OneLogin integrations

Prev Next

Available in Classic and VPC

This section describes how to integrate OneLogin, a user authentication and access permissions management solution, with a NAVER Cloud Platform account. Users within the organization can log into the NAVER Cloud Platform console with the OneLogin account being used and utilize the services within the granted permissions.

The sequence of integrating NAVER Cloud Platform accounts and OneLogin accounts is as follows:

1. Download metadata from OneLogin.
2. Register external IdP information from NAVER Cloud Platform.
3. Configure OneLogin authentication.
4. Configure NAVER Cloud Platform authentication.
5. Verify integrations.

1. Download metadata from OneLogin

When registering external IdP information in the Ncloud Single Sign-On service, OneLogin metadata is required. This section describes how to download OneLogin metadata.

To download metadata from OneLogin:

  1. Access OneLogin and click Applications > Applications at the top of the interface.
  2. Click the [Add App].
  3. Enter "SAML Custom Connector (Advanced)" in the search component and click the search result.
  4. Enter a name in Display Name and click the [Save].
  5. Click the Configuration menu on the left side of the interface.
  6. On the top right of the interface, click More Actions > SAML Metadata.
  7. Confirm the file downloaded to the user's PC.

2. Register external IdP information from NAVER Cloud Platform

To register OneLogin metadata in the Ncloud Single Sign-On service:

  1. From the NAVER Cloud Platform console, navigate to i_menu > Services > Management & Governance > Ncloud Single Sign-On.
  2. In the Tenant menu, click [Register external IdP].
  3. In the Metadata item, paste the metadata information downloaded from 1. Download metadata from OneLogin, then click the [Save].
    • The sub-information will be entered automatically.
  4. Click the [Register].

3. Configure OneLogin authentication

This section describes how to enter external IdP metadata information and user profiles obtained from the NAVER Cloud Platform console into OneLogin.

Note

When mapping user profiles, there are methods to manually enter the profile and to set it to receive information from IdP during login. This guide is based on how to receive information from IdP during login.

Enter SAML information

To enter SAML information in OneLogin:

  1. After accessing OneLogin, click Applications > SAML Custom Connector (Advanced).
  2. Click the Configuration menu on the left side of the interface.
  3. Enter as follows:
  4. Once you enter the mandatory information, click the [Save] located at the top right of the interface.

Copy SAML integration information

To integrate Ncloud Single Sign-On and IdP, you need the Assertion Consumer Service (ACS) URL information, which is the endpoint to receive the SAML response from IdP, and the Issuer URL information to identify the IdP.
To confirm the ACS URL and Issuer URL of NAVER Cloud Platform:

  1. From the NAVER Cloud Platform console, navigate to i_menu > Services > Management & Governance > Ncloud Single Sign-On.
  2. Copy the following information from the External IdP Metadata component in the Tenant menu:
    • Assertion Consumer Service (ACS) URL
    • Issuer URL
    • Login URL

Configure attribute mapping

To map user profiles of OneLogin with the Ncloud Single Sign-On service, this defines the user property information to be forwarded from OneLogin to NAVER Cloud Platform.

Note

This guide describes the user property information primarily used in authentication, which are FirstName, LastName, and Email.

To define user property information in OneLogin:

  1. Click the Parameters menu on the right side of the interface in OneLogin.
  2. Click the [+] button in the SAML Custom Connector (Advanced) field component.
  3. Enter "FirstName" in Field Name, then click the [Save].
    • The entered field name will be used during user profile mapping in the Ncloud Single Sign-On service.
  4. Click the Value dropdown button and select the value to map to FirstName, then click the [Save].
  5. Register LastName in the same manner.

Add OneLogin user

To add a user in OneLogin:

  1. Click the Users > Users menu at the top of the interface.
  2. Click the New User at the upper right of the interface.
  3. Enter the First name, Last name, Email, and Username information of the user to be added, then click the [Save User].
  4. To set the password for the created user, click More Actions > Change Password.

Assign application to user

To assign an application to OneLogin users:

  1. Click the Users > Users menu at the top of the interface.
  2. Click the user to whom the application will be assigned.
  3. Click the Applications menu on the left side of the interface.
  4. Click the [+] button in the Applications component.
  5. Select the application to connect to, and then click the [Continue].
  6. Check the information, and then click the [Save].

4. Configure NAVER Cloud Platform authentication

This section describes how to register the OneLogin account to be integrated with NAVER Cloud Platform console and then map user profiles.

Add SSO user

You need to create an SSO user in the Ncloud Single Sign-On service using the email information of the user created in the Add OneLogin user step.
To add an SSO user in the Ncloud Single Sign-On service:

  1. From the NAVER Cloud Platform console, navigate to i_menu > Services > Management & Governance > Ncloud Single Sign-On.
  2. Click External IdP login > Users > [Create user].
  3. Enter the email address of the user created in Add OneLogin users, then click the [Create]
Note

For more information about how to create an SSO user in Ncloud Single Sign-On, see Users.

Configure attribute mapper in NAVER Cloud Platform

To link the user property information set in OneLogin to the user property information of Ncloud Single Sign-On service:

  1. From the NAVER Cloud Platform console, navigate to i_menu > Services > Management & Governance > Ncloud Single Sign-On.
  2. Click the Tenant menu.
  3. Click the [Attribute mapper].
  4. When the attribute mapper interface appears, enter the registered content in Configure attribute mapping in External IdP parameter.
  5. In sync mode, set the user profile update method.
    • None: Do not update user profile.
    • Import: Update user profiles only at first login.
    • Force: Update the user profile at every login.
  6. Click the [Save].

5. Verify integrations

To verify if the OneLogin account and the NAVER Cloud Platform account are integrated:

  1. From the NAVER Cloud Platform console, navigate to i_menu > Services > Management & Governance > Ncloud Single Sign-On.
  2. Copy the Login URL from the Tenant menu, then access the URL.
    • The SSO role switch interface appears.
  3. Click the [Console access] or [API access] on the SSO role switch interface.
    • Depending on the access type set for the logged-in SSO user, the [Console access] or [API Gateway access] button appears.
  4. Click Services > Management & Governance > Ncloud Single Sign-On > External IdP login > User.
  5. Click the [Profile] tab in the details of the logged-in SSO user, then check if the user profile has been updated.