How to Configure SAML Authentication for Hot Profile

Item

Details

Pre-check

  • Prior configuration in Hot Profile is required.

  • Please refer to the manual provided by Hot Profile for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Identity Provisioning supported (account management available in GMO TrustLogin)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: Verification of the Android native app is in progress.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Hot Profile (SAML)".
    02.png

  3. Note the "Identity Provider URL" in "Identity Provider Information", and download the certificate using "Get Certificate".
    03.png

  4. In "Service Provider Settings", enter the domain of your SSO login URL into the two blank fields for "Entity ID" and "ACS URL for the Service".

    https://[Customer ID].[Hot Profile URL] is your SSO login URL. Please check the activation email from Hot Profile for your SSO login URL.
    Example: If your SSO login URL is https://000001.hammock.hotprofile.biz, enter 000001.hammock.hotprofile.biz.

    08.png

  5. Click the "Register" button to save.

Hot Profile Settings

  1. Log in with an administrator account and open "Gear Icon > User Management > User Management" at the top right.
    04.png

  2. Open "SAML Authentication Settings".
    05.png

  3. Select "Enabled" for "SAML Authentication" to expand the detailed information fields below, configure the items as follows, and finally click the "Register" button.

    Identity Provider SSO Endpoint URL The Identity Provider URL noted from TrustLogin
    Identity Provider SLO Endpoint URL https://portal.trustlogin.com/
    Uncheck "Use SAMLResponse on Logout"
    Public Key Certificate Signed by the Identity Provider The certificate downloaded from TrustLogin

    06.png

  4. Open the user information edit screen using the "Edit" button next to the user for whom you want to enable SAML authentication, and update the information as follows.
    HotProfile Account

    Enabled: You can still log in with your Hot Profile ID and password after SAML authentication is enabled.
    Disabled: Once SAML authentication is enabled, you will no longer be able to log in with your Hot Profile ID and password. Please be aware of this.

    SAML Authentication Select "Enabled"
    SAML Authentication Linkage ID Your TrustLogin email address

    09.png

    07.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Hot Profile (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Hot Profile (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Hot Profile

Item

Details

Pre-check

  • Prior configuration in Hot Profile is required.

  • Please refer to the manual provided by Hot Profile for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Identity Provisioning supported (account management available in GMO TrustLogin)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: Verification of the Android native app is in progress.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Hot Profile (SAML)".
    02.png

  3. Note the "Identity Provider URL" in "Identity Provider Information", and download the certificate using "Get Certificate".
    03.png

  4. In "Service Provider Settings", enter the domain of your SSO login URL into the two blank fields for "Entity ID" and "ACS URL for the Service".

    https://[Customer ID].[Hot Profile URL] is your SSO login URL. Please check the activation email from Hot Profile for your SSO login URL.
    Example: If your SSO login URL is https://000001.hammock.hotprofile.biz, enter 000001.hammock.hotprofile.biz.

    08.png

  5. Click the "Register" button to save.

Hot Profile Settings

  1. Log in with an administrator account and open "Gear Icon > User Management > User Management" at the top right.
    04.png

  2. Open "SAML Authentication Settings".
    05.png

  3. Select "Enabled" for "SAML Authentication" to expand the detailed information fields below, configure the items as follows, and finally click the "Register" button.

    Identity Provider SSO Endpoint URL The Identity Provider URL noted from TrustLogin
    Identity Provider SLO Endpoint URL https://portal.trustlogin.com/
    Uncheck "Use SAMLResponse on Logout"
    Public Key Certificate Signed by the Identity Provider The certificate downloaded from TrustLogin

    06.png

  4. Open the user information edit screen using the "Edit" button next to the user for whom you want to enable SAML authentication, and update the information as follows.
    HotProfile Account

    Enabled: You can still log in with your Hot Profile ID and password after SAML authentication is enabled.
    Disabled: Once SAML authentication is enabled, you will no longer be able to log in with your Hot Profile ID and password. Please be aware of this.

    SAML Authentication Select "Enabled"
    SAML Authentication Linkage ID Your TrustLogin email address

    09.png

    07.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Hot Profile (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Hot Profile (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.