SonicWall Cloud Secure Edge SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in SonicWall Cloud Secure Edge (hereinafter "CSE") is required.

  • For the latest setup instructions, please check the manual provided by CSE.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:

Notes

  • Verification testing of the CSE App has not been performed on the Linux version.

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

CSE Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Verification

Prerequisites

Create a group in TrustLogin that maps to a CSE Role, and assign members to it.
(If you can operate using an existing group, you may use that instead.)

For instructions on how to create a group and assign members, please refer to the following page.
Register a Group

[Example Group Configuration on the TrustLogin Side]

  • Create an "Administrator" group and assign its members to the CSE role "Admin"
  • Create a "General User" group and assign its members to the CSE role "User"

[Example Role Configuration on the CSE Side]
In the CSE Web management console, open "HOME" > "OverView" > "Roles", click "+Add Role", set any name you like for "Role Name" (e.g., "Admin" in this example), and add the group name you configured in TrustLogin (e.g., "Administrator" in this example) under "Role Attributes" using "By Group".
Add a Role configuration in the same way for each group.

00.png

With this configuration, when users belonging to the "Administrator" / "General User" groups log in to CSE via SAML, they will automatically be assigned the "Admin" / "User" role.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the value of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
    03.png

Now, switch to configuring CSE.
Do not click the "Register" button yet — open CSE in a separate window.

CSE Settings

  1. Log in to the CSE Web management console as a user with administrator privileges, and click the edit button (pencil icon) for "Settings" > "Idendity and Access" > "End User".
    04.png

  2. Configure each item under "User Identity Provider" as follows.
    Provider Name Select "Other" and set any name you like (e.g., TrustLogin)
    Provider Protocol Select "SAML"
    Redirect URL Keep the default value and make a note of it
    Entity Issuer Copy and paste the Redirect URL string

    05.png

  3. Configure each item under "IDP Settings" as follows.
    IDP SSO Url

    The "Identity Provider URL" obtained from TrustLogin

    IDP CA Certificate The contents of the "Certificate" obtained from TrustLogin
    Username Username
    Email Email
    Groups Groups

    06.png

  4. Save by clicking the "Save" button.

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Redirect URL" obtained from CSE
    Entity ID The "Redirect URL" obtained from CSE
    Name ID Format Select "persistent"
    ACS URL to Service The "Redirect URL" obtained from CSE

    07.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure it as follows. For the Groups attribute value, select the group name from the dropdown; you can add multiple groups using the "+" icon on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    Username Email Username

    Member

    Member - Email Address

    Email Email Email

    Member

    Member - Email Address

    Groups Unspecified Groups

    Group

    Select the configured group names and add them all using the "+" button


    08.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Verification

  1. Log in to the CSE Web management console as a user with administrator privileges, and open "Settings" > "SonicWall CSE Client" > "Deployment".

  2. Download the CSE Client for your OS.
    Make a note of the "INVITE CODE", as it will be required during installation.
    09.png

  3. Run the downloaded file and follow the steps to start the installation.
    When you enter the "INVITE CODE", the TrustLogin authentication screen will open in your browser — complete the authentication there.

  4. A screen indicating successful authentication will be displayed.
    10.png

  5. After that, register the device, and once complete, you will be able to access securely.


    For details on how to configure the CSE Client, please refer to the CSE help documentation.

SonicWall Cloud Secure Edge SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in SonicWall Cloud Secure Edge (hereinafter "CSE") is required.

  • For the latest setup instructions, please check the manual provided by CSE.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:

Notes

  • Verification testing of the CSE App has not been performed on the Linux version.

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

CSE Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Verification

Prerequisites

Create a group in TrustLogin that maps to a CSE Role, and assign members to it.
(If you can operate using an existing group, you may use that instead.)

For instructions on how to create a group and assign members, please refer to the following page.
Register a Group

[Example Group Configuration on the TrustLogin Side]

  • Create an "Administrator" group and assign its members to the CSE role "Admin"
  • Create a "General User" group and assign its members to the CSE role "User"

[Example Role Configuration on the CSE Side]
In the CSE Web management console, open "HOME" > "OverView" > "Roles", click "+Add Role", set any name you like for "Role Name" (e.g., "Admin" in this example), and add the group name you configured in TrustLogin (e.g., "Administrator" in this example) under "Role Attributes" using "By Group".
Add a Role configuration in the same way for each group.

00.png

With this configuration, when users belonging to the "Administrator" / "General User" groups log in to CSE via SAML, they will automatically be assigned the "Admin" / "User" role.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the value of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
    03.png

Now, switch to configuring CSE.
Do not click the "Register" button yet — open CSE in a separate window.

CSE Settings

  1. Log in to the CSE Web management console as a user with administrator privileges, and click the edit button (pencil icon) for "Settings" > "Idendity and Access" > "End User".
    04.png

  2. Configure each item under "User Identity Provider" as follows.
    Provider Name Select "Other" and set any name you like (e.g., TrustLogin)
    Provider Protocol Select "SAML"
    Redirect URL Keep the default value and make a note of it
    Entity Issuer Copy and paste the Redirect URL string

    05.png

  3. Configure each item under "IDP Settings" as follows.
    IDP SSO Url

    The "Identity Provider URL" obtained from TrustLogin

    IDP CA Certificate The contents of the "Certificate" obtained from TrustLogin
    Username Username
    Email Email
    Groups Groups

    06.png

  4. Save by clicking the "Save" button.

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Redirect URL" obtained from CSE
    Entity ID The "Redirect URL" obtained from CSE
    Name ID Format Select "persistent"
    ACS URL to Service The "Redirect URL" obtained from CSE

    07.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure it as follows. For the Groups attribute value, select the group name from the dropdown; you can add multiple groups using the "+" icon on the right.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    Username Email Username

    Member

    Member - Email Address

    Email Email Email

    Member

    Member - Email Address

    Groups Unspecified Groups

    Group

    Select the configured group names and add them all using the "+" button


    08.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Verification

  1. Log in to the CSE Web management console as a user with administrator privileges, and open "Settings" > "SonicWall CSE Client" > "Deployment".

  2. Download the CSE Client for your OS.
    Make a note of the "INVITE CODE", as it will be required during installation.
    09.png

  3. Run the downloaded file and follow the steps to start the installation.
    When you enter the "INVITE CODE", the TrustLogin authentication screen will open in your browser — complete the authentication there.

  4. A screen indicating successful authentication will be displayed.
    10.png

  5. After that, register the device, and once complete, you will be able to access securely.


    For details on how to configure the CSE Client, please refer to the CSE help documentation.