How to Configure SAML Authentication for Zabbix

Item

Details

Pre-check

  • Prior configuration in Zabbix is required.

  • You need to create a Zabbix account using the same email address as your TrustLogin account in advance.

  • For the latest setup instructions, please refer to the manual provided by Zabbix.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: Depends on the compatibility of the server on which Zabbix is installed

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Add App" button in the upper right of the screen.
    01.png

  2. Search on the "Add Enterprise App" screen and select "Zabbix (SAML)".
    zabbix01.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    zabbix02.png

  4. Enter your "Zabbix" login URL into "Service ACS URL" under "Service Provider Settings".
    Example: https://example.com/zabbix/ui, http://another.example.com/zabbix, etc.
    zabbix05.png

  5. Click the "Register" button to save the settings.

Zabbix Settings

  1. Log in with an administrator account and open "Administration > Authentication".
    zabbix03.png

  2. In the "SAML settings" section, configure as follows and click "Update".
    Enable SAML authentication Check the box
    IdP entity ID The "Issuer/Entity ID" you noted from TrustLogin
    SSO service URL The "Identity Provider URL" you noted from TrustLogin
    usrEmail
    SP entity ID zabbix
    Case-sensitive login Check the box

    zabbix04.png

  3. Download the certificate you noted from TrustLogin as idp.crt into the ui/conf/certs folder, and run the following to set permissions to 644.

    chmod 644 idp.crt

TrustLogin User Settings

① When a user adds it from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Zabbix (SAML)" on the "Add App" screen and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Zabbix (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Zabbix

Item

Details

Pre-check

  • Prior configuration in Zabbix is required.

  • You need to create a Zabbix account using the same email address as your TrustLogin account in advance.

  • For the latest setup instructions, please refer to the manual provided by Zabbix.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: Depends on the compatibility of the server on which Zabbix is installed

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Add App" button in the upper right of the screen.
    01.png

  2. Search on the "Add Enterprise App" screen and select "Zabbix (SAML)".
    zabbix01.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    zabbix02.png

  4. Enter your "Zabbix" login URL into "Service ACS URL" under "Service Provider Settings".
    Example: https://example.com/zabbix/ui, http://another.example.com/zabbix, etc.
    zabbix05.png

  5. Click the "Register" button to save the settings.

Zabbix Settings

  1. Log in with an administrator account and open "Administration > Authentication".
    zabbix03.png

  2. In the "SAML settings" section, configure as follows and click "Update".
    Enable SAML authentication Check the box
    IdP entity ID The "Issuer/Entity ID" you noted from TrustLogin
    SSO service URL The "Identity Provider URL" you noted from TrustLogin
    usrEmail
    SP entity ID zabbix
    Case-sensitive login Check the box

    zabbix04.png

  3. Download the certificate you noted from TrustLogin as idp.crt into the ui/conf/certs folder, and run the following to set permissions to 644.

    chmod 644 idp.crt

TrustLogin User Settings

① When a user adds it from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Zabbix (SAML)" on the "Add App" screen and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Zabbix (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.