|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
ー |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Users (SAML authentication only); Administrators (password authentication only) |
|
| Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Settings |
Prerequisites
To create users with their full name in Verona Client (Verona Cloud Console) from TrustLogin, you must configure a custom attribute in advance. Set the user's full name as the attribute value.
Note: The attribute name can be anything you choose. In this example, we set it to "fullname".
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure this.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
- Configure the "Application Name" and "Icon" (optional).
Note: If you need an icon, download one from here.
- Note the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.
[Convert the Certificate Format]
Convert the file extension of the downloaded certificate to ".cer".
Now, switch to configuring the Verona Cloud Console side.
Do not click the "Register" button yet — open Verona Cloud Console in a separate window.
Verona Cloud Console Settings
- Log in to Verona Cloud Console and open "Owner > Edit Owner > Single Sign-On". Configure the settings as follows, then click "Update".
Single Sign-On Enabled SAML JIT Provisioning Enabled Identifier (Entity ID) Copy and make a note of it Response URL Copy and make a note of it Login URL The "IdP URL" noted from TrustLogin Issuer Identifier The "Issuer/Entity ID" noted from TrustLogin Verona Client Login URL Copy and make a note of it
Note: This is the URL entered when logging in to Verona Client.
Share this URL with Verona Client users.
This is not the URL to configure on the TrustLogin side.
- Select the TrustLogin certificate from "Choose File" and upload it.
Note: Upload the certificate with the file extension converted to ".cer".
Now return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Sign SAML Response Check the box Value for Name ID Select "Member" - "email" (leave as default) Entity ID The "Identifier (Entity ID)" noted from Verona Cloud Console Name ID Format Select emailAddress ACS URL to Service The "Response URL" noted from Verona Cloud Console
- In "SAML Attribute Settings", add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value mail Unspecified mail Member
Member - Email Address
displayname Unspecified displayname Custom Attribute
The attribute name you configured
(e.g., fullname)
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Login Method
- Launch Verona Client and open "Option Settings".
- Click "Verona Cloud, IDaaS".
- Enter the "Verona Client Login URL" you noted from Verona Cloud Console into "Login URL", and
click "OK".
- You will be redirected to the TrustLogin login screen. Please log in there.
If You Want to Switch the User Logging in to Verona Client
Enter "https://portal.trustlogin.com/users/sign_out" into "Login URL", and click "OK" to log out of TrustLogin.
After that, perform the steps in "Login Method > 3." again, and log in with the TrustLogin user information you want to switch to. This will allow you to switch users.