|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side settings |
〇 |
Configured by the administrator |
|
Request the SP to configure it |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; users cannot be deleted) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified device compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "JUST.DB (SAML)".
- Note down the "IdP URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, let's move on to the settings on the JUST.DB side.
Do not click the "Register" button yet — open JUST.DB in a separate window.
JUST.DB Settings
-
Log in to JUST.DB and open the "Operation Management Screen".
- Open "Single Sign-On Settings", configure each item as follows, and click "Save Settings".
Enable SAML Authentication Check the box Restrict to Single Sign-On Configure according to your operations
Note: Checking this box restricts login to SSO only, and password login will no longer be available. We recommend checking this box only after SAML authentication has been confirmed to work successfully.
Identity Provider Entity ID The "Issuer / Entity ID" you noted down from TrustLogin Identity Provider Single Sign-On URL The "IdP URL" you noted down from TrustLogin Identity Provider Single Logout URL https://portal.trustlogin.com/
Note: Single Logout is planned as a future feature but is not yet implemented and does not currently function.Identity Provider Signing Certificate Upload the "Certificate" you noted down from TrustLogin using the "Browse" button Signature Settings Check the box User Identification Select "Email Address" Download Service Provider Metadata Download it and keep it on hand Behavior When Login Is Required Configure according to your operations
Note: Selecting "Log in with Single Sign-On" means the login screen will no longer be displayed during SSO login.
Behavior When Login Is Required (Mobile) Configure according to your operations
-
Open "User Management", select the users for whom you want to enable Single Sign-On, check "Single Sign-On" under "Authentication Type", and click "Save".
Now return to the TrustLogin Admin Page.
TrustLogin Admin Page Settings (continued)
- Configure "Service Provider Settings" as follows.
Login URL The "Login URL" from JUST.DB Metadata Upload the "Service Provider Metadata" downloaded from JUST.DB
- Click "Register" to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- Select "JUST.DB (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
- Enter a new value if you want to change the "Display Name", then click the "Register" button.
② When an administrator adds a member
- Search for and click the "JUST.DB (SAML)" app from the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.