The municipality of Eindhoven intends to change the current way of 'authentication' to 'SAML' authentication.
The current way of authenticating is based on 'Windows Active Directory'.
Within Eindhoven we use the publishing of FME Desktop scripts to FME server via the so-called 'FMEServerJobSubmitter'.
This is based on an Active Directory account.
FME version 2022.2.1
On the Safe website we find several articles that authentication within an FME flow via SAML does not support a number of transformers.
One of them is the 'FMEServerJobSubmitter'.
Two possible 'workarounds' are mentioned.
We do have some questions about this. Hopefully someone can comment on this.
1. Use a System Account
FME Server can consist of both SAML and system user accounts. Consider creating a system user account whose credentials can be shared with those users who author workspaces in FME Desktop. This account can be used to create the web connection for FME Server transformers.
• Eindhoven works with AD accounts in FME desktop.
Is the above workaround applicable?
• Is this solution based on a single system user account?
• Or is it possible to use multiple system user accounts?
This is the desirable situation given various rights/roles on the FME server
• Does this solution have an added value because you continue to work with AD accounts on FME desktop, and have a SAML authentication on the FME server.
2 . Use FME Server Automations
The FME Server Automations framework intends to provide equivalent, if not more powerful functionality as FME Server transformers. Consider migrating existing workflows that contain these transformers to Automations, and going forward create Automations as opposed to leveraging FME Server transformers in your workspaces.
• The above workaround seems possible.
Impact is significant.
Customize all scripts for various user groups.
All in all, further research shows that a transition to SAML authentication has quite an impact on the FME desktop and server setup.
As a supplier/customer or client , do you have experience and advice on how and when you can best switch to SAML authentication?
Best regards and thanks in advance for a reply.
John van der Kleijn
municipality Eindhoven