GitHub SAML JIT Setup Guide

Item

Details

Pre-check

  • The SAML SSO covered in this manual authenticates a specific organization in GitHub. A separate GitHub account and sign-in are required.

  • Your GitHub Organization must be using GitHub Enterprise Cloud.
  • For the latest setup instructions, please refer to the manual provided by GitHub.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01_.png

  2. Search on the "Register Company App" screen and select "GitHub (SAML)".
    02.png

  3. Make a note of the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the "Certificate".
    03.png

  4. Enter your GitHub Organization account name in the two blank fields under "Service Provider Settings".
    Example: For https://github.com/test, enter "test"
    04.png

  5. Save by clicking the "Register" button.

  6. To perform a connection test in the GitHub settings below, add the administrator performing this configuration as a member of the SAML app you created. Search for the "GitHub (SAML)" app in the "Admin Page > App" menu, and add the administrator account using "Add Member".
    09.png

GitHub Settings

  1. After logging in to GitHub with an Owner account, click the icon in the upper right > "Your Organization".
    05.png

  2. Click "Settings" to the right of the target Organization name.
    06.png

  3. Click "Security" > "Authentication security" in the left menu.
    07.png

  4. Configure each item of "SAML single sign-on" as follows.
    Enable SAML authentication Check the checkbox
    Sign on URL The "IdP URL" you noted from TrustLogin
    Issuer The "Issuer / Entity ID" you noted from TrustLogin
    Public Certificate The contents of the certificate downloaded from TrustLogin

    08.png

  5. Click " Test SAML configuration" and confirm that SAML authentication succeeds.

  6. For the "Require SAML SSO authentication for all members of the test-globalsign organization" checkbox, please review the following and check it as needed based on your operational requirements.
    Enforcing SAML single sign-on for your organization - GitHub Enterprise Cloud Docs

  7. Click "SAVE".

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "GitHub (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

②When an administrator adds members

  1. Search for and click the "GitHub (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In to GitHub

Single sign-on via GitHub's SAML authentication authenticates a specific organization in GitHub. It cannot authenticate GitHub itself. Members must separately sign in to their individual account in GitHub.

How to log in when you are already logged in to your GitHub.com individual account

  1. Click "GitHub (SAML)" from TrustLogin's "My Page" or the browser extension.
  2. Login to the GitHub Organization is complete.

② How to log in when you are not logged in to your GitHub.com individual account

  1. Click "GitHub (SAML)" from TrustLogin's "My Page" or the browser extension.
  2. You will be taken to the GitHub login screen. Enter your individual account password and click the sign-in button.
    10.png
  3. Login to the GitHub Organization is complete.




GitHub SAML JIT Setup Guide

Item

Details

Pre-check

  • The SAML SSO covered in this manual authenticates a specific organization in GitHub. A separate GitHub account and sign-in are required.

  • Your GitHub Organization must be using GitHub Enterprise Cloud.
  • For the latest setup instructions, please refer to the manual provided by GitHub.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01_.png

  2. Search on the "Register Company App" screen and select "GitHub (SAML)".
    02.png

  3. Make a note of the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the "Certificate".
    03.png

  4. Enter your GitHub Organization account name in the two blank fields under "Service Provider Settings".
    Example: For https://github.com/test, enter "test"
    04.png

  5. Save by clicking the "Register" button.

  6. To perform a connection test in the GitHub settings below, add the administrator performing this configuration as a member of the SAML app you created. Search for the "GitHub (SAML)" app in the "Admin Page > App" menu, and add the administrator account using "Add Member".
    09.png

GitHub Settings

  1. After logging in to GitHub with an Owner account, click the icon in the upper right > "Your Organization".
    05.png

  2. Click "Settings" to the right of the target Organization name.
    06.png

  3. Click "Security" > "Authentication security" in the left menu.
    07.png

  4. Configure each item of "SAML single sign-on" as follows.
    Enable SAML authentication Check the checkbox
    Sign on URL The "IdP URL" you noted from TrustLogin
    Issuer The "Issuer / Entity ID" you noted from TrustLogin
    Public Certificate The contents of the certificate downloaded from TrustLogin

    08.png

  5. Click " Test SAML configuration" and confirm that SAML authentication succeeds.

  6. For the "Require SAML SSO authentication for all members of the test-globalsign organization" checkbox, please review the following and check it as needed based on your operational requirements.
    Enforcing SAML single sign-on for your organization - GitHub Enterprise Cloud Docs

  7. Click "SAVE".

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "GitHub (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

②When an administrator adds members

  1. Search for and click the "GitHub (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In to GitHub

Single sign-on via GitHub's SAML authentication authenticates a specific organization in GitHub. It cannot authenticate GitHub itself. Members must separately sign in to their individual account in GitHub.

How to log in when you are already logged in to your GitHub.com individual account

  1. Click "GitHub (SAML)" from TrustLogin's "My Page" or the browser extension.
  2. Login to the GitHub Organization is complete.

② How to log in when you are not logged in to your GitHub.com individual account

  1. Click "GitHub (SAML)" from TrustLogin's "My Page" or the browser extension.
  2. You will be taken to the GitHub login screen. Enter your individual account password and click the sign-in button.
    10.png
  3. Login to the GitHub Organization is complete.