How to Configure SAML Authentication for CloudLog

Item

Details

Prerequisites

  • Prior configuration is required in CloudLog.

  • You must create an account in CloudLog using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by CloudLog.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "CloudLog (SAML)".
    CloudLog.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to the configuration on the CloudLog side.
Do not click the "Register" button yet — open CloudLog in a separate window.

CloudLog Configuration

  1. Open "Admin > Basic Settings > Security Settings".
    Configure each item as follows, then save by clicking the "Save" button.
    External Authentication Select "SAML Authentication"
    Metadata XML Select the "metadata" obtained from TrustLogin
    The subsequent IdP configuration fields will be entered automatically

    SLO URL

    Depending on your desired logout behavior from CloudLog, overwrite the automatically entered value as follows

    [To also log out of TrustLogin]
    https://portal.trustlogin.com/users/sign_in


    [To redirect to the TrustLogin My Page]
    https://portal.trustlogin.com/

    [To redirect to the CloudLog login page]
    Leave blank (TrustLogin will not be logged out)

    Sign-on URL

    This is not used in the TrustLogin-side configuration, but it will be the login URL used when signing in via SP-Initiated SSO, so obtain it if needed

    Entity ID Copy the value using the copy icon on the right and keep a record of it
    ACS URL Copy the value using the copy icon on the right and keep a record of it

    04.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from CloudLog
    ACS URL for the Service The "ACS URL" obtained from CloudLog

    05.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "CloudLog (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the "CloudLog (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for CloudLog

Item

Details

Prerequisites

  • Prior configuration is required in CloudLog.

  • You must create an account in CloudLog using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by CloudLog.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "CloudLog (SAML)".
    CloudLog.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to the configuration on the CloudLog side.
Do not click the "Register" button yet — open CloudLog in a separate window.

CloudLog Configuration

  1. Open "Admin > Basic Settings > Security Settings".
    Configure each item as follows, then save by clicking the "Save" button.
    External Authentication Select "SAML Authentication"
    Metadata XML Select the "metadata" obtained from TrustLogin
    The subsequent IdP configuration fields will be entered automatically

    SLO URL

    Depending on your desired logout behavior from CloudLog, overwrite the automatically entered value as follows

    [To also log out of TrustLogin]
    https://portal.trustlogin.com/users/sign_in


    [To redirect to the TrustLogin My Page]
    https://portal.trustlogin.com/

    [To redirect to the CloudLog login page]
    Leave blank (TrustLogin will not be logged out)

    Sign-on URL

    This is not used in the TrustLogin-side configuration, but it will be the login URL used when signing in via SP-Initiated SSO, so obtain it if needed

    Entity ID Copy the value using the copy icon on the right and keep a record of it
    ACS URL Copy the value using the copy icon on the right and keep a record of it

    04.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from CloudLog
    ACS URL for the Service The "ACS URL" obtained from CloudLog

    05.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "CloudLog (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the "CloudLog (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.