> For the complete documentation index, see [llms.txt](https://docs.fortifiedid.se/use-cases/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fortifiedid.se/use-cases/misc/digitala-nationella-prov-dnp-skolfederation/active-directory-ldap-with-bankid-as-step-up-method.md).

# Active Directory / LDAP with BankID as step-up-method

## Scenario

In this scenario, the web resource DNP (Digitala Nationella Prov) will be protected by a SAML IdP (Integrity Web), using Skolfederationen as the integration layer.

A user directory source, such as Active Directory, will be used for primary authentication, verifying forms-based authentication (username and password). The integration between Integrity and the user directory is based on LDAP. The LDAP source contains user attributes necessary for DNP. The LDAP source also contains an attribute with the mfa identifier value, in order for the step-up verification to work. These attributes will be fetched by Integrity and passed along the authentication chain.

Based on data passed in the initial SAML2 authnRequest from DNP to Integrity, a decision will be automatically made if the user should be prompted for step-up-authentication (BankID).

The identifier of the result of the BankID authentication will be compared to the mfa identifier value, to verify that the step-up was performed by the correct person.

**! This scenario could easily be copied and modified to fulfill other DNP login requirements:**

* **Using IWA as the primary authentication method, with username/password (forms) as backup.**
* **Other DIGG-certified LOA3 step-up methods, such as Freja, SITHS, EFOS, AB Svenska Pass**
* **Other primary authentication sources, such as Google, Entra, ADFS, or a combination of many primary authentication sources.**<br>

## Prerequisite

There are some prerequisite for this use case. You will need the following:

* **BankID certificate**. To be able to communicate with bankid backend.
* **LDAP host**
* **LDAP port**
* **LDAP service account DN**
* **LDAP service account password**
* **Host (DNS) name** of the Integrity service (external access)
* **Access to Skolfederationen metadata administration.** To be able to upload metadata
* **eduPersonPrincipalName (eppn)** stored on the LDAPuser object
* **Social security number (personnummer)** stored on the LDAP user object (only for teachers (lärare/skolpersonal))
* **Outgoing TCP/443 communication.** To be able to communicate with BankID backend and metadata services.

## Configuration

### Download and extract configuration files

1. Open the folder where you have installed Web
   1. Rename the customer folder to **customer\_OLD**.\
      Result should look like below:\
      \&#xNAN;**\\..\FortifiedID\web\customer\_OLD**
2. Download the following ZIP-file, [use\_case\_dnp\_standalone-integrity\_bankid.zip](https://share.fortifiedid.se/index.php/s/DJqLfseX9FqBj8x/download).
   1. Unzip the file
   2. Copy the **customer\_WEB** folder to **\\..\FortifiedID\web\\**
   3. Rename customer\_WEB to customer, result should look like:\
      \\..\FortifiedID\web\customer

### Update configuration to map your environment

#### Globals

In this section we will look at parts of the configuration and add/replace data for your environment. In this use case we are using the globals concept which is using variables to easily replace data specific to an environment or if a value is used in many places just update it in one place.

First of all, open the file customer/config/globals.json. Change according to the instructions below.

1. **base\_dir**

   1. base\_dir is the top folder where data is located that you do not want to be overwritten by an upgrade. Update the **base\_dir** folder to map your installation.
      1. For Windows the value should be:\
         "base\_dir": "../customer"
      2. For Docker, the value should be:\
         "base\_dir": ".",

   ```json
   "base_dir": "../customer"
   ```
2. **host**\
   Set the host value to your DNS name entry, including https\://.

   ```json
   "host": "https://skolfed.integrity.local",
   ```
3. **http**

   Update the http information to map your environment. This is the port that Integrity Web will use to host the SAML IdP service.\
   ! The recommendation is to always use SSL to encrypt the communication to Integrity Web.<br>

   ```json
    "http": {
               "http_port": 443,
               "http_use_ssl": true
           }
   ```
4. **keystore - https**

   Either you use the test certificate provided by us, if so you do not need to change anything. If you have a keystore then update the values below to point to your keystore.

