Tasks that Require Control Hub Credentials

When SAML authentication is enabled, the following tasks require that users be authenticated by Control Hub:

  • Update the SAML IdP configuration in the organization details if the SAML IdP is incorrectly configured in Control Hub.
  • Use the Data Collector command line interface.
  • Log into a Data Collector running in disconnected mode.
  • Use the Control Hub REST API or the SDK for Python.
To complete these tasks when SAML is enabled, users must have one of the following roles:
  • Organization Administrator

    Users with the Organization Administrator role can complete all of these tasks.

  • Control Hub Authentication

    Users with the Control Hub Authentication role can complete all of the tasks except for updating the SAML IdP configuration, as long as they have all other required roles. For example, to delete jobs using the Control Hub REST API when SAML is enabled, a user must have the Control Hub Authentication role, Organization User role, and the Job Operator role.

Users with the Organization Administrator role or the Control Hub Authentication role can be authenticated by the SAML IdP using IdP credentials or by Control Hub using Control Hub credentials. In most cases, users with these roles will log in just like any other user in the organization and will be authenticated by the SAML IdP.

However, when needed, users with the Organization Administrator role or the Control Hub Authentication role can use the following page to log into Control Hub using Control Hub credentials:

https://cloud.streamsets.com/security/dpmlogin
https://<hostname>:18631/security/dpmlogin

For example, if the SAML IdP is incorrectly configured within Control Hub, users cannot log in using SAML authentication. Users with the Organization Administrator role can use their Control Hub credentials to log in using this URL to re-enable access to Control Hub.

Because users with the Organization Administrator role or the Control Hub Authentication role can be authenticated by Control Hub, users with these roles must define a password to use with their Control Hub user account. When a new user or an existing user is assigned one of these roles, Control Hub sends the user a password reset email.
Note: When needed, the Control Hub system administrator can configure an organization property to disable this SAML backdoor. However, disable the backdoor with caution. If disabled and the SAML IdP is incorrectly configured within Control Hub, you must work with StreamSets customer support to resolve the issue.