|
Item |
Description |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, click here |
||
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports API-based provisioning (account management available in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Company App Registration" screen, search and select "Shoplan Headquarters (SAML)."
- Note down the "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate from "Get Certificate."
-
Enter your domain in the blank fields for "Login URL," "Entity ID," and "ACS URL for Service" under "Service Provider Settings."
Note: To check your domain, refer to the login URL provided by Shoplan.
Example: https://[Your Domain]/h2/Login.do
-
Note down the "Entity ID" (you will enter this in Shoplan later).
Example: https://[Your Domain]/head
Now, let's move on to the Shoplan configuration. Please open Shoplan in a separate window.
Shoplan Configuration
- Log in to the headquarters account using an administrator account.
- Open the "Management" tab and select "System Management."
- From the "Option Management" tab, select "Security Settings."
- In the "External Service Headquarters User Authentication" section, select "Authenticate with SAML 2.0" and configure the fields as follows.
IdP Entity ID The Issuer/Entity ID noted from TrustLogin SP Entity ID The Entity ID entered in TrustLogin's "Service Provider Settings"
https://[Your Domain]/head
Login Name Policy Select urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
SAML Sign-On Endpoint URL The IdP URL noted from TrustLogin SAML Logout Endpoint URL https://portal.trustlogin.com/ X.509 Certificate Open the certificate downloaded from TrustLogin and paste it in
- For "Combined Use with ID/Password Authentication," selecting "Prioritize External Service" will result in SAML-only login. While configuring SAML, we recommend selecting "Use ID/Password Authentication Together."
Note: If you select "Prioritize External Service" and are unable to log in due to an error in the SAML configuration, you can log in with your ID and password by accessing https://[Your Domain]/h2/Login.do?identity=skip. - Click "Change" at the bottom of the page.
TrustLogin User Configuration
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page."
- On the "App Registration" screen, select "Shoplan Headquarters (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
- Click the app from "My Page" or the browser extension, and confirm that login is successful.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "Shoplan Headquarters (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.