|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Prerequisites
With KiteRa's SAML JIT, you can choose to sync the following items.
This preparation is only required if you plan to sync "Groups".
If you do not plan to sync "Groups", please proceed to the next section, "TrustLogin Admin Page Settings".
- Last Name
- First Name
- Role
- Group
Create a Group and Assign Members
Create a group to map to a KiteRa group, and assign members to it.
(If an existing group can be used for this purpose, you may use an existing group instead.)
For instructions on how to create a group and assign members, please refer to the following page.
Registering a Group
[Configuration Example]
- Create an "Administrator" group and map it to the "Administrator" group in KiteRa
- Create a "Sales" group and map it to the "Sales" group in KiteRa
With this setup, when a user belonging to the "Administrator" group performs a SAML login to KiteRa, they will automatically be assigned to the "Administrator" group.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and "Icon" (optional).
-
Download the metadata from the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring KiteRa.
Do not click the "Register" button yet — open KiteRa in a separate window.
KiteRa Settings
- Click "Workspace Settings" in the left-hand menu.
- Open "Security" and check the box for "Configure Single Sign-On".
- Configure each item as follows.
Entity ID Copy the value using the copy button and make a note of it ACS URL Copy the value using the copy button and make a note of it IdP Settings Upload the "Metadata" obtained from TrustLogin using the "Upload IdP Metadata" button Default Group [If not using group mapping]
Set the default group to be applied when a new user is created.
(If set to "Not set", the user will not belong to any group)
[If using group mapping]
Set the default group to be applied to users who do not belong to any of the mapped groups.
(If set to "Not set", the user will not belong to any group)Keep Group Assignment in Sync [If not using group mapping]
If the checkbox is OFF, group mapping is applied only on the first login.
Turn the checkbox OFF
[If using group mapping]
Turn the checkbox ON if you want group mapping to be overwritten on every SAML login
The following items only need to be configured if you are using group mapping.
Group Mapping Settings Enter the name of the TrustLogin group to map to the KiteRa group
To perform a connection test, return to the TrustLogin settings for now.
Leave KiteRa open as it is.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Entity ID" obtained from KiteRa Name ID Format unspecified ACS URL to Service The "ACS URL" obtained from KiteRa
-
[Optional]
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure the items you want to sync as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value firstName Basic firstName Member
Member - First Name
lastName Basic lastName Member
Member - Last Name
role Basic role Member
Member - Role
groups Basic groups Group
Select the group name you configured and add it using the "+" button
Note: If you do not sync last name/first name, the user's email address will be synced as the user name in KiteRa.
Note: The "Role" is only synced when a user is created for the first time. It is not overwritten on subsequent logins, so if you want to change a user's role, you will need to do so in KiteRa's member management screen.
If you do not configure the "Role" sync, users will be created with the "Member" role.
TrustLogin Permission KiteRa User "Role" Admin Administrator General Member
[Example ①: When not syncing any items]
No configuration in "SAML Attribute Settings" is required.
[Example ②: When syncing only last name/first name]
[Example ③: When syncing all items]
For the group attribute value, select a group name from the dropdown; you can add multiple groups using the "+" mark on the right.
- Save by clicking the "Register" button.
- Add the administrator conducting the test as a member of the SAML app you created.
For instructions on how to add members, please refer to "TrustLogin User Settings" below.
Return to KiteRa again.
KiteRa Settings (Continued)
-
[Connection Test]
Click "Verify Connection with IdP" and confirm that the page displays correctly.
- Once the test is complete, check "Enable Single Sign-On" and save by clicking "Save Settings".
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
② When an Administrator Adds Members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Configure Domain Restriction
If you want to allow user creation only for email addresses in approved domains,
check "Enable Domain Restriction" under "Workspace Settings > Security > @Domain Restriction", and enter the approved domain in the email address domain field.
Save by clicking the "Save Settings" button.