|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "GitHub (SAML)".
- Make a note of the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the "Certificate".
- Enter your GitHub Organization account name in the two blank fields under "Service Provider Settings".
Example: For https://github.com/test, enter "test"
- Save by clicking the "Register" button.
- To perform a connection test in the GitHub settings below, add the administrator performing this configuration as a member of the SAML app you created. Search for the "GitHub (SAML)" app in the "Admin Page > App" menu, and add the administrator account using "Add Member".
GitHub Settings
- After logging in to GitHub with an Owner account, click the icon in the upper right > "Your Organization".
- Click "Settings" to the right of the target Organization name.
- Click "Security" > "Authentication security" in the left menu.
- Configure each item of "SAML single sign-on" as follows.
Enable SAML authentication Check the checkbox Sign on URL The "IdP URL" you noted from TrustLogin Issuer The "Issuer / Entity ID" you noted from TrustLogin Public Certificate The contents of the certificate downloaded from TrustLogin
- Click " Test SAML configuration" and confirm that SAML authentication succeeds.
- For the "Require SAML SSO authentication for all members of the test-globalsign organization" checkbox, please review the following and check it as needed based on your operational requirements.
Enforcing SAML single sign-on for your organization - GitHub Enterprise Cloud Docs
- Click "SAVE".
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "GitHub (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
②When an administrator adds members
- Search for and click the "GitHub (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
How to Log In to GitHub
Single sign-on via GitHub's SAML authentication authenticates a specific organization in GitHub. It cannot authenticate GitHub itself. Members must separately sign in to their individual account in GitHub.
① How to log in when you are already logged in to your GitHub.com individual account
- Click "GitHub (SAML)" from TrustLogin's "My Page" or the browser extension.
- Login to the GitHub Organization is complete.
② How to log in when you are not logged in to your GitHub.com individual account
- Click "GitHub (SAML)" from TrustLogin's "My Page" or the browser extension.
- You will be taken to the GitHub login screen. Enter your individual account password and click the sign-in button.
- Login to the GitHub Organization is complete.