| Item | Details | |
|---|---|---|
| Pre-check |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For how to configure custom attributes, see here | ||
| SP Configuration | 〇 | Configured by the Administrator |
| Request SP to configure | ||
| Provisioning | API-based Provisioning supported (Account management available in TrustLogin) | |
| SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available) | ||
| 〇 | None (accounts created in each system) | |
| Access Method | 〇 | SP-Initiated SSO |
| ー | IdP-Initiated SSO | |
| Device Compatibility | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Default Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| 〇 | iOS - Native App | |
| 〇 | Android - Default Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| 〇 | Android - Native App | |
| SAML Authentication Scope | ー | Enabled for all users |
| 〇 | Other: Enabled for all users (both SAML authentication and password authentication available) | |
| Notes | For customers using the old template, please refer to the old manual. | |
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Company App Registration" screen, search for and select "[New Platform] SmartDB (SAML)".
- Note down the "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, proceed to the SmartDB settings.
Do not click the "Register" button yet; open SmartDB in a separate window.
SmartDB Settings
- Log in with an administrator account and select "System Administration" from the icon in the top right.
- Open "Authentication and Security > Authentication" and click "Edit" for "SAML".
-
Configure each item on the "Basic Items" tab as follows and save.
Button name displayed on the login page Any button name of your choice
Note: The button name you set will be displayed on the login screen. You may also leave it as the default.SAML Sign-on Endpoint URL The "Identity Provider URL" obtained from TrustLogin X.509 Certificate The content of the "Certificate" obtained from TrustLogin Name ID Unspecified (UNSPECIFIED) Authenticate using the device's default browser ON
(If you are using client authentication, login will not be possible if this is set to OFF)Use universal links Optional
Note: You can change the SSO login button name using "Button name displayed on the login page".
- Click "Metadata" and use the "Copy" button to get and note down the displayed "Identifier (Entity ID)" and "Response URL (ACS URL)".
- Open the "IP Address Control" tab and configure it according to your company's policy.
Note: This setting is optional.
Note: If you select the "Allow List" method, SAML login via the mobile app will not be possible.
-
Save by clicking the "Save" button.
Return to the TrustLogin Admin Page.
TrustLogin Admin Page Settings (Continued)
-
Configure the "Service Provider Settings" as follows.
Login URL The "Response URL (ACS URL)" obtained from SmartDB Entity ID The "Identifier (Entity ID)" obtained from SmartDB ACS URL to the Service The "Response URL (ACS URL)" obtained from SmartDB - Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
Note: The SAML app must be configured by the Administrator in advance.
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "[New Platform] SmartDB (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for the "[New Platform] SmartDB (SAML)" app and click it.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In
① How to Log in via SP-Initiated SSO
- Open the SmartDB login screen, enter your email address, and proceed.
- Click the SSO login button.
- If you are already logged in to TrustLogin, you will be logged in to SmartDB immediately.
If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen; once you authenticate, login to SmartDB will be complete.
② How to Install and Log in via the Native App
- Log in from a PC or smartphone, and open "Mobile Usage" from the icon in the top right of the page.
- Scan the QR code displayed on your mobile device to install the app.
- Open the app, confirm that the SmartDB Company ID has been entered automatically, and click "Next".
Note: If the Company ID is not entered after installation, scan the QR code again.
- Click the SSO login button and log in.