Secioss Identity Suite Cloud Edition SaaSƳÆþ

Secioss Identity Suite Cloud Edition¤Ï¡¢¥¯¥é¥¦¥É¥³¥ó¥Ô¥å¡¼¥Æ¥£¥ó¥°´Ä¶­¤Ë¤ª¤¤¤ÆSAML 2.0¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤äSOAPÄÌ¿®¤Ë¤è¤ë¥¢¥«¥¦¥ó¥ÈƱ´ü¤ò¥µ¥¤¥È´Ö¤Ç¼Â¸½¤¹¤ë¥½¥Õ¥È¥¦¥§¥¢¤Ç¤¹¡£

 

Secioss Identity Suite Cloud Edition¡Ê°Ê¹ßIdentity Suite Cloud¤È¤·¤Þ¤¹¡Ë¤òSaaS·¿¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƳÆþ¤¹¤ë¤³¤È¤Ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ°Ê²¼¤Îµ¡Ç½¤ò´Êñ¤ËÄɲ乤뤳¤È¤Ç¤­¤Þ¤¹¡£

 

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
SAML¤ÎService Provider¤È¤·¤ÆÆ°ºî¤·¡¢SAML¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¤¤Þ¤¹¡£SaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÏIdentity Suite Cloud¤ÎÂåÍýǧ¾Úµ¡Ç½¤Ë¤è¤ê´Êñ¤ËSAMLǧ¾Úµ¡Ç½¤òÁȤ߹þ¤à¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

¥¢¥«¥¦¥ó¥ÈƱ´ü
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥¢¥«¥¦¥ó¥È´ÉÍýÍÑSOAP API¤òÄ󶡤·¡¢SOAP·Ðͳ¤Ç¤Î¥¢¥«¥¦¥ó¥È´ÉÍý¤äSaaS´Ö¤Ç¤Î¥¢¥«¥¦¥ó¥ÈƱ´ü¤ò¼Â¸½¤·¤Þ¤¹¡£Identity Suite Cloud¤Ï¡¢SOAP API¤Ç¼õ¤±ÉÕ¤±¤¿¹¹¿·Í×µá¤ò¡¢LISM¤Ë¤è¤êSaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤ØÈ¿±Ç¤·¤Þ¤¹¡£

 

º£²ó¤ÏSaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËIdentity Suite Cloud¤òSaaS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƳÆþ¤·¤Æ¡¢Æ°ºî¸¡¾Ú¤ò¹Ô¤¦¤¿¤á¤ÎÊýË¡¤Ë¤Ä¤¤¤Æ²òÀ⤷¤Þ¤¹¡£ 

 

¥ª¡¼¥×¥ó¥½¡¼¥¹¥×¥í¥¸¥§¥¯¥È

Identity Suite Cloud¤Ë¤Ä¤¤¤Æ¤Ï¡¢¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤È¤·¤ÆGPL¥é¥¤¥»¥ó¥¹¤Ë¤è¤ê¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£
¡¦¥×¥í¥¸¥§¥¯¥È¥µ¥¤¥È¡§http://sourceforge.jp/projects/secioss-auth/
¡¦¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¡§http://lists.sourceforge.jp/mailman/listinfo/secioss-auth-users

 

 

1. ¥¤¥ó¥¹¥È¡¼¥ë

Identity Suite Cloud SP¤Î¿ä¾©´Ä¶­¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£
¡¦OS¡§ CentOS 5¡¢RedHat Enterprise Linux 5
¡¦Web¥µ¡¼¥Ð¡§ Apache 2.2

º£²ó¤Î¥¤¥ó¥¹¥È¡¼¥ë´Ä¶­¤È¤·¤Æ¤Ï¡¢Linux¤ÎCentOS 5¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£

 

1.1  ɬÍפʥ½¥Õ¥È¥¦¥§¥¢¤Î¥¤¥ó¥¹¥È¡¼¥ë

# yum install libtool-ltdl
# yum install perl-LDAP
# yum install perl-DBI
# yum install perl-DBD-Pg
# yum install perl-XML-LibXML
# yum install perl-XML-Simple
# yum install perl-TimeDate
# yum install php-pear
# yum install php-xml
# yum install php-soap 

 

1.2 Identity Suite Cloud SP

http://sourceforge.jp/projects/secioss-auth/releases/¤«¤ésecioss-idsuite-cloud-sp-2.0.x.tgz¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ²¼¤µ¤¤¡£

secioss-idsuite-cloud-sp¥Ñ¥Ã¥±¡¼¥¸¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£
# tar zxvf secioss-idsuite-cloud-sp-2.0.x.tgz
# cd secioss-idsuite-cloud-sp-2.0.x
# ./install.sh install

 

¤Þ¤¿¡¢¥Ñ¥Ã¥±¡¼¥¸¤ò¥¢¥Ã¥×¥Ç¡¼¥È¤¹¤ë¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./install.sh update

 

1.3 ¥í¥°¤ÎÀßÄê

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈIDƱ´ü¤Î¥í¥°¤Ï¡¢¤½¤ì¤¾¤ìsyslog¤Îlocal5¡¢local4¤Ë½ÐÎϤ·¤Þ¤¹¡£
/etc/syslog.conf¤Ë°Ê²¼¤ÎÀßÄê¤òÄɵ­¤·¤Æ¡¢syslog¥Ç¡¼¥â¥ó¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£


local5.*                                         -/var/log/auth.log
local4.*                                         -/var/log/lism.log


 

 

2. ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó

2.1 SAMLǧ¾Ú¤ÎÀßÄê

SAMLǧ¾Ú¡ÊSP¡Ë¤ÎÀßÄê¤ò¹Ô¤¦¤Ë¤Ï¡¢°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./config.sh sso
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¡§ ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL
¥»¥Ã¥·¥ç¥ó¤Î¥¯¥Ã¥­¡¼Ì¾¡§¡¡¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥»¥Ã¥·¥ç¥ó¤òÊÝ»ý¤¹¤ë¥¯¥Ã¥­¡¼Ì¾

 

¼¡¤ËSAMLǧ¾ÚÍѤÎÈëÌ©¸°¤È¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
°Ê²¼¤ÏOpenSSL¤Ë¤è¤ëÈëÌ©¸°¤È¸ø³«¸°¤ÎºîÀ®¼ê½ç¤Ç¤¹¡£
­¡ ÈëÌ©¸°¤òºîÀ®¤·¤Þ¤¹¡£
# cd /etc/pki/tls/certs
# make test.key
ÈëÌ©¸°¤«¤é¥Ñ¥¹¥ï¡¼¥É¤òºï½ü¤·¤Þ¤¹¡£
# openssl rsa -in test.key -out test.key

­¢ ¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
# make test.crt
Country Name (2 letter code) [GB]:JP¡¡←¡¡¹ñ̾
State or Province Name (full name) [Berkshire]:Tokyo¡¡←¡¡ÅÔÆ»Éܸ©Ì¾
Locality Name (eg, city) [Newbury]:Bunkyo¡¡←¡¡»Ô¶èĮ¼̾
Organization Name (eg, company) [My Company Ltd]:TEST, Inc¡¡←¡¡²ñ¼Ò̾
Organizational Unit Name (eg, section) []:¡¡←¡¡¶õENTER
Common Name (eg, your name or your server's hostname) []:sp.test.co.jp¡¡←¡¡¥Û¥¹¥È̾
Email Address []:admin@test.co.jp¡¡←¡¡´ÉÍý¼Ô¥á¡¼¥ë¥¢¥É¥ì¥¹

 

ÈëÌ©¸°¤Ï¡¢"/usr/share/simplesamlphp/cert/PrivateKey.pem"¤Ë¥³¥Ô¡¼¤·¤Æ¡¢½êÍ­¼Ô¤òapache¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£
# chown apache /usr/share/simplesamlphp/cert/PrivateKey.pem

 

¸ø³«¸°¤Ï¡¢idsuite@secioss.co.jp°¸¤Ë°Ê²¼¤ÎÆâÍÆ¤È¤È¤â¤Ë¥á¡¼¥ë¤ÇÁ÷¿®¤·¤Æ¡¢Ç§¾Ú¥µ¡¼¥Ð¤ËÂФ¹¤ëÀܳ³Îǧ¤Î¿½ÀÁ¤ò¹Ô¤¤¤Þ¤¹¡£
¡¦»á̾
¡¦²ñ¼Ò̾
¡¦¥É¥á¥¤¥ó̾¡Ê¥Æ¥Ê¥ó¥ÈID¤Ë¤Ê¤ê¤Þ¤¹¡Ë
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¡ÊÎã¡§ https://sp.example.com/app/¡Ë
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾¡Ê±Ñ¿ô»ú¤Î¤ß¡¡Îã¡§ SugarCRM¡Ë
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¥í¥°¥¤¥ó¤¹¤ëID¤Î·Á¼°¡Ê¥æ¡¼¥¶ID¡¢¤Þ¤¿¤Ï¥á¡¼¥ë¥¢¥É¥ì¥¹¡Ë
¡¦´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾¡Ê±Ñ¿ô»ú¤Î¤ß¡Ë
¡¦¥Ñ¥¹¥ï¡¼¥É¡ÊǤ°Õ¡Ë
¡¦»ÈÍÑÌÜŪ

 

ºÇ¸å¤ËApache¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£
# /etc/init.d/httpd restart

 

 

2.2 ÂåÍýǧ¾Ú¤ÎÀßÄê

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¼«Æ°¤Ç¥í¥°¥¤¥ó¤¹¤ë¤¿¤á¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£

ÀßÄê¥Õ¥¡¥¤¥ë¤Ï¡¢"/var/www/conf/<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾¡ÊÁ´¤Æ¾®Ê¸»ú¡Ë>.ini"¤È¤·¤ÆºîÀ®¤·¤Æ²¼¤µ¤¤¡£
°Ê²¼¤ÏSugarCRMÍѤÎÀßÄêÎã¤Ç¤¹¡£


[url]
login = "https://sp.example.com/SugarCE/index.php?action=Login&module=Users"
back = "/SugarCE/"

 

[postName]
username = user_name
password = user_password

 

[postData]
module = Users
action = Authenticate
return_module = Users
return_action = Login
cant_login = ""
login_module = ""
login_action = ""
login_record = ""
login_theme = Sugar
login_language = ja
login_button = "  ¥í¥°¥¤¥ó  "


 

url

login

¥í¥°¥¤¥ó¤¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL

back

¥í¥°¥¤¥ó¸å¤Ëɽ¼¨¤¹¤ë²èÌ̤ÎURL

postName

username

¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥æ¡¼¥¶Ì¾¤ÎÊÑ¿ô̾

password

¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥Ñ¥¹¥ï¡¼¥É¤ÎÊÑ¿ô̾

 

[postData]¤Ë¤Ï¡¢POST¤¹¤ë¥Ç¡¼¥¿¤ÎÊÑ¿ô̾¤ÈÃͤÎÁȤ߹ç¤ï¤»¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£   

 

 

2.3 ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î³Îǧ

"<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL>/sso/autologin.php?sso_app=<2.2¹à¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾>"¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¹¤ë¤³¤È¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£

 

 

3. IDƱ´ü

3.1  IDƱ´ü¤ÎÀßÄê

Identity Suite Cloud¤Ï¡¢LISM¤Ë¤è¤Ã¤ÆÄê´üŪ¤ËSeciosLink¤«¤é¹¹¿·¥Ç¡¼¥¿¤ò¼èÆÀ¤·¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤äLDAP¤Î¥¢¥«¥¦¥ó¥È¤ò¹¹¿·¤·¤Þ¤¹¡£

ºÇ½é¤Ë¡¢°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./config.sh idm
¥Æ¥Ê¥ó¥ÈID¡§¡¡SeciossLink¤Î¥Æ¥Ê¥ó¥ÈID
¥µ¡¼¥Ó¥¹ID¡§¡¡2.3¹à¤Î¥µ¡¼¥Ó¥¹ID¡Ê¥Æ¥Ê¥ó¥ÈID¤Ï½ü¤¯¡Ë
´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾¡§¡¡SeciossLink¤Î´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾
´ÉÍý¼Ô¥Ñ¥¹¥ï¡¼¥É¡§¡¡´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Î¥Ñ¥¹¥ï¡¼¥É
¥æ¡¼¥¶ID¤Î°À­ [1.¥æ¡¼¥¶ID|2.¥æ¡¼¥¶ID@¥Æ¥Ê¥ó¥ÈID|3.¥á¡¼¥ë¥¢¥É¥ì¥¹|4.¼Ò°÷ÈÖ¹æ|5.¥µ¡¼¥Ó¥¹¸ÄÊÌ¤Î¥í¥°¥¤¥óID]¡§¡¡ IDƱ´üÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥æ¡¼¥¶ID¤Ë»ÈÍѤ¹¤ë°À­¤òÈÖ¹æ¤Ç»ØÄê

 

LISM¤ÎÀßÄê¥Õ¥¡¥¤¥ëlism.conf¤Ë¤Ï¡¢¹¹¿·ÂоݤΥǡ¼¥¿¥Ù¡¼¥¹¡¢¤Þ¤¿¤ÏLDAP¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
LISM¤ÎÀßÄêÊýË¡¤Ë¤Ä¤¤¤Æ¤Ï¡¢LISM¤Î¥µ¥¤¥È¤ò¤´Í÷²¼¤µ¤¤¡£  

SugarCRM¤òÎã¤È¤·¤ÆLISM¤ÎÀßÄê¤òÎ㼨¤·¤Þ¤¹¡£ 

 

lism.conf


<config>
  <sync>
    <data name="SP">
      <object name="User">
        <syncdn>ou=People</syncdn>
        <syncfilter>(&amp;(!(seciossAccountStatus=deleted))(&amp;(seciossAllowedService=sp01)(objectClass=inetOrgPerson)))</syncfilter>
        <syncattr>
          <name>sn</name>
        </syncattr>
        <syncattr>
          <name>givenName</name>
        </syncattr>
        <syncattr>
          <name>sn;lang-ja;phonetic</name>
        </syncattr>
        <syncattr>
          <name>givenName;lang-ja;phonetic</name>
        </syncattr>
        <syncattr>
          <name>mail</name>
        </syncattr>
      </object>
    </data>
  </sync>
  <data name="SP">
    <container>
      <oc>organizationalUnit</oc>
      <rdn>o=SP</rdn>
    </container>
    <handler name="Rewrite">
      <rewrite context="request" match="createtimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="createtimestamp: %1-%2-%3 %4:%5:%6"/>
      <rewrite context="searchResult" match="createtimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="createtimestamp: %1%2%3%4%5%6Z"/>
      <rewrite context="request" match="modifytimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="modifytimestamp: %1-%2-%3 %4:%5:%6"/>
      <rewrite context="searchResult" match="modifytimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="modifytimestamp: %1%2%3%4%5%6Z"/>
    </handler>
    <storage name="SQL" hash="MD5:hex">
      <libload>LISM/Utils/lism_util.pl</libload>
      <libload>LISM/Utils/lism_sugarcrm.pl</libload>
      <dsn>DBI:mysql:sugarcrm:localhost</dsn>
      <admin>admin</admin>
      <passwd>secret</passwd>
      <initquery>set names utf8</initquery>
      <noop>delete</noop>
      <object name="User">
        <container>
          <rdn>ou=People</rdn>
          <oc>organizationalUnit</oc>
        </container>
        <table>users</table>
        <id>
          <column>id</column>
        </id>
        <oc>Person</oc>
        <oc>inetOrgPerson</oc>
        <oc>seciossIamAccount</oc>
        <rdn>uid</rdn>
        <attr name="uid">
          <column>user_name</column>
        </attr>
        <attr name="cn">
          <selexpr>ifnull(concat(last_name, ' ', first_name), last_name)</selexpr>
        </attr>
        <attr name="sn">
          <column>last_name</column>
        </attr>
        <attr name="givenname">
          <column>first_name</column>
        </attr>
        <attr name="title">
          <column>title</column>
        </attr>
        <attr name="department">
          <column>department</column>
        </attr>
        <attr name="userpassword">
          <column>user_hash</column>
        </attr>
        <attr name="homephone">
          <column>phone_home</column>
        </attr>
        <attr name="telephonenumber">
          <column>phone_work</column>
        </attr>
        <attr name="mobile">
          <column>phone_mobile</column>
        </attr>
        <attr name="facsimiletelephonenumber">
          <column>phone_fax</column>
        </attr>
        <attr name="ipphone">
          <column>phone_other</column>
        </attr>
        <attr name="street">
          <column>address_street</column>
        </attr>
        <attr name="l">
          <column>address_city</column>
        </attr>
        <attr name="st">
          <column>address_state</column>
        </attr>
        <attr name="c">
          <column>address_country</column>
        </attr>
        <attr name="postalcode">
          <column>address_postalcode</column>
        </attr>
        <attr name="createtimestamp">
          <column>date_entered</column>
        </attr>
        <attr name="modifytimestamp">
          <column>date_modified</column>
        </attr>
        <attr name="description">
          <column>description</column>
        </attr>
        <attr name="mail">
          <selexpr>email_address</selexpr>
          <fromtbls>email_addresses,email_addr_bean_rel</fromtbls>
          <joinwhere>email_addr_bean_rel.bean_id = users.id and email_addr_bean_rel.email_address_id = email_addresses.id</joinwhere>
          <addproc>insert into email_addresses values('%{createGuid()}', '%a', upper('%a'), 0, 0, now(), now(), 0)</addproc>
          <addproc>set @paddr=if((select count(*) from email_addr_bean_rel where bean_id = '%o'), 0, 1)</addproc>
          <addproc>insert into email_addr_bean_rel values('%{createGuid()}', (select id from email_addresses where email_addr
ess = '%a'), '%o', 'Users', @paddr, if(@paddr, 0, 1), now(), now(), 0)</addproc>
          <delproc>set @mailid=(select id from email_addresses where email_address = '%a' and id in (select email_address_id from email_addr_bean_rel where bean_id = '%o'))</delproc>
          <delproc>delete from email_addresses where id = @mailid</delproc>
          <delproc>delete from email_addr_bean_rel where bean_id = '%o' and email_address_id = @mailid</delproc>
        </attr>
        <attr name="manager">
          <oname>User</oname>
          <where>id = (select reports_to_id from users where id = '%o')</where>
          <addproc>update users set reports_to_id = '%a' where id = '%o'</addproc>
          <delproc>update users set reports_to_id = null where id = '%o'</delproc>
        </attr>
        <strginfo>
          <column>id</column>
          <value type="function">createGuid()</value>
        </strginfo>
        <strginfo>
          <column>status</column>
          <value type="constant">Active</value>
          <delproc>update users set status = 'Inactive' where id = '%o'</delproc>
        </strginfo>
        <strginfo>
          <addproc>insert into user_preferences values('%{createGuid()}', 'global', 0, now(), now(), '%o', '%{encode_base64(getFileContents("/opt/secioss/etc/sugarcrm-userpref.txt"), "")}')</addproc>
        </strginfo>
      </object>
    </storage>
  </data>
</config>


