How to Configure SAML Authentication for Canbus.

 Item

Details 

Prior Confirmation

  • Prior configuration in Canbus. is required.

  • You must create an account in Canbus. using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Canbus.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts created in each system)
Note: For configuration steps when using provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: If you are using client authentication, SSO is not available for iOS - Native App or Android - Native App.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Canbus. (SAML)".
    02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Convert the extension of the downloaded certificate to ".crt".

  5. In the "Service Provider Settings" section, enter your Canbus. tenant ID in the "Entity ID" and "ACS URL for Service" input fields.
    05.png

  6. Save by clicking the "Register" button.

 

Canbus. Configuration

  1. Log in with an administrator account, open "Admin > System Administration > Authentication", and configure each item as follows.
    Enable login using SAML 2.0 Identity Provider Check the box
    Login Page URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Certificate

    The "Certificate" obtained from TrustLogin, converted

    to Crt format

    Login Button Label (Optional) The label name for the SSO button on the login page

    04.png

  2. Save the configuration by clicking the "Save" button.

 

TrustLogin User Configuration

① When Users Add the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Canbus. (SAML)" and click the "Next" button at the top right of the screen.
  3. Enter a value if you want to change the "Display Name", then click the "Register" button.

② When an Administrator Adds Members

  1. Search for the "Canbus. (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Canbus.

 Item

Details 

Prior Confirmation

  • Prior configuration in Canbus. is required.

  • You must create an account in Canbus. using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Canbus.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts created in each system)
Note: For configuration steps when using provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: If you are using client authentication, SSO is not available for iOS - Native App or Android - Native App.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Canbus. (SAML)".
    02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Convert the extension of the downloaded certificate to ".crt".

  5. In the "Service Provider Settings" section, enter your Canbus. tenant ID in the "Entity ID" and "ACS URL for Service" input fields.
    05.png

  6. Save by clicking the "Register" button.

 

Canbus. Configuration

  1. Log in with an administrator account, open "Admin > System Administration > Authentication", and configure each item as follows.
    Enable login using SAML 2.0 Identity Provider Check the box
    Login Page URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Certificate

    The "Certificate" obtained from TrustLogin, converted

    to Crt format

    Login Button Label (Optional) The label name for the SSO button on the login page

    04.png

  2. Save the configuration by clicking the "Save" button.

 

TrustLogin User Configuration

① When Users Add the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Canbus. (SAML)" and click the "Next" button at the top right of the screen.
  3. Enter a value if you want to change the "Display Name", then click the "Register" button.

② When an Administrator Adds Members

  1. Search for the "Canbus. (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.