How to Configure SAML Authentication for FRA (Flexible Remote Access)

Item

Description

Pre-check

  • Prior configuration is required in the FRA (Flexible Remote Access) (hereinafter "FRA") settings.

  • You must create an account in FRA using the same email address as your TrustLogin account.

  • For the latest setup procedure, please refer to the manual provided by FRA.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, seehere

SP Configuration

Configured by the administrator

 

Request the SP to configure

Provisioning

 

Supports API-basedprovisioning (account management possible in TrustLogin)

 

SAML JITprovisioningsupported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device
(Note)

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • If you use IDF authentication integration, configure different settings for System 0/System 1 (for each area's System 0/System 1 if using East-West redundancy).
  • After changing the settings, be sure to commit the changes on both System 0 and System 1.
  • After changing the settings, reconnect the FRA client to apply the changes.
  • When committing, we recommend committing on one system first, confirming that the connection works, and then committing on the other system.
  • If you have subscribed to East-West redundancy and need to register different portal metadata in FRA for each of the East and West areas, automatic failover via DNS switching will not be possible in the event of an area failure.
  • Please note that if the authentication profile associated with each server profile is incorrect, it will not work correctly.

(Note) For details on the verified operation status by device, please also refer to[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin section.

Table of Contents:

TrustLogin Admin Page Configuration

TrustLogin User Configuration

FRA Configuration

[Reference] Verifying the Connection to FRA

[Reference] Checking the Signed-In User Name

[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Company App Registration" screen, search and select "FRA(Flexible Remote Access)".
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

  4. Check the "Identifier", "Reply URL", and "Sign-on URL" information under "Configuration Information" on the Fsec console, and enter the unique domain information that is the same for each FRA group into the blank field.

    The FRA group-specific domain information refers to the following portion of the URL for the portal and each gateway.

    Authentication Portal https://**-***-portal.fra.ntt.com is the URL where "https://" and "-portal.fra.ntt.com" sandwich the **-*** portion.
    Gateway (System 0) https://**-***-gw0.fra.ntt.com is the URL where "https//" and "-gw0.fra.ntt.com" sandwich the **-*** portion.
    Gateway (System 1) https://**-***-gw1.fra.ntt.com is the URL where "https://" and "-gw1.fra.ntt.com" sandwich the **-*** portion.


    For the verification method, see  here .


    04.png

  5. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "FRA(Flexible Remote Access)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "FRA(Flexible Remote Access)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

FRA Configuration

① Fsec Console Configuration

  1. From the SDPF portal menu, select "Flexible Remote Access" to access the Fsec con
    sole.

  2. ① From "Service Group Information" in the left menu, select the service group you created.
    ② Click "External Authentication Integration (LDAP/SAML)".
    30.png

  3. Click the "Add New" button.
    31.png

  4. Enter the required information on the "Add New SAML Authentication Integration Server Profile" screen. When you have finished entering the information, click the "Confirm" button.
    Server Profile Name Enter the name of the server profile. Only single-byte alphanumeric characters and symbols (-_) can be used.
    Description You can register any description for this setting.
    FQDN specified when creating the metadata file In this procedure, multiple FQDNs are linked to a single metadata file, so select all applicable FQDNs.
    Metadata File
    Click the "Add File" button and add the metadata file obtained from TrustLogin.

    32.png

  5. Check the information you entered, and click the "Execute" button.
    33.png

  6. Click the "OK" button.
    34.png

  7. Confirm that the SAML authentication integration server profile has been created on the "External Authentication Integration (LDAP/SAML)" screen.
    35.png

  8. Click [Operation History] in the left menu, and confirm on the "Operation History" screen that the status is "COMPLETE".

Note: For each metadata file created in TrustLogin, a SAML authentication integration server profile must be created.

