How to Configure SAML Authentication for Kinro no Shishi

 Item

Details

Pre-check

  • Prior configuration in Kinro no Shishi is required.

  • The Extended User ID (Extended Employee ID) in Kinro no Shishi must match the custom attribute in TrustLogin.

  • For the latest setup instructions, please check the manual provided by Kinro no Shishi.

Name ID

 

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP Configuration

 

Configured by the Administrator

Request SP to configure

Provisioning

 

API-based Provisioning supported (account management possible in TrustLogin)

 

SAML JITProvisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

  • User information must be registered separately in both the Kinro no Shishi admin screen and personal screen. Note: If user information is registered in only one of the two screens, you will not be able to log in to the screen where it is not registered.
  • If you want to log in via SSO to both the admin screen and personal screen, since a custom attribute is set in TrustLogin, you must set the same value for the "User ID" in the admin screen and the "Employee Code" in the personal screen. If you register the "Extended User ID (Extended Employee ID)" in advance, you must set the same value in both the admin screen and personal screen.

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings

Kinro no Shishi Configuration

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Initial Login Method (Linking Account Information)

 

Preparation

[Optional] Register an "Extended User ID (Extended Employee ID)" in Kinro no Shishi

Register the Extended User ID (Extended Employee ID) in the user information on the Kinro no Shishi side.
Note: This configuration is optional. Even if it is not configured in advance, the information can be linked during the first SSO login. For the linking method, see Initial Login Method (Linking Account Information).

[Admin Screen]
KinroNoShishi08.png

[Personal Screen]KinroNoShishi09.png

 

Add a Custom Attribute to Member Information

Add the Kinro no Shishi User ID (Employee Code) as a custom attribute in the TrustLogin member information. If the Extended User ID (Extended Employee ID) has already been configured on the Kinro no Shishi side, add the Extended User ID (Extended Employee ID) instead.

[TrustLogin Custom Attribute Configuration Example]KinroNoShishi11.png

For instructions on how to configure a custom attribute, see the pages below. The attribute name for the custom attribute can be anything you like.

Custom Attribute Configuration Method (Individual Registration)
  Custom Attribute Configuration Method (Bulk Registration)

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Kinro no Shishi (SAML)".
    KinroNoShishi10.png

  3. From "Identity Provider Information," download the metadata using the "Download Metadata" button.03.png

  4. Save by clicking the "Register" button.

Kinro no Shishi Configuration

  1. Log in to the Kinro no Shishi admin screen and open "Options > SSO Settings."KinroNoShishi02.png


  2. Select "Provider Settings."
    KinroNoShishi03.png

  3. Note down the "Entity ID" and "Response URL" listed under "Provided Information (SAS → Customer)."
    KinroNoShishi05.png

  4. Paste the contents of the metadata you obtained from TrustLogin into "Provided Information (Customer → SAS)" and click the "Register" button.
    KinroNoShishi04.png

 

TrustLogin Admin Page Settings (Continued)

  1. Once you receive confirmation of completed configuration from SAS Co., Ltd., resume the configuration. At this time, the "SSO Login URL" will also be provided, so note down the URL.
    Search for the registered app on the TrustLogin app management screen and open "Change SAML App Settings."KinroNoShishi13.png

  2. Configure the "Service Provider Settings" as follows.
    Login URL

    Kinro no Shishi's "SSO Login URL"

    Note: If you want to log in via SSO to both the admin screen and the personal screen, we recommend registering one of the URLs here and using a bookmark template or your browser's bookmark feature for the other.

    For instructions on how to configure a "bookmark template," click here

    Entity ID The "Entity ID" you noted down from Kinro no Shishi
    Name ID Value Custom attribute — Select the attribute name of the custom attribute configured in "Preparation"
    ACS URL to the Service The "Response URL" you noted down from Kinro no Shishi

    KinroNoShishi12.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "Kinro no Shishi (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "Kinro no Shishi (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

 

Initial Login Method (Linking Account Information)

If the Extended User ID (Extended Employee ID) has not been registered in Kinro no Shishi, the user information will be linked during the first SSO login. Note: This step is not required if the Extended User ID (Extended Employee ID) has already been registered on the Kinro no Shishi side in advance.

  1. Click the app from TrustLogin, or access the Kinro no Shishi SSO Login URL.

  2. The first time, you will need to log in with a password. Enter your user ID and password to log in.
    KinroNoShishi01.png

  3. Once login is complete, the custom attribute linked to the Extended User ID (Extended Employee ID) will be reflected in the Kinro no Shishi user information.

    [Admin Screen User Information]
    KinroNoShishi08.png

    [Personal Information Details]
    KinroNoShishi09.png

  4. From the second login onward, you can log in via SSO without entering a password.

How to Configure SAML Authentication for Kinro no Shishi

 Item

Details

Pre-check

  • Prior configuration in Kinro no Shishi is required.

