|
Item |
Description |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, seehere |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure |
||
|
Provisioning |
Supports API-basedprovisioning (account management possible in TrustLogin) |
|
|
SAML JITprovisioning supported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified Operation Status by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
〇 |
Enabled for all users (SAML authentication only) |
| ー |
Other |
|
|
Notes |
|
|
|
Table of Contents: |
Preparation
Note: If the "User ID" in Keiwaza Web uses the same email address as TrustLogin, this configuration is not required, so please proceed to the next step.
Add the Keiwaza Web "User ID" information to a custom attribute in the TrustLogin member information.
【TrustLogin Custom Attribute Configuration Example】
For how to configure custom attributes, please refer to the pages below. The attribute name of the custom attribute is arbitrary.
Custom Attribute Configuration Method (Individual Registration)
Custom Attribute Configuration Method (Bulk Registration)
TrustLogin Admin Page Configuration
- Log in to TrustLogin , open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
- Set the "Application Name" and "Icon" (optional).
- Note down the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
-
Configure each item under "Service Provider Settings" as follows.
Login URL http://[Keiwaza Web server]/[virtual directory name]/kwzlogin Entity ID kwzsaml Name ID Format unspecified ACS URL to the Service http://[Keiwaza Web server]/[virtual directory name]/kwzlogin
-
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then click the "Add SAML Attribute" button to add a row (attribute) and configure it as follows.
(Note) If the "User ID" in Keiwaza Web uses the same email address as TrustLogin, select "Member > Member - Email Address".Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value LoginId unspecified LoginId Custom attribute (Note)
Select the custom attribute configured in the preparation step (Note)
If you added the Keiwaza Web "User ID" information to a custom attribute in the member information
If the "User ID" in Keiwaza Web uses the same email address as TrustLogin
- Click the "Register" button to save.
Keiwaza Web Configuration
- Log in with an administrator account, open "Administrator Settings > Authentication Settings", and configure each item as follows.
Login Method SAML Authentication SSO Method Standard Login Authentication Authentication Server Endpoint SSO URL The "Identity Provider URL" obtained from TrustLogin Authentication Identifier The "Issuer/Entity ID" obtained from TrustLogin Certificate Upload the "Certificate" obtained from TrustLogin
- Click the "Update" button to save.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select the custom SAML app you created and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
② When an administrator adds members
- Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.