 

② FRA Portal Configuration

  1. Access the FRA portal, open "Device > SAML Identity Provider", and confirm that the server profile has been added.
    05.png

  2. Click "Authentication Profile > Add".
    06.png

  3. The authentication profile creation screen is displayed. Configure the "Authentication" items as follows.
    Name Enter any name to identify the profile
    Type SAML
    IdP Server Profile Select the SAML authentication integration server profile you added

    07.png

    08.png

  4. Open the "Details" section, click "Allow List > Add", and select "all" from the drop-down list.
    09.png

  5. Click "OK".
    10.png

  6. Confirm that the authentication profile has been added, and click "NETWORK".
    12.png

  7. Click "Portal > GP-portal".11.png

  8. Click "Authentication > Add".
    13.png

  9. The client authentication addition screen is displayed. Configure each item as follows.
    Name Any name used to identify the client authentication setting
    Authentication Profile Select the authentication profile you created
    Allow authentication using user credentials or client certificate YES

    14.png

  10. Click "OK".
    16.png

  11. Move the authentication setting you added to the top. Check the client authentication you created, and click "Move Up" to move it to the top.
    17.png

  12. Click "OK".
    18.png

  13. Click "Gateway > GP-GW".
    19.png

  14. Click "Authentication > Add".
    20.png

  15. The client authentication addition screen is displayed. Configure each item as follows.
    Name Any name used to identify the client authentication setting
    Authentication Profile Select the authentication profile you created
    Allow authentication using user credentials or client certificate YES

    21.png

  16. Click "OK".
    22.png

  17. Move the authentication setting you added to the top. Check the client authentication you created, and click "Move Up" to move it to the top.
    23.png

  18. Click "OK".
    24.png

  19. Commit the settings and confirm that they have been applied successfully.
    25.png

[Reference] Verifying the Connection to FRA

  1. Click the hamburger icon (three lines) in the upper right of the FRA Agent screen and select "Settings".
    26.png

  2. Click "Sign Out" > "OK" to delete the user's authentication information and disconnect once.
    Click "Connect" again.
    27.png

  3. The TrustLogin authentication screen is displayed. Complete the authentication.

  4. After authentication, the connection is complete.
    28.png

 

[Reference] Checking the Signed-In User Name

  1. Click the hamburger icon (three lines) in the upper right of the FRA Agent screen and select "Settings".
    26.png

  2. The name of the currently signed-in user is displayed in the lower left.
    29.png

[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin

This section describes the supported devices, authentication methods, and other environments when integrating authentication between FRA and TrustLogin.
By default, authentication integration is performed using the browser built into the agent.

FRA Agent's Built-in Browser – Authentication Integration with TrustLogin (Default/Recommended)

Supported Authentication Method Windows Mac

iOS/iPadOS

Android
Password Authentication
One-Time Password

FIDO Passwordless Authentication

ー *1 ー *1
Client Authentication

Push Notification Authentication

Legend) 〇: Supported ー: Not Supported
*1 Not supported as of (December 2024), but support is planned in the future.

  • Some authentication methods cannot be used with the built-in browser; changing the settings to perform authentication integration using the device's standard browser (Edge/Safari) may make them available.
  • Using the standard browser disables some FRA features, such as the automatic connection feature, so we recommend using the agent's built-in browser as a general rule.
  • FRA and TrustLogin cannot provide guidance on individual functional limitations when using the device's standard browser. Please verify operation on an actual device beforehand and use it at your own responsibility.

(Reference) Using the Device's Standard Browser for Authentication Integration with docomo business RINK IDaaS (Not Recommended)

Supported Authentication Method Windows Mac

iOS/iPadOS

Android
Password Authentication
One-Time Password

FIDO Passwordless Authentication

Client Authentication

Push Notification Authentication

Legend) 〇: Supported ー: Not Supported



About the Browser Used for Authentication Integration

For reference, this section describes the browsers used for authentication integration.

  • FRA Agent's Built-in Browser: FRA Agent's own proprietary built-in browser. Used only during FRA's SAML authentication integration.

  • Device's Standard Browser: PCs, mobile devices, and other devices' commonly pre-installed browsers (Microsoft Edge/Safari/Google Chrome, etc.).

