|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed from TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search and select "Phrase Strings (SAML)".
-
Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
Now, switch to configuring the Phrase Strings side.
Do not click the "Register" button yet — open Phrase Strings in a separate window.
Phrase Strings Configuration
- From the icon at the top right, open "Settings > Organization".
- Open the "SSO" tab and click "Enable SSO".
- In "Phrase Settings," configure the items as follows and note down the values.
Auto provisioning Do not check Enforce SSO Configure according to your operational needs Single sign-on callback URL Copy and note down Single sign-on entity Copy and note down EmailAddress
- In "Identity Provider Settings," configure the items as follows, then save by clicking the "Save" button at the end.
Single sign-on URL The "IdP URL" obtained from TrustLogin Issuer The "Issuer / Entity ID" obtained from TrustLogin X.509 Certificate Upload the TrustLogin certificate Fingerprint algorithm SHA256
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Single sign-on entity" noted from Phrase Strings Service ACS URL The "Single sign-on callback URL" noted from Phrase Strings
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Phrase Strings (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "Phrase Strings (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.
First Login Method
When accessing via SAML for the first time, the screen below will be displayed. Confirm the email address shown, and click "Request Link".
A verification email will be sent to the user's email address; click the link in that email. At that point, a TrustLogin error screen may appear, but authentication has already been completed at the moment you clicked the link, so please close that screen and try logging in from My Page or the Phrase Strings login page.