How to Configure SAML Authentication for NEXTa Meishi

Item

Details

Prerequisites

  • Prior configuration in NEXTa Meishi is required.

  • You must create an account in NEXTa Meishi using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by NEXTa Meishi.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The native app has been verified to work with NEXTa Meishi. If you are using client authentication, SSO is not available on the iOS native app or Android native app.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "NEXTa Meishi (SAML)."
    NEXTa Meishi08.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring the NEXTa Meishi side.
Do not click the "Register" button yet — open NEXTa Meishi in a separate window.

NEXTa Meishi Configuration

  1. Log in to NEXTa Meishi, open "More," and click "Admin Settings."
    NEXTa Meishi01.png

  2. Click "User Management."
    NEXTa Meishi02.png

  3. Open "SSO Settings" and configure it as follows.
    Endpoint Copy and note it down
    Entity ID Copy and note it down
    SAML 2.0 Endpoint URL Enter the "IdP URL" noted from TrustLogin
    IdP Name Enter the "Issuer/Entity ID" noted from TrustLogin
    Public Certificate Paste the contents of the "Certificate" noted from TrustLogin

    NEXTa Meishi03.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" noted from NEXTa Meishi
    ACS URL for the Service The "Endpoint" noted from NEXTa Meishi

    NEXTa Meishi09.png

  2. Save by clicking the "Register" button.

  3. Add a user to the "NEXTa Meishi (SAML)" app to perform a connection test.

Return to NEXTa Meishi again.

NEXTa Meishi Admin Page Configuration (Continued)

  1. Return to the "SSO Settings" screen and click "Save Settings and Test."
    NEXTa Meishi10.png

  2. If SAML authentication is successful, the following screen will be displayed.NEXTa Meishi04.png

  3. After confirming that SSO was successful, turn on "Enable SSO." Then click "Open User Management Page."
    NEXTa Meishi05.png

  4. Select the user to apply SSO to, check "Enable SSO" on the edit screen, and click the "Submit" button.
    NEXTa Meishi06.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "NEXTa Meishi (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "NEXTa Meishi (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Login Method

When logging in via SSO, if both "Nexta Meishi" and "Nexta Scheduler" apps are assigned in NEXTa Meishi, a login destination selection screen will be displayed. Select the app you want to log in to and proceed.

Note: This is also displayed in the iOS/Android standard browsers and the iOS/Android TrustLogin mobile app in-app browser.

Note: If only one app is assigned, the selection screen will not be displayed.NEXTa Meishi07.png

How to Configure SAML Authentication for NEXTa Meishi

Item

Details

Prerequisites

  • Prior configuration in NEXTa Meishi is required.

  • You must create an account in NEXTa Meishi using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by NEXTa Meishi.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The native app has been verified to work with NEXTa Meishi. If you are using client authentication, SSO is not available on the iOS native app or Android native app.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "NEXTa Meishi (SAML)."
    NEXTa Meishi08.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring the NEXTa Meishi side.
Do not click the "Register" button yet — open NEXTa Meishi in a separate window.

NEXTa Meishi Configuration

  1. Log in to NEXTa Meishi, open "More," and click "Admin Settings."
    NEXTa Meishi01.png

  2. Click "User Management."
    NEXTa Meishi02.png

  3. Open "SSO Settings" and configure it as follows.
    Endpoint Copy and note it down
    Entity ID Copy and note it down
    SAML 2.0 Endpoint URL Enter the "IdP URL" noted from TrustLogin
    IdP Name Enter the "Issuer/Entity ID" noted from TrustLogin
    Public Certificate Paste the contents of the "Certificate" noted from TrustLogin

    NEXTa Meishi03.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Entity ID" noted from NEXTa Meishi
    ACS URL for the Service The "Endpoint" noted from NEXTa Meishi

    NEXTa Meishi09.png

  2. Save by clicking the "Register" button.

  3. Add a user to the "NEXTa Meishi (SAML)" app to perform a connection test.

Return to NEXTa Meishi again.

NEXTa Meishi Admin Page Configuration (Continued)

  1. Return to the "SSO Settings" screen and click "Save Settings and Test."
    NEXTa Meishi10.png

  2. If SAML authentication is successful, the following screen will be displayed.NEXTa Meishi04.png

  3. After confirming that SSO was successful, turn on "Enable SSO." Then click "Open User Management Page."
    NEXTa Meishi05.png

  4. Select the user to apply SSO to, check "Enable SSO" on the edit screen, and click the "Submit" button.
    NEXTa Meishi06.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "NEXTa Meishi (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "NEXTa Meishi (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

Login Method

When logging in via SSO, if both "Nexta Meishi" and "Nexta Scheduler" apps are assigned in NEXTa Meishi, a login destination selection screen will be displayed. Select the app you want to log in to and proceed.

Note: This is also displayed in the iOS/Android standard browsers and the iOS/Android TrustLogin mobile app in-app browser.

Note: If only one app is assigned, the selection screen will not be displayed.NEXTa Meishi07.png