KiteRa SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in KiteRa is required.

  • Please refer to the manual provided by KiteRa for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

With KiteRa's SAML JIT, you can choose to sync the following items.
This preparation is only required if you plan to sync "Groups".
If you do not plan to sync "Groups", please proceed to the next section, "TrustLogin Admin Page Settings".

  • Last Name
  • First Name
  • Role
  • Group

Create a Group and Assign Members

Create a group to map to a KiteRa group, and assign members to it.
(If an existing group can be used for this purpose, you may use an existing group instead.)

For instructions on how to create a group and assign members, please refer to the following page.
Registering a Group

[Configuration Example]

  • Create an "Administrator" group and map it to the "Administrator" group in KiteRa
  • Create a "Sales" group and map it to the "Sales" group in KiteRa

With this setup, when a user belonging to the "Administrator" group performs a SAML login to KiteRa, they will automatically be assigned to the "Administrator" group.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring KiteRa.
Do not click the "Register" button yet — open KiteRa in a separate window.

KiteRa Settings

  1. Click "Workspace Settings" in the left-hand menu.
    04.png

  2. Open "Security" and check the box for "Configure Single Sign-On".
    05.png

  3. Configure each item as follows.
    Entity ID Copy the value using the copy button and make a note of it
    ACS URL Copy the value using the copy button and make a note of it
    IdP Settings Upload the "Metadata" obtained from TrustLogin using the "Upload IdP Metadata" button
    Default Group

    [If not using group mapping]
    Set the default group to be applied when a new user is created.
    (If set to "Not set", the user will not belong to any group)


    [If using group mapping]
    Set the default group to be applied to users who do not belong to any of the mapped groups.
    (If set to "Not set", the user will not belong to any group)

    Keep Group Assignment in Sync

    [If not using group mapping]
    Turn the checkbox OFF

    [If using group mapping]
    Turn the checkbox ON if you want group mapping to be overwritten on every SAML login

    If the checkbox is OFF, group mapping is applied only on the first login.

    The following items only need to be configured if you are using group mapping.
    Group Mapping Settings Enter the name of the TrustLogin group to map to the KiteRa group

    06.png

To perform a connection test, return to the TrustLogin settings for now.
Leave KiteRa open as it is.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from KiteRa
    Name ID Format unspecified
    ACS URL to Service The "ACS URL" obtained from KiteRa

    07.png

  2. [Optional]
    Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure the items you want to sync as follows.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    firstName Basic firstName

    Member

    Member - First Name

    lastName Basic lastName

    Member

    Member - Last Name

    role Basic role

    Member

    Member - Role

    groups Basic groups

    Group

    Select the group name you configured and add it using the "+" button


    Note: If you do not sync last name/first name, the user's email address will be synced as the user name in KiteRa.
    Note: The "Role" is only synced when a user is created for the first time. It is not overwritten on subsequent logins, so if you want to change a user's role, you will need to do so in KiteRa's member management screen.
    If you do not configure the "Role" sync, users will be created with the "Member" role.
    TrustLogin Permission KiteRa User "Role"
    Admin Administrator
    General Member


    [Example ①: When not syncing any items]
    No configuration in "SAML Attribute Settings" is required.
    11.png



    [Example ②: When syncing only last name/first name]
    08.png

    [Example ③: When syncing all items]
    For the group attribute value, select a group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    09.png


  3. Save by clicking the "Register" button.

  4. Add the administrator conducting the test as a member of the SAML app you created.
    For instructions on how to add members, please refer to "TrustLogin User Settings" below.

Return to KiteRa again.

KiteRa Settings (Continued)

  1. [Connection Test]
    Click "Verify Connection with IdP" and confirm that the page displays correctly.

  2. Once the test is complete, check "Enable Single Sign-On" and save by clicking "Save Settings".
    10.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure Domain Restriction

If you want to allow user creation only for email addresses in approved domains,
check "Enable Domain Restriction" under "Workspace Settings > Security > @Domain Restriction", and enter the approved domain in the email address domain field.
Save by clicking the "Save Settings" button.
12.png

KiteRa SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in KiteRa is required.

