How to Configure SAML Authentication for Fileforce

Item

Description

Prerequisites

  • Prior configuration on the Fileforce side is required.

  • You must create an account in Fileforce using the same email address as your TrustLogin account.

  • If a Fileforce user has a duplicate email address registered, you will not be able to select that email address in Fileforce's single sign-on settings. Please make sure email addresses are not duplicated.

  • For the latest setup instructions, please refer to the manual provided by Fileforce.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in GMO TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app (Fileforce Drive)

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app (Fileforce(E))

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Fileforce(SAML)."
    Fileforce01.jpg

  3. Make a note of the "IdP URL" under "Identity Provider Information," then download the certificate from "Get Certificate."
    03.png

  4. After downloading the certificate, change the certificate file's extension to "cer" and save it.
  5. In "Service Provider Settings," enter your Fileforce "site name" in the four blank fields: "Login URL," "Entity ID," "ACS URL for the service," and "Logout URL."
    Enter the site name portion from the login ID used when logging in, in the format user ID@site name. Please check the email you received from Fileforce at the time of activation for your user ID and site name.
    Fileforce_03.jpg

  6. Click the "Register" button to save.

Fileforce Configuration

  1. Log in with an administrator account and open "Tools > User Management > Admin Console" at the top right.
    Fileforce04.jpg

  2. Open "Single Sign-On Settings."
    Fileforce_05.jpg

  3. Click "Start Editing."Fileforce_06.jpg

  4. Check "Enable Single Sign-On" and configure the fields as follows.
    Fileforce_07.jpg

    Login page URL The IdP URL you noted from TrustLogin
    Logout page URL

    Enter https://portal.trustlogin.com/user/

    Federation ID type Select "Email address"
    Authentication verification

    Upload the certificate downloaded from TrustLogin with its extension changed to "cer"

  5. Click the "Save" button, then click "Finish Editing."

How to Configure SSO for the Native App

Fileforce supports an iOS mobile app. Both administrators and users registered in Fileforce can use it via the method below.

  1. Download the Fileforce(E) app (icon shown below) from the iOS App Store.Fileforce_10.png

  2. Open the downloaded mobile app and tap "Add Profile" to launch the camera.IMG-0007.PNG

  3. Log in to Fileforce on your PC and open "Tools > Applications."Fileforce_08.png

  4. Select "Apps," then use the mobile app's camera to scan the "Login Type: Single Sign-On" QR code shown on screen.
    Fileforce_09.png

  5. Save the profile.
    IMG-0008.PNG 
      
  6. Select the saved profile.
    IMG-0009.PNG  

  7. Log in to TrustLogin and confirm that login succeeds.
    IMG-0010.PNG

TrustLogin User Configuration

① When a user adds it from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Fileforce(SAML)," then click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "Extension," and confirm that login succeeds.

② When an administrator adds members

  1. On the "Admin Page > Apps" menu, search for and click the "Fileforce(SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Fileforce

Item

Description

Prerequisites

  • Prior configuration on the Fileforce side is required.

  • You must create an account in Fileforce using the same email address as your TrustLogin account.

  • If a Fileforce user has a duplicate email address registered, you will not be able to select that email address in Fileforce's single sign-on settings. Please make sure email addresses are not duplicated.

  • For the latest setup instructions, please refer to the manual provided by Fileforce.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in GMO TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app (Fileforce Drive)

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app (Fileforce(E))

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Fileforce(SAML)."
    Fileforce01.jpg

  3. Make a note of the "IdP URL" under "Identity Provider Information," then download the certificate from "Get Certificate."
    03.png

  4. After downloading the certificate, change the certificate file's extension to "cer" and save it.
  5. In "Service Provider Settings," enter your Fileforce "site name" in the four blank fields: "Login URL," "Entity ID," "ACS URL for the service," and "Logout URL."
    Enter the site name portion from the login ID used when logging in, in the format user ID@site name. Please check the email you received from Fileforce at the time of activation for your user ID and site name.
    Fileforce_03.jpg

  6. Click the "Register" button to save.

Fileforce Configuration

  1. Log in with an administrator account and open "Tools > User Management > Admin Console" at the top right.
    Fileforce04.jpg

  2. Open "Single Sign-On Settings."
    Fileforce_05.jpg

  3. Click "Start Editing."Fileforce_06.jpg

  4. Check "Enable Single Sign-On" and configure the fields as follows.
    Fileforce_07.jpg

    Login page URL The IdP URL you noted from TrustLogin
    Logout page URL

    Enter https://portal.trustlogin.com/user/

    Federation ID type Select "Email address"
    Authentication verification

    Upload the certificate downloaded from TrustLogin with its extension changed to "cer"

  5. Click the "Save" button, then click "Finish Editing."

How to Configure SSO for the Native App

Fileforce supports an iOS mobile app. Both administrators and users registered in Fileforce can use it via the method below.

  1. Download the Fileforce(E) app (icon shown below) from the iOS App Store.Fileforce_10.png

  2. Open the downloaded mobile app and tap "Add Profile" to launch the camera.IMG-0007.PNG

  3. Log in to Fileforce on your PC and open "Tools > Applications."Fileforce_08.png

  4. Select "Apps," then use the mobile app's camera to scan the "Login Type: Single Sign-On" QR code shown on screen.
    Fileforce_09.png

  5. Save the profile.
    IMG-0008.PNG 
      
  6. Select the saved profile.
    IMG-0009.PNG  

  7. Log in to TrustLogin and confirm that login succeeds.
    IMG-0010.PNG

TrustLogin User Configuration

① When a user adds it from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Fileforce(SAML)," then click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "Extension," and confirm that login succeeds.

② When an administrator adds members

  1. On the "Admin Page > Apps" menu, search for and click the "Fileforce(SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.