ÀßÄê¤Î³Îǧ¤Ï¡¢LISM¥µ¡¼¥Ð¤Î¥Ç¡¼¥â¥ó¤òµ¯Æ°¤·¤Æ¡¢¥Ç¡¼¥¿¤Î¸¡º÷¤ä¹¹¿·¤òLISM¤ËÂФ·¤Æ¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¥Ç¡¼¥â¥ó¤òµ¯Æ°¤¹¤ë¾ì¹ç¤Ï¡¢°ì»þŪ¤Ë"<oc>seciossIamAccount</oc>"¤Î¹Ô¤ò¥³¥á¥ó¥È¥¢¥¦¥È¤·¤Æ²¼¤µ¤¤¡£
# cp /opt/secioss/etc/openldap/slapd.conf.lism /opt/secioss/etc/openldap/slapd.conf
# /opt/secioss/sbin/slapd -h ldap://:3890 -u ldap -d256
# ldapseach -H ldap://:3890 -b 'dc=lism,dc=com'  # ¸¡º÷¤Î¾ì¹ç

 

 

3.2 IDƱ´ü¤Î³Îǧ

https://slink.secioss.com/tenantadmin/¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Ç¥í¥°¥¤¥ó¤·¤Þ¤¹¡£
º¸Â¦¥á¥Ë¥å¡¼¤Î¥ê¥ó¥¯¤«¤éID´ÉÍý¤Ë¥¢¥¯¥»¥¹¤·¤Æ²¼¤µ¤¤¡£
¥æ¡¼¥¶¤Î”¿·µ¬ÅÐÏ¿”¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢¿·µ¬ÅÐÏ¿²èÌ̤«¤é¡¢µö²Ä¤¹¤ë¥µ¡¼¥Ó¥¹¤Ë¼«¿È¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÁªÂò¤·¤Æ¡¢ÅÐÏ¿¤ò¹Ô¤¤¤Þ¤¹¡£
¿·µ¬ÅÐÏ¿¤ÎÀµ¾ï½ªÎ»¸å¡¢¥æ¡¼¥¶¤Î¸¡º÷¥á¥Ë¥å¡¼¤Î”¥·¥¹¥Æ¥à”¤«¤é¼«¿È¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤òÁªÂò¤·¤Æ¡¢¸¡º÷¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£ÅÐÏ¿¤·¤¿¥æ¡¼¥¶¤¬¸¡º÷·ë²Ì¤Ëɽ¼¨¤µ¤ì¤ì¤Ð¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ØÀµ¾ï¤Ë¥æ¡¼¥¶¤¬Æ±´ü¤µ¤ì¤Æ¤¤¤Þ¤¹¡£

Àµ¾ï¤ËƱ´ü¤µ¤ì¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ï¡¢¾åÉô¤Î¥á¥Ë¥å¡¼¤Î¥í¥°¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢ID´ÉÍý¤Î¥í¥°¤ò¸¡º÷¤·¤Æ¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£

 

ID´ÉÍý

SaaS·¿¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó/Åý¹çID´ÉÍý SeciossLink

SeciossLink¤Ï¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈÅý¹çID´ÉÍý¤ò¥»¥Ã¥È¤Ë¤·¤¿SaaS·¿¥µ¡¼¥Ó¥¹¤Ç¤¹¡£

 

Google Apps¤äSalsforceÅù¡¢Â¾¤ÎSaaS¥µ¡¼¥Ó¥¹¤«¤é¥×¥é¥¤¥Ù¡¼¥È¥¯¥é¥¦¥É¤ä¼ÒÆâ¤Î¥ª¥ó¥×¥ì¥ß¥¹¤Î¥·¥¹¥Æ¥à¤Þ¤Ç¡¢Åý¹çŪ¤Ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈID´ÉÍý¤ò¹Ô¤¦¤³¤È¤¬²Äǽ¤Ç¤¹¡£
¤µ¤é¤Ë¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥óÏ¢·ÈÍѤΥ½¥Õ¥È¥¦¥§¥¢¡ÖSecioss Identity Suite Cloud Edition SP¡×¤òƳÆþ¤¤¤¿¤À¤¯¤³¤È¤Ç¡¢Google Gadget¤È¥×¥é¥¤¥Ù¡¼¥È¥¯¥é¥¦¥É¤ä¥ª¥ó¥×¥ì¥ß¥¹¤Î¥·¥¹¥Æ¥à¤È¤Î´Ö¤Ç¥Ç¡¼¥¿¤ÎÏ¢·È¤¬²Äǽ¤È¤Ê¤ê¡¢Google Apps¤Î¥Ý¡¼¥¿¥ë¤«¤éGadget¤Ë¤è¤ê¡¢³Æ¥·¥¹¥Æ¥à¤Î¥Ç¡¼¥¿¤ò»²¾È¡¢¹¹¿·¤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£

 

¤Þ¤¿¡¢AWS¡ÊAmazon Web Services¡Ë¤äNifty CloudÅù¤Î¥¯¥é¥¦¥É´Ä¶­¤Ç¡¢Â¿¿ô¤Î¥¤¥ó¥¹¥¿¥ó¥¹¤ò´ÉÍý¤¹¤ëºÝ¤ÎLinux¥¢¥«¥¦¥ó¥È¤È¥í¥°¥¤¥óÍѤθø³«¸°¤ò°ì¸µ´ÉÍý¤¹¤ë¤³¤È¤â²Äǽ¤Ç¤¹¡£

 

¥µ¡¼¥Ó¥¹¤Ï¡¢£±¥æ¡¼¥¶¤«¤éÍøÍѲÄǽ¤Ç¡¢£±¥æ¡¼¥¶¤Î´ðËÜÎÁ¶â·î³Û150±ß¤«¤é¤ÈÄ㥳¥¹¥È¤Ç¤Î¤´ÍøÍѤ¬²Äǽ¤Ç¤¹¡£¥³¥¹¥ÈŪ¤Ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤äÅý¹çID´ÉÍý¤ÎƳÆþ¤¬Æñ¤·¤«¤Ã¤¿Ãæ¾®´ë¶ÈÍͤˤ⡢¤´ÍøÍѤ·¤ä¤¹¤¤²Á³Ê¤È¤Ê¤Ã¤Æ¤ª¤ê¤Þ¤¹¡£

 

SeciossLink¤Ï¡¢AWS¾å¤Ç±¿ÍѤ·¤Æ¤ª¤ê¡¢¾®µ¬ÌϤ«¤éÂ絬ÌϤʤªµÒÍͤޤǽÀÆð¤ËÂбþ²Äǽ¤Ç¤¹¡£

 

µ¡Ç½

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó

  • ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
    SAML¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤Ç¤¹¡£SAML¤Ë̤Âбþ¤Î¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ¤Ï¡¢Secioss Identity Suite Cloud Edition SP¤ò³Æ¥·¥¹¥Æ¥à¤ËƳÆþ¤¤¤¿¤À¤¯¤³¤È¤Ç¡¢¥·¥¹¥Æ¥à¦¤Î¥«¥¹¥¿¥Þ¥¤¥º¤ò¹Ô¤¦¤³¤È¤Ê¤¯¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£

  • ÂåÍýǧ¾Ú
    ÂåÍýǧ¾Ú¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤Ç¤¹¡£SAML̤Âбþ¤ÎSaaS¡¢ASPÅù¡¢Secioss Identity Suite Cloud Edition¤òƳÆþ¤¹¤ë¤³¤È¤¬º¤Æñ¤Ê¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ¤â¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤Ç¤¹¡£

  • ¥¹¥Þ¡¼¥È¥Õ¥©¥ó¡¢PC¡¢·ÈÂÓÅÅÏäÎüËöǧ¾Ú
    ¥¹¥Þ¡¼¥È¥Õ¥©¥ó¡ÊAndroid¡¢iPhone¡Ë¡¢·ÈÂÓÅÅÏá¢PC¤Ë´Ø¤·¤Æµö²Ä¤µ¤ì¤¿¥æ¡¼¥¶¤ÎüËö¤Î¤ß¥í¥°¥¤¥ó¤òµö²Ä¤·¤Þ¤¹¡£Ç§¾Ú¥ë¡¼¥ëµ¡Ç½¤ÈÁȤ߹ç¤ï¤»¤ë¤³¤È¤Ç¡¢¥µ¡¼¥Ó¥¹¤òÍøÍѤǤ­¤ë¥¹¥Þ¡¼¥È¥Õ¥©¥ó¤ÎÀ©¸Â¤ä¡¢¼Ò³°¤«¤é¥Î¡¼¥ÈPC¤Ê¤É¤Ç¥µ¡¼¥Ó¥¹¤òÍøÍѤ¹¤ëºÝ¤ÎPC¤ÎÀ©¸Â¤ò¹Ô¤¦¤³¤È¤¬²Äǽ¤Ç¤¹¡£

  • ǧ¾Ú¥ë¡¼¥ë
    ǧ¾Ú¤Ë¤Ï¡¢ID/¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤Î¾¤Ë¼ÒÆâ¤ÎActive Directory¤Ë¤è¤ëǧ¾Ú¤òÁªÂò¤¹¤ë¤³¤È²Äǽ¤Ç¤¹¡£Active Directoryǧ¾Ú¤ò¹Ô¤¦¾ì¹ç¡¢¼ÒÆâ¤Ë¥ª¡¼¥×¥ó¥½¡¼¥¹¤ÎSecioss Identity Suite Cloud Edition  IdP¤òƳÆþ¤¤¤¿¤À¤­¤Þ¤¹¡£

  • ¥Ñ¥¹¥ï¡¼¥É¥Ý¥ê¥·¡¼
    ¥Ñ¥¹¥ï¡¼¥É¥Ý¥ê¥·¡¼¤ÎÀßÄ꤬²Äǽ¤Ç¤¹¡£¥Ñ¥¹¥ï¡¼¥É¤Îʸ»úÎó¤äÍúÎò¿ô¡¢Í­¸ú´ü´Ö¡¢¤½¤·¤ÆÇ§¾Ú¼ºÇÔ»þ¤Î¥¢¥«¥¦¥ó¥È¥í¥Ã¥¯¤òÀßÄꤹ¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£ 

  • ¥¢¥¯¥»¥¹À©¸æ
    ¥æ¡¼¥¶¡¢¥°¥ë¡¼¥×¡¢Ç§¾ÚÊý¼°¡¢¥¯¥é¥¤¥¢¥ó¥È¤ÎIP¥¢¥É¥ì¥¹¡¢»þ´ÖÂӤˤè¤ë¥¢¥¯¥»¥¹À©¸æ¤¬²Äǽ¤Ç¤¹¡£

  • ¥í¥°¥¤¥óÍúÎò
    ¥æ¡¼¥¶¤Î¥í¥°¥¤¥ó¡¢¥í¥°¥¢¥¦¥È¡¢Google Apps¤äSalesforce¤Ø¤Î¥í¥°¥¤¥ó¤Ë´Ø¤¹¤ë¥í¥°¤òWeb¤«¤é¸¡º÷¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

Åý¹çID´ÉÍý

  • IDƱ´ü
    Google Apps¤äSalesforceÅù¤ÎSaaS¥µ¡¼¥Ó¥¹¤ä¥ª¥ó¥×¥ì¥ß¥¹¤Î¥·¥¹¥Æ¥à¤ÈID¤ÎƱ´ü¤ò¹Ô¤¦¤³¤È¤¬²Äǽ¤Ç¤¹¡£¥æ¡¼¥¶Ã±°Ì¤ÇID¤ÎƱ´üÂоݤȤ¹¤ë¥·¥¹¥Æ¥à¤ò»ØÄꤹ¤ë¤³¤È¤â¤Ç¤­¤Þ¤¹¡£
    ¥ª¥ó¥×¥ì¥ß¥¹¤Î¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ¤Ï¡¢³Æ¥·¥¹¥Æ¥à¤ËSecioss Identity Suite Cloud Edition SP¤òƳÆþ¤¤¤¿¤À¤­¤Þ¤¹¡£

  • Active DirectoryÏ¢·È
    ¼ÒÆâ¤ÎActive Directory¤«¤éID¤òƱ´ü¤¹¤ë¤³¤È¤â²Äǽ¤Ç¤¹¡£
    ¤½¤Î¾ì¹ç¡¢¼ÒÆâ¤ËSecioss Identity Suite Cloud Edition IdP¤òƳÆþ¤¤¤¿¤À¤­¤Þ¤¹¡£  

  • LDAPÏ¢·È¡Ê¸ø³«¸°´ÉÍý¡Ë
    AWS¡¢Nifty CloudÅù¤Î¥¯¥é¥¦¥É´Ä¶­¤ÎLinux¥¢¥«¥¦¥ó¥È¤Èssh¥í¥°¥¤¥óÍѤθø³«¸°¤òLDAP¤Ë¤è¤ê°ì¸µ´ÉÍý¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

  • ¥æ¡¼¥¶¥»¥ë¥Õ¥µ¡¼¥Ó¥¹
    ¥æ¡¼¥¶¥»¥ë¥Õ¥µ¡¼¥Ó¥¹¤È¤·¤Æ¡¢¥æ¡¼¥¶¤Ë¤è¤ë¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¡¢ssh¥í¥°¥¤¥óÍѸø³«¸°¤ÎÅÐÏ¿¤¬²Äǽ¤Ç¤¹¡£

  • ¹¹¿·ÍúÎò
    SeciossLink¤Î¥æ¡¼¥¶¡¢¥°¥ë¡¼¥×¤À¤±¤Ç¤Ê¤¯¡¢Google Apps¤äSalesforceÅù¤Î³Æ¥µ¡¼¥Ó¥¹¤Î¥æ¡¼¥¶¡¢¥°¥ë¡¼¥×¤ËÂФ¹¤ë¹¹¿·¤Î¥í¥°¤òWeb¤«¤é¸¡º÷¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

¥¢¥×¥ê¥±¡¼¥·¥ç¥óÏ¢·È

  • Google GadgetÏ¢·È
    Secioss Identity Suite Cloud Edition SP¤ò³Æ¥·¥¹¥Æ¥à¤ËƳÆþ¤¤¤¿¤À¤¯¤³¤È¤Ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¦¤Î¥«¥¹¥¿¥Þ¥¤¥º¤ò¹Ô¤¦¤³¤È¤Ê¤¯¡¢2-legged OAuth¤Ë¤è¤ê¡¢Google Gadget¤È¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎÏ¢·È¤¬²Äǽ¤È¤Ê¤ê¡¢Google Apps¤Î¥Ý¡¼¥¿¥ë²èÌ̤«¤é¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¤ò»²¾È¡¢¹¹¿·¤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£

