How to Configure SAML Authentication for SS1 Cloud

Item

Details

Pre-check

  • Advance configuration in SS1 Cloud is required.

  • For the latest configuration steps, please refer to the manual provided by SS1 Cloud.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Enabled for all users (SAML authentication and password authentication can be used together, selectable)

Notes

None in particular

Table of Contents:

Preparation

TrustLogin Admin Page Settings

SS1 Cloud Configuration

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Preparation

Add a Custom Attribute to Member Information


Add the SS1 Cloud "Account ID" information as a custom attribute in the TrustLogin member information.

[TrustLogin Custom Attribute Configuration Example]


For instructions on how to configure a custom attribute, see the pages below. The attribute name for the custom attribute can be anything you like.

Custom Attribute Configuration Method (Individual Registration)

Custom Attribute Configuration Method (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "SS1 Cloud (SAML)."

  3. Note down the values for "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png


At this point, switch to configuring the SS1 Cloud side.
Do not click the "Register" button yet. Open SS1 Cloud in a separate window.

SS1 Cloud Configuration

  1. Click "Hamburger Menu > Settings" at the top of the SS1 Cloud screen.

  2. Scroll to the bottom of the settings menu and click "Change" next to "Login Authentication Settings."


  3. Select "Use SAML Authentication for Login," and configure the "IdP Settings" as follows.
    Entity ID The "Issuer/Entity ID" you noted down from TrustLogin
    Login URL The "IdP URL" you noted down from TrustLogin
    Certificate

    Click "Select File" and upload the certificate obtained from TrustLogin




  4. Under "Login Screen Settings," check "Display a Link to the Identity Provider on the Login Screen," and enter a "Display Name."
    (The "Display Name" configured here will be shown on the SS1 Cloud login screen.)

    Check "Allow Login with ID and Password."
    Note: Unchecking this option restricts the login method to SAML only, but we recommend switching to this only after confirming the SAML connection is successful and notifying your users.


  5. Note down the values for "Login URL" and "Entity ID/Metadata ID" under "Settings for the Identity Provider," then click "Update" to save the settings.



    Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID/Metadata ID" you noted down from SS1 Cloud
    Name ID Value Select "Custom Attribute," and choose the attribute name of the custom attribute you configured in "Preparation."
    ACS URL to the Service The "Login URL" you noted down from SS1 Cloud



  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "SS1 Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "SS1 Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for SS1 Cloud

Item

Details

Pre-check

  • Advance configuration in SS1 Cloud is required.

  • For the latest configuration steps, please refer to the manual provided by SS1 Cloud.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Enabled for all users (SAML authentication and password authentication can be used together, selectable)

Notes

None in particular

Table of Contents:

Preparation

TrustLogin Admin Page Settings

SS1 Cloud Configuration

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Preparation

Add a Custom Attribute to Member Information


Add the SS1 Cloud "Account ID" information as a custom attribute in the TrustLogin member information.

[TrustLogin Custom Attribute Configuration Example]


For instructions on how to configure a custom attribute, see the pages below. The attribute name for the custom attribute can be anything you like.

Custom Attribute Configuration Method (Individual Registration)

Custom Attribute Configuration Method (Bulk Registration)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "SS1 Cloud (SAML)."

  3. Note down the values for "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png


At this point, switch to configuring the SS1 Cloud side.
Do not click the "Register" button yet. Open SS1 Cloud in a separate window.

SS1 Cloud Configuration

  1. Click "Hamburger Menu > Settings" at the top of the SS1 Cloud screen.

  2. Scroll to the bottom of the settings menu and click "Change" next to "Login Authentication Settings."


  3. Select "Use SAML Authentication for Login," and configure the "IdP Settings" as follows.
    Entity ID The "Issuer/Entity ID" you noted down from TrustLogin
    Login URL The "IdP URL" you noted down from TrustLogin
    Certificate

    Click "Select File" and upload the certificate obtained from TrustLogin




  4. Under "Login Screen Settings," check "Display a Link to the Identity Provider on the Login Screen," and enter a "Display Name."
    (The "Display Name" configured here will be shown on the SS1 Cloud login screen.)

    Check "Allow Login with ID and Password."
    Note: Unchecking this option restricts the login method to SAML only, but we recommend switching to this only after confirming the SAML connection is successful and notifying your users.


  5. Note down the values for "Login URL" and "Entity ID/Metadata ID" under "Settings for the Identity Provider," then click "Update" to save the settings.



    Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID/Metadata ID" you noted down from SS1 Cloud
    Name ID Value Select "Custom Attribute," and choose the attribute name of the custom attribute you configured in "Preparation."
    ACS URL to the Service The "Login URL" you noted down from SS1 Cloud



  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "SS1 Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "SS1 Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.