  • The Extended User ID (Extended Employee ID) in Kinro no Shishi must match the custom attribute in TrustLogin.

  • For the latest setup instructions, please check the manual provided by Kinro no Shishi.

Name ID

 

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP Configuration

 

Configured by the Administrator

Request SP to configure

Provisioning

 

API-based Provisioning supported (account management possible in TrustLogin)

 

SAML JITProvisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

  • User information must be registered separately in both the Kinro no Shishi admin screen and personal screen. Note: If user information is registered in only one of the two screens, you will not be able to log in to the screen where it is not registered.
  • If you want to log in via SSO to both the admin screen and personal screen, since a custom attribute is set in TrustLogin, you must set the same value for the "User ID" in the admin screen and the "Employee Code" in the personal screen. If you register the "Extended User ID (Extended Employee ID)" in advance, you must set the same value in both the admin screen and personal screen.

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings

Kinro no Shishi Configuration

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Initial Login Method (Linking Account Information)

 

Preparation

[Optional] Register an "Extended User ID (Extended Employee ID)" in Kinro no Shishi

Register the Extended User ID (Extended Employee ID) in the user information on the Kinro no Shishi side.
Note: This configuration is optional. Even if it is not configured in advance, the information can be linked during the first SSO login. For the linking method, see Initial Login Method (Linking Account Information).

[Admin Screen]
KinroNoShishi08.png

[Personal Screen]KinroNoShishi09.png

 

Add a Custom Attribute to Member Information

Add the Kinro no Shishi User ID (Employee Code) as a custom attribute in the TrustLogin member information. If the Extended User ID (Extended Employee ID) has already been configured on the Kinro no Shishi side, add the Extended User ID (Extended Employee ID) instead.

[TrustLogin Custom Attribute Configuration Example]KinroNoShishi11.png

For instructions on how to configure a custom attribute, see the pages below. The attribute name for the custom attribute can be anything you like.

Custom Attribute Configuration Method (Individual Registration)
  Custom Attribute Configuration Method (Bulk Registration)

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Kinro no Shishi (SAML)".
    KinroNoShishi10.png

  3. From "Identity Provider Information," download the metadata using the "Download Metadata" button.03.png

  4. Save by clicking the "Register" button.

Kinro no Shishi Configuration

  1. Log in to the Kinro no Shishi admin screen and open "Options > SSO Settings."KinroNoShishi02.png


  2. Select "Provider Settings."
    KinroNoShishi03.png

  3. Note down the "Entity ID" and "Response URL" listed under "Provided Information (SAS → Customer)."
    KinroNoShishi05.png

  4. Paste the contents of the metadata you obtained from TrustLogin into "Provided Information (Customer → SAS)" and click the "Register" button.
    KinroNoShishi04.png

 

TrustLogin Admin Page Settings (Continued)

  1. Once you receive confirmation of completed configuration from SAS Co., Ltd., resume the configuration. At this time, the "SSO Login URL" will also be provided, so note down the URL.
    Search for the registered app on the TrustLogin app management screen and open "Change SAML App Settings."KinroNoShishi13.png

  2. Configure the "Service Provider Settings" as follows.
    Login URL

    Kinro no Shishi's "SSO Login URL"

    Note: If you want to log in via SSO to both the admin screen and the personal screen, we recommend registering one of the URLs here and using a bookmark template or your browser's bookmark feature for the other.

    For instructions on how to configure a "bookmark template," click here

    Entity ID The "Entity ID" you noted down from Kinro no Shishi
    Name ID Value Custom attribute — Select the attribute name of the custom attribute configured in "Preparation"
    ACS URL to the Service The "Response URL" you noted down from Kinro no Shishi

    KinroNoShishi12.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "Kinro no Shishi (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it and click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "Kinro no Shishi (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

 

Initial Login Method (Linking Account Information)

If the Extended User ID (Extended Employee ID) has not been registered in Kinro no Shishi, the user information will be linked during the first SSO login. Note: This step is not required if the Extended User ID (Extended Employee ID) has already been registered on the Kinro no Shishi side in advance.

  1. Click the app from TrustLogin, or access the Kinro no Shishi SSO Login URL.

  2. The first time, you will need to log in with a password. Enter your user ID and password to log in.
    KinroNoShishi01.png

  3. Once login is complete, the custom attribute linked to the Extended User ID (Extended Employee ID) will be reflected in the Kinro no Shishi user information.

    [Admin Screen User Information]
    KinroNoShishi08.png

    [Personal Information Details]
    KinroNoShishi09.png

  4. From the second login onward, you can log in via SSO without entering a password.