 

¥·¥¹¥Æ¥à¹½À®

 

 

¥µ¡¼¥Ó¥¹²Á³Ê

¡¦¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¡¦Åý¹çID´ÉÍý ´ðËÜÎÁ¶â¡§¡¡150±ß¡Ê£±¥æ¡¼¥¶·î³Û¡Ë

¡¦¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¡¦IDÏ¢·È 1¥·¥¹¥Æ¥à¡§ 15±ß¡Ê£±¥æ¡¼¥¶·î³Û¡Ë
¡¡¢¨ ÂåÍýǧ¾Ú¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ë¤Ä¤¤¤Æ¤Ï¡¢´ðËÜÎÁ¶â¤Î¤ß¤ÇÊÌÅÓ¥·¥¹¥Æ¥àñ°Ì¤ÎÈñÍѤÏɬÍפ´¤¶¤¤¤Þ¤»¤ó¡£  

 

¢¨ °Ê²¼¤Îµ¡Ç½¤Ï¡¢´ðËÜÎÁ¶â¤Ë´Þ¤Þ¤ì¤Þ¤¹¡£
¡¡ ¡¦Google Apps¤È¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¡¦IDÏ¢·È
¡¡ ¡¦Active Directoryǧ¾ÚÍѤÎActive Directory¤È¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¡¦IDÏ¢·È

¢¨ üËöǧ¾Ú¤Ï¡¢¥ª¥×¥·¥ç¥óµ¡Ç½¤È¤Ê¤ê¤Þ¤¹¡£²Á³Ê¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤³¤Á¤é¤«¤é¤ªÌä¹ç¤»²¼¤µ¤¤¡£

¢¨ Secioss Identity Suite Cloud Edition¤ÎƳÆþ¥µ¡¼¥Ó¥¹¤Ë¤Ä¤¤¤Æ¤Ï¡¢ÊÌÅÓÈñÍѤò¤¬É¬ÍפȤʤê¤Þ¤¹¡£

 

Âбþ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó

¥×¥é¥¤¥Ù¡¼¥È CA Gléas¡ÊJCCH¡¦¥»¥­¥å¥ê¥Æ¥£¡¦¥½¥ê¥å¡¼¥·¥ç¥ó¡¦¥·¥¹¥Æ¥à¥º¡Ë

Gléas ¤¬¡¢SeciossLink ¤ËÂбþ¤·¤¿¤³¤È¤Ë¤è¤ê¡¢PC ¤ª¤è¤Ó iPhone / iPad ¤«¤é¡¢Google Apps ¡¦ Salesforce¤Ê¤É¤Î¥¯¥é¥¦¥É¥µ¡¼¥Ó¥¹¤Ë²Ã¤¨¡¢¥×¥é¥¤¥Ù¡¼¥È¥¯¥é¥¦¥É¡¢¼ÒÆâ¤Î¥ª¥ó¥×¥ì¥ß¥¹¥·¥¹¥Æ¥à¤Ê¤É¤Î½ÅÍ×¤Ê¼ÒÆâ¾ðÊó»ñ»º¤Ø¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÎºÝ¤Ë¡¢ÅŻҾÚÌÀ½ñ¤Ë¤è¤ë¸·³Ê¤Êǧ¾Ú¶¯²½¤¬²Äǽ¤È¤Ê¤ê¤Þ¤·¤¿¡£ÅŻҾÚÌÀ½ñ¤òüËö¤Ë¥¤¥ó¥Ý¡¼¥È¤¹¤ë¤³¤È¤ÇüËö¤Îǧ¾Ú¤ò¡¢ÅŻҾÚÌÀ½ñ¤ò USB ¥È¡¼¥¯¥ó¤ä IC ¥«¡¼¥É¤Ê¤É¤Î¥»¥­¥å¥ê¥Æ¥£¥Ç¥Ð¥¤¥¹¤Ë¥¤¥ó¥Ý¡¼¥È¤¹¤ë¤³¤È¤Ç¿Í¤Îǧ¾Ú¤ò¼Â¸½¤Ç¤­¤Þ¤¹¤Î¤Ç¡¢´ë¶È¤Î¥»¥­¥å¥ê¥Æ¥£¥Ý¥ê¥·¡¼¤Ë¹ç¤ï¤»¤Æ½ÀÆð¤Êǧ¾Ú¥Ý¥ê¥·¡¼¤òÀ߷פ¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£
¾ÜºÙ

 

¥Þ¥Ë¥å¥¢¥ë

SeciossLink¤Î»ÈÍÑÊýË¡¤Ë¤Ä¤¤¤Æ¤Ï¡¢¥Þ¥Ë¥å¥¢¥ë¤ò¤´Í÷²¼¤µ¤¤¡£

¡¦´ÉÍý¼Ô¥¬¥¤¥É

¡¦¥æ¡¼¥¶¥¬¥¤¥É

 

Ìä¹ç¤»

ËÜ¥µ¡¼¥Ó¥¹¤Ë´Ø¤¹¤ë¤ªÌä¹ç¤»¤Ï¤³¤Á¤é¤«¤é¤ª´ê¤¤¤·¤Þ¤¹¡£

Secioss Identity Suite Cloud Edition

Secioss Identity Suite Cloud Edition¤Ï¡¢¥¯¥é¥¦¥É¥³¥ó¥Ô¥å¡¼¥Æ¥£¥ó¥°´Ä¶­¤Ë¤ª¤¤¤ÆSAML 2.0¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤äSOAPÄÌ¿®¤Ë¤è¤ë¥¢¥«¥¦¥ó¥ÈƱ´ü¤ò¥µ¥¤¥È´Ö¤Ç¼Â¸½¤¹¤ë¥½¥Õ¥È¥¦¥§¥¢¤Ç¤¹¡£

 

Secioss Identity Suite Cloud Edition¡Ê°Ê¹ßIdentity Suite Cloud¤È¤·¤Þ¤¹¡Ë¤ò¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƳÆþ¤¹¤ë¤³¤È¤Ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ°Ê²¼¤Îµ¡Ç½¤ò´Êñ¤ËÄɲ乤뤳¤È¤Ç¤­¤Þ¤¹¡£

 

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
SAML¤ÎService Provider¤È¤·¤ÆÆ°ºî¤·¡¢SAML¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¤¤Þ¤¹¡£¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÏIdentity Suite Cloud¤ÎÂåÍýǧ¾Úµ¡Ç½¤Ë¤è¤ê´Êñ¤ËSAMLǧ¾Úµ¡Ç½¤òÁȤ߹þ¤à¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

IDƱ´ü
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎID´ÉÍýÍÑSOAP API¤òÄ󶡤·¡¢SOAP·Ðͳ¤Ç¤ÎID´ÉÍý¤ä¥µ¥¤¥È´Ö¤Ç¤ÎIDƱ´ü¤ò¼Â¸½¤·¤Þ¤¹¡£Identity Suite Cloud¤Ï¡¢Äê´üŪ¤ËSOAP API¤Ç¹¹¿·¥Ç¡¼¥¿¤ò¼èÆÀ¤·¡¢LISM¤Ë¤è¤ê¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤ØÈ¿±Ç¤·¤Þ¤¹¡£

 

Google Gadget¤Ë¤è¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥óÏ¢·È
¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈÏ¢·È¤·¤Æ¡¢2-legged OAuth¤Ë¤è¤êGoogle Gadget¤«¤é¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤Îǧ²Ä¤ò¹Ô¤¤¤Þ¤¹¡£
Google Gadget¤Ë¤è¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥óÏ¢·È¤Ï¡¢Identity Suite Cloud V3.1¤«¤é»ÈÍѲÄǽ¤Ç¤¹¡£

 

 

¥é¥¤¥»¥ó¥¹

Identity Suite Cloud¤Ï¡¢¥Ð¡¼¥¸¥ç¥ó3.0¤Þ¤Ç¤Î¥½¥Õ¥È¥¦¥§¥¢¤ò¥ª¡¼¥×¥ó¥½¡¼¥¹¤È¤·¤ÆGPL¥é¥¤¥»¥ó¥¹¤Ë¤è¤ê¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£
¡¦¥×¥í¥¸¥§¥¯¥È¥µ¥¤¥È¡§http://sourceforge.jp/projects/secioss-auth/
¡¦¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¡§http://lists.sourceforge.jp/mailman/listinfo/secioss-auth-users

Identity Suite Cloud¤Î¥Ð¡¼¥¸¥ç¥ó3.1°Ê¹ß¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤³¤Á¤é¤Ë¤ªÌä¹ç¤»²¼¤µ¤¤¡£

 

¾¦ÍÑ¥µ¡¼¥Ó¥¹

Identity Suite Cloud¤Ë´Ø¤¹¤ë¥³¥ó¥µ¥ë¥Æ¥£¥ó¥°¡¢Êݼ饵¡¼¥Ó¥¹¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤³¤Á¤é¤Ø¤ªÌä¹ç¤»²¼¤µ¤¤¡£
¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Îǧ¾Ú¥µ¡¼¥Ð¡¢¥¢¥«¥¦¥ó¥ÈƱ´ü¤ÎÅý¹çID´ÉÍý¥µ¡¼¥Ð¤¬SeciossLink¡¢¤Þ¤¿¤ÏSecioss Access Manager Enterprise Edition¡¢Secioss Identity Manager¤Î¾ì¹ç¤Ï¡¢Ìµ½þ¤ÇÊݼ饵¡¼¥Ó¥¹¤òÄ󶡤¤¤¿¤·¤Þ¤¹¡£

 

1. ¥¤¥ó¥¹¥È¡¼¥ë

Identity Suite Cloud SP¤Î¿ä¾©´Ä¶­¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£
¡¦OS¡§ CentOS 5¡¢RedHat Enterprise Linux 5
¡¦Web¥µ¡¼¥Ð¡§ Apache 2.2

º£²ó¤Î¥¤¥ó¥¹¥È¡¼¥ë´Ä¶­¤È¤·¤Æ¤Ï¡¢Linux¤ÎCentOS 5¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£
¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Îǧ¾Ú¥µ¡¼¥Ð¡¢Åý¹çID´ÉÍý¥µ¡¼¥Ð¤Ï¡¢ÊÀ¼ÒSaaS¥µ¡¼¥Ó¥¹SeciossLink¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£

 

¤Þ¤¿¡¢º£²ó¤Ï¥ª¥ó¥×¥ì¥ß¥¹¤Î¥·¥¹¥Æ¥à¤Ø¤ÎƳÆþ¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£SaaS·¿¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ø¤ÎƳÆþ¤ò¸¡Æ¤¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ï¡¢¤³¤Á¤é¤ò¤´Í÷²¼¤µ¤¤¡£

 

1.1  ɬÍפʥ½¥Õ¥È¥¦¥§¥¢¤Î¥¤¥ó¥¹¥È¡¼¥ë

# yum install libtool-ltdl
# yum install perl-LDAP
# yum install perl-DBI
# yum install perl-DBD-Pg
# yum install perl-XML-LibXML
# yum install perl-XML-Simple
# yum install perl-TimeDate
# yum install php-pear
# yum install php-xml
# yum install php-soap 

 

1.2 Identity Suite Cloud SP

http://sourceforge.jp/projects/secioss-auth/releases/¤«¤ésecioss-idsuite-cloud-sp-2.0.x.tgz¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ²¼¤µ¤¤¡£

secioss-idsuite-cloud-sp¥Ñ¥Ã¥±¡¼¥¸¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£
# tar zxvf secioss-idsuite-cloud-sp-3.0.x.tgz
# cd secioss-idsuite-cloud-sp-3.0.x
# ./install.sh install

 

¤Þ¤¿¡¢¥Ñ¥Ã¥±¡¼¥¸¤ò¥¢¥Ã¥×¥Ç¡¼¥È¤¹¤ë¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./install.sh update

 

1.3 Basicǧ¾Ú¤ÎÀßÄê

Basicǧ¾Ú¤ÎID/¥Ñ¥¹¥ï¡¼¥É¤òÅÐÏ¿¤·¤Þ¤¹¡£
# htpasswd -c /var/www/conf/.htpasswd <ID>

 

1.4 ¥í¥°¤ÎÀßÄê

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈIDƱ´ü¤Î¥í¥°¤Ï¡¢¤½¤ì¤¾¤ìsyslog¤Îlocal5¡¢local4¤Ë½ÐÎϤ·¤Þ¤¹¡£
/etc/syslog.conf¤Ë°Ê²¼¤ÎÀßÄê¤òÄɵ­¤·¤Æ¡¢syslog¥Ç¡¼¥â¥ó¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£


local5.*                                         -/var/log/auth.log
local4.*                                         -/var/log/lism.log


 

 

2. ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó

2.1 SAMLǧ¾Ú¤ÎÀßÄê

SAMLǧ¾Ú¡ÊSP¡Ë¤ÎÀßÄê¤ò¹Ô¤¦¤Ë¤Ï¡¢°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./config.sh sso
¡¦Ç§¾Ú¥µ¡¼¥Ó¥¹¤ÎURL¡§ ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¦Ç§¾Ú¥µ¡¼¥Ó¥¹¤ÎURL
  ¢¨https://slink.secioss.com¤Î¾ì¹ç¤ÏÆþÎÏÉÔÍפǤ¹¡£
¡¦¥Æ¥Ê¥ó¥ÈID¡§¡¡Ç§¾Ú¥µ¡¼¥Ó¥¹¤Î¥Æ¥Ê¥ó¥ÈID
¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¡§ ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL
  ¢¨¥Ñ¥¹¤Ë¤Ä¤¤¤Æ¤Ï¡¢ºÇ¸å¤Ë"/"¤òÉղ䷤Ʋ¼¤µ¤¤¡£
¡¦¥»¥Ã¥·¥ç¥ó¤Î¥¯¥Ã¥­¡¼Ì¾¡§¡¡¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥»¥Ã¥·¥ç¥ó¤òÊÝ»ý¤¹¤ë¥¯¥Ã¥­¡¼Ì¾
¡¦ ¥Ñ¥¹¥ï¡¼¥É¤ÎƱ´ü[1.¤¹¤ë|2.¤·¤Ê¤¤]¡§¡¡¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ç¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¥í¥°¥¤¥ó¤·¤¿ºÝ¤Ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤È¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ñ¥¹¥ï¡¼¥É¤òƱ´ü¤¹¤ë¤«¤É¤¦¤«»ØÄꤷ¤Þ¤¹¡£
¡¡¢¨¤³¤Îµ¡Ç½¤ò»ÈÍѤ¹¤ë¾ì¹ç¤Ï¡¢”3. IDƱ´ü”¤ÎÀßÄ꤬ºÑ¤ó¤Ç¤¤¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£
¡¦¥¢¥¯¥»¥¹À©¸Â[1.¤¹¤ë|2.¤·¤Ê¤¤]¡§¡¡¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ñ¥¹¥ï¡¼¥É¤ò¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤È°Û¤Ê¤ë¥Ñ¥¹¥ï¡¼¥É¤ËÊѹ¹¤¹¤ë¤³¤È¤Ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥í¥°¥¤¥ó²èÌ̤«¤é¤ÏľÀÜ¥í¥°¥¤¥ó¤Ç¤­¤Ê¤¤¤è¤¦¤Ë¤·¤Þ¤¹¡£Ç§¾Ú¥µ¡¼¥Ó¥¹¤Ç¤³¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ¥¢¥¯¥»¥¹À©¸æ¤ò¹Ô¤¦¾ì¹ç¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£

 

¼¡¤ËSAMLǧ¾ÚÍѤÎÈëÌ©¸°¤È¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
°Ê²¼¤ÏOpenSSL¤Ë¤è¤ëÈëÌ©¸°¤È¸ø³«¸°¤ÎºîÀ®¼ê½ç¤Ç¤¹¡£
­¡ ÈëÌ©¸°¤òºîÀ®¤·¤Þ¤¹¡£
# cd /etc/pki/tls/certs
# make test.key
ÈëÌ©¸°¤«¤é¥Ñ¥¹¥ï¡¼¥É¤òºï½ü¤·¤Þ¤¹¡£
# openssl rsa -in test.key -out test.key

­¢ ¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
# make test.crt
Country Name (2 letter code) [GB]:JP¡¡←¡¡¹ñ̾
State or Province Name (full name) [Berkshire]:Tokyo¡¡←¡¡ÅÔÆ»Éܸ©Ì¾
Locality Name (eg, city) [Newbury]:Bunkyo¡¡←¡¡»Ô¶èĮ¼̾
Organization Name (eg, company) [My Company Ltd]:TEST, Inc¡¡←¡¡²ñ¼Ò̾
Organizational Unit Name (eg, section) []:¡¡←¡¡¶õENTER
Common Name (eg, your name or your server's hostname) []:sp.test.co.jp¡¡←¡¡¥Û¥¹¥È̾
Email Address []:admin@test.co.jp¡¡←¡¡´ÉÍý¼Ô¥á¡¼¥ë¥¢¥É¥ì¥¹

