Kingsoft Cloud role-based SSO

Updated at:

Role-based single sign-on (SSO) lets your enterprise users log in to Kingsoft Cloud using their IDaaS accounts, without creating a separate sub-account for each member.

Prerequisites

Before you begin, make sure you have:

  • An active IDaaS instance in the IDaaS console

  • Admin access to both the IDaaS console and the Kingsoft Cloud console

  • The Kingsoft Cloud main account ID (available in the Kingsoft Cloud console under Account and Security)

Important

The identity provider (IdP) name you set in IDaaS (Step 2) must exactly match the IdP name you create in Kingsoft Cloud (Step 3). A mismatch causes SSO to fail.

Step 1: Add the application in IDaaS

  1. Log on to the IDaaS console.

  2. On the EIAM page, locate your instance and click Manage in the Actions column.

  3. In the left-side navigation pane, choose Applications > Add Application.

  4. On the Marketplace tab, search for Kingsoft Cloud Role-Based SSO and click Add Application.

  5. Confirm the application name and click Add.

Step 2: Configure SSO for the application

After the application is added, you are automatically redirected to the SSO tab.

Configure the following parameters, then click Save.

Parameter Required Description
Kingsoft Cloud Main Account ID Required Your Kingsoft Cloud account ID. Log on to the Kingsoft Cloud console and go to the Account and Security page to get it.
IdP Name Required The IdP name. Must exactly match the IdP name on the Role-based SSO tab of the SSO page in the Kingsoft Cloud console. For example: AliyunIDaaSRole. If no IdP exists yet, complete Step 3 first, then return here.
Other parameters Retain the default values.
By default, Application Username is set to IDaaS Username. The username of your IDaaS account must match the username in the application — otherwise SSO fails. To configure Application Username, see the "Application account" section of the "Configure SSO" topic. To restrict which IDaaS accounts can access the application, configure the Authorize parameter. For details, see the "Authorization scope" section of the "Configure SSO" topic.

Step 3: Create an IdP in Kingsoft Cloud

This step establishes the trust relationship between Kingsoft Cloud and IDaaS by uploading the IdP metadata file.

Download the metadata file from IDaaS

In the Application Settings section of the IDaaS application, download the IdP metadata file to your computer. In most cases, the metadata file is in the XML format and contains the logon URLs, the public key for verifying SAML assertions, and the assertion format.

Create the IdP in Kingsoft Cloud

  1. Log on to the Kingsoft Cloud console.

  2. In the left-side navigation pane, click SSO.

  3. On the SSO page, click Create IdP.

  4. In the dialog box, enter the IdP name and description, then upload the metadata file you downloaded.

    Use the same IdP name that you entered (or plan to enter) in the IdP Name field in Step 2.
  5. Click Submit.

Step 4: Create a role in Kingsoft Cloud

  1. Log on to the Kingsoft Cloud console.

  2. In the left-side navigation pane, click Roles.

  3. On the Roles page, click Create Role.

  4. In the Select trusted entity type section, select IdP.

  5. In the Set role information section, enter a role name and description.

  6. In the Set Carrier information section, select IdP.

  7. Click Next.

Step 5: Assign the role to an IDaaS account

  1. In the IDaaS console, open the application you added in Step 1.

  2. On the Sign-In tab, go to the Application User tab.

  3. Select the IDaaS account to use for role-based SSO and add an application account for it. The application account name must match the Kingsoft Cloud role name exactly. To assign multiple Kingsoft Cloud roles to the same IDaaS account, create a separate application account for each role.

Step 6: Test SSO

  1. Log on to the IDaaS application portal using the IDaaS account configured in Step 5.

  2. Click the Kingsoft Cloud role-based SSO icon to initiate SSO.

  3. If the account has multiple application accounts or Kingsoft Cloud roles assigned, select only one to proceed.