Secioss Identity Suite Cloud Edition SaaSƳÆþ
Secioss Identity Suite Cloud Edition¤Ï¡¢¥¯¥é¥¦¥É¥³¥ó¥Ô¥å¡¼¥Æ¥£¥ó¥°´Ä¶¤Ë¤ª¤¤¤ÆSAML 2.0¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤äSOAPÄÌ¿®¤Ë¤è¤ë¥¢¥«¥¦¥ó¥ÈƱ´ü¤ò¥µ¥¤¥È´Ö¤Ç¼Â¸½¤¹¤ë¥½¥Õ¥È¥¦¥§¥¢¤Ç¤¹¡£
Secioss Identity Suite Cloud Edition¡Ê°Ê¹ßIdentity Suite Cloud¤È¤·¤Þ¤¹¡Ë¤òSaaS·¿¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƳÆþ¤¹¤ë¤³¤È¤Ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ°Ê²¼¤Îµ¡Ç½¤ò´Êñ¤ËÄɲ乤뤳¤È¤Ç¤¤Þ¤¹¡£
¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
SAML¤ÎService Provider¤È¤·¤ÆÆ°ºî¤·¡¢SAML¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¤¤Þ¤¹¡£SaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÏIdentity Suite Cloud¤ÎÂåÍýǧ¾Úµ¡Ç½¤Ë¤è¤ê´Êñ¤ËSAMLǧ¾Úµ¡Ç½¤òÁȤ߹þ¤à¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
¥¢¥«¥¦¥ó¥ÈƱ´ü
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥¢¥«¥¦¥ó¥È´ÉÍýÍÑSOAP API¤òÄ󶡤·¡¢SOAP·Ðͳ¤Ç¤Î¥¢¥«¥¦¥ó¥È´ÉÍý¤äSaaS´Ö¤Ç¤Î¥¢¥«¥¦¥ó¥ÈƱ´ü¤ò¼Â¸½¤·¤Þ¤¹¡£Identity Suite Cloud¤Ï¡¢SOAP API¤Ç¼õ¤±ÉÕ¤±¤¿¹¹¿·Í×µá¤ò¡¢LISM¤Ë¤è¤êSaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤ØÈ¿±Ç¤·¤Þ¤¹¡£
º£²ó¤ÏSaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËIdentity Suite Cloud¤òSaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƳÆþ¤·¤Æ¡¢Æ°ºî¸¡¾Ú¤ò¹Ô¤¦¤¿¤á¤ÎÊýË¡¤Ë¤Ä¤¤¤Æ²òÀ⤷¤Þ¤¹¡£
¥ª¡¼¥×¥ó¥½¡¼¥¹¥×¥í¥¸¥§¥¯¥È
Identity Suite Cloud¤Ë¤Ä¤¤¤Æ¤Ï¡¢¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤È¤·¤ÆGPL¥é¥¤¥»¥ó¥¹¤Ë¤è¤ê¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£
¡¦¥×¥í¥¸¥§¥¯¥È¥µ¥¤¥È¡§http://sourceforge.jp/projects/secioss-auth/
¡¦¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¡§http://lists.sourceforge.jp/mailman/listinfo/secioss-auth-users
1. ¥¤¥ó¥¹¥È¡¼¥ë
Identity Suite Cloud SP¤Î¿ä¾©´Ä¶¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£
¡¦OS¡§ CentOS 5¡¢RedHat Enterprise Linux 5
¡¦Web¥µ¡¼¥Ð¡§ Apache 2.2
º£²ó¤Î¥¤¥ó¥¹¥È¡¼¥ë´Ä¶¤È¤·¤Æ¤Ï¡¢Linux¤ÎCentOS 5¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£
1.1 ɬÍפʥ½¥Õ¥È¥¦¥§¥¢¤Î¥¤¥ó¥¹¥È¡¼¥ë
# yum install libtool-ltdl
# yum install perl-LDAP
# yum install perl-DBI
# yum install perl-DBD-Pg
# yum install perl-XML-LibXML
# yum install perl-XML-Simple
# yum install perl-TimeDate
# yum install php-pear
# yum install php-xml
# yum install php-soap
1.2 Identity Suite Cloud SP
http://sourceforge.jp/projects/secioss-auth/releases/¤«¤ésecioss-idsuite-cloud-sp-2.0.x.tgz¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ²¼¤µ¤¤¡£
secioss-idsuite-cloud-sp¥Ñ¥Ã¥±¡¼¥¸¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£
# tar zxvf secioss-idsuite-cloud-sp-2.0.x.tgz
# cd secioss-idsuite-cloud-sp-2.0.x
# ./install.sh install
¤Þ¤¿¡¢¥Ñ¥Ã¥±¡¼¥¸¤ò¥¢¥Ã¥×¥Ç¡¼¥È¤¹¤ë¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./install.sh update