  • Please refer to the manual provided by KiteRa for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

With KiteRa's SAML JIT, you can choose to sync the following items.
This preparation is only required if you plan to sync "Groups".
If you do not plan to sync "Groups", please proceed to the next section, "TrustLogin Admin Page Settings".

  • Last Name
  • First Name
  • Role
  • Group

Create a Group and Assign Members

Create a group to map to a KiteRa group, and assign members to it.
(If an existing group can be used for this purpose, you may use an existing group instead.)

For instructions on how to create a group and assign members, please refer to the following page.
Registering a Group

[Configuration Example]

  • Create an "Administrator" group and map it to the "Administrator" group in KiteRa
  • Create a "Sales" group and map it to the "Sales" group in KiteRa

With this setup, when a user belonging to the "Administrator" group performs a SAML login to KiteRa, they will automatically be assigned to the "Administrator" group.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Register the "Application Name" and "Icon" (optional).
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring KiteRa.
Do not click the "Register" button yet — open KiteRa in a separate window.

KiteRa Settings

  1. Click "Workspace Settings" in the left-hand menu.
    04.png

  2. Open "Security" and check the box for "Configure Single Sign-On".
    05.png

  3. Configure each item as follows.
    Entity ID Copy the value using the copy button and make a note of it
    ACS URL Copy the value using the copy button and make a note of it
    IdP Settings Upload the "Metadata" obtained from TrustLogin using the "Upload IdP Metadata" button
    Default Group

    [If not using group mapping]
    Set the default group to be applied when a new user is created.
    (If set to "Not set", the user will not belong to any group)


    [If using group mapping]
    Set the default group to be applied to users who do not belong to any of the mapped groups.
    (If set to "Not set", the user will not belong to any group)

    Keep Group Assignment in Sync

    [If not using group mapping]
    Turn the checkbox OFF

    [If using group mapping]
    Turn the checkbox ON if you want group mapping to be overwritten on every SAML login

    If the checkbox is OFF, group mapping is applied only on the first login.

    The following items only need to be configured if you are using group mapping.
    Group Mapping Settings Enter the name of the TrustLogin group to map to the KiteRa group

    06.png

To perform a connection test, return to the TrustLogin settings for now.
Leave KiteRa open as it is.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from KiteRa
    Name ID Format unspecified
    ACS URL to Service The "ACS URL" obtained from KiteRa

    07.png

  2. [Optional]
    Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure the items you want to sync as follows.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    firstName Basic firstName

    Member

    Member - First Name

    lastName Basic lastName

    Member

    Member - Last Name

    role Basic role

    Member

    Member - Role

    groups Basic groups

    Group

    Select the group name you configured and add it using the "+" button


    Note: If you do not sync last name/first name, the user's email address will be synced as the user name in KiteRa.
    Note: The "Role" is only synced when a user is created for the first time. It is not overwritten on subsequent logins, so if you want to change a user's role, you will need to do so in KiteRa's member management screen.
    If you do not configure the "Role" sync, users will be created with the "Member" role.
    TrustLogin Permission KiteRa User "Role"
    Admin Administrator
    General Member


    [Example ①: When not syncing any items]
    No configuration in "SAML Attribute Settings" is required.
    11.png



    [Example ②: When syncing only last name/first name]
    08.png

    [Example ③: When syncing all items]
    For the group attribute value, select a group name from the dropdown; you can add multiple groups using the "+" mark on the right.
    09.png


  3. Save by clicking the "Register" button.

  4. Add the administrator conducting the test as a member of the SAML app you created.
    For instructions on how to add members, please refer to "TrustLogin User Settings" below.

Return to KiteRa again.

KiteRa Settings (Continued)

  1. [Connection Test]
    Click "Verify Connection with IdP" and confirm that the page displays correctly.

  2. Once the test is complete, check "Enable Single Sign-On" and save by clicking "Save Settings".
    10.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure Domain Restriction

If you want to allow user creation only for email addresses in approved domains,
check "Enable Domain Restriction" under "Workspace Settings > Security > @Domain Restriction", and enter the approved domain in the email address domain field.
Save by clicking the "Save Settings" button.
12.png