How to Configure SAML Authentication for WowTalk

Item

Content

Prerequisites

  • Prior configuration is required in WowTalk.

  • The WowTalk member's ID and the TrustLogin email address must match.

  • For the latest configuration procedure, please refer to the manual provided by WowTalk.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning(account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App (※)

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for everyone (SAML authentication only)

Other: Enabled for everyone (both SAML authentication and password authentication are possible)

Notes

(※) If you are using client authentication, SSO is not possible on PC - Desktop App (Windows legacy PC version / Mac β version).

Table of Contents:

Configuring the TrustLogin Admin Page

Configuring WowTalk

Configuring TrustLogin Users

How to Log In

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "WowTalk (SAML)".
    WowTalk01.png

  3. Note the "Identity Provider URL" value under "Identity Provider Information," then download the certificate from the "Get Certificate" button.03.png

  4. Save by clicking the "Register" button.

  5. [Converting the certificate format]
    Convert the extension of the downloaded certificate to ".cer".

Configuring WowTalk

  1. Log in to the WowTalk admin site and open "External Service Integration > SSO Integration Settings".
    Turn on "Use SAML Authentication," configure the settings as follows, and save by clicking "Set".
    Note: If "SSO Integration Settings" is not displayed, please contact Kingsoft Corporation.
    Identity Provider Select "GMO Trust Login"
    Identity Provider's SSO Endpoint URL The "Identity Provider URL" you noted from TrustLogin
    Identity Provider's Certificate Upload the certificate (converted to .cer) that you obtained from TrustLogin

    04.png

  2. To perform SAML authentication, the member's ID and the TrustLogin email address must match.
    Set the TrustLogin email address as the "ID" in the member information.
    05.png

Configuring TrustLogin Users

① When a user adds the app from My Page

Note: The administrator must configure the SAML app in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "WowTalk (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "WowTalk (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In

① Logging in with "WowTalk (SAML)" (Browser)

Running "WowTalk (SAML)" from My Page or the browser extension takes you to the WowTalk external integration authentication login screen. After entering your "Corporate ID" and "ID," click "Login" to complete the login.
WowTalk03.png

② Using the helper app (PC browser only)

A helper app that can automatically enter your "Corporate ID" and "ID" is also available.
Search for it on the app search screen and register "[SAML Helper] WowTalk" to use it.
Note: The helper app can only be used in a PC browser.
WowTalk02.png

Logging in with the smartphone native app

Enter only your "Corporate ID" and "Personal ID," then click the "External Integration Authentication Account Login" button. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
06.png

Logging in with the desktop app (Windows new PC version)

  1. Click "Log in with External Integration Authentication Account".
    07.png

  2. Enter your "Corporate ID" and "User ID," check "Use external browser for authentication," and log in. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
    08.png

Logging in with the desktop app (Windows legacy PC version)

  1. Click "External Integration Authentication Account Login".
    09.png

  2. Enter your "Corporate ID" and "User ID" and log in. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
    10.png

Logging in with the desktop app (Mac β version)

  1. Click "Log in with Active Directory Account".
    11.png

  2. Enter your "Corporate ID" and "User ID" and log in. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
    12.png

How to Configure SAML Authentication for WowTalk

Item

Content

Prerequisites

  • Prior configuration is required in WowTalk.

  • The WowTalk member's ID and the TrustLogin email address must match.

  • For the latest configuration procedure, please refer to the manual provided by WowTalk.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning(account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App (※)

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for everyone (SAML authentication only)

Other: Enabled for everyone (both SAML authentication and password authentication are possible)

Notes

(※) If you are using client authentication, SSO is not possible on PC - Desktop App (Windows legacy PC version / Mac β version).

Table of Contents:

Configuring the TrustLogin Admin Page

Configuring WowTalk

Configuring TrustLogin Users

How to Log In

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "WowTalk (SAML)".
    WowTalk01.png

  3. Note the "Identity Provider URL" value under "Identity Provider Information," then download the certificate from the "Get Certificate" button.03.png

  4. Save by clicking the "Register" button.

  5. [Converting the certificate format]
    Convert the extension of the downloaded certificate to ".cer".

Configuring WowTalk

  1. Log in to the WowTalk admin site and open "External Service Integration > SSO Integration Settings".
    Turn on "Use SAML Authentication," configure the settings as follows, and save by clicking "Set".
    Note: If "SSO Integration Settings" is not displayed, please contact Kingsoft Corporation.
    Identity Provider Select "GMO Trust Login"
    Identity Provider's SSO Endpoint URL The "Identity Provider URL" you noted from TrustLogin
    Identity Provider's Certificate Upload the certificate (converted to .cer) that you obtained from TrustLogin

    04.png

  2. To perform SAML authentication, the member's ID and the TrustLogin email address must match.
    Set the TrustLogin email address as the "ID" in the member information.
    05.png

Configuring TrustLogin Users

① When a user adds the app from My Page

Note: The administrator must configure the SAML app in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "WowTalk (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "WowTalk (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In

① Logging in with "WowTalk (SAML)" (Browser)

Running "WowTalk (SAML)" from My Page or the browser extension takes you to the WowTalk external integration authentication login screen. After entering your "Corporate ID" and "ID," click "Login" to complete the login.
WowTalk03.png

② Using the helper app (PC browser only)

A helper app that can automatically enter your "Corporate ID" and "ID" is also available.
Search for it on the app search screen and register "[SAML Helper] WowTalk" to use it.
Note: The helper app can only be used in a PC browser.
WowTalk02.png

Logging in with the smartphone native app

Enter only your "Corporate ID" and "Personal ID," then click the "External Integration Authentication Account Login" button. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
06.png

Logging in with the desktop app (Windows new PC version)

  1. Click "Log in with External Integration Authentication Account".
    07.png

  2. Enter your "Corporate ID" and "User ID," check "Use external browser for authentication," and log in. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
    08.png

Logging in with the desktop app (Windows legacy PC version)

  1. Click "External Integration Authentication Account Login".
    09.png

  2. Enter your "Corporate ID" and "User ID" and log in. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
    10.png

Logging in with the desktop app (Mac β version)

  1. Click "Log in with Active Directory Account".
    11.png

  2. Enter your "Corporate ID" and "User ID" and log in. You will be taken to the TrustLogin authentication screen, and once authenticated, login to WowTalk is complete.
    12.png