1.3 ¥í¥°¤ÎÀßÄê
¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈIDƱ´ü¤Î¥í¥°¤Ï¡¢¤½¤ì¤¾¤ìsyslog¤Îlocal5¡¢local4¤Ë½ÐÎϤ·¤Þ¤¹¡£
/etc/syslog.conf¤Ë°Ê²¼¤ÎÀßÄê¤òÄɵ¤·¤Æ¡¢syslog¥Ç¡¼¥â¥ó¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£
local5.* -/var/log/auth.log
local4.* -/var/log/lism.log
2. ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
2.1 SAMLǧ¾Ú¤ÎÀßÄê
SAMLǧ¾Ú¡ÊSP¡Ë¤ÎÀßÄê¤ò¹Ô¤¦¤Ë¤Ï¡¢°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./config.sh sso
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¡§ ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL
¥»¥Ã¥·¥ç¥ó¤Î¥¯¥Ã¥¡¼Ì¾¡§¡¡¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥»¥Ã¥·¥ç¥ó¤òÊÝ»ý¤¹¤ë¥¯¥Ã¥¡¼Ì¾
¼¡¤ËSAMLǧ¾ÚÍѤÎÈëÌ©¸°¤È¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
°Ê²¼¤ÏOpenSSL¤Ë¤è¤ëÈëÌ©¸°¤È¸ø³«¸°¤ÎºîÀ®¼ê½ç¤Ç¤¹¡£
¡ ÈëÌ©¸°¤òºîÀ®¤·¤Þ¤¹¡£
# cd /etc/pki/tls/certs
# make test.key
ÈëÌ©¸°¤«¤é¥Ñ¥¹¥ï¡¼¥É¤òºï½ü¤·¤Þ¤¹¡£
# openssl rsa -in test.key -out test.key
¢ ¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
# make test.crt
Country Name (2 letter code) [GB]:JP¡¡←¡¡¹ñ̾
State or Province Name (full name) [Berkshire]:Tokyo¡¡←¡¡ÅÔÆ»Éܸ©Ì¾
Locality Name (eg, city) [Newbury]:Bunkyo¡¡←¡¡»Ô¶èĮ¼̾
Organization Name (eg, company) [My Company Ltd]:TEST, Inc¡¡←¡¡²ñ¼Ò̾
Organizational Unit Name (eg, section) []:¡¡←¡¡¶õENTER
Common Name (eg, your name or your server's hostname) []:sp.test.co.jp¡¡←¡¡¥Û¥¹¥È̾
Email Address []:admin@test.co.jp¡¡←¡¡´ÉÍý¼Ô¥á¡¼¥ë¥¢¥É¥ì¥¹
ÈëÌ©¸°¤Ï¡¢"/usr/share/simplesamlphp/cert/PrivateKey.pem"¤Ë¥³¥Ô¡¼¤·¤Æ¡¢½êͼԤòapache¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£
# chown apache /usr/share/simplesamlphp/cert/PrivateKey.pem
¸ø³«¸°¤Ï¡¢idsuite@secioss.co.jp°¸¤Ë°Ê²¼¤ÎÆâÍÆ¤È¤È¤â¤Ë¥á¡¼¥ë¤ÇÁ÷¿®¤·¤Æ¡¢Ç§¾Ú¥µ¡¼¥Ð¤ËÂФ¹¤ëÀܳ³Îǧ¤Î¿½ÀÁ¤ò¹Ô¤¤¤Þ¤¹¡£
¡¦»á̾
¡¦²ñ¼Ò̾
¡¦¥É¥á¥¤¥ó̾¡Ê¥Æ¥Ê¥ó¥ÈID¤Ë¤Ê¤ê¤Þ¤¹¡Ë
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¡ÊÎã¡§ https://sp.example.com/app/¡Ë
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾¡Ê±Ñ¿ô»ú¤Î¤ß¡¡Îã¡§ SugarCRM¡Ë
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¥í¥°¥¤¥ó¤¹¤ëID¤Î·Á¼°¡Ê¥æ¡¼¥¶ID¡¢¤Þ¤¿¤Ï¥á¡¼¥ë¥¢¥É¥ì¥¹¡Ë
¡¦´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾¡Ê±Ñ¿ô»ú¤Î¤ß¡Ë
¡¦¥Ñ¥¹¥ï¡¼¥É¡ÊǤ°Õ¡Ë
¡¦»ÈÍÑÌÜŪ
ºÇ¸å¤ËApache¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£
# /etc/init.d/httpd restart
2.2 ÂåÍýǧ¾Ú¤ÎÀßÄê
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¼«Æ°¤Ç¥í¥°¥¤¥ó¤¹¤ë¤¿¤á¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
ÀßÄê¥Õ¥¡¥¤¥ë¤Ï¡¢"/var/www/conf/<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾¡ÊÁ´¤Æ¾®Ê¸»ú¡Ë>.ini"¤È¤·¤ÆºîÀ®¤·¤Æ²¼¤µ¤¤¡£
°Ê²¼¤ÏSugarCRMÍѤÎÀßÄêÎã¤Ç¤¹¡£
[url]
login = "https://sp.example.com/SugarCE/index.php?action=Login&module=Users"
