|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
|
Configured by the administrator |
| 〇 |
Request SP to configure |
|
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Preparation
●TrustLogin Configuration
You need to configure a custom attribute in advance to link the company ID of Ekispert Commuting Expenses Web to the member information in TrustLogin. Set the company ID of Ekispert Commuting Expenses Web as the attribute value.
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for configuration instructions.
●Ekispert Commuting Expenses Web Configuration
Select an employee from "Master Management > Employee Information" and enter the same
email address as TrustLogin in the "SSO-ID" field.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and "Icon" (optional).
- Download the metadata using the "Download Metadata" button under "Identity Provider Information". Also, download the certificate using the "Get Certificate" button.
- Configure the "Service Provider Settings" as follows.
Name ID Value Select "Member" - "email" (default setting) Entity ID TsukinhiWeb Name ID Format unspecified ACS URL for the Service https://teiki.ekispert.com/teiki/Saml2/Acs
- Add a row (attribute) using the "Add SAML Attribute" button under "SAML Attribute Settings" and configure it as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value tenantid Unspecified tenantid Custom attribute
The attribute name you configured
- Save by clicking the "Register" button.
- Send the TrustLogin metadata and certificate to your contact at Val Laboratory Corporation and request SAML configuration.
- Once you receive notification from your contact at Val Laboratory Corporation that the metadata configuration is complete, add the app and try SAML authentication.
Ekispert Commuting Expenses Web Configuration
- Select an employee from "Master Management > Employee Information". For "Password Login," select either "Not allowed (SSO only)" or "Allowed," and update the information.
Note: If you select "Not allowed (SSO only)," users will no longer be able to set a new password or reset their password. This setting also changes the login URL included in notification emails.
(SSO only → URL for SSO login; Password allowed → URL for password login)
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an administrator adds members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.