How to Configure SAML Authentication for Phrase Strings

Item

Details

Prerequisites

  • Phrase Strings requires prior configuration.
  • You must create an account in Phrase Strings using the same email address as your TrustLogin account.
  • For the latest configuration steps, please refer to the manual provided by Phrase Strings.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on how to configure provisioning, see here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app


TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Phrase Strings (SAML)".
    Phrase

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png


Now, switch to configuring the Phrase Strings side.
Do not click the "Register" button yet — open Phrase Strings in a separate window.

Phrase Strings Configuration

  1. From the icon at the top right, open "Settings > Organization".
    Phrase

  2. Open the "SSO" tab and click "Enable SSO".
    Phrase

  3. In "Phrase Settings," configure the items as follows and note down the values.
    Auto provisioning Do not check
    Enforce SSO Configure according to your operational needs
    Single sign-on callback URL Copy and note down
    Single sign-on entity Copy and note down
    EmailAddress

    Phrase

  4. In "Identity Provider Settings," configure the items as follows, then save by clicking the "Save" button at the end.
    Single sign-on URL The "IdP URL" obtained from TrustLogin
    Issuer The "Issuer / Entity ID" obtained from TrustLogin
    X.509 Certificate Upload the TrustLogin certificate
    Fingerprint algorithm SHA256

    Phrase

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Single sign-on entity" noted from Phrase Strings
    Service ACS URL The "Single sign-on callback URL" noted from Phrase Strings

    Phrase

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase Strings (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Phrase Strings (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

First Login Method

When accessing via SAML for the first time, the screen below will be displayed. Confirm the email address shown, and click "Request Link".Phrase

A verification email will be sent to the user's email address; click the link in that email. At that point, a TrustLogin error screen may appear, but authentication has already been completed at the moment you clicked the link, so please close that screen and try logging in from My Page or the Phrase Strings login page.

How to Configure SAML Authentication for Phrase Strings

Item

Details

Prerequisites

  • Phrase Strings requires prior configuration.
  • You must create an account in Phrase Strings using the same email address as your TrustLogin account.
  • For the latest configuration steps, please refer to the manual provided by Phrase Strings.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on how to configure provisioning, see here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app


TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Phrase Strings (SAML)".
    Phrase

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
    03.png


Now, switch to configuring the Phrase Strings side.
Do not click the "Register" button yet — open Phrase Strings in a separate window.

Phrase Strings Configuration

  1. From the icon at the top right, open "Settings > Organization".
    Phrase

  2. Open the "SSO" tab and click "Enable SSO".
    Phrase

  3. In "Phrase Settings," configure the items as follows and note down the values.
    Auto provisioning Do not check
    Enforce SSO Configure according to your operational needs
    Single sign-on callback URL Copy and note down
    Single sign-on entity Copy and note down
    EmailAddress

    Phrase

  4. In "Identity Provider Settings," configure the items as follows, then save by clicking the "Save" button at the end.
    Single sign-on URL The "IdP URL" obtained from TrustLogin
    Issuer The "Issuer / Entity ID" obtained from TrustLogin
    X.509 Certificate Upload the TrustLogin certificate
    Fingerprint algorithm SHA256

    Phrase

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Single sign-on entity" noted from Phrase Strings
    Service ACS URL The "Single sign-on callback URL" noted from Phrase Strings

    Phrase

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Phrase Strings (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Phrase Strings (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

First Login Method

When accessing via SAML for the first time, the screen below will be displayed. Confirm the email address shown, and click "Request Link".Phrase

A verification email will be sent to the user's email address; click the link in that email. At that point, a TrustLogin error screen may appear, but authentication has already been completed at the moment you clicked the link, so please close that screen and try logging in from My Page or the Phrase Strings login page.