|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning supported (account management possible via TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Corporate App" screen and select "LStep (SAML)".
- Note down the values of the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the "Certificate".
- In the two blank fields under "Service Provider Settings", enter your LStep environment's "(protocol)://(hostname)/".
Example: https://tenantid.lstep.jp/ (be sure to include the trailing /)
- Click the "Register" button to save.
LStep Configuration
- Log in to LStep with an administrator account and open the "Admin Screen".
- Open "Single Sign-On Settings" from "Site Settings" in the left menu.
- Configure the "SAML Authentication Settings" and "Configuration Parameters" as follows, then click the "Change" button to save.
SAML Authentication Settings Set to "Enabled" Configuration Parameters Using the template below, replace the text in red with the values obtained from TrustLogin, then save.
entity_id=The "Issuer/Entity ID" noted from TrustLogin
sso_url=The "IdP URL" noted from TrustLogin
name_id_format=urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
cert=The contents of the certificate downloaded from TrustLogin (see Note below)Note: Delete the "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----" lines.
Note: Remove all line breaks.
TrustLogin User Configuration
① When a user adds the app from My Page
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "LStep (SAML)", then click the "Next" button at the top right of the screen.
- Enter a new value if you want to change the "Display Name", then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "LStep (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.