How to Configure SAML Authentication for Knowledge Suite

Item

Details

Prerequisites

  • Prior configuration in Knowledge Suite is required.

  • You must create an account in Knowledge Suite using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by Knowledge Suite.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For setup instructions if provisioning is required, see here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: Native app operation for both iOS and Android is currently being verified.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click "Register App" in the upper right of the screen.
    01.png

  2. On the "Corporate App Registration" screen, search for and select "Knowledge Suite (SAML)".
    02.png

  3. Note the "IdP URL" under "Identity Provider Information," and download the "Certificate".
    03.png

At this point, switch over to the Knowledge Suite settings.
Do not click the "Register" button yet — open the Knowledge Suite admin page in a separate tab.

Knowledge Suite Settings

  1. Log in to Knowledge Suite with administrator privileges, and click "Settings" at the top of the screen.
    04.png

  2. Open "Knowledge Suite Settings > SSO Settings" from the left-hand menu.
    05.png

  3. For "SSO Usage Settings," select "Disabled," enter any subdomain in "URL for SSO Use," and click "Save Settings".
    06.png

TrustLogin Admin Page Settings (Continued)
Return to the TrustLogin admin page.

  1. In the "Service Provider Settings," enter the subdomain you configured in step 3 of "Knowledge Suite Settings" above into the blank fields for "Login URL," "Entity ID," and "ACS URL for Service".
    07.png

  2. Click the "Register" button.

Knowledge Suite Settings (Continued)

  1. Open "Knowledge Suite Settings > SSO Settings" again.

  2. Configure each item as follows, and click "Save Settings".
    SSO Usage Settings Change to "Enabled"
    Normal Login Permission Settings for SSO Use Select who is permitted to use normal login
    JIT Integration Usage Settings Select "Disabled"
    Identifier Format Select "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
    IdP Login URL The "IdP URL" you noted from the TrustLogin admin page
    IdP Logout URL Specify https://portal.trustlogin.com/
    IdP Certificate Upload the certificate downloaded from the TrustLogin admin page

    09.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button in "My Page".
  2. On the "App Registration" screen, select "Knowledge Suite (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, and click the "Register" button.

② When an administrator adds a member

  1. In the "Admin Page > Apps" menu, search for and click the "Knowledge Suite (SAML)" app.
  2. Click "Add Member," select the user you want to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Knowledge Suite

Item

Details

Prerequisites

  • Prior configuration in Knowledge Suite is required.

  • You must create an account in Knowledge Suite using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by Knowledge Suite.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For setup instructions if provisioning is required, see here

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: Native app operation for both iOS and Android is currently being verified.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click "Register App" in the upper right of the screen.
    01.png

  2. On the "Corporate App Registration" screen, search for and select "Knowledge Suite (SAML)".
    02.png

  3. Note the "IdP URL" under "Identity Provider Information," and download the "Certificate".
    03.png

At this point, switch over to the Knowledge Suite settings.
Do not click the "Register" button yet — open the Knowledge Suite admin page in a separate tab.

Knowledge Suite Settings

  1. Log in to Knowledge Suite with administrator privileges, and click "Settings" at the top of the screen.
    04.png

  2. Open "Knowledge Suite Settings > SSO Settings" from the left-hand menu.
    05.png

  3. For "SSO Usage Settings," select "Disabled," enter any subdomain in "URL for SSO Use," and click "Save Settings".
    06.png

TrustLogin Admin Page Settings (Continued)
Return to the TrustLogin admin page.

  1. In the "Service Provider Settings," enter the subdomain you configured in step 3 of "Knowledge Suite Settings" above into the blank fields for "Login URL," "Entity ID," and "ACS URL for Service".
    07.png

  2. Click the "Register" button.

Knowledge Suite Settings (Continued)

  1. Open "Knowledge Suite Settings > SSO Settings" again.

  2. Configure each item as follows, and click "Save Settings".
    SSO Usage Settings Change to "Enabled"
    Normal Login Permission Settings for SSO Use Select who is permitted to use normal login
    JIT Integration Usage Settings Select "Disabled"
    Identifier Format Select "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
    IdP Login URL The "IdP URL" you noted from the TrustLogin admin page
    IdP Logout URL Specify https://portal.trustlogin.com/
    IdP Certificate Upload the certificate downloaded from the TrustLogin admin page

    09.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button in "My Page".
  2. On the "App Registration" screen, select "Knowledge Suite (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter a new one, and click the "Register" button.

② When an administrator adds a member

  1. In the "Admin Page > Apps" menu, search for and click the "Knowledge Suite (SAML)" app.
  2. Click "Add Member," select the user you want to add from the member list, and click the "Register" button to add them.