|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, click here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
ー |
Android - Native app |
|
Configuring the TrustLogin Admin Page
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the upper right of the screen.
- Search on the "Register Corporate App" screen and select "ZAC (SAML)."
- Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
Now, switch to the configuration on the ZAC side.
Do not click the "Register" button yet — open ZAC in a separate window.
Configuring ZAC
- From the admin screen menu, open "Accounting/Administration > Master > External Authentication Master" and click the "New Registration" button.
- Configure each item as follows and save by clicking the "Register" button.
Code Any string Name Any string (this becomes the button name displayed on the login page) Authentication method Select "SAML2" Certificate Upload the certificate file
Note: This is the certificate used by the authentication server to verify that requests to the authentication server come from your ZAC.
Note: Unlike the certificate downloaded from the TrustLogin SAML app configuration page, this certificate must be prepared by you.
Note: For details, please contact your representative at Oro Corporation.Certificate password The password required to use the certificate
- Click the "Configure" button in the "IdP-Side (Authentication Server-Side) Information" section, configure the authentication server settings screen as follows, and save by clicking the "Update" button.
IdP information input method Select "Upload metadata file" IdP metadata file Upload the metadata downloaded from TrustLogin by drag-and-drop or by selecting the file Single logout Turn the checkbox OFF
- Click the "Configure" button in "ID Federation Details," configure the ID federation detail settings screen as follows, and save by clicking the "Update" button.
ID federation method ZAC attribute ID federation field NameId Field value format Email Address Target ZAC attribute Employee Email
-
Make a note of the "Entity ID," "Assertion Consumer Service Url," and "Single Logout Url" values in the "SP-Side (ZAC-Side) Information" section.
Note: If you are creating a SAML app for external connections, switch to the external connection tab to obtain this information.
-
Click "Enable" to activate SAML.
Now return to the TrustLogin Admin Page.
Configuring the TrustLogin Admin Page (Continued)
- Configure the "Service Provider Settings" as follows.
Note: Single logout is planned to be added as a future feature, but it is not yet implemented and does not currently workEntity ID The "Entity ID" obtained from ZAC ACS URL for the service The "Assertion Consumer Service Url" obtained from ZAC Logout URL The "Single Logout Url" obtained from ZAC
- Save by clicking the "Register" button.
Configuring TrustLogin Users
① When a user adds the app from My Page
- On "My Page," click the "Add App" button.
- On the "Register App" screen, select "ZAC (SAML)" and click the "Next" button at the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "ZAC (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.
When Using the External Connection Option
If you are using the external connection option and external connection users will also use SAML, repeat the steps above to register separate configurations for the standard (internal) connection and the external connection in both ZAC and TrustLogin.