| Item | Details | |
|---|---|---|
| Prior Confirmation |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For instructions on how to configure custom attributes, clickhere | ||
| SP-side Settings | 〇 | Configured by the administrator |
| Request configuration from the SP | ||
| Provisioning | Supportsprovisioningvia API (accounts can be managed in TrustLogin) | |
| Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported) | ||
| 〇 |
None (accounts are created in each system) |
|
| Access Method | 〇 | SP-Initiated SSO |
| IdP-Initiated SSO | ||
| Device Verification Status | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Standard Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App Internal Browser | |
| 〇 | iOS - Native App | |
| 〇 | Android - Standard Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App Internal Browser | |
| 〇 | Android - Native App | |
Configuring the TrustLogin Admin Page
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "Kaonavi (SAML)."
- Note down the "IdP URL," "Issuer/Entity ID," and "Certificate" (the contents of the text file) under "Identity Provider Information."
Now, let's move on to the settings on the Kaonavi side.
Do not click the "Register" button yet — open Kaonavi in a separate window.
Kaonavi Settings
- Open the Kaonavi administrator menu and go to "Single Sign-On Management."
-
Click the "Edit" button to open "Edit IdP Settings." Configure each item as shown below, then click "Save."
IdP Name Any name Entity The "Issuer/Entity ID" you noted down from TrustLogin SSO URL The "IdP URL" you noted down from TrustLogin x509cert The contents of the certificate text file
Note: Remove the first line "-----BEGIN CERTIFICATE-----" and
the last line "-----END CERTIFICATE-----."
- After saving, note down the "Login Page," "Entity," and "ACS URL" settings shown under "Kaonavi Configuration."
Return to the TrustLogin Admin Page again.
Configuring the TrustLogin Admin Page
- In "Service Provider Settings," extract the "text/numeric" portion from the settings information you obtained from Kaonavi and enter it into the corresponding blank fields for "Login URL," "Entity ID," and "ACS URL for Service."
- Click the "Register" button to save.
Configuring TrustLogin Users
① Adding the App as a User via My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "Kaonavi (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② Adding a Member as an Administrator
- On the "Admin Page > Apps" menu, search for the "Kaonavi (SAML)" app and click it.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.
How to Log In
① Logging in with "Kaonavi (SAML)"
When you launch "Kaonavi (SAML)" from the TrustLogin My Page or browser extension, you will be redirected to the Kaonavi login screen. Click the button with the IdP name you configured in "Kaonavi Settings > 2." to complete the login.
② Using the Auxiliary App
We also provide an auxiliary app that lets you skip the "clicking the IdP name button" step described in the login procedure in ①. Please register the corporate app "[SAML Auxiliary] Kaonavi" to use this feature.
Note: The auxiliary app is only available on PC browsers and iOS/Android internal browsers.
- Search on the "Register Corporate App" screen and select "[SAML Auxiliary] Kaonavi."
- Overwrite the "Login URL" with the "Login Page" URL obtained from Kaonavi.
- Click the "Register" button to save.
- Add the app following the same procedure as a normal app registration, either as the administrator or by the user themselves.
Some items on the registration screen are marked "No input required," but no input is needed for those items.
SSO Authentication Method for the Native App
If you are using the native app, you can use the following method.
- Open the Kaonavi administrator menu and select "Smartphone App Management."
- Select the users to allow to use the smartphone app, and turn "App Usage" to "ON."
- Download and open the Kaonavi native app.
- Select "SSO Login," enter your email address, and click "Login."
- The button with the IdP name you configured in "Kaonavi Settings > 2." will be displayed. After clicking the button, you will be redirected to the TrustLogin login screen. Log in to TrustLogin to use the app.