How to Configure SAML Authentication for One人事

Item

Details

Prior Confirmation

  • Prior configuration in One人事 is required.

  • You must create an account in One人事 using the same email address as TrustLogin.

  • For the latest setup instructions, please check the manual provided by One人事.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "One人事 (SAML)".
    One人事07.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring the One人事 side.
Do not click the "Register" button yet; open One人事 in a separate window.

One人事 Settings

  1. From the One人事 Talent Management top screen, open "Setup > Login Settings".
    One人事01.png

  2. Open the "SAML Settings" tab and click "Create".
    One人事02.png

  3. On the SAML creation screen, configure the settings as follows, and click "Create".
    Display Name Any name of your choice
    Icon Upload any image of your choice

    One人事03.png

  4. Use the copy button to note down the "SSO URL" and "Audience URI". Click the edit button next to the display name.
    One人事04.png

  5. On the SAML edit screen, configure the settings as follows, and save the settings using the "Save" button.
    Usage Status On
    Identity Provider Single Sign-On URL The "Identity Provider URL" you noted down from TrustLogin
    Identity Provider Issuer The "Issuer / Entity ID" you noted down from TrustLogin
    X.509 Certificate Paste the contents of the "Certificate" you noted down from TrustLogin

    One人事06.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Audience URI" you noted down from One人事
    ACS URL to Service The "SSO URL" you noted down from One人事
    One人事05.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "One人事 (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "One人事 (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for One人事

Item

Details

Prior Confirmation

  • Prior configuration in One人事 is required.

  • You must create an account in One人事 using the same email address as TrustLogin.

  • For the latest setup instructions, please check the manual provided by One人事.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "One人事 (SAML)".
    One人事07.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring the One人事 side.
Do not click the "Register" button yet; open One人事 in a separate window.

One人事 Settings

  1. From the One人事 Talent Management top screen, open "Setup > Login Settings".
    One人事01.png

  2. Open the "SAML Settings" tab and click "Create".
    One人事02.png

  3. On the SAML creation screen, configure the settings as follows, and click "Create".
    Display Name Any name of your choice
    Icon Upload any image of your choice

    One人事03.png

  4. Use the copy button to note down the "SSO URL" and "Audience URI". Click the edit button next to the display name.
    One人事04.png

  5. On the SAML edit screen, configure the settings as follows, and save the settings using the "Save" button.
    Usage Status On
    Identity Provider Single Sign-On URL The "Identity Provider URL" you noted down from TrustLogin
    Identity Provider Issuer The "Issuer / Entity ID" you noted down from TrustLogin
    X.509 Certificate Paste the contents of the "Certificate" you noted down from TrustLogin

    One人事06.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Audience URI" you noted down from One人事
    ACS URL to Service The "SSO URL" you noted down from One人事
    One人事05.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "One人事 (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "One人事 (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.