How to Configure SAML Authentication for Ashita no Cloud (Configuration Using Custom Attributes)

 Item

Details

Prior Confirmation

  • Prior configuration in Ashita no Cloud is required.

  • For the latest setup instructions, please check the manual provided by Ashita no Cloud.

Name ID

 

Email address

If you want to use SSO integration with an email address, please see here.

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


Preparation

Add a Custom Attribute to User Information

Add Ashita no Cloud's "Login ID" information as a custom attribute in the TrustLogin member information.

【Ashita no Cloud Account Information Screen】
AshitaNoCloud06.png

【TrustLogin Custom Attribute Configuration Example】
AshitaNoCloud07.png

For how to configure custom attributes, please refer to the pages below. The attribute name of the custom attribute is arbitrary.

Custom Attribute Configuration Method (Individual Registration)

Custom Attribute Configuration Method (Bulk Registration)

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Ashita no Cloud (SAML)".
    AshitaNoCloud01.png


  3. Note the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring the Ashita no Cloud side.
Do not click the "Register" button yet; please open Ashita no Cloud in a separate window.

Ashita no Cloud Settings

  1. Log in with an account that has administrator privileges and select "System Settings>Company Information Settings".
    AshitaNoCloud.png

  2. Scroll down to the bottom of the "Company Information - Edit" screen and click "Edit".

  3. In the "Single Sign-On (SAML 2.0) Settings" section, select "Use", configure the settings as follows, and save by clicking "Update".
    Identity Provider Name Any name of your choice Note: In this example, "TrustLogin" is used.
    Application ID Copy and make a note of it
    Response URL Copy and make a note of it
    Endpoint URL Enter the "Identity Provider URL" you noted from TrustLogin
    Redirect URL After Logout https://portal.trustlogin.com/
    Certificate Copy and paste the contents of the "certificate" you downloaded from TrustLogin
    Allow Normal Login for All Users

    Checking this enables normal login (login using an ID and password).

    If you want to restrict login to SSO only, we recommend unchecking this only after confirming SSO works successfully and notifying users.

    You can also individually select which users are allowed to use normal login.


    AshitaNoCloud02.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Application ID" you noted from Ashita no Cloud
    Value for Name ID Set to "Custom Attribute > the custom attribute name you configured"
    ACS URL to Service The "Response URL" you noted from Ashita no Cloud

    AshitaNoCloud05.png

  2. Save by clicking the "Register" button.

 

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Ashita no Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Ashita no Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

 

 

 

 

 

How to Configure SAML Authentication for Ashita no Cloud (Configuration Using Custom Attributes)

 Item

Details

Prior Confirmation

  • Prior configuration in Ashita no Cloud is required.

  • For the latest setup instructions, please check the manual provided by Ashita no Cloud.

Name ID

 

Email address

If you want to use SSO integration with an email address, please see here.

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


Preparation

Add a Custom Attribute to User Information

Add Ashita no Cloud's "Login ID" information as a custom attribute in the TrustLogin member information.

【Ashita no Cloud Account Information Screen】
AshitaNoCloud06.png

【TrustLogin Custom Attribute Configuration Example】
AshitaNoCloud07.png

For how to configure custom attributes, please refer to the pages below. The attribute name of the custom attribute is arbitrary.

Custom Attribute Configuration Method (Individual Registration)

Custom Attribute Configuration Method (Bulk Registration)

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Ashita no Cloud (SAML)".
    AshitaNoCloud01.png


  3. Note the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring the Ashita no Cloud side.
Do not click the "Register" button yet; please open Ashita no Cloud in a separate window.

Ashita no Cloud Settings

  1. Log in with an account that has administrator privileges and select "System Settings>Company Information Settings".
    AshitaNoCloud.png

  2. Scroll down to the bottom of the "Company Information - Edit" screen and click "Edit".

  3. In the "Single Sign-On (SAML 2.0) Settings" section, select "Use", configure the settings as follows, and save by clicking "Update".
    Identity Provider Name Any name of your choice Note: In this example, "TrustLogin" is used.
    Application ID Copy and make a note of it
    Response URL Copy and make a note of it
    Endpoint URL Enter the "Identity Provider URL" you noted from TrustLogin
    Redirect URL After Logout https://portal.trustlogin.com/
    Certificate Copy and paste the contents of the "certificate" you downloaded from TrustLogin
    Allow Normal Login for All Users

    Checking this enables normal login (login using an ID and password).

    If you want to restrict login to SSO only, we recommend unchecking this only after confirming SSO works successfully and notifying users.

    You can also individually select which users are allowed to use normal login.


    AshitaNoCloud02.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Application ID" you noted from Ashita no Cloud
    Value for Name ID Set to "Custom Attribute > the custom attribute name you configured"
    ACS URL to Service The "Response URL" you noted from Ashita no Cloud

    AshitaNoCloud05.png

  2. Save by clicking the "Register" button.

 

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Ashita no Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Ashita no Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.