KB No. 10: Configuring Wallix Trustelem as an Identity Provider (IdP) with Olfeo SaaS
Background
This document covers the implementation of the Wallix Trustelem solution with the Olfeo SaaS product. To facilitate this process, an Olfeo application is available in the Wallix catalog.
Wallix Trustelem is a solution that unifies, secures, and simplifies user access to business applications. It acts as an IDP, providing single sign-on (SSO) and centralized identity management for products that can delegate authentication, whether web-based or on-premise. To learn more about the features of this solution, please visit: Wallix Trustelem.
Prerequisites
Have synchronized your company directory with Olfeo SaaS. For this part, refer to the Olfeo SaaS technical documentation: configuring and managing directories.
Ensuring that the endpoints required for authentication (in particular, the Trustelem authentication URL) are publicly exposed on the internet.
You must select the SAML authentication method in your Olfeo directory.
Configuration steps:
- Go to Applications and click on "Add Application."

- Under "Pre-integrated Applications," search for Olfeo, then select it.

- Once in the Olfeo SaaS application, enter the following information:
- Application description
- Entity ID: Entity identifier: https://saas.trustlane.io/api/sso/saml/XXXXX/login
- Assertion Customer Service: Response URL (ACS): https://saas.trustlane.io/api/sso/saml/XXXXX/acs
- Specific login URL: Login URL: https://saas.trustlane.io/api/sso/saml/XXXXX/login
- NameID Attribute: Select the identifier property defined when synchronizing your directory with Olfeo SaaS.
- Select the desired certificate, then save.

- Once registered, download the Trusleme metadata file, then return to the Olfeo SaaS administration interface, go to Configuration, Directories, Directory editing, Authentication, and complete the "Provider metadata" section.

- Next, in Wallix Trustelem, you will need to go to the permissions section to assign users or groups to the Olfeo SaaS application.

- At this stage, all you have to do is perform an authentication test with a user.
