This page introduces
the procedure, in an iOS environment, for requesting and installing the certificate used by the device certificate feature.
Note: On some older iPhone/iPad devices, the certificate request process may not complete successfully unless a SIM card is inserted.
Step 1: Request a Device Certificate [iOS]
Step 2: Install the Device Certificate [iOS]
Supplement 1: How to Uninstall Secure Authentication Suite [iOS]
Supplement 2: How to Delete a Certificate [iOS]
For setup instructions on other operating systems, please refer to here.
For troubleshooting, please refer to here.
Step 1: Request a Device Certificate [iOS]
Install the certificate import tool
(Secure Authentication Suite, provided by Sixscape) required to request a device certificate,
and then request the certificate.
Steps
- Access the App Store, search for "sixscape", and
install the "Secure Authentication Suite" app.
- Launch the "Secure Authentication Suite" app.
A form requesting login information will appear. Enter the following information in each field and tap "Connect".
・Username or email address: email address
・Domain name : trustlogin.com
Note: If the following message appears, tap "Continue".
- The TrustLogin login screen will appear. Log in.
- Authentication will begin. This may take some time, so please wait.
- Once authentication is complete, you will be taken to this screen.
Tap "Strong Device Authentication".
- You will be taken to the screen below.
Tap "Start" to begin loading.
- You will be taken to the screen for downloading the configuration profile.
Tap "Allow" to download the profile, then tap "Close".
- Exit the "Secure Authentication Suite" app and open the iOS "Settings" app.
- Tap the profile you just downloaded to display it.
Note: If it is not displayed here, go to "General > VPN & Device Management".
- Tap the downloaded profile "Device enrollment plofile" to proceed,
then tap "Install".
- A confirmation screen will appear. Proceed with "Install > Install".
- Installation will begin, so please wait.
- Once loading finishes,
the message "Unable to Install Profile" will appear,
but if it shows (PENDING error 3), this is normal behavior. Tap "OK".
Note: After tapping "OK", do not tap "Cancel" — proceed to step 14.
- Open the "Secure Authentication Suite" app again,
and tap "Strong Device Authentication".
-
Confirm that the status shown in the upper right is "Pending".
This completes the Step 1 procedure. Please exit the app.
Actions by the Administrator
Based on the operation in Step 1, the administrator will approve or deny the request. Please wait.
Once the request is approved, TrustLogin will send an email
with the subject "[GMO TrustLogin] Your Device Certificate Is Ready to Be Obtained".
If you receive this email, please proceed to the next step.
Note: Please contact your administrator regarding the status after making a request.
Step 2: Install the Device Certificate [iOS]
After requesting the certificate, these are the steps to follow once you have received
the "[GMO TrustLogin] Your Device Certificate Is Ready to Be Obtained" email.
Steps
- Open the iOS "Settings" app.
- Tap the profile you downloaded in Step 1 to display it.
Note: If it is not displayed here, go to "General > VPN & Device Management".
- Tap the downloaded profile "Device enrollment plofile" to proceed,
then tap "Install".
Note: If the profile is still not displayed on this screen, please check here.
- A confirmation screen will appear. Proceed with "Install > Install".
- Installation will begin, so please wait.
- Once the installation succeeds, tap "Done".
- Confirm that "Device enrollment plofile" has been added under
"General > VPN & Device Management > Configuration Profile", then exit the "Settings" app.
- Launch the "Secure Authentication Suite" app,
and tap "Strong Device Authentication".
- Tap "Verify".
- A form requesting login information will appear.
Confirm that the following information is entered in each field, then tap "Connect".
・Username or email address: email address
・Domain name : trustlogin.com
Note: If the following screen appears, tap "Continue".
- The TrustLogin login screen will appear. Log in.
- Authentication will begin. This may take some time, so please wait.
- Once authentication is complete, the screen below will appear.
The status in the upper right will change to "Active", and you can check the certificate information from the "Certificate" tab.
This completes the certificate installation process.
Step 3: How to Log In as a User Subject to Device Restrictions [iOS]
- In the TrustLogin login form, enter your Company ID and email address.
- The "Select a Certificate" dialog will appear. Select the installed client certificate.
Note: If multiple certificates are displayed, please select the certificate whose subject is your own email address.
-
Once you select the correct certificate, the password entry screen will appear. Please log in as usual.
Note: If you do not select the correct certificate, the error message "This client certificate is not permitted by the administrator." will be displayed. If you selected the wrong certificate, you will need to restart your browser.
Note: When using client authentication together with SAML authentication, whether single sign-on is possible outside the browser (e.g., in a mobile app) depends on the specifications of the app.
Supplement 1: How to Uninstall Secure Authentication Suite [iOS]
- On the home screen, press and hold the SAS icon, then delete (uninstall) the app.
This completes the uninstallation process.
Supplement 2: How to Delete a Certificate [iOS]
- Open the Settings app, go to General > VPN & Device Management, then tap the certificate you want to delete.
- After tapping "Remove Profile", enter your device passcode, then tap Delete.
This completes the certificate deletion process.