|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "TOKIUM (SAML)".
- Download the metadata from the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring TOKIUM.
Do not click the "Register" button yet — open TOKIUM in a separate window.
TOKIUM Settings
- After logging in to TOKIUM, open the "System Settings" dropdown and select "Security".
- Enter your "Subdomain" and click "Save" to register the subdomain.
- After registering the subdomain, make a note of the URL displayed in "Login URL".
(You will use this later when configuring TrustLogin.)
- Click "SAML Settings > Create".
- Enter a "Setting Name" and "Description", then click "Create".
Note: You may enter any name or description you like.
- Select the SAML setting name you created in step 5 (in this example, "TrustLogin").
- Make a note of the "Entity ID", "ACS URL", and "Logout URL" under "Service Provider Information". (You will use these later when configuring TrustLogin.)
- Select "SAML Settings > Edit". Click "Choose File", upload the metadata you saved from TrustLogin, and click "Save".
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "Login URL" you noted from TOKIUM Entity ID The "Entity ID" you noted from TOKIUM ACS URL to Service The "ACS URL" you noted from TOKIUM Logout URL The "Logout URL" you noted from TOKIUM
Note: Single logout is planned for a future release, but is not currently implemented and does not function - Save the settings by clicking the "Register" button.
- Add the user who is currently performing the SAML configuration to the "TOKIUM (SAML)" app.
Search for the "TOKIUM (SAML)" app from "Admin Page > App", and add the user via "Add Member".
TOKIUM Settings (Continued)
- Verify that the SAML settings configured so far are working correctly by testing the connection. Return to the SAML settings in TOKIUM, and under "Check SAML Settings", click "Verify Settings".
- If the connection is successful, "SAML connection succeeded" will be displayed.
- After confirming the connection is successful, turn on "Enable SAML Authentication" to activate it.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "TOKIUM (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an Administrator Adds Members
- Search for and click the "TOKIUM (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In
- When you access TrustLogin's My Page or TOKIUM's login URL, the "Setting Name" of the IdP configured in TOKIUM will be displayed. Select the IdP you want to use to log in via SAML, and log in.
SSO Authentication Method for the Native App
TOKIUM supports a native app. If you use the native app, you can log in using the method described below.
- Download and open the TOKIUM native app.
- Select "Other Login Methods".
-
Select "Use Subdomain".
- Enter the subdomain you configured in TOKIUM and click "Next".
- Select "Other Login Methods" again.
- The configured IdP name will be displayed. Select the IdP name you want to use to log in, and log in.