directly.

For complete step-by-step setup instructions, please visit our Help Center.

What are the advantages of integration?

  • Single login: Users log in to their company account once and automatically gain access to Flexopus – no additional password is required.
  • Compatible with any SAML2-compliant Identity Provider: Whether CAS, Shibboleth or another system – Flexopus connects to any provider that supports the SAML2 standard.
  • Automatic user setup: New employees are automatically registered in Flexopus upon their first login, without requiring any intervention from the administration.
  • Synchronization of user data: Name, email address, department and other attributes are taken directly from the Identity Provider and kept up to date.
  • Central access control: You control which users or groups have access to Flexopus via your Identity Provider – permissions can be adjusted at any time.
  • Enhanced security: Authentication is performed via your existing, hardened identity provider. Multi-factor authentication (MFA) is supported.
  • Data minimization: Only the user attributes necessary for the operation of Flexopus are transmitted.
  • Included free of charge: SAML2 SSO integration is included in the Flexopus subscription (depending on the chosen plan) – without additional license costs.
Categories
Developed By
Flexopus GmbH
Frequently Asked Questions

questions and answers

Which identity providers are supported?

Flexopus supports any Identity Provider that complies with the open SAML2 standard. These include CAS, Shibboleth, Microsoft Entra ID (Azure AD), Google Workspace, Okta, Keycloak, Ping Identity and many others. Flexopus provides specific instructions for the most common providers in its help center.

What happens when a user is deleted from the Identity Provider?

If a user is deactivated or deleted in the Identity Provider, they can no longer log in to Flexopus, as authentication is done via the Identity Provider. User access will be automatically blocked. Manual deactivation in Flexopus is not required in this case.

How is user data protected?

Communication between your Identity Provider and Flexopus takes place via signed SAML2 assertions. This means that all transmitted data is checked for authenticity. Additionally, assertions can optionally be encrypted. Only the user attributes necessary for the operation of Flexopus are transmitted.

Can multiple identity providers be integrated simultaneously?

Yes. Flexopus supports the simultaneous integration of multiple single sign-on providers. This is particularly relevant for organizations with multiple subsidiaries or different IT environments. Each Identity Provider receives a unique URL through which the login process is controlled.

What happens if the username (UPN) changes?

In Flexopus, the User Principal Name (UPN) is a unique, unchanging identifier. Changing the UPN subsequently can lead to duplicate user entries. It is therefore strongly recommended not to change the UPN after setup. Should a change be necessary, please contact Flexopus support.