|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on setting up a custom attribute, see here |
||
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure this |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible) |
||
|
〇 |
None (accounts are created individually in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "Bill One (SAML)."
- Make a note of the values for "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
- Convert the extension of the downloaded certificate to ".cer."
Now, switch to the Bill One settings.
Do not click the "Register" button yet; open Bill One in a separate window.
Bill One Settings
- From the Bill One global menu, click "System Settings."
- From the side menu, click "SSO (Single Sign-On) Settings."
- In "Step 1," register your domain and verify domain ownership. For detailed configuration steps, please refer to the manual provided by Bill One.
Bill One's manual is available here
- Configure "Step 2. Integration Settings" as follows.
Integration Method SAML IdP Identifier The "Issuer/Entity ID" you noted down from TrustLogin Sign-in URL The "IdP URL" you noted down from TrustLogin SAML Signing Certificate The "certificate" you noted down from TrustLogin, with its extension converted to ".cer"
- Using the copy buttons, make a note of the "Response URL (AssertionConsumerURL)," "Identifier (EntityID)," and "URL for SSO." Configure the "Certificate Renewal Reminder" as needed.
Now, return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "URL for SSO" you noted down from Bill One Entity ID The "Identifier (EntityID)" you noted down from Bill One ACS URL to the Service The "Response URL (AssertionConsumerURL)" you noted down from Bill One
- Save by clicking the "Register" button.
- Add the user who is currently performing the SAML configuration to the "Bill One (SAML)" app.
From "Admin Page > App," search for the "Bill One (SAML)" app, and add the user via "Add Member."
Bill One Settings (Continued)
- Click the "Start Connection Test" button and confirm that authentication succeeds.
- If the connection test completes without issues, the test is finished. Click [Save Settings and Proceed] to save the configuration.
- Change the status of users who will use SSO to [In Use].
- If you want to enable SSO in bulk for each domain, click [Bulk Change], select the domains for which you want to enable SSO from the domain list displayed on the bulk change screen, and click [Change to In Use].
For details, please refer to the Bill One manual.
TrustLogin User Settings
① When a User Adds the App from My Page
- On "My Page," click the "Add App" button.
- On the "Register App" screen, select "Bill One (SAML)," and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter a new one, then click the "Register" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for and click the "Bill One (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.