Documentation for Identity Federation for AWS 2.1 – other releases are available in the Identity Federation for AWS Documentation Directory.
View

Unknown macro: {spacejump}

or visit the current documentation home.

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 16 Next »

 

This page provides answers to frequently asked questions regarding Identity Federation for AWS:

On this page:

General FAQ

How do I set up Identity Federation for AWS?

Please refer to the Installation and Upgrade Guide.

Which Atlassian products are currently supported by Identity Federation for AWS?

Identity Federation for AWS aims to be a cross product solution and currently supports JIRA and Bamboo (see Compatibility Notes for details) - please don't hesitate to get in touch, if you are interested in support for other Atlassian products, we are eager to learn more about your use case and adjusting our respective roadmap accordingly (see below for a notable special case though).

Will Identity Federation for AWS be available for Atlassian Crowd?

Identity Federation for AWS aims to be a cross product solution and Atlassian Crowd would be the most obvious target product for Enterprise deployments. The add-on could work within Crowd in principle, however Crowd currently lacks the Universal Plugin Manager (UPM) and support for selling Crowd add-ons via the Atlassian Marketplace in turn.

Does Identity Federation for AWS support SAML?  

While we would love to support AWS Identity and Access Management Using SAML, true integration of SAML (Security Assertion Markup Language) is outside of the realm of Identity Federation for AWS, however: 

Identity Federation between Atlassian Crowd and AWS

That being said, the main use case of this add-on is to provide similar functionality by leveraging the alternative AWS options for Identity Federation - you thereby gain the same benefits of federated access and a unified directory for all Atlassian products via Crowd.

  • (info) True SAML support would best be addressed by Atlassian Crowd itself - a related feature request is tracked by Atlassian in General SAML Support (CWD-1822), so please add your vote there to increase the priority. Also, don't hesitate to get in touch with us to discuss alternatives.

Support FAQ

What is the relation between Identity Federation for AWS 1.x and the Identity Federation for AWS 2.x series?

Identity Federation for AWS 2.0 for JIRA and Bamboo are the successor of the deprecated Identity Federation for AWS 1.x (which has been switched to maintenance mode, see below) - Identity Federation for AWS has been designed as a cross-product add-on, however, the Atlassian Marketplace meanwhile prevents cross-product 'Paid-via-Atlassian' add-ons, which required us to refactor the product into separate editions per application.

Will Identity Federation for AWS 1.x remain available?

While deprecated, Identity Federation for AWS 1.x will remain supported for a while to ease the migration. However, we are going to archive it soon and are switching it to maintenance mode, which means we will continue to fix functional issues, but are not going to add any features and improvements and focus on Identity Federation for AWS 2.x instead - please get in touch if you have any questions or suggestions about this transition.

How can I migrate from Identity Federation for AWS 1.x to Identity Federation for AWS (JIRA) 2.x?

Unfortunately there is no upgrade path for existing users for technical reasons outside of our control. To ease the migration, you can start using versions 1.x and 2.x for JIRA side by side, as they are entirely independent add-ons. Both expose identical user interface entries for menus and links though and you need to take care differentiating those as follows:

Providing an explicit (automated) migration option is not out of the question, but a disproportionate amount of work for us right now - please get in touch, if your use case requires a migration option regardless, we are willing to discuss this on a case by case basis.

Security FAQ

How are my persisted long-term AWS security credentials secured against unauthorized usage?

The persisted long-term AWS security credentials (comprised of an Access Key Id and a Secret Access Key) are stored in the database encrypted with a 128-bit Advanced Encryption Standard (AES) private secret key, which is stored on the file system and unique per application instance (e.g. JIRA installation). This means you can loose either your database or your file system without compromising your AWS accounts right away.

Licensing & Purchasing

Do my Atlassian host application and Identity Federation for AWS licenses have to match?

Yes, this is a limitation imposed by the Atlassian Marketplace, see the Marketplace Licensing and Pricing FAQ:

Which license do I choose when purchasing an add-on?:

The Atlassian host application (for example, JIRA, Confluence, etc.) license tier determines the license type you need for an add-on that is paid-via-Atlassian.  For example, if you are installing an add-on into a JIRA with 25-user license, you must purchase a 25-user license for the add-on, even if fewer users will actually use it.

IMPORTANT: If you do not purchase a license that matches your Atlassian application license, your add-on will not work.

 

Obviously there are many valid use cases where this limitation doesn't make sense. Accordingly, many customers and vendors have requested the ability to decouple the add-on user tier from the host application - please contact Atlassian directly for any questions in this regard, maybe they will reconsider this over time.

 Do I need an Identity Federation for AWS license when integrating the product with another licensed Utoolity add-on like Tasks for AWS?

 

No, customers of other AWS related  Utoolity add-ons are eligible for a free license of Identity Federation for AWS:

  • (plus)  there is no action required: Identity Federation for AWS will detect other licensed Utoolity add-ons and be fully functional without a dedicated license of its own then
  • (lightbulb) promotional licenses are available: please get in touch, if you'd prefer to use a dedicated license for Identity Federation for AWS instead, complimentary 100% discount codes are available for eligible customers

 


https://<host>/<context>/plugins/servlet/identity-federation-for-aws/aws-console-login/fd3f4265-1ba1-4045-92d4-142a1e271c7d

  • No labels