Overview
Onelogin is one of the Identity Providers that your organization can configure for SSO and use to log in to your Zilla Security tenant.
Scope: Admins
This article covers the following topics:
Prerequisites
Admin account with Zilla Security
SSO has not been configured or SSO configuration has been deleted in admin settings
You must be logged in as a Onelogin Super User or have the Manage Applications privilege
Onelogin App Connector Creation
In your Onelogin admin console, click the
Applications
tab, then clickAdd App
.Search for and select the
SAML Custom Connector (Advanced)
.Rename the application as desired. Add the Zilla icon from our Image Assets.
Onelogin Custom Parameter Setup
In your Onelogin Connector, navigate to
Parameters
.Zilla expects the exact values listed below in a SAML assertion. Add 3 custom parameters to the connector for:
email
firstName
lastName
When creating these values, map them to their appropriate Onelogin field and be sure to select the
Include in SAML Assertion
check box.
Zilla SAML Provider Setup
Log in as a Zilla admin and click on the
Settings
tab on the left side of the page. On theDiscovery & Configuration
tab, expand theSingle Sign-On Provider
dropdown and clickConfigure
.
Select
SAML
and then clickConfigure
.
A Configure SAML window will appear.
Copy the
Zilla ACS URL
andZilla Entity ID
to your clipboard.In Onelogin, click the
Configuration
tab of your new connector and paste these values into the appropriate spaces.
For the
ACS URL Validator
field, use the following value:^https:\/\/app\.zillasecurity\.com\/$
and clickSave
.
For security reasons, please ensure you use the exact value above. Using .*
as an ACS Validator is not suited for production use in any application.
In Onelogin, proceed to the
SSO
section.
13. Copy the SAML 2.0 Endpoint
and the Issuer URL
values, and paste them into the Zilla IDP SSO URL
and IDP Entity ID
, respectively.
In Onelogin, click
View Details
of your X.509 Certificate. Copy this value to your clipboard and paste it into theZilla IDP X.509 Certificate
field.
Important: When pasting this certificate into the Zilla IDP X.509 Certificate field, you will need to remove -----BEGIN CERTIFICATE-----
and -----END CERTIFICATE-----
from the pasted value.
Click
Validate
in the Zilla SSO Configuration window. The test should be successful if the admin testing the configuration has been assigned to the Zilla connector in Onelogin correctly.
Any reviewers, technical owners, or app owners can now log in to Zilla to see the apps and reviews they have been assigned using Onelogin SSO.
When you have completed the steps above, review the information that was synced in Zilla. If you encounter any issues, please refer to our troubleshooting articles or visit support.zillasecurity.com and submit a ticket. Our support team will assist you in resolving the problem as quickly as possible.