Note: You must create an account in AWS using the same email address as your TrustLogin (formerly SKUID) account.
Note: Depending on the AWS service, unique SAML authentication specifications may be required. For details, please refer to the manual for each AWS service.
Note: For the latest configuration steps, please refer to the manual provided by AWS.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "AWS IAM (SAML)."
- Download the metadata from "Download Metadata" under "Identity Provider Information."
Now, let's move on to the settings on the AWS side.
Without clicking the "Register" button, open the AWS Management Console in a separate window.
AWS Settings
- Search for "IAM" in the service search bar to open the IAM management screen.
-
[Create an Identity Provider]
Reference: Creating an IAM SAML identity provider
Open "Identity providers" in the left menu and click "Add provider."
- Select "SAML" from the "Select provider type" dropdown and proceed with "Next Step" in the lower right.
- Enter a "Provider Name" and upload the metadata downloaded from TrustLogin to "Metadata Document."
(The "Provider Name" can be anything you like. Here, we use TrustLogin as an example.)
Proceed with "Next Step" in the lower right.
- Click "Create" in the lower right.
- Select the provider you created to open it.
- Make a note of the "Provider ARN."
-
[Create a Role]
Reference: Creating a role for SAML 2.0 federation (console)
Open "Roles" in the left menu and click "Create role."
- Select "SAML 2.0 federation" and configure each of the fields displayed below as follows.
SAML provider
Select the provider you created earlier. Attribute SAML:aud
Value https://signin.aws.amazon.com/saml
Proceed with "Next: Permissions."
- Select a policy according to the service you plan to use, and proceed with "Next: Tags."
- Proceed with "Next: Review" as is.
- Enter a "Role name" (any name you like) and click "Create role."
- Select the role you created to open it.
- Make a note of the "Role ARN."
Return to the TrustLogin settings page again.
TrustLogin Admin Page Settings (Continued)
- In the "SAML Attribute Settings" section of "Service Provider Settings," enter the "Role ARN" and "Provider ARN" you noted down from AWS in the field outlined in red below, separated by a comma, in the format "Role ARN,Provider ARN."
You can leave the "Redirect URL After Successful SP Authentication" field blank.
- Click the "Register" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "AWS IAM (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds a member
- Search for the "AWS IAM (SAML)" app in the "Admin Page > Apps" menu and click it.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.