How to Configure SAML JIT for Electronic Seal GMO Sign (Formerly Agree)

If you want to configure SAML authentication together with identity federation for Electronic Seal GMO Sign (formerly Agree), follow the steps below.
For instructions on configuring SAML authentication without identity federation, click here.

Note: Prior application and a request for SAML configuration with Electronic Seal GMO Sign are required.
SSO/IdP Integration (SAML) Setup Steps

Note: After applying for the SAML feature option, GMO Sign will send you the metadata.

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    agree_01.png

  2. Register the "Application Name" and "Icon" (optional).
    agree_02.png

  3. Download the "Metadata" and "Certificate" from "Identity Provider Information".
    03.png

  4. Leave "Value for Name ID" under "Service Provider Settings" unchanged as "Member > email", and upload the metadata provided by Electronic Seal GMO Sign using "Select Metadata".
    agree_04.png

  5. Add an attribute using the "Add SAML Attribute" button under "SAML Attribute Settings", and configure it as follows.

    Service Provider Attribute   TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name     Attribute Value
    user_first_name Basic user_first_name ↔︎ Member Member - First Name
    user_last_name Basic user_last_name ↔︎ Member Member - Last Name
    division Basic division ↔︎ Member Member - Department
    group_name Basic group_name ↔︎ Group Select an existing group from the dropdown and add it using the "+" button
    role Basic role ↔︎ Custom attribute The attribute name is arbitrary
    (e.g., gmosign_role)

    mceclip0.png

    The custom attribute name is arbitrary.
    The attribute values that can be specified for gmosign_role are as follows.

    Administrator
    Administrator + Signer
    Document Administrator
    Document Administrator + Signer
    Document Viewer
    Signer


    For instructions on how to configure custom attributes, please refer to the following pages.

  6. Click "Register" to save the settings.
    agree_06.png

  7. Send the "Metadata" and "Certificate" downloaded in step 3 to the GMO Sign Operations Team and request SAML configuration.


  8. A representative from the GMO Sign Operations Team will perform the SAML configuration.
    Note: At this point, the GMO Sign account will be in a SAML-enabled state.

  9. After confirming that login works without issues, request that the GMO Sign Operations Team delete the password for existing users (final configuration).
    Note: Once the final configuration is performed, logging in to GMO Sign without going through the IdP will no longer be possible.

  10. Final configuration performed by the GMO Sign Operations Team

    [Caution] At this point, direct login to GMO Sign using an ID and password will no longer be possible.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and confirm that sign-in succeeds.

 

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the custom SAML app you created.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

 

How to Configure SAML JIT for Electronic Seal GMO Sign (Formerly Agree)

If you want to configure SAML authentication together with identity federation for Electronic Seal GMO Sign (formerly Agree), follow the steps below.
For instructions on configuring SAML authentication without identity federation, click here.

Note: Prior application and a request for SAML configuration with Electronic Seal GMO Sign are required.
SSO/IdP Integration (SAML) Setup Steps

Note: After applying for the SAML feature option, GMO Sign will send you the metadata.

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    agree_01.png

  2. Register the "Application Name" and "Icon" (optional).
    agree_02.png

  3. Download the "Metadata" and "Certificate" from "Identity Provider Information".
    03.png

  4. Leave "Value for Name ID" under "Service Provider Settings" unchanged as "Member > email", and upload the metadata provided by Electronic Seal GMO Sign using "Select Metadata".
    agree_04.png

  5. Add an attribute using the "Add SAML Attribute" button under "SAML Attribute Settings", and configure it as follows.

    Service Provider Attribute   TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name     Attribute Value
    user_first_name Basic user_first_name ↔︎ Member Member - First Name
    user_last_name Basic user_last_name ↔︎ Member Member - Last Name
    division Basic division ↔︎ Member Member - Department
    group_name Basic group_name ↔︎ Group Select an existing group from the dropdown and add it using the "+" button
    role Basic role ↔︎ Custom attribute The attribute name is arbitrary
    (e.g., gmosign_role)

    mceclip0.png

    The custom attribute name is arbitrary.
    The attribute values that can be specified for gmosign_role are as follows.

    Administrator
    Administrator + Signer
    Document Administrator
    Document Administrator + Signer
    Document Viewer
    Signer


    For instructions on how to configure custom attributes, please refer to the following pages.

  6. Click "Register" to save the settings.
    agree_06.png

  7. Send the "Metadata" and "Certificate" downloaded in step 3 to the GMO Sign Operations Team and request SAML configuration.


  8. A representative from the GMO Sign Operations Team will perform the SAML configuration.
    Note: At this point, the GMO Sign account will be in a SAML-enabled state.

  9. After confirming that login works without issues, request that the GMO Sign Operations Team delete the password for existing users (final configuration).
    Note: Once the final configuration is performed, logging in to GMO Sign without going through the IdP will no longer be possible.

  10. Final configuration performed by the GMO Sign Operations Team

    [Caution] At this point, direct login to GMO Sign using an ID and password will no longer be possible.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and confirm that sign-in succeeds.

 

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the custom SAML app you created.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.