|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation Status by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Corporate App" screen, search for and select "Zweisoft ERP (SAML)."
- Note the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
At this point, move on to the configuration on the Zweisoft ERP side.
Do not click the "Register" button yet; open Zweisoft ERP in a separate window.
Zweisoft ERP Configuration
- Open "Admin Menu > Account Management," and click "SAML Settings > Settings Page" at the bottom of the page.
- Click the "Add IdP" button.
- Configure each item as follows, then save by clicking the "Create" button at the end.
Name Any string (up to 15 characters) Identification Code Any string (up to 15 characters) IDP Entity Id The "Issuer/Entity ID" obtained from TrustLogin Sso Target URL The "IdP URL" obtained from TrustLogin Slo Target URL The "IdP URL" obtained from TrustLogin IDP X509 Certification The contents of the "certificate" obtained from TrustLogin Status "Enabled"
- Confirm that the IdP has been added, enable "SAML Authentication," and click the "Update" button.
Note: Disabling "Normal Login" will prevent login using an ID and password. If you want to allow login only via SAML authentication, we recommend switching this to "Enabled" only after verification and operational readiness are complete.
- Note the values of each item under "SP Information" in the IdP settings you created.
Now, return to the TrustLogin Admin Page.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Login URL The "Login URL" obtained from Zweisoft ERP Redirect URL After Successful SP Authentication Your Zweisoft ERP subdomain portion
(for example, "xxxxxxx" in https://xxxxxxx.tsubaiso.net/eap/)Entity ID The "Entity ID" obtained from Zweisoft ERP ACS URL to the Service The "ACS URL" obtained from Zweisoft ERP
- Save by clicking the "Register" button.
TrustLogin User Configuration
(1) When a User Adds the App from My Page
- On "My Page," click the "Add App" button.
- On the "Register App" screen, select "Zweisoft ERP (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
(2) When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "Zweisoft ERP (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.