|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Preparation (Optional)
Via SAML JIT, if you want to manage the Kibela user's "role" in TrustLogin, you need to add a custom attribute to the TrustLogin member information in advance and register the Kibela role.
If you are not managing roles via SAML JIT, this step is not required. If this step is not performed, users newly created via SAML JIT will be assigned the "Full Member" role.
Configure a custom attribute in the TrustLogin member information to link the profile.
Please refer to the following pages for instructions on how to configure it.
[TrustLogin Custom Attribute Configuration Example]
- owner - Owner
- admin - Administrator
- full_member - Full Member
- guest - Guest
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
- Register the "Application Name" and "Icon" (optional).
-
Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
Now, switch to configuring Kibela.
Do not click the "Register" button yet — open Kibela in a separate window.
Kibela Settings
- Open "Settings" from the icon in the top right and click "Single Sign-On."
- Switch to the "SAML 2.0 Authentication" settings tab.
-
Configure each item of the identity provider settings as follows, and save by clicking the "Save" button.
Download Download the metadata file from the link Identifier The "Issuer / Entity ID" obtained from TrustLogin Login URL The "Identity Provider URL" obtained from TrustLogin Certificate The contents of the "Certificate" obtained from TrustLogin
Return to the TrustLogin settings page.
Please leave the Kibela page open as is.
TrustLogin Admin Page Settings (Continued)
- Resume the TrustLogin configuration.
Under "Service Provider Settings," upload the metadata you downloaded from Kibela using the "Select Metadata" button. -
[Only if you are managing the Kibela user's "role" in TrustLogin via SAML JIT]
Configure "SAML Attribute Settings" as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value kibela.user.role Basic kibela.user.role Custom attribute
The attribute name you configured
- Save by clicking the "Register" button.
-
To perform a connection test in Kibela, add the administrator running the test as a member to the SAML app you created.
For instructions on how to add a member, see TrustLogin User Settings below.
Return to Kibela again.
Kibela Settings (Continued)
- Click the "Test" button to perform a connection test.
- Once the test success screen is displayed, go back. (Re-login is required.)
- Change the SSO setting from "Disabled" to either "Migration Mode" or "SAML2 SSO Only Enabled."
Note: If you select "SAML2 SSO Only Enabled," users other than administrators will no longer be able to log in with their Kibela ID/password. We recommend keeping it set to "Migration Mode" until all operation verification and user notification have been completed.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
②When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
Creating New Users via SAML JIT
When a user logs in to Kibela for the first time via SAML JIT, the account registration screen is displayed.
The username is automatically filled in with the account name portion of the email address, but you can change it on this screen.