 

 

How to Configure SAML Authentication for FRA (Flexible Remote Access)

Item

Description

Pre-check

  • Prior configuration is required in the FRA (Flexible Remote Access) (hereinafter "FRA") settings.

  • You must create an account in FRA using the same email address as your TrustLogin account.

  • For the latest setup procedure, please refer to the manual provided by FRA.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, seehere

SP Configuration

Configured by the administrator

 

Request the SP to configure

Provisioning

 

Supports API-basedprovisioning (account management possible in TrustLogin)

 

SAML JITprovisioningsupported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device
(Note)

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • If you use IDF authentication integration, configure different settings for System 0/System 1 (for each area's System 0/System 1 if using East-West redundancy).
  • After changing the settings, be sure to commit the changes on both System 0 and System 1.
  • After changing the settings, reconnect the FRA client to apply the changes.
  • When committing, we recommend committing on one system first, confirming that the connection works, and then committing on the other system.
  • If you have subscribed to East-West redundancy and need to register different portal metadata in FRA for each of the East and West areas, automatic failover via DNS switching will not be possible in the event of an area failure.
  • Please note that if the authentication profile associated with each server profile is incorrect, it will not work correctly.

(Note) For details on the verified operation status by device, please also refer to[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin section.

Table of Contents:

TrustLogin Admin Page Configuration

TrustLogin User Configuration

FRA Configuration

[Reference] Verifying the Connection to FRA

[Reference] Checking the Signed-In User Name

[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Company App Registration" screen, search and select "FRA(Flexible Remote Access)".
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

  4. Check the "Identifier", "Reply URL", and "Sign-on URL" information under "Configuration Information" on the Fsec console, and enter the unique domain information that is the same for each FRA group into the blank field.

    The FRA group-specific domain information refers to the following portion of the URL for the portal and each gateway.

    Authentication Portal https://**-***-portal.fra.ntt.com is the URL where "https://" and "-portal.fra.ntt.com" sandwich the **-*** portion.
    Gateway (System 0) https://**-***-gw0.fra.ntt.com is the URL where "https//" and "-gw0.fra.ntt.com" sandwich the **-*** portion.
    Gateway (System 1) https://**-***-gw1.fra.ntt.com is the URL where "https://" and "-gw1.fra.ntt.com" sandwich the **-*** portion.


    For the verification method, see  here .


    04.png

  5. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "FRA(Flexible Remote Access)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "FRA(Flexible Remote Access)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

FRA Configuration

① Fsec Console Configuration

  1. From the SDPF portal menu, select "Flexible Remote Access" to access the Fsec con
    sole.

  2. ① From "Service Group Information" in the left menu, select the service group you created.
    ② Click "External Authentication Integration (LDAP/SAML)".
    30.png

  3. Click the "Add New" button.
    31.png

  4. Enter the required information on the "Add New SAML Authentication Integration Server Profile" screen. When you have finished entering the information, click the "Confirm" button.
    Server Profile Name Enter the name of the server profile. Only single-byte alphanumeric characters and symbols (-_) can be used.
    Description You can register any description for this setting.
    FQDN specified when creating the metadata file In this procedure, multiple FQDNs are linked to a single metadata file, so select all applicable FQDNs.
    Metadata File
    Click the "Add File" button and add the metadata file obtained from TrustLogin.

    32.png

  5. Check the information you entered, and click the "Execute" button.
    33.png

  6. Click the "OK" button.
    34.png

  7. Confirm that the SAML authentication integration server profile has been created on the "External Authentication Integration (LDAP/SAML)" screen.
    35.png

  8. Click [Operation History] in the left menu, and confirm on the "Operation History" screen that the status is "COMPLETE".

Note: For each metadata file created in TrustLogin, a SAML authentication integration server profile must be created.

