|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, click here |
||
|
SP-Side Settings |
〇 |
Configured by the administrator |
|
Request the SP to configure it |
||
|
Provisioning |
Supports Provisioning via API (account management possible with GMO TrustLogin) |
|
|
Supports SAML JIT Provisioning(account management possible with GMO TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created individually in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "MAJOR FLOW Z CLOUD(SAML)".
- Make a note of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
- After downloading the certificate, change its extension to ".crt".
-
Configure each item under "Service Provider Settings" as follows.
Entity ID Any ID of your choice (here, MAJORFLOWZ)
Note: You will enter this later in MAJOR FLOW Z. Make a note of the Entity ID you entered in TrustLogin.
ACS URL for the Service
Please check with your MAJOR FLOW Z service representative.
- Click "Register" to save the settings.
Now switch to the MAJOR FLOW Z side settings.
MAJOR FLOW Z CLOUD Configuration
- Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
- Select "Edit Various Information".
- Select the user for whom you want to configure SAML authentication, and click "Edit".
- Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the registered email address field.
(Example: In the registration field shown below, since it is registered in "e-mail1", note down 1.)
- Return to the MAJOR FLOW Z admin screen and open "System Settings".
- Select "System Parameters".
-
From the "All" pull-down, select "SAML Authentication Settings".
- "Click "Edit" in the "CertificationSetting" field.
- Enter the following information in the value field for each setting, and click the "Register" button.
SAML Authentication Enabled Enter 1 IdP Settings Enter 2
- Return to the "SAML Authentication Settings" screen, and click "Edit" in the "GsuiteSetting" field.
- Enter the following information for each setting item, and click the "Register" button.
SSO URL Add "?1=1" to the end of the "Identity Provider URL" you noted from TrustLogin.
Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1
Entity ID Enter the same ID that you entered in the "Entity ID" field under TrustLogin's "Service Provider Settings".
(Here, MAJORFLOWZ)
Authentication Settings Enter 1 Response URL SamlAcs/Acs Authentication Email Address Settings Enter the registration number of the email address field you noted in step 4 of the MAJOR FLOW Z settings. (Here, enter 1 as an example)
- Click the "Confirm" button.
- Return to the "SAML Authentication Settings" screen, and click "Edit" in the certificate header/footer fields of "CertificateSetting".
- Confirm that "\n" is entered in both the "Certificate Header" and "Certificate Footer" fields.
- Return to the MAJOR FLOW Z admin screen and open "Certificate Settings".
- Click "Register Certificate".
- Select "MFZC_SAML" as the target app.
Upload the certificate you downloaded from TrustLogin (with the extension changed to .crt) using "Choose File", and click "Start Import".
- After confirming the message "No issues were found with the certificate file.", click "Apply".
- Certificate registration is complete.
TrustLogin User Settings
① When a User Adds the App via My Page
- In "My Page", click the "Add App" button.
- On the "Register App" screen, select "MAJOR FLOW Z(SAML)", and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
- Click the app in "My Page" or the browser extension, and check whether login succeeds.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "MAJOR FLOW Z CLOUD(SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.