 

ÈëÌ©¸°¤Ï¡¢"/usr/share/simplesamlphp/cert/PrivateKey.pem"¤Ë¥³¥Ô¡¼¤·¤Æ¡¢½êÍ­¼Ô¤òapache¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£
# chown apache /usr/share/simplesamlphp/cert/PrivateKey.pem

 

ºÇ¸å¤ËApache¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£
# /etc/init.d/httpd restart

 

 

2.2 ÂåÍýǧ¾Ú¤ÎÀßÄê

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¼«Æ°¤Ç¥í¥°¥¤¥ó¤¹¤ë¤¿¤á¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£

ÀßÄê¥Õ¥¡¥¤¥ë¤Ï¡¢"/var/www/conf/<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾¡ÊÁ´¤Æ¾®Ê¸»ú¡Ë>.ini"¤È¤·¤ÆºîÀ®¤·¤Æ²¼¤µ¤¤¡£
°Ê²¼¤ÏSugarCRMÍѤÎÀßÄêÎã¤Ç¤¹¡£


[url]
login = "https://sp.example.com/SugarCE/index.php?action=Login&module=Users"
back = "/SugarCE/"

 

[postName]
username = user_name
password = user_password

 

[postData]
module = Users
action = Authenticate
return_module = Users
return_action = Login
cant_login = ""
login_module = ""
login_action = ""
login_record = ""
login_theme = Sugar
login_language = ja
login_button = "  ¥í¥°¥¤¥ó  "


 

url

login

¥í¥°¥¤¥ó¤¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL

back

¥í¥°¥¤¥ó¸å¤Ëɽ¼¨¤¹¤ë²èÌ̤ÎURL

postName

username

¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥æ¡¼¥¶Ì¾¤ÎÊÑ¿ô̾

password

¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥Ñ¥¹¥ï¡¼¥É¤ÎÊÑ¿ô̾

 

[postData]¤Ë¤Ï¡¢POST¤¹¤ë¥Ç¡¼¥¿¤ÎÊÑ¿ô̾¤ÈÃͤÎÁȤ߹ç¤ï¤»¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£   

 

 

2.3 Ç§¾Ú¥µ¡¼¥Ó¥¹¤ÎÀßÄê

<ǧ¾Ú¥µ¡¼¥Ó¥¹¤ÎURL>/tenantadmin/¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Ç¥í¥°¥¤¥ó¤·¤Þ¤¹¡£
²èÌ̾åÉô¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¥¯¥ê¥Ã¥¯¤·¤«¤é¡¢º¸Â¦¥á¥Ë¥å¡¼¤Î”SAML ¥µ¡¼¥Ó¥¹¥×¥í¥Ð¥¤¥À”¤ò¥¯¥ê¥Ã¥¯¤·¤Æ²¼¤µ¤¤¡£
”¿·µ¬ÅÐÏ¿”¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢SP¤ÎÀßÄê¤òÅÐÏ¿¤·¤Þ¤¹¡£
¡¦¥µ¡¼¥Ó¥¹¡§¡¡¥µ¡¼¥Ó¥¹ID¤òÁªÂò¤·¤Æ²¼¤µ¤¤¡£
¡¦¥µ¡¼¥Ó¥¹Ì¾¡§¡¡SP¤Î¥µ¡¼¥Ó¥¹Ì¾¡ÊǤ°Õ¤ÎÃ͡ˤòÀßÄꤷ¤Æ²¼¤µ¤¤¡£
¡¦URL¡§¡¡2.1¹à¤ÇÀßÄꤷ¤¿¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£
¡¦¥æ¡¼¥¶ID¤Î°À­¡§¡¡SP¤ËÅϤ¹¥æ¡¼¥¶ID¤Î°À­¤òÁªÂò¤·¤Æ²¼¤µ¤¤¡£
¡¦°Å¹æ²½ÍѸø³«¸°¡§¡¡2.1¹à¤ÇºîÀ®¤·¤¿¸ø³«¸°¤òÅÐÏ¿¤·¤Æ²¼¤µ¤¤¡£
¡¦¥µ¡¼¥Ó¥¹¥×¥í¥Ð¥¤¥À¤Î¥Ñ¥¹¥ï¡¼¥É¡§
¡¡- ¤Ê¤·¡§ ¥Ñ¥¹¥ï¡¼¥É¤òÁ÷¿®¤·¤Ê¤¤
¡¡- ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î¥Ñ¥¹¥ï¡¼¥É¡§ ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î¥Ñ¥¹¥ï¡¼¥É¤òÁ÷¿®
¡¡- ¥µ¡¼¥Ó¥¹¸ÄÊ̤Υѥ¹¥ï¡¼¥É¡§ ¥µ¡¼¥Ó¥¹¸ÄÊ̤Υѥ¹¥ï¡¼¥É¤òÁ÷¿®
¡¡- ¥é¥ó¥À¥à¥Ñ¥¹¥ï¡¼¥É¡§ ¥é¥ó¥À¥à¤Ê¥Ñ¥¹¥ï¡¼¥É¤òÁ÷¿®
¡¡¢¨¥é¥ó¥À¥à¥Ñ¥¹¥ï¡¼¥É¤òÀßÄꤷ¤¿¾ì¹ç¡¢”2.1 SAMLǧ¾Ú”¤ÎÀßÄê¤Ç”¥¢¥¯¥»¥¹À©¸Â”¤ò”1.¤¹¤ë”¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£ 

 

SPÅÐÏ¿

 

 

 

3. IDƱ´ü

3.1  IDƱ´ü¤ÎÀßÄê

Identity Suite Cloud¤Ï¡¢LISM¤Ë¤è¤Ã¤ÆÄê´üŪ¤ËSeciosLink¤«¤é¹¹¿·¥Ç¡¼¥¿¤ò¼èÆÀ¤·¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤äLDAP¤Î¥¢¥«¥¦¥ó¥È¤ò¹¹¿·¤·¤Þ¤¹¡£

ºÇ½é¤Ë¡¢°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# ./config.sh idm
¡¦Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤ÎURL¡§ Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤ÎURL
  ¢¨https://slink.secioss.com¤Î¾ì¹ç¤ÏÆþÎÏÉÔÍפǤ¹¡£
¡¦¥Æ¥Ê¥ó¥ÈID¡§¡¡Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤Î¥Æ¥Ê¥ó¥ÈID
¡¦´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾¡§¡¡Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤ËÀܳ¤¹¤ë´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾
¡¦´ÉÍý¼Ô¥Ñ¥¹¥ï¡¼¥É¡§¡¡´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Î¥Ñ¥¹¥ï¡¼¥É
¡¦Æ±´ü¤ÎÊý¸þ[1.Åý¹çID´ÉÍý -> ¥µ¡¼¥Ó¥¹|2.¥µ¡¼¥Ó¥¹ -> Åý¹çID´ÉÍý]
¡¡¢¨2¤òÁªÂò¤·¤¿¾ì¹ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¦¤ÎDB¤¬ID¤Î¸¶ËܤȤʤê¤Þ¤¹¡£
°Ê²¼¤Ï¡¢Æ±´ü¤ÎÊý¸þ¤Ç1¤òÁªÂò¤·¤¿¾ì¹ç¤Î¤ß¡¢ÀßÄꤷ¤Þ¤¹¡£
¡¦¥µ¡¼¥Ó¥¹ID¡§¡¡2.3¹à¤Î¥µ¡¼¥Ó¥¹ID¡Ê¥Æ¥Ê¥ó¥ÈID¤Ï½ü¤¯¡Ë
¡¦¥æ¡¼¥¶ID¤Î°À­ [1.¥æ¡¼¥¶ID|2.¥æ¡¼¥¶ID@¥Æ¥Ê¥ó¥ÈID|3.¥á¡¼¥ë¥¢¥É¥ì¥¹|4.¼Ò°÷ÈÖ¹æ|5.¥µ¡¼¥Ó¥¹¸ÄÊÌ¤Î¥í¥°¥¤¥óID]¡§¡¡ IDƱ´üÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥æ¡¼¥¶ID¤Ë»ÈÍѤ¹¤ë°À­¤òÈÖ¹æ¤Ç»ØÄê

 

LISM¤ÎÀßÄê¥Õ¥¡¥¤¥ë¡ÊƱ´ü¤ÎÊý¸þ¤¬1¤Î¾ì¹ç/opt/secioss/etc/lism.conf¡¢2¤Î¾ì¹ç/opt/secioss/etc/lism-idp.conf¡Ë¤Ë¡¢¹¹¿·ÂоݤΥǡ¼¥¿¥Ù¡¼¥¹¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
http://<¥Û¥¹¥È̾>/lism/ ¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥Ç¡¼¥¿¥Ù¡¼¥¹¤ÎÀßÄê¤ÈLDAP¤Î°À­¤ÈDB¤Î¥Õ¥£¡¼¥ë¥É¤Î¥Þ¥Ã¥Ô¥ó¥°¤ò¹Ô¤¤¡¢Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤ÈƱ´ü¤¹¤ë°À­¤Ë¥Á¥§¥Ã¥¯¤ò¤·¤Æ²¼¤µ¤¤¡£

³ÆÂ°À­¤Î°ÕÌ£¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£ 
¡¦primary key¡§ DB¤Î¥×¥é¥¤¥Þ¥ê¥­¡¼
¡¦uid¡§ ¥æ¡¼¥¶ID
¡¦cn¡§ »á̾
¡¦sn¡§ À«
¡¦givenname¡§ ̾
¡¦cn;lang-ja;phonetic¡§ »á̾¡Ê¤«¤Ê¡Ë
¡¦sn;lang-ja;phonetci¡§ À«¡Ê¤«¤Ê¡Ë
¡¦givenname;lang-ja;phonetic¡§ ̾¡Ê¤«¤Ê¡Ë
¡¦mail¡§ ¥á¡¼¥ë¥¢¥É¥ì¥¹
¡¦userpassword¡§ ¥Ñ¥¹¥ï¡¼¥É
¡¦createtimestamp¡§ ÅÐÏ¿Æü»þ
¡¦modifytimestamp¡§ ¹¹¿·Æü»þ
"primary key"¡¢"uid"¡¢"sn"¤Ë¤Ä¤¤¤Æ¤Ï¡¢É¬¤ºDB¤Î¥Õ¥£¡¼¥ë¥É¤È¤Î¥Þ¥Ã¥Ô¥ó¥°¤ò¹Ô¤Ã¤Æ²¼¤µ¤¤¡£
 ¤µ¤é¤Ë¡¢"sn"¤Ë¤Ä¤¤¤Æ¤Ï¡¢É¬¤ºÆ±´ü¤Ë¥Á¥§¥Ã¥¯¤ò¤·¤Æ²¼¤µ¤¤¡£

 

LISM GUI

 

lism.conf¡¢¤Þ¤¿¤Ïlism-idp.conf¤ÎÀßÄê¤Ç¡¢ÀßÄê²èÌ̤«¤éÀßÄê¤Ç¤­¤Ê¤¤¹àÌܤ¬¤¢¤ë¾ì¹ç¤Ï¡¢Ä¾ÀÜÀßÄê¥Õ¥¡¥¤¥ë¤ò½¤Àµ¤·¤Æ²¼¤µ¤¤¡£LISM¤ÎÀßÄêÊýË¡¤Ë¤Ä¤¤¤Æ¤Ï¡¢LISM¤Î¥µ¥¤¥È¤ò¤´Í÷²¼¤µ¤¤¡£ 

SugarCRM¤òÎã¤È¤·¤ÆLISM¤ÎÀßÄê¤òÎ㼨¤·¤Þ¤¹¡£ 

 

lism.conf


<config>
  <sync>
    <data name="SP">
      <object name="User">
        <syncdn>ou=People</syncdn>
        <syncfilter>(&amp;(!(seciossAccountStatus=deleted))(&amp;(objectClass=inetOrgPerson)(|(seciossAllowedService=sp01-secioss.co.jp)(seciossAllowedService;x-perm-group=sp01-secioss.co.jp))))</syncfilter>
        <syncattr>
          <name>sn</name>
        </syncattr>
        <syncattr>
          <name>givenName</name>
        </syncattr>
        <syncattr>
          <name>sn;lang-ja;phonetic</name>
        </syncattr>
        <syncattr>
          <name>givenName;lang-ja;phonetic</name>
        </syncattr>
        <syncattr>
          <name>mail</name>
        </syncattr>
      </object>
    </data>
  </sync>
  <data name="SP">
    <container>
      <oc>organizationalUnit</oc>
      <rdn>o=SP</rdn>
    </container>
    <handler name="Rewrite">
      <rewrite context="request" match="createtimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="createtimestamp: %1-%2-%3 %4:%5:%6"/>
      <rewrite context="searchResult" match="createtimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="createtimestamp: %1%2%3%4%5%6Z"/>
      <rewrite context="request" match="modifytimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="modifytimestamp: %1-%2-%3 %4:%5:%6"/>
      <rewrite context="searchResult" match="modifytimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="modifytimestamp: %1%2%3%4%5%6Z"/>
    </handler>
    <storage name="SQL" hash="MD5:hex">
      <libload>LISM/Utils/lism_util.pl</libload>
      <libload>LISM/Utils/lism_sugarcrm.pl</libload>
      <dsn>DBI:mysql:sugarcrm:localhost</dsn>
      <admin>admin</admin>
      <passwd>secret</passwd>
      <initquery>set names utf8</initquery>
      <noop>delete</noop>
      <object name="User">
        <container>
          <rdn>ou=People</rdn>
          <oc>organizationalUnit</oc>
        </container>
        <table>users</table>
        <id>
          <column>id</column>
        </id>
        <oc>Person</oc>
        <oc>inetOrgPerson</oc>
        <oc>seciossIamAccount</oc>
        <rdn>uid</rdn>
        <attr name="uid">
          <column>user_name</column>
        </attr>
        <attr name="cn">
          <selexpr>ifnull(concat(last_name, ' ', first_name), last_name)</selexpr>
        </attr>
        <attr name="sn">
          <column>last_name</column>
        </attr>
        <attr name="givenname">
          <column>first_name</column>
        </attr>
        <attr name="title">
          <column>title</column>
        </attr>
        <attr name="department">
          <column>department</column>
        </attr>
        <attr name="userpassword">
          <column>user_hash</column>
        </attr>
        <attr name="homephone">
          <column>phone_home</column>
        </attr>
        <attr name="telephonenumber">
          <column>phone_work</column>
        </attr>
        <attr name="mobile">
          <column>phone_mobile</column>
        </attr>
        <attr name="facsimiletelephonenumber">
          <column>phone_fax</column>
        </attr>
        <attr name="ipphone">
          <column>phone_other</column>
        </attr>
        <attr name="street">
          <column>address_street</column>
        </attr>
        <attr name="l">
          <column>address_city</column>
        </attr>
        <attr name="st">
          <column>address_state</column>
        </attr>
        <attr name="c">
          <column>address_country</column>
        </attr>
        <attr name="postalcode">
          <column>address_postalcode</column>
        </attr>
        <attr name="createtimestamp">
          <column>date_entered</column>
        </attr>
        <attr name="modifytimestamp">
          <column>date_modified</column>
        </attr>
        <attr name="description">
          <column>description</column>
        </attr>
        <attr name="mail">
          <selexpr>email_address</selexpr>
          <fromtbls>email_addresses,email_addr_bean_rel</fromtbls>
          <joinwhere>email_addr_bean_rel.bean_id = users.id and email_addr_bean_rel.email_address_id = email_addresses.id</joinwhere>
          <addproc>insert into email_addresses values('%{createGuid()}', '%a', upper('%a'), 0, 0, now(), now(), 0)</addproc>
          <addproc>set @paddr=if((select count(*) from email_addr_bean_rel where bean_id = '%o'), 0, 1)</addproc>
          <addproc>insert into email_addr_bean_rel values('%{createGuid()}', (select id from email_addresses where email_addr
ess = '%a'), '%o', 'Users', @paddr, if(@paddr, 0, 1), now(), now(), 0)</addproc>
          <delproc>set @mailid=(select id from email_addresses where email_address = '%a' and id in (select email_address_id from email_addr_bean_rel where bean_id = '%o'))</delproc>
          <delproc>delete from email_addresses where id = @mailid</delproc>
          <delproc>delete from email_addr_bean_rel where bean_id = '%o' and email_address_id = @mailid</delproc>
        </attr>
        <attr name="manager">
          <oname>User</oname>
          <where>id = (select reports_to_id from users where id = '%o')</where>
          <addproc>update users set reports_to_id = '%a' where id = '%o'</addproc>
          <delproc>update users set reports_to_id = null where id = '%o'</delproc>
        </attr>
        <strginfo>
          <column>id</column>
          <value type="function">createGuid()</value>
        </strginfo>
        <strginfo>
          <column>status</column>
          <value type="constant">Active</value>
          <delproc>update users set status = 'Inactive' where id = '%o'</delproc>
        </strginfo>
        <strginfo>
          <addproc>insert into user_preferences values('%{createGuid()}', 'global', 0, now(), now(), '%o', '%{encode_base64(getFileContents("/opt/secioss/etc/sugarcrm-userpref.txt"), "")}')</addproc>
        </strginfo>
      </object>
    </storage>
  </data>
</config>


