How to Configure SAML Authentication for Terraform Cloud

Item

Details

Prerequisites

  • Advance configuration is required on the Terraform Cloud side.

  • You must create a Terraform Cloud account using the same email address as your TrustLogin account.

  • Please refer to the latest setup instructions provided by Terraform Cloud for the most up-to-date configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created individually on each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Standard browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

TrustLogin Admin Page settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Terraform Cloud (SAML)."
    02.png

  3. Note the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, switch over to the Terraform Cloud settings.
Do not click the "Register" button yet — open Terraform Cloud in a separate window.

Terraform Cloud settings

  1. Open "Settings > SSO" and click "Setup SSO."
    04.png

  2. Select "SAML" and proceed by clicking "Next."
    05.png

  3. Turn on "Toggle to edit settings for Single Sign-On URL, Issuer URL and X.509 Certificate," then configure each field as follows. Finally, save by clicking "Save settings."
    Single Sign-On URL The "IdP URL" obtained from TrustLogin
    Entity ID or Issuer URL The "Issuer / Entity ID" obtained from TrustLogin
    X.509 Certificate The contents of the "certificate" obtained from TrustLogin
    Turn the toggle OFF

    006.png

    06.png

  4. Copy the values of "Entity ID" and "Assertion Consumer URL."
    07.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page settings (continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from Terraform Cloud
    ACS URL for the service The "Assertion Consumer URL" obtained from Terraform Cloud

    10.png

  2. Save by clicking the "Register" button.

TrustLogin user settings

① When a user adds the app from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Terraform Cloud (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Terraform Cloud (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Return to Terraform Cloud again.

Terraform Cloud settings (connection test and activation)

  1. Click "Status > Test."
    08.png

  2. Once the test succeeds, click "Configuration > Enable," then click "Enable SAML" in the dialog that appears.
    Note: Users who are not members of the owners team will no longer be able to log in with an ID/password.
    09.png

    11.png

How to Configure SAML Authentication for Terraform Cloud

Item

Details

Prerequisites

  • Advance configuration is required on the Terraform Cloud side.

  • You must create a Terraform Cloud account using the same email address as your TrustLogin account.

  • Please refer to the latest setup instructions provided by Terraform Cloud for the most up-to-date configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created individually on each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Standard browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

TrustLogin Admin Page settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Terraform Cloud (SAML)."
    02.png

  3. Note the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, switch over to the Terraform Cloud settings.
Do not click the "Register" button yet — open Terraform Cloud in a separate window.

Terraform Cloud settings

  1. Open "Settings > SSO" and click "Setup SSO."
    04.png

  2. Select "SAML" and proceed by clicking "Next."
    05.png

  3. Turn on "Toggle to edit settings for Single Sign-On URL, Issuer URL and X.509 Certificate," then configure each field as follows. Finally, save by clicking "Save settings."
    Single Sign-On URL The "IdP URL" obtained from TrustLogin
    Entity ID or Issuer URL The "Issuer / Entity ID" obtained from TrustLogin
    X.509 Certificate The contents of the "certificate" obtained from TrustLogin
    Turn the toggle OFF

    006.png

    06.png

  4. Copy the values of "Entity ID" and "Assertion Consumer URL."
    07.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page settings (continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from Terraform Cloud
    ACS URL for the service The "Assertion Consumer URL" obtained from Terraform Cloud

    10.png

  2. Save by clicking the "Register" button.

TrustLogin user settings

① When a user adds the app from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Terraform Cloud (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Terraform Cloud (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Return to Terraform Cloud again.

Terraform Cloud settings (connection test and activation)

  1. Click "Status > Test."
    08.png

  2. Once the test succeeds, click "Configuration > Enable," then click "Enable SAML" in the dialog that appears.
    Note: Users who are not members of the owners team will no longer be able to log in with an ID/password.
    09.png

    11.png