How to Configure SAML Authentication for Active! gate SS

Item

Details

Prerequisites

  • Prior configuration is required in Active! gate SS.

  • You must create an account in Active! gate SS using the same email address as your TrustLogin account.

  • For the latest configuration instructions, please refer to the manual provided by Active! gate SS.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request the SP to configure the settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For how to configure provisioning, see here (←★★Remove this if the SP does not support provisioning★★)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Device compatibility verification status

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari) Note: excludes access via the TrustLogin mobile app

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome) Note: excludes access via the TrustLogin mobile app

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Active! gate SS(SAML)".
    active_saml_02.png

  3. Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate via "Get Certificate".
    03.png

Now, let's move on to the settings on the Active! gate SS side. Please open Active! gate SS in a separate window.

Active! gate SS Settings

  1. Log in to the Active! gate SS administrator screen and open "User Management > Single Sign-On".

  2. Check the "Target Domain", and select "Change" for "Use as Service Provider". Register the information noted in step 3 of "TrustLogin Admin Page Settings" above as follows.

    IdP Template Select "Other"
    IdP EntityID The "Issuer/Entity ID" noted from TrustLogin
    IdP Login Page URL The "IdP URL" noted from TrustLogin
    IdP Certificate The "certificate" downloaded from TrustLogin
    EntityID The "Issuer/Entity ID" noted from TrustLogin

    active_saml_04.png

  3. Click the "OK" button.

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Enter the following into the three fields "Login URL" and "ACS URL to Service" under "Service Provider Settings".

    ❶・❹ Your Active! gate SS ID

    Target Domain
    Note: If you are using Active! gate SS with a subdomain, please enter the subdomain.

    The "Issuer/Entity ID" from TrustLogin's Identity Provider Information


    05.png

  2. Click the "Register" button at the top right to complete the setup.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button in "My Page".
  2. Select "Active! gate SS(SAML)" on the "Register App" screen, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app in "My Page" or the browser extension, and check whether login succeeds.

② When an Administrator Adds a Member

  1. Search for and click the "Active! gate SS(SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Active! gate SS

Item

Details

Prerequisites

  • Prior configuration is required in Active! gate SS.

  • You must create an account in Active! gate SS using the same email address as your TrustLogin account.

  • For the latest configuration instructions, please refer to the manual provided by Active! gate SS.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request the SP to configure the settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For how to configure provisioning, see here (←★★Remove this if the SP does not support provisioning★★)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Device compatibility verification status

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari) Note: excludes access via the TrustLogin mobile app

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome) Note: excludes access via the TrustLogin mobile app

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Active! gate SS(SAML)".
    active_saml_02.png

  3. Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate via "Get Certificate".
    03.png

Now, let's move on to the settings on the Active! gate SS side. Please open Active! gate SS in a separate window.

Active! gate SS Settings

  1. Log in to the Active! gate SS administrator screen and open "User Management > Single Sign-On".

  2. Check the "Target Domain", and select "Change" for "Use as Service Provider". Register the information noted in step 3 of "TrustLogin Admin Page Settings" above as follows.

    IdP Template Select "Other"
    IdP EntityID The "Issuer/Entity ID" noted from TrustLogin
    IdP Login Page URL The "IdP URL" noted from TrustLogin
    IdP Certificate The "certificate" downloaded from TrustLogin
    EntityID The "Issuer/Entity ID" noted from TrustLogin

    active_saml_04.png

  3. Click the "OK" button.

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Enter the following into the three fields "Login URL" and "ACS URL to Service" under "Service Provider Settings".

    ❶・❹ Your Active! gate SS ID

    Target Domain
    Note: If you are using Active! gate SS with a subdomain, please enter the subdomain.

    The "Issuer/Entity ID" from TrustLogin's Identity Provider Information


    05.png

  2. Click the "Register" button at the top right to complete the setup.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button in "My Page".
  2. Select "Active! gate SS(SAML)" on the "Register App" screen, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app in "My Page" or the browser extension, and check whether login succeeds.

② When an Administrator Adds a Member

  1. Search for and click the "Active! gate SS(SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.