How to Configure Bio-IDiom Facial Recognition SSO External IdP Integration

This page explains how to use NEC Corporation's Bio-IDiom Facial Recognition SSO as a SAML Identity Provider (IdP)
and integrate it with TrustLogin.

Configuration is performed on both the Bio-IDiom Facial Recognition SSO side and the TrustLogin Admin Page.

Prerequisites

  • A TrustLogin Pro Plan or optional contract is required to use this feature.
    For pricing, click here
  • This assumes that authenticator information, photos, and other prior setup have already been completed on the Bio-IDiom Facial Recognition SSO side.
    For prior setup and the latest configuration procedures, after contracting for Bio-IDiom Facial Recognition SSO,
    please refer to the manual available from NEC Cloud Services.
  • If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
    Note: we recommend that administrator users be assigned password authentication in case of emergency.
     Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords

Configuration Steps

Preparation

Replace the {TenantID} (tenant ID) portion of the URL below with your ID, access it, and obtain the SAML Metadata. (This will be used when configuring the TrustLogin side.)

https://sso.bio-auth.com/auth/realms/{TenantID}/protocol/saml/descriptor

Configuration on the Bio-IDiom Facial Recognition SSO Side

Note: For the latest configuration procedures, please refer to the manual provided by NEC Cloud Services.

  1. Log in to the Bio-IDiom Facial Recognition SSO admin screen and go to the "Settings > Clients" screen.
    BioAuth01.png
  2. Click the "Create" button in the upper right of the screen.
    BioAuth02.png
  3. On the Add Client screen, set the following values and click "Save".

    Item Setting Value / Details
    Client ID trustlogin-saml-sp
    Client Protocol saml

    BioAuth27.png

  4. On the Client Details screen, set values for the following items.
    Note: for any values not set in this procedure, the default values are fine. (Settings Item List)

    Item Setting Value / Details
    Client ID (Note: already set in Step 3) trustlogin-saml-sp
    Name ID Format username
    Valid Redirect URIs https://portal.trustlogin.com/saml/acs
    SAML Endpoint Advanced Settings
    > Assertion Consumer Service POST Binding URL
    https://portal.trustlogin.com/saml/acs
    Authentication Flow Overrides
    > Browser Flow
    bis_webapp

  5. Click "Save" to save the settings.
    BioAuth08.png
  6. Open the "Mappers" tab of the client configuration you created, and click "Create".
    BioAuth26.png
  7. On the "Create Protocol Mapper" screen, set the following values and click "Save".

    Item Setting Value / Details
    Name NameID
    Mapper Type User Attribute Mapper For NameID
    Name ID Format urn:oasis:names:SAML:1.1:nameid-format:emailAddress
    User Attribute username

    BioAuth09.png

    This completes the configuration on the Bio-IDiom Facial Recognition SSO side.
    Next, configure the TrustLogin side.

Configuration on the TrustLogin Side

  1. Log in to TrustLogin,
    and open "Settings > Optional Features > External IdP Integration > Settings" on the Admin Page.
    BioAuth13.png
  2. Click "Add SAML IdP".
    BioAuth14.png
  3. On the "Create SAML Identity Provider" screen, enter the following information.

    Item Setting Value / Details
    Name Enter any name you like.
    Example: Bio-IDiom Facial Recognition SSO
    SSO URL Preparation > the endpoint URL in the obtained metadata (the value of Location)
    BioAuth17.png
    Entity ID Preparation > the entity ID in the obtained metadata (the value of entityID)
    BioAuth18.png
    SAML Identity Provider Certificate Preparation > the certificate information in the obtained metadata (the value of X509Certificate)
    BioAuth19.png
    NameID Format Specifies the format to send as the NameID.
    Preparation > select the value that matches the specified format.

    Note: for details, click here
    Preferred NameID Attribute Specifies the member attribute to prioritize when matching the NameID.

    Note: for details, click here
    Case Sensitivity Specifies whether to distinguish between uppercase and lowercase letters when matching the NameID.
    Note: for details, click here


  4. Click "Register".
    BioAuth16.png
  5. Next, assign the members who will log in with their Bio-IDiom Facial Recognition SSO ID.
    Click "Add Member". (To add by group, click "Add Group".)
    BioAuth20.png
  6. Select the target members and click the "Register" button.
    BioAuth21.png

    The member addition is complete.
    This completes the configuration.

Verifying the Configuration

From the TrustLogin login page, enter your Company ID and email address, and confirm that you can log in using facial recognition.

BioAuth22.png
BioAuth23.png

If multiple authentication methods are assigned, log in using the button for the configured external IdP name.
BioAuth24.png

Note: the button name can be changed on the settings screen.
BioAuth25.png

Notes

  • Client Detailed Settings Item List
    BioAuth28.png

    Note: to return to the procedure, click here

How to Configure Bio-IDiom Facial Recognition SSO External IdP Integration

This page explains how to use NEC Corporation's Bio-IDiom Facial Recognition SSO as a SAML Identity Provider (IdP)
and integrate it with TrustLogin.

