|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (new user creation only; update and deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Prerequisites
You need to configure a custom attribute in TrustLogin member information in advance to link the employee number.
Note: Only configure the custom attribute if you want to add the employee number when creating a user.
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure this.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Configure the "Application Name" and "Icon" (optional).
- Note down the "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate from "Get Certificate".
Now, switch to configuring the Re:lation side. Please open Re:lation in a separate window.
Re:lation Settings
- Log in with an administrator account and select "System Settings" from the icon in the upper right.
- Select "SAML" from the menu on the left, and click the edit button for "Identity Provider Information".
- In "Edit SAML Settings", configure the information you noted down from TrustLogin as follows, and click "Save".
Mode Select as you prefer. (We recommend setting this to "Migration Mode" while configuring SAML.) IdP Identifier
The "Issuer / Entity ID" you noted down from TrustLogin Login URL
The "Identity Provider URL" you noted down from TrustLogin Certificate
Open the "Certificate" you noted down from TrustLogin and paste it in
- Copy and note down the "IdP Identifier" and "Response URL (Assertion Consumer Service URL)" under "Service Provider Information".
TrustLogin Admin Page Settings (Continued)
-
Configure each item under "Service Provider Settings" as follows.
Sign SAML response Check the box Value for Name ID [Member]-[email] Entity ID Enter the "IdP Identifier" you noted down from Re:lation Name ID Format Select "Unspecified" ACS URL to Service Enter the "Response URL (Assertion Consumer Service URL)" you noted down from Re:lation
- Add an attribute using the "Add SAML Attribute" button under "SAML Attribute Settings", and configure it as follows.
Note: The "emp_no" item in row 4 is optional. Only add this attribute if you want to add the employee number.Service Provider Attribute TrustLogin (IdP) Attribute Attribute Designation Name Attribute Type Attribute Name Attribute Value first_name Basic first_name ↔︎ Member Member - First Name last_name Basic last_name ↔︎ Member Member - Last Name dept_name Basic dept_name ↔︎ Member Member - Department emp_no Basic emp_no ↔︎ Custom Attribute Attribute name is optional
(e.g., Employee Number)
- Click "Register" to save the settings.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
- Click the app on "My Page" or in the browser extension, and confirm that login succeeds.
②When an administrator adds members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
How to Log in to Re:lation
- Open Re:lation from the app icon on TrustLogin's My Page or in the browser extension.
- When logging in as a user not yet registered in Re:lation, the user registration screen below will be displayed. Click the "Register User" button to log in.
Note: The user information registered in step 2 of "TrustLogin Admin Page Settings (Continued)" will be automatically reflected.