How to Configure SAML Authentication for OBIC7

Item

Details

Prerequisites

  • Preliminary configuration in OBIC7 is required.

  • For the latest setup instructions, please refer to the manual provided by OBIC7.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Preliminary Preparation

Add a Custom Attribute to User Information

Add the OBIC7 "User ID" information as a custom attribute to the member information in TrustLogin.

[TrustLogin Custom Attribute Configuration Example]
OBIC7.png

For instructions on how to configure custom attributes, refer to the pages below. The custom attribute name can be anything you like.

Custom Attribute Configuration (Individual Registration)

Custom Attribute Configuration (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "OBIC7 (SAML)".
    OBIC701.png

  3. Note down the value of "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03__3_.png


  4. Contact your OBIC representative with the SAML configuration information and request that they complete the configuration.

    IdP SAML Endpoint URL The "IdP URL" noted down from TrustLogin
    Certificate The certificate downloaded from TrustLogin

  5. Configure each item under the service provider settings as shown below.
    Login URL The "Connection URL" notified by OBIC7
    Entity ID The "Identifier" notified by OBIC7
    Value for Name ID Set to "Custom Attribute > the custom attribute name you configured"
    ACS URL for the Service The "Response URL" notified by OBIC7

    OBIC702.png

  6. Click the "Register" button to save the configuration.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "OBIC7" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "OBIC7" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for OBIC7

Item

Details

Prerequisites

  • Preliminary configuration in OBIC7 is required.

  • For the latest setup instructions, please refer to the manual provided by OBIC7.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Preliminary Preparation

Add a Custom Attribute to User Information

Add the OBIC7 "User ID" information as a custom attribute to the member information in TrustLogin.

[TrustLogin Custom Attribute Configuration Example]
OBIC7.png

For instructions on how to configure custom attributes, refer to the pages below. The custom attribute name can be anything you like.

Custom Attribute Configuration (Individual Registration)

Custom Attribute Configuration (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "OBIC7 (SAML)".
    OBIC701.png

  3. Note down the value of "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03__3_.png


  4. Contact your OBIC representative with the SAML configuration information and request that they complete the configuration.

    IdP SAML Endpoint URL The "IdP URL" noted down from TrustLogin
    Certificate The certificate downloaded from TrustLogin

  5. Configure each item under the service provider settings as shown below.
    Login URL The "Connection URL" notified by OBIC7
    Entity ID The "Identifier" notified by OBIC7
    Value for Name ID Set to "Custom Attribute > the custom attribute name you configured"
    ACS URL for the Service The "Response URL" notified by OBIC7

    OBIC702.png

  6. Click the "Register" button to save the configuration.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "OBIC7" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "OBIC7" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.