Verona Client (Verona Cloud Console) SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Verona Cloud Console is required.

  • This manual describes the steps to create users in Verona Client (Verona Cloud Console) via SAML JIT using their last name and email address from TrustLogin. If you want to create users with their full name, follow the setup steps in this manual.
  • For the latest setup instructions, please check the manual provided by Verona.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Users (SAML authentication only); Administrators (password authentication only)

Notes
  • SAML JIT for Verona Client (Verona Cloud Console) only supports creating new users.
  • Existing users cannot be switched to SAML authentication. If you want to switch a user to SAML authentication, delete the user and recreate them via SAML JIT.
  • When a user is created via SAML JIT, the authentication type in Verona Cloud Console switches to "IDaaS".
  • SCIM is not currently supported, so if you need to sync user deletions or changes, you must perform these operations directly in Verona Cloud Console.

Table of Contents:

TrustLogin Admin Page Settings

Verona Cloud Console Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Login Method

If You Want to Switch the User Logging in to Verona Client

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Verona Client (SAML)".
    verona05.png

  3. Note the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.03.png


[Convert the Certificate Format]
Convert the file extension of the downloaded certificate to ".cer".

Now, switch to configuring the Verona Cloud Console side.
Do not click the "Register" button yet — open Verona Cloud Console in a separate window.

Verona Cloud Console Settings

  1. Log in to Verona Cloud Console and open "Owner > Edit Owner > Single Sign-On". Configure the settings as follows, then click "Update".
    Single Sign-On Enabled
    SAML JIT Provisioning Enabled
    Identifier (Entity ID) Copy and make a note of it
    Response URL Copy and make a note of it
    Login URL The "IdP URL" noted from TrustLogin
    Issuer Identifier The "Issuer/Entity ID" noted from TrustLogin
    Verona Client Login URL

    Copy and make a note of it

    Note: This is the URL entered when logging in to Verona Client.

    Share this URL with Verona Client users.

    This is not the URL to configure on the TrustLogin side.


    verona03.png
  2. Select the TrustLogin certificate from "Choose File" and upload it.
    Note: Upload the certificate with the file extension converted to ".cer".
    verona06.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Identifier (Entity ID)" noted from Verona Cloud Console
    ACS URL to Service The "Response URL" noted from Verona Cloud Console

    verona01.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Verona Client (SAML)", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "Verona Client (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

  1. Launch Verona Client and open "Option Settings".
    verona04.png

  2. Click "Verona Cloud, IDaaS".
    verona.png

  3. Enter the "Verona Client Login URL" you noted from Verona Cloud Console into "Login URL", and
    click "OK".
    verona02.png

  4. You will be redirected to the TrustLogin login screen. Please log in there.

If You Want to Switch the User Logging in to Verona Client

In "Login URL", enter "https://portal.trustlogin.com/users/sign_out", and click "OK" to log out of TrustLogin.

After that, perform the steps in "Login Method > 3." again, and log in with the TrustLogin user information you want to switch to. This will allow you to switch users.
verona07.png

Verona Client (Verona Cloud Console) SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Verona Cloud Console is required.

  • This manual describes the steps to create users in Verona Client (Verona Cloud Console) via SAML JIT using their last name and email address from TrustLogin. If you want to create users with their full name, follow the setup steps in this manual.
  • For the latest setup instructions, please check the manual provided by Verona.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Users (SAML authentication only); Administrators (password authentication only)

Notes
  • SAML JIT for Verona Client (Verona Cloud Console) only supports creating new users.
  • Existing users cannot be switched to SAML authentication. If you want to switch a user to SAML authentication, delete the user and recreate them via SAML JIT.
  • When a user is created via SAML JIT, the authentication type in Verona Cloud Console switches to "IDaaS".
  • SCIM is not currently supported, so if you need to sync user deletions or changes, you must perform these operations directly in Verona Cloud Console.

Table of Contents:

TrustLogin Admin Page Settings

Verona Cloud Console Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Login Method

If You Want to Switch the User Logging in to Verona Client

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Verona Client (SAML)".
    verona05.png

  3. Note the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.03.png


[Convert the Certificate Format]
Convert the file extension of the downloaded certificate to ".cer".

Now, switch to configuring the Verona Cloud Console side.
Do not click the "Register" button yet — open Verona Cloud Console in a separate window.

Verona Cloud Console Settings

  1. Log in to Verona Cloud Console and open "Owner > Edit Owner > Single Sign-On". Configure the settings as follows, then click "Update".
    Single Sign-On Enabled
    SAML JIT Provisioning Enabled
    Identifier (Entity ID) Copy and make a note of it
    Response URL Copy and make a note of it
    Login URL The "IdP URL" noted from TrustLogin
    Issuer Identifier The "Issuer/Entity ID" noted from TrustLogin
    Verona Client Login URL

    Copy and make a note of it

    Note: This is the URL entered when logging in to Verona Client.

    Share this URL with Verona Client users.

    This is not the URL to configure on the TrustLogin side.


    verona03.png
  2. Select the TrustLogin certificate from "Choose File" and upload it.
    Note: Upload the certificate with the file extension converted to ".cer".
    verona06.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Identifier (Entity ID)" noted from Verona Cloud Console
    ACS URL to Service The "Response URL" noted from Verona Cloud Console

    verona01.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Verona Client (SAML)", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "Verona Client (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

  1. Launch Verona Client and open "Option Settings".
    verona04.png

  2. Click "Verona Cloud, IDaaS".
    verona.png

  3. Enter the "Verona Client Login URL" you noted from Verona Cloud Console into "Login URL", and
    click "OK".
    verona02.png

  4. You will be redirected to the TrustLogin login screen. Please log in there.

If You Want to Switch the User Logging in to Verona Client

In "Login URL", enter "https://portal.trustlogin.com/users/sign_out", and click "OK" to log out of TrustLogin.

After that, perform the steps in "Login Method > 3." again, and log in with the TrustLogin user information you want to switch to. This will allow you to switch users.
verona07.png