1. SAML Settings
TrustLogin Admin Page Settings
SP (Salesforce) Settings
TrustLogin Admin Page Settings (Continued)
TrustLogin User Settings
Connection Verification
2. Reconfiguring the SAML Settings
Netskope Settings
SP (Salesforce) Settings
TrustLogin Settings
3. Verification
1. SAML Settings
As a prerequisite for the Netskope Reverse Proxy configuration, configure SAML authentication settings for both the IdP (TrustLogin) and the SP. Here, Salesforce is used as an example SP. For SAML authentication configuration for other SPs, please refer to each SP's manual.
For Netskope (Reverse Proxy) SAML settings, the configuration items differ, so instead of using the standard SAML configuration template, configure it using the custom SAML app registration method.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
-
Register an "Application Name" (any name of your choice) and an "Icon" (optional).
Under "Identity Provider Information", download the "Metadata" from "Download Metadata". Also make a note of the "Identity Provider URL", and download the "Certificate".
Now, switch to the SP (Salesforce) side configuration.
Do not click "Register" yet — open the SP (Salesforce) in a separate window.
SP (Salesforce) Settings
- Log in to Salesforce as an administrator, and open "ID > Single Sign-On Settings" from the menu.
-
Click the "Edit" button, then check the "SAML Enabled" checkbox, and click "Save" to save it.
- Click the "New from Metadata File" button, then click "Choose File" and select and upload the metadata you downloaded from TrustLogin.
-
Confirm that the information from the metadata has been reflected, and configure the other items as follows.
Name Any name of your choice (here, used as an example: TrustLogin_Netskope) API Name Any name of your choice (here, used as an example: TrustLogin_Netskope) Issuer Confirm that it has been populated from the metadata Entity ID Confirm that it has been populated from the metadata SP-Initiated Request Binding Select "HTTP POST" Identity Provider Login URL Confirm that it has been populated from the metadata Enable Single Logout Uncheck it
- Confirm that TrustLogin's information is displayed under "Identity Provider Certificate", and make a note of the endpoint information.
-
Open "Company Settings > My Domain" from the menu, and click the "Edit" button under "Authentication Configuration".
- Check the box for the authentication service name you configured in step 4 under "Authentication Service", and click "Save".
Now return to the TrustLogin settings.
TrustLogin Admin Page Settings (Continued)
- Configure each item under "Service Provider Settings" with the information you noted from Salesforce, as follows.
Login URL The "Login URL" you noted from Salesforce Entity ID TrustLogin's "Issuer / Entity ID" Name ID Format Select "unspecified" ACS URL for the Service The "Login URL" you noted from Salesforce
- Click "Register" to save.
TrustLogin User Settings
① When a User Adds the App via My Page
- In "My Page", click the "Add App" button.
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
- Click the app in "My Page" or the browser extension, and check whether login succeeds.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the custom SAML app you created.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Connection Verification
Confirm that SAML authentication works correctly, and that after authenticating with TrustLogin, you are able to SSO into the SP (Salesforce).
2. Reconfiguring the SAML Settings
Reconfigure the SAML authentication settings configured in section 1 so that they work via Netskope.
Netskope Settings
- Log in to Netskope as an administrator, and open "Settings" from the left-hand menu.
- Open "Security Cloud Platform".
- Open "REVERSE PROXY > SAML" and click "ADD ACCOUNT".
-
Configure each item on the New Account settings screen as follows, and click the "SAVE" button to save.
NAME Any name of your choice (here, used as an example: TrustLogin RP Settings) APPLICATION Select "Salesforce" ACS URL The "Login URL" you noted from Salesforce IDP SSO URL The "Identity Provider URL" you noted from TrustLogin IDP CERTIFICATE Paste the contents (text) of the "Certificate" you downloaded from TrustLogin
- Confirm that the message "Successfully saved SAML Proxy configuration" is displayed, then
click "Netskope Settings" for the SAML configuration you created. - Make a note of the Netskope Settings information.
("ORGANIZATION ID", "SAML PROXY IDP URL", "SAML PROXY ACS URL", "SAML PROXY ISSUER CERTIFICATE")
SP (Salesforce) Settings
-
Return to the SP (Salesforce) settings screen, change the "Issuer", "Identity Provider Certificate", and "Identity Provider Login URL" to the information you obtained from Netskope in step 6, and click "Save".
Issuer "ORGANIZATION ID" Identity Provider Certificate Copy the "SAML PROXY ISSUER CERTIFICATE", paste it into Notepad or similar, save it in .cert format, then upload it Identity Provider Login URL "SAML PROXY IDP URL"
- Confirm that the "Issuer", "Identity Provider Login URL", and "Identity Provider Certificate" now reflect the Netskope values.
TrustLogin Settings
- Change the "ACS URL for the Service" under "Service Provider Settings" to the "SAML PROXY ACS URL" you noted from Netskope.
- Click "Register" to save.
3. Verification
- Access the SP.
- You will be redirected to TrustLogin, so log in.
- You will be SSO'd into the SP. You can confirm that "~rproxy.goskope.com~" has been added to the URL, indicating that the connection is going through Netskope.
- Log in to Netskope with an administrator account, open "Skope IT > Application Events", and confirm that you can view the login history for Salesforce in the log.