How to Configure SAML Authentication for Smart Session

Item

Details

Prior Confirmation

  • Prior configuration in Smart Session is required.

  • For the latest setup instructions, please check the manual provided by Smart Session.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Preparation

Add a Custom Attribute to User Information

Add the Smart Session "Member ID" information as a custom attribute in the TrustLogin member information.
Note: This is not necessary if the "Smart Session Member ID" matches the "email address registered in TrustLogin". Please proceed to the next step.

[Smart Session Member Management Screen]
00_1.png

[TrustLogin Custom Attribute Configuration Example]
00_2.png

Please refer to the following pages for instructions on how to configure a custom attribute. The custom attribute name can be anything you like.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Smart Session (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate by clicking the "Get Certificate" button.
    03.png

  4. Convert the downloaded certificate's file extension to ".pem".

Now, switch to configuring Smart Session.
Do not click the "Register" button yet — open Smart Session in a separate window.

Smart Session Settings

  1. Open "System Administration > SAML Authentication Settings".
    04.png

  2. Configure each item as follows, and finally save by clicking the "Apply" button.
    SAML Authentication Select "Use"
    Identifier (Entity ID) (SP Setting) Copy and note it down
    Response URL (ACS URL) Copy and note it down
    Identifier (Entity ID) (IdP Setting) The "Issuer/Entity ID" obtained from TrustLogin
    Login URL (SSO URL) The "Identity Provider URL" obtained from TrustLogin
    Token Signing Certificate Upload the "certificate" obtained from TrustLogin, converted to PEM format, using the "Choose File" button
    Sign Response Turn the checkbox OFF
    Sign Assertion Turn the checkbox ON
    IdP Initiated SSO Do not allow

    05.png

    Click the "Apply" button on the confirmation message.
    06.png

  3. For registered members to use SAML integration, you must reset their password in the member management screen, leaving the password field blank when resetting.

    When registering a new user, leave the password field blank when registering.

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The customer's login URL to redirect to after clicking the SAML app
    In Smart Session, SAML authentication can be performed from the following login screens.

    ・Management Tool (eDocManager)
    ・Web Client

    Entity ID The "Identifier (Entity ID)" obtained from Smart Session
    Name ID Value "Custom Attribute > the custom attribute name you configured"

    Note: If the "Smart Session Member ID" matches the "TrustLogin email address", set "Member > email"
    ACS URL to Service The "Response URL (ACS URL)" obtained from Smart Session

    07.png

  2. Click the "Register" button to save.


TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Smart Session (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Smart Session (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Smart Session

Item

Details

Prior Confirmation

  • Prior configuration in Smart Session is required.

  • For the latest setup instructions, please check the manual provided by Smart Session.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Preparation

Add a Custom Attribute to User Information

Add the Smart Session "Member ID" information as a custom attribute in the TrustLogin member information.
Note: This is not necessary if the "Smart Session Member ID" matches the "email address registered in TrustLogin". Please proceed to the next step.

[Smart Session Member Management Screen]
00_1.png

[TrustLogin Custom Attribute Configuration Example]
00_2.png

Please refer to the following pages for instructions on how to configure a custom attribute. The custom attribute name can be anything you like.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Smart Session (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate by clicking the "Get Certificate" button.
    03.png

  4. Convert the downloaded certificate's file extension to ".pem".

Now, switch to configuring Smart Session.
Do not click the "Register" button yet — open Smart Session in a separate window.

Smart Session Settings

  1. Open "System Administration > SAML Authentication Settings".
    04.png

  2. Configure each item as follows, and finally save by clicking the "Apply" button.
    SAML Authentication Select "Use"
    Identifier (Entity ID) (SP Setting) Copy and note it down
    Response URL (ACS URL) Copy and note it down
    Identifier (Entity ID) (IdP Setting) The "Issuer/Entity ID" obtained from TrustLogin
    Login URL (SSO URL) The "Identity Provider URL" obtained from TrustLogin
    Token Signing Certificate Upload the "certificate" obtained from TrustLogin, converted to PEM format, using the "Choose File" button
    Sign Response Turn the checkbox OFF
    Sign Assertion Turn the checkbox ON
    IdP Initiated SSO Do not allow

    05.png

    Click the "Apply" button on the confirmation message.
    06.png

  3. For registered members to use SAML integration, you must reset their password in the member management screen, leaving the password field blank when resetting.

    When registering a new user, leave the password field blank when registering.

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The customer's login URL to redirect to after clicking the SAML app
    In Smart Session, SAML authentication can be performed from the following login screens.

    ・Management Tool (eDocManager)
    ・Web Client

    Entity ID The "Identifier (Entity ID)" obtained from Smart Session
    Name ID Value "Custom Attribute > the custom attribute name you configured"

    Note: If the "Smart Session Member ID" matches the "TrustLogin email address", set "Member > email"
    ACS URL to Service The "Response URL (ACS URL)" obtained from Smart Session

    07.png

  2. Click the "Register" button to save.


TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Smart Session (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Smart Session (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.