How to Configure SAML Authentication for Shoplan (Headquarters User)

 Item

Description 

Prerequisites

  • Advance configuration in Shoplan is required.
  • You need to register the same email address as TrustLogin in Shoplan's "Login ID."
  • For the latest configuration steps, please refer to the manual provided by Shoplan.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, click here

SP-Side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports API-based provisioning (account management available in TrustLogin)

 

Supports SAML JIT provisioning (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Company App Registration" screen, search and select "Shoplan Headquarters (SAML)."
    Shop______.__png.png

  3. Note down the "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate from "Get Certificate."
    Sho__01.png
  4. Enter your domain in the blank fields for "Login URL," "Entity ID," and "ACS URL for Service" under "Service Provider Settings."
    Note: To check your domain, refer to the login URL provided by Shoplan.
     Example: https://[Your Domain]/h2/Login.do

  5. Note down the "Entity ID" (you will enter this in Shoplan later).
     Example: https://[Your Domain]
    /head
    shop__02.png

    Now, let's move on to the Shoplan configuration. Please open Shoplan in a separate window.

Shoplan Configuration

  1. Log in to the headquarters account using an administrator account.
  2. Open the "Management" tab and select "System Management."
    Shop__03.png

  3. From the "Option Management" tab, select "Security Settings."
    Shop__04.png

  4. In the "External Service Headquarters User Authentication" section, select "Authenticate with SAML 2.0" and configure the fields as follows.
    IdP Entity ID The Issuer/Entity ID noted from TrustLogin
    SP Entity ID

    The Entity ID entered in TrustLogin's "Service Provider Settings"

    https://[Your Domain]/head

    Login Name Policy

    Select urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

    SAML Sign-On Endpoint URL The IdP URL noted from TrustLogin
    SAML Logout Endpoint URL https://portal.trustlogin.com/
    X.509 Certificate Open the certificate downloaded from TrustLogin and paste it in

    Shop__05.png

  5. For "Combined Use with ID/Password Authentication," selecting "Prioritize External Service" will result in SAML-only login. While configuring SAML, we recommend selecting "Use ID/Password Authentication Together."
    Note: If you select "Prioritize External Service" and are unable to log in due to an error in the SAML configuration, you can log in with your ID and password by accessing https://[Your Domain]/h2/Login.do?identity=skip.
    Shop__06.png
  6. Click "Change" at the bottom of the page.Shop__07.png

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "App Registration" screen, select "Shoplan Headquarters (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Shoplan Headquarters (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Shoplan (Headquarters User)

 Item

Description 

Prerequisites

  • Advance configuration in Shoplan is required.
  • You need to register the same email address as TrustLogin in Shoplan's "Login ID."
  • For the latest configuration steps, please refer to the manual provided by Shoplan.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, click here

SP-Side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports API-based provisioning (account management available in TrustLogin)

 

Supports SAML JIT provisioning (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Company App Registration" screen, search and select "Shoplan Headquarters (SAML)."
    Shop______.__png.png

  3. Note down the "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate from "Get Certificate."
    Sho__01.png
  4. Enter your domain in the blank fields for "Login URL," "Entity ID," and "ACS URL for Service" under "Service Provider Settings."
    Note: To check your domain, refer to the login URL provided by Shoplan.
     Example: https://[Your Domain]/h2/Login.do

  5. Note down the "Entity ID" (you will enter this in Shoplan later).
     Example: https://[Your Domain]
    /head
    shop__02.png

    Now, let's move on to the Shoplan configuration. Please open Shoplan in a separate window.

Shoplan Configuration

  1. Log in to the headquarters account using an administrator account.
  2. Open the "Management" tab and select "System Management."
    Shop__03.png

  3. From the "Option Management" tab, select "Security Settings."
    Shop__04.png

  4. In the "External Service Headquarters User Authentication" section, select "Authenticate with SAML 2.0" and configure the fields as follows.
    IdP Entity ID The Issuer/Entity ID noted from TrustLogin
    SP Entity ID

    The Entity ID entered in TrustLogin's "Service Provider Settings"

    https://[Your Domain]/head

    Login Name Policy

    Select urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

    SAML Sign-On Endpoint URL The IdP URL noted from TrustLogin
    SAML Logout Endpoint URL https://portal.trustlogin.com/
    X.509 Certificate Open the certificate downloaded from TrustLogin and paste it in

    Shop__05.png

  5. For "Combined Use with ID/Password Authentication," selecting "Prioritize External Service" will result in SAML-only login. While configuring SAML, we recommend selecting "Use ID/Password Authentication Together."
    Note: If you select "Prioritize External Service" and are unable to log in due to an error in the SAML configuration, you can log in with your ID and password by accessing https://[Your Domain]/h2/Login.do?identity=skip.
    Shop__06.png
  6. Click "Change" at the bottom of the page.Shop__07.png

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "App Registration" screen, select "Shoplan Headquarters (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Shoplan Headquarters (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.