Configuration is performed on both the Bio-IDiom Facial Recognition SSO side and the TrustLogin Admin Page.

Prerequisites

  • A TrustLogin Pro Plan or optional contract is required to use this feature.
    For pricing, click here
  • This assumes that authenticator information, photos, and other prior setup have already been completed on the Bio-IDiom Facial Recognition SSO side.
    For prior setup and the latest configuration procedures, after contracting for Bio-IDiom Facial Recognition SSO,
    please refer to the manual available from NEC Cloud Services.
  • If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
    Note: we recommend that administrator users be assigned password authentication in case of emergency.
     Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords

Configuration Steps

Preparation

Replace the {TenantID} (tenant ID) portion of the URL below with your ID, access it, and obtain the SAML Metadata. (This will be used when configuring the TrustLogin side.)

https://sso.bio-auth.com/auth/realms/{TenantID}/protocol/saml/descriptor

Configuration on the Bio-IDiom Facial Recognition SSO Side

Note: For the latest configuration procedures, please refer to the manual provided by NEC Cloud Services.

  1. Log in to the Bio-IDiom Facial Recognition SSO admin screen and go to the "Settings > Clients" screen.
    BioAuth01.png
  2. Click the "Create" button in the upper right of the screen.
    BioAuth02.png
  3. On the Add Client screen, set the following values and click "Save".

    Item Setting Value / Details
    Client ID trustlogin-saml-sp
    Client Protocol saml

    BioAuth27.png

  4. On the Client Details screen, set values for the following items.
    Note: for any values not set in this procedure, the default values are fine. (Settings Item List)

    Item Setting Value / Details
    Client ID (Note: already set in Step 3) trustlogin-saml-sp
    Name ID Format username
    Valid Redirect URIs https://portal.trustlogin.com/saml/acs
    SAML Endpoint Advanced Settings
    > Assertion Consumer Service POST Binding URL
    https://portal.trustlogin.com/saml/acs
    Authentication Flow Overrides
    > Browser Flow
    bis_webapp

  5. Click "Save" to save the settings.
    BioAuth08.png
  6. Open the "Mappers" tab of the client configuration you created, and click "Create".
    BioAuth26.png
  7. On the "Create Protocol Mapper" screen, set the following values and click "Save".

    Item Setting Value / Details
    Name NameID
    Mapper Type User Attribute Mapper For NameID
    Name ID Format urn:oasis:names:SAML:1.1:nameid-format:emailAddress
    User Attribute username

    BioAuth09.png

    This completes the configuration on the Bio-IDiom Facial Recognition SSO side.
    Next, configure the TrustLogin side.

Configuration on the TrustLogin Side

  1. Log in to TrustLogin,
    and open "Settings > Optional Features > External IdP Integration > Settings" on the Admin Page.
    BioAuth13.png
  2. Click "Add SAML IdP".
    BioAuth14.png
  3. On the "Create SAML Identity Provider" screen, enter the following information.

    Item Setting Value / Details
    Name Enter any name you like.
    Example: Bio-IDiom Facial Recognition SSO
    SSO URL Preparation > the endpoint URL in the obtained metadata (the value of Location)
    BioAuth17.png
    Entity ID Preparation > the entity ID in the obtained metadata (the value of entityID)
    BioAuth18.png
    SAML Identity Provider Certificate Preparation > the certificate information in the obtained metadata (the value of X509Certificate)
    BioAuth19.png
    NameID Format Specifies the format to send as the NameID.
    Preparation > select the value that matches the specified format.

    Note: for details, click here
    Preferred NameID Attribute Specifies the member attribute to prioritize when matching the NameID.

    Note: for details, click here
    Case Sensitivity Specifies whether to distinguish between uppercase and lowercase letters when matching the NameID.
    Note: for details, click here


  4. Click "Register".
    BioAuth16.png
  5. Next, assign the members who will log in with their Bio-IDiom Facial Recognition SSO ID.
    Click "Add Member". (To add by group, click "Add Group".)
    BioAuth20.png
  6. Select the target members and click the "Register" button.
    BioAuth21.png

    The member addition is complete.
    This completes the configuration.

Verifying the Configuration

From the TrustLogin login page, enter your Company ID and email address, and confirm that you can log in using facial recognition.

BioAuth22.png
BioAuth23.png

If multiple authentication methods are assigned, log in using the button for the configured external IdP name.
BioAuth24.png

Note: the button name can be changed on the settings screen.
BioAuth25.png

Notes

  • Client Detailed Settings Item List
    BioAuth28.png

    Note: to return to the procedure, click here