How to Configure SAML Authentication for Alibaba Cloud (Role-Based SSO)

Item

Details

Prerequisites

  • This page provides instructions for using Role-Based SSO.
    For instructions on User-Based SSO, please see this page.

  • Prior configuration on Alibaba Cloud is required.
  • You must create a user in Alibaba Cloud with the same email address used in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Alibaba Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see this page

SP-Side Configuration

To be configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible via TrustLogin)

SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
    01.png

  2. Register the "Application Name" and (optionally) an "Icon".
    02.png

  3. Download the metadata under "Identity Provider Information" in advance.
    03.png

Now switch to configuring Alibaba Cloud.
In a separate window, log in to the Alibaba Cloud RAM console with an administrator account.

Alibaba Cloud Configuration

  1. [Create IdP]
    Open "SSO > Role-based SSO Login Method" and click "Create IdP" on the SAML tab.
    04.png

  2. Enter any name for "IdP Name", upload the metadata downloaded from TrustLogin via "Upload" under the metadata file, and click "OK" to save.
    05.png

  3. Click the name of the IdP you created and note down the "ARN" value.
    06.png

    07.png

  4. [RAM Role Configuration]
    Open "Identity > Roles" and click "Create Role".
    08.png

  5. Select "IdP" and click "Next" to proceed.
    09.png

  6. Enter any name for "RAM Role Name", select "SAML" for "IdP Type", select the IdP you created under "Select IdP", and click "Complete" to save.
    10.png

  7. Click "Grant Permissions to RAM Role".
    11.png

  8. Select the policy to grant permissions to the RAM role and click "OK".
    For details, please refer to "Grant permissions to a RAM role".
    12.png

  9. Once permissions have been granted successfully, click the "Complete" button.
    13.png

  10. Click the name of the role you created and note down the "ARN" value.
    14.png
    15.png

Return to the TrustLogin configuration again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure each item under "Service Provider Settings" as follows.
    Value for Name ID

    Select "Member" > "email"

    Entity ID urn:alibaba:cloudcomputing:international
    Name ID Format Select "emailAddress"

    ACS URL for Service

    https://signin.alibabacloud.com/saml-role/sso

    16.png

  2. In "SAML Attribute Settings", click the "Specify Custom Attribute" button, then click "Add SAML Attribute" to add a row (attribute). Configure as follows.
    Service Provider Attributes TrustLogin (IdP) Attributes
    Attribute Name (as specified) Attribute Type Attribute Name Attribute Value
    NameID Unspecified NameID

    Member

    Member - Email Address

    Value of ① below Unspecified Value of ① below Member

    Member - Email Address

    Value of ② below Unspecified Value of ② below Fixed Value

    "Role ARN", "IdP ARN"

    (Separate the "Role ARN" and "IdP ARN" with a comma (,))


    ①: https://www.aliyun.com/SAML-Role/Attributes/RoleSessionName
    ②: https://www.aliyun.com/SAML-Role/Attributes/Role

    17.png

  3. Click "Register" to save.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. In "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app in "My Page" or the "Browser Extension" and verify that login is successful.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the custom SAML app you created.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Alibaba Cloud (Role-Based SSO)

Item

Details

Prerequisites

  • This page provides instructions for using Role-Based SSO.
    For instructions on User-Based SSO, please see this page.

  • Prior configuration on Alibaba Cloud is required.
  • You must create a user in Alibaba Cloud with the same email address used in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Alibaba Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see this page

SP-Side Configuration

To be configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible via TrustLogin)

SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
    01.png

  2. Register the "Application Name" and (optionally) an "Icon".
    02.png

  3. Download the metadata under "Identity Provider Information" in advance.
    03.png

Now switch to configuring Alibaba Cloud.
In a separate window, log in to the Alibaba Cloud RAM console with an administrator account.

Alibaba Cloud Configuration

  1. [Create IdP]
    Open "SSO > Role-based SSO Login Method" and click "Create IdP" on the SAML tab.
    04.png

  2. Enter any name for "IdP Name", upload the metadata downloaded from TrustLogin via "Upload" under the metadata file, and click "OK" to save.
    05.png

  3. Click the name of the IdP you created and note down the "ARN" value.
    06.png

    07.png

  4. [RAM Role Configuration]
    Open "Identity > Roles" and click "Create Role".
    08.png

  5. Select "IdP" and click "Next" to proceed.
    09.png

  6. Enter any name for "RAM Role Name", select "SAML" for "IdP Type", select the IdP you created under "Select IdP", and click "Complete" to save.
    10.png

  7. Click "Grant Permissions to RAM Role".
    11.png

  8. Select the policy to grant permissions to the RAM role and click "OK".
    For details, please refer to "Grant permissions to a RAM role".
    12.png

  9. Once permissions have been granted successfully, click the "Complete" button.
    13.png

  10. Click the name of the role you created and note down the "ARN" value.
    14.png
    15.png

Return to the TrustLogin configuration again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure each item under "Service Provider Settings" as follows.
    Value for Name ID

    Select "Member" > "email"

    Entity ID urn:alibaba:cloudcomputing:international
    Name ID Format Select "emailAddress"

    ACS URL for Service

    https://signin.alibabacloud.com/saml-role/sso

    16.png

  2. In "SAML Attribute Settings", click the "Specify Custom Attribute" button, then click "Add SAML Attribute" to add a row (attribute). Configure as follows.
    Service Provider Attributes TrustLogin (IdP) Attributes
    Attribute Name (as specified) Attribute Type Attribute Name Attribute Value
    NameID Unspecified NameID

    Member

    Member - Email Address

    Value of ① below Unspecified Value of ① below Member

    Member - Email Address

    Value of ② below Unspecified Value of ② below Fixed Value

    "Role ARN", "IdP ARN"

    (Separate the "Role ARN" and "IdP ARN" with a comma (,))


    ①: https://www.aliyun.com/SAML-Role/Attributes/RoleSessionName
    ②: https://www.aliyun.com/SAML-Role/Attributes/Role

    17.png

  3. Click "Register" to save.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. In "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app in "My Page" or the "Browser Extension" and verify that login is successful.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the custom SAML app you created.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.