|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
ー |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Users (SAML authentication only); Administrators (password authentication only) |
|
| Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Verona Client (SAML)".
- Note the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.
[Convert the Certificate Format]
Convert the file extension of the downloaded certificate to ".cer".
Now, switch to configuring the Verona Cloud Console side.
Do not click the "Register" button yet — open Verona Cloud Console in a separate window.
Verona Cloud Console Settings
- Log in to Verona Cloud Console and open "Owner > Edit Owner > Single Sign-On". Configure the settings as follows, then click "Update".
Single Sign-On Enabled SAML JIT Provisioning Enabled Identifier (Entity ID) Copy and make a note of it Response URL Copy and make a note of it Login URL The "IdP URL" noted from TrustLogin Issuer Identifier The "Issuer/Entity ID" noted from TrustLogin Verona Client Login URL Copy and make a note of it
Note: This is the URL entered when logging in to Verona Client.
Share this URL with Verona Client users.
This is not the URL to configure on the TrustLogin side.
- Select the TrustLogin certificate from "Choose File" and upload it.
Note: Upload the certificate with the file extension converted to ".cer".
Now return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Identifier (Entity ID)" noted from Verona Cloud Console ACS URL to Service The "Response URL" noted from Verona Cloud Console
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "Verona Client (SAML)", and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
②When an Administrator Adds a Member
- Search for and click the "Verona Client (SAML)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Login Method
- Launch Verona Client and open "Option Settings".
- Click "Verona Cloud, IDaaS".
- Enter the "Verona Client Login URL" you noted from Verona Cloud Console into "Login URL", and
click "OK".
- You will be redirected to the TrustLogin login screen. Please log in there.
If You Want to Switch the User Logging in to Verona Client
In "Login URL", enter "https://portal.trustlogin.com/users/sign_out", and click "OK" to log out of TrustLogin.
After that, perform the steps in "Login Method > 3." again, and log in with the TrustLogin user information you want to switch to. This will allow you to switch users.