How to Configure SAML Authentication for LegalOn

Item

Details

Prerequisites

  • Advance configuration on the LegalOn side is required.

  • You must create an account in LegalOn using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by LegalOn.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Enabled only for users with the email domain specified by the SP

Remarks

None in particular

Table of Contents:

Configuring the TrustLogin Admin Page

Configuring LegalOn

Configuring the TrustLogin Admin Page (Continued)

Configuring TrustLogin Users

How to Log In

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "LegalOn (SAML)."
    02.png

  3. Make a note of the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, switch over to the LegalOn side configuration.
Do not click the "Register" button yet; open LegalOn in a separate window.

Configuring LegalOn

  1. From the menu in the upper left, open "Administrator Settings," then open "SSO Settings" from the left-side menu.
    Configure each item as follows, and save by clicking the "Register" button.
    Endpoint URL Copy the value and make a note of it
    Entity ID Copy the value and make a note of it
    Email Domain

    Set the domain of the email address you use
    Note: Please be careful not to set a domain you do not own, or a general domain (such as gmail.com).

    IdP Endpoint URL The "IdP URL" obtained from TrustLogin
    Public Key Certificate Used by the IdP for Signing The contents of the "certificate" obtained from TrustLogin

    04.png

  2. When you turn on "Use SSO," a message will be displayed. Check it and enable the setting.
    05.png

If you enable SSO while the configuration contains an error, you will be unable to log in once you close the browser or log out.
Keep the SSO settings screen open, complete the TrustLogin-side configuration described in the next section, and then verify that SSO succeeds using a different browser or the same browser's private/incognito mode before closing the SSO settings screen.

Configuring the TrustLogin Admin Page (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from LegalOn
    ACS URL to the Service The "Endpoint URL" obtained from LegalOn

    06.png

  2. Save by clicking the "Register" button.

Configuring TrustLogin Users

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "LegalOn (SAML)," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "LegalOn (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In

① When Logging In Using "LegalOn (SAML)"

When you launch "LegalOn (SAML)" from TrustLogin's My Page or the browser extension, you will be taken to the LegalOn login screen. Click the "Get Started" button, enter your email address, and proceed by clicking "Continue" to complete the login.
07.png

08.png

② When Using the Auxiliary App

This is included in the login behavior described in ①. We also provide an auxiliary app that lets you skip the steps of clicking the "Get Started" button, entering your email address, and proceeding by clicking "Continue." Please register the "[For SAML Auxiliary Use] LegalOn" app to use it.
Note: The auxiliary app can only be used in a PC browser.


Add the app using the same procedure as a normal app registration, either as the administrator or by the user themselves.
09.png

How to Configure SAML Authentication for LegalOn

Item

Details

Prerequisites

  • Advance configuration on the LegalOn side is required.

  • You must create an account in LegalOn using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by LegalOn.

Name ID

Email address

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Enabled only for users with the email domain specified by the SP

Remarks

None in particular

Table of Contents:

Configuring the TrustLogin Admin Page

Configuring LegalOn

Configuring the TrustLogin Admin Page (Continued)

Configuring TrustLogin Users

How to Log In

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "LegalOn (SAML)."
    02.png

  3. Make a note of the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png

Now, switch over to the LegalOn side configuration.
Do not click the "Register" button yet; open LegalOn in a separate window.

Configuring LegalOn

  1. From the menu in the upper left, open "Administrator Settings," then open "SSO Settings" from the left-side menu.
    Configure each item as follows, and save by clicking the "Register" button.
    Endpoint URL Copy the value and make a note of it
    Entity ID Copy the value and make a note of it
    Email Domain

    Set the domain of the email address you use
    Note: Please be careful not to set a domain you do not own, or a general domain (such as gmail.com).

    IdP Endpoint URL The "IdP URL" obtained from TrustLogin
    Public Key Certificate Used by the IdP for Signing The contents of the "certificate" obtained from TrustLogin

    04.png

  2. When you turn on "Use SSO," a message will be displayed. Check it and enable the setting.
    05.png

If you enable SSO while the configuration contains an error, you will be unable to log in once you close the browser or log out.
Keep the SSO settings screen open, complete the TrustLogin-side configuration described in the next section, and then verify that SSO succeeds using a different browser or the same browser's private/incognito mode before closing the SSO settings screen.

Configuring the TrustLogin Admin Page (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Entity ID The "Entity ID" obtained from LegalOn
    ACS URL to the Service The "Endpoint URL" obtained from LegalOn

    06.png

  2. Save by clicking the "Register" button.

Configuring TrustLogin Users

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "LegalOn (SAML)," and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "LegalOn (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In

① When Logging In Using "LegalOn (SAML)"

When you launch "LegalOn (SAML)" from TrustLogin's My Page or the browser extension, you will be taken to the LegalOn login screen. Click the "Get Started" button, enter your email address, and proceed by clicking "Continue" to complete the login.
07.png

08.png

② When Using the Auxiliary App

This is included in the login behavior described in ①. We also provide an auxiliary app that lets you skip the steps of clicking the "Get Started" button, entering your email address, and proceeding by clicking "Continue." Please register the "[For SAML Auxiliary Use] LegalOn" app to use it.
Note: The auxiliary app can only be used in a PC browser.


Add the app using the same procedure as a normal app registration, either as the administrator or by the user themselves.
09.png