This page explains the procedure for using Salesforce as a SAML Identity Provider (IdP)
and integrating it with TrustLogin.
Configuration is performed on both the Salesforce side and the TrustLogin Admin Page.
Prerequisites
- You must apply for the External IdP Integration option under TrustLogin's optional features.
- You must create a TrustLogin account using the same email address as your Salesforce account.
Note: If you use the login ID for matching, the email addresses do not need to match.
Reference: NameID Settings for External IdP (SAML) Integration - TrustLogin's External IdP Integration only supports SP-Initiated SSO.
- If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
Note: We recommend that administrator users keep password authentication assigned in case of emergencies.
Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords
Configuration Steps
Salesforce Configuration
Note: For the latest configuration steps, please check the manual provided by Salesforce.
Reference (external site): Define a Service Provider Using a SAML-Enabled Connected App
-
Log in to Salesforce with an administrator account.
- Under "Administration" > "Security Controls" > "Identity Provider," click the "Enable Identity Provider" button.
On the next screen, select a certificate from the dropdown menu.
- Under "Identity Provider Setup," note down the "Issuer," and
save the certificate file using the "Download Certificate" button.
-
Next to "Service Provider," click
"A service provider has been created with a connected app. Click here."
to proceed to the "New Connected App" screen.
Set each field in "Basic Information" as shown below, and
upload the logo.Field Value / Details Connected App Name TrustLogin API Name TrustLogin Contact Email idaas-jp@globalsign.com
-
Next, in "Web App Settings," turn on "SAML Enabled,"
configure each field as shown below, and click the "Save" button.Field Value / Details Start URL (Optional) Note: External IdP Integration normally only supports SP-Initiated SSO,
but setting the following URL in "Start URL" allows you to initiate the flow from the IdP.
Configure this as needed.https://portal.trustlogin.com/
Entity ID trustlogin-saml-sp ACS URL https://portal.trustlogin.com/saml/acs Subject Type Username Name ID Format Specify the format of the user attribute to send as the NameID.
- Click the "Manage" button and note the "SP-Initiated Redirect Endpoint (SSO URL)" on the next screen. Also,
click the "Manage Profiles" button and select the profiles of the users who will use the IdP integration.
This completes the Salesforce-side configuration.
Next, configure the TrustLogin side.
TrustLogin Configuration
- Log in to TrustLogin, and
on the "Admin Page," open "Settings > Optional Features > External IdP Integration > Configure."
- Open "Add SAML IDP."
-
On the "Create SAML Identity Provider" screen, enter the following information.
Field Value / Details Name Enter any name you like.
Example: SalesforceSSO URL Salesforce Configuration > the "SSO URL" value noted in Step 5 Entity ID Salesforce Configuration > the "Issuer" value noted in Step 3 SAML Identity Provider Certificate Salesforce Configuration > the certificate information downloaded in Step 3
Note: Open the certificate in a text editor and copy and paste the text.NameID Format Specify the format to send as the NameID.
Salesforce Configuration > Select a value that matches the format specified in "Name ID Format" in Step 5.
Note: For details, see herePreferred NameID Attribute Specify the member attribute to prioritize when matching the NameID.
Note: For details, see hereCase-Sensitive Specify whether to distinguish between uppercase and lowercase letters when matching the NameID.
Note: For details, see here
- Click "Register."
- Next, assign the members who will log in using their Salesforce ID.
From the External IdP list, click the name of the SAML IDP you just added.
- Click "Add Member." (If adding by group, click "Add Group" instead.)
-
Select the target members and click the "Register" button.
The member addition is now complete.
This completes the configuration.
Verifying the Configuration
On the TrustLogin login page, enter your company ID and email address, and a Salesforce button will appear.
Log in using that button.