How to Configure SAML Authentication for iboss

Item

Details

Prerequisites

  • Prior configuration on the iboss side is required.

  • You must create an account in iboss using the same email address as TrustLogin.

  • SAML authentication is performed using Cloud Connector. SAML authentication over other types of connections is not supported.
    Note: The version verified for this manual is "Windows Cloud Connector 6.0.130.0"
  • The information in this manual may differ if the specifications of the iboss Cloud version change.
    For the latest configuration procedures, please refer to the manual provided by iboss.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports API-based provisioning (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device-specific Verification Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-app Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-app Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Enterprise App Registration" screen and select "iboss (SAML)".
    02.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".
    03.png

At this point, switch to configuring the iboss side.
Do not click the "Register" button yet; open the iboss platform in a separate tab.

iboss Configuration

  1. Open "Users, Groups, Devices > User SSO > IdP Settings".
    04.png

  2. Click "Edit General Settings".
    05.png
  3. Configure each SAML setting item as follows, and save using the "Edit General Settings" button.
    Enable SAML ON
    Use Cluster SAML ON
    Enable Message Logging OFF
    Enable Error Logging OFF
    SAML Authentication Method Cloud Connector-based
    SAML Authentication Bypass Domains

    portal.trustlogin.com,trustlogin.com,cert.sku.id,cert.trustlogin.com,

    ocsp.globalsign.com,crl.globalsign.com,secure.globalsign.com,

    cloud.iboss.com,iboss.com

    SAML IDP Domain

    portal.trustlogin.com,trustlogin.com,cert.sku.id,cert.trustlogin.com,

    ocsp.globalsign.com,crl.globalsign.com,secure.globalsign.com,

    cloud.iboss.com,iboss.com

    Session Timeout Any duration (minutes)

    06.png

  4. Click the edit button for "General SAML Settings".
    07.png

  5. Make a note of the "SP ACS URL" value.
    Paste the contents of the metadata downloaded from TrustLogin into "IDP Metadata".
    Finally, save using the "Edit IdP Settings" button.
    08.png

  6. Configure "User Authentication Method" and "Connector Registration Method" under "Proxy & Cache > Proxy Settings > Settings" as follows, then save using the "Save" button.
    User Authentication Method Local user credentials + cloud connection
    Connector Registration Method Standard registration + SAML

    09.png

  7. Open "Proxy & Cache > SSL Decryption > General Settings", configure as follows, then save using the "Save" button.
    Enable Proxy SSL Decryption YES
    Perform SSL Decryption All destinations

    10.png

  8. Open "Connect Devices > Cloud Connector > Connector Settings", configure as follows, then save using the "Save" button.
    Enable Session Timeout YES
    Session Timeout (minutes)

    120


    11.png
  9. Open "Connect Devices > Connector Policy", click "Add Connector Policy", and create a policy with any policy name you like.
    12.png

  10. Configure the following items on the "Connector Settings" tab as shown below, then save using the "Save" button.
    General Settings > Runtime Mode YES
    General Settings > Captive Portal Detection All destinations
    Desktop App > Enable Desktop App Enable the setting

    13.png
    14.png

  11. Open the "Dynamic Link" tab and configure the targets to which the policy will be applied.
    15.png

Now return to the TrustLogin configuration.

TrustLogin Admin Page Configuration (Continued)

  1. Enter the "SP ACS URL" obtained from iboss into "ACS URL for Service" under "Service Provider Settings".
    16.png

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "iboss (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for and click the "iboss (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

Verification

  1. Open the Desktop App and confirm that it is running in SAML mode. Clicking the "Authenticate" button redirects you to the TrustLogin authentication screen.

  2. Once authentication succeeds, iboss's SAML Success page is displayed.

  3. In the logs, the entry is displayed under the TrustLogin username (email address).
    17.png

How to Configure SAML Authentication for iboss

Item

Details

Prerequisites

  • Prior configuration on the iboss side is required.

  • You must create an account in iboss using the same email address as TrustLogin.

  • SAML authentication is performed using Cloud Connector. SAML authentication over other types of connections is not supported.
    Note: The version verified for this manual is "Windows Cloud Connector 6.0.130.0"
  • The information in this manual may differ if the specifications of the iboss Cloud version change.
    For the latest configuration procedures, please refer to the manual provided by iboss.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports API-based provisioning (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device-specific Verification Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-app Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-app Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Enterprise App Registration" screen and select "iboss (SAML)".
    02.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".
    03.png

At this point, switch to configuring the iboss side.
Do not click the "Register" button yet; open the iboss platform in a separate tab.

iboss Configuration

  1. Open "Users, Groups, Devices > User SSO > IdP Settings".
    04.png

  2. Click "Edit General Settings".
    05.png
  3. Configure each SAML setting item as follows, and save using the "Edit General Settings" button.
    Enable SAML ON
    Use Cluster SAML ON
    Enable Message Logging OFF
    Enable Error Logging OFF
    SAML Authentication Method Cloud Connector-based
    SAML Authentication Bypass Domains

    portal.trustlogin.com,trustlogin.com,cert.sku.id,cert.trustlogin.com,

    ocsp.globalsign.com,crl.globalsign.com,secure.globalsign.com,

    cloud.iboss.com,iboss.com

    SAML IDP Domain

    portal.trustlogin.com,trustlogin.com,cert.sku.id,cert.trustlogin.com,

    ocsp.globalsign.com,crl.globalsign.com,secure.globalsign.com,

    cloud.iboss.com,iboss.com

    Session Timeout Any duration (minutes)

    06.png

  4. Click the edit button for "General SAML Settings".
    07.png

  5. Make a note of the "SP ACS URL" value.
    Paste the contents of the metadata downloaded from TrustLogin into "IDP Metadata".
    Finally, save using the "Edit IdP Settings" button.
    08.png

  6. Configure "User Authentication Method" and "Connector Registration Method" under "Proxy & Cache > Proxy Settings > Settings" as follows, then save using the "Save" button.
    User Authentication Method Local user credentials + cloud connection
    Connector Registration Method Standard registration + SAML

    09.png

  7. Open "Proxy & Cache > SSL Decryption > General Settings", configure as follows, then save using the "Save" button.
    Enable Proxy SSL Decryption YES
    Perform SSL Decryption All destinations

    10.png

  8. Open "Connect Devices > Cloud Connector > Connector Settings", configure as follows, then save using the "Save" button.
    Enable Session Timeout YES
    Session Timeout (minutes)

    120


    11.png
  9. Open "Connect Devices > Connector Policy", click "Add Connector Policy", and create a policy with any policy name you like.
    12.png

  10. Configure the following items on the "Connector Settings" tab as shown below, then save using the "Save" button.
    General Settings > Runtime Mode YES
    General Settings > Captive Portal Detection All destinations
    Desktop App > Enable Desktop App Enable the setting

    13.png
    14.png

  11. Open the "Dynamic Link" tab and configure the targets to which the policy will be applied.
    15.png

Now return to the TrustLogin configuration.

TrustLogin Admin Page Configuration (Continued)

  1. Enter the "SP ACS URL" obtained from iboss into "ACS URL for Service" under "Service Provider Settings".
    16.png

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "iboss (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for and click the "iboss (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

Verification

  1. Open the Desktop App and confirm that it is running in SAML mode. Clicking the "Authenticate" button redirects you to the TrustLogin authentication screen.

  2. Once authentication succeeds, iboss's SAML Success page is displayed.

  3. In the logs, the entry is displayed under the TrustLogin username (email address).
    17.png