back = "/SugarCE/"
[postName]
username = user_name
password = user_password
[postData]
module = Users
action = Authenticate
return_module = Users
return_action = Login
cant_login = ""
login_module = ""
login_action = ""
login_record = ""
login_theme = Sugar
login_language = ja
login_button = " ¥í¥°¥¤¥ó "
|
url |
login |
¥í¥°¥¤¥ó¤¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL |
|
back |
¥í¥°¥¤¥ó¸å¤Ëɽ¼¨¤¹¤ë²èÌ̤ÎURL |
|
|
postName |
username |
¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥æ¡¼¥¶Ì¾¤ÎÊÑ¿ô̾ |
|
password |
¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥Ñ¥¹¥ï¡¼¥É¤ÎÊÑ¿ô̾ |
[postData]¤Ë¤Ï¡¢POST¤¹¤ë¥Ç¡¼¥¿¤ÎÊÑ¿ô̾¤ÈÃͤÎÁȤ߹ç¤ï¤»¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£
2.3 ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î³Îǧ
"<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL>/sso/autologin.php?sso_app=<2.2¹à¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾>"¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¹¤ë¤³¤È¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£
3. IDƱ´ü
3.1 IDƱ´ü¤ÎÀßÄê
Identity Suite Cloud¤Ï¡¢LISM¤Ë¤è¤Ã¤ÆÄê´üŪ¤ËSeciosLink¤«¤é¹¹¿·¥Ç¡¼¥¿¤ò¼èÆÀ¤·¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤äLDAP¤Î¥¢¥«¥¦¥ó¥È¤ò¹¹¿·¤·¤Þ¤¹¡£
ºÇ½é¤Ë¡¢°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./config.sh idm
¥Æ¥Ê¥ó¥ÈID¡§¡¡SeciossLink¤Î¥Æ¥Ê¥ó¥ÈID
¥µ¡¼¥Ó¥¹ID¡§¡¡2.3¹à¤Î¥µ¡¼¥Ó¥¹ID¡Ê¥Æ¥Ê¥ó¥ÈID¤Ï½ü¤¯¡Ë
´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾¡§¡¡SeciossLink¤Î´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾
´ÉÍý¼Ô¥Ñ¥¹¥ï¡¼¥É¡§¡¡´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Î¥Ñ¥¹¥ï¡¼¥É
¥æ¡¼¥¶ID¤Î°À [1.¥æ¡¼¥¶ID|2.¥æ¡¼¥¶ID@¥Æ¥Ê¥ó¥ÈID|3.¥á¡¼¥ë¥¢¥É¥ì¥¹|4.¼Ò°÷ÈÖ¹æ|5.¥µ¡¼¥Ó¥¹¸ÄÊÌ¤Î¥í¥°¥¤¥óID]¡§¡¡ IDƱ´üÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥æ¡¼¥¶ID¤Ë»ÈÍѤ¹¤ë°À¤òÈÖ¹æ¤Ç»ØÄê
LISM¤ÎÀßÄê¥Õ¥¡¥¤¥ëlism.conf¤Ë¤Ï¡¢¹¹¿·ÂоݤΥǡ¼¥¿¥Ù¡¼¥¹¡¢¤Þ¤¿¤ÏLDAP¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
LISM¤ÎÀßÄêÊýË¡¤Ë¤Ä¤¤¤Æ¤Ï¡¢LISM¤Î¥µ¥¤¥È¤ò¤´Í÷²¼¤µ¤¤¡£
SugarCRM¤òÎã¤È¤·¤ÆLISM¤ÎÀßÄê¤òÎ㼨¤·¤Þ¤¹¡£
lism.conf
<config>
<sync>
<data name="SP">
<object name="User">
<syncdn>ou=People</syncdn>
<syncfilter>(&(!(seciossAccountStatus=deleted))(&(seciossAllowedService=sp01)(objectClass=inetOrgPerson)))</syncfilter>
<syncattr>
<name>sn</name>
</syncattr>
<syncattr>
<name>givenName</name>
</syncattr>
<syncattr>
<name>sn;lang-ja;phonetic</name>
</syncattr>
<syncattr>
<name>givenName;lang-ja;phonetic</name>
</syncattr>
<syncattr>
<name>mail</name>
</syncattr>
</object>
</data>
</sync>
<data name="SP">
<container>
<oc>organizationalUnit</oc>
<rdn>o=SP</rdn>
</container>
<handler name="Rewrite">
<rewrite context="request" match="createtimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="createtimestamp: %1-%2-%3 %4:%5:%6"/>
