How to Configure SAML Authentication for JUST.DB

Item

Details

Pre-check

  • Prior setup is required in JUST.DB.

  • You must create an account in JUST.DB using the same email address as TrustLogin.

  • Configuring SAML in JUST.DB also enables SSO integration with JUST.SFA.
  • Please refer to the manual provided by JUST.DB for the latest setup instructions.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request the SP to configure it

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "JUST.DB (SAML)".
    JUST.DB.png

  3. Note down the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03 (1).png

Now, let's move on to the settings on the JUST.DB side.
Do not click the "Register" button yet — open JUST.DB in a separate window.

JUST.DB Settings

  1. Log in to JUST.DB and open the "Operation Management Screen".
    JUST.DB02.png

  2. Open "Single Sign-On Settings", configure each item as follows, and click "Save Settings".
    Enable SAML Authentication Check the box
    Restrict to Single Sign-On

    Configure according to your operations

    Note: Checking this box restricts login to SSO only, and password login will no longer be available. We recommend checking this box only after SAML authentication has been confirmed to work successfully.

    Identity Provider Entity ID The "Issuer / Entity ID" you noted down from TrustLogin
    Identity Provider Single Sign-On URL The "IdP URL" you noted down from TrustLogin
    Identity Provider Single Logout URL

    https://portal.trustlogin.com/

    Note: Single Logout is planned as a future feature but is not yet implemented and does not currently function.
    Identity Provider Signing Certificate Upload the "Certificate" you noted down from TrustLogin using the "Browse" button
    Signature Settings Check the box
    User Identification Select "Email Address"
    Download Service Provider Metadata Download it and keep it on hand
    Behavior When Login Is Required

    Configure according to your operations

    Note: Selecting "Log in with Single Sign-On" means the login screen will no longer be displayed during SSO login.

    Behavior When Login Is Required (Mobile) Configure according to your operations

    JUST.DB03.png

  3. Open "User Management", select the users for whom you want to enable Single Sign-On, check "Single Sign-On" under "Authentication Type", and click "Save".
    JUST.DB04.png

Now return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" from JUST.DB
    Metadata Upload the "Service Provider Metadata" downloaded from JUST.DB

    JUST.DB05.png

  2. Click "Register" to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "JUST.DB (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. Enter a new value if you want to change the "Display Name", then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the "JUST.DB (SAML)" app from the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for JUST.DB

Item

Details

Pre-check

  • Prior setup is required in JUST.DB.

  • You must create an account in JUST.DB using the same email address as TrustLogin.

  • Configuring SAML in JUST.DB also enables SSO integration with JUST.SFA.
  • Please refer to the manual provided by JUST.DB for the latest setup instructions.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request the SP to configure it

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "JUST.DB (SAML)".
    JUST.DB.png

  3. Note down the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03 (1).png

Now, let's move on to the settings on the JUST.DB side.
Do not click the "Register" button yet — open JUST.DB in a separate window.

JUST.DB Settings

  1. Log in to JUST.DB and open the "Operation Management Screen".
    JUST.DB02.png

  2. Open "Single Sign-On Settings", configure each item as follows, and click "Save Settings".
    Enable SAML Authentication Check the box
    Restrict to Single Sign-On

    Configure according to your operations

    Note: Checking this box restricts login to SSO only, and password login will no longer be available. We recommend checking this box only after SAML authentication has been confirmed to work successfully.

    Identity Provider Entity ID The "Issuer / Entity ID" you noted down from TrustLogin
    Identity Provider Single Sign-On URL The "IdP URL" you noted down from TrustLogin
    Identity Provider Single Logout URL

    https://portal.trustlogin.com/

    Note: Single Logout is planned as a future feature but is not yet implemented and does not currently function.
    Identity Provider Signing Certificate Upload the "Certificate" you noted down from TrustLogin using the "Browse" button
    Signature Settings Check the box
    User Identification Select "Email Address"
    Download Service Provider Metadata Download it and keep it on hand
    Behavior When Login Is Required

    Configure according to your operations

    Note: Selecting "Log in with Single Sign-On" means the login screen will no longer be displayed during SSO login.

    Behavior When Login Is Required (Mobile) Configure according to your operations

    JUST.DB03.png

  3. Open "User Management", select the users for whom you want to enable Single Sign-On, check "Single Sign-On" under "Authentication Type", and click "Save".
    JUST.DB04.png

Now return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" from JUST.DB
    Metadata Upload the "Service Provider Metadata" downloaded from JUST.DB

    JUST.DB05.png

  2. Click "Register" to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "JUST.DB (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. Enter a new value if you want to change the "Display Name", then click the "Register" button.

② When an administrator adds a member

  1. Search for and click the "JUST.DB (SAML)" app from the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.