How to Configure SAML Authentication for Lookout

Item

Details

Prerequisites

  • Prior configuration on the Lookout side is required.

  • You must have an account created in Lookout using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Lookout.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Enterprise App" screen and select "Lookout (SAML)".
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png

  4. Uploading the metadata exported from TrustLogin directly to Lookout as-is will cause authentication to fail, so the metadata must be edited.

    Open the downloaded metadata file in a text editor, delete everything from the section starting with
    <ds:Signature〜 through </ds:Signature>, and save (overwrite) the file.
    (It is easier to find this by searching the file for "signature".)
    04.png

Now switch to the configuration on the Lookout side.
Open the Lookout Management Console in a separate window.

Configuring Lookout

  1. Log in with an account that has System Administrator privileges, and open "Administration > Enterprise Integration".
    05.png

  2. Open "Single Sign-On" from the left-hand menu, and download the metadata from "SP METADATA".
    06.png

  3. Open the "SSO Providers" tab and click the "+New" button.
    07.png

  4. Configure each item as follows and click the "Register" button to save.
    Name Any name of your choice
    Type Select "Identity Provider"

    SSO Group

    Select "Default"
    Metadata Link ① Click the "Upload a File" button and select the metadata file you downloaded from TrustLogin and edited earlier
    ② Click the "Validate" button
    ③ Confirm that a value is populated in the "Entity ID" field below

    08.png

  5. Confirm that the IdP information has been added.
    09.png

  6. Open "Administration > System Setting".
    10.png

  7. Open "Enterprise Authentication" from the left-hand menu, configure each item under "Enterprise Single Sign-On Settings" as follows, and click the "Register" button to save.
    Identity Provider Select the IdP you created
    Management Console Toggle ON
    Relay State Copy the value using the "Copy" button on the right and keep it for later
    Decryption Client Toggle OFF

    11.png

Now return to the TrustLogin settings again.

Configuring the TrustLogin Admin Page (continued)

  1. Open the metadata file you downloaded from Lookout in a text editor and obtain the following two values.

    ① Search the file for "entityID" and extract the value of EntityDescriptor entityID
    12.png

    ② Search the file for "AssertionConsumerService index=\"1\"" and extract the value of Location
    13.png

  2. Configure each item under "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication The "Relay State" you noted from Lookout
    Entity ID ① EntityDescriptor entityID extracted in step 1
    ACS URL for the service ② AssertionConsumerService Location extracted in step 1

    14.png

  3. Click the "Register" button to save.

Configuring the TrustLogin User

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Lookout (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and check that login succeeds.

② When an administrator adds members

  1. Search for the "Lookout (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Lookout

Item

Details

Prerequisites

  • Prior configuration on the Lookout side is required.

  • You must have an account created in Lookout using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Lookout.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Enterprise App" screen and select "Lookout (SAML)".
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png

  4. Uploading the metadata exported from TrustLogin directly to Lookout as-is will cause authentication to fail, so the metadata must be edited.

    Open the downloaded metadata file in a text editor, delete everything from the section starting with
    <ds:Signature〜 through </ds:Signature>, and save (overwrite) the file.
    (It is easier to find this by searching the file for "signature".)
    04.png

Now switch to the configuration on the Lookout side.
Open the Lookout Management Console in a separate window.

Configuring Lookout

  1. Log in with an account that has System Administrator privileges, and open "Administration > Enterprise Integration".
    05.png

  2. Open "Single Sign-On" from the left-hand menu, and download the metadata from "SP METADATA".
    06.png

  3. Open the "SSO Providers" tab and click the "+New" button.
    07.png

  4. Configure each item as follows and click the "Register" button to save.
    Name Any name of your choice
    Type Select "Identity Provider"

    SSO Group

    Select "Default"
    Metadata Link ① Click the "Upload a File" button and select the metadata file you downloaded from TrustLogin and edited earlier
    ② Click the "Validate" button
    ③ Confirm that a value is populated in the "Entity ID" field below

    08.png

  5. Confirm that the IdP information has been added.
    09.png

  6. Open "Administration > System Setting".
    10.png

  7. Open "Enterprise Authentication" from the left-hand menu, configure each item under "Enterprise Single Sign-On Settings" as follows, and click the "Register" button to save.
    Identity Provider Select the IdP you created
    Management Console Toggle ON
    Relay State Copy the value using the "Copy" button on the right and keep it for later
    Decryption Client Toggle OFF

    11.png

Now return to the TrustLogin settings again.

Configuring the TrustLogin Admin Page (continued)

  1. Open the metadata file you downloaded from Lookout in a text editor and obtain the following two values.

    ① Search the file for "entityID" and extract the value of EntityDescriptor entityID
    12.png

    ② Search the file for "AssertionConsumerService index=\"1\"" and extract the value of Location
    13.png

  2. Configure each item under "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication The "Relay State" you noted from Lookout
    Entity ID ① EntityDescriptor entityID extracted in step 1
    ACS URL for the service ② AssertionConsumerService Location extracted in step 1

    14.png

  3. Click the "Register" button to save.

Configuring the TrustLogin User

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Lookout (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and check that login succeeds.

② When an administrator adds members

  1. Search for the "Lookout (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.