How to Configure SAML Authentication for LStep

Item

Details

Prerequisites

  • Prior configuration on the LStep side is required.

  • The "Login ID" of the LStep user must match the user's email address in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by LStep.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible via TrustLogin)

SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01_.png

  2. Search on the "Register Corporate App" screen and select "LStep (SAML)".
    Lstep.png

  3. Note down the values of the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the "Certificate".
    03.png

  4. In the two blank fields under "Service Provider Settings", enter your LStep environment's "(protocol)://(hostname)/".
    Example: https://tenantid.lstep.jp/ (be sure to include the trailing /)
    04.png

  5. Click the "Register" button to save.

LStep Configuration

  1. Log in to LStep with an administrator account and open the "Admin Screen".
    05.png

  2. Open "Single Sign-On Settings" from "Site Settings" in the left menu.
    06.png

  3. Configure the "SAML Authentication Settings" and "Configuration Parameters" as follows, then click the "Change" button to save.
    SAML Authentication Settings Set to "Enabled"
    Configuration Parameters

    Using the template below, replace the text in red with the values obtained from TrustLogin, then save.

    entity_id=The "Issuer/Entity ID" noted from TrustLogin
    sso_url=The "IdP URL" noted from TrustLogin
    name_id_format=urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    cert=The contents of the certificate downloaded from TrustLogin (see Note below)

    Note: Delete the "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----" lines.
    Note: Remove all line breaks.


    07.png

TrustLogin User Configuration

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "LStep (SAML)", then click the "Next" button at the top right of the screen.
  3. Enter a new value if you want to change the "Display Name", then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "LStep (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for LStep

Item

Details

Prerequisites

  • Prior configuration on the LStep side is required.

  • The "Login ID" of the LStep user must match the user's email address in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by LStep.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible via TrustLogin)

SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01_.png

  2. Search on the "Register Corporate App" screen and select "LStep (SAML)".
    Lstep.png

  3. Note down the values of the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the "Certificate".
    03.png

  4. In the two blank fields under "Service Provider Settings", enter your LStep environment's "(protocol)://(hostname)/".
    Example: https://tenantid.lstep.jp/ (be sure to include the trailing /)
    04.png

  5. Click the "Register" button to save.

LStep Configuration

  1. Log in to LStep with an administrator account and open the "Admin Screen".
    05.png

  2. Open "Single Sign-On Settings" from "Site Settings" in the left menu.
    06.png

  3. Configure the "SAML Authentication Settings" and "Configuration Parameters" as follows, then click the "Change" button to save.
    SAML Authentication Settings Set to "Enabled"
    Configuration Parameters

    Using the template below, replace the text in red with the values obtained from TrustLogin, then save.

    entity_id=The "Issuer/Entity ID" noted from TrustLogin
    sso_url=The "IdP URL" noted from TrustLogin
    name_id_format=urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    cert=The contents of the certificate downloaded from TrustLogin (see Note below)

    Note: Delete the "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----" lines.
    Note: Remove all line breaks.


    07.png

TrustLogin User Configuration

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "LStep (SAML)", then click the "Next" button at the top right of the screen.
  3. Enter a new value if you want to change the "Display Name", then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "LStep (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.