This page explains how to use NEC Corporation's Bio-IDiom Facial Recognition SSO as a SAML Identity Provider (IdP)
and integrate it with TrustLogin.
Configuration is performed on both the Bio-IDiom Facial Recognition SSO side and the TrustLogin Admin Page.
Prerequisites
- A TrustLogin Pro Plan or optional contract is required to use this feature.
For pricing, click here - This assumes that authenticator information, photos, and other prior setup have already been completed on the Bio-IDiom Facial Recognition SSO side.
For prior setup and the latest configuration procedures, after contracting for Bio-IDiom Facial Recognition SSO,
please refer to the manual available from NEC Cloud Services. - If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
Note: we recommend that administrator users be assigned password authentication in case of emergency.
Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords
Configuration Steps
Preparation
Replace the {TenantID} (tenant ID) portion of the URL below with your ID, access it, and obtain the SAML Metadata. (This will be used when configuring the TrustLogin side.)
https://sso.bio-auth.com/auth/realms/{TenantID}/protocol/saml/descriptor
Configuration on the Bio-IDiom Facial Recognition SSO Side
Note: For the latest configuration procedures, please refer to the manual provided by NEC Cloud Services.
- Log in to the Bio-IDiom Facial Recognition SSO admin screen and go to the "Settings > Clients" screen.
- Click the "Create" button in the upper right of the screen.
-
On the Add Client screen, set the following values and click "Save".
Item Setting Value / Details Client ID trustlogin-saml-sp Client Protocol saml
-
On the Client Details screen, set values for the following items.
Note: for any values not set in this procedure, the default values are fine. (Settings Item List)Item Setting Value / Details Client ID (Note: already set in Step 3) trustlogin-saml-sp Name ID Format username Valid Redirect URIs https://portal.trustlogin.com/saml/acs SAML Endpoint Advanced Settings
> Assertion Consumer Service POST Binding URLhttps://portal.trustlogin.com/saml/acs Authentication Flow Overrides
> Browser Flowbis_webapp - Click "Save" to save the settings.
- Open the "Mappers" tab of the client configuration you created, and click "Create".
-
On the "Create Protocol Mapper" screen, set the following values and click "Save".
Item Setting Value / Details Name NameID Mapper Type User Attribute Mapper For NameID Name ID Format urn:oasis:names:SAML:1.1:nameid-format:emailAddress User Attribute username
This completes the configuration on the Bio-IDiom Facial Recognition SSO side.
Next, configure the TrustLogin side.
Configuration on the TrustLogin Side
- Log in to TrustLogin,
and open "Settings > Optional Features > External IdP Integration > Settings" on the Admin Page.
- Click "Add SAML IdP".
-
On the "Create SAML Identity Provider" screen, enter the following information.
Item Setting Value / Details Name Enter any name you like.
Example: Bio-IDiom Facial Recognition SSOSSO URL Preparation > the endpoint URL in the obtained metadata (the value of Location) Entity ID Preparation > the entity ID in the obtained metadata (the value of entityID) SAML Identity Provider Certificate Preparation > the certificate information in the obtained metadata (the value of X509Certificate) NameID Format Specifies the format to send as the NameID.
Preparation > select the value that matches the specified format.
Note: for details, click herePreferred NameID Attribute Specifies the member attribute to prioritize when matching the NameID.
Note: for details, click hereCase Sensitivity Specifies whether to distinguish between uppercase and lowercase letters when matching the NameID.
Note: for details, click here
- Click "Register".
- Next, assign the members who will log in with their Bio-IDiom Facial Recognition SSO ID.
Click "Add Member". (To add by group, click "Add Group".)
-
Select the target members and click the "Register" button.
The member addition is complete.
This completes the configuration.
Verifying the Configuration
From the TrustLogin login page, enter your Company ID and email address, and confirm that you can log in using facial recognition.
If multiple authentication methods are assigned, log in using the button for the configured external IdP name.
Note: the button name can be changed on the settings screen.
Notes
-
Client Detailed Settings Item List
Note: to return to the procedure, click here