|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) Note: For setup instructions when provisioning is not required, see here |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "AI-Q (SAML)".
- Make a note of the "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", then download the certificate from "Download Certificate".
Now, switch to configuring the AI-Q side.
Do not click the "Register" button yet — open the AI-Q admin page in a separate tab.
AI-Q Settings
- Log in to AI-Q with an administrator account, then open "Environment Settings > SAML Settings" from the "Main Menu".
- ① Click the "Register/Update" button under "Register Information to SP".
- Register the information you noted down in step 3 of "TrustLogin Admin Page Settings" above as follows. After registering, click "Save".
Identity Provider's Entity ID (entityID) The "Issuer / Entity ID" you noted from TrustLogin Identity Provider's Login URL (SingleSignOnService) The "Identity Provider URL" you noted from TrustLogin Identity Provider's Certificate (X509Data) Open the "certificate" you noted from TrustLogin and paste it in Login Name Policy (NameIDFormat) urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified - ② Click "Metadata (SP)" under "Register Information to IdP" to download the metadata.
Return to the TrustLogin admin page again.
TrustLogin Admin Page Settings (Continued)
- Upload the metadata you noted from AI-Q to "Metadata" under "Service Provider Settings".
- Click the "Register" button.
- Search for and select the "AI-Q (SAML)" app in the "Admin Page > App" menu.
- Under "Add Member", add the user who has SAML configured, then click "Register".
- Log out of TrustLogin and return to the SAML settings on the AI-Q side again.
AI-Q Settings (Continued)
- ③ Click "Communication Test to IdP", then click the "SAML Test" button. (Alternatively, note down the URL below "SAML Test" and access it while logged out.)
Note: Please perform the SAML test while logged out of TrustLogin. - You will be redirected to the TrustLogin login page. Please log in to TrustLogin.
- After confirming the message "SAML settings are incomplete. Please configure them.", log in to AI-Q with your email address and password.
- After logging in, open "Environment Settings > SAML Settings" from the "Main Menu" again.
- ④ Confirm that the "Register/Update" and "Delete" buttons are displayed to the right of "Configure User Management", then click "Register/Update".
- Configure each item on the SAML settings screen as follows, then click "Save".
ID used for login (email) NameID (entered automatically) Username 1 obtained from IdP information NameID (entered automatically) User's password when using SSO Any password User's role when using SSO Select Administrator or User Automatically create a user with the IdP account Create - ⑤ Click "Set Up Link", note down the URL of the "Login page for SSO", then open a separate browser, access it, and log in.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "AI-Q (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the "browser extension" and check that login succeeds.
② When an administrator adds a member
- Search for and click the "AI-Q" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.