|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Basic Information
The information that can be sent to CloudSign via the SAML JIT feature when an account is created is as follows.
| Email address | Required | |
| Company name | Optional | |
| Full name | Optional | If left blank, the part of the linked email address before the "@" will be set as the name in CloudSign |
| Member Group ID | Optional |
Multiple member groups can be linked using comma separation |
-
If linking the full name and Member Group ID is not required
You can configure this using a SAML template.
Please refer to the manual here and proceed with the configuration.
-
If you want to link the full name and Member Group ID
You need to add a custom attribute to the TrustLogin member information.
[TrustLogin Custom Attribute Configuration Example]
Note: The attribute name can be anything you choose.
Note: For the Member Group ID attribute value, set the CloudSign group ID.
You can check the CloudSign group ID on the CloudSign group details screen.
Please refer to the following pages for instructions on how to configure custom attributes.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and "Icon" (optional).
- Download the metadata from the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring CloudSign.
Do not click the "Register" button yet — open the CloudSign admin screen in a separate tab using an account with "SSO Administrator" privileges.
CloudSign Settings
- From the left menu of the admin screen, select "Team > SSO Settings".
- From "Settings > Metadata File Settings > Select File", upload the metadata obtained from TrustLogin.
- Make a note of the "Audience" and "ACS URL" under "Settings > Service Provider Information".
Note: Be sure to keep this screen open and proceed with the next TrustLogin configuration.
If you turn "ON" the "SSO Settings for Each Team" at the bottom of this screen before the TrustLogin configuration is complete, you will no longer be able to log in to the CloudSign admin screen.
Now return to the TrustLogin settings page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Login URL https://www.cloudsign.jp/login Entity ID The "Audience" obtained from CloudSign Name ID Format unspecified ACS URL to Service The "ACS URL" obtained from CloudSign
- Configure "SAML Attribute Settings" as follows.
The first row is required; rows 2-4 are optional and should be configured for any items you want to link.
(*) http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressService Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value Value of (*) Email Value of (*) Member
Member - Email Address
organization Basic organization Member
Member - Company Name
username Basic username Custom Attribute
The attribute name you configured
member_group_ids Basic member_group_ids Custom Attribute
The attribute name you configured
- Save by clicking the "Register" button.
Now return to the CloudSign settings page again.
CloudSign Settings (Enabling SSO)
Turn ON the teams subject to SSO under "SSO Settings for Each Team".
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
②When an administrator adds members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log in to CloudSign
Logging in from CloudSign
- Access the CloudSign login page directly, or click the CloudSign SAML app in TrustLogin to be linked to the CloudSign login page.
Enter your email address and click "Next".
- Click the "Log In" button.
If you enter an email address that does not yet have an account in CloudSign, a new account will be created via the SAML JIT feature.
- If you are already logged in to TrustLogin, you will be logged in to CloudSign.
If you are not logged in to TrustLogin, the TrustLogin login screen will be displayed; after authenticating, you will be logged in to CloudSign.
How to Log in Using the Auxiliary App
When accessing via SAML authentication from the TrustLogin My Page or browser extension, you can register a separate "[For SAML Auxiliary Use] CloudSign" app to automatically fill in the email address and log in to CloudSign.
Note: The auxiliary app is only available on PC browsers and Android - Standard Browser (Chrome).
- Search on the "Register Company App" screen, select "[For SAML Auxiliary Use] CloudSign", and register it.
- Click the "Add App" button on "My Page" and select "[For SAML Auxiliary Use] CloudSign".
- Enter the email address registered with CloudSign in the "Email Address" field and click the "Save" button.
- Click the app from "My Page" or the "Browser Extension" and confirm that login succeeds.