Secioss Identity Suite Cloud Edition SP WindowsÈÇ

Secioss Identity Suite Cloud Edition¤Ï¡¢¥¯¥é¥¦¥É¥³¥ó¥Ô¥å¡¼¥Æ¥£¥ó¥°´Ä¶­¤Ë¤ª¤¤¤ÆSAML 2.0¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤äSOAPÄÌ¿®¤Ë¤è¤ë¥¢¥«¥¦¥ó¥ÈƱ´ü¤ò¥µ¥¤¥È´Ö¤Ç¼Â¸½¤¹¤ë¥½¥Õ¥È¥¦¥§¥¢¤Ç¤¹¡£

 

Secioss Identity Suite Cloud Edition¡Ê°Ê¹ßIdentity Suite Cloud¤È¤·¤Þ¤¹¡Ë¤ò¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƳÆþ¤¹¤ë¤³¤È¤Ç¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ°Ê²¼¤Îµ¡Ç½¤ò´Êñ¤ËÄɲ乤뤳¤È¤Ç¤­¤Þ¤¹¡£

 

¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó
SAML¤ÎService Provider¤È¤·¤ÆÆ°ºî¤·¡¢SAML¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¤¤Þ¤¹¡£¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÏIdentity Suite Cloud¤ÎÂåÍýǧ¾Úµ¡Ç½¤Ë¤è¤ê´Êñ¤ËSAMLǧ¾Úµ¡Ç½¤òÁȤ߹þ¤à¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

IDƱ´ü
¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎID´ÉÍýÍÑSOAP API¤òÄ󶡤·¡¢SOAP·Ðͳ¤Ç¤ÎID´ÉÍý¤ä¥µ¥¤¥È´Ö¤Ç¤ÎIDƱ´ü¤ò¼Â¸½¤·¤Þ¤¹¡£Identity Suite Cloud¤Ï¡¢Äê´üŪ¤ËSOAP API¤Ç¹¹¿·¥Ç¡¼¥¿¤ò¼èÆÀ¤·¡¢LISM¤Ë¤è¤ê¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤ØÈ¿±Ç¤·¤Þ¤¹¡£

 

¥ª¡¼¥×¥ó¥½¡¼¥¹¥×¥í¥¸¥§¥¯¥È

Identity Suite Cloud¤Ë¤Ä¤¤¤Æ¤Ï¡¢¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤È¤·¤ÆGPL¥é¥¤¥»¥ó¥¹¤Ë¤è¤ê¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£
¡¦¥×¥í¥¸¥§¥¯¥È¥µ¥¤¥È¡§http://sourceforge.jp/projects/secioss-auth/
¡¦¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¡§http://lists.sourceforge.jp/mailman/listinfo/secioss-auth-users

 

 

1. ¥¤¥ó¥¹¥È¡¼¥ë

Identity Suite Cloud SP¤òWindows´Ä¶­¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ëÊýË¡¤Ë¤Ä¤¤¤Æ¡¢²òÀ⤷¤Þ¤¹¡£
Identity Suite Cloud SP¤Î¿ä¾©´Ä¶­¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£
¡¦OS¡§ Windows Server 2003°Ê¹ß
¡¦Web¥µ¡¼¥Ð¡§  IIS 6°Ê¹ß

 

º£²ó¤Î¥¤¥ó¥¹¥È¡¼¥ë´Ä¶­¤È¤·¤Æ¤Ï¡¢Windows Server 2008¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£
¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Îǧ¾Ú¥µ¡¼¥Ð¡¢Åý¹çID´ÉÍý¥µ¡¼¥Ð¤Ï¡¢ÊÀ¼ÒSaaS¥µ¡¼¥Ó¥¹SeciossLink¤òÁÛÄꤷ¤Æ¤¤¤Þ¤¹¡£  

 