<rewrite context="searchResult" match="createtimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="createtimestamp: %1%2%3%4%5%6Z"/>
<rewrite context="request" match="modifytimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="modifytimestamp: %1-%2-%3 %4:%5:%6"/>
<rewrite context="searchResult" match="modifytimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="modifytimestamp: %1%2%3%4%5%6Z"/>
</handler>
<storage name="SQL" hash="MD5:hex">
<libload>LISM/Utils/lism_util.pl</libload>
<libload>LISM/Utils/lism_sugarcrm.pl</libload>
<dsn>DBI:mysql:sugarcrm:localhost</dsn>
<admin>admin</admin>
<passwd>secret</passwd>
<initquery>set names utf8</initquery>
<noop>delete</noop>
<object name="User">
<container>
<rdn>ou=People</rdn>
<oc>organizationalUnit</oc>
</container>
<table>users</table>
<id>
<column>id</column>
</id>
<oc>Person</oc>
<oc>inetOrgPerson</oc>
<oc>seciossIamAccount</oc>
<rdn>uid</rdn>
<attr name="uid">
<column>user_name</column>
</attr>
<attr name="cn">
<selexpr>ifnull(concat(last_name, ' ', first_name), last_name)</selexpr>
</attr>
<attr name="sn">
<column>last_name</column>
</attr>
<attr name="givenname">
<column>first_name</column>
</attr>
<attr name="title">
<column>title</column>
</attr>
<attr name="department">
<column>department</column>
</attr>
<attr name="userpassword">
<column>user_hash</column>
</attr>
<attr name="homephone">
<column>phone_home</column>
</attr>
<attr name="telephonenumber">
<column>phone_work</column>
</attr>
<attr name="mobile">
<column>phone_mobile</column>
</attr>
<attr name="facsimiletelephonenumber">
<column>phone_fax</column>
</attr>
<attr name="ipphone">
<column>phone_other</column>
</attr>
<attr name="street">
<column>address_street</column>
</attr>
<attr name="l">
<column>address_city</column>
</attr>
<attr name="st">
<column>address_state</column>
</attr>
<attr name="c">
<column>address_country</column>
</attr>
<attr name="postalcode">
<column>address_postalcode</column>
</attr>
<attr name="createtimestamp">
<column>date_entered</column>
</attr>
<attr name="modifytimestamp">
<column>date_modified</column>
</attr>
<attr name="description">
<column>description</column>
</attr>
<attr name="mail">
<selexpr>email_address</selexpr>
<fromtbls>email_addresses,email_addr_bean_rel</fromtbls>
<joinwhere>email_addr_bean_rel.bean_id = users.id and email_addr_bean_rel.email_address_id = email_addresses.id</joinwhere>
<addproc>insert into email_addresses values('%{createGuid()}', '%a', upper('%a'), 0, 0, now(), now(), 0)</addproc>
<addproc>set @paddr=if((select count(*) from email_addr_bean_rel where bean_id = '%o'), 0, 1)</addproc>
