|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Newt (SAML)".
- Note down the values of "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, switch to configuring Newt.
Do not click the "Register" button yet — open Newt in a separate window.
Newt Settings
- Log in to Newt with an administrator account and select "Space Settings".
- Open "Security > Single Sign-On". Click the copy button for "Entity ID", "Sign-on URL", and "Sign-out URL" under "Service Provider Configuration Information" and note them down.
- Configure "Identity Provider Configuration Information" as follows, and click "Save".
Entity ID The "Issuer / Entity ID" noted down from TrustLogin Sign-on URL The "Identity Provider URL" noted down from TrustLogin Sign-out URL https://portal.trustlogin.com/ X.509 Certificate Paste in the contents of the "Certificate" noted down from TrustLogin Default Role Select the space role to be assigned to an account when it newly joins the space via SAML JIT. Default App to Join Select the App to join when the account newly joins the space via SAML JIT. Restricted Mode Prohibits members who belong to the space from logging in using an email address and password, Google login, or other SSO methods. If you enable this, we recommend doing so only after confirming that SAML authentication is working successfully.
Now return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Entity ID" noted down from Newt ACS URL to Service The "Sign-on URL" noted down from Newt Logout URL The "Sign-out URL" noted down from Newt
Note: Single logout is planned to be added as a feature in the future, but it is not yet implemented and does not currently work
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Newt (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an Administrator Adds Members
- Search for and click the "Newt (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
First Login Method
When an existing user logs in via SAML authentication, their user information is linked at the first login.
This step is not required for SAML JIT.
- At the first login via SAML authentication, an identity verification email is sent to the corresponding email address.
- Check the email and click the link to go to the password login screen. After entering the email address and password, log in by clicking the "Log In" button.
Note: If the user accesses the link while already logged in to a Newt account with the corresponding email address, the screen below will not appear and entering the email address and password is not required.
- After logging in to Newt from the single sign-on confirmation screen, the information linkage is complete.
From the second login onward, no password entry is required and you can log in via SSO.