ÀßÄê¤Î³Îǧ¤Ï¡¢LISM¥µ¡¼¥Ð¤Î¥Ç¡¼¥â¥ó¤òµ¯Æ°¤·¤Æ¡¢¥Ç¡¼¥¿¤Î¸¡º÷¤ä¹¹¿·¤òLISM¤ËÂФ·¤Æ¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¥Ç¡¼¥â¥ó¤òµ¯Æ°¤¹¤ë¾ì¹ç¤Ï¡¢°ì»þŪ¤Ë"<oc>seciossIamAccount</oc>"¤Î¹Ô¤ò¥³¥á¥ó¥È¥¢¥¦¥È¤·¤Æ²¼¤µ¤¤¡£
# cp /opt/secioss/etc/openldap/slapd.conf.lism /opt/secioss/etc/openldap/slapd.conf
# /opt/secioss/sbin/slapd -h ldap://:3890 -u ldap -d256
# ldapseach -H ldap://:3890 -b 'dc=lism,dc=com'  # ¸¡º÷¤Î¾ì¹ç

 

 

4. ưºî³Îǧ

4.1 IDƱ´ü¤Î³Îǧ

4.1.1 Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹->¥¢¥×¥ê¥±¡¼¥·¥ç¥ó

”3.1 IDƱ´ü¤ÎÀßÄê”¤ÎÆ±´ü¤ÎÊý¸þ¤Ç”1.Åý¹çID´ÉÍý -> ¥µ¡¼¥Ó¥¹”¤òÁªÂò¤·¤¿¾ì¹ç¤Ë¡¢°Ê²¼¤Îºî¶È¤ò¹Ô¤Ã¤Æ²¼¤µ¤¤¡£
Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤«¤éID¤Î¹¹¿·¥Ç¡¼¥¿¤ò¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƱ´ü¤·¤Þ¤¹¡£
¡¡# /opt/secioss/sbin/idsync sp

 

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ¹¤ë¥Ç¡¼¥¿¤Î¹¹¿·¤Ï¹Ô¤ï¤º¤Ë¡¢¹¹¿·¥Ç¡¼¥¿¤Î³Îǧ¤Î¤ß¤·¤¿¤¤¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ¡¢"/opt/secioss/var/lib/csv/user.csv"¤ÎÆâÍÆ¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£
¡¡# /opt/secioss/sbin/idsync -n sp

 

¤Þ¤¿¡¢º¹Ê¬¥Ç¡¼¥¿¤Î¥Á¥§¥Ã¥¯¤Î¤ß¹Ô¤¦¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¡¡# perl C:\opt\secioss\sbin\idsync -r sp

 

Àµ¾ï¤Ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤ÆID¤ÎƱ´ü¤¬¹Ô¤¨¤ë¤³¤È¤ò³Îǧ¤Ç¤­¤¿¤é¡¢cron¤Ë1»þ´Ö¤Ë1²ó "/opt/secioss/sbin/idsync sp"¤ò¼Â¹Ô¤¹¤ë¤è¤¦¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£

 

4.1.2 ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó->Åý¹çID´ÉÍý¥µ¡¼¥Ó¥¹

”3.1 IDƱ´ü¤ÎÀßÄê”¤ÎÆ±´ü¤ÎÊý¸þ¤Ç¡¢”2.¥µ¡¼¥Ó¥¹ -> Åý¹çID´ÉÍý”¤òÀßÄꤷ¤¿¾ì¹ç¡¢°Ê²¼¤Îºî¶È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤«¤éID¤Îº¹Ê¬¥Ç¡¼¥¿¤òÅý¹çID´ÉÍý¥µ¡¼¥Ó¥¹¤ËƱ´ü¤·¤Þ¤¹¡£
¡¡# /opt/secioss/sbin/idsync idp

 

¤Þ¤¿¡¢º¹Ê¬¥Ç¡¼¥¿¤Î¥Á¥§¥Ã¥¯¤Î¤ß¹Ô¤¦¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¡¡# perl C:\opt\secioss\sbin\idsync -r idp 

 

4.2 ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î³Îǧ  

"<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL>/sso/autologin.php?sso_app=<2.2¹à¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾>"¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¹¤ë¤³¤È¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£

 

 

5. OAuth 2.0 + Restful API

OAuth 2.0 + Restful API¤òÀßÄꤹ¤ëÁ°¤Ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ÈIDƱ´ü¤ÎÀßÄ꤬´°Î»¤·¤Æ¤¤¤ë¤â¤Î¤È¤·¤Þ¤¹¡£

5.1  OAuth¤ÎÀßÄê

ºÇ½é¤ËOAuthÍѤΥǡ¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡£
¥Ç¡¼¥¿¥Ù¡¼¥¹¥µ¡¼¥Ð¤¬mysql¤Î¾ì¹ç¡¢°Ê²¼¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
# cd secioss-idsuite-cloud-sp-2.0.x
# mysql --user=<DB¥æ¡¼¥¶> --password=<DB¥Ñ¥¹¥ï¡¼¥É>
mysql> create database oauth2;
mysql> use oauth2;
mysql> source ./src/oauth2/mysql_create_tables.sql

 

¼¡¤ËOAuth¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
# ./config.sh oauth
¡¦¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¼ïÎà[1. mysql|2. PostgreSQL]¡§¡¡¥Ç¡¼¥¿¥Ù¡¼¥¹¥µ¡¼¥Ð¤Î¼ïÎà
¡¦¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¥Û¥¹¥È̾¡§¡¡¥Ç¡¼¥¿¥Ù¡¼¥¹¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾
¡¦¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¥æ¡¼¥¶¡§¡¡¥Ç¡¼¥¿¥Ù¡¼¥¹¤ËÀܳ¤¹¤ë¥æ¡¼¥¶
¡¦¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¥Ñ¥¹¥ï¡¼¥É¡§¡¡¥Ç¡¼¥¿¥Ù¡¼¥¹¤ËÀܳ¤¹¤ë¥Ñ¥¹¥ï¡¼¥É

 

5.2  Restful API¤ÎÀßÄê

Restful API¤«¤é¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¤ò»²¾È²Äǽ¤È¤¹¤ëÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
°Ê²¼¤ÏMosP¤Î¶ÐÂÕ¾ðÊó¤ò»²¾È²Äǽ¤È¤¹¤ëÀßÄê¤Ç¤¹¡£

 

/opt/secioss/etc/lism_rest.conf


<config>
  <data name="MosP">
    <container>
      <oc>organization</oc>
      <rdn>ou=MosP</rdn>
    </container>
    <storage name="SQL" hash="MD5:hex:2">
      <libload>LISM/Utils/lism_util.pl</libload>
      <dsn>DBI:Pg:dbname=mospv4;host=localhost</dsn>
      <admin>usermosp</admin>
      <passwd>passmosp</passwd>
      <object name="User">
        <noop>add</noop>
        <noop>modify</noop>
        <noop>delete</noop>
        <table>pfm_user</table>
        <id>
          <column>pfm_user_id</column>
        </id>
        <oc>user</oc>
        <rdn>uid</rdn>
        <attr name="uid">
          <column>user_id</column>
        </attr>
      </object>
      <object name="Attendance">
        <container>
          <oname>User</oname>
          <joinwhere>pfm_user.personal_id = tmd_attendance.personal_id</joinwhere>
        </container>
        <subcontainer>
          <rdn>ou=Attendances</rdn>
          <oc>organizationalUnit</oc>
        </subcontainer>
        <noop>add</noop>
        <noop>modify</noop>
        <noop>delete</noop>
        <table>tmd_attendance</table>
        <id>
          <column>tmd_attendance_id</column>
        </id>
        <sort>work_date</sort>
        <oc>attendance</oc>
        <rdn>work_date</rdn>
        <attr name="work_date">
          <column>work_date</column>
          <type>date</type>
        </attr>
        <attr name="start_time">
          <column>start_time</column>
        </attr>
        <attr name="end_time">
          <column>end_time</column>
        </attr>
        <attr name="work_type">
          <selexpr>tmm_work_type.work_type_name</selexpr>
          <fromtbls>tmm_work_type</fromtbls>
          <joinwhere>tmd_attendance.work_type_code = tmm_work_type.work_type_code</joinwhere>
        </attr>
        <attr name="rest">
          <selexpr>rest_start || ' ' || rest_end</selexpr>
          <fromtbls>tmd_rest</fromtbls>
          <joinwhere>tmd_attendance.personal_id = tmd_rest.personal_id and tmd_attendance.work_date = tmd_rest.work_date</joinwhere>
        </attr>
      </object>
    </storage>
  </data>
</config>


 

Restful API¤Î¥Ñ¥¹¤ò"/cgi-bin/lism/attendance.cgi"¤È¤¹¤ë¾ì¹ç¡¢°Ê²¼¤ÎÀßÄê¤ò¹Ô¤Ã¤Æ²¼¤µ¤¤¡£
/etc/httpd.conf¤ÎÂÀ»ú¤Î²Õ½ê¤ò½¤Àµ¤·¤Æ²¼¤µ¤¤¡£


<Directory "/var/www/cgi-bin">
    AllowOverride None
    Options None
    Options FollowSymLinks
    Order allow,deny
    Allow from all
</Directory>


 

/var/www/cgi-bin/lism/lism_restapi.conf¤Ë°Ê²¼¤ÎÀßÄê¤òÄɵ­¤·¤Æ²¼¤µ¤¤¡£
attendancedn "ou=Attendances,uid=%u,ou=MosP"

 

Restful APIÍѤΥ·¥ó¥Ü¥ê¥Ã¥¯¥ê¥ó¥¯¤òºîÀ®¸å¡¢httpd¤òºÆµ¯Æ°¤·¤Æ²¼¤µ¤¤¡£
# cd /var/www/cgi-bin/lism
# ln -s lism_rest.cgi attendance.cgi
# /etc/init.d/httpd restart

 

5.3  Àܳ³Îǧ

Restful APIÀܳ³ÎǧÍѤΥ¹¥¯¥ê¥×¥È¤òWeb¥µ¡¼¥Ð¤ËÇÛÃÖ¤·¤Æ²¼¤µ¤¤¡£
URL¤Ï¡¢https://<¥Û¥¹¥È̾>/oauth_client.php¤È¤·¤Þ¤¹¡£

 

oauth_client.php


<?php
   $app_id = "test";
   $app_secret = "test";
   $my_url = "https://<¥Û¥¹¥È̾>/oauth_client.php";

   session_start();
   $code = $_REQUEST["code"];

   if(empty($code)) {
     $_SESSION['state'] = md5(uniqid(rand(), TRUE)); //CSRF protection
     $url = "https://<Restful API¤Î¥Û¥¹¥È̾>/path/oauth/authorize.php?client_id="
       . $app_id . "&redirect_uri=" . urlencode($my_url) . "&state="
       . $_SESSION['state'];

     echo("<script> top.location.href='" . $url . "'</script>");
   }

   if($_REQUEST['state'] == $_SESSION['state']) {
     if (!isset($_SESSION['access_token'])) {
         $url = "https://<Resutful API¤Î¥Û¥¹¥È̾>/path/oauth/token.php?"
           . "client_id=" . $app_id . "&redirect_uri=" . urlencode($my_url)
           . "&client_secret=" . $app_secret . "&code=" . $code;

         $response = file_get_contents($url);
         $params = null;
         $params = json_decode($response);
         $_SESSION['access_token'] = $params->access_token;
     }

     $url = "https://<Restful API¤Î¥Û¥¹¥È̾>/cgi-bin/lism/attendance.cgi?oauth_token=".$_SESSION['access_token']."&action=search&filter=".urlencode("(work_date>=20xx-yy-zz)");

     $response = file_get_contents($url);
     $json_res = json_decode($response);
     for ($i = 0; $i < count($json_res->entries); $i++) {
         print("ÆüÉÕ: ".$json_res->entries[0]->work_date[$i]."<br>");
         print("³«»Ï: ".$json_res->entries[0]->start_time[$i]."<br>");
         print("½ªÎ»: ".$json_res->entries[0]->end_time[$i]."<br>");
         print("<br>");
     }
   } else {
     echo("The state does not match. You may be a victim of CSRF.");
   }
?>


 

 

¼¡¤Ëhttps://<Restful API¤Î¥Û¥¹¥È̾>/path/oauth/addclient.php¤«¤é¡¢¥¯¥é¥¤¥¢¥ó¥È¤È¤·¤ÆÀܳ³ÎǧÍѤΥ¹¥¯¥ê¥×¥È¤òÅÐÏ¿¤·¤Æ²¼¤µ¤¤¡£
¡¦Client ID: ¥¹¥¯¥ê¥×¥È¤Î$app_id¤ÎÃÍ
¡¦Client Secret: ¥¹¥¯¥ê¥×¥È¤Î$app_secret¤ÎÃÍ
¡¦Redirect URL:  ¥¹¥¯¥ê¥×¥È¤Î$my_url¤ÎÃÍ

 

https://<¥Û¥¹¥È̾>/oauth_client.php¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤È¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î¥í¥°¥¤¥ó²èÌ̤¬É½¼¨¤µ¤ì¤Þ¤¹¤Î¤Ç¡¢¥í¥°¥¤¥ó¤·¤Æ²¼¤µ¤¤¡£
¥í¥°¥¤¥ó¤·¤¿¥æ¡¼¥¶¤Î¶ÐÂÕ¾ðÊó¤¬É½¼¨¤µ¤ì¤ì¤ÐÀܳÀ®¸ù¤Ç¤¹¡£

¥ª¡¼¥×¥ó¥½¡¼¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¡ÖSecioss Access Manager Community Edition¡×

¶áǯ¡¢´ë¶È¤Ë¤ª¤±¤ëÆâÉôÅýÀ©¤Î½ÅÍ×À­¤¬Èó¾ï¤Ë¹â¤Þ¤Ã¤Æ¤ª¤ê¡¢¤½¤ì¤Ëȼ¤¤¡¢´ë¶ÈÆâ¤Î¥·¥¹¥Æ¥à¤ä¥Ç¡¼¥¿¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤òÀµ¤·¤¯´ÉÍý¤¹¤ë»ÅÁȤߤ¬É¬ÍפȤµ¤ì¤Æ¤¤¤Þ¤¹¡£¥¢¥¯¥»¥¹¤Î´ÉÍý¤Ë¤Ï¡¢¥¢¥¯¥»¥¹¤·¤Æ¤¤¤ëID¤¬ÍøÍѼÔËܿͤǤ¢¤ë¤³¤È¤òÊݾڤ¹¤ë¤È¤È¤â¤Ë¡¢¥·¥¹¥Æ¥à¤ä¥Ç¡¼¥¿¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¸¢¸Â¤ò¤­¤Á¤ó¤ÈÀßÄꤹ¤ë¤³¤È¤¬É¬ÍפȤʤê¤Þ¤¹¡£

 

¥»¥·¥ª¥¹¤Ç¤Ï¡¢OpenLDAP¡¢Shibboleth¡¢mod_auth_tktÅù¤Î¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤ò³èÍѤ·¤¿¥ª¡¼¥×¥ó¥½¡¼¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥½¥ê¥å¡¼¥·¥ç¥ó¡ÖSecioss Access Manager Community Edition¡×¤ò¤´Ä󶡤¤¤¿¤·¤Þ¤¹¡£

Secioss Access Manager Community Edition¤Ï¡¢GPL¤È¾¦Íѥ饤¥»¥ó¥¹¤Î¥Ç¥å¥¢¥ë¥é¥¤¥»¥ó¥¹¡ÊShibbolethÅù¼ýÏ¿¤·¤Æ¤¤¤ë¥½¥Õ¥È¥¦¥§¥¢¤Î¥é¥¤¥»¥ó¥¹¤Ï¤½¤ì¤¾¤ì¤Î¤â¤Î¤Ë½àµò¤·¤Þ¤¹¡Ë¤Ç¡¢°Ê²¼¤«¤é¥À¥¦¥ó¥í¡¼¥É¤Ç¤­¤Þ¤¹¡£
¡¦¥À¥¦¥ó¥í¡¼¥É¡§ http://sourceforge.jp/projects/secioss-auth/releases/

 

