How to Configure SAML Authentication for Rakuraku Workflow II Cloud

Item

Details

Pre-check

  • Prior configuration in Rakuraku Workflow II Cloud is required.

  • You must create an account in Rakuraku Workflow II Cloud using the same email address as TrustLogin.

  • Please refer to the manual provided by Rakuraku Workflow II Cloud for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Workflow II Cloud (SAML)".
    Rakuraku Workflow II

  3. Note the value of the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png

  4. Set the two blank fields in "Service ACS URL" under "Service Provider Settings" as follows.
    Rakuraku Workflow II Cloud server domain

    Check the domain name included in your login URL
    Note: (e.g.) rakwf.net, delta.rakrak-wfc.net, etc.

    Company Identifier Check this in the Rakuraku Workflow II Cloud admin screen ("System Administration" > "System Settings Change")
    See steps 4-6 of "Rakuraku Workflow II Cloud Configuration" below

    04.png

  5. Save by clicking the "Register" button.

Rakuraku Workflow II Cloud Configuration

  1. Log in to the Rakuraku Workflow II Cloud support site and click "Download > Various Modules" from the left menu.
    05__1_.png

  2. Download the "SAML Configuration Sample (zip file)".
    06.png

  3. After extracting the archive, you will find 3 XML files. Open the two files "SeiSamlLoginRequest.xml" and "SeiSamlLogoutRequest.xml" in a text editor, edit them as follows, and overwrite-save them.

    ① SeiSamlLoginRequest.xml

    Edit the part 【http://★IdP server FQDN★/★IdP server context path★/SSORedirect/metaAlias/idp】
    to the "IdP URL
    " you noted from TrustLogin

    Edit the part 【★WF server domain (rakwf.net or delta.rakrak-wfc.net)★】
    to either of your server's domain names (2 locations)
    Edit the part 【★Company Identifier★】
    to your company identifier

    (Before editing)
    07.png
    (After editing)
    08.png

    ① SeiSamlLogoutRequest.xml

    Edit the part 【http://★IdP server FQDN★/★IdP server context path★/UI/Logout】
    to "https://portal.trustlogin.com/"

    Edit the part 【http://★IdP server FQDN★/★IdP server context path★】
    to the "IdP URL" you noted from TrustLogin
    Edit the part 【★WF server domain (rakwf.net or delta.rakrak-wfc.net)★】
    to either of your server's domain names

    (Before editing)
    09.png
    (After editing)
    10.png

  4. Log in to Rakuraku Workflow II Cloud with an administrator account and click "System Administration".
    11.png

  5. Open "System Settings Change".
    12.png

  6. Click "Update".
    13.png

  7. Set each item in "SAML Authentication Settings" as follows.
    IdP Server Login URL

    The "IdP URL" you noted from TrustLogin

    IdP Server Logout URL https://portal.trustlogin.com/
    IdP Server Certificate The "Certificate" downloaded from TrustLogin
    Login Request XML to IdP Server The "SeiSamlLoginRequest.xml" created in step 3
    Logout Request XML to IdP Server The "SeiSamlLogoutRequest.xml" created in step 3
    Login with This Site's Password "Allow" (recommended)
    Email Address Login "Enable"
    Note: For the "Login with This Site's Password" setting, we recommend changing it to match your operational method after completing the SAML configuration and confirming that SAML authentication is successful.

    14.png

  8. Save the settings by clicking the "Update" button.
    15.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Rakuraku Workflow II Cloud (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Workflow II Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Rakuraku Workflow II Cloud

Item

Details

Pre-check

  • Prior configuration in Rakuraku Workflow II Cloud is required.

  • You must create an account in Rakuraku Workflow II Cloud using the same email address as TrustLogin.

  • Please refer to the manual provided by Rakuraku Workflow II Cloud for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Workflow II Cloud (SAML)".
    Rakuraku Workflow II

  3. Note the value of the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png

  4. Set the two blank fields in "Service ACS URL" under "Service Provider Settings" as follows.
    Rakuraku Workflow II Cloud server domain

    Check the domain name included in your login URL
    Note: (e.g.) rakwf.net, delta.rakrak-wfc.net, etc.

    Company Identifier Check this in the Rakuraku Workflow II Cloud admin screen ("System Administration" > "System Settings Change")
    See steps 4-6 of "Rakuraku Workflow II Cloud Configuration" below

    04.png

  5. Save by clicking the "Register" button.

Rakuraku Workflow II Cloud Configuration

  1. Log in to the Rakuraku Workflow II Cloud support site and click "Download > Various Modules" from the left menu.
    05__1_.png

  2. Download the "SAML Configuration Sample (zip file)".
    06.png

  3. After extracting the archive, you will find 3 XML files. Open the two files "SeiSamlLoginRequest.xml" and "SeiSamlLogoutRequest.xml" in a text editor, edit them as follows, and overwrite-save them.

    ① SeiSamlLoginRequest.xml

    Edit the part 【http://★IdP server FQDN★/★IdP server context path★/SSORedirect/metaAlias/idp】
    to the "IdP URL
    " you noted from TrustLogin

    Edit the part 【★WF server domain (rakwf.net or delta.rakrak-wfc.net)★】
    to either of your server's domain names (2 locations)
    Edit the part 【★Company Identifier★】
    to your company identifier

    (Before editing)
    07.png
    (After editing)
    08.png

    ① SeiSamlLogoutRequest.xml

    Edit the part 【http://★IdP server FQDN★/★IdP server context path★/UI/Logout】
    to "https://portal.trustlogin.com/"

    Edit the part 【http://★IdP server FQDN★/★IdP server context path★】
    to the "IdP URL" you noted from TrustLogin
    Edit the part 【★WF server domain (rakwf.net or delta.rakrak-wfc.net)★】
    to either of your server's domain names

    (Before editing)
    09.png
    (After editing)
    10.png

  4. Log in to Rakuraku Workflow II Cloud with an administrator account and click "System Administration".
    11.png

  5. Open "System Settings Change".
    12.png

  6. Click "Update".
    13.png

  7. Set each item in "SAML Authentication Settings" as follows.
    IdP Server Login URL

    The "IdP URL" you noted from TrustLogin

    IdP Server Logout URL https://portal.trustlogin.com/
    IdP Server Certificate The "Certificate" downloaded from TrustLogin
    Login Request XML to IdP Server The "SeiSamlLoginRequest.xml" created in step 3
    Logout Request XML to IdP Server The "SeiSamlLogoutRequest.xml" created in step 3
    Login with This Site's Password "Allow" (recommended)
    Email Address Login "Enable"
    Note: For the "Login with This Site's Password" setting, we recommend changing it to match your operational method after completing the SAML configuration and confirming that SAML authentication is successful.

    14.png

  8. Save the settings by clicking the "Update" button.
    15.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Rakuraku Workflow II Cloud (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Workflow II Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.