|
Item |
Details |
|
|---|---|---|
|
Pre-Check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Provisioning via API supported (account management possible in TrustLogin) |
|
| 〇 |
SAML JIT provisioning supported(account management possible in TrustLogin; user deletion not supported) |
|
|
|
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled for all users (SAML authentication and password authentication can be used together) |
|
|
Notes |
None |
|
The setup method differs depending on whether you manage the user's Mackerel-side permissions in TrustLogin. If you do not manage Mackerel-side permissions in TrustLogin, refer to "① When Adding Users via SAML JIT with the 'Viewer' Role."
If you do manage Mackerel-side permissions in TrustLogin, refer to "② When Mapping User Permissions to TrustLogin Attributes."
Please configure your setup according to the section that applies to you.
① When Adding Users via SAML JIT with the "Viewer" Role
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Mackerel (SAML)".
-
Download the metadata from the "Download Metadata" button under "Identity Provider Information".
- Save by clicking the "Register" button.
Mackerel Settings
- Log in with an administrator account, click the account display in the upper right, and open "Organization Group Settings".
- Click the target organization group.
- Configure each item as follows, and finally save by clicking the "Update" button.
IdP Metadata XML Upload the metadata obtained from TrustLogin.
Once successfully loaded, the values for "IdP Entity ID", "Single Sign On URL", and "IdP X509 Certificate" will be automatically filled in.Force SAML Authentication You can restrict the login method to SAML authentication only.
We recommend keeping this OFF during the initial SAML setup, and turning it ON only after you have verified that SAML SSO works correctly and notified your users.Add Users as Viewers by Default ON
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Mackerel (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds Members
- Search for and click the "Mackerel (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
② When Mapping User Permissions to TrustLogin Attributes
Prerequisites (Configuring Custom Attributes)
Add the permission you want to map in Mackerel as a custom attribute in TrustLogin member information. Set the custom attribute name to "MackerelRole" and set the attribute value to any name you choose.
You will configure the attribute mapping rules on the Mackerel side later.
As an example, this manual walks through the following configuration example.
・Assign the "General User" role to users whose custom attribute MackerelRole is "User"
・Assign the "Administrator" role to users whose custom attribute MackerelRole is "Admin"
・Assign the "Viewer" role to users whose custom attribute MackerelRole is "Viewer"
[TrustLogin Custom Attribute Configuration Example]
This is a configuration example for assigning the "Viewer" role to a Mackerel user. Set the attribute value to "Viewer".
Please refer to the following pages for instructions on how to configure custom attributes.
Custom Attribute Setup (Individual Registration)
Custom Attribute Setup (Bulk Registration)
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Configure the "Application Name" and "Icon" (optional).
-
Download the metadata from the "Download Metadata" button under "Identity Provider Information".
-
Configure each item under "Service Provider Settings" as follows.
Entity ID https://mackerel.io/saml/metadata.xml Name ID Format emailAddress ACS URL to Service https://mackerel.io/saml/acs
-
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value MackerelRole Unspecified MackerelRole Custom Attribute
Select "MackerelRole"
- Save by clicking the "Register" button.
Mackerel Settings
- Log in with an administrator account, click the account display in the upper right, and open "Organization Group Settings".
- Click the target organization group.
- Open "Attribute Mapping" and click "Add New".
- Configure each item as follows, and add it by clicking the "Add" button.
Mapping Name Enter a management name (optional) for the attribute mapping configuration. Attribute Name Enter "MackerelRole" Value Enter the corresponding TrustLogin custom attribute value. Memo You can freely enter a description of the attribute mapping. Role Select the corresponding role.
- Repeat steps 3–4 for each mapping you want to configure.
- Return to "Basic Settings" under "Organization Group Settings", configure each item as follows, and finally save by clicking the "Update" button.
IdP Metadata XML Upload the metadata obtained from TrustLogin.
Once successfully loaded, the values for "IdP Entity ID", "Single Sign On URL", and "IdP X509 Certificate" will be automatically filled in.Force SAML Authentication ON Enable Attribute Mapping ON
[Caution]
- Permissions assigned via attribute mapping cannot be changed on the organization's member list screen.
- The organization owner is not affected by attribute mapping.
- If you turn ON "Enable Attribute Mapping" without fully creating the attribute mapping configuration in Mackerel and the custom attribute configuration in TrustLogin, members of the organization may be treated as having no assigned permissions, which could prevent members other than the organization owner from accessing the organization.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds Members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.