Configuring Laserfiche Directory Server When Enabling Single Sign-on for Laserfiche 10 and Laserfiche 11 Web Products

The following video explores how to configure Laserfiche Directory Server and the Security Token Service (or STS) on a single machine with Windows Authentication. For more information, see the documentation.

On the computer hosting the Directory Server Security Token Service (STS), open a web browser and browse to:

https://localhost/LFDSSTS/configuration

Verify that the default Directory Server host name and port are correct.

Timeout Settings

Set the maximum number of minutes a session can remain idle before the user is signed out. These settings apply to all sessions that are authenticated through the STS instance being configured.

Allowed Iframe Hosts

Configure the set of allowed domains that can embed the Directory Server sign-in page in an iframe. This option is available in Laserfiche Directory Server Update 4 and later. Specify multiple domains by separating each domain with a space.

Sign-in Page Customizations

Note: If both the Hide Laserfiche Authentication checkbox and Hide Windows Authentication checkbox are selected, the Directory Server sign-in page will be an empty page if you do not have AD FS authentication or SAML authentication turned on and configured for an identity provider.

You can configure further settings for each licensing site you have on Directory Server.

Click Update to apply your settings.