Commune SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Commune is required.

  • For the latest setup instructions, please check the manual provided by Commune.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Commune (SAML)".
    02.png

  3. Make a note of the "Identity Provider URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Enter the Commune community subdomain into the three input fields under "Service Provider Settings".
    06.png

  5. Save by clicking the "Register" button.

Commune Configuration

  1. Open "Settings > Tool Integrations" on the admin screen and click the "Add" button under "SAML Authentication SP Settings".
    04.png

  2. Configure each item as follows, then click the "Add" button.
    IdP SSO Endpoint URL The "Identity Provider URL" obtained from TrustLogin
    IdP Certificate

    The string obtained by removing the --BEGIN CERTIFICATE-- and --END CERTIFICATE-- header lines and all line breaks from the "Certificate" obtained from TrustLogin

    IdP User Identifier (NameIDFormat) Email address (emailAddress)

    05.png

  3. Open "Settings > Community Settings", turn on "Advanced Settings", and configure the logout URL. Specify a URL that is not a URL within Commune.
    https://portal.trustlogin.com/ is one example.
    09.png

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Commune (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "Commune (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Creating a New User

  1. When a user not yet registered in Commune logs in via SAML, the account registration screen is displayed. Click the "Register" button.
    07.png

  2. Set the display name and username, then click "Next" to complete account registration and log in to Commune.
    08.png

Commune SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Commune is required.

  • For the latest setup instructions, please check the manual provided by Commune.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Commune (SAML)".
    02.png

  3. Make a note of the "Identity Provider URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Enter the Commune community subdomain into the three input fields under "Service Provider Settings".
    06.png

  5. Save by clicking the "Register" button.

Commune Configuration

  1. Open "Settings > Tool Integrations" on the admin screen and click the "Add" button under "SAML Authentication SP Settings".
    04.png

  2. Configure each item as follows, then click the "Add" button.
    IdP SSO Endpoint URL The "Identity Provider URL" obtained from TrustLogin
    IdP Certificate

    The string obtained by removing the --BEGIN CERTIFICATE-- and --END CERTIFICATE-- header lines and all line breaks from the "Certificate" obtained from TrustLogin

    IdP User Identifier (NameIDFormat) Email address (emailAddress)

    05.png

  3. Open "Settings > Community Settings", turn on "Advanced Settings", and configure the logout URL. Specify a URL that is not a URL within Commune.
    https://portal.trustlogin.com/ is one example.
    09.png

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Commune (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "Commune (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Creating a New User

  1. When a user not yet registered in Commune logs in via SAML, the account registration screen is displayed. Click the "Register" button.
    07.png

  2. Set the display name and username, then click "Next" to complete account registration and log in to Commune.
    08.png