learningBOX SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in learningBOX is required.

  • The user's "last name" and "first name" are synced only when the account is first created.

  • The login ID is created from the portion of the email address before the @.

  • Please refer to the manual provided by learningBOX for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "learningBOX (SAML)".
    learningBOX04.png

  3. Note down the values of "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring learningBOX.
Do not click the "Register" button yet — open learningBOX in a separate window.

learningBOX Settings

  1. Log in as a user with access permissions to the settings page, and open "Side Menu > System Settings > Site Customizer > Basic Settings".learningBOX14.png


  2. Open "External System Integration > Use SAML > Detailed Settings" and configure as follows.
    Automatically register account upon successful SAML authentication On
    Include RequestedAuthnContext attribute On
    Issuer URL(IdP Entity ID) The "Issuer / Entity ID" noted down from TrustLogin
    HTTP-POST URL The "Identity Provider URL" noted down from TrustLogin
    X509Certificate Paste the contents of the "Certificate" noted down from TrustLogin

    learningBOX13.png

  3. Scroll down the screen and select "Name > Add".
    learningBOX09.png

  4. Select "surname: {urn:oid:2.5.4.4}" from the dropdown and add it.
    learningBOX10.png

  5. Click "Name > Add" again, then select "givenName: {urn:oid:2.5.4.42}" from the dropdown and add it.
    learningBOX11.png

  6. Confirm that the selected values are populated in the Name fields, and save the settings by clicking the "Save" button.
    learningBOX12.png

  7. Open "SP (learningBOX) Configuration Information" and note down the "learningBOX Entity ID" and "learningBOX ACS URL".
    Note: The "learningBOX Login URL" is the SP-Initiated URL. Note it down if needed.
      SP-Initiated login is also available from the learningBOX login screen.
    learningBOX05.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "learningBOX Entity ID" noted down from learningBOX
    ACS URL to Service The "learningBOX ACS URL" noted down from learningBOX

    learningBOX06.png


  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "learningBOX (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

②When an administrator adds members

  1. Search for and click the "learningBOX (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

learningBOX SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in learningBOX is required.

  • The user's "last name" and "first name" are synced only when the account is first created.

  • The login ID is created from the portion of the email address before the @.

  • Please refer to the manual provided by learningBOX for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "learningBOX (SAML)".
    learningBOX04.png

  3. Note down the values of "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring learningBOX.
Do not click the "Register" button yet — open learningBOX in a separate window.

learningBOX Settings

  1. Log in as a user with access permissions to the settings page, and open "Side Menu > System Settings > Site Customizer > Basic Settings".learningBOX14.png


  2. Open "External System Integration > Use SAML > Detailed Settings" and configure as follows.
    Automatically register account upon successful SAML authentication On
    Include RequestedAuthnContext attribute On
    Issuer URL(IdP Entity ID) The "Issuer / Entity ID" noted down from TrustLogin
    HTTP-POST URL The "Identity Provider URL" noted down from TrustLogin
    X509Certificate Paste the contents of the "Certificate" noted down from TrustLogin

    learningBOX13.png

  3. Scroll down the screen and select "Name > Add".
    learningBOX09.png

  4. Select "surname: {urn:oid:2.5.4.4}" from the dropdown and add it.
    learningBOX10.png

  5. Click "Name > Add" again, then select "givenName: {urn:oid:2.5.4.42}" from the dropdown and add it.
    learningBOX11.png

  6. Confirm that the selected values are populated in the Name fields, and save the settings by clicking the "Save" button.
    learningBOX12.png

  7. Open "SP (learningBOX) Configuration Information" and note down the "learningBOX Entity ID" and "learningBOX ACS URL".
    Note: The "learningBOX Login URL" is the SP-Initiated URL. Note it down if needed.
      SP-Initiated login is also available from the learningBOX login screen.
    learningBOX05.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "learningBOX Entity ID" noted down from learningBOX
    ACS URL to Service The "learningBOX ACS URL" noted down from learningBOX

    learningBOX06.png


  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "learningBOX (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

②When an administrator adds members

  1. Search for and click the "learningBOX (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.