How to Configure SAML Authentication for DeployGate

Item

Details

Pre-check

  • Prior configuration in DeployGate is required.

  • You need to create a DeployGate account using the same email address as your TrustLogin account in advance.

  • Once you link your SAML authentication credentials, password login will no longer be available. Only administrators can still log in with a password by resetting and updating their password after configuring SAML authentication.
  • For the latest setup instructions, please refer to the manual provided by DeployGate.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: TrustLogin does not support IdP-Initiated SSO.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Add App" button in the upper right of the screen.
    01.png

  2. Search on the "Add Enterprise App" screen and select "DeployGate (SAML)".
    deploygate01.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Change the extension of the downloaded certificate to ".cer".

Now, let's move on to the settings on the DeployGate side.
Without clicking the "Register" button, please open DeployGate in a separate window.

DeployGate Settings

  1. Log in with an account that has administrator privileges, and select your company name from the profile icon in the upper right.
    deploygate06.png

  2. Select "Admin Console > Settings".deploygate07.png

  3. Under "Authentication > SSO Authentication Settings > SAML2.0 Authentication", click the "Enable SAML Authentication" button.
    deploygate.png

  4. Configure the "Your IdP Settings" section as follows and click the "Save" button.
    IdP Name (required) Any name
    Entity ID (required) The "Issuer/Entity ID" obtained from TrustLogin
    SSO (Single Sign-On) URL (required) The "Identity Provider URL" obtained from TrustLogin
    Certificate

    The "Certificate" obtained from TrustLogin

    Note: The one with the extension changed to ".cer"


    deploygate02.png

  5. Note the "Entity ID" and "SP-initiated SSO URL" from "DeployGate Settings".
    deploygate09.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "SP-initiated SSO URL" obtained from DeployGate
    Entity ID The "Entity ID" obtained from DeployGate

    kickflow.png

  2. Click the "Register" button to save.

  3. Add a user to test the connection to the "DeployGate (SAML)" app.

DeployGate Settings (Continued)

  1. Return to "DeployGate Settings" and click the "Enable SAML Authentication" button.
    deploygate08.png

  2. Enter your password in DeployGate, and once SAML authentication succeeds, you will be redirected to a screen saying "SAML authentication succeeded".
    deploygate03.png

TrustLogin User Settings

① When a user adds it from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "DeployGate (SAML)" on the "Add App" screen and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "DeployGate (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Enabling SAML Authentication

  1. After configuring SAML authentication, when you log in with your email address and password, the account authorization screen shown below will appear on your first login. Linking your credentials on this screen will complete the SAML authentication linkage.

    Note: A link for linking your credentials will also be sent to your registered email address. You can also link your credentials from there.
    Note: Once you perform this operation, you will only be able to log in via SAML authentication, and password login will no longer be available.
    Note: If you do not link your credentials, you can still use the service with password authentication for a 14-day transition period.
    deploygate010.png

How to Configure SAML Authentication for DeployGate

Item

Details

Pre-check

  • Prior configuration in DeployGate is required.

  • You need to create a DeployGate account using the same email address as your TrustLogin account in advance.

  • Once you link your SAML authentication credentials, password login will no longer be available. Only administrators can still log in with a password by resetting and updating their password after configuring SAML authentication.
  • For the latest setup instructions, please refer to the manual provided by DeployGate.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: TrustLogin does not support IdP-Initiated SSO.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Add App" button in the upper right of the screen.
    01.png

  2. Search on the "Add Enterprise App" screen and select "DeployGate (SAML)".
    deploygate01.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Change the extension of the downloaded certificate to ".cer".

Now, let's move on to the settings on the DeployGate side.
Without clicking the "Register" button, please open DeployGate in a separate window.

DeployGate Settings

  1. Log in with an account that has administrator privileges, and select your company name from the profile icon in the upper right.
    deploygate06.png

  2. Select "Admin Console > Settings".deploygate07.png

  3. Under "Authentication > SSO Authentication Settings > SAML2.0 Authentication", click the "Enable SAML Authentication" button.
    deploygate.png

  4. Configure the "Your IdP Settings" section as follows and click the "Save" button.
    IdP Name (required) Any name
    Entity ID (required) The "Issuer/Entity ID" obtained from TrustLogin
    SSO (Single Sign-On) URL (required) The "Identity Provider URL" obtained from TrustLogin
    Certificate

    The "Certificate" obtained from TrustLogin

    Note: The one with the extension changed to ".cer"


    deploygate02.png

  5. Note the "Entity ID" and "SP-initiated SSO URL" from "DeployGate Settings".
    deploygate09.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "SP-initiated SSO URL" obtained from DeployGate
    Entity ID The "Entity ID" obtained from DeployGate

    kickflow.png

  2. Click the "Register" button to save.

  3. Add a user to test the connection to the "DeployGate (SAML)" app.

DeployGate Settings (Continued)

  1. Return to "DeployGate Settings" and click the "Enable SAML Authentication" button.
    deploygate08.png

  2. Enter your password in DeployGate, and once SAML authentication succeeds, you will be redirected to a screen saying "SAML authentication succeeded".
    deploygate03.png

TrustLogin User Settings

① When a user adds it from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "DeployGate (SAML)" on the "Add App" screen and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "DeployGate (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Enabling SAML Authentication

  1. After configuring SAML authentication, when you log in with your email address and password, the account authorization screen shown below will appear on your first login. Linking your credentials on this screen will complete the SAML authentication linkage.

    Note: A link for linking your credentials will also be sent to your registered email address. You can also link your credentials from there.
    Note: Once you perform this operation, you will only be able to log in via SAML authentication, and password login will no longer be available.
    Note: If you do not link your credentials, you can still use the service with password authentication for a 14-day transition period.
    deploygate010.png