|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Provisioning via API supported (account management possible in TrustLogin) |
|
| 〇 |
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
|
|
|
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Company App" screen and select "Sentry (SAML)".
-
Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
- Enter the Sentry Organization ID (Organization Slug) in both the "Entity ID" and "ACS URL to Service" fields under "Service Provider Settings".
Note: You can find the Sentry Organization ID (Organization Slug) under "Organization Settings > Organization Slug" in Sentry. - Save by clicking the "Register" button.
-
Sentry performs a connection check when you configure the settings on its side, so please assign an administrator to the SAML app you created to perform the connection check.
Reference) TrustLogin User Configuration
Sentry Configuration
-
Open "Organization Settings > Auth" and click the "Configure" button for "SAML2".
-
Select the "IdP Data" tab and configure each item as follows.
Save by clicking the "Save Metadata" button.
Entity ID The "Issuer/Entity ID" obtained from TrustLogin Single Sign On URL The "Identity Provider URL" obtained from TrustLogin x509 public certificate The contents of the "Certificate" obtained from TrustLogin
-
Configure each item with the following values and save by clicking the "Save Attributes" button.
IdP User ID http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name User Email http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress First Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname Last Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- A message is displayed when SSO is configured correctly.
- The "Login URL" is the login URL used for SP-Initiated SSO. Make a note of it if needed.
- Scroll down to "General Settings" and configure each item according to your operational needs.
Require SSO Turn this ON if you want to require SAML SSO.
Note: We recommend keeping this OFF until testing and user notification are complete.Enable SCIM Turn this OFF Default Role Specify the role to assign when a user is created.
TrustLogin User Configuration
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Sentry (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
②When an Administrator Adds a Member
- Search for and click the "Sentry (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.