{"repo":"Versent/saml2aws","free":true,"listed":false,"github":"https://github.com/Versent/saml2aws","clone":"git clone https://github.com/Versent/saml2aws.git","description":"CLI tool which enables you to login and retrieve AWS temporary credentials using a SAML IDP","language":"Go","stars":2240,"topics":["aws","saml","adfs","osx","windows","linux","macos","macosx"],"license":"MIT","category":"cli-tools","readme_excerpt":"saml2aws CLI tool which enables you to login and retrieve AWS temporary credentials using with ADFS or PingFederate Identity Providers. This is based on python code from How to Implement a General Solution for Federated API/CLI Access Using SAML 2.0. The process goes something like this: Setup an account alias, either using the default or given a name Prompt user for credentials Log in to Identity Provider using form based authentication Build a SAML assertion containing AWS roles Optionally cache the SAML assertion (the cache is not encrypted) Exchange the role and SAML assertion with AWS STS service to get a temporary set of credentials Save these credentials to an aws profile named \"saml\" Table of Contents - saml2aws - Table of Contents - Requirements - Caveats - Install - macOS - Windows - Linux - Ubuntu - Other - Using Make - Arch Linux and its derivatives - Void Linux - Autocomplete - Bash - Zsh - Dependency Setup - Usage - saml2aws script - saml2aws exec - Configuring IDP Accounts - Example - Advanced Configuration - Windows Subsystem Linux (WSL) Configuration - Option 1: Disable Keychain - Option 2: Configure Pass to be the default keyring - Configuring Multiple Accounts - Dev Account Setup - Test Account Setup - Advanced Configuration (Multiple AWS account access but SAML authenticate against a single 'SSO' AWS account) - Advanced Configuration - additional parameters - Building - macOS - Linux - Environment vars - Dependencies - Releasing - Debugging Issues with IDP","default_branch":null,"files":null,"tree":[],"storefront":"/r/Versent","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Versent/saml2aws/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}