How to Configure SAML Authentication for Rakuraku Meisai

Item

Details

Pre-check

  • Prior configuration in Rakuraku Meisai is required.

  • The "SSO Authenticated ID (NameID)" in the Rakuraku Meisai staff information must match the TrustLogin email address.
  • Please refer to the manual provided by Rakuraku Meisai for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Meisai (SAML)".
    ____01.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    ________01.png

    Now, switch to configuring Rakuraku Meisai. Open Rakuraku Meisai in a separate window.

Rakuraku Meisai Configuration

  1. Log in with an administrator account and open the "Basic Settings" tab.
    ____01.png

  2. Open "System Settings".
    ____02.png

  3. Select "Use" for "Single Sign-On", and configure the items as follows.
    Identity Provider Login URL The IdP URL noted from TrustLogin
    Identity Provider Logout URL https://portal.trustlogin.com/
    Identity Provider Certificate

    Upload the certificate downloaded from TrustLogin


    ____03.png

  4. Using "Download Metadata", download the metadata, and finally click "Change".
  5. Return to the "Basic Settings" tab and open "Staff Management".____05.png

  6. Select the user for whom you want to configure SAML, and click the pencil icon in the operation column.
    __.__06png.png

  7. In "Single Sign-On Authenticated ID (NameID)", enter the email address registered in TrustLogin, and click "Update".
    ____04.png

    Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata you noted from Rakuraku Meisai using "Select Metadata" in "Service Provider Settings".

    ________02.png

  2. Save the configuration by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Rakuraku Meisai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Meisai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Rakuraku Meisai

Item

Details

Pre-check

  • Prior configuration in Rakuraku Meisai is required.

  • The "SSO Authenticated ID (NameID)" in the Rakuraku Meisai staff information must match the TrustLogin email address.
  • Please refer to the manual provided by Rakuraku Meisai for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Rakuraku Meisai (SAML)".
    ____01.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    ________01.png

    Now, switch to configuring Rakuraku Meisai. Open Rakuraku Meisai in a separate window.

Rakuraku Meisai Configuration

  1. Log in with an administrator account and open the "Basic Settings" tab.
    ____01.png

  2. Open "System Settings".
    ____02.png

  3. Select "Use" for "Single Sign-On", and configure the items as follows.
    Identity Provider Login URL The IdP URL noted from TrustLogin
    Identity Provider Logout URL https://portal.trustlogin.com/
    Identity Provider Certificate

    Upload the certificate downloaded from TrustLogin


    ____03.png

  4. Using "Download Metadata", download the metadata, and finally click "Change".
  5. Return to the "Basic Settings" tab and open "Staff Management".____05.png

  6. Select the user for whom you want to configure SAML, and click the pencil icon in the operation column.
    __.__06png.png

  7. In "Single Sign-On Authenticated ID (NameID)", enter the email address registered in TrustLogin, and click "Update".
    ____04.png

    Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata you noted from Rakuraku Meisai using "Select Metadata" in "Service Provider Settings".

    ________02.png

  2. Save the configuration by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Rakuraku Meisai (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Rakuraku Meisai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.