Due to an update to SmartDB, the latest manual is published on a separate page.
This is the old manual page. If you are setting up SmartDB SSO for the first time, please refer to the new manual page.
| Item | Details | |
|---|---|---|
| Prerequisites |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For instructions on setting custom attributes, see here | ||
| SP-side settings | 〇 | Configured by the administrator |
| Request the SP to configure the settings | ||
| Provisioning | Supports provisioning via API (accounts can be managed in TrustLogin) | |
| Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported) | ||
| 〇 |
None (accounts are created in each system) |
|
| Access Method | 〇 | SP-Initiated SSO |
| ー | IdP-Initiated SSO | |
| Verified Operation by Device | 〇 | PC - Browser |
| ー | PC - Desktop app | |
| 〇 | iOS - Standard browser (Safari) | |
| 〇 | iOS - TrustLogin mobile app in-app browser | |
| ※ | iOS - Native app | |
| 〇 | Android - Standard browser (Chrome) | |
| 〇 | Android - TrustLogin mobile app in-app browser | |
| 〇 | Android - Native app | |
| SAML Authentication Scope | ー | Enabled for everyone |
| 〇 |
Other: Enabled for everyone (both SAML authentication and password authentication are available) |
|
| Notes |
|
|
|
Table of Contents: |
Configuring the TrustLogin Admin Page
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "SmartDB (SAML)".
Note: Due to the release of a new template, the app name has been changed to "[Legacy] SmartDB (SAML)".
- Note down the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
-
Enter the login URL notified by SmartDB into all of the "Login URL", "Entity ID", and "ACS URL for Service" fields under "Service Provider Settings".
Example: https://[your domain].smartdb.jp
Note: Please make sure not to include a trailing "/".
- Click the "Register" button to save.
Configuring SmartDB
- Log in with an administrator account and select "System Administration" from the icon in the upper right.
- Open "Authentication & Security > Authentication" and click "Edit" for "SAML".
-
Configure each item on the "Basic Settings" tab as follows and save.
Button name displayed on the login page Any button name
Note: The button name you set will be displayed on the login screen. The default setting is also acceptable.SAML Sign-On Endpoint URL The "Identity Provider URL" obtained from TrustLogin X.509 Certificate The contents of the "Certificate" obtained from TrustLogin Name ID Unspecified (UNSPECIFIED) Authenticate using the device's default browser ON
(If you are using client authentication, you will not be able to log in if this is OFF)Use universal links Optional
Note: You can change the SSO login button name in "Button name displayed on the login page".
- Open the "IP Address Control" tab and configure it according to your company's policy.
Note: This setting is optional.
Note: If you select "Allow List", enter and save the IP addresses that are allowed to log in. If "Allow List" is selected, SAML login from the mobile app will no longer be possible.
- Click the "Save" button to save.
Configuring TrustLogin Users
① When a user adds the app from My Page
Note: The administrator must have already set up the SAML app in advance.
- Click the "Add App" button on "My Page".
- Select "SmartDB (SAML)" on the "Register App" screen and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds a member
- Search for the "SmartDB (SAML)" app on the "Admin Page > Apps" menu and click it.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In
① How to Log In via SP-Initiated SSO
- Open the SmartDB login screen, enter your email address, and proceed.
- Click the SSO login button.
- If you are already logged in to TrustLogin, you will be logged in to SmartDB automatically.
If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen. Once you authenticate, you will be logged in to SmartDB.
② How to Install the Native App
- Log in from your PC or smartphone, and open "Mobile Use" from the icon in the upper right of the page.
- Scan the QR code displayed on your mobile device to install the app.
- Open the app, confirm that the SmartDB company ID has been entered automatically, and click "Next".
Note: If the company ID is not entered after installation, scan the QR code again.
- Click the SSO login button and log in.