|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for users in the domain covered by SSO (SAML authentication only) |
|
|
Notes |
If SSO configuration fails or SSO is not functioning, you can access the workspace using the recovery account's username and password. | |
|
Table of Contents: |
Prerequisites
To access HPE GreenLake workspaces via SAML SSO, you need to add the required SAML attributes to the custom attributes in TrustLogin member information in advance. Specify the workspaces the user can access and the role to be assigned.
[TrustLogin Custom Attribute Configuration Example]
Please refer to the HPE GreenLake manual for how to construct the value to set for the attribute value.
・HPE GreenLake Platform SAML Attributes
・hpe_ccs_attribute Configuration Example
Please refer to the following pages for instructions on how to configure custom attributes. The attribute name for the custom attribute can be anything you choose.
Custom Attribute Setup (Individual Registration)
Custom Attribute Setup (Bulk Registration)
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Configure the "Application Name" and "Icon" (optional).
- Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
-
Configure "Service Provider Settings" as follows.
Redirect URL after successful SP authentication https://common.cloud.hpe.com Entity ID https://sso.common.cloud.hpe.com ACS URL to Service
https://sso.common.cloud.hpe.com/sp/ACS.saml2
-
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value NameId Unspecified NameId Member
Member - Email Address
FirstName Unspecified FirstName Member
Member - First Name
LastName Unspecified LastName Member
Member - Last Name
hpe_ccs_attribute Unspecified hpe_ccs_attribute Custom Attribute
Select the configured attribute name
- Save by clicking the "Register" button.
HPE GreenLake Configuration
- Log in to HPE GreenLake and open "Manage Workspaces".
-
[Domain Verification]
Verify the domain to which you want to apply SAML SSO. If the domain has already been verified, proceed to step 7.
Open "Organization Governance" > "Domain".
- Click "Add Domain".
- Enter the target domain name and click "Claim Domain".
- Copy the "Domain Verification TXT Record" that is displayed, and click "Close".
Add the copied TXT record to the domain's DNS records.
For instructions on configuring DNS records for your domain, please refer to your domain registrar's help documentation.
- After some time has passed (DNS record updates may take up to approximately 72 hours), click "Verify Domain Now" for the target domain. Domain verification is complete once the "Claim" status changes to "Verified".
-
[SSO Profile Configuration]
Open "Organization Governance" > "SSO Profile".
- Click "Create SSO Profile".
- Configure each item as follows and click the "Next" button.
SSO Profile Name Any name of your choice Domain Select the target domain Authentication Method Select "Use SSO SAML Response for session-based authentication"
- Click "Next" without changing anything.
- Click "Next" without changing anything.
Note: As a precaution, please confirm that there are no discrepancies with the values you configured in step 4 of "TrustLogin Admin Page Configuration".
- Select "Upload Metadata XML File", and upload the "metadata" you obtained from TrustLogin by dragging and dropping it or using "Choose File".
Confirm that the metadata has been loaded successfully, and click "Next".
- You can create a recovery account that allows you to access the workspace with a username and password if SSO configuration fails or SSO is not functioning.
Make a note of the displayed username, and register the "Recovery Account Contact Email Address" and "Password".
Click the "Next" button.
- Specify the session timeout and click the "Next" button.
- Review the configuration and click the "Create" button.
TrustLogin User Configuration
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.