|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled for all users (SAML authentication and password authentication can be used together) |
|
|
Notes |
None. |
|
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "YOMEL (SAML)".
- Note the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, switch to the YOMEL configuration.
Do not click the "Register" button yet; open YOMEL in a separate window.
YOMEL Settings
- Log in with an administrator account and click "Space Settings > Open SAML SSO Settings".
- Click "Show Service Provider Information".
- Use the "Copy" button to obtain and note the values of "Audience", "ACS URL", and "Single Sign On URL" shown in the displayed information.
Click the "Close" button to close the window.
- Click "Open SAML SSO Initial Settings".
- Configure the SAML SSO initial settings as follows, and save by clicking "Save Settings".
Single SignON Post URL The "Identity Provider URL" obtained from TrustLogin X.509 Certificate The contents of the "Certificate" obtained from TrustLogin
Leave the YOMEL page open and return to the TrustLogin Admin Page.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Login URL The "Single Sign On URL" obtained from YOMEL Entity ID The "Audience" obtained from YOMEL ACS URL for the Service The "ACS URL" obtained from YOMEL
- Save by clicking the "Register" button.
- Since you will perform a connection test in YOMEL next, refer to "TrustLogin User Settings" and add the administrator user who configured the settings to the registered "YOMEL (SAML)".
Return to the YOMEL page again.
YOMEL Settings (Continued)
- Click "Connect to IdP and Test Whether the Settings Are Correct".
- Confirm that the test connection was successful, and enable it via "Enable SSO".
- For users to perform SAML SSO, the "Linked IdP Account" must be configured.
① When the administrator configures the "Linked IdP Account"
Open the user information edit screen for the target user from "User Management", and set the user's TrustLogin email address in "Linked IdP Account". You can also bulk-update multiple users' information via CSV. For details, please refer to YOMEL's help documentation.
② When allowing users to configure the "Linked IdP Account" themselves
The administrator turns on "Allow Users to Configure Their Own SSO Linking Settings" in the SAML SSO settings. Add the target users to "YOMEL (SAML)" as registered in TrustLogin.
The user opens "Preferences" from the icon in the upper right and clicks "Link SSO Account".
If the user is already logged in to TrustLogin, the linking is completed automatically.
If the user is not logged in to TrustLogin, they will be redirected to the TrustLogin login screen. Linking is completed once they log in.
- (Optional) Turning on "Force SSO Login for All Users" restricts users' login method to SAML SSO only. To turn on this setting, all users must have completed their "Linked IdP Account" configuration.
- (Optional) After SSO is enabled, you can change the label of the "SSO Login" button displayed on the YOMEL login screen to any text you like.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "YOMEL (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an administrator adds members
- Search for and click the "YOMEL (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In
[Logging in from a PC/Mobile Browser]
When you run the SAML app from TrustLogin's My Page or the browser extension, the YOMEL login screen opens. Click the SSO login button to complete the login.
[Logging in from the Smartphone App or PC App]
Enter your "Space ID" and proceed to log in. On the smartphone app, an in-app browser will open, and on the PC app, you will be redirected to a browser, where the YOMEL login screen opens. As with logging in from a PC/mobile browser, click the SSO login button to complete the login.