   1. Find in section: **keystore**

      <pre class="language-json"><code class="lang-json"><strong>"https": {
      </strong>                "ref": {
                          "path": "${globals.base_dir}/config/resources_internal/certificates/fortifiedid.p12",
                          "password": "password"
                      },
                      "http_key_alias": "1",
                      "http_key_password": "password"
                  },
      </code></pre>
5. **keystore - bankid**

   For connecting against BankID test environment, you don't need to do anything.\
   For production connectivity, please use your BankID keystore and change the variables below to reflect that. Truststore changes will not be needed.\
   Find in section: **keystore**<br>

   ```json
              "bid": {
                   "ssl_keystore_path": "${globals.base_dir}/config/resources_internal/certificates/BankID/bankid_test_rp.p12",
                   "ssl_keystore_password": "qwerty123",
                   "ssl_key_alias": "1",
                   "ssl_key_password": "qwerty123",
                   "ssl_truststore_path": "${globals.base_dir}/config//resources_internal/certificates/trust_jks/bankidtrust.jks",
                   "ssl_truststore_password": "password"
               },
   ```
6. **keystore - signing and encryption**\
   The keystore used for signing and encrypting SAML messages, is configured in the last part of the keystore section.\
   Either you use the test certificate provided by us, if so you do not need to change anything. If you have a keystore then update the values below to point to your keystore.<br>

   ```json
   "alias": "1",
   "key_password": "password",
   "password": "password",
   "path": "${globals.base_dir}/config/resources_internal/certificates/fortifiedid.p12"
   ```
7. **saml**\
   You define the SAML2 metadata URLs in the SAML section.\
   To connect to Skolfederation Trial, leave the *skolfederation\_metadata* url unchanged. To connect to production, you can find the correct url [here](https://wiki.federationer.internetstiftelsen.se/pages/viewpage.action?pageId=36307974#Productionenvironment\(Skolfederation\)-Metadata).<br>

   ```json
   "saml": {
     "skolfederation_metadata": "https://fed.skolfederation.se/trial/md/skolfederation-trial-3_1.xml"
    },
   ```
8. **ldap**\
   Change the parameters below to connect to your LDAP store.\
   \&#xNAN;*username\_identifier\_user\_attribute* is the user object attribute that will match the username value, entered by the end user.\
   \&#xNAN;*eppn\_user\_attrbute* is the user object attribute containing the eppn value.\
   \&#xNAN;*mfa\_identifier\_user\_attribute* is the user object attribute containing the "personnummer" value.

   ```json
   "ldap": {
       "host": "host.docker.internal",
       "port": "389",
       "use_ssl": false,
       "bind_dn": "cn=integrityserviceaccount,ou=services,dc=example,dc=com",
       "bind_password": "Gargamel77",
       "base_dn": "ou=users,dc=example,dc=com",
       "username_identifier_user_attribute": "sAMAccountName",
       "eppn_user_attrbute": "mail",
       "mfa_identifier_user_attribute": "serialNumber" 
   }
   ```
9. **bankid environment**\
   \&#xNAN;*bid\_mode* controls which BankID environment to connect to, test or production. Leave unchanged for test. Change to *production* for production connectivity.

   <pre class="language-json"><code class="lang-json"><strong>"bid_mode" : "test"
   </strong></code></pre>

Save the globals.json file.

#### Update metadata

Update the IdP metadata, using [this](/use-cases/misc/digitala-nationella-prov-dnp-skolfederation/common-configuration.md#xml-metadata-templates) instruction, step 1-7.

#### Start the Integrity WEB service

Start the service and verify the start by looking through the server.log file.

#### Upload the IdP metadata to Skolfederationen

Upload the IdP metadata to Skolfederationen, using [this](/use-cases/misc/digitala-nationella-prov-dnp-skolfederation/common-configuration.md#upload-the-idp-metadata-to-skolfederationen) instruction.

## Test the configuration

### Login to DNP with step-up (lärare / skolpersonal)

1. Open a browser
2. Browse to <https://fidustest.skolverket.se/DNP-staging/> (DNP test environment) or <https://fidustest.skolverket.se/DNP/> (DNP production environment)
3. Select *Inloggning med e-legitimation*
4. Select your IdP
5. You should be redirected to Integrity
6. Enter your AD credentials
7. You should be prompted with BankID authentication
8. Fulfill BankID authentication
9. You should now be redirected back to DNP. If successful, this should be presented.

Tip. Use a SAML tracer tool for your browser to view the data added.

### Login to DNP without step-up (elev)

1. Open a browser
2. Browse to <https://fidustest.skolverket.se/DNP-staging/> (DNP test environment) or <https://fidustest.skolverket.se/DNP/> (DNP production environment)
3. Select *Inloggning utan e-legitimation*
4. Select your IdP
5. You should be redirected to Integrity
6. Enter your AD credentials
7. You should now be redirected back to DNP. If successful, this should be presented.
