|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
|
Email address |
| 〇 |
Custom attribute Note: For instructions on setting up a custom attribute, see here |
|
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure this |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible) |
||
|
〇 |
None |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: |
|
|
Notes |
None in particular |
|
|
Table of Contents: TrustLogin Admin Page Settings |
Preparation
Add a Custom Attribute to Member Information
Add the SS1 Cloud "Account ID" information as a custom attribute in the TrustLogin member information.
[TrustLogin Custom Attribute Configuration Example]
For instructions on how to configure a custom attribute, see the pages below. The attribute name for the custom attribute can be anything you like.
Custom Attribute Configuration Method (Individual Registration)
Custom Attribute Configuration Method (Bulk Registration)
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "SS1 Cloud (SAML)."
-
Note down the values for "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
At this point, switch to configuring the SS1 Cloud side.
Do not click the "Register" button yet. Open SS1 Cloud in a separate window.
SS1 Cloud Configuration
- Click "Hamburger Menu > Settings" at the top of the SS1 Cloud screen.
- Scroll to the bottom of the settings menu and click "Change" next to "Login Authentication Settings."
- Select "Use SAML Authentication for Login," and configure the "IdP Settings" as follows.
Entity ID The "Issuer/Entity ID" you noted down from TrustLogin Login URL The "IdP URL" you noted down from TrustLogin Certificate Click "Select File" and upload the certificate obtained from TrustLogin
- Under "Login Screen Settings," check "Display a Link to the Identity Provider on the Login Screen," and enter a "Display Name."
(The "Display Name" configured here will be shown on the SS1 Cloud login screen.)
Check "Allow Login with ID and Password."
Note: Unchecking this option restricts the login method to SAML only, but we recommend switching to this only after confirming the SAML connection is successful and notifying your users.
- Note down the values for "Login URL" and "Entity ID/Metadata ID" under "Settings for the Identity Provider," then click "Update" to save the settings.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Entity ID The "Entity ID/Metadata ID" you noted down from SS1 Cloud Name ID Value Select "Custom Attribute," and choose the attribute name of the custom attribute you configured in "Preparation." ACS URL to the Service The "Login URL" you noted down from SS1 Cloud
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "SS1 Cloud (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it and click the "Register" button.
② When an Administrator Adds Members
- Search for and click the "SS1 Cloud (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.