# Setup: Authentication: SSO integration by using a Custom HTTP module

**URL:** <https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619>\
**Category:** Authentication\
**Created:** [January 3, 2014, 10:50am UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619 "2014-01-03T10:50:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![wfg-admin](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.workflowgen.com/wfg-admin/32/714_2.png) [@wfg-admin](https://discuss.workflowgen.com/u/wfg-admin)\
**Post date:** [January 3, 2014, 10:50am UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/1 "2014-01-03T10:50:53Z")

</div>

WorkflowGen supports Single Sign On integration with a tier application. Two main technical solutions are possible:

- Form authentication (see the [Setup: Authentication: SSO integration by using form authentication](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-form-authentication/618) topic for more information)

- Custom HTTP module

The advantage of the custom HTTP module solution is that it secures all WorkflowGen HTTP requests, including web services. It also provides more customization possibilities than the form authentication-based solution.

This article focuses on the custom authentication module solution.

**Note:** We recommend securing the WorkflowGen website with SSL and using encryption to secure the token. The code provided below is a basic sample, so you may have to customize it to enforce security and hide detailed error messages.

#### WorkflowGen Custom module authentication configuration

1. Configure WorkflowGen to use Custom authentication module.

2. In IIS, change the Authentication configuration. Enable `Anonymous` on all IIS applications in the WorkflowGen website:

3. Create a Visual Studio project to edit the `CustomAuthModuleSSO.cs` file. In the Authentication function, change the following variables according to your tier app:

#### Tier application configuration

1. Call WorkflowGen with the token. Your tier app has to encode (or encrypt) the username.

2. Put the encoded username into a cookie (set to a parent domain), a URL parameter (the token value has to be URL encoded) or an HTTP header (for web service calls).

3. If you have to call WorkflowGen web services, you must add an HTTP header with the token value.

4. Manage the authentication request from WorkflowGen.

5. Manage the sign out request done by the tier app to log out the user in WorkflowGen.

#### Encryption Method

The example provided supports base64 encoding or encryption. For the encryption option, `loginsso.aspx` uses 3DES mode ECB with MD5 to hash the private key by default. You can customize the `loginsso.aspx` code according to your requirements.

##### PHP code example

```auto
$key = 'mykey';

$string = 'string to be encrypted';

$encrypted = base64_encode(mcrypt_encrypt(MCRYPT_3DES, md5($key), $string, MCRYPT_MODE_ECB);

```

---

<div class="post-metadata">

**Author:** ![Craig](https://avatars.discourse-cdn.com/v4/letter/c/ed8c4c/32.png) [@Craig](https://discuss.workflowgen.com/u/Craig)\
**Post date:** [February 24, 2018, 10:05am UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/2 "2018-02-24T10:05:11Z")

</div>

It appears the CustomAuthModuleSSO.dll is not included with the attached CustomAuthModuleSSO.zip?

Trying to setup WFG with ADFS and not finding it easy. Any other doco out there on setting this up?

---

<div class="post-metadata">

**Author:** ![eddy.daouk](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.workflowgen.com/eddy.daouk/32/672_2.png) [@eddy.daouk](https://discuss.workflowgen.com/u/eddy.daouk)\
**Post date:** [February 26, 2018, 2:18pm UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/3 "2018-02-26T14:18:36Z")

</div>

Thanks for pointing this out, we’ve reworked the instructions to make the procedure clearer.

---

<div class="post-metadata">

**Author:** ![ParadimeWeb](https://avatars.discourse-cdn.com/v4/letter/p/8e8cbc/32.png) [@ParadimeWeb](https://discuss.workflowgen.com/u/ParadimeWeb)\
**Post date:** [March 6, 2018, 7:03pm UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/4 "2018-03-06T19:03:19Z")

</div>

I am trying to install the Advantys.My.dll and Advantys.Security.dll in the GAC, but am receiving an error saying the assembly does not have a strong name. Are these assemblies signed? Where can I get a copy of those?

---

<div class="post-metadata">

**Author:** ![eddy.daouk](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.workflowgen.com/eddy.daouk/32/672_2.png) [@eddy.daouk](https://discuss.workflowgen.com/u/eddy.daouk)\
**Post date:** [March 6, 2018, 8:19pm UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/5 "2018-03-06T20:19:23Z")

</div>

Hi,

No, those assemblies are not signed. You can add those DLLs in the Bin folder of your project.  
If your project is installed on WorkflowGen’s website then you should refer to the WorkflowGen’s Bin folder.

Best Regards,  
Eddy.

---

<div class="post-metadata">

**Author:** ![ParadimeWeb](https://avatars.discourse-cdn.com/v4/letter/p/8e8cbc/32.png) [@ParadimeWeb](https://discuss.workflowgen.com/u/ParadimeWeb)\
**Post date:** [March 6, 2018, 8:27pm UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/6 "2018-03-06T20:27:19Z")

</div>

Might be good not to recommend adding the files in the GAC. The post clearly says that you can also add these files to the GAC…??.. It is very confusing.

---

<div class="post-metadata">

**Author:** ![pnicoll](https://yyz2.discourse-cdn.com/flex030/user_avatar/discuss.workflowgen.com/pnicoll/32/454_2.png) [@pnicoll](https://discuss.workflowgen.com/u/pnicoll)\
**Post date:** [March 7, 2018, 2:49pm UTC](https://discuss.workflowgen.com/t/setup-authentication-sso-integration-by-using-a-custom-http-module/619/7 "2018-03-07T14:49:05Z")

</div>

Hi,

Thanks for bringing this to our attention. We’ve corrected the instructions accordingly.

Best regards,

Peter