¥¯¥¤¥Ã¥¯¥¹¥¿¡¼¥È¥¬¥¤¥É¤ò¤´Í÷ĺ¤¯¤È¡¢´Êñ¤ËGoogle Apps¤ÈSalesforce¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò´Ä¶­¤ò¹½ÃÛ¤¤¤¿¤À¤±¤Þ¤¹¡£

 

¥ª¡¼¥×¥ó¥½¡¼¥¹¤ò³èÍѤ¹¤ë¤³¤È¤Ç¡¢ ¥·¥ó¥×¥ë¤«¤Ä¥«¥¹¥¿¥Þ¥¤¥ºÀ­¤Î¹â¤¤¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤ò¼Â¸½¤¤¤¿¤·¤Þ¤¹¡£ ¤ªµÒÍͤÎÍ×˾¤Ë¹ç¤ï¤»¤Æ¡¢´ë¶È¥·¥¹¥Æ¥à¤Ø¤ÎƳÆþ¤ä¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ø¤ÎÁȤ߹þ¤ß¤Ë½ÀÆð¤ËÂбþ¤·¡¢¥»¥­¥å¥ê¥Æ¥£¤Î¶¯²½¤ä¥æ¡¼¥¶¤ÎÍøÊØÀ­¸þ¾å¤Ë¹×¸¥¤¤¤¿¤·¤Þ¤¹¡£

 

¤µ¤é¤Ë¡¢ÊÀ¼Ò¤ÎÅý¹çID´ÉÍý¥½¥ê¥å¡¼¥·¥ç¥ó¡ÖSecioss Identity Manager¡×¤ÈÁȤ߹ç¤ï¤»¤Æ¤¤¤¿¤À¤¯¤³¤È¤Ç¡¢ID¤ä¥¢¥¯¥»¥¹¸¢¸Â¤Î°ì¸µ´ÉÍý¤¬²Äǽ¤È¤Ê¤ê¡¢¤è¤ê¶¯¸Ç¤Ê¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó´Ä¶­¤ò¹½ÃÛ¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

 

¥·¥¹¥Æ¥à¹½À®

system.JPG

 

 

Secioss Access Manager Community Edition

¼ÒÆâ¤Î¥·¥¹¥Æ¥à¤ËÂФ¹¤ëWeb¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤È¥°¥ë¡¼¥×¤Ë¤è¤ë¥¢¥¯¥»¥¹À©¸æ¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£Web¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ç¤Ï¡¢¥·¥¹¥Æ¥à¤Ë¥í¥°¥¤¥ó½èÍý¤¬É¬Íפʾì¹ç¤Ç¤â¡¢ÂåÍýǧ¾Úµ¡Ç½¤Ë¤è¤Ã¤ÆSecioss Access Manager Community Edition¤¬¼«Æ°Åª¤Ë¥í¥°¥¤¥ó¤ò¹Ô¤¤¤Þ¤¹¡£¤Þ¤¿¡¢Åý¹çWindowsǧ¾Úµ¡Ç½¤ò»ÈÍѤ¹¤ë¤³¤È¤Ç¡¢Windows¤Î¥í¥°¥¤¥ó¤È¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤òÏ¢·È¤µ¤»¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

ÆÃħ

  • Secioss Access Manager Community Edition¤Ø¥í¥°¥¤¥ó¤¹¤ë¤À¤±¤Ç¡¢³Æ¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤¬²Äǽ¤Ç¤¹¡£

  • ¥ê¥Ð¡¼¥¹¥×¥í¥­¥·Êý¼°¡¢¥¨¡¼¥¸¥§¥ó¥ÈÊý¼°¤Ë²Ã¤¨¤Æ¡¢Shibboleth¡¢SAML¤äOpenID¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£ 

  • ID¡¦¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤Î¾¤ËÅý¹çWindowsǧ¾Ú¡¢¥¯¥é¥¤¥¢¥ó¥È¾ÚÌÀ½ñ¡¢¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¡¢·ÈÂÓÅÅÏäθÄÂμ±ÊÌÈÖ¹æÇ§¾Ú¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£

  • Åý¹çWindowsǧ¾Ú¤Ë¤è¤êWindows¥Þ¥·¥ó¤Ë¥í¥°¥¤¥ó¤¹¤ë¤À¤±¤Ç¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£

  • ·ÈÂÓÅÅÏ䫤饷¥¹¥Æ¥à¤Ø¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ë¤âÂбþ¤·¤Æ¤¤¤Þ¤¹¡£

  • ¥·¥¹¥Æ¥à¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤ò¡¢ÆÃÄê¤Î¥°¥ë¡¼¥×¤Ë½ê°¤¹¤ë¥æ¡¼¥¶¤ËÀ©¸Â¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

¸ú²Ì

  • ¥·¥¹¥Æ¥à¤Ø¥í¥°¥¤¥ó¤¹¤ë¼ê´Ö¤ò¾Ê¤¯¤³¤È¤Ç¡¢¥æ¡¼¥¶¤ÎÀ¸»ºÀ­¤¬¸þ¾å¤·¤Þ¤¹¡£

  • ¥æ¡¼¥¶¤Ï¥Ñ¥¹¥ï¡¼¥É¤ò£±¤Ä´ÉÍý¤¹¤ì¤Ð¤è¤¯¡¢¥Ñ¥¹¥ï¡¼¥É˺¤ì¤Ë¤è¤ë¥Ñ¥¹¥ï¡¼¥É¤ÎºÆÈ¯¹Ô¤òºï¸º¤Ç¤­¤Þ¤¹¡£

  • ǧ¾Ú¤ä¥¢¥¯¥»¥¹À©¸æ¤ò°ì¸µÅª¤Ë´ÉÍý¤·¡¢¼ÒÆâ¥·¥¹¥Æ¥à¤ËÅý°ìŪ¤Ê¥»¥­¥å¥ê¥Æ¥£¥Ý¥ê¥·¡¼¤òŬÍѤǤ­¤Þ¤¹¡£

 

 

ÂбþOS

  • Red Hat Enterprise Linux 5

  • CentOS 5

 

 

Âбþ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó

¼¡¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¤ÎÏ¢·È¤¬²Äǽ¤Ç¤¹¡£
¤½¤Î¾¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¤Ä¤¤¤Æ¤âÂбþ²Äǽ¤Ç¤¹¤Î¤Ç¡¢¤´ÁêÃ̲¼¤µ¤¤¡£

  • ¥°¥ë¡¼¥×¥¦¥§¥¢
    ¡¡¡¦Aipo
    ¡¡¡¦¥µ¥¤¥Ü¥¦¥º¥¬¥ë¡¼¥ó£²

  • ¶ÐÂÕ´ÉÍý
    ¡¡¡¦MosP

  • SaaS¥µ¡¼¥Ó¥¹
    ¡¡¡¦Salesforce
    ¡¡¡¦Google Apps

  • ¥Ý¡¼¥¿¥ë
    ¡¡¡¦NetCommons
    ¡¡¡¦XOOPS Cube

  • ¥Ö¥í¥°
    ¡¡¡¦MovableType

  • CRM
    ¡¡¡¦SugarCRM

  • ¥¢¥ó¥±¡¼¥È¥·¥¹¥Æ¥à
    ¡¡¡¦LimeSurvey

 

 

¥µ¥Ý¡¼¥È

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤òÄ󶡤·¤Æ¤¤¤Þ¤¹¡£ 

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤ÎÆâÍÆ¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£

  • À½ÉʤΥ¤¥ó¥¹¥È¡¼¥ëÊýË¡¡¢ÀßÄêÊýË¡¡¢µ¡Ç½¤Ë´Ø¤¹¤ë¥á¡¼¥ë¤Ë¤è¤ë¥Þ¥Ë¥å¥¢¥ë¥ì¥Ù¥ë¤ÎÌ䤤¹ç¤ï¤»Âбþ

  • ¥á¡¼¥ë¤Ç¤Î¥ª¥Õ¥µ¥¤¥È¾ã³²Ä´ºº 

  • À½ÉʤΥС¼¥¸¥ç¥ó¥¢¥Ã¥×ÈǤÎÄó¶¡

 

 

Ìä¹ç¤»

ËÜ¥½¥Õ¥È¥¦¥§¥¢¤Ë´Ø¤¹¤ë¤ªÌä¹ç¤»¤Ï¤³¤Á¤é¤«¤é¤ª´ê¤¤¤·¤Þ¤¹¡£

Secioss Identity/Access Manager

¥¯¥é¥¦¥É¥µ¡¼¥Ó¥¹¤Î¹­¤¬¤ê¤È¤È¤â¤Ë¡¢º£¤Þ¤Ç¤Î¼ÒÆâ¥Í¥Ã¥È¥ï¡¼¥¯¤À¤±¤ÎID´ÉÍý¤ä¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ç¤ÏÂбþ¤Ç¤­¤Ê¤¤¾ìÌ̤¬Áý¤¨¤Æ¤ª¤ê¤Þ¤¹¡£¤½¤³¤ÇÊÀ¼Ò¤Ç¤Ï¥¯¥é¥¦¥É¥µ¡¼¥Ó¥¹¤ËÂбþ¤·¤¿ID´ÉÍý¡¦¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥½¥ê¥å¡¼¥·¥ç¥ó¤òÄ󶡤¤¤¿¤·¤Þ¤¹¡£

 

¡¦Secioss Identity Manager Enterprise Edition¡§¡¡¤ªµÒÍÍ´ë¶È¤ÎID¤òÅý¹ç´ÉÍý¤¹¤ë¥½¥ê¥å¡¼¥·¥ç¥ó¤Ç¤¹¡£
¡¦Secioss Access Manager Enterprise Edition¡§¡¡¤ªµÒÍÍ´ë¶È¤ÇÍøÍѤ¹¤ë¥µ¡¼¥Ó¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¦¥½¥ê¥å¡¼¥·¥ç¥ó¤Ç¤¹¡£
¡¦Secioss Identity/Access Manager SaaS Edition¡§¡¡¤ªµÒÍͤΥ¨¥ó¥É¥æ¡¼¥¶¤ËÂФ·¤ÆSaaS·¿¤ÇÅý¹çID´ÉÍý¡¦¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥µ¡¼¥Ó¥¹¤òÄó¶¡²Äǽ¤È¤¹¤ë¥½¥ê¥å¡¼¥·¥ç¥ó¤Ç¤¹¡£

 

¥·¥¹¥Æ¥à¹½À®

´ë¶ÈƳÆþ¤Î¾ì¹ç

 

system_cloud1.jpg

 

SaaS·¿¤Î¾ì¹ç

 

system_cloud2.jpg

 

Secioss Identity Manager

µ¡Ç½

  • ¥æ¡¼¥¶´ÉÍý
    Google Apps¡¢Salesforce¤ä¥ª¥ó¥×¥ì¥ß¥¹¡¢¥×¥é¥¤¥Ù¡¼¥È¥¯¥é¥¦¥ÉÆâ¤Î¥·¥¹¥Æ¥à¤ÎID¤òÅý¹ç´ÉÍý¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£
    ¤Þ¤¿¡¢¥·¥¹¥Æ¥àËè¤ËÏ¢·È¤¹¤ë¥æ¡¼¥¶¤ò»ØÄꤹ¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

  • ¥°¥ë¡¼¥×´ÉÍý
    ¥æ¡¼¥¶¤Î¥°¥ë¡¼¥×¤ò´ÉÍý¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£Google Apps¤Î¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¤Î¥á¥ó¥Ð¤Î°ì³çÅÐÏ¿Åù¤â²Äǽ¤Ç¤¹¡£

  • ¥Ñ¥¹¥ï¡¼¥É¥Ý¥ê¥·¡¼ 
    ¥Ñ¥¹¥ï¡¼¥É¤Î¥Ý¥ê¥·¡¼´ÉÍý¤¬²Äǽ¤Ç¤¹¡£Í­¸ú´ü¸Â¤ä¥Ñ¥¹¥ï¡¼¥É¤Î»ÈÍÑʸ»ú¤Ê¤É¤Î»ØÄ꤬²Äǽ¤Ç¤¹¡£

  • IDƱ´ü¤ÎÊÂÎó½èÍý
    Ʊ´ü½èÍý¤òÊÂÎó¤Ë¥Ð¥Ã¥¯¥°¥é¥¦¥ó¥É¤Ç¼Â¹Ô¤¹¤ë¤¿¤á¡¢Ï¢·È¤¹¤ë¥µ¡¼¥Ó¥¹¤¬Áý²Ã¤·¤¿¾ì¹ç¤â¡¢IDÁàºî¤Î¥ì¥¹¥Ý¥ó¥¹»þ´Ö¤ÏÁý²Ã¤·¤Þ¤»¤ó¡£ 

  • ¥í¥°¸¡º÷
    ¥æ¡¼¥¶¡¢¥°¥ë¡¼¥×¤Î¹¹¿·¤Ë´Ø¤¹¤ë¥í¥°¤òWeb¤«¤é¸¡º÷¡¢É½¼¨¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

  • ¥Þ¥ë¥Á¥Æ¥Ê¥ó¥È
    ¥Þ¥ë¥Á¥Æ¥Ê¥ó¥È¤ËÂбþ¤·¤Æ¤ª¤ê¡¢¥Æ¥Ê¥ó¥Èñ°Ì¤Ç¤ÎID´ÉÍý¤¬²Äǽ¤È¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£
    SaaS Edition¤Ç¤Ï¡¢¥Æ¥Ê¥ó¥Èñ°Ì¤ÇÏ¢·È¤¹¤ë¥µ¡¼¥Ó¥¹¤òÀßÄꤹ¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

Secioss Access Manager

µ¡Ç½

  • ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
    Google Apps¡¢Salesforce¤ä¥ª¥ó¥×¥ì¥ß¥¹¡¢ ¥×¥é¥¤¥Ù¡¼¥È¥¯¥é¥¦¥ÉÆâ¤Î¥·¥¹¥Æ¥à¤È¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤Ç¤¹¡£
    ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÊý¼°¤È¤·¤Æ¡¢SAML¡¢OpenID¡¢¥ê¥Ð¡¼¥¹¥×¥í¥­¥·Êý¼°¡¢¥¨¡¼¥¸¥§¥ó¥ÈÊý¼°¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£

  • ǧ¾Ú
    ID/¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¡¢Åý¹çWindowsǧ¾Ú¡¢¥¯¥é¥¤¥¢¥ó¥È¾ÚÌÀ½ñǧ¾Ú¡¢¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¡¢·ÈÂÓÅÅÏÃüËöǧ¾Ú¡¢SAMLǧ¾Ú¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£
    ¥¯¥é¥¤¥¢¥ó¥È¤Î¥¢¥¯¥»¥¹¸µ¥Í¥Ã¥È¥ï¡¼¥¯¤ä»þ´ÖÂӤˤè¤Ã¤Æ¡¢Ç§¾Ú¥ë¡¼¥ë¡ÊÊ£¿ô¤Îǧ¾ÚÊý¼°¤òÁȤ߹ç¤ï¤»¤¿¤ê¡¢½çÈÖ¤ò»ØÄꤹ¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡Ë¤òÀßÄꤹ¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

  • ¥¢¥«¥¦¥ó¥È¤Î¥í¥Ã¥¯¥¢¥¦¥È
    »ØÄꤷ¤¿»þ´ÖÆâ¤Ë»ØÄꤷ¤¿²ó¿ôǧ¾Ú¤Ë¼ºÇÔ¤·¤¿¾ì¹ç¡¢¥¢¥«¥¦¥ó¥È¤ò¥í¥Ã¥¯¥¢¥¦¥È¤·¤Þ¤¹¡£

  • ¥¢¥¯¥»¥¹À©¸æ
    ¥æ¡¼¥¶¡¢¥°¥ë¡¼¥×¡¢¥¯¥é¥¤¥¢¥ó¥È¤Î¥¢¥¯¥»¥¹¸µ¥Í¥Ã¥È¥ï¡¼¥¯¤Ï¤â¤Á¤í¤ó¡¢»þ´ÖÂÓ¤äǧ¾ÚÊý¼°¤Ç¤Î¥µ¡¼¥Ó¥¹¤ËÂФ¹¤ë¥¢¥¯¥»¥¹À©¸æ¤¬²Äǽ¤Ç¤¹¡£ 
    ǧ¾ÚÊý¼°¤Ë¤è¤ë¥¢¥¯¥»¥¹À©¸æ¤Ç¤Ï¡¢»ØÄê¤Îǧ¾ÚÊý¼°¤Ë¤è¤ë¥í¥°¥¤¥ó¤¬¹Ô¤ï¤ì¤Æ¤¤¤Ê¤¤¾ì¹ç¡¢¥µ¡¼¥Ó¥¹¤Ë¥¢¥¯¥»¥¹¤·¤¿¥¿¥¤¥ß¥ó¥°¤Ç»ØÄê¤Îǧ¾Ú¤¬Í׵ᤵ¤ì¤Þ¤¹¡£

