Initial Setup Steps for Identity Provisioning with Kibela

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Kibela.

Note: For detailed instructions on operating Kibela, please refer to the documentation provided by Kibela.

Item Details
Pre-check
  • Kibela administrator privileges are required.
Setup Flow / Manual

Note: After connecting TrustLogin and Kibela using the steps on this page,
 please proceed to configuring user synchronization.

Provisioning Target Supports user provisioning
Supports group provisioning
SAML Authentication Setup Manual

SAML JIT Setup Method for Kibela

  • The Identity Provisioning configuration created in this procedure can be linked to an existing SAML app.
    For details on the SAML app configuration, please see above.
  • To prevent conflicts in user attribute updates caused by using Identity Provisioning together with SAML JIT,
    we recommend not configuring "SAML Attribute Settings" for any duplicate user attributes when creating a SAML app.
    Note: Behavior depends on the service specifications, so please check the details with each SP.
Notes
  • None in particular

Setup Steps

Kibela Settings

  1. Log in to Kibela with administrator privileges, click the icon in the upper right of the screen, then click "Member Management".
  2. Scroll down the screen and click "Provisioning" under the "Team Settings" section.

  3. Click "Create New Token".
  4. On the confirmation screen, click "Create".

  5. Copy the displayed token and save it.
    Note: You will not be able to view the token again after saving. Please make sure you have copied it without omission.

  6. Copy and save the "{customer environment's kibela subdomain}.kibe.la/" (FQDN) portion of the Admin Page URL.


    This completes the preparation on the Kibela side. Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png

  2. Click "Add Service".
    IDProvServiceCommon02.png
  3. On the Add Service screen, search for and select "Kibela", then click the "Add" button.
    IDProvServiceCommon03.png
  4. You will be redirected to the "Identity Provisioning > Kibela" page.
    Click the "Edit" button.
    IDProvServiceCommon04.png
  5. Open "Access Settings", enter the following values for the settings items, and click "Save".

    Connection URL Kibela Settings The "{customer environment's kibela subdomain}.kibe.la/" portion you copied in step 6
    Access Token Kibela Settings The value of the token you copied in step 5

    zen_IDProv_02.png

  6. Click the "Connect" button in the upper right of the screen.
    zen_IDProv_03.png

  7. Once the button status updates to "Connected", the initial setup is complete.
    Connected_IDProv.png

Next step: The manual for configuring user synchronization is available here

Values You Can Configure in Attribute Mapping

You can map any attribute on the TrustLogin side to any attribute on the Kibela side.
For configuration instructions, see here

Available Default Functions

Value Description
Generates a Kibela username
from the user's email address
Extracts the portion of the email address before the "@",
replaces any disallowed characters (any character other than uppercase letters, lowercase letters, numbers, periods ".", hyphens "-", and underscores "_")
with an underscore, and limits the result to a maximum of 30 characters.

Initial Setup Steps for Identity Provisioning with Kibela

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Kibela.

Note: For detailed instructions on operating Kibela, please refer to the documentation provided by Kibela.

Item Details
Pre-check
  • Kibela administrator privileges are required.
Setup Flow / Manual

Note: After connecting TrustLogin and Kibela using the steps on this page,
 please proceed to configuring user synchronization.

Provisioning Target Supports user provisioning
Supports group provisioning
SAML Authentication Setup Manual

SAML JIT Setup Method for Kibela

  • The Identity Provisioning configuration created in this procedure can be linked to an existing SAML app.
    For details on the SAML app configuration, please see above.
  • To prevent conflicts in user attribute updates caused by using Identity Provisioning together with SAML JIT,
    we recommend not configuring "SAML Attribute Settings" for any duplicate user attributes when creating a SAML app.
    Note: Behavior depends on the service specifications, so please check the details with each SP.
Notes
  • None in particular

Setup Steps

Kibela Settings

  1. Log in to Kibela with administrator privileges, click the icon in the upper right of the screen, then click "Member Management".
  2. Scroll down the screen and click "Provisioning" under the "Team Settings" section.

  3. Click "Create New Token".
  4. On the confirmation screen, click "Create".

  5. Copy the displayed token and save it.
    Note: You will not be able to view the token again after saving. Please make sure you have copied it without omission.

  6. Copy and save the "{customer environment's kibela subdomain}.kibe.la/" (FQDN) portion of the Admin Page URL.


    This completes the preparation on the Kibela side. Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png

  2. Click "Add Service".
    IDProvServiceCommon02.png
  3. On the Add Service screen, search for and select "Kibela", then click the "Add" button.
    IDProvServiceCommon03.png
  4. You will be redirected to the "Identity Provisioning > Kibela" page.
    Click the "Edit" button.
    IDProvServiceCommon04.png
  5. Open "Access Settings", enter the following values for the settings items, and click "Save".

    Connection URL Kibela Settings The "{customer environment's kibela subdomain}.kibe.la/" portion you copied in step 6
    Access Token Kibela Settings The value of the token you copied in step 5

    zen_IDProv_02.png

  6. Click the "Connect" button in the upper right of the screen.
    zen_IDProv_03.png

  7. Once the button status updates to "Connected", the initial setup is complete.
    Connected_IDProv.png

Next step: The manual for configuring user synchronization is available here

Values You Can Configure in Attribute Mapping

You can map any attribute on the TrustLogin side to any attribute on the Kibela side.
For configuration instructions, see here

Available Default Functions

Value Description
Generates a Kibela username
from the user's email address
Extracts the portion of the email address before the "@",
replaces any disallowed characters (any character other than uppercase letters, lowercase letters, numbers, periods ".", hyphens "-", and underscores "_")
with an underscore, and limits the result to a maximum of 30 characters.