|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, see this page |
||
|
SP-Side Configuration |
〇 |
To be configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning supported (account management possible via TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
ー |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Devices |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and (optionally) an "Icon".
- Download the metadata under "Identity Provider Information" in advance.
Now switch to configuring Alibaba Cloud.
In a separate window, log in to the Alibaba Cloud RAM console with an administrator account.
Alibaba Cloud Configuration
-
[Create IdP]
Open "SSO > Role-based SSO Login Method" and click "Create IdP" on the SAML tab.
- Enter any name for "IdP Name", upload the metadata downloaded from TrustLogin via "Upload" under the metadata file, and click "OK" to save.
- Click the name of the IdP you created and note down the "ARN" value.
-
[RAM Role Configuration]
Open "Identity > Roles" and click "Create Role".
- Select "IdP" and click "Next" to proceed.
- Enter any name for "RAM Role Name", select "SAML" for "IdP Type", select the IdP you created under "Select IdP", and click "Complete" to save.
- Click "Grant Permissions to RAM Role".
- Select the policy to grant permissions to the RAM role and click "OK".
For details, please refer to "Grant permissions to a RAM role".
- Once permissions have been granted successfully, click the "Complete" button.
- Click the name of the role you created and note down the "ARN" value.
Return to the TrustLogin configuration again.
TrustLogin Admin Page Configuration (Continued)
- Configure each item under "Service Provider Settings" as follows.
Value for Name ID Select "Member" > "email"
Entity ID urn:alibaba:cloudcomputing:international Name ID Format Select "emailAddress" ACS URL for Service
https://signin.alibabacloud.com/saml-role/sso
- In "SAML Attribute Settings", click the "Specify Custom Attribute" button, then click "Add SAML Attribute" to add a row (attribute). Configure as follows.
Service Provider Attributes TrustLogin (IdP) Attributes Attribute Name (as specified) Attribute Type Attribute Name Attribute Value NameID Unspecified NameID Member
Member - Email Address
Value of ① below Unspecified Value of ① below Member Member - Email Address
Value of ② below Unspecified Value of ② below Fixed Value "Role ARN", "IdP ARN"
(Separate the "Role ARN" and "IdP ARN" with a comma (,))
①: https://www.aliyun.com/SAML-Role/Attributes/RoleSessionName
②: https://www.aliyun.com/SAML-Role/Attributes/Role
- Click "Register" to save.
TrustLogin User Configuration
① When a User Adds the App via My Page
- In "My Page", click the "Add App" button.
- On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app in "My Page" or the "Browser Extension" and verify that login is successful.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the custom SAML app you created.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.