Kibela SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Kibela is required.

  • SAML JIT cannot sync the "Last Name" and "First Name" of TrustLogin member information. Users must set these in Kibela's profile editing screen.
  • Please refer to the manual provided by Kibela for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Preparation (Optional)

Via SAML JIT, if you want to manage the Kibela user's "role" in TrustLogin, you need to add a custom attribute to the TrustLogin member information in advance and register the Kibela role.
If you are not managing roles via SAML JIT, this step is not required. If this step is not performed, users newly created via SAML JIT will be assigned the "Full Member" role.

Configure a custom attribute in the TrustLogin member information to link the profile.
Please refer to the following pages for instructions on how to configure it.

[TrustLogin Custom Attribute Configuration Example]
00.png

  • owner - Owner
  • admin - Administrator
  • full_member - Full Member
  • guest - Guest


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    01.png

  2. Register the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring Kibela.
Do not click the "Register" button yet — open Kibela in a separate window.

Kibela Settings

  1. Open "Settings" from the icon in the top right and click "Single Sign-On."
    04.png
    05.png

  2. Switch to the "SAML 2.0 Authentication" settings tab.
    06.png

  3. Configure each item of the identity provider settings as follows, and save by clicking the "Save" button.
    Download Download the metadata file from the link
    Identifier The "Issuer / Entity ID" obtained from TrustLogin
    Login URL The "Identity Provider URL" obtained from TrustLogin
    Certificate The contents of the "Certificate" obtained from TrustLogin

    07.png

Return to the TrustLogin settings page.
Please leave the Kibela page open as is.

TrustLogin Admin Page Settings (Continued)

  1. Resume the TrustLogin configuration.
    Under "Service Provider Settings," upload the metadata you downloaded from Kibela using the "Select Metadata" button.
    08.png

  2. [Only if you are managing the Kibela user's "role" in TrustLogin via SAML JIT]
    Configure "SAML Attribute Settings" as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    kibela.user.role Basic kibela.user.role

    Custom attribute

    The attribute name you configured


    13.png

  3. Save by clicking the "Register" button.

  4. To perform a connection test in Kibela, add the administrator running the test as a member to the SAML app you created.
    For instructions on how to add a member, see TrustLogin User Settings below.

Return to Kibela again.

Kibela Settings (Continued)

  1. Click the "Test" button to perform a connection test.
    09.png

  2. Once the test success screen is displayed, go back. (Re-login is required.)
    10.png

  3. Change the SSO setting from "Disabled" to either "Migration Mode" or "SAML2 SSO Only Enabled."
    Note: If you select "SAML2 SSO Only Enabled," users other than administrators will no longer be able to log in with their Kibela ID/password. We recommend keeping it set to "Migration Mode" until all operation verification and user notification have been completed.
    11.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Creating New Users via SAML JIT

When a user logs in to Kibela for the first time via SAML JIT, the account registration screen is displayed.
The username is automatically filled in with the account name portion of the email address, but you can change it on this screen.


12.png

Kibela SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Kibela is required.

  • SAML JIT cannot sync the "Last Name" and "First Name" of TrustLogin member information. Users must set these in Kibela's profile editing screen.
  • Please refer to the manual provided by Kibela for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Preparation (Optional)

Via SAML JIT, if you want to manage the Kibela user's "role" in TrustLogin, you need to add a custom attribute to the TrustLogin member information in advance and register the Kibela role.
If you are not managing roles via SAML JIT, this step is not required. If this step is not performed, users newly created via SAML JIT will be assigned the "Full Member" role.

Configure a custom attribute in the TrustLogin member information to link the profile.
Please refer to the following pages for instructions on how to configure it.

[TrustLogin Custom Attribute Configuration Example]
00.png

  • owner - Owner
  • admin - Administrator
  • full_member - Full Member
  • guest - Guest


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    01.png

  2. Register the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring Kibela.
Do not click the "Register" button yet — open Kibela in a separate window.

Kibela Settings

  1. Open "Settings" from the icon in the top right and click "Single Sign-On."
    04.png
    05.png

  2. Switch to the "SAML 2.0 Authentication" settings tab.
    06.png

  3. Configure each item of the identity provider settings as follows, and save by clicking the "Save" button.
    Download Download the metadata file from the link
    Identifier The "Issuer / Entity ID" obtained from TrustLogin
    Login URL The "Identity Provider URL" obtained from TrustLogin
    Certificate The contents of the "Certificate" obtained from TrustLogin

    07.png

Return to the TrustLogin settings page.
Please leave the Kibela page open as is.

TrustLogin Admin Page Settings (Continued)

  1. Resume the TrustLogin configuration.
    Under "Service Provider Settings," upload the metadata you downloaded from Kibela using the "Select Metadata" button.
    08.png

  2. [Only if you are managing the Kibela user's "role" in TrustLogin via SAML JIT]
    Configure "SAML Attribute Settings" as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    kibela.user.role Basic kibela.user.role

    Custom attribute

    The attribute name you configured


    13.png

  3. Save by clicking the "Register" button.

  4. To perform a connection test in Kibela, add the administrator running the test as a member to the SAML app you created.
    For instructions on how to add a member, see TrustLogin User Settings below.

Return to Kibela again.

Kibela Settings (Continued)

  1. Click the "Test" button to perform a connection test.
    09.png

  2. Once the test success screen is displayed, go back. (Re-login is required.)
    10.png

  3. Change the SSO setting from "Disabled" to either "Migration Mode" or "SAML2 SSO Only Enabled."
    Note: If you select "SAML2 SSO Only Enabled," users other than administrators will no longer be able to log in with their Kibela ID/password. We recommend keeping it set to "Migration Mode" until all operation verification and user notification have been completed.
    11.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Creating New Users via SAML JIT

When a user logs in to Kibela for the first time via SAML JIT, the account registration screen is displayed.
The username is automatically filled in with the account name portion of the email address, but you can change it on this screen.


12.png