How to Configure SAML Authentication for Rakuraku Hanbai

Item

Details

Pre-check

  • Prior configuration in Rakuraku Hanbai is required.

  • You must have already created an account in Rakuraku Hanbai using the same email address as your TrustLogin account.
  • Please refer to the manual provided by Rakuraku Hanbai for the latest configuration steps.

Important Notes

  • The first time you log in after configuring SAML, you will be redirected to the Rakuraku Hanbai login screen and will need to enter your Rakuraku Hanbai login ID and password. (From the second login onward, entering the login ID and password will not be required.)

  • After configuring SAML, only login via SAML will be available. If there is an error in the SAML configuration and you become unable to log in, you can log in to Rakuraku Hanbai with your ID and password by accessing the following URL: https:///xxxxxxxx.htdb.jp/your-URL/sso/off
    .

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Hanbai (SAML)".
    ____01.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    ________01.png

    Now, switch to configuring Rakuraku Hanbai. Open Rakuraku Hanbai in a separate window.

Rakuraku Hanbai Configuration

  1. Log in with an administrator account and click the "Administrator Settings" button.
    ____01.png

  2. Open the "System Settings" tab and click "General Detailed Settings".
    ____02.png

  3. Configure the following items in "Single Sign-On Settings".

    Single Sign-On Check "Use"

    Identity Provider Login URL

    The IdP URL noted from TrustLogin
    Identity Provider Logout URL https://portal.trustlogin.com/
    Identity Provider Certificate Change the file extension of the certificate downloaded from TrustLogin to ".crt" and upload it

    ____03.png

  4. Download the metadata from "Download Metadata", and finally click "Confirm".

    Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Enter the Rakuraku Hanbai login URL in the "Login URL" field of "Service Provider Settings".
  2. Upload the metadata noted from Rakuraku Hanbai using "Select Metadata".

    ____04.png

  3. Save the configuration by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Rakuraku Hanbai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Hanbai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Rakuraku Hanbai

Item

Details

Pre-check

  • Prior configuration in Rakuraku Hanbai is required.

  • You must have already created an account in Rakuraku Hanbai using the same email address as your TrustLogin account.
  • Please refer to the manual provided by Rakuraku Hanbai for the latest configuration steps.

Important Notes

  • The first time you log in after configuring SAML, you will be redirected to the Rakuraku Hanbai login screen and will need to enter your Rakuraku Hanbai login ID and password. (From the second login onward, entering the login ID and password will not be required.)

  • After configuring SAML, only login via SAML will be available. If there is an error in the SAML configuration and you become unable to log in, you can log in to Rakuraku Hanbai with your ID and password by accessing the following URL: https:///xxxxxxxx.htdb.jp/your-URL/sso/off
    .

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Hanbai (SAML)".
    ____01.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    ________01.png

    Now, switch to configuring Rakuraku Hanbai. Open Rakuraku Hanbai in a separate window.

Rakuraku Hanbai Configuration

  1. Log in with an administrator account and click the "Administrator Settings" button.
    ____01.png

  2. Open the "System Settings" tab and click "General Detailed Settings".
    ____02.png

  3. Configure the following items in "Single Sign-On Settings".

    Single Sign-On Check "Use"

    Identity Provider Login URL

    The IdP URL noted from TrustLogin
    Identity Provider Logout URL https://portal.trustlogin.com/
    Identity Provider Certificate Change the file extension of the certificate downloaded from TrustLogin to ".crt" and upload it

    ____03.png

  4. Download the metadata from "Download Metadata", and finally click "Confirm".

    Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Enter the Rakuraku Hanbai login URL in the "Login URL" field of "Service Provider Settings".
  2. Upload the metadata noted from Rakuraku Hanbai using "Select Metadata".

    ____04.png

  3. Save the configuration by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Rakuraku Hanbai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Hanbai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.