|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Provisioning via API supported (account management possible in TrustLogin) |
|
| 〇 |
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
|
|
|
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Prerequisites
Only if you want to automatically assign users to a Rapid7 group, perform the following prerequisite setup.
Create groups with the same name in both Rapid7 and TrustLogin.
[Configuration Example]
The following is an example for illustration purposes. Please configure group names and assigned products/roles to match your own operational needs.
- Configure groups in Rapid7. (User Management > User Groups)
Create the groups "Admin" and "Viewer" and assign a product and role to each.
- Also create groups named "Admin" and "Viewer" in TrustLogin and assign members to them.
For instructions on how to register groups and assign members, please refer to the following page.
Register a Group
With this configuration, when a user belonging to the "Admin" group in TrustLogin performs SAML login to Rapid7, they will automatically become a member of the "Admin" group and be assigned the configured product and role.
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
- Configure the "Application Name" and "Icon" (optional).
- Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, switch to configuring the Rapid7 side.
Do not click the "Register" button yet — open Rapid7 in a separate window.
Rapid7 Configuration
- Open the "Data management" icon at the top right > "Agents".
- Open the "Settings" icon in the left menu > "SSO Settings", and configure each item as follows.
Select your Identity Provider (IdP) Select "Other" Add your IdP Certificate Drag and drop the "certificate" obtained from TrustLogin into the box, or upload it using the "Browse" button
Assertion Consumer Service (ACS) URL Copy the value using the "Copy" button on the right Audience (EntityID) Copy the value using the "Copy" button on the right Relay State Copy the value using the "Copy" button on the right Entity ID The "Issuer/Entity ID" obtained from TrustLogin Single Sign-On Service URL The "Identity Provider URL" obtained from TrustLogin
- Configure "Set Up Default Access Profile".
This lets you define the product and role that will automatically be assigned to newly provisioned users.
For detailed steps, please see here. -
Configure "Synchronize IdP Groups with User Groups".
If you want to automatically assign users to a Rapid7 group Select "IdP group synchronization active" If you do not want to automatically assign users to a Rapid7 group Select "IdP group synchronization inactive"
- Save your settings by clicking the "Submit and turn on SSO" button.
- Even after enabling SSO, existing "local users" can still log in to Rapid7 with an ID/password. However, once a user authenticates via SSO, they become an "IdP user" and can no longer log in with an ID/password afterward. Please be aware of this.
- An IdP user cannot be reverted to a local user.
-
For this reason, we recommend keeping at least one local user as a platform administrator user.
IdP users and local users can be distinguished by the badge shown in the user list.
Now return to the TrustLogin admin page again.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Redirect URL after successful SP authentication The "Relay State" obtained from Rapid7 Value for Name ID "Member" > "email" Entity ID The "Audience (EntityID)" obtained from Rapid7 Name ID Format "Unspecified" ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Rapid7
-
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure each row as follows.
The Group row only needs to be configured if you want to automatically assign users to a group.
Select the group name for the group attribute value from the dropdown; you can add multiple groups using the "+" mark on the right.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value FirstName Unspecified FirstName Member
Member - First Name
LastName Unspecified LastName Member
Member - Last Name
Email Unspecified Email Member
Member - Email Address
rbacGroups Unspecified rbacGroups Group
Select the configured group name and add all of them using the "+" button
[When automatically assigning users to a group]
[When not automatically assigning users to a group]
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
②When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.