How to Configure SAML Authentication for Crypto Bin

Item

Details

Pre-check

  • Prior setup in Crypto Bin is required.

  • You need to create an account in Crypto Bin using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the manual provided by Crypto Bin.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Verification Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Enabled for all users (option to use both SAML authentication and password authentication together)

Notes

This manual has been verified using Crypto Bin v2.18.0.

Table of Contents:

TrustLogin Admin Page Settings

Crypto Bin Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Crypto Bin (SAML)".
    CryptoBin01.png


  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to configuring Crypto Bin.
Do not click the "Register" button yet — open Crypto Bin in a separate window.

Crypto Bin Settings

  1. Log in to the administrator screen, open "Section Settings > Feature Settings > Authentication Integration", and click the "Edit" button.
    04.png

  2. Configure each item as follows, then click the "Confirm Details" button.
    EntityID (IdP) The "Issuer/Entity ID" obtained from TrustLogin
    Error URL The URL of the page that users connected via authentication integration are redirected to when they are logged out of Crypto Bin due to an error. Specify a page such as your company's or organization's internal portal site.
    Logout URL The URL of the page that users connected via authentication integration are returned to when they log out of Crypto Bin. This is usually set to the same value as the "Error URL".
    Single Sign-On Service URL The "IdP URL" obtained from TrustLogin
    Primary Certificate (base64) The contents of the "Certificate" obtained from TrustLogin
    Authentication Integration Feature Specify the users to whom SAML SSO applies, according to your operational needs

    05 (4).png

  3. Review the configured settings and click the "Update" button.
    06.png

  4. Click the "Download" button to download the "IdP Configuration File".
    07.png

  5. Go to "Contract Information > Section Information" and note down the URL for "General User (Authentication Integration: Screen Input Type)".
    08.png

  6. In the "Login Method" section of each user's user information screen, you can set whether to allow the target user to also log in using their Crypto Bin ID.
    Authentication integration only

    Login is only possible via SAML SSO

    Also use login with Crypto Bin ID Both SAML SSO and login with Crypto Bin ID are possible

    10.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "General User (Authentication Integration: Screen Input Type)" URL obtained from Crypto Bin
    Metadata Upload the "IdP Configuration File" (sp.xml) obtained from Crypto Bin

    09.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Crypto Bin (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Crypto Bin (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Crypto Bin

Item

Details

Pre-check

  • Prior setup in Crypto Bin is required.

  • You need to create an account in Crypto Bin using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the manual provided by Crypto Bin.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Verification Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Enabled for all users (option to use both SAML authentication and password authentication together)

Notes

This manual has been verified using Crypto Bin v2.18.0.

Table of Contents:

TrustLogin Admin Page Settings

Crypto Bin Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Crypto Bin (SAML)".
    CryptoBin01.png


  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to configuring Crypto Bin.
Do not click the "Register" button yet — open Crypto Bin in a separate window.

Crypto Bin Settings

  1. Log in to the administrator screen, open "Section Settings > Feature Settings > Authentication Integration", and click the "Edit" button.
    04.png

  2. Configure each item as follows, then click the "Confirm Details" button.
    EntityID (IdP) The "Issuer/Entity ID" obtained from TrustLogin
    Error URL The URL of the page that users connected via authentication integration are redirected to when they are logged out of Crypto Bin due to an error. Specify a page such as your company's or organization's internal portal site.
    Logout URL The URL of the page that users connected via authentication integration are returned to when they log out of Crypto Bin. This is usually set to the same value as the "Error URL".
    Single Sign-On Service URL The "IdP URL" obtained from TrustLogin
    Primary Certificate (base64) The contents of the "Certificate" obtained from TrustLogin
    Authentication Integration Feature Specify the users to whom SAML SSO applies, according to your operational needs

    05 (4).png

  3. Review the configured settings and click the "Update" button.
    06.png

  4. Click the "Download" button to download the "IdP Configuration File".
    07.png

  5. Go to "Contract Information > Section Information" and note down the URL for "General User (Authentication Integration: Screen Input Type)".
    08.png

  6. In the "Login Method" section of each user's user information screen, you can set whether to allow the target user to also log in using their Crypto Bin ID.
    Authentication integration only

    Login is only possible via SAML SSO

    Also use login with Crypto Bin ID Both SAML SSO and login with Crypto Bin ID are possible

    10.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "General User (Authentication Integration: Screen Input Type)" URL obtained from Crypto Bin
    Metadata Upload the "IdP Configuration File" (sp.xml) obtained from Crypto Bin

    09.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Crypto Bin (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Crypto Bin (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.