Item |
Details |
|
|---|---|---|
Pre-check |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For how to configure custom attributes, seehere | ||
| SP Configuration | 〇 | Configured by the Administrator |
| Request SP to configure | ||
| Provisioning | 〇 | API-based Provisioning supported (Account management available in TrustLogin) |
| SAML JITProvisioning supported (Account management available in TrustLogin; user deletion not available) | ||
| None (accounts created in each system) | ||
| Access Method | 〇 | SP-Initiated SSO |
| 〇 | IdP-Initiated SSO | |
| Device Compatibility | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Default Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| ー | iOS - Native App | |
| 〇 | Android - Default Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| ー | Android - Native App | |
| SAML Authentication Scope | ー | Enabled for all users (SAML authentication only) |
| 〇 | Users (SAML authentication only); Administrators (password authentication only) | |
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Settings GitHub Enterprise Managed Users Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Company App" screen, search and select "GitHub Enterprise Managed Users (SAML)".
- Under "Identity Provider Information", note down the values of "Identity Provider URL" and "Issuer / Entity ID", and download the certificate using the "Get Certificate" button.
- In "Service Provider Settings", enter your GitHub "Enterprise Name" into the blank fields for "Entity ID" and "Service ACS URL".
- Save by clicking the "Save" button.
- Add the user who is currently performing the SAML configuration to the "GitHub Enterprise Managed Users (SAML)" app. Please add the user using "Add Member".
Next, switch to configuring the GitHub Enterprise Managed Users side.
GitHub Enterprise Managed Users Settings
-
From "Overview", click "Enable single sign-on".
-
Click "Add SAML configuration".
-
Configure "SAML single sign-on" as follows. After configuring, click "Test SAML configuration" to run a connection test.
Sign on URL The "Identity Provider URL" noted down from TrustLogin Issuer The "Issuer / Entity ID" noted down from TrustLogin Public certificate Paste the contents of the "Certificate" noted down from TrustLogin -
If "Passed: Successfully authenticated your SAML SSO identity." is displayed, the connection test was successful.
Save the configuration by clicking "Save SAML settings". -
Note down the recovery codes under "Single sign-on recovery codes", then click "Enable SAML authentication" to activate SSO.
GitHub Enterprise Managed Users Provisioning Settings
- Please configure provisioning by following "Initial Setup Procedure for GitHub ID Provisioning".
TrustLogin User Settings
① When a User Adds the App from My Page
Note: The SAML app must be configured by the Administrator in advance.
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "GitHub Enterprise Managed Users (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for and click the "GitHub Enterprise Managed Users (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
SP-Initiated Login Method
- If you want to log in via SP-initiated login, access "https://github.com/enterprises/{Enterprise Name}/sso".
-
Clicking "Continue" starts the SSO login.