|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Phrase Strings (SAML)".
-
Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
Now, switch to configuring Phrase Strings.
Do not click the "Register" button yet — open Phrase Strings in a separate window.
Phrase Strings Settings
- Open "Settings > Organization" from the icon in the upper right.
- Open the "SSO" tab and click "Enable SSO".
- In "Phrase Settings", configure the items as follows and make a note of the values.
Automatic Provisioning Check the box Enforce SSO Configure according to your operational needs Single Sign-On Callback URL Copy and make a note of it Single Sign-On Subject Copy and make a note of it EmailAddress
- In "Identity Provider Settings", configure the items as follows, and finally save by clicking the "Save" button.
Single Sign-On URL The "IdP URL" obtained from TrustLogin Issuer The "Issuer/Entity ID" obtained from TrustLogin X.509 Certificate Upload the TrustLogin certificate Fingerprint Algorithm SHA256
Now return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Single Sign-On Subject" noted from Phrase Strings ACS URL to Service The "Single Sign-On Callback URL" noted from Phrase Strings
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Phrase Strings (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an administrator adds members
- Search for and click the "Phrase Strings (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
First Login Method
When accessing via SAML for the first time, the screen below will be displayed. Check the displayed email address and click "Request Link".
A verification email will be sent to the new user's email address; click the link in the email. At that point, a TrustLogin error screen will be displayed, but the new user has already been created at the moment you clicked the link, so please close that screen and try logging in from My Page or the Phrase Strings login page.