|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports API-based provisioning (account management possible from TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Device-specific Verification Status |
ー |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-app Browser |
|
|
ー |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-app Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Enterprise App Registration" screen and select "iboss (SAML)".
- Download the metadata using the "Download Metadata" button under "Identity Provider Information".
At this point, switch to configuring the iboss side.
Do not click the "Register" button yet; open the iboss platform in a separate tab.
iboss Configuration
- Open "Users, Groups, Devices > User SSO > IdP Settings".
- Click "Edit General Settings".
- Configure each SAML setting item as follows, and save using the "Edit General Settings" button.
Enable SAML ON Use Cluster SAML ON Enable Message Logging OFF Enable Error Logging OFF SAML Authentication Method Cloud Connector-based SAML Authentication Bypass Domains portal.trustlogin.com,trustlogin.com,cert.sku.id,cert.trustlogin.com,
ocsp.globalsign.com,crl.globalsign.com,secure.globalsign.com,
cloud.iboss.com,iboss.com
SAML IDP Domain portal.trustlogin.com,trustlogin.com,cert.sku.id,cert.trustlogin.com,
ocsp.globalsign.com,crl.globalsign.com,secure.globalsign.com,
cloud.iboss.com,iboss.com
Session Timeout Any duration (minutes)
- Click the edit button for "General SAML Settings".
- Make a note of the "SP ACS URL" value.
Paste the contents of the metadata downloaded from TrustLogin into "IDP Metadata".
Finally, save using the "Edit IdP Settings" button. -
Configure "User Authentication Method" and "Connector Registration Method" under "Proxy & Cache > Proxy Settings > Settings" as follows, then save using the "Save" button.
User Authentication Method Local user credentials + cloud connection Connector Registration Method Standard registration + SAML
-
Open "Proxy & Cache > SSL Decryption > General Settings", configure as follows, then save using the "Save" button.
Enable Proxy SSL Decryption YES Perform SSL Decryption All destinations
-
Open "Connect Devices > Cloud Connector > Connector Settings", configure as follows, then save using the "Save" button.
Enable Session Timeout YES Session Timeout (minutes) 120
-
Open "Connect Devices > Connector Policy", click "Add Connector Policy", and create a policy with any policy name you like.
-
Configure the following items on the "Connector Settings" tab as shown below, then save using the "Save" button.
General Settings > Runtime Mode YES General Settings > Captive Portal Detection All destinations Desktop App > Enable Desktop App Enable the setting
- Open the "Dynamic Link" tab and configure the targets to which the policy will be applied.
Now return to the TrustLogin configuration.
TrustLogin Admin Page Configuration (Continued)
- Enter the "SP ACS URL" obtained from iboss into "ACS URL for Service" under "Service Provider Settings".
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "iboss (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds members
- Search for and click the "iboss (SAML)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
Verification
- Open the Desktop App and confirm that it is running in SAML mode. Clicking the "Authenticate" button redirects you to the TrustLogin authentication screen.
- Once authentication succeeds, iboss's SAML Success page is displayed.
- In the logs, the entry is displayed under the TrustLogin username (email address).