|
Item |
Description |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, seehere |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure |
||
|
Provisioning |
Supports API-basedprovisioning (account management possible in TrustLogin) |
|
|
SAML JITprovisioningsupported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified Operation Status by Device |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
|
SAML Authentication Scope |
〇 |
Enabled for all users (SAML authentication only) |
| ー |
Other |
|
|
Notes |
|
|
(Note) For details on the verified operation status by device, please also refer to[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin section.
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Company App Registration" screen, search and select "FRA(Flexible Remote Access)".
- Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
- Check the "Identifier", "Reply URL", and "Sign-on URL" information under "Configuration Information" on the Fsec console, and enter the unique domain information that is the same for each FRA group into the blank field.
The FRA group-specific domain information refers to the following portion of the URL for the portal and each gateway.
Authentication Portal https://**-***-portal.fra.ntt.com is the URL where "https://" and "-portal.fra.ntt.com" sandwich the **-*** portion. Gateway (System 0) https://**-***-gw0.fra.ntt.com is the URL where "https//" and "-gw0.fra.ntt.com" sandwich the **-*** portion. Gateway (System 1) https://**-***-gw1.fra.ntt.com is the URL where "https://" and "-gw1.fra.ntt.com" sandwich the **-*** portion.
For the verification method, see here .
- Click the "Register" button to save.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "FRA(Flexible Remote Access)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
② When an administrator adds members
- Search for and click the "FRA(Flexible Remote Access)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
FRA Configuration
① Fsec Console Configuration
-
From the SDPF portal menu, select "Flexible Remote Access" to access the Fsec con
sole. -
① From "Service Group Information" in the left menu, select the service group you created.② Click "External Authentication Integration (LDAP/SAML)".
- Click the "Add New" button.
- Enter the required information on the "Add New SAML Authentication Integration Server Profile" screen. When you have finished entering the information, click the "Confirm" button.
Server Profile Name Enter the name of the server profile. Only single-byte alphanumeric characters and symbols (-_) can be used. Description You can register any description for this setting. FQDN specified when creating the metadata file In this procedure, multiple FQDNs are linked to a single metadata file, so select all applicable FQDNs. Metadata File Click the "Add File" button and add the metadata file obtained from TrustLogin.
- Check the information you entered, and click the "Execute" button.
- Click the "OK" button.
- Confirm that the SAML authentication integration server profile has been created on the "External Authentication Integration (LDAP/SAML)" screen.
- Click [Operation History] in the left menu, and confirm on the "Operation History" screen that the status is "COMPLETE".
Note: For each metadata file created in TrustLogin, a SAML authentication integration server profile must be created.
② FRA Portal Configuration
- Access the FRA portal, open "Device > SAML Identity Provider", and confirm that the server profile has been added.
- Click "Authentication Profile > Add".
- The authentication profile creation screen is displayed. Configure the "Authentication" items as follows.
Name Enter any name to identify the profile Type SAML IdP Server Profile Select the SAML authentication integration server profile you added
- Open the "Details" section, click "Allow List > Add", and select "all" from the drop-down list.
- Click "OK".
- Confirm that the authentication profile has been added, and click "NETWORK".
- Click "Portal > GP-portal".
- Click "Authentication > Add".
- The client authentication addition screen is displayed. Configure each item as follows.
Name Any name used to identify the client authentication setting Authentication Profile Select the authentication profile you created Allow authentication using user credentials or client certificate YES
- Click "OK".
- Move the authentication setting you added to the top. Check the client authentication you created, and click "Move Up" to move it to the top.
- Click "OK".
- Click "Gateway > GP-GW".
- Click "Authentication > Add".
- The client authentication addition screen is displayed. Configure each item as follows.
Name Any name used to identify the client authentication setting Authentication Profile Select the authentication profile you created Allow authentication using user credentials or client certificate YES
- Click "OK".
- Move the authentication setting you added to the top. Check the client authentication you created, and click "Move Up" to move it to the top.
- Click "OK".
- Commit the settings and confirm that they have been applied successfully.
[Reference] Verifying the Connection to FRA
- Click the hamburger icon (three lines) in the upper right of the FRA Agent screen and select "Settings".
- Click "Sign Out" > "OK" to delete the user's authentication information and disconnect once.
Click "Connect" again.
- The TrustLogin authentication screen is displayed. Complete the authentication.
- After authentication, the connection is complete.
[Reference] Checking the Signed-In User Name
- Click the hamburger icon (three lines) in the upper right of the FRA Agent screen and select "Settings".
- The name of the currently signed-in user is displayed in the lower left.
[Reference] Supported Environments for FRA's Authentication Integration with TrustLogin
This section describes the supported devices, authentication methods, and other environments when integrating authentication between FRA and TrustLogin.
By default, authentication integration is performed using the browser built into the agent.
FRA Agent's Built-in Browser – Authentication Integration with TrustLogin (Default/Recommended)
| Supported Authentication Method | Windows | Mac |
iOS/iPadOS |
Android |
| Password Authentication | 〇 | 〇 | 〇 | 〇 |
| One-Time Password | 〇 | 〇 | 〇 | 〇 |
|
FIDO Passwordless Authentication |
ー *1 | ー *1 | ー | ー |
| Client Authentication | 〇 | ー | ー | ー |
|
Push Notification Authentication |
〇 | 〇 | 〇 | 〇 |
Legend) 〇: Supported ー: Not Supported
*1 Not supported as of (December 2024), but support is planned in the future.
-
Some authentication methods cannot be used with the built-in browser; changing the settings to perform authentication integration using the device's standard browser (Edge/Safari) may make them available.
-
Using the standard browser disables some FRA features, such as the automatic connection feature, so we recommend using the agent's built-in browser as a general rule.
-
FRA and TrustLogin cannot provide guidance on individual functional limitations when using the device's standard browser. Please verify operation on an actual device beforehand and use it at your own responsibility.
(Reference) Using the Device's Standard Browser for Authentication Integration with docomo business RINK IDaaS (Not Recommended)
| Supported Authentication Method | Windows | Mac |
iOS/iPadOS |
Android |
| Password Authentication | 〇 | 〇 | ー | ー |
| One-Time Password | 〇 | 〇 | ー | ー |
|
FIDO Passwordless Authentication |
〇 | 〇 | ー | ー |
| Client Authentication | 〇 | 〇 | ー | ー |
|
Push Notification Authentication |
〇 | 〇 | ー | ー |
Legend) 〇: Supported ー: Not Supported
About the Browser Used for Authentication Integration
For reference, this section describes the browsers used for authentication integration.
-
FRA Agent's Built-in Browser: FRA Agent's own proprietary built-in browser. Used only during FRA's SAML authentication integration.
- Device's Standard Browser: PCs, mobile devices, and other devices' commonly pre-installed browsers (Microsoft Edge/Safari/Google Chrome, etc.).