|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side settings |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created individually on each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - In-app browser of the TrustLogin mobile app |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - In-app browser of the TrustLogin mobile app |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Corporate App" screen and select "Terraform Cloud (SAML)."
- Note the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
Now, switch over to the Terraform Cloud settings.
Do not click the "Register" button yet — open Terraform Cloud in a separate window.
Terraform Cloud settings
- Open "Settings > SSO" and click "Setup SSO."
- Select "SAML" and proceed by clicking "Next."
- Turn on "Toggle to edit settings for Single Sign-On URL, Issuer URL and X.509 Certificate," then configure each field as follows. Finally, save by clicking "Save settings."
Single Sign-On URL The "IdP URL" obtained from TrustLogin Entity ID or Issuer URL The "Issuer / Entity ID" obtained from TrustLogin X.509 Certificate The contents of the "certificate" obtained from TrustLogin Turn the toggle OFF
- Copy the values of "Entity ID" and "Assertion Consumer URL."
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page settings (continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Entity ID" obtained from Terraform Cloud ACS URL for the service The "Assertion Consumer URL" obtained from Terraform Cloud
- Save by clicking the "Register" button.
TrustLogin user settings
① When a user adds the app from My Page
- On "My Page," click the "Add App" button.
- On the "Register App" screen, select "Terraform Cloud (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "Terraform Cloud (SAML)" app.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
Return to Terraform Cloud again.
Terraform Cloud settings (connection test and activation)
- Click "Status > Test."
- Once the test succeeds, click "Configuration > Enable," then click "Enable SAML" in the dialog that appears.
Note: Users who are not members of the owners team will no longer be able to log in with an ID/password.