HPE GreenLake SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in HPE GreenLake is required.

  • Domain ownership and verification are required to apply SAML SSO.

  • Please refer to the manual provided by HPE GreenLake for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users in the domain covered by SSO (SAML authentication only)
Note: If a user in the domain covered by SSO logs in with an ID and password, they will not be able to access the SSO-enabled workspace.

Notes

If SSO configuration fails or SSO is not functioning, you can access the workspace using the recovery account's username and password.

Table of Contents:

Prerequisites

TrustLogin Admin Page Configuration

HPE GreenLake Configuration

TrustLogin User Configuration

Prerequisites

To access HPE GreenLake workspaces via SAML SSO, you need to add the required SAML attributes to the custom attributes in TrustLogin member information in advance. Specify the workspaces the user can access and the role to be assigned.


[TrustLogin Custom Attribute Configuration Example]
21.png

Please refer to the HPE GreenLake manual for how to construct the value to set for the attribute value.
HPE GreenLake Platform SAML Attributes
hpe_ccs_attribute Configuration Example


Please refer to the following pages for instructions on how to configure custom attributes. The attribute name for the custom attribute can be anything you choose.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

  4. Configure "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication https://common.cloud.hpe.com
    Entity ID https://sso.common.cloud.hpe.com

    ACS URL to Service

    https://sso.common.cloud.hpe.com/sp/ACS.saml2

    22.png

  5. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    NameId Unspecified NameId

    Member

    Member - Email Address

    FirstName Unspecified FirstName

    Member

    Member - First Name

    LastName Unspecified LastName

    Member

    Member - Last Name

    hpe_ccs_attribute Unspecified hpe_ccs_attribute

    Custom Attribute

    Select the configured attribute name


    23.png

  6. Save by clicking the "Register" button.

HPE GreenLake Configuration

  1. Log in to HPE GreenLake and open "Manage Workspaces".
    04.png

  2. [Domain Verification]
    Verify the domain to which you want to apply SAML SSO. If the domain has already been verified, proceed to step 7.

    Open "Organization Governance" > "Domain".
    05.png

    06.png

  3. Click "Add Domain".
    07.png

  4. Enter the target domain name and click "Claim Domain".08.png

  5. Copy the "Domain Verification TXT Record" that is displayed, and click "Close".
    Add the copied TXT record to the domain's DNS records.
    For instructions on configuring DNS records for your domain, please refer to your domain registrar's help documentation.
    09.png

  6. After some time has passed (DNS record updates may take up to approximately 72 hours), click "Verify Domain Now" for the target domain. Domain verification is complete once the "Claim" status changes to "Verified".
    10.png

    11.png

  7. [SSO Profile Configuration]
    Open "Organization Governance" > "SSO Profile".
    12.png

  8. Click "Create SSO Profile".
    13.png

  9. Configure each item as follows and click the "Next" button.
    SSO Profile Name Any name of your choice
    Domain Select the target domain
    Authentication Method Select "Use SSO SAML Response for session-based authentication"

    14.png

  10. Click "Next" without changing anything.
    15.png

  11. Click "Next" without changing anything.
    Note: As a precaution, please confirm that there are no discrepancies with the values you configured in step 4 of "TrustLogin Admin Page Configuration".
    16.png

  12. Select "Upload Metadata XML File", and upload the "metadata" you obtained from TrustLogin by dragging and dropping it or using "Choose File".
    Confirm that the metadata has been loaded successfully, and click "Next".
    17.png

  13. You can create a recovery account that allows you to access the workspace with a username and password if SSO configuration fails or SSO is not functioning.
    Make a note of the displayed username, and register the "Recovery Account Contact Email Address" and "Password".
    Click the "Next" button.
    18.png

  14. Specify the session timeout and click the "Next" button.
    19.png

  15. Review the configuration and click the "Create" button.
    20.png

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.



HPE GreenLake SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in HPE GreenLake is required.

  • Domain ownership and verification are required to apply SAML SSO.

  • Please refer to the manual provided by HPE GreenLake for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users in the domain covered by SSO (SAML authentication only)
Note: If a user in the domain covered by SSO logs in with an ID and password, they will not be able to access the SSO-enabled workspace.

Notes

If SSO configuration fails or SSO is not functioning, you can access the workspace using the recovery account's username and password.

Table of Contents:

Prerequisites

TrustLogin Admin Page Configuration

HPE GreenLake Configuration

TrustLogin User Configuration

Prerequisites

To access HPE GreenLake workspaces via SAML SSO, you need to add the required SAML attributes to the custom attributes in TrustLogin member information in advance. Specify the workspaces the user can access and the role to be assigned.


[TrustLogin Custom Attribute Configuration Example]
21.png

Please refer to the HPE GreenLake manual for how to construct the value to set for the attribute value.
HPE GreenLake Platform SAML Attributes
hpe_ccs_attribute Configuration Example


Please refer to the following pages for instructions on how to configure custom attributes. The attribute name for the custom attribute can be anything you choose.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

  4. Configure "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication https://common.cloud.hpe.com
    Entity ID https://sso.common.cloud.hpe.com

    ACS URL to Service

    https://sso.common.cloud.hpe.com/sp/ACS.saml2

    22.png

  5. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    NameId Unspecified NameId

    Member

    Member - Email Address

    FirstName Unspecified FirstName

    Member

    Member - First Name

    LastName Unspecified LastName

    Member

    Member - Last Name

    hpe_ccs_attribute Unspecified hpe_ccs_attribute

    Custom Attribute

    Select the configured attribute name


    23.png

  6. Save by clicking the "Register" button.

HPE GreenLake Configuration

  1. Log in to HPE GreenLake and open "Manage Workspaces".
    04.png

  2. [Domain Verification]
    Verify the domain to which you want to apply SAML SSO. If the domain has already been verified, proceed to step 7.

    Open "Organization Governance" > "Domain".
    05.png

    06.png

  3. Click "Add Domain".
    07.png

  4. Enter the target domain name and click "Claim Domain".08.png

  5. Copy the "Domain Verification TXT Record" that is displayed, and click "Close".
    Add the copied TXT record to the domain's DNS records.
    For instructions on configuring DNS records for your domain, please refer to your domain registrar's help documentation.
    09.png

  6. After some time has passed (DNS record updates may take up to approximately 72 hours), click "Verify Domain Now" for the target domain. Domain verification is complete once the "Claim" status changes to "Verified".
    10.png

    11.png

  7. [SSO Profile Configuration]
    Open "Organization Governance" > "SSO Profile".
    12.png

  8. Click "Create SSO Profile".
    13.png

  9. Configure each item as follows and click the "Next" button.
    SSO Profile Name Any name of your choice
    Domain Select the target domain
    Authentication Method Select "Use SSO SAML Response for session-based authentication"

    14.png

  10. Click "Next" without changing anything.
    15.png

  11. Click "Next" without changing anything.
    Note: As a precaution, please confirm that there are no discrepancies with the values you configured in step 4 of "TrustLogin Admin Page Configuration".
    16.png

  12. Select "Upload Metadata XML File", and upload the "metadata" you obtained from TrustLogin by dragging and dropping it or using "Choose File".
    Confirm that the metadata has been loaded successfully, and click "Next".
    17.png

  13. You can create a recovery account that allows you to access the workspace with a username and password if SSO configuration fails or SSO is not functioning.
    Make a note of the displayed username, and register the "Recovery Account Contact Email Address" and "Password".
    Click the "Next" button.
    18.png

  14. Specify the session timeout and click the "Next" button.
    19.png

  15. Review the configuration and click the "Create" button.
    20.png

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.