How to Configure SAML Authentication for Shachihata Cloud

Item

Content

Preliminary Check

  • Prior configuration is required on Shachihata Cloud.

  • You must create an account on Shachihata Cloud using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Shachihata Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (provisioning; account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Shachihata Cloud (SAML)".
    02.png


  3. Download the metadata by clicking the "Download Metadata" button under "Identity Provider Information".
    03.png

  4. Send the following required information to your Shachihata Cloud representative and request SAML configuration.
    URL Domain Identifier
    An identifier used by Shachihata Cloud to identify your company. Specify any string of your choice.
    SAML Identifier (Entity ID)

    The Entity ID to be configured in TrustLogin. Specify any string of your choice.

    SAML Metadata
    The "metadata" downloaded from TrustLogin


  5. Configure each item of the Service Provider settings as follows.
    Login URL https://appX.shachihata.com/app/sso/[URL Domain Identifier]
    The number in the X part of appX differs for each customer. You can check it in your login URL.
    Entity ID The "SAML Identifier (Entity ID)" you specified
    ACS URL for the Service

    https://appX.shachihata.com/app/shachi/sso/acs
    The number in the X part of appX differs for each customer. You can check it in your login URL.


    04.png
    Note: "app4" and "trustlogin-samlsso" in the image are example values.

  6. Save by clicking the "Register" button.

  7. Once you receive notification from Shachihata Cloud that the SAML configuration is complete, SAML login will be enabled.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Shachihata Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Shachihata Cloud (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Shachihata Cloud

Item

Content

Preliminary Check

  • Prior configuration is required on Shachihata Cloud.

  • You must create an account on Shachihata Cloud using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Shachihata Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (provisioning; account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Shachihata Cloud (SAML)".
    02.png


  3. Download the metadata by clicking the "Download Metadata" button under "Identity Provider Information".
    03.png

  4. Send the following required information to your Shachihata Cloud representative and request SAML configuration.
    URL Domain Identifier
    An identifier used by Shachihata Cloud to identify your company. Specify any string of your choice.
    SAML Identifier (Entity ID)

    The Entity ID to be configured in TrustLogin. Specify any string of your choice.

    SAML Metadata
    The "metadata" downloaded from TrustLogin


  5. Configure each item of the Service Provider settings as follows.
    Login URL https://appX.shachihata.com/app/sso/[URL Domain Identifier]
    The number in the X part of appX differs for each customer. You can check it in your login URL.
    Entity ID The "SAML Identifier (Entity ID)" you specified
    ACS URL for the Service

    https://appX.shachihata.com/app/shachi/sso/acs
    The number in the X part of appX differs for each customer. You can check it in your login URL.


    04.png
    Note: "app4" and "trustlogin-samlsso" in the image are example values.

  6. Save by clicking the "Register" button.

  7. Once you receive notification from Shachihata Cloud that the SAML configuration is complete, SAML login will be enabled.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Shachihata Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Shachihata Cloud (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.