|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, see here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning supported (account management possible in GMO TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible in GMO TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app in-app browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app in-app browser |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Corporate App" screen, search for and select "[Attendance Management] MAJOR FLOW Z CLOUD (SAML)".
- Note down the "IdP URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
After downloading the certificate, change its file extension to ".crt".
-
Configure each item under "Service Provider Settings" as follows.
Entity ID Any ID of your choice (this guide uses MAJORFLOWZ)
Note: You will enter this later in MAJOR FLOW Z. Please make a note of the entity ID you entered in TrustLogin.
ACS URL for the Service
Please check with your MAJOR FLOW Z service representative.
- Click the "Register" button to save the settings.
Now, switch to configuring the MAJOR FLOW Z side.
MAJOR FLOW Z CLOUD Configuration
- Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
- Select "Edit Various Information".
- Select the user for whom you want to configure SAML authentication, and click "Edit".
- Confirm that "MAJOR FLOW Z CLOUD Attendance Management" is checked under "Services to Use".
Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the email address field where it is registered.
(Example: In the registration field shown below, since the address is registered in "e-mail1", make a note of 1.)
- Return to the MAJOR FLOW Z admin screen and open "Attendance Management > System Settings".
- Click "System Parameters".
-
From the "All" dropdown, select "SAML Authentication Settings".
- Click "Edit" in the certificate header and footer fields of "ZtCertificateSetting".
- Confirm that "\n" is entered in both the "Certificate Header" and "Certificate Footer" fields.
Note: If "\n" is not entered, refer to the image below, enter "\n" in each of the "Certificate Header" and "Certificate Footer" fields, click the "Register" button, and then click "Confirm".
- Return to "System Parameters" and click "Edit" in the "ZtCertificationSetting" field.
- Enter the following information in the value field for each setting, and click the "Register button".
SAML Authentication Enabled Enter 1 IdP Settings Enter 2
- Click "Confirm".
- Return to the "SAML Authentication Settings" screen, and click "Edit" in the "ZtGsuiteSetting" field.
- Enter the following information for each setting item, and click the "Register" button.
SSO URL Add "?1=1" to the end of the "IdP URL"
you noted from TrustLogin.
Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1
Entity ID Enter the same ID that you entered in "Entity ID" under "Service Provider Settings" in TrustLogin.
(In this guide, MAJORFLOWZ)
Authentication Settings Enter 1 Response URL SamlAcs/Acs Authentication Email Address Settings Enter the registration number of the email address field you noted in step 4 of the MAJOR FLOW Z configuration. (In this example, enter 1)
- Click the "Confirm" button.
- Return to the MAJOR FLOW Z admin screen and open "Common > Certificate Settings".
- Click "Register Certificate".
- From the target app selection dropdown, select "MFZT_SAML".
- Upload the certificate you downloaded from TrustLogin (with the file extension changed to .crt) using "Select File", and click "Start Import".
- After confirming the message "No issues were found with the certificate file.", click "Apply Content".
- The certificate registration is complete.
TrustLogin User Configuration
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "[Attendance Management] MAJOR FLOW Z CLOUD (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app from "My Page" or the browser extension, and confirm that login succeeds.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "[Attendance Management] MAJOR FLOW Z CLOUD (SAML)" app.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.