|
Item |
Description |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to set up custom attributes, see here |
||
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning(account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verification Status by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search for and select "AirCourse (SAML)."
- From "Identity Provider Information," click the "Download Metadata" button to download the metadata.
Now, switch over to configuring the AirCourse side.
Do not click the "Register" button yet. Open AirCourse in a separate window.
AirCourse Configuration
- In the left menu, under Administrator mode, open "Settings > Security > Single Sign-On," and click "Configure" for SAML authentication.
- Configure each item as shown below, then save by clicking the "Save" button.
Note: Once SAML authentication is enabled, logging in via password authentication will no longer be possible. We recommend that the person configuring SAML not log out, and instead use a different PC or browser with a different user account to test the SAML connection.
Enable SAML Authentication Check the box Allow Password Authentication for Specific Users Only Choose according to your operational needs
If checked, enabling "Enable Password Authentication" on the target user's detailed settings screen allows that user's authentication method to be set to password authentication (SAML authentication will not be available for that user)Upload Metadata Upload the "metadata" obtained from TrustLogin
The IdP information will be loaded automaticallyEnable Single Logout Uncheck the box Logout URL Leave blank Identifier (Entity ID) Copy the value and keep a note of it Reply URL (Assertion Consumer Service URL) Copy the value and keep a note of it Sign-on URL Copy the value and keep a note of it
Now return to the TrustLogin Admin Page.
TrustLogin Admin Page Configuration (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "Sign-on URL" obtained from AirCourse Entity ID The "Identifier (Entity ID)" obtained from AirCourse ACS URL for the Service The "Reply URL (Assertion Consumer Service URL)" obtained from AirCourse
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "AirCourse (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
②When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "AirCourse (SAML)" app.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.