<addproc>insert into email_addr_bean_rel values('%{createGuid()}', (select id from email_addresses where email_addr
ess = '%a'), '%o', 'Users', @paddr, if(@paddr, 0, 1), now(), now(), 0)</addproc>
<delproc>set @mailid=(select id from email_addresses where email_address = '%a' and id in (select email_address_id from email_addr_bean_rel where bean_id = '%o'))</delproc>
<delproc>delete from email_addresses where id = @mailid</delproc>
<delproc>delete from email_addr_bean_rel where bean_id = '%o' and email_address_id = @mailid</delproc>
</attr>
<attr name="manager">
<oname>User</oname>
<where>id = (select reports_to_id from users where id = '%o')</where>
<addproc>update users set reports_to_id = '%a' where id = '%o'</addproc>
<delproc>update users set reports_to_id = null where id = '%o'</delproc>
</attr>
<strginfo>
<column>id</column>
<value type="function">createGuid()</value>
</strginfo>
<strginfo>
<column>status</column>
<value type="constant">Active</value>
<delproc>update users set status = 'Inactive' where id = '%o'</delproc>
</strginfo>
<strginfo>
<addproc>insert into user_preferences values('%{createGuid()}', 'global', 0, now(), now(), '%o', '%{encode_base64(getFileContents("/opt/secioss/etc/sugarcrm-userpref.txt"), "")}')</addproc>
</strginfo>
</object>
</storage>
</data>
</config>
ÀßÄê¤Î³Îǧ¤Ï¡¢LISM¥µ¡¼¥Ð¤Î¥Ç¡¼¥â¥ó¤òµ¯Æ°¤·¤Æ¡¢¥Ç¡¼¥¿¤Î¸¡º÷¤ä¹¹¿·¤òLISM¤ËÂФ·¤Æ¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¥Ç¡¼¥â¥ó¤òµ¯Æ°¤¹¤ë¾ì¹ç¤Ï¡¢°ì»þŪ¤Ë"<oc>seciossIamAccount</oc>"¤Î¹Ô¤ò¥³¥á¥ó¥È¥¢¥¦¥È¤·¤Æ²¼¤µ¤¤¡£
# cp /opt/secioss/etc/openldap/slapd.conf.lism /opt/secioss/etc/openldap/slapd.conf
# /opt/secioss/sbin/slapd -h ldap://:3890 -u ldap -d256
# ldapseach -H ldap://:3890 -b 'dc=lism,dc=com' # ¸¡º÷¤Î¾ì¹ç
3.2 IDƱ´ü¤Î³Îǧ
https://slink.secioss.com/tenantadmin/¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Ç¥í¥°¥¤¥ó¤·¤Þ¤¹¡£
º¸Â¦¥á¥Ë¥å¡¼¤Î¥ê¥ó¥¯¤«¤éID´ÉÍý¤Ë¥¢¥¯¥»¥¹¤·¤Æ²¼¤µ¤¤¡£
¥æ¡¼¥¶¤Î”¿·µ¬ÅÐÏ¿”¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢¿·µ¬ÅÐÏ¿²èÌ̤«¤é¡¢µö²Ä¤¹¤ë¥µ¡¼¥Ó¥¹¤Ë¼«¿È¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÁªÂò¤·¤Æ¡¢ÅÐÏ¿¤ò¹Ô¤¤¤Þ¤¹¡£
¿·µ¬ÅÐÏ¿¤ÎÀµ¾ï½ªÎ»¸å¡¢¥æ¡¼¥¶¤Î¸¡º÷¥á¥Ë¥å¡¼¤Î”¥·¥¹¥Æ¥à”¤«¤é¼«¿È¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÁªÂò¤·¤Æ¡¢¸¡º÷¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£ÅÐÏ¿¤·¤¿¥æ¡¼¥¶¤¬¸¡º÷·ë²Ì¤Ëɽ¼¨¤µ¤ì¤ì¤Ð¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ØÀµ¾ï¤Ë¥æ¡¼¥¶¤¬Æ±´ü¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
Àµ¾ï¤ËƱ´ü¤µ¤ì¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ï¡¢¾åÉô¤Î¥á¥Ë¥å¡¼¤Î¥í¥°¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢ID´ÉÍý¤Î¥í¥°¤ò¸¡º÷¤·¤Æ¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£
- µ»ö¤Î¾ÜºÙ¤Ï¤³¤Á¤é
- by
- at 23:55
- Trackbacks (0)



