|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search for and select "Rakuraku Workflow II Cloud (SAML)".
- Note the value of the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
- Set the two blank fields in "Service ACS URL" under "Service Provider Settings" as follows.
Rakuraku Workflow II Cloud server domain Check the domain name included in your login URL
Note: (e.g.) rakwf.net, delta.rakrak-wfc.net, etc.Company Identifier Check this in the Rakuraku Workflow II Cloud admin screen ("System Administration" > "System Settings Change")
See steps 4-6 of "Rakuraku Workflow II Cloud Configuration" below
- Save by clicking the "Register" button.
Rakuraku Workflow II Cloud Configuration
- Log in to the Rakuraku Workflow II Cloud support site and click "Download > Various Modules" from the left menu.
- Download the "SAML Configuration Sample (zip file)".
- After extracting the archive, you will find 3 XML files. Open the two files "SeiSamlLoginRequest.xml" and "SeiSamlLogoutRequest.xml" in a text editor, edit them as follows, and overwrite-save them.
① SeiSamlLoginRequest.xml
① Edit the part 【http://★IdP server FQDN★/★IdP server context path★/SSORedirect/metaAlias/idp】
to the "IdP URL" you noted from TrustLogin② Edit the part 【★WF server domain (rakwf.net or delta.rakrak-wfc.net)★】
to either of your server's domain names (2 locations)③ Edit the part 【★Company Identifier★】
to your company identifier
(Before editing)
(After editing)
① SeiSamlLogoutRequest.xml
① Edit the part 【http://★IdP server FQDN★/★IdP server context path★/UI/Logout】
to "https://portal.trustlogin.com/"② Edit the part 【http://★IdP server FQDN★/★IdP server context path★】
to the "IdP URL" you noted from TrustLogin③ Edit the part 【★WF server domain (rakwf.net or delta.rakrak-wfc.net)★】
to either of your server's domain names
(Before editing)
(After editing)
- Log in to Rakuraku Workflow II Cloud with an administrator account and click "System Administration".
- Open "System Settings Change".
- Click "Update".
- Set each item in "SAML Authentication Settings" as follows.
Note: For the "Login with This Site's Password" setting, we recommend changing it to match your operational method after completing the SAML configuration and confirming that SAML authentication is successful.IdP Server Login URL The "IdP URL" you noted from TrustLogin
IdP Server Logout URL https://portal.trustlogin.com/ IdP Server Certificate The "Certificate" downloaded from TrustLogin Login Request XML to IdP Server The "SeiSamlLoginRequest.xml" created in step 3 Logout Request XML to IdP Server The "SeiSamlLogoutRequest.xml" created in step 3 Login with This Site's Password "Allow" (recommended) Email Address Login "Enable"
- Save the settings by clicking the "Update" button.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "Rakuraku Workflow II Cloud (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the browser extension, and confirm that login is successful.
② When an Administrator Adds Members
- Search for and click the "Rakuraku Workflow II Cloud (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.