How to Configure SAML Authentication for Kairos3

Item

Details

Pre-check

  • Prior configuration in Kairos3 is required.

  • You must create an account in Kairos3 using the same email address as your TrustLogin account.

  • For the latest setup instructions, please check the manual provided by Kairos3.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, click here

SP Configuration

Configured by the administrator

Request the SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all (SAML authentication only)

Other: Enabled for all (both SAML authentication and password authentication can be selected)

Notes

None in particular

Table of Contents:

TrustLogin Admin Page Settings

Kairos3 Settings

TrustLogin Admin Page Settings (Continued)

Kairos3 Settings (Continued)

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Kairos3 (SAML)".
    02.png

  3. Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, let's move on to the Kairos3 settings.
Do not click the "Register" button yet — open Kairos3 in a separate window.

Kairos3 Settings

  1. Log in with an administrator account and click "Admin Tools" > "Single Sign-On".
    04.png

  2. Click "Login via Single Sign-On" to switch it ON.
    05.png

  3. Configure each item as follows.
    Note: Do not click the "Save Settings" button yet.
    Entity ID (SP Information) Make a note of it using the "Copy" button
    Login URL (ACS URL) Make a note of it using the "Copy" button
    Entity ID (IdP Information) The "Issuer/Entity ID" obtained from TrustLogin
    Login URL (IdP Information) The "IdP URL" obtained from TrustLogin
    X.509 Certificate The contents of the "Certificate" obtained from TrustLogin

    06.png

Now, return to the TrustLogin Admin Page.
Keep the Kairos3 page open.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from Kairos3
    ACS URL to Service The "Login URL (ACS URL)" obtained from Kairos3

    07.png

  2. Save by clicking the "Register" button.

  3. Since a connection check is performed at the same time as saving the Kairos3 settings, add the administrator who performed the configuration as a user to the "Kairos3 (SAML)" app you created.
    For how to add a user, please refer to "TrustLogin User Settings".

Now, return to the Kairos3 page.

Kairos3 Settings (Continued)

  1. Click the "Save Settings" button at the bottom of the page.
    08.png

  2. Click "OK" on the confirmation message that appears, and once the setup completion screen is displayed, the configuration is complete.
    Click "Login via Single Sign-On" to log in again.
    09.png

  3. If you want to restrict users' login method to SAML SSO only, click "Password Login Settings" in the upper right, and turn Password Login Settings "OFF".
    Note: Password-based login will no longer be possible, so please make this switch only after notifying users.
    Note: Disabling password login will also disable login via the "Kairos3 Sales" mobile app.

    10.png

    11.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Kairos3 (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Kairos3 (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Kairos3

Item

Details

Pre-check

  • Prior configuration in Kairos3 is required.

  • You must create an account in Kairos3 using the same email address as your TrustLogin account.

  • For the latest setup instructions, please check the manual provided by Kairos3.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, click here

SP Configuration

Configured by the administrator

Request the SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all (SAML authentication only)

Other: Enabled for all (both SAML authentication and password authentication can be selected)

Notes

None in particular

Table of Contents:

TrustLogin Admin Page Settings

Kairos3 Settings

TrustLogin Admin Page Settings (Continued)

Kairos3 Settings (Continued)

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Kairos3 (SAML)".
    02.png

  3. Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, let's move on to the Kairos3 settings.
Do not click the "Register" button yet — open Kairos3 in a separate window.

Kairos3 Settings

  1. Log in with an administrator account and click "Admin Tools" > "Single Sign-On".
    04.png

  2. Click "Login via Single Sign-On" to switch it ON.
    05.png

  3. Configure each item as follows.
    Note: Do not click the "Save Settings" button yet.
    Entity ID (SP Information) Make a note of it using the "Copy" button
    Login URL (ACS URL) Make a note of it using the "Copy" button
    Entity ID (IdP Information) The "Issuer/Entity ID" obtained from TrustLogin
    Login URL (IdP Information) The "IdP URL" obtained from TrustLogin
    X.509 Certificate The contents of the "Certificate" obtained from TrustLogin

    06.png

Now, return to the TrustLogin Admin Page.
Keep the Kairos3 page open.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from Kairos3
    ACS URL to Service The "Login URL (ACS URL)" obtained from Kairos3

    07.png

  2. Save by clicking the "Register" button.

  3. Since a connection check is performed at the same time as saving the Kairos3 settings, add the administrator who performed the configuration as a user to the "Kairos3 (SAML)" app you created.
    For how to add a user, please refer to "TrustLogin User Settings".

Now, return to the Kairos3 page.

Kairos3 Settings (Continued)

  1. Click the "Save Settings" button at the bottom of the page.
    08.png

  2. Click "OK" on the confirmation message that appears, and once the setup completion screen is displayed, the configuration is complete.
    Click "Login via Single Sign-On" to log in again.
    09.png

  3. If you want to restrict users' login method to SAML SSO only, click "Password Login Settings" in the upper right, and turn Password Login Settings "OFF".
    Note: Password-based login will no longer be possible, so please make this switch only after notifying users.
    Note: Disabling password login will also disable login via the "Kairos3 Sales" mobile app.

    10.png

    11.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Kairos3 (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Kairos3 (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.