Note: Advance configuration is required on the Sumo Logic side.
Note: For the latest configuration steps, please refer to the manual provided by Sumo Logic.
Set Up SAML for Single Sign-On
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Corporate App" screen and select "Sumo Logic (SAML)".
- Make a note of the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate from "Get Certificate".
Now let's move on to the configuration on the Sumo Logic side. Please open Sumo Logic in a separate window.
Sumo Logic Configuration
- Log in with an administrator account, open "Administration > Security > SAML", and click "+ Add Configuration".
- Configure the "Add Configuration" page as follows.
Selecting the "Debug Mode" option will display details when a user encounters an authentication error.Configuration Name Any name you like (e.g., "Trust Login" in this example) Issuer The "Issuer/Entity ID" you noted from TrustLogin X.509 Certificate The contents of the certificate you downloaded from TrustLogin Attribute Mapping Use SAML Subject (leave as the default; no change needed)
For more information, please see here.
After the SAML configuration is complete, an SSO login button will appear on the login page (https://your-subdomain.sumologic.com/ui/), and the "Configuration Name" you set here will become the button label.
- Scroll further down to "Optional Settings" and check "SP Initiated Login Configuration". Once the detailed input fields expand, enter the "IdP URL" you noted from TrustLogin into "Authn Request URL".
Click the "Add" button to save the configuration.
- Click the configuration you created from the Configuration List, and the SP information will be displayed on the right. Make a note of the "Assertion Consumer" and "Entity ID" information.
Caution:
Even after turning it ON, we recommend adding administrators and others to "Allow these users to sign in using passwords in addition to SAML" so that they can still log in with an ID/password.
Let's go back to the TrustLogin configuration.
TrustLogin Admin Page Configuration (Continued)
-
Configure each item under "Service Provider Settings" as follows.
Entity ID The "Entity ID" you noted from Sumo Logic ACS URL for the service The "Assertion Consumer" you noted from Sumo Logic
- Click the "Register" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Sumo Logic (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the browser extension and check that login succeeds.
② When an administrator adds a member
- On the "Admin Page > Apps" menu, search for and click the "Sumo Logic (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.