How to Configure SAML Authentication for ActionPassport

Item

Description

Prerequisites

  • Prior configuration on the ActionPassport side is required.

  • You must create an account in ActionPassport using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by ActionPassport.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in GMO TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

ActionPassport Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.

    ws_saml_01.png

  2. On the "Register Corporate App" screen, search for and select "ActionPassport (SAML)."

    ActionPassport01.png
  3. Make a note of the "IdP URL" under "Identity Provider Information," then download the "Certificate."Acttionpassport_02.png

  4. Send the following information to ActionPassport and request that they configure SAML.

    IdP login URL (HTTP Redirect)

    IdP URL
    IdP logout URL https://portal.trustlogin.com/user/
    IdP certificate Change the extension of the certificate downloaded from TrustLogin to one of "CRT," "PEM," or "CER" and send it
    User identifier field on the connected system for the user you want to test

    emailAdress


TrustLogin Admin Page Configuration

  1. In "Service Provider Settings," enter the Entity ID and ACS URL provided by ActionPassport into the "Entity ID" and "ACS URL for the service" fields, respectively.
    Actionpassport_03.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds it from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "ActionPassport (SAML)," then click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "Extension," and confirm that login succeeds.

② When an administrator adds members

  1. On the "Admin Page > Apps" menu, search for and click the "ActionPassport (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for ActionPassport

Item

Description

Prerequisites

  • Prior configuration on the ActionPassport side is required.

  • You must create an account in ActionPassport using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by ActionPassport.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in GMO TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

ActionPassport Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.

    ws_saml_01.png

  2. On the "Register Corporate App" screen, search for and select "ActionPassport (SAML)."

    ActionPassport01.png
  3. Make a note of the "IdP URL" under "Identity Provider Information," then download the "Certificate."Acttionpassport_02.png

  4. Send the following information to ActionPassport and request that they configure SAML.

    IdP login URL (HTTP Redirect)

    IdP URL
    IdP logout URL https://portal.trustlogin.com/user/
    IdP certificate Change the extension of the certificate downloaded from TrustLogin to one of "CRT," "PEM," or "CER" and send it
    User identifier field on the connected system for the user you want to test

    emailAdress


TrustLogin Admin Page Configuration

  1. In "Service Provider Settings," enter the Entity ID and ACS URL provided by ActionPassport into the "Entity ID" and "ACS URL for the service" fields, respectively.
    Actionpassport_03.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds it from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "ActionPassport (SAML)," then click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "Extension," and confirm that login succeeds.

② When an administrator adds members

  1. On the "Admin Page > Apps" menu, search for and click the "ActionPassport (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.