|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Settings |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each individual system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
※ |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
※ |
Android - Native App |
|
Note: Available for use with the Garoon mobile app
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Company App" screen, search for and select "Cybozu (SAML)".
-
Note the value of the "IdP URL" under "Identity Provider Information", and click the "Get Certificate" button to download the certificate.
- Change the extension of the downloaded certificate to ".cer" so that the file format becomes a CER file.
Now, let's move on to the cybozu.com-side configuration.
Do not click the "Register" button yet — open cybozu.com in a separate window.
cybozu.com Settings
- Open "cybozu.com Common Administration" and open "Security > Login" in the left-hand menu.
Under "SAML Authentication", check "Enable SAML Authentication" and configure each item as follows.
Require Use of SAML Authentication Do not check (recommended)
Note: If you want to restrict the login method to SAML authentication only, complete the SAML configuration and operational verification, and notify your users, before checking this box to switch over. Please also note that some services and apps will no longer be available.
Identity Provider's SSO Endpoint URL The "IdP URL" obtained from TrustLogin URL to Redirect to After Logging Out of cybozu.com https://portal.trustlogin.com Public Key Certificate Used by the Identity Provider for Signing The "Certificate" obtained from TrustLogin (converted to a CER file)
- Click the "Save" button to save the settings.
- Download the metadata from "Download Service Provider Metadata".
- From the "User Management > Organization/Users" menu, open the "Edit User Information" screen for the target user, and set the TrustLogin email address in the "Login Name" field.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Login URL Your cybozu.com login URL Metadata Upload the "Service Provider Metadata" obtained from cybozu.com
- Click the "Register" button to save.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Cybozu (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds Members
- From the "Admin Page > Apps" menu, search for and click the "Cybozu (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Logging In with a Password to an Account with SAML Authentication Enabled
Even if "Require Use of SAML Authentication" is enabled, only the cybozu.com Common Administrator can log in to cybozu.com using password authentication.
The URL below is, by design, unable to be disabled, in order to avoid a situation in which you become unable to log in to cybozu.com if the SAML authentication configuration fails.
-
Access the following URL.
https://(subdomain name).cybozu.com/login?saml=off -
Enter the login name and password registered in cybozu.com Common Administration, and log in to cybozu.com.