 

② FRA Portal Configuration

  1. Access the FRA portal, open "Device > SAML Identity Provider", and confirm that the server profile has been added.
    05.png

  2. Click "Authentication Profile > Add".
    06.png

  3. The authentication profile creation screen is displayed. Configure the "Authentication" items as follows.
    Name Enter any name to identify the profile
    Type SAML
    IdP Server Profile Select the SAML authentication integration server profile you added

    07.png

    08.png

  4. Open the "Details" section, click "Allow List > Add", and select "all" from the drop-down list.
    09.png

  5. Click "OK".
    10.png

  6. Confirm that the authentication profile has been added, and click "NETWORK".
    12.png

  7. Click "Portal > GP-portal".11.png

  8. Click "Authentication > Add".
    13.png

  9. The client authentication addition screen is displayed. Configure each item as follows.
    Name Any name used to identify the client authentication setting
    Authentication Profile Select the authentication profile you created
    Allow authentication using user credentials or client certificate YES

    14.png

  10. Click "OK".
    16.png

  11. Move the authentication setting you added to the top. Check the client authentication you created, and click "Move Up" to move it to the top.
    17.png

  12. Click "OK".
    18.png

  13. Click "Gateway > GP-GW".
    19.png

  14. Click "Authentication > Add".
    20.png

  15. The client authentication addition screen is displayed. Configure each item as follows.
    Name Any name used to identify the client authentication setting
    Authentication Profile Select the authentication profile you created
    Allow authentication using user credentials or client certificate YES

    21.png

  16. Click "OK".
    22.png

  17. Move the authentication setting you added to the top. Check the client authentication you created, and click "Move Up" to move it to the top.
    23.png

  18. Click "OK".
    24.png

  19. Commit the settings and confirm that they have been applied successfully.
    25.png

[Reference] Verifying the Connection to FRA

  1. Click the hamburger icon (three lines) in the upper right of the FRA Agent screen and select "Settings".
    26.png

  2. Click "Sign Out" > "OK" to delete the user's authentication information and disconnect once.
    Click "Connect" again.
    27.png

  3. The TrustLogin authentication screen is displayed. Complete the authentication.

  4. After authentication, the connection is complete.
    28.png

 

[Reference] Checking the Signed-In User Name

  1. Click the hamburger icon (three lines) in the upper right of the FRA Agent screen and select "Settings".
    26.png

  2. The name of the currently signed-in user is displayed in the lower left.
    29.png

[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin

This section describes the supported devices, authentication methods, and other environments when integrating authentication between FRA and TrustLogin.
By default, authentication integration is performed using the browser built into the agent.

FRA Agent's Built-in Browser – Authentication Integration with TrustLogin (Default/Recommended)

Supported Authentication Method Windows Mac

iOS/iPadOS

Android
Password Authentication
One-Time Password

FIDO Passwordless Authentication

ー *1 ー *1
Client Authentication

Push Notification Authentication

Legend) 〇: Supported ー: Not Supported
*1 Not supported as of (December 2024), but support is planned in the future.

  • Some authentication methods cannot be used with the built-in browser; changing the settings to perform authentication integration using the device's standard browser (Edge/Safari) may make them available.
  • Using the standard browser disables some FRA features, such as the automatic connection feature, so we recommend using the agent's built-in browser as a general rule.
  • FRA and TrustLogin cannot provide guidance on individual functional limitations when using the device's standard browser. Please verify operation on an actual device beforehand and use it at your own responsibility.

(Reference) Using the Device's Standard Browser for Authentication Integration with docomo business RINK IDaaS (Not Recommended)

Supported Authentication Method Windows Mac

iOS/iPadOS

Android
Password Authentication
One-Time Password

FIDO Passwordless Authentication

Client Authentication

Push Notification Authentication

Legend) 〇: Supported ー: Not Supported



About the Browser Used for Authentication Integration

For reference, this section describes the browsers used for authentication integration.

  • FRA Agent's Built-in Browser: FRA Agent's own proprietary built-in browser. Used only during FRA's SAML authentication integration.

  • Device's Standard Browser: PCs, mobile devices, and other devices' commonly pre-installed browsers (Microsoft Edge/Safari/Google Chrome, etc.).