|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed from TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search and select "Dexeco (SAML)".
- Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
Now, switch to configuring the Dexeco side. Do not click the "Register" button yet — open Dexeco in a separate window.
Dexeco Configuration
- Log in to Dexeco, open "Organization Settings > SSO Settings", and configure each item as follows.
Single Sign-OnCheck "Enable".
Note: If you check "Allow login only via single sign-on," logging in with an email address will no longer be possible. We recommend leaving this unchecked when configuring SAML.
Entity ID The "Issuer / Entity ID" obtained from TrustLogin Target URL The "IdP URL" obtained from TrustLogin IdP Certificate The contents of the "certificate" obtained from TrustLogin
- Note down the "Assertion Consumer Service URL", "Issuer", and "Login URL", then click "Save".
Note: The "Login URL" is used for SP-Initiated SSO.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Issuer" obtained from Dexeco Service ACS URL The "Assertion Consumer Service URL" obtained from Dexeco
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Dexeco (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "Dexeco (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.