|
Item |
Description |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure |
||
|
Provisioning |
Supports API-based provisioning (account management possible in TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
| ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
〇 |
Enabled for all users (SAML authentication only) |
| ー |
Other |
|
|
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Configuration |
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Company App Registration" screen, search and select "FSG(Flexible Secure Gateway)".
-
Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
Now, switch to the FSG-side configuration.
Do not click the "Register" button yet; open the FSG console in a separate window.
FSG Configuration
- Log in to the FSG console, select the target cell group from the drop-down list, and open "Active Directory".
-
Click the "v" to the left of Microsoft Entra ID to expand the Microsoft Entra ID configuration accordion.
-
Click "Add New" under "SAML Identity Provider Config".
- Set an arbitrary name for the SAML Identity Provider Config in "Name", and upload the metadata obtained from TrustLogin in "Federation Metadata XML Upload". When you have finished editing, click "Confirm".
- Check the details and click "Execute".
- Confirm the application completion message and click "OK".
-
To display the latest information, click the "Refresh" button.
- Click the "Apply Config" button in the left menu to apply the settings to the cell.
Config Application Procedure
- Click the "View Identifier/Reply URL" button to the right of "SAML Identity Provider Config".
- Make a note of the IP address of each cell.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Configuration (Continued)
- Configure each item under "Service Provider Configuration" as follows.
Login URL The IP address of any cell from the identifier/reply URL confirmed in the FSG console Entity ID The IP address of any cell from the identifier/reply URL confirmed in the FSG console
Note: enter the same value (the IP address of the same cell) for both the Login URL and Entity IDACS URL to the Service The IP addresses of all cells from the reply URL confirmed in the FSG console
Note: If cells are redundant, enter the IP address of each cell in the cell group one by one in each field
- Click the "Register" button to save.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "FSG(Flexible Secure Gateway)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
② When an administrator adds members
- Search for and click the "FSG(Flexible Secure Gateway)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ①
[Register Custom URL Category]
When integrating with TrustLogin, you need to configure authentication exclusion settings on the Captive Portal and communication permission settings on the UTM for the traffic used for authentication.
This section registers the TrustLogin URLs, which are specified as the communication destinations in each setting, as a custom URL category.
From the FSG console, register the URLs that are the destinations of TrustLogin authentication traffic as a category.
For the setup procedure, see Configuring a Custom URL Category.
Depending on your usage, you may also need to register the URL lists in ② and ③.
| Name |
Any identifiable name
|
| URL List ① |
Required
・portal.trustlogin.com
・tl-prod-cluster-images.s3.*.amazonaws.com
|
| URL List ② |
Required if using AD integration (optional)
・a-mq-ad.services.sku.id:5671
・b-mq-ad.services.sku.id:5671
|
| URL List ③ |
Required if using client authentication (optional)
・cert.sku.id
・cert.trustlogin.com
・ocsp.globalsign.com
・crl.globalsign.com
・secure.globalsign.com
|
Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ②
[Add Security Policy Rule]
This section adds a security policy that explicitly allows the traffic used during TrustLogin authentication integration on the UTM.
For any parameters not listed below, specify values of your choosing.
From the FSG console, follow the procedure in Configuring the UTM Feature (Security Policy Rules) to add a security policy that allows the following TrustLogin authentication traffic.
| Name | Any identifiable name |
| Log | Log enabled |
| Source IP Address | any |
| Destination IP Address | any |
| Destination TCP Port | any |
| Custom URL Category/Custom URL Category List | the previous section's URL category |
| Application List | any |
| Action | Allow |
- Due to UTM specifications, security policy rules deny all traffic that is not explicitly allowed by a rule, in principle.
- For any outbound traffic that needs to be allowed after successful TrustLogin authentication, add an allow rule below the rule you configured in this section.
After adding the security policy, click "Change Priority" in the FSG console to move the created policy to the top.
Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ③
[Add Captive Portal Authentication Exclusion Setting]
This section adds a setting to explicitly exclude the traffic used during TrustLogin authentication integration from Captive Portal authentication determination.
From the FSG console, follow the procedure for configuring Captive Portal authentication exclusion to add the following TrustLogin authentication traffic to the Captive Portal authentication settings.
| Name | Any identifiable name |
| Source IP Address | any |
| Destination IP Address | any |
| Destination TCP Port | any |
| Custom URL Category/Custom URL Category List | the section before last's URL category |