|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
|
Email address |
| 〇 |
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
|
|
SP Configuration |
|
Configured by the Administrator |
| 〇 |
Request SP to configure |
|
|
Provisioning |
API-based Provisioning supported (account management possible in TrustLogin) |
|
|
SAML JITProvisioning supported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
|
〇 |
Other: Enabled for all users (both SAML authentication and password authentication available) |
|
|
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Settings |
Preparation
[Optional] Register an "Extended User ID (Extended Employee ID)" in Kinro no Shishi
Register the Extended User ID (Extended Employee ID) in the user information on the Kinro no Shishi side.
Note: This configuration is optional. Even if it is not configured in advance, the information can be linked during the first SSO login. For the linking method, see Initial Login Method (Linking Account Information).
[Admin Screen]
[Personal Screen]
Add a Custom Attribute to Member Information
Add the Kinro no Shishi User ID (Employee Code) as a custom attribute in the TrustLogin member information. If the Extended User ID (Extended Employee ID) has already been configured on the Kinro no Shishi side, add the Extended User ID (Extended Employee ID) instead.
[TrustLogin Custom Attribute Configuration Example]
For instructions on how to configure a custom attribute, see the pages below. The attribute name for the custom attribute can be anything you like.
Custom Attribute Configuration Method (Individual Registration)
Custom Attribute Configuration Method (Bulk Registration)
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Kinro no Shishi (SAML)".
- From "Identity Provider Information," download the metadata using the "Download Metadata" button.
- Save by clicking the "Register" button.
Kinro no Shishi Configuration
- Log in to the Kinro no Shishi admin screen and open "Options > SSO Settings."
- Select "Provider Settings."
- Note down the "Entity ID" and "Response URL" listed under "Provided Information (SAS → Customer)."
- Paste the contents of the metadata you obtained from TrustLogin into "Provided Information (Customer → SAS)" and click the "Register" button.
TrustLogin Admin Page Settings (Continued)
- Once you receive confirmation of completed configuration from SAS Co., Ltd., resume the configuration. At this time, the "SSO Login URL" will also be provided, so note down the URL.
Search for the registered app on the TrustLogin app management screen and open "Change SAML App Settings."
- Configure the "Service Provider Settings" as follows.
Login URL Kinro no Shishi's "SSO Login URL"
Note: If you want to log in via SSO to both the admin screen and the personal screen, we recommend registering one of the URLs here and using a bookmark template or your browser's bookmark feature for the other.
For instructions on how to configure a "bookmark template," click here
Entity ID The "Entity ID" you noted down from Kinro no Shishi Name ID Value Custom attribute — Select the attribute name of the custom attribute configured in "Preparation" ACS URL to the Service The "Response URL" you noted down from Kinro no Shishi
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "Kinro no Shishi (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it and click the "Register" button.
② When an Administrator Adds Members
- Search for and click the "Kinro no Shishi (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
Initial Login Method (Linking Account Information)
If the Extended User ID (Extended Employee ID) has not been registered in Kinro no Shishi, the user information will be linked during the first SSO login. Note: This step is not required if the Extended User ID (Extended Employee ID) has already been registered on the Kinro no Shishi side in advance.
- Click the app from TrustLogin, or access the Kinro no Shishi SSO Login URL.
- The first time, you will need to log in with a password. Enter your user ID and password to log in.
- Once login is complete, the custom attribute linked to the Extended User ID (Extended Employee ID) will be reflected in the Kinro no Shishi user information.
[Admin Screen User Information]
[Personal Information Details]
- From the second login onward, you can log in via SSO without entering a password.