How to Configure SAML Authentication for Zweisoft ERP

 Item

Details 

Prerequisites

  • Prior configuration in Zweisoft ERP is required.

  • You must create an account in Zweisoft ERP using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Zweisoft ERP.

Name ID

Email address

 

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App



TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Zweisoft ERP (SAML)."
    ____ERP.png

  3. Note the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png

At this point, move on to the configuration on the Zweisoft ERP side.
Do not click the "Register" button yet; open Zweisoft ERP in a separate window.

Zweisoft ERP Configuration

  1. Open "Admin Menu > Account Management," and click "SAML Settings > Settings Page" at the bottom of the page.
    04.png
    05.png

  2. Click the "Add IdP" button.
    06.png

  3. Configure each item as follows, then save by clicking the "Create" button at the end.
    Name Any string (up to 15 characters)
    Identification Code Any string (up to 15 characters)
    IDP Entity Id The "Issuer/Entity ID" obtained from TrustLogin
    Sso Target URL The "IdP URL" obtained from TrustLogin
    Slo Target URL The "IdP URL" obtained from TrustLogin
    IDP X509 Certification The contents of the "certificate" obtained from TrustLogin
    Status "Enabled"

    07.png

  4. Confirm that the IdP has been added, enable "SAML Authentication," and click the "Update" button.
    Note: Disabling "Normal Login" will prevent login using an ID and password. If you want to allow login only via SAML authentication, we recommend switching this to "Enabled" only after verification and operational readiness are complete.
    08.png

  5. Note the values of each item under "SP Information" in the IdP settings you created.
    09.png


Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" obtained from Zweisoft ERP
    Redirect URL After Successful SP Authentication Your Zweisoft ERP subdomain portion
    (for example, "xxxxxxx" in https://xxxxxxx.tsubaiso.net/eap/)
    Entity ID The "Entity ID" obtained from Zweisoft ERP
    ACS URL to the Service The "ACS URL" obtained from Zweisoft ERP

    10.png

  2. Save by clicking the "Register" button.

 

TrustLogin User Configuration

(1) When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Zweisoft ERP (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

(2) When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Zweisoft ERP (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Zweisoft ERP

 Item

Details 

Prerequisites

  • Prior configuration in Zweisoft ERP is required.

  • You must create an account in Zweisoft ERP using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Zweisoft ERP.

Name ID

Email address

 

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App



TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Zweisoft ERP (SAML)."
    ____ERP.png

  3. Note the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png

At this point, move on to the configuration on the Zweisoft ERP side.
Do not click the "Register" button yet; open Zweisoft ERP in a separate window.

Zweisoft ERP Configuration

  1. Open "Admin Menu > Account Management," and click "SAML Settings > Settings Page" at the bottom of the page.
    04.png
    05.png

  2. Click the "Add IdP" button.
    06.png

  3. Configure each item as follows, then save by clicking the "Create" button at the end.
    Name Any string (up to 15 characters)
    Identification Code Any string (up to 15 characters)
    IDP Entity Id The "Issuer/Entity ID" obtained from TrustLogin
    Sso Target URL The "IdP URL" obtained from TrustLogin
    Slo Target URL The "IdP URL" obtained from TrustLogin
    IDP X509 Certification The contents of the "certificate" obtained from TrustLogin
    Status "Enabled"

    07.png

  4. Confirm that the IdP has been added, enable "SAML Authentication," and click the "Update" button.
    Note: Disabling "Normal Login" will prevent login using an ID and password. If you want to allow login only via SAML authentication, we recommend switching this to "Enabled" only after verification and operational readiness are complete.
    08.png

  5. Note the values of each item under "SP Information" in the IdP settings you created.
    09.png


Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" obtained from Zweisoft ERP
    Redirect URL After Successful SP Authentication Your Zweisoft ERP subdomain portion
    (for example, "xxxxxxx" in https://xxxxxxx.tsubaiso.net/eap/)
    Entity ID The "Entity ID" obtained from Zweisoft ERP
    ACS URL to the Service The "ACS URL" obtained from Zweisoft ERP

    10.png

  2. Save by clicking the "Register" button.

 

TrustLogin User Configuration

(1) When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Zweisoft ERP (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

(2) When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Zweisoft ERP (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.