  • ¥í¥°¸¡º÷
    ǧ¾Ú¤Ë´Ø¤¹¤ë¥í¥°¤òWeb¤«¤é¸¡º÷¡¢É½¼¨¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

  • ÂåÍýǧ¾Ú
    SAML̤Âбþ¤ÎSaaS¤äASPÅù¡¢¥µ¡¼¥Ó¥¹Â¦¤Ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¦¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤¬¤Ê¤¤¾ì¹ç¡¢ÂåÍýǧ¾Ú¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¦¤³¤È¤¬²Äǽ¤Ç¤¹¡£
    SaaS Edition¤Î¤ß¤Îµ¡Ç½¤Ç¤¹¡£

  • ¥Þ¥ë¥Á¥Æ¥Ê¥ó¥È
    ¥Æ¥Ê¥ó¥Èñ°Ì¤Ç¡¢Ç§¾Ú¥ë¡¼¥ë¡¢¥¢¥¯¥»¥¹À©¸æ¤ÎÀßÄ꤬²Äǽ¤Ç¤¹¡£
    SaaS Edition¤Ç¤Ï¡¢¥Æ¥Ê¥ó¥Èñ°Ì¤Ç»ÈÍѲÄǽ¤Êǧ¾ÚÊý¼°¤äÏ¢·È¤¹¤ë¥µ¡¼¥Ó¥¹¤òÀßÄꤹ¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

 

ÂбþOS

  • Red Hat Enterprise Linux 5

  • CentOS 5

 

 

Âбþ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó

¼¡¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¤ÎÏ¢·È¤¬²Äǽ¤Ç¤¹¡£
¤½¤Î¾¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¤Ä¤¤¤Æ¤âÂбþ²Äǽ¤Ç¤¹¤Î¤Ç¡¢¤´ÁêÃ̲¼¤µ¤¤¡£

Secioss Identity Manager Enterprise Edition
  • ¥°¥ë¡¼¥×¥¦¥§¥¢
    ¡¡¡¦Aipo

  • ¶ÐÂÕ´ÉÍý
    ¡¡¡¦MosP

  • ÈÎÇä´ÉÍý
    ¡¡¡¦SalesCube

  • Saas¥µ¡¼¥Ó¥¹
    ¡¡¡¦Salesforce
    ¡¡¡¦Google Apps

  • ¥á¡¼¥ë¥·¥¹¥Æ¥à
    ¡¡¡¦Zimbra

  • ¥á¡¼¥ë¥¢¡¼¥«¥¤¥Ö
    ¡¡¡¦MailArchiva

  • ¥Ý¡¼¥¿¥ë
    ¡¡¡¦NetCommons
    ¡¡¡¦Liferay
    ¡¡¡¦XOOPS Cube

  • ECM¡Ê´ë¶È¸þ¤±¥³¥ó¥Æ¥ó¥Ä´ÉÍý¥·¥¹¥Æ¥à¡Ë
    ¡¡¡¦Alfresco

  • ʸ½ñ´ÉÍý
    ¡¡¡¦KnowledgeTree

  • ¥Ö¥í¥°
    ¡¡¡¦MovableType

  • CRM
    ¡¡¡¦SugarCRM

Secioss Access Manager Eterprise Edition
  • ¾ÚÌÀ½ñǧ¾Ú
    ¡¡¡¦Gleas¡ÊJCCH¡¦¥»¥­¥å¥ê¥Æ¥£¡¦¥½¥ê¥å¡¼¥·¥ç¥ó¡¦¥·¥¹¥Æ¥à¥º¡Ë

  • ¥°¥ë¡¼¥×¥¦¥§¥¢
    ¡¡¡¦Aipo
    ¡¡¡¦¥µ¥¤¥Ü¥¦¥º¥¬¥ë¡¼¥ó£²

  • ¶ÐÂÕ´ÉÍý
    ¡¡¡¦MosP

  • ÈÎÇä´ÉÍý
    ¡¡¡¦SalesCube

  • SaaS¥µ¡¼¥Ó¥¹
    ¡¡¡¦Salesforce
    ¡¡¡¦Google Apps

  • ¥á¡¼¥ë¥¢¡¼¥«¥¤¥Ö
    ¡¡¡¦MailArchiva

  • ¥Ý¡¼¥¿¥ë
    ¡¡¡¦NetCommons ¡¡¡¦XOOPS Cube

  • ʸ½ñ´ÉÍý
    ¡¡¡¦KnowledgeTree

  • ¥Ö¥í¥°
    ¡¡¡¦MovableType

  • CRM
    ¡¡¡¦SugarCRM

  • ¥¢¥ó¥±¡¼¥È¥·¥¹¥Æ¥à
    ¡¡¡¦LimeSurvey

 

 

²Á³Ê

¥½¥Õ¥È¥¦¥§¥¢

¥é¥¤¥»¥ó¥¹²Á³Ê¤Î¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤³¤Á¤é¤Ë¤ªÌä¹ç¤»²¼¤µ¤¤¡£

 

¥µ¥Ý¡¼¥È

ǯ´Ö¤Î¥µ¥Ý¡¼¥ÈÎÁ¤Ï¡¢¥é¥¤¥»¥ó¥¹²Á³Ê¤Ë´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£ 

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤ÎÆâÍÆ¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£

  • À½ÉʤΥ¤¥ó¥¹¥È¡¼¥ëÊýË¡¡¢ÀßÄêÊýË¡¡¢µ¡Ç½¤Ë´Ø¤¹¤ë¥á¡¼¥ë¤Ë¤è¤ë¥Þ¥Ë¥å¥¢¥ë¥ì¥Ù¥ë¤ÎÌ䤤¹ç¤ï¤»Âбþ

  • ¥á¡¼¥ë¤Ç¤Î¥ª¥Õ¥µ¥¤¥È¾ã³²Ä´ºº 

  • À½ÉʤΥޥ¤¥Ê¡¼¥Ð¡¼¥¸¥ç¥ó¥¢¥Ã¥×ÈǤÎÄó¶¡

 

 

Ìä¹ç¤»

ËÜÀ½Éʤ˴ؤ¹¤ë¤ªÌä¹ç¤»¤Ï¤³¤Á¤é¤«¤é¤ª´ê¤¤¤·¤Þ¤¹¡£

·ÈÂÓÅÅÏäò»ÈÍѤ·¤¿¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¥½¥ê¥å¡¼¥·¥ç¥ó¡ÖSeciossOTP¡×

Secioss OTP¤Ï¡¢·ÈÂÓÅÅÏäò»ÈÍѤ·¤¿¥ª¡¼¥×¥ó¥½¡¼¥¹¥Ù¡¼¥¹¤Î¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¥½¥ê¥å¡¼¥·¥ç¥ó¤Ç¤¹¡£
¥¢¥ë¥´¥ê¥º¥à¤Ë¤Ï¡¢RFCɸ½à¤ÎHOTP¤òºÎÍѤ·¤Æ¤¤¤Þ¤¹¡£ 

 

¥È¡¼¥¯¥ó¤Ë¡¢½¾Íè¤Î¤è¤¦¤ÊÀìÍѵ¡´ï¤Ç¤Ï¤Ê¤¯¡¢Ã¯¤Ç¤â»ý¤Ã¤Æ¤¤¤ë·ÈÂÓÅÅÏäȥª¡¼¥×¥ó¥½¡¼¥¹¤Î¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤òÍøÍѤ¹¤ë¤³¤È¤Ç¡¢µ¡´ï¤Î¹ØÆþ¤ä¥æ¡¼¥¶¤Ø¤ÎÇÛÉÛ¥³¥¹¥È¤ò̵¤¯¤·¡¢Ç§¾Ú¥µ¡¼¥Ð¤â̵½þ¤ÇÍøÍѲÄǽ¤Ç¤¹¤Î¤Ç¡¢½¾Íè¤è¤ê¤âÂçÉý¤ËÄ㤤¥³¥¹¥È¤Ç¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤òƳÆþ¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

Secioss OTP¤Ï¡¢¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤Ë¤è¤ê60ÉÃËè¤ËÀ¸À®¤µ¤ì¤ë1²ó¸Â¤êÍ­¸ú¤Ê¥Ñ¥¹¥ï¡¼¥É¤Ë¤è¤Ã¤ÆËÜ¿Íǧ¾Ú¤ò¹Ô¤¤¤Þ¤¹¡£¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤Ï¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È·Ðͳ¤Ç·ÈÂÓÅÅÏä˥À¥¦¥ó¥í¡¼¥É¤·¤ÆÍøÍѤ¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

Secioss OTP¤Îǧ¾Ú¥µ¡¼¥Ð¤Ï¡¢¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤È¤·¤ÆREST¡¢µÚ¤Ó¥ª¥×¥·¥ç¥ó¤ÇRADIUS¤òÄ󶡤·¤Æ¤ª¤ê¤Þ¤¹¤Î¤Ç¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤äVPN¡¢Unix·ÏOS¤Îǧ¾Ú¤ò´Êñ¤Ë¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¤ËÊѹ¹¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

¤µ¤é¤Ë¡¢¥»¥·¥ª¥¹¤ÎSecioss Identity Suite Cloud Edition¤äSecioss Access Manager Enterprise¤ÈÏ¢·È¤¹¤ë¤³¤È¤Ç¡¢Google Apps¤äSalesforceÅù¤ÎSaaS¥µ¡¼¥Ó¥¹¤Ë¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤òŬÍѤ¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

 

Secioss OTP¤Î¥À¥¦¥í¡¼¥É¤Ï¡¢¤³¤Á¤é¤«¤é¹Ô¤Ã¤Æ²¼¤µ¤¤¡£

 

Secioss OTP

 

 

¥½¥Õ¥È¥¦¥§¥¢

Secioss OTP¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó

¥é¥¤¥»¥ó¥¹¤¬GPL¤Î¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤Ç¤¹¡£°Ê²¼¤Î¥­¥ã¥ê¥¢¤Î·ÈÂÓÅÅÏäËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£

  • NTT¥É¥³¥â

  • au

  • Softbank

  • iPhone

  • Android

Secioss OTPǧ¾Ú¥µ¡¼¥Ð

°Ê²¼¤ÎOS¤Çưºî¤·¤Þ¤¹¡£

  • RedHat Enterprise Linux 5

  • CentOS 5  

RADIUS¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ò»ÈÍѤ¹¤ë¾ì¹ç¤Ï°Ê²¼¤Î´Ä¶­¤¬É¬Íפˤʤê¤Þ¤¹¡£

  • OS¡§ RedHat Enterprise Linux 5¡¢CentOS 5

  • RADIUS¥µ¡¼¥Ð¡§ FreeRadius 2

 

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹

Í­½þ¤Î¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤ò¹Ô¤Ã¤Æ¤ª¤ê¤Þ¤¹¡£

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤Î¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¤³¤Á¤é¤«¤é¤ªÌä¹ç¤»²¼¤µ¤¤¡£

ÆâÉôÅýÀ©Âкö¤ò¶¯²½¤·¤¿¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¹½Ãۻٱ祵¡¼¥Ó¥¹

ÆâÉôÅýÀ©Âкö¤Î¶¯²½¤¬µá¤á¤é¤ì¤Æ¤¤¤ëºòº£¡¢¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£¡¦¥¢¥¯¥»¥¹´ÉÍýÀ½ÉʤÇÇݤ俥Υ¦¥Ï¥¦¤ò³è¤«¤·¡¢Äã²Á³Ê¡¦Ã»´ü´Ö¤ÇÅý¹çǧ¾Ú¡¦LDAPÏ¢·È²Äǽ¤Ê¥°¥ë¡¼¥×¥¦¥§¥¢Aipo¡¢¶ÐÂÕ´ÉÍý¥·¥¹¥Æ¥àMosP¤Î´Ä¶­¹½ÃÛ¤ò¤¤¤¿¤·¤Þ¤¹¡£

ÆÃÄê¤ÎÉô½ð¤Ë½ê°¤¹¤ë¥æ¡¼¥¶¤È¤¤¤¦¤è¤¦¤Ë¡¢LDAPÏ¢·È¤ÎÂоݤ˾ò·ï¤òÀßÄꤹ¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¤Î¤Ç¡¢Éô½ðñ°Ì¤ÇƳÆþ¤·¤¿¥°¥ë¡¼¥×¥¦¥§¥¢¤ËÂФ·¤Æ¤âLDAP¤Ë¤è¤ë£É£ÄÅý¹ç´ÉÍý¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

Åý¹çǧ¾Ú¡¦LDAPÏ¢·Èµ¡Ç½¤òÁȤ߹þ¤ß²Äǽ¤Ê¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£

  • ¥°¥ë¡¼¥×¥¦¥§¥¢¡§ Aipo

  • ¶ÐÂÕ´ÉÍý¥·¥¹¥Æ¥à¡§ MosP

 

Aipo¡¢MosP°Ê³°¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ¹¤ëÅý¹çǧ¾Ú¡¢LDAPÏ¢·È¤ÎƳÆþ¤Ë¤Ä¤¤¤Æ¤â¸ÄÊ̤ËÂбþ¤¤¤¿¤·¤Þ¤¹¡£

 


Aipo4

ƳÆþ¤Ë¤è¤ë¥á¥ê¥Ã¥È

¥í¥°¥¤¥ó½èÍý¤ÎÏ«ÎϺ︺

¥æ¡¼¥¶¤ÏÅý¹çWindowsǧ¾Ú¤Ë¤è¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ø¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤Ë¤Ê¤ê¡¢WindowsüËö¤Ë¥í¥°¥ª¥ó¤¹¤ë¤À¤±¤ÇID¡¦¥Ñ¥¹¥ï¡¼¥ÉÆþÎϤʤ·¤Ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤¬ÍøÍѤǤ­¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê;·×¤Ê¥í¥°¥¤¥ó½èÍý¡¢¥Ñ¥¹¥ï¡¼¥É¤Î´ÉÍý¤ò¾Ê¤¯¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

ID´ÉÍý¤Î¸úΨ²½

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥æ¡¼¥¶¾ðÊó¤òLDAP¥µ¡¼¥Ð¤Î¾ðÊó¤ËÄê´üŪ¤ËƱ´ü¤µ¤»¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¥æ¡¼¥¶¾ðÊó¤Î´ÉÍý¤¬LDAP¤ËÅý¹ç¤µ¤ì°ÂÁ´À­¡¦ÍøÊØÀ­¤È¤â¤Ë¸þ¾å¤·¤Þ¤¹¡£¤µ¤é¤Ë¥ª¥×¥·¥ç¥ó¤Ç¾¤Î¥·¥¹¥Æ¥à¡Ê¿Í»ö¥·¥¹¥Æ¥àÅù¡Ë¤«¤é¤ÎƱ´ü¤â²Äǽ¤Ç¤¹¤Î¤Ç¤µ¤é¤Ê¤ë¸úΨ²½¤¬Ë¾¤á¤Þ¤¹¡£

¥»¥­¥å¥ê¥Æ¥£¶¯²½

¥æ¡¼¥¶¤Ï£±²ó¤Î¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¤Ç¡¢LDAP¤È¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ñ¥¹¥ï¡¼¥É¤òƱ»þ¤ËÊѹ¹¤Ç¤­¤Þ¤¹¡£¤Þ¤¿¡¢´ÉÍý¼Ô¤Ï¥Ñ¥¹¥ï¡¼¥É¤ÎŤµ¤ä»ÈÍÑʸ»ú¡¢Í­¸ú´ü¸Â¤Ê¤É¤Î¥Ñ¥¹¥ï¡¼¥É¥Ý¥ê¥·¡¼¤òÀßÄê¤Ç¤­¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¥Ñ¥¹¥ï¡¼¥É¤ÎÅðÍѤˤè¤ëÉÔÀµ¥¢¥¯¥»¥¹¤òÇÓ½ü¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

¥Ï¡¼¥É¥¦¥§¥¢¥³¥¹¥È¤Îºï¸º

Åý¹çǧ¾Úµ¡Ç½¡¦LDAPÏ¢·Èµ¡Ç½¤È¤â¤ËLinux¡¢Windows¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¤Î¤Ç¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÈƱ°ì¥µ¡¼¥Ð¤Ë¥¤¥ó¥¹¥È¡¼¥ë²Äǽ¤Ç¤¹¡£¤è¤Ã¤ÆÊÌÅÓ¥µ¡¼¥Ð¤òÍѰդ¹¤ëɬÍפ¬¤Ê¤¯¥Ï¡¼¥É¥¦¥§¥¢¥³¥¹¥È¤òºï¸º¤Ç¤­¤Þ¤¹¡£

