Note: Prior configuration in Lychee Redmine is required.
Note: You must create an account in Lychee Redmine using the same email address as your TrustLogin account.
Note: Please refer to the manual provided by Lychee Redmine for the most up-to-date configuration steps.
Lychee SAML Authentication
https://manual.lychee-redmine.jp/saml_authentication/saml_authentication.html#%E2%9D%8F-%E3%81%9D%E3%81%AE%E4%BB%96%E3%81%AEIdP
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Corporate App" screen, search for and select "Lychee Redmine (SAML)".
- Make a note of the "Identity Provider URL" under "Identity Provider Information".
- Next, download the certificate from "Get Certificate".
- Open the downloaded certificate in a text editor and copy its contents.
-
Open this page and paste the copied content into "X.509 cert".
Select "sha256" for "Algorithm" and click "CALCULATE FINGERPRINT".
Copy the value displayed in "Formatted FingerPrint" and make a note of it.
Now, switch to configuring the Lychee Redmine side.
Do not click the "Register" button yet — open the Lychee Redmine admin page in a separate tab.
Lychee Redmine Configuration
- Log in to Lychee Redmine with an administrator account and open "Admin > SAML Authentication".
- Click "SAML Authentication".
-
Configure each item as follows.
Type Select "Other" Name Any name of your choosing Domain The portion of the login URL before "/login"
Example: If the login URL is https://samltest.cloudmine.jp/login
then https://samltest.cloudmine.jp is the DomainIdP SSO target URL
Paste the "Identity Provider URL" you noted from TrustLogin in step 3 above Attribute mapping mail Enter "Email" IdP Cert Algorithm Select "SHA256"
IdP Cert Fingerprint Paste the "Formatted FingerPrint" generated in step 6 above
-
Configure this item ONLY IF YOU ARE USING SAML JIT. If you are not using SAML JIT, proceed to step 5.
If you are using SAML JIT, also configure the following three items.
Attribute mapping firstname Enter "FirstName" Attribute mapping lastname Enter "LastName" Automatically create a user if one does not exist Turn the checkbox ON
-
Click the "Save" button to save the settings.
- Copy and make a note of the Recipient value displayed after saving.
Note: If you click "Test" on this screen to run a test, an error will be displayed, but this is not an issue for actual SAML authentication.
Return to the TrustLogin admin page again.
TrustLogin Admin Page Configuration (Continued)
- Paste the Recipient value you noted from Lychee Redmine in step 6 above into both the "Entity ID" and "ACS URL for Service" fields under "Service Provider Settings".
- Click the "Register" button to save.
TrustLogin User Configuration
① When a User Adds the App from My Page
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "Lychee Redmine (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter a new one, then click the "Register" button.
- Click the app from "My Page" or the browser extension and confirm that login is successful.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the "Lychee Redmine (SAML)" app.
- Click "Add Member", select the user you want to add from the member list, and click the "Register" button to add them.
Lychee Redmine User Configuration
- Open "Admin > Users".
- Click the login ID of the user to whom you want to apply SAML authentication.
-
Change the authentication method from Internal to the SAML you configured, and update it by clicking "Save".
How to Log In to Lychee Redmine
When performing SAML authentication in Lychee Redmine, you must start from the Lychee Redmine login page. You cannot log in from TrustLogin's My Page or the browser extension.
- Open the Lychee Redmine login page, enter only the Login ID (the screenshot shows this in English as "Login"), and click the "Login" button.
- [If you are not logged in to TrustLogin]
You will be redirected to the TrustLogin login screen, so please log in.
After logging in, SAML authentication will be performed and you will be redirected to your Lychee Redmine My Page.
[If you are already logged in to TrustLogin]
SAML authentication will be performed and you will be redirected to your Lychee Redmine My Page.