Two-Factor Authentication for Bitbucket on-premise Setups with SAML

Protect your Bitbucket Account with secure authentication from SecSign ID

The perfect solution to complete your Atlassian on-premise security with secure Authentication

Simply integrate the SecSign ID Two-Factor Authentication plugin and offer your users secure authentication with your Bitbucket system, including convenient SSO setups. Connect your on-premise directory service for simple user management and added two-factor authentication security.

Use SecSign ID Bitbucket two-factor authentication for your Bitbucket account with SAML to securely protect all your data and access points and . Works for iOS or Android mobile devices as well as for desktop.


Find out why our Two-Factor Authentication is the best, some key-facts for developers and why you should upgrade to SecSign for your business.

Learn more about the options of on-premise use and your own customized ID App in your corporate design.

Download the plugin as cloud version for a free and convenient protection.

Table of contents

    Bitbucket is a web application for version control repository hosting service that can be used for source code and development process. It was developed by the company Atlassian. Bitbucket has comprehensive features and a high adaptability.Thus, the functionality of Bitbucket can be optionally expanded or adapted by using plugins (add-on’s).
    SecSign ID is a plugin for real two-factor authentication (2FA) for Bitbucket. 2FA adds another layer of security to your installation by using a second token. In this case the physical token is your smartphone.

    For on-premise Bitbucket protection without SAML please refer to our guide on the integration of our SecSign ID on-premise Bitbucket plugin.
    Bitbucket on-premise protection
    To add on-premise authentication protection to your Cloud Atlassian setup, please refer to our SAML integration with the Atlassian Identity Manager.
    Cloud Bitbucket on-premise protection

    Questions? Feel free to get in touch with us if you need help setting up your SecSign ID plugin or to request a plugin for a not yet supported environment.

    MORE INFORMATION

    1. Pre-requirements

    To integrate the SecSign ID Two-Factor Authentication with Bitbucket you first need to setup an account with Bitbucket and have administrative access rights. More information about setting up an account and managing user rights are available on the Bitbucket website.

    You also need access to the SecSign ID administrative panel. If you need assistance managing your administrative account please contact us.

    2. Edit SecSig ID administrative Settings


    Log-in to the administration page of the SecSign ID Server and navigate to SAML Service Provider from the menu. Select “New SAML service provider”.

    Enter the following parameter in the corresponding fields.

    Name for example: Bitbucket

    NameID Attribute store: SecSign ID Server
    NameID source attribute: SecSign ID
    Please leave Format blank.

    Service Provider Issuer: https://< your Bitbucket server >/plugins/servlet/samlsso
    SAML response URL: https://< your Bitbucket server >/plugins/servlet/samlsso
    RelayState left blank
    Audience Restriction: https://< your Bitbucket server >/plugins/servlet/samlsso
    Auth Context left blank

    User group to sign: The user group to which you have assigned a
    technical user owning the private key to sign SAML responses.
    Example
    user group name: “SAML response signers.”
    Hash algorithm: Server selects.
    PSS padding: Server selects.
    No SAML attributes selected.

    Save the settings.

    Navigate to “User groups” and select the user groups whose members shall be allowed to log-in at your Bitbucket server.

    Double click the newly created SAML Service Provider in the list and
    then copy the URL beside “Import the IdP SAML meta data from this URL”.


    3. Edit the Bitbucket administrative settings



    Use a different browser to log-in at your Bitbucket server. Navigate to the Add-on Menu. Select “SAML Single Sign On (SSO) for Bitbucket by Resolution Reichert Network Solutions GmbH” and install it.




    Go to the SAML Single Sign-On Plugin Configuration.
    Select Add an IdP and enter the following parameter:

    IdP Type: Import Metadata from URL
    Name for example: SecSign ID
    Description (for example): SecSign ID Server

    Click next.




    Paste the metadata URL copied from the SecSign ID Server.
    Click Import, followed by Next.




    No changes needed in the dialog “User ID attribute and transformation”.




    Continue and check “Enable User creation or update” if necessary.



    Save the settings and select Next since you already set-up the IdP (the SecSign ID server).



    Start the test and verify a successful SecSign ID log-in.




    Then click on Next.
    Check “Enable SSO Redirect” if required.

    Select “No redirection after logout”, then Save and Close.


    4. Available APIS

    We provide an ever growing list of APIs and plugins to easily integrate the SecSign ID Two-Factor Authentication in any project. An overview is available at Plugin and APIs.
    We do not only offer APIs in different programming languages but also plugins for CMS, Server and VPN environments, oAuth2 and many more. These plugins use our APIs and offer additional functionalities, for example user management, easy and native installation, logging or integration in firewalls or Active Directory.

    The JIRA plugin for example uses the JAVA-API. The PHP-Api and JS-API is used by WordPress, Joomla, Drupal, Typo3 and many more. The ASP.net/C#-API is used for the Windows and Cisco VPN and the C-API is used for protecting Unix SSH services. The Objective-C API is used by our AppleTV and iPhone/iPad apps.

    available_apis

    5. See for yourself

    You can experience the SecSign ID two-factor authentication and the two-factor login by simply integrating the plugin into your website or test environment. Or you can try out the login process on our website without having to register first. You already have a SecSign ID or you want one? Login now and use the portal or use our hassle free registration.

    See for yourself how fast and convenient the login process using challenge-response authentication with 2048-bit key pairs is. There is no need for passwords, and no passwords or other confidential information are ever transmitted. It is easy to integrate and simple to use.

    For more information about the patented SafeKey procedure and it's unique security can be found here.

    If you are missing an API for the programming language you are working with, feel free to contact us and we’ll find a solution with you. If you need help with the integration into an existing system or you can’t find the plugin for your content management system you are working with, don’t hesitate to contact our support team.

    Your own ID-Server

    On premise installations of SecSign ID offer the flexibility to connect with your preferred servers, services, and devices. And you can customize the SecSign ID with your own organization’s branding.

    your_own_id

    Why upgrade to SecSign?

    On-premise or in the cloud

    Choose between our SecSign ID Cloud or operate your own on-premise Two-Factor Authentication server.

    Easy customization

    Operate your own YourBrand ID app - Two-Factor Authentication customized to your needs.

    Ready-to-use SDK

    Integrate SecSign ID Two-Factor Authentication in existing apps with our ready-to-use SDK.

    Easy user management

    Use the Two-Factor Authentication Server to secure your company Active Directory/LDAP. Your own Identity and Access Management System, for example for mandatory updates and additional security features.

    Cover all logins

    Integration in any login environment: web, local, VPN, remote desktop, mobile logins and many more.

    Plugins for all your needs

    No need for complex integration: we have plugins for almost all environments.


    We offer SAML solutions for any setup – tailored for your needs

    Do you have a service that needs SAML two-factor authentication protection? You didn’t find any information about your setup? We offer custom solutions for almost any SAML setup. Message us for a fast and convenient solution for your service.

    Do you intend to operate the SecSign ID Two-Factor Authentication server On-Premise or in the cloud?

    Stop Patchwork-Solutions:
    2FA for all your Atlassian services

    Landing Page

    More information about the SecSign ID Atlassian setups are available on our Atlassian Landing Page.

    Do NOT follow this link or you will be banned from the site!