|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Settings |
〇 |
Configured by the administrator |
|
Request the SP to configure |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
※ |
IdP-Initiated SSO |
|
|
Verified Devices |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
〇 |
Android - Native App |
|
Note: TrustLogin does not support IdP-Initiated SSO.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Add App" button in the upper right of the screen.
- Search on the "Add Enterprise App" screen and select "DeployGate (SAML)".
- Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Change the extension of the downloaded certificate to ".cer".
Now, let's move on to the settings on the DeployGate side.
Without clicking the "Register" button, please open DeployGate in a separate window.
DeployGate Settings
- Log in with an account that has administrator privileges, and select your company name from the profile icon in the upper right.
- Select "Admin Console > Settings".
- Under "Authentication > SSO Authentication Settings > SAML2.0 Authentication", click the "Enable SAML Authentication" button.
- Configure the "Your IdP Settings" section as follows and click the "Save" button.
IdP Name (required) Any name Entity ID (required) The "Issuer/Entity ID" obtained from TrustLogin SSO (Single Sign-On) URL (required) The "Identity Provider URL" obtained from TrustLogin Certificate The "Certificate" obtained from TrustLogin
Note: The one with the extension changed to ".cer"
- Note the "Entity ID" and "SP-initiated SSO URL" from "DeployGate Settings".
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "SP-initiated SSO URL" obtained from DeployGate Entity ID The "Entity ID" obtained from DeployGate
- Click the "Register" button to save.
- Add a user to test the connection to the "DeployGate (SAML)" app.
DeployGate Settings (Continued)
- Return to "DeployGate Settings" and click the "Enable SAML Authentication" button.
- Enter your password in DeployGate, and once SAML authentication succeeds, you will be redirected to a screen saying "SAML authentication succeeded".
TrustLogin User Settings
① When a user adds it from My Page
- Click the "Add App" button on "My Page".
- Select "DeployGate (SAML)" on the "Add App" screen and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an administrator adds members
- Search for and click the "DeployGate (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Enabling SAML Authentication
- After configuring SAML authentication, when you log in with your email address and password, the account authorization screen shown below will appear on your first login. Linking your credentials on this screen will complete the SAML authentication linkage.
Note: A link for linking your credentials will also be sent to your registered email address. You can also link your credentials from there.
Note: Once you perform this operation, you will only be able to log in via SAML authentication, and password login will no longer be available.
Note: If you do not link your credentials, you can still use the service with password authentication for a 14-day transition period.