How to Configure SAML Authentication for AI-Q

Item

Description

Prerequisites

  • Advance configuration in AI-Q is required.

  • You must create an AI-Q account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by AI-Q.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from GMO TrustLogin; user deletion is not supported)

None (accounts are created in each system)

Note: For setup instructions when using provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "AI-Q(SAML)".

    AI-Q__01.jpg

  3. Note down the "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate".

    AI-Q_03.jpg

Now, switch to the configuration on the AI-Q side.
Do not click the "Register" button yet — open the AI-Q admin page in a separate tab.

AI-Q Configuration

  1. Log in to AI-Q with an administrator account, and from the "Main Menu," open "Environment Settings > SAML Settings".

    AI-Q_04.jpg

  2. ① From "Register Information to SP," click the "Register/Update" button.
    AI-Q_05.jpg

  3. Register the information you noted in step 3 of "TrustLogin Admin Page Configuration" above, as follows. After registering, click "Save". 
    Identity Provider Entity ID (entityID) The "Issuer / Entity ID" you noted from TrustLogin
    Identity Provider Login URL (SingleSignOnService) The "IdP URL" you noted from TrustLogin
    Identity Provider Certificate (X509Data) Open the "certificate" you downloaded from TrustLogin and paste its contents
    Login Name Policy (NameIDFormat) urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    AI-Q_06.jpg
  4. ② From "Register Information to IdP," click "Metadata (SP)" to download the metadata.                  AI-Q_07.jpg

    Return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. In "Service Provider Settings," upload the metadata you downloaded from AI-Q to "Metadata".   AI-Q_08.jpg
  2. Click the "Register" button.
  3. In the "Admin Page > Apps" menu, search for and select the "AI-Q(SAML)" app.
  4. Under "Add Member," add the user for whom you configured SAML, and click "Register".AI-Q_15.jpgAI-Q_16.jpg
  5. Log out of TrustLogin, and return to the SAML settings on the AI-Q side again.     

AI-Q Configuration (Continued)

  1. ③ Click "Communication Test to IdP," then click the "SAML Test" button. (Alternatively, note down the URL below "SAML Test" and access it while logged out.)Note: Perform the SAML test while logged out of TrustLogin.AI-Q_09.jpg
  2. You will be redirected to the TrustLogin login page. Log in to TrustLogin.AI-Q_11.jpg
  3. After confirming the message "SAML configuration is incomplete. Please configure it," log in to AI-Q using your email address and password.AI-Q_10.jpg
  4. After logging in, open "Environment Settings > SAML Settings" from the "Main Menu" again.
  5. ④ Confirm that the "Register/Update" and "Delete" buttons are displayed to the right of "Configure User Management," then click "Register/Update".AI-Q_12.jpg
  6. Configure each item on the SAML settings screen as follows, then click "Save".
    ID used at login (email) NameID (auto-filled)
    Username 1 obtained from IdP information NameID (auto-filled)
    User's password when using SSO Any password
    User's role when using SSO Select Administrator or User
    Automatically create users from the IdP account Do not create
    AI-Q_13.jpg
  7. ⑤ Click "Set Up Link," note the URL of the "SSO Login Page," then open it in a different browser and log in. AI-Q_14.jpg

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "AI-Q(SAML)", then click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app from "My Page" or the "Browser Extension" and check that login succeeds.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "AI-Q(SAML)" app.
  2. Click "Add Member," select the user to add from the member list, then click the "Register" button to add them.

How to Configure SAML Authentication for AI-Q

Item

Description

Prerequisites

  • Advance configuration in AI-Q is required.

  • You must create an AI-Q account using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by AI-Q.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed from GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed from GMO TrustLogin; user deletion is not supported)

None (accounts are created in each system)

Note: For setup instructions when using provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "AI-Q(SAML)".

    AI-Q__01.jpg

  3. Note down the "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate".

    AI-Q_03.jpg

Now, switch to the configuration on the AI-Q side.
Do not click the "Register" button yet — open the AI-Q admin page in a separate tab.

AI-Q Configuration

  1. Log in to AI-Q with an administrator account, and from the "Main Menu," open "Environment Settings > SAML Settings".

    AI-Q_04.jpg

  2. ① From "Register Information to SP," click the "Register/Update" button.
    AI-Q_05.jpg

  3. Register the information you noted in step 3 of "TrustLogin Admin Page Configuration" above, as follows. After registering, click "Save". 
    Identity Provider Entity ID (entityID) The "Issuer / Entity ID" you noted from TrustLogin
    Identity Provider Login URL (SingleSignOnService) The "IdP URL" you noted from TrustLogin
    Identity Provider Certificate (X509Data) Open the "certificate" you downloaded from TrustLogin and paste its contents
    Login Name Policy (NameIDFormat) urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    AI-Q_06.jpg
  4. ② From "Register Information to IdP," click "Metadata (SP)" to download the metadata.                  AI-Q_07.jpg

    Return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. In "Service Provider Settings," upload the metadata you downloaded from AI-Q to "Metadata".   AI-Q_08.jpg
  2. Click the "Register" button.
  3. In the "Admin Page > Apps" menu, search for and select the "AI-Q(SAML)" app.
  4. Under "Add Member," add the user for whom you configured SAML, and click "Register".AI-Q_15.jpgAI-Q_16.jpg
  5. Log out of TrustLogin, and return to the SAML settings on the AI-Q side again.     

AI-Q Configuration (Continued)

  1. ③ Click "Communication Test to IdP," then click the "SAML Test" button. (Alternatively, note down the URL below "SAML Test" and access it while logged out.)Note: Perform the SAML test while logged out of TrustLogin.AI-Q_09.jpg
  2. You will be redirected to the TrustLogin login page. Log in to TrustLogin.AI-Q_11.jpg
  3. After confirming the message "SAML configuration is incomplete. Please configure it," log in to AI-Q using your email address and password.AI-Q_10.jpg
  4. After logging in, open "Environment Settings > SAML Settings" from the "Main Menu" again.
  5. ④ Confirm that the "Register/Update" and "Delete" buttons are displayed to the right of "Configure User Management," then click "Register/Update".AI-Q_12.jpg
  6. Configure each item on the SAML settings screen as follows, then click "Save".
    ID used at login (email) NameID (auto-filled)
    Username 1 obtained from IdP information NameID (auto-filled)
    User's password when using SSO Any password
    User's role when using SSO Select Administrator or User
    Automatically create users from the IdP account Do not create
    AI-Q_13.jpg
  7. ⑤ Click "Set Up Link," note the URL of the "SSO Login Page," then open it in a different browser and log in. AI-Q_14.jpg

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "AI-Q(SAML)", then click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app from "My Page" or the "Browser Extension" and check that login succeeds.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "AI-Q(SAML)" app.
  2. Click "Add Member," select the user to add from the member list, then click the "Register" button to add them.