This page introduces the procedure, in a macOS environment,
for requesting and installing the certificate used by the device certificate feature.
Step 1: Request a Device Certificate [Mac]
Step 2: Install the Device Certificate [Mac]
Supplement 1: How to Uninstall Secure Authentication Suite [Mac]
Supplement 2: How to Delete a Certificate [Mac]
For setup instructions on other operating systems, please refer to here.
For troubleshooting, please refer to here.
Step 1: Request a Device Certificate [Mac]
Install the certificate import tool
(Secure Authentication Suite, provided by Sixscape) required to request a device certificate,
and then request the certificate.
Note: OS administrator permission is required.
Steps
- Download the Secure Authentication Suite installer file from the link below.
Download Link
- Double-click the downloaded installer to run it.
Note: If you cannot run it by double-clicking, right-click it and select "Open" to run it.
- Launch Secure Authentication Suite.
A form requesting login information will appear. Enter the following information in each field and click "Connect".
・Username or email address: email address
・Domain name : trustlogin.com
- The TrustLogin login screen will appear. Log in.
- Authentication will begin. This may take some time, so please wait.
- Once authentication is complete, you will be taken to this screen.
Select "Strong Device Authentication".
- You will be taken to the screen below. Select "Start".
- Loading will occur, and you will be taken to the screen below.
Confirm that the status shown in the upper right is "Pending".
This completes the Step 1 procedure. Please exit the app.
Actions by the Administrator
Based on the operation in Step 1, the administrator will approve or deny the request. Please wait.
Once the request is approved, TrustLogin will send an email
with the subject "[GMO TrustLogin] Your Device Certificate Is Ready to Be Obtained".
If you receive this email, please proceed to the next step.
Note: Please contact your administrator regarding the status after making a request.
Step 2: Install the Certificate [Mac]
After requesting the certificate, these are the steps to follow once you have received
the "[GMO TrustLogin] Your Device Certificate Is Ready to Be Obtained" email.
Steps
- Launch the "Secure Authentication Suite" app.
If the status shown in the upper right is "Pending", tap "Verify".
Note: If the status is "Approved", please skip ahead to Step 5.
- A form requesting login information will appear. Enter the following information in each field and tap "Connect".
・Username or email address: email address
・Domain name : trustlogin.com
- The TrustLogin login screen will appear. Log in.
- Authentication will begin. This may take some time, so please wait.
- The screen below will appear. Once the status becomes "Approved",
select "Enable".
- A loading screen will appear and activation will begin.
This may take some time, so please wait.
- When this screen appears, the certificate has been installed successfully.
Tap "Finish".
- The screen below will appear.
The status in the upper right will change to "Active", and you can check the certificate information from the "Certificate" tab.
This completes the certificate installation process.
- Since you need to configure trust settings for the installed certificate, launch "Keychain Access" from LaunchPad or Finder.
Note: On macOS Sequoia or later, open Spotlight search with "Command + Space", search for "Keychain", and launch "Keychain Access".
Note: A trust setting prompt will appear when accessing Keychain.
Enter the password of a user with administrator privileges on the PC to proceed.
- After Keychain Access opens, double-click the installed certificate.
The certificate issued by TrustLogin has the following information:
name: your own email address
Issued by: TrustLogin Client Authentication 〜
- For "When using this certificate", select "Always Trust".
If the screen below appears, enter the password of a user with administrator privileges on the PC and click "Update Settings".
- Open "Apple menu (apple icon) in the upper left of the screen > System Settings > General (left menu) > Login Items & Extensions (right menu)".
- Under "Allow in the Background", uncheck "Secure Authentication Suite.app". (You may need to scroll.)
Note: If "Secure Authentication Suite.app" does not appear under "Allow in the Background", no action is needed.
This completes the setup.
Step 3: How to Log In as a User Subject to Device Restrictions [Mac]
- In the TrustLogin login form, enter your Company ID and email address.
- The "Select a Certificate" dialog will appear. Select the installed client certificate and click "OK".
Note: If multiple certificates are displayed, please select the certificate whose subject is your own email address.
-
Once you select the correct certificate, the password entry screen will appear. Please log in as usual.
Note: If you do not select the correct certificate, the error message "This client certificate is not permitted by the administrator." will be displayed. If you selected the wrong certificate, you will need to restart your browser.
Note: When using client authentication together with SAML authentication, whether single sign-on is possible outside the browser (e.g., in a mobile app) depends on the specifications of the app.
Note: If the following dialog appears the first time you connect, enter the password of a user with administrator privileges on the PC and click "Always Allow".
Supplement 1: Secure Authentication Suite Uninstallation Method [Mac]
- If Secure Authentication Suite is running, right-click the app icon and close it.
- From the Applications folder in Finder, right-click "Secure Authentication Suite.app" and delete it.
- After completing step 2, open Terminal, type the command "open ~/Library/Containers", and press Enter.
- Find "Secure Authentication Suite" in the Containers folder, right-click it, and delete it.
Note: Depending on the OS version, it may be labeled "com.sixscape.sas".
This completes the uninstallation process.
Supplement 2: How to Delete a Certificate [Mac]
- Launch "Keychain Access" from LaunchPad or Finder.
Note: On macOS Sequoia or later, open Spotlight search with "Command + Space", search for "Keychain", and launch "Keychain Access".
- Open the My Certificates tab, then right-click the certificate you want to delete and delete it.
The certificate issued by TrustLogin has the following information:
name: your own email address
Issued by: TrustLogin Client Authentication 〜
This completes the certificate deletion process.