|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
|
Email address |
| 〇 |
Custom attribute Note: For instructions on how to configure a custom attribute, see here |
|
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning supported (account management possible in TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Preparation
Add a Custom Attribute to User Information
Add the Smart Session "Member ID" information as a custom attribute in the TrustLogin member information.
Note: This is not necessary if the "Smart Session Member ID" matches the "email address registered in TrustLogin". Please proceed to the next step.
[Smart Session Member Management Screen]
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure a custom attribute. The custom attribute name can be anything you like.
Custom Attribute Setup (Individual Registration)
Custom Attribute Setup (Bulk Registration)
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Smart Session (SAML)".
- Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate by clicking the "Get Certificate" button.
- Convert the downloaded certificate's file extension to ".pem".
Now, switch to configuring Smart Session.
Do not click the "Register" button yet — open Smart Session in a separate window.
Smart Session Settings
- Open "System Administration > SAML Authentication Settings".
- Configure each item as follows, and finally save by clicking the "Apply" button.
SAML Authentication Select "Use" Identifier (Entity ID) (SP Setting) Copy and note it down Response URL (ACS URL) Copy and note it down Identifier (Entity ID) (IdP Setting) The "Issuer/Entity ID" obtained from TrustLogin Login URL (SSO URL) The "Identity Provider URL" obtained from TrustLogin Token Signing Certificate Upload the "certificate" obtained from TrustLogin, converted to PEM format, using the "Choose File" button Sign Response Turn the checkbox OFF Sign Assertion Turn the checkbox ON IdP Initiated SSO Do not allow
Click the "Apply" button on the confirmation message.
- For registered members to use SAML integration, you must reset their password in the member management screen, leaving the password field blank when resetting.
When registering a new user, leave the password field blank when registering.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Login URL The customer's login URL to redirect to after clicking the SAML app
In Smart Session, SAML authentication can be performed from the following login screens.
・Management Tool (eDocManager)
・Web ClientEntity ID The "Identifier (Entity ID)" obtained from Smart Session Name ID Value "Custom Attribute > the custom attribute name you configured"
Note: If the "Smart Session Member ID" matches the "TrustLogin email address", set "Member > email"ACS URL to Service The "Response URL (ACS URL)" obtained from Smart Session
- Click the "Register" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Smart Session (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an administrator adds members
- Search for and click the "Smart Session (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.