This document includes the specific authentication methods available to Swank Residence Life Cinema (RLC) customers.
IP Address Authentication
This restricts viewing to the allowed public IPs of the campus or facility. This is sufficient for allowing access across the entire campus population and is required for all Resident Life Cinema deployments. Provide your public IP range(s) and this can be configured by our Accounts and Support Teams. Note: Single Sign On may also be required if needing to restrict to a specific audience within your campus.
Single Sign On (SSO) Integration
SSO cannot be used as an alternative for IP auth in RLC markets as IP auth is required to restrict access to the campus only. SSO would be in addition to the IP Authentication requirement. RLC sites cannot be accessed while off-campus. In these markets, SSO should only be used if the audience needs to be further restricted to a select group and can be filtered using SAML Attributes.
*Please contact your Account Manager and Swank Digital Support before proceeding with SAML or OIDC setup as additional configurations will need to be made by Swank.
We currently offer integration with SAML and OIDC. Please find the guides at the following link for SAML and OIDC integrations.
General Overview of SAML SSO Setup
This section outlines the high-level steps to integrate a SAML provider with Swank Cloud Streaming portal. The Metadata XML approach is the suggested approach because it reduces errors in transmission and manual configuration
-
Configure SAML Identity Provider:
- Preferred Approach: Use the SAML Service Provider Metadata XML file provided by Swank to import our configuration into your SAML Identity Provider. You can download the file here.
- Alternate Approach: If your identity provider does not support importing an XML Metadata file, use the manual configuration.
-
Configure Swank Streaming Portal:
- Login with your admin credentials provided by your Account Manager.
- Configure your settings via the XML document in the SAML Settings portion of the Cloud Streaming Admin Portal.
- Preferred Approach: Generate a SAML Identity Provider Metadata XML file from your Identity Provider service and import into "Load Settings" area with the "SAML External" tab
- Alternate Approach: If your identity provider does not support exporting an Identity Provider Metadata XML file, use the manual configuration
-
Elevate User Roles: Users that need additional permissions will need to be elevated to the Admin role either by claim/attribute or a manual update of the user account in the streaming portal.
- Admin will have the capability to:
- Add/remove custom content.
- Modify SSO configuration
- Modify Appearance settings.
- Modify Categorization settings.
- Admin will have the capability to:
-
Testing: Test the integration to ensure access.
- If there are issues, you will need to create a test account for each role.
- Activate SSO: Swank will need to be notified before activation in order to configure your portal to work with SSO and IP Auth together.
Comments
0 comments
Please sign in to leave a comment.