This page explains how administrators can use the Device Certificate option.
|
Table of Contents: 1. Basic Settings for the Device Certificate Option 2. Assigning Members and Groups 3. Reviewing Certificate Requests from Members (Approve/Deny) |
Subject of Certificates Issued Under "Device Restriction"
The subject of the private certificate used for TrustLogin authentication is as follows.
E = [Email address]
CN = [Email address]
O = [Company ID]
C = JP
1. Basic Settings for the Device Certificate Option
-
Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, then
click the "Configure" button to the right of "Device Certificate."
Check the configuration.
You can toggle the following two items on/off using the "Edit" button. (Green indicates "on")
① Enable Device Certificate Check:
When on, this enforcesdevice certificate authentication for everyone assigned to the option.
In principle, only turn this on after device certificate distribution is complete.
Note: If you turn this "on" while the operator is assigned to this option,
they will be forced to log out immediately and will be unable to log in without a device certificate.
Be sure to obtain the device certificate on a PC that can access the Admin Page before
switching this "on."
Note: Even with this setting enabled, a device certificate is not required
when logging in via the certificate import tool "Secure Authentication Suite."
② Notify Assigned Members:
When on, at the time the option is assigned, TrustLogin sends the user
a notification email containing the setup guide URL "[GMO TrustLogin]Notice: How to Use the Device Certificate Option" email.
When off, no email is sent at the time of assignment. Please guide the member on how to use it yourself.
Note: The system email sent by this option is currently available in Japanese only. (An English version is planned for the future.)
2. Assigning Members and Groups
-
On the Device Certificate settings screen, use "Add Member" or "Add Group"
to select the members/groups you want to assign device restriction to, then click the "Add" button.
Note: If "Enable Device Certificate Check" is turned "on" and
the operator assigns themselves to the option via "Add Member" or "Add Group,"
they will be forced to log out and will be unable to log in without a device certificate.
If you need to remove this option, please ask another administrator to do so.
- An email titled
"[GMO TrustLogin] Notice: How to Use the Device Certificate Option" is sent
to the registered members or to members belonging to the registered groups.
Note that if "Notify Assigned Members" is set to OFF,
please provide the usage instructions to members yourself.
Also, the "All Assigned Members & Devices" list displays the members assigned
via each of the "Member" and "Group" assignments.
Please confirm that the invitation status of the target member is "Invited."
The meaning of each invitation status is as follows.
| Invitation Status | Description |
| Invited | The member's invitation is complete and device registration is available. |
| Cannot Invite | The same email address is registered under another company ID and is assigned the Device Certificate option. Since the option cannot be used across multiple company IDs, you must remove the option assignment from the company ID(s) you are not using. |
3. Reviewing Certificate Requests from Members (Approve/Deny)
- When a member submits a certificate request from the tool,
the requesting device's information appears under "Device Information" on the Device Certificate settings screen.
- Check the device information with a status of "Pending Approval" and approve or deny the request.
To Approve a Request
① Select the target device and click the "Approve" button.
② Click "Yes" on the confirmation screen.
③ Once the status changes to "Approved," the approval is complete.
An email titled
"[GMO TrustLogin] Your Device Certificate Is Ready to Download" is sent
to the member who requested the certificate, and the certificate can now be installed.
To Deny a Request
① Select the target device and click the "Block" button.
② Click "Yes" on the confirmation screen.
③ Once the status changes to "Rejected," the device is blocked (denied).
An email titled
"[GMO TrustLogin] Your Device Certificate Request Has Been Denied" is sent
to the member who requested the certificate.
Note: Even for a device that has been blocked, selecting it and clicking "Unblock" will
make it eligible for approval again.
An email titled
"[GMO TrustLogin] Your Device Certificate Denial Has Been Lifted" is sent
to the member who requested the certificate.
Deleting a Registered Device
A device removed using this procedure can be reused as another user's device.
Note: The certificate issued for the target device will be revoked and cannot be restored, so please be careful.
- Select the target device and click "Remove."
- Click "Yes" on the confirmation screen.
- The device registration is removed and the device information is deleted from the list.
Note: If another user will reuse the removed device, please reinstall the certificate import tool "Secure Authentication Suite" that is already installed.
(On Windows and Mac, you will also need to clear the installer cache. For details, please check here.)
The meaning of each device status is as follows.
| Status | Description |
| Pending Approval | A certificate request has been submitted by a member and is awaiting administrator approval. |
| Approved | The administrator has approved the request. |
| Pre-Approved | The administrator has registered the device as pre-approved. |
| Distributed | The member has completed installing the certificate. |
| Rejected | The administrator has blocked (denied) the request. |
4. Managing Device Certificates
About Issued Certificates
・Each issued certificate is tied to a specific device and has its own unique serial number.
・The maximum number of certificates (devices) a single user can use at the same time is 10.
・Certificates can be revoked individually by serial number (per device).
Note: Revoked certificates are not counted toward the concurrent usage limit.
Checking Certificate Status
Information about certificates issued so far can be checked
under "Certificate Information" on the Device Certificate settings screen.
The meaning of each certificate status is as follows.
| Status | Description |
| Valid | Issued and installed through the member's action, and available for use in access restriction. |
| Revoked | Revoked by the administrator and no longer available for use in access restriction. |
Root Certificate / Intermediate CA Certificate
Please download them from the links below when needed.
Root certificate: trustloginrootca2022.crt
Intermediate CA certificate: trustloginclientauthca2022.crt
Revoking a Certificate
Note: A revoked certificate cannot be restored to its original state.
To issue a certificate again for the target device, the member must perform the operation again and
the administrator must approve it, so please be aware of this.
① Select the target certificate and click the "Revoke" button.
② Click "Yes" on the confirmation screen.
③ Once the status changes to "Revoked," the certificate has been revoked.
Notes
There are some specification-related notes about this option. Administrators should be aware of the following.
・This option cannot be used for a user with the same email address across multiple company IDs.
You must remove the option assignment from the company ID(s) you are not using.
・The system emails sent by this option are currently available in Japanese only.
(An English version is planned for the future.)
・Logs generated by this option's asynchronous processing are recorded as actions taken by
the administrator who created the company ID.
・Device certificates for multiple users cannot be installed on the same device.
Any attempt to install will fail with an error.
・On some older iPhone/iPad models, device information cannot be obtained unless a SIM is inserted,
so a device certificate cannot be obtained.
・This option cannot be used together with the Client Authentication option for the same member.
When turning on "Enable Device Certificate Check,"
you must unassign the Client Authentication option.
5. Troubleshooting
Frequently asked questions are compiled on this page. Please check it if you run into any issues.