Note: SAML authentication can be used with the web browser, desktop app, and mobile app.
Note: Prior setup on the Nulab side is required.
Note: For the latest setup instructions, please refer to the manual provided by Nulab.
If you use multiple services linked to Nulab Pass, after completing the SAML setup in this manual, please also refer to the following manual.
How to Use a Single SAML Authentication Setup for Multiple Apps
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Corporate App" screen and select "Nulab Pass (Backlog / Cacoo) (SAML)".
- Make a note of the "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate from "Get Certificate". (You will need these later when configuring settings on the Nulab side.)
Now, let's move on to the settings on the Nulab Pass side.
Do not click the "Register" button yet — open the Nulab Pass page in a separate tab.
Nulab Pass Settings
- Log in to either Backlog or Cacoo (whichever you use) with an administrator account, and go to the SAML settings screen.
【For Backlog】Click "Organization Name > Organization Settings" at the top right of the admin settings screen
【For Cacoo】Click "Organization Name > Settings" at the top right of the admin settings screen, then "Edit" below the organization name
(For Cacoo)
- Open the "Domain" item and add a TXT record containing the displayed authentication code to the DNS records of the target domain to be verified.
Note: The DNS record setup procedure varies depending on your domain registrar. Please refer to your domain registrar's help documentation. It may take up to approximately 72 hours for DNS records to propagate.
- After adding the TXT record, enter the target domain and click the "Verify" button to verify it.
Once verified, "Verified" will be displayed in the domain list below.
- Open the "Authentication" item and click the "Change" button.
-
Make a note of the displayed "SP Entity ID" and "SP Endpoint URL (ACS)" information.
Set the "IdP Entity ID", "IdP Endpoint URL", and "X.509 Certificate (Base64)" as follows, then click the "Apply" button.IdP Entity ID The "Issuer / Entity ID" you noted from TrustLogin IdP Endpoint URL The "IdP URL" you noted from TrustLogin X.509 Certificate (Base64) Open the "certificate" you downloaded from TrustLogin in a text editor or similar application, and copy and paste the entire contents
- Migrate the accounts that will use SAML authentication to "Managed Accounts".
Open the "Members" screen and click "Migrate Existing Accounts". Checkboxes will appear next to accounts that can be migrated (email addresses in the verified domain); check the accounts to migrate and click "Next".
A message will be displayed; click "Send".
The target members should follow the instructions in the email they receive to migrate to a managed account. Once migration is complete, they will be able to log in using SAML authentication.
Now, let's go back to the TrustLogin settings.
TrustLogin Admin Page Settings (Registering SP Information)
-
Register the information you noted from Nulab into each field of "Service Provider Settings" as follows.
Entity ID The "SP Entity ID" you noted from Nulab ACS URL for the Service The "SP Endpoint URL (ACS)" you noted from Nulab
- Click the "Register" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Nulab Pass (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter a new one, then click the "Register" button.
- Click the app on "My Page" or in the browser extension, and confirm that login succeeds.
② When an administrator adds a member
- In the "Admin Page > Apps" menu, search for and click the "Nulab Pass (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.