How to Configure SAML Authentication for Keiwaza Web

Item

Description

Pre-check

  • Prior configuration is required in Keiwaza Web.

  • Fuji Electric IT Solutions Co., Ltd., the provider of Keiwaza Web, does not verify SAML integration with TrustLogin. For inquiries, please contact our support desk.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, seehere

SP Configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports API-basedprovisioning (account management possible in TrustLogin)

SAML JITprovisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • If SAML configuration fails and you are unable to log in, or if you are unable to log in via SAML due to a TrustLogin outage or other issue, you can bypass SAML authentication and log in using password authentication by accessing the URL below.

    http://[Keiwaza Web server]/[virtual directory name]/kwzLogin.aspx?Act=HDNLOGIN

  • The Excel add-on and tablet features do not support SAML login.

Table of Contents:

Preparation
TrustLogin Admin Page Configuration

Keiwaza Web Configuration

TrustLogin User Configuration

Preparation

Note: If the "User ID" in Keiwaza Web uses the same email address as TrustLogin, this configuration is not required, so please proceed to the next step.

Add the Keiwaza Web "User ID" information to a custom attribute in the TrustLogin member information.

【TrustLogin Custom Attribute Configuration Example】
001.png


For how to configure custom attributes, please refer to the pages below. The attribute name of the custom attribute is arbitrary.

Custom Attribute Configuration Method (Individual Registration)

Custom Attribute Configuration Method (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin , open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
    01.png

  2. Set the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Configure each item under "Service Provider Settings" as follows.
    Login URL http://[Keiwaza Web server]/[virtual directory name]/kwzlogin
    Entity ID kwzsaml
    Name ID Format unspecified
    ACS URL to the Service http://[Keiwaza Web server]/[virtual directory name]/kwzlogin

    04.png

  5. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then click the "Add SAML Attribute" button to add a row (attribute) and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    LoginId unspecified LoginId

    Custom attribute (Note)

    Select the custom attribute configured in the preparation step (Note)

    (Note) If the "User ID" in Keiwaza Web uses the same email address as TrustLogin, select "Member > Member - Email Address".

    If you added the Keiwaza Web "User ID" information to a custom attribute in the member information
    05.png

    If the "User ID" in Keiwaza Web uses the same email address as TrustLogin
    06.png

  6. Click the "Register" button to save.

Keiwaza Web Configuration

  1. Log in with an administrator account, open "Administrator Settings > Authentication Settings", and configure each item as follows.
    Login Method SAML Authentication
    SSO Method Standard Login Authentication
    Authentication Server Endpoint SSO URL The "Identity Provider URL" obtained from TrustLogin
    Authentication Identifier The "Issuer/Entity ID" obtained from TrustLogin
    Certificate Upload the "Certificate" obtained from TrustLogin

    07.png

  2. Click the "Update" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Keiwaza Web

Item

Description

Pre-check

  • Prior configuration is required in Keiwaza Web.

  • Fuji Electric IT Solutions Co., Ltd., the provider of Keiwaza Web, does not verify SAML integration with TrustLogin. For inquiries, please contact our support desk.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, seehere

SP Configuration

Configured by the administrator

Request the SP to configure

Provisioning

Supports API-basedprovisioning (account management possible in TrustLogin)

SAML JITprovisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • If SAML configuration fails and you are unable to log in, or if you are unable to log in via SAML due to a TrustLogin outage or other issue, you can bypass SAML authentication and log in using password authentication by accessing the URL below.

    http://[Keiwaza Web server]/[virtual directory name]/kwzLogin.aspx?Act=HDNLOGIN

  • The Excel add-on and tablet features do not support SAML login.

Table of Contents:

Preparation
TrustLogin Admin Page Configuration

Keiwaza Web Configuration

TrustLogin User Configuration

Preparation

Note: If the "User ID" in Keiwaza Web uses the same email address as TrustLogin, this configuration is not required, so please proceed to the next step.

Add the Keiwaza Web "User ID" information to a custom attribute in the TrustLogin member information.

【TrustLogin Custom Attribute Configuration Example】
001.png


For how to configure custom attributes, please refer to the pages below. The attribute name of the custom attribute is arbitrary.

Custom Attribute Configuration Method (Individual Registration)

Custom Attribute Configuration Method (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin , open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
    01.png

  2. Set the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Configure each item under "Service Provider Settings" as follows.
    Login URL http://[Keiwaza Web server]/[virtual directory name]/kwzlogin
    Entity ID kwzsaml
    Name ID Format unspecified
    ACS URL to the Service http://[Keiwaza Web server]/[virtual directory name]/kwzlogin

    04.png

  5. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then click the "Add SAML Attribute" button to add a row (attribute) and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    LoginId unspecified LoginId

    Custom attribute (Note)

    Select the custom attribute configured in the preparation step (Note)

    (Note) If the "User ID" in Keiwaza Web uses the same email address as TrustLogin, select "Member > Member - Email Address".

    If you added the Keiwaza Web "User ID" information to a custom attribute in the member information
    05.png

    If the "User ID" in Keiwaza Web uses the same email address as TrustLogin
    06.png

  6. Click the "Register" button to save.

Keiwaza Web Configuration

  1. Log in with an administrator account, open "Administrator Settings > Authentication Settings", and configure each item as follows.
    Login Method SAML Authentication
    SSO Method Standard Login Authentication
    Authentication Server Endpoint SSO URL The "Identity Provider URL" obtained from TrustLogin
    Authentication Identifier The "Issuer/Entity ID" obtained from TrustLogin
    Certificate Upload the "Certificate" obtained from TrustLogin

    07.png

  2. Click the "Update" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.