|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Provisioning via API supported (account management possible in TrustLogin) |
|
| 〇 |
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
|
|
|
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
|
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for SSO users |
|
|
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Configuration |
Prerequisites
Note: Configure this section only if you want to link and manage the "User Name" and "Permission Group" in Synergy!'s user information using custom attributes from TrustLogin member information.
If you are not linking these, no configuration is required. Please proceed to the next step.
① "User Name"
If you do not configure linkage via a custom attribute, the TrustLogin email address will be set as the user name. You can also specify an existing custom attribute or a member information field such as "Last Name" or "Email Address".
② "Permission Group"
If you do not configure linkage via a custom attribute, the "Default Permission Group" configured in Synergy! will be assigned when the user is created. Changes to the permission group are made by the administrator in Synergy! .
Add a Custom Attribute to User Information
Add the Synergy! "Member ID" information as a custom attribute in TrustLogin member information. The attribute name for the custom attribute can be anything you choose.
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure custom attributes.
Custom Attribute Setup (Individual Registration)
Custom Attribute Setup (Bulk Registration)
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button at the top right of the screen.
- Configure the "Application Name" and "Icon" (optional).
- Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
At this point, switch over to configuring the Synergy! side.
Do not click the "Register" button yet — open Synergy! in a separate window.
Synergy! Configuration
- Open "Other > Common Settings > SSO Management" and click "Create New".
- Enter any name (e.g., TrustLogin) for "SSO Configuration Name" and click "Create".
- Configure each item as follows, and finally save by clicking "Save Settings".
Entity ID Make a note of the value using the "Copy" button ACS URL Make a note of the value using the "Copy" button Default Permission Group Specify the permission group to be assigned by default when a new user is created
(if linkage is configured, the linkage settings take priority)SAML 2.0 Metadata The contents of the metadata obtained from TrustLogin Enable SSO Configuration ON
Return to the TrustLogin admin page again.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Value for Name ID Member - email Entity ID The "Entity ID" obtained from Synergy! ACS URL to Service The "ACS URL" obtained from Synergy!
-
Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
Note: "email" does not need to be configured if "Value for Name ID" is set to "Member - Email Address". If you use something other than the email address for the Name ID, configure it as shown in the table below.
Note: "displayName" and "authorityGroupId" only need to be configured if you are setting up linkage.
(*) You can also select existing TrustLogin member information (such as email address or last name).Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value email Unspecified email Member
Email Address
displayName Unspecified displayName Custom Attribute (*)
Select the custom attribute configured in Prerequisites (*)
authorityGroupId Unspecified authorityGroupId Custom Attribute
Select the custom attribute configured in Prerequisites
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a User Adds the App via My Page
Note: The SAML app must be configured in advance by an administrator.
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > Apps" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.