EQ Portal SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in EQ Portal is required.

  • For the latest setup instructions, please check the manual provided by EQ Portal.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

None in particular.

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

EQ Portal Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Prerequisites

EQ Portal's SAML JIT supports the following two patterns.

  1. Synchronize the TrustLogin user's "Last Name" and "First Name" to register new users and manage user information in EQ Portal (group information is not synchronized; group management is performed within EQ Portal)
  2. Synchronize the TrustLogin user's "Last Name", "First Name", and "Group" to register new users and synchronize user information and group information in EQ Portal

If you are not synchronizing group information as in option 2, this prerequisite configuration is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings".


Create a Group and Assign Members

Create a group to map to a group in EQ Portal, and assign members to it.
(If you can operate using an existing group, you may use an existing group instead.)

For instructions on how to create a group and assign members, please refer to the following page.
Register a Group

Note: Due to specifications on the EQ Portal side, please use only single-byte alphanumeric characters and symbols for the TrustLogin group name.

[Configuration Example]

  • Create an "admin" group in TrustLogin and synchronize it with the "Administrator" group in EQ Portal
  • Create a "user" group in TrustLogin and synchronize it with the "General User" group in EQ Portal

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Configure the "Application Name" and "Icon" (optional).
    jit02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
    03.png

  4. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure it as follows.
    For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" icon on the right.
    Note: Only configure the "groupid" row if you are synchronizing group information. If you are not synchronizing group information, this is not required.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    surname Basic surname

    Member

    Member's Last Name

    givenname Basic givenname

    Member

    Member's First Name

    groupid Basic groupid Group Select the configured group name(s) and add them all using the "+" button

    jit04.png

Now, switch to configuring the EQ Portal side.
Do not click the "Register" button yet — open the EQ Portal site in a separate window.

EQ Portal Settings

  1. Open "Settings" in the left menu and turn on the checkbox for "Enable Single Sign-On".
    04.png

  2. When you turn on "Enable Single Sign-On", the "SAML Authentication Settings" section expands. Configure each item as follows.
    Single Sign-On URL The "Identity Provider URL" obtained from TrustLogin
    Enable Signature Verification Turn on the checkbox and upload the "Certificate" obtained from TrustLogin using "File Upload"
    Entity ID Make a note of the value using the "Copy" button

    ACS URL

    Make a note of the value using the "Copy" button
    Single Sign-On Login Button Settings You can choose whether to display the Single Sign-On login button on the EQ Portal login screen. Please select according to your operational needs.
    Single Sign-On Test URL Make a note of the value using the "Copy" button
    User Registration Settings Select "Automatically Register"
    Group Information Update Settings
    • If synchronizing group information → select "Update"
    • If not synchronizing group information → select "Do Not Update"

    jit05.png

  3. Click the "Update" button to save.
    06.png

  4. In "Group Management", open the edit screen for the target group, set the TrustLogin group name to synchronize in "IdP Group ID", and update.
    jit08.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL

    The "Single Sign-On Test URL" obtained from EQ Portal

    Entity ID The "Entity ID" obtained from EQ Portal
    Name ID Format Select "emailAddress"
    ACS URL to Service The "ACS URL" obtained from EQ Portal

    jit07.png

  2. Click the "Register" button to save your settings.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

EQ Portal SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in EQ Portal is required.

  • For the latest setup instructions, please check the manual provided by EQ Portal.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

None in particular.

Table of Contents:

Prerequisites

TrustLogin Admin Page Settings

EQ Portal Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Prerequisites

EQ Portal's SAML JIT supports the following two patterns.

  1. Synchronize the TrustLogin user's "Last Name" and "First Name" to register new users and manage user information in EQ Portal (group information is not synchronized; group management is performed within EQ Portal)
  2. Synchronize the TrustLogin user's "Last Name", "First Name", and "Group" to register new users and synchronize user information and group information in EQ Portal

If you are not synchronizing group information as in option 2, this prerequisite configuration is not required.
Please proceed to the next section, "TrustLogin Admin Page Settings".


Create a Group and Assign Members

Create a group to map to a group in EQ Portal, and assign members to it.
(If you can operate using an existing group, you may use an existing group instead.)

For instructions on how to create a group and assign members, please refer to the following page.
Register a Group

Note: Due to specifications on the EQ Portal side, please use only single-byte alphanumeric characters and symbols for the TrustLogin group name.

[Configuration Example]

  • Create an "admin" group in TrustLogin and synchronize it with the "Administrator" group in EQ Portal
  • Create a "user" group in TrustLogin and synchronize it with the "General User" group in EQ Portal

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Configure the "Application Name" and "Icon" (optional).
    jit02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
    03.png

  4. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure it as follows.
    For the group attribute value, select the group name from the dropdown; you can add multiple groups using the "+" icon on the right.
    Note: Only configure the "groupid" row if you are synchronizing group information. If you are not synchronizing group information, this is not required.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    surname Basic surname

    Member

    Member's Last Name

    givenname Basic givenname

    Member

    Member's First Name

    groupid Basic groupid Group Select the configured group name(s) and add them all using the "+" button

    jit04.png

Now, switch to configuring the EQ Portal side.
Do not click the "Register" button yet — open the EQ Portal site in a separate window.

EQ Portal Settings

  1. Open "Settings" in the left menu and turn on the checkbox for "Enable Single Sign-On".
    04.png

  2. When you turn on "Enable Single Sign-On", the "SAML Authentication Settings" section expands. Configure each item as follows.
    Single Sign-On URL The "Identity Provider URL" obtained from TrustLogin
    Enable Signature Verification Turn on the checkbox and upload the "Certificate" obtained from TrustLogin using "File Upload"
    Entity ID Make a note of the value using the "Copy" button

    ACS URL

    Make a note of the value using the "Copy" button
    Single Sign-On Login Button Settings You can choose whether to display the Single Sign-On login button on the EQ Portal login screen. Please select according to your operational needs.
    Single Sign-On Test URL Make a note of the value using the "Copy" button
    User Registration Settings Select "Automatically Register"
    Group Information Update Settings
    • If synchronizing group information → select "Update"
    • If not synchronizing group information → select "Do Not Update"

    jit05.png

  3. Click the "Update" button to save.
    06.png

  4. In "Group Management", open the edit screen for the target group, set the TrustLogin group name to synchronize in "IdP Group ID", and update.
    jit08.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL

    The "Single Sign-On Test URL" obtained from EQ Portal

    Entity ID The "Entity ID" obtained from EQ Portal
    Name ID Format Select "emailAddress"
    ACS URL to Service The "ACS URL" obtained from EQ Portal

    jit07.png

  2. Click the "Register" button to save your settings.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.