|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, see this page |
||
|
SP-Side Configuration |
〇 |
To be configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning supported (account management possible via TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Devices |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Add App" button in the upper right of the screen.
- On the "Add Enterprise App" screen, search for and select "Alibaba Cloud (User-Based SSO) (SAML)".
- Download the metadata under "Identity Provider Information" in advance.
Now switch to configuring Alibaba Cloud.
In a separate window, log in to the Alibaba Cloud RAM console with an administrator account.
Alibaba Cloud Configuration
- Open "SSO > User-based SSO Login Method" and click "Edit".
- Enable "SSO Status" and upload the metadata downloaded from TrustLogin via "Upload" under Metadata File.
Change the "Auxiliary Domain Name" to match your operational requirements.
Click "OK" to save the settings.
- Copy the URL under "SAML Service Provider Metadata URL" and open it in a separate window.
- Extract and note down the Entity ID value enclosed in entityID="" near the beginning of the file.
Return to the TrustLogin configuration again.
TrustLogin Admin Page Configuration (Continued)
- Enter the Entity ID extracted from the Alibaba Cloud metadata into the "Entity ID" field under "Service Provider Settings".
- Click "Register" to save.
TrustLogin User Configuration
① When a User Adds the App via My Page
- In "My Page", click the "Add App" button.
- On the "App Registration" screen, select "Alibaba Cloud (User-Based SSO) (SAML)", and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the "Alibaba Cloud (User-Based SSO) (SAML)" app.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.