Êä­

Åý¹çǧ¾Ú¤Ë¤Ï¡¢¥É¥á¥¤¥ó¥³¥ó¥È¥í¡¼¥é¤¬É¬Íפˤʤê¤Þ¤¹¤¬¡¢¥É¥á¥¤¥ó¥³¥ó¥È¥í¡¼¥é¤È¤·¤ÆActive Directory¡¢Samba¤ÎξÊý¤ËÂбþ¤¤¤¿¤·¤Þ¤¹¡£¤Þ¤¿¡¢¥ª¥×¥·¥ç¥ó¥µ¡¼¥Ó¥¹¤È¤·¤Æ¡¢¥É¥á¥¤¥ó¥³¥ó¥È¥í¡¼¥é¤Î¹½Ãۤ⾵¤ê¤Þ¤¹¡£

 

 


  • ËÜÊ¸Ãæ¤Ëµ­ºÜ¤µ¤ì¤Æ¤¤¤ëÀ½ÉÊ̾¤Ê¤É¤Î¸Çͭ̾»ì¤Ï¡¢³Æ¼Ò¤Î¾¦É¸¤Þ¤¿¤ÏÅÐÏ¿¾¦É¸¤Ç¤¹¡£

  • Windows/Active Directory¤ÏÊÆ¹ñMicrosoft Corporation¤ÎÊÆ¹ñ¤ª¤è¤Ó¤½¤Î¾¤Î¹ñ¤Ë¤ª¤±¤ëÅÐÏ¿¾¦É¸¤Ç¤¹¡£

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥Ý¡¼¥¿¥ë

ÊÀ¼Ò¤Ç¤Ï¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥½¥Õ¥È¥¦¥§¥¢Secioss Access Manager¤È¥ª¡¼¥×¥ó¥½¡¼¥¹¤ÎCMS¡ÊContents Management System¡Ë NetCommons¤òÁȤ߹ç¤ï¤»¤ë¤³¤È¤Ç¡¢´ë¶ÈÆâ¤ä³ØÆâ¤Î¥·¥¹¥Æ¥à¤Ø¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò²Äǽ¤È¤·¤¿¥Ý¡¼¥¿¥ë¥µ¥¤¥È¤ò¹½ÃÛ¤¤¤¿¤·¤Þ¤¹¡£

Secioss Access Manager¤Î¥á¥ê¥Ã¥È

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óµ¡Ç½¤ò¥Ý¡¼¥¿¥ë¤ËÁȤ߹þ¤à¤³¤È¤Ç¡¢¤è¤êÍøÊØÀ­¤Î¹â¤¤¥Ý¡¼¥¿¥ë¥µ¥¤¥È¤ò¼Â¸½¤·¤Þ¤¹¡£NetCommons¤Ë¥í¥°¥¤¥ó¤¹¤ì¤Ð¡¢¥æ¡¼¥¶¤Ï³Æ¥·¥¹¥Æ¥à¤Ë¥í¥°¥¤¥ó¤»¤º¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£¤µ¤é¤ËÅý¹çWindowsǧ¾Ú¤òÀßÄꤹ¤ì¤ÐWindows¤Î¥í¥°¥ª¥ó¤Î¤ß¤ÇNetCmmons¤Ø¤Î¥í¥°¥¤¥ó¤âɬÍפʤ¯¤Ê¤ê¤Þ¤¹¡£

¤Þ¤¿¡¢¥æ¡¼¥¶¤ËÂФ·¤Æ¤Î¥¢¥¯¥»¥¹À©¸æ¤â²Äǽ¤Ç¤¹¡£NetCommon¤Ë¤Ï¡¢¥æ¡¼¥¶¤¬µö²Ä¤µ¤ì¤¿¥·¥¹¥Æ¥à¤Î¥ê¥ó¥¯Àè¤Î¤ß¤¬É½¼¨¤µ¤ì¡¢µö²Ä¤µ¤ì¤¿¥·¥¹¥Æ¥à°Ê³°¤Ø¤Î¥¢¥¯¥»¥¹¤ÏµñÈݤµ¤ì¤Þ¤¹¡£

 

¥Ý¡¼¥¿¥ë²èÌÌ

¥Ý¡¼¥¿¥ë²èÌÌ

 

¤µ¤é¤Ë¡¢ÊÀ¼Ò¤ÎSecioss Identity Manager¤òƳÆþ¤¤¤¿¤À¤¯¤È¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤À¤±¤Ç¤Ï¤Ê¤¯¡¢³Æ¥·¥¹¥Æ¥à¤È¤ÎIDÏ¢·È¤â²Äǽ¤È¤Ê¤ê¡¢ID´ÉÍý¤Ë´Ø¤ï¤ë´ÉÍý¥³¥¹¥È¤òÂçÉý¤Ëºï¸º¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡£

 

ID´ÉÍý¡¡¥Ý¡¼¥¿¥ë

  ID´ÉÍý²èÌÌ

 

NetCommons¤È¤Ï

NetCommons¤Ï¡¢¹ñΩ¾ðÊ󳨏¦µæ½êNetCommons¥×¥í¥¸¥§¥¯¥È¤Ç³«È¯¤µ¤ì¤Æ¤¤¤ë¥ª¡¼¥×¥ó¥½¡¼¥¹¤ÎCMS¤Ç¤¹¡£
¢¨ NetCommons¤ÏÂç³Ø¶¦Æ±ÍøÍѵ¡´ØË¡¿Í¾ðÊ󡦥·¥¹¥Æ¥à¸¦µæµ¡¹½¤ÎÅÐÏ¿¾¦É¸¤Ç¤¹¡£

 

 

¥Ý¡¼¥¿¥ë

Secioss Identity Manager Enterprise

¶áǯ¡¢´ë¶È¤Ë¤ª¤±¤ëÆâÉôÅýÀ©¤Î½ÅÍ×À­¤¬Èó¾ï¤Ë¹â¤Þ¤Ã¤Æ¤ª¤ê¡¢¤½¤ì¤Ëȼ¤¤¡¢´ë¶ÈÆâ¤Î¥·¥¹¥Æ¥à¤ä¥Ç¡¼¥¿¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤òÀµ¤·¤¯´ÉÍý¤¹¤ë»ÅÁȤߤ¬É¬ÍפȤµ¤ì¤Æ¤¤¤Þ¤¹¡£¥¢¥¯¥»¥¹¤Î´ÉÍý¤Ë¤Ï¡¢¥¢¥¯¥»¥¹¤·¤Æ¤¤¤ëID¤¬ÍøÍѼÔËܿͤǤ¢¤ë¤³¤È¤òÊݾڤ¹¤ë¤È¤È¤â¤Ë¡¢ID¤Î´ÉÍý¤òŬÀڤ˹Ԥ¤¡¢¥·¥¹¥Æ¥à¤ä¥Ç¡¼¥¿¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¸¢¸Â¤ò¤­¤Á¤ó¤ÈÀßÄꤹ¤ë¤³¤È¤¬É¬ÍפȤʤê¤Þ¤¹¡£

 

¿Í»ö¥·¥¹¥Æ¥à¡¢¥×¥í¥¸¥§¥¯¥È´ÉÍý¥·¥¹¥Æ¥à¡¢¥Õ¥¡¥¤¥ë¶¦Í­¥µ¡¼¥ÐÅù¡¢ÍÍ¡¹¤Ê¥·¥¹¥Æ¥à¤¬º®ºß¤¹¤ë´ë¶È¤Ë¤ª¤¤¤Æ¤Ï¡¢¤³¤ì¤é¤ÎID¾ðÊó¤ä¥¢¥¯¥»¥¹¸¢¸Â¤òÅý¹çŪ¤Ë´ÉÍý¤¹¤ëID´ÉÍý¤Î»ÅÁȤߤ¬É¬Í×ÉԲķç¤Ç¤¹¡£

 

¥»¥·¥ª¥¹¤Ï¡¢OpenLDAP¡¢LISMÅù¤Î¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤ò³èÍѤ·¤¿Äã²Á³Ê¤ÊÅý¹çID´ÉÍý¥½¥ê¥å¡¼¥·¥ç¥ó¡ÖSecioss Identity Manager Enterprise¡×¤ò¤´Ä󶡤¤¤¿¤·¤Þ¤¹¡£

 

Secioss Identity Manager Enterprise¤Ï¥ª¡¼¥×¥ó¥½¡¼¥¹¤ò³èÍѤ¹¤ë¤³¤È¤Ç¡¢ ¥·¥ó¥×¥ë¤«¤Ä¥«¥¹¥¿¥Þ¥¤¥ºÀ­¤Î¹â¤¤Åý¹çID´ÉÍý¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤ò¼Â¸½¤¤¤¿¤·¤Þ¤¹¡£ ¤ªµÒÍͤÎÍ×˾¤Ë¹ç¤ï¤»¤Æ¡¢´ë¶È¥·¥¹¥Æ¥à¤Ø¤ÎƳÆþ¤ä¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ø¤ÎÁȤ߹þ¤ß¤Ë½ÀÆð¤ËÂбþ¤·¡¢¥»¥­¥å¥ê¥Æ¥£¤Î¶¯²½¤äID´ÉÍý¥³¥¹¥È¤Îºï¸º¤Ë¹×¸¥¤¤¤¿¤·¤Þ¤¹¡£

 

¥·¥¹¥Æ¥à¹½À®

system.JPG

 

 

Secioss Identity Manager Enterprise

¼ÒÆâ¤ÎÍÍ¡¹¤Ê¥·¥¹¥Æ¥à¤Ë»¶ºß¤¹¤ëID¡¢¤½¤·¤Æ¥¢¥¯¥»¥¹¸¢¸Â¡ÊÁÈ¿¥¡¢Ìò¿¦Åù¤Î¥°¥ë¡¼¥×¡Ë¤òÅý¹çŪ¤Ë´ÉÍý¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

ÆÃħ

  • ¼¡¤Î¥Ç¡¼¥¿³ÊǼ·Á¼°¤Î¥·¥¹¥Æ¥à´Ö¤Ç¥Ç¡¼¥¿Æ±´ü¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£
    ¡¡¡¦LDAP
    ¡¡¡¦Active Directory
    ¡¡¡¦RDB
    ¡¡¡¦CSV
    ¡¡¡¦Google Apps

  • Active Directory¤Î¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¤òÁ´¥·¥¹¥Æ¥à¤Ë¥ê¥¢¥ë¥¿¥¤¥à¤ÇƱ´ü¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£ 

  • HTTP¥×¥í¥È¥³¥ë·Ðͳ¤Ç¡¢Â¾µòÅÀ¤Î¥·¥¹¥Æ¥à¤È¥Ç¡¼¥¿Æ±´ü¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

  • ¥·¥¹¥Æ¥à´Ö¤Î¥Ç¡¼¥¿º¹Ê¬¤ò¥Á¥§¥Ã¥¯¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£
    ¡¡¡¡¤µ¤é¤Ëº¹Ê¬¥Ç¡¼¥¿¤òƱ´ü¤·¤Æ¥·¥¹¥Æ¥à´Ö¤Î¥Ç¡¼¥¿ÉÔÀ°¹ç¤ò²ò¾Ã¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

¸ú²Ì

  • Active Directory¡¢LDAP¥µ¡¼¥Ð¤ä¿Í»ö¥·¥¹¥Æ¥à¤Î¼Ò°÷¾ðÊó¤äÁÈ¿¥¡¢Ìò¿¦¤ËÂФ¹¤ë¹¹¿·¤òÁ´¥·¥¹¥Æ¥à¤Ø¼«Æ°Åª¤ËÈ¿±Ç¤·¤Þ¤¹¡£  

  • Secioss Identity Manager Enterprise¤ËÂФ·¤Æ¹¹¿·¤ò¹Ô¤¦¤À¤±¤Ç¡¢µòÅÀ¤Î°Û¤Ê¤ë¥·¥¹¥Æ¥à¤â´Þ¤á¡¢Á´¥·¥¹¥Æ¥à¤Î¾ðÊó¤ò¹¹¿·¤Ç¤­¤ë¤¿¤á¡¢¥·¥¹¥Æ¥à¿ô¤ËÈæÎ㤷¤Æ±¿ÍÑ´ÉÍý¥³¥¹¥È¤òºï¸º¤Ç¤­¤Þ¤¹¡£

  • Active Directory¤Î¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¤òÁ´¥·¥¹¥Æ¥à¤ËƱ´ü¤¹¤ë¤³¤È¤¬¤Ç¤­¤ë¤¿¤á¡¢¥æ¡¼¥¶¤Ï;·×¤Ê¥Ñ¥¹¥ï¡¼¥É¤ò´ÉÍý¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤»¤ó¡£

  • ID¾ðÊó¤Î´ÉÍýÉÔÈ÷¤Ë¤è¤Ã¤Æ¡¢Â࿦¼Ò°÷¤ÎID¤Î¤è¤¦¤Ê̤»ÈÍÑID¤¬ÊüÃÖ¤µ¤ì¡¢°­ÍѤµ¤ì¤ë¤³¤È¤òËɤ®¤Þ¤¹¡£

  • ¥Ç¡¼¥¿¤Îº¹Ê¬¤ò¥Á¥§¥Ã¥¯¤¹¤ë¤³¤È¤Ç¡¢ID¡¢¸¢¸Â¤Î´ÉÍý¥ß¥¹¤ò´Æºº¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

  • ID¾ðÊó¤Î¹¹¿·¤¬¿×®¤Ë¹Ô¤ï¤ì¤ë¤¿¤á¡¢”¤¤¤Ä¤Þ¤Ç¤¿¤Ã¤Æ¤â¥·¥¹¥Æ¥à¤¬»È¤¨¤Ê¤¤”¤È¤¤¤Ã¤¿¥æ¡¼¥¶¤ÎÉÔËþ¤ò²ò¾Ã¤·¤Þ¤¹¡£

 

 

ÂбþOS

  • Red Hat Enterprise Linux 5

  • CentOS 5

 

 

Âбþ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó

¼¡¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¤ÎÏ¢·È¤¬²Äǽ¤Ç¤¹¡£
¤½¤Î¾¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¤Ä¤¤¤Æ¤âÂбþ²Äǽ¤Ç¤¹¤Î¤Ç¡¢¤´ÁêÃ̲¼¤µ¤¤¡£

  • ¥°¥ë¡¼¥×¥¦¥§¥¢
    ¡¡¡¦Aipo4

  • ¶ÐÂÕ´ÉÍý
    ¡¡¡¦MosP

  • Saas¥µ¡¼¥Ó¥¹
    ¡¡¡¦Google Apps

  • ¥Ý¡¼¥¿¥ë
    ¡¡¡¦Liferay
    ¡¡¡¦XOOPS Cube

  • ECM¡Ê´ë¶È¸þ¤±¥³¥ó¥Æ¥ó¥Ä´ÉÍý¥·¥¹¥Æ¥à¡Ë
    ¡¡¡¦Alfresco

  • ¥Ö¥í¥°
    ¡¡¡¦MovableType

  • CRM
    ¡¡¡¦SugarCRM

 

 

²Á³Ê

¥½¥Õ¥È¥¦¥§¥¢

Secioss Identity Manager Enterprise¤Î¥µ¥Ö¥¹¥¯¥ê¥×¥·¥ç¥ó¥é¥¤¥»¥ó¥¹²Á³Ê¤Ï¡¢Ç¯´Ö300¥æ¡¼¥¶36Ëü±ß¤«¤é¤È¤Ê¤ê¤Þ¤¹¡£
¥é¥¤¥»¥ó¥¹²Á³Ê¤Î¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤³¤Á¤é¤Ë¤ªÌä¹ç¤»²¼¤µ¤¤¡£

 

¥µ¥Ý¡¼¥È

ǯ´Ö¤Î¥µ¥Ý¡¼¥ÈÎÁ¤Ï¡¢¥é¥¤¥»¥ó¥¹²Á³Ê¤Ë´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£ 

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤ÎÆâÍÆ¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£

  • À½ÉʤΥ¤¥ó¥¹¥È¡¼¥ëÊýË¡¡¢ÀßÄêÊýË¡¡¢µ¡Ç½¤Ë´Ø¤¹¤ë¥á¡¼¥ë¤Ë¤è¤ë¥Þ¥Ë¥å¥¢¥ë¥ì¥Ù¥ë¤ÎÌ䤤¹ç¤ï¤»Âбþ

  • ¥á¡¼¥ë¤Ç¤Î¥ª¥Õ¥µ¥¤¥È¾ã³²Ä´ºº 

  • À½ÉʤΥС¼¥¸¥ç¥ó¥¢¥Ã¥×ÈǤÎÄó¶¡

 

 

Ìä¹ç¤»

ËÜÀ½Éʤ˴ؤ¹¤ë¤ªÌä¹ç¤»¤Ï¤³¤Á¤é¤«¤é¤ª´ê¤¤¤·¤Þ¤¹¡£