|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Settings |
〇 |
Configured by the administrator |
|
Request the SP to configure settings |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Device Verification Status |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: |
|
|
Notes |
This manual has been verified using Crypto Bin v2.18.0. |
|
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Corporate App" screen, search for and select "Crypto Bin (SAML)".
- Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
At this point, switch to configuring Crypto Bin.
Do not click the "Register" button yet — open Crypto Bin in a separate window.
Crypto Bin Settings
- Log in to the administrator screen, open "Section Settings > Feature Settings > Authentication Integration", and click the "Edit" button.
- Configure each item as follows, then click the "Confirm Details" button.
EntityID (IdP) The "Issuer/Entity ID" obtained from TrustLogin Error URL The URL of the page that users connected via authentication integration are redirected to when they are logged out of Crypto Bin due to an error. Specify a page such as your company's or organization's internal portal site. Logout URL The URL of the page that users connected via authentication integration are returned to when they log out of Crypto Bin. This is usually set to the same value as the "Error URL". Single Sign-On Service URL The "IdP URL" obtained from TrustLogin Primary Certificate (base64) The contents of the "Certificate" obtained from TrustLogin Authentication Integration Feature Specify the users to whom SAML SSO applies, according to your operational needs
- Review the configured settings and click the "Update" button.
- Click the "Download" button to download the "IdP Configuration File".
- Go to "Contract Information > Section Information" and note down the URL for "General User (Authentication Integration: Screen Input Type)".
- In the "Login Method" section of each user's user information screen, you can set whether to allow the target user to also log in using their Crypto Bin ID.
Authentication integration only Login is only possible via SAML SSO
Also use login with Crypto Bin ID Both SAML SSO and login with Crypto Bin ID are possible
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "General User (Authentication Integration: Screen Input Type)" URL obtained from Crypto Bin Metadata Upload the "IdP Configuration File" (sp.xml) obtained from Crypto Bin
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Crypto Bin (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the "Crypto Bin (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.