About this page
This page explains how to use SeciossLink as an IdP and set up SAML integration with ZUNDA ID. Once you complete this setup, users signed in to SeciossLink can use those credentials to log in to ZUNDA ID via single sign-on.
What you'll need
Make sure you have the following ready in advance.
-
A SeciossLink administrator account
You need an account with permission to create and edit single sign-on settings.
-
A ZUNDA ID user with authentication method admin permissions
You need a user with ZUNDA ID admin permissions to create and configure the SAML provider.
-
A recovery key issued and stored in advance
To prevent a lockout caused by a misconfiguration or an IdP outage, see How to Configure Recovery Settings for Login Methods and issue a recovery key in advance.
-
SeciossLink-side configuration (service provider registration, assignment to users)
You need to register ZUNDA ID as a service provider in SeciossLink and assign the service to the target users (or groups, organization, etc.). See the SeciossLink manual for details.
Setup steps
You'll switch back and forth between the ZUNDA ID and SeciossLink admin screens. It's easiest to keep both open at the same time.
Open the Login Method Settings screen in ZUNDA ID, and click Add SAML Provider
In the dialog that appears, enter a display name of your choice to identify this provider (for example, SeciossLink), then click Create to go to the provider details screen. The name you enter here is shown on the login screen and in settings screens.
Log in to the SeciossLink admin console, open Single Sign-On → SAML from the left sidebar menu, and click Register in the top-right corner
Return to the provider details screen in ZUNDA ID, and click Download next to Metadata URL (SP) to save the SP metadata XML
The SP metadata contains the ZUNDA ID (SP) information SeciossLink needs, such as the ACS URL and entity ID. Uploading this file to SeciossLink lets you populate most of the required settings in one step.
Scroll down the SeciossLink SAML service provider registration screen, choose the SP metadata XML file you just downloaded from Choose File in the Metadata section, and click Load
If the load succeeds, values such as the entity ID and Assertion Consumer Service are filled in automatically.
Scroll back up and enter the Service ID and Service Name
- Service ID
zunda-id(any unique identifier you choose) - Service Name
ZUNDA ID
Confirm that the entity ID and Assertion Consumer Service were already filled in automatically from the metadata in the previous step.
Change Attribute of ID to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress, and User ID Attribute to Email Address
This setting is required because ZUNDA ID expects emailAddress as the NameID format and uses the email address to link the user.
In the Attributes to Send section, check Last Name, First Name, and Alias (Display Name), and enter the schema URI ZUNDA ID expects for each Attribute Name
- Last name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- First name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- Display name (alias): http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
With this attribute mapping, SeciossLink sends the user's last name, first name, and display name to ZUNDA ID during SAML login, so ZUNDA ID can correctly import the user's name during JIT sign-up.
Registering the SP certificate and enabling signature verification (optional)
This step isn't required, but registering the ZUNDA ID SP certificate with SeciossLink and enabling AuthnRequest signature verification lets SeciossLink cryptographically verify that a request genuinely came from the SP (ZUNDA ID), strengthening protection against impersonation and request tampering.
Scroll further down the SeciossLink registration screen, check Enabled under Request Signature Verification, and select Apply to Both Assertion and Response under Signature Scope
From the provider details screen in ZUNDA ID, click Download in the SP Certificates section to download the primary SP certificate file
Return to the SeciossLink registration screen, click Choose File in the SP Certificates section, and upload the SP certificate file you just downloaded
Once you've configured everything up to this point, click Save to save the SeciossLink-side settings.
Retrieving and importing the IdP metadata
Download the IdP metadata from SeciossLink and import it into ZUNDA ID to bring in the IdP-side settings in one step.
In SeciossLink, open Single Sign-On → SAML, click the Settings tab in the top-right corner, and click Download next to IdP Metadata to save the IdP metadata XML
This metadata includes the SeciossLink IdP Entity ID, SSO URL, IdP signing certificate, and more — importing it into ZUNDA ID lets you bring in all of these IdP-side settings at once.
Return to the provider details screen in ZUNDA ID, and click Import Metadata XML
In the dialog that appears, click Upload from file and select the IdP metadata XML file you saved earlier. Once you confirm it has loaded, click Import Metadata XML.
Confirm that the IdP Entity ID, SSO URL, IdP certificate, and other values have all been imported.
Running a test
Once the setup is complete, always run a login test before enabling the provider to confirm the settings are correct and that SeciossLink user information imports correctly. Because the test requires the target service to be assigned to a user on the SeciossLink side, assign the service you created to the test user's account in advance.
From the SeciossLink provider details screen in ZUNDA ID, click the Test button
Clicking the Test button opens the SeciossLink login screen in a pop-up window. If pop-ups are blocked, temporarily disable your browser's pop-up blocker.
The SeciossLink login screen appears — log in to SeciossLink using the test user's account
If the login succeeds, "SSO login test succeeded" is displayed as shown below, and the setup is complete once the check results for NameID, email address, last name, and first name all show green checkmarks (the display name is optional, so if it isn't set, ZUNDA ID sets it automatically)
If the test fails, check the following:
- Whether the SeciossLink IdP metadata was imported correctly into ZUNDA ID
- Whether the schema URIs for the Attributes to Send are configured correctly on the SeciossLink side
- Whether the created service is assigned to the test user's account
Once the test is complete, return to the provider details screen and switch Status to ON to enable SAML login via SeciossLink.
We strongly recommend completing How to Configure Recovery Settings for Login Methods in advance, in case the login method becomes unavailable. Once your setup is complete, see How to Use the SAML Provider You Created as a Login Method to enable it as a login method.