How to Configure SAML Authentication for cybozu.com

Item

Details

Pre-check

  • Prior configuration in cybozu.com is required.

  • The "Login Name" in the cybozu.com user information must match the TrustLogin email address.

  • For the most up-to-date setup instructions, please refer to the manual provided by cybozu.com.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each individual system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: Available for use with the Garoon mobile app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "Cybozu (SAML)".
    02.png

  3. Note the value of the "IdP URL" under "Identity Provider Information", and click the "Get Certificate" button to download the certificate.
    03.png

  4. Change the extension of the downloaded certificate to ".cer" so that the file format becomes a CER file.

Now, let's move on to the cybozu.com-side configuration.
Do not click the "Register" button yet — open cybozu.com in a separate window.

cybozu.com Settings

  1. Open "cybozu.com Common Administration" and open "Security > Login" in the left-hand menu.
    Under "SAML Authentication", check "Enable SAML Authentication" and configure each item as follows.
    Require Use of SAML Authentication

    Do not check (recommended)

    Note: If you want to restrict the login method to SAML authentication only, complete the SAML configuration and operational verification, and notify your users, before checking this box to switch over. Please also note that some services and apps will no longer be available.

    Identity Provider's SSO Endpoint URL The "IdP URL" obtained from TrustLogin
    URL to Redirect to After Logging Out of cybozu.com https://portal.trustlogin.com
    Public Key Certificate Used by the Identity Provider for Signing The "Certificate" obtained from TrustLogin (converted to a CER file)

    04.png

  2. Click the "Save" button to save the settings.

  3. Download the metadata from "Download Service Provider Metadata".
    06.png

  4. From the "User Management > Organization/Users" menu, open the "Edit User Information" screen for the target user, and set the TrustLogin email address in the "Login Name" field.
    08.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL Your cybozu.com login URL
    Metadata Upload the "Service Provider Metadata" obtained from cybozu.com

    07.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Cybozu (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. From the "Admin Page > Apps" menu, search for and click the "Cybozu (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.


Logging In with a Password to an Account with SAML Authentication Enabled

Even if "Require Use of SAML Authentication" is enabled, only the cybozu.com Common Administrator can log in to cybozu.com using password authentication.
The URL below is, by design, unable to be disabled, in order to avoid a situation in which you become unable to log in to cybozu.com if the SAML authentication configuration fails.

  1. Access the following URL.
    https://(subdomain name).cybozu.com/login?saml=off

  2. Enter the login name and password registered in cybozu.com Common Administration, and log in to cybozu.com.

How to Configure SAML Authentication for cybozu.com

Item

Details

Pre-check

  • Prior configuration in cybozu.com is required.

  • The "Login Name" in the cybozu.com user information must match the TrustLogin email address.

  • For the most up-to-date setup instructions, please refer to the manual provided by cybozu.com.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each individual system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: Available for use with the Garoon mobile app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "Cybozu (SAML)".
    02.png

  3. Note the value of the "IdP URL" under "Identity Provider Information", and click the "Get Certificate" button to download the certificate.
    03.png

  4. Change the extension of the downloaded certificate to ".cer" so that the file format becomes a CER file.

Now, let's move on to the cybozu.com-side configuration.
Do not click the "Register" button yet — open cybozu.com in a separate window.

cybozu.com Settings

  1. Open "cybozu.com Common Administration" and open "Security > Login" in the left-hand menu.
    Under "SAML Authentication", check "Enable SAML Authentication" and configure each item as follows.
    Require Use of SAML Authentication

    Do not check (recommended)

    Note: If you want to restrict the login method to SAML authentication only, complete the SAML configuration and operational verification, and notify your users, before checking this box to switch over. Please also note that some services and apps will no longer be available.

    Identity Provider's SSO Endpoint URL The "IdP URL" obtained from TrustLogin
    URL to Redirect to After Logging Out of cybozu.com https://portal.trustlogin.com
    Public Key Certificate Used by the Identity Provider for Signing The "Certificate" obtained from TrustLogin (converted to a CER file)

    04.png

  2. Click the "Save" button to save the settings.

  3. Download the metadata from "Download Service Provider Metadata".
    06.png

  4. From the "User Management > Organization/Users" menu, open the "Edit User Information" screen for the target user, and set the TrustLogin email address in the "Login Name" field.
    08.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL Your cybozu.com login URL
    Metadata Upload the "Service Provider Metadata" obtained from cybozu.com

    07.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Cybozu (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. From the "Admin Page > Apps" menu, search for and click the "Cybozu (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.


Logging In with a Password to an Account with SAML Authentication Enabled

Even if "Require Use of SAML Authentication" is enabled, only the cybozu.com Common Administrator can log in to cybozu.com using password authentication.
The URL below is, by design, unable to be disabled, in order to avoid a situation in which you become unable to log in to cybozu.com if the SAML authentication configuration fails.

  1. Access the following URL.
    https://(subdomain name).cybozu.com/login?saml=off

  2. Enter the login name and password registered in cybozu.com Common Administration, and log in to cybozu.com.