How to Configure SAML Authentication for ZAC

Item

Details

Prerequisites

  • Prior configuration in ZAC is required.

  • The email address set in the employee information in ZAC must match the email address used in TrustLogin.

  • You will need to prepare the certificate used by the authentication server for verification.
  • Please have an administrator with access to the internal network perform the external authentication configuration.
  • For the latest configuration steps, please refer to the manual provided by ZAC.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, click here

SP-side configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "ZAC (SAML)."
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

Now, switch to the configuration on the ZAC side.
Do not click the "Register" button yet — open ZAC in a separate window.

Configuring ZAC

  1. From the admin screen menu, open "Accounting/Administration > Master > External Authentication Master" and click the "New Registration" button.
    04.png
    05.png

  2. Configure each item as follows and save by clicking the "Register" button.
    Code Any string
    Name Any string (this becomes the button name displayed on the login page)
    Authentication method Select "SAML2"
    Certificate

    Upload the certificate file
    Note: This is the certificate used by the authentication server to verify that requests to the authentication server come from your ZAC.
    Note: Unlike the certificate downloaded from the TrustLogin SAML app configuration page, this certificate must be prepared by you.
    Note: For details, please contact your representative at Oro Corporation.

    Certificate password The password required to use the certificate

    06.png

  3. Click the "Configure" button in the "IdP-Side (Authentication Server-Side) Information" section, configure the authentication server settings screen as follows, and save by clicking the "Update" button.
    IdP information input method Select "Upload metadata file"
    IdP metadata file Upload the metadata downloaded from TrustLogin by drag-and-drop or by selecting the file
    Single logout Turn the checkbox OFF

    07.png
    08.png

  4. Click the "Configure" button in "ID Federation Details," configure the ID federation detail settings screen as follows, and save by clicking the "Update" button.
    ID federation method ZAC attribute
    ID federation field NameId
    Field value format Email Address
    Target ZAC attribute Employee Email

    11_1.png
    11.png

  5. Make a note of the "Entity ID," "Assertion Consumer Service Url," and "Single Logout Url" values in the "SP-Side (ZAC-Side) Information" section.
    Note: If you are creating a SAML app for external connections, switch to the external connection tab to obtain this information.
    12.png

  6. Click "Enable" to activate SAML.
    13.png

Now return to the TrustLogin Admin Page.

Configuring the TrustLogin Admin Page (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from ZAC
    ACS URL for the service The "Assertion Consumer Service Url" obtained from ZAC
    Logout URL The "Single Logout Url" obtained from ZAC
    Note: Single logout is planned to be added as a future feature, but it is not yet implemented and does not currently work

    14.png

  2. Save by clicking the "Register" button.

Configuring TrustLogin Users

① When a user adds the app from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "ZAC (SAML)" and click the "Next" button at the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "ZAC (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

When Using the External Connection Option

If you are using the external connection option and external connection users will also use SAML, repeat the steps above to register separate configurations for the standard (internal) connection and the external connection in both ZAC and TrustLogin.

15.png

16.png

How to Configure SAML Authentication for ZAC

Item

Details

Prerequisites

  • Prior configuration in ZAC is required.

  • The email address set in the employee information in ZAC must match the email address used in TrustLogin.

  • You will need to prepare the certificate used by the authentication server for verification.
  • Please have an administrator with access to the internal network perform the external authentication configuration.
  • For the latest configuration steps, please refer to the manual provided by ZAC.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, click here

SP-side configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "ZAC (SAML)."
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

Now, switch to the configuration on the ZAC side.
Do not click the "Register" button yet — open ZAC in a separate window.

Configuring ZAC

  1. From the admin screen menu, open "Accounting/Administration > Master > External Authentication Master" and click the "New Registration" button.
    04.png
    05.png

  2. Configure each item as follows and save by clicking the "Register" button.
    Code Any string
    Name Any string (this becomes the button name displayed on the login page)
    Authentication method Select "SAML2"
    Certificate

    Upload the certificate file
    Note: This is the certificate used by the authentication server to verify that requests to the authentication server come from your ZAC.
    Note: Unlike the certificate downloaded from the TrustLogin SAML app configuration page, this certificate must be prepared by you.
    Note: For details, please contact your representative at Oro Corporation.

    Certificate password The password required to use the certificate

    06.png

  3. Click the "Configure" button in the "IdP-Side (Authentication Server-Side) Information" section, configure the authentication server settings screen as follows, and save by clicking the "Update" button.
    IdP information input method Select "Upload metadata file"
    IdP metadata file Upload the metadata downloaded from TrustLogin by drag-and-drop or by selecting the file
    Single logout Turn the checkbox OFF

    07.png
    08.png

  4. Click the "Configure" button in "ID Federation Details," configure the ID federation detail settings screen as follows, and save by clicking the "Update" button.
    ID federation method ZAC attribute
    ID federation field NameId
    Field value format Email Address
    Target ZAC attribute Employee Email

    11_1.png
    11.png

  5. Make a note of the "Entity ID," "Assertion Consumer Service Url," and "Single Logout Url" values in the "SP-Side (ZAC-Side) Information" section.
    Note: If you are creating a SAML app for external connections, switch to the external connection tab to obtain this information.
    12.png

  6. Click "Enable" to activate SAML.
    13.png

Now return to the TrustLogin Admin Page.

Configuring the TrustLogin Admin Page (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from ZAC
    ACS URL for the service The "Assertion Consumer Service Url" obtained from ZAC
    Logout URL The "Single Logout Url" obtained from ZAC
    Note: Single logout is planned to be added as a future feature, but it is not yet implemented and does not currently work

    14.png

  2. Save by clicking the "Register" button.

Configuring TrustLogin Users

① When a user adds the app from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "ZAC (SAML)" and click the "Next" button at the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "ZAC (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

When Using the External Connection Option

If you are using the external connection option and external connection users will also use SAML, repeat the steps above to register separate configurations for the standard (internal) connection and the external connection in both ZAC and TrustLogin.

15.png

16.png