1.1 ActivePerl¤Î¥¤¥ó¥¹¥È¡¼¥ë

ActivePerl¤òhttp://www.activestate.com/activeperl/downloads/¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¡¢¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£ ¤Þ¤¿¡¢¹ç¤ï¤»¤ÆIIS¤ÇPerl¤ÎCGI¤¬»ÈÍѤǤ­¤ë¤è¤¦¤ËÀßÄꤷ¤Æ¤ª¤¤¤Æ²¼¤µ¤¤¡£

¼¡¤Ë¡¢°Ê²¼¤ÎPerl¥â¥¸¥å¡¼¥ë¤ò¥³¥Þ¥ó¥É¥×¥í¥ó¥×¥È¤«¤é¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£

Config-General¡¢Config-IniFiles¡¢Log-Dispatch¡¢Log-Dispatch-FileRotate¡¢Class-Inspector¡¢DBD-mysql
¡¡ppm install <¥Ñ¥Ã¥±¡¼¥¸Ì¾

 

1.2 PHP¤Î¥¤¥ó¥¹¥È¡¼¥ë

http://www.php.net/downloads.php¤«¤éPHP¤ÎWindows binary zip¥Õ¥¡¥¤¥ë¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¡¢¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£

PHP¤ÎExtension¤È¤·¤Æ¡¢°Ê²¼¤Î¥â¥¸¥å¡¼¥ë¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£
¡¦ php_openssl.dll

 

1.3 Secioss Identity Suite Cloud Edition SP

secioss-idsuite-cloud-sp-win-3.x.x.zip¤òŸ³«¤·¤Æ¡¢opt¥Õ¥©¥ë¥À¤òC:\opt¤È¤·¤ÆÇÛÃÖ¤·¤Þ¤¹¡£

¼¡¤ËC:\opt¤Î[¥×¥í¥Ñ¥Æ¥£]->[¥»¥­¥å¥ê¥Æ¥£]¤«¤é¡¢IUSR¡ÊWindows 2003 Server¤Ç¤ÏIUSR_<¥Þ¥·¥ó̾>¡Ë¡¢Users¤ËÂФ·¤Æ¥¢¥¯¥»¥¹µö²Ä¤òÍ¿¤¨¤Þ¤¹¡£

¤µ¤é¤Ë¡¢°Ê²¼¤Î¥Õ¥©¥ë¥À¤Ë¤ÏIUSR¡¢Users¤ËÂФ·¤Æ¥Õ¥ë¥³¥ó¥È¥í¡¼¥ë¤Î¥¢¥¯¥»¥¹µö²Ä¤òÍ¿¤¨¤Þ¤¹¡£
¡¦ C:\opt\secioss\share\simplesamlphp\log
¡¦ C:\opt\secioss\var\log 

 

1.4 IIS¥Þ¥Í¡¼¥¸¥ã¤ÎÀßÄê

»ÈÍѤ¹¤ë¥½¥Õ¥È¥¦¥§¥¢¤Ë¤Ä¤¤¤Æ°Ê²¼¤Î¤è¤¦¤Ë²¾Áۥǥ£¥ì¥¯¥È¥ê¤òÀßÄꤷ¤Þ¤¹¡£
¡¡SAML ¥¨¥¤¥ê¥¢¥¹¡§<¥¢¥×¥ê¥±¡¼¥·¥ç¥óURL¤Î¥Ñ¥¹>/saml¡¡¥Ñ¥¹¡§C:\opt\secioss\share\simplesamlphp\www
¡¡ÂåÍýǧ¾Ú ¥¨¥¤¥ê¥¢¥¹¡§ <¥¢¥×¥ê¥±¡¼¥·¥ç¥óURL¤Î¥Ñ¥¹>/sso¡¡¥Ñ¥¹¡§ C:\opt\secioss\var\www\sso
¢¨ ¥¢¥×¥ê¥±¡¼¥·¥ç¥óURL¤Î¥Ñ¥¹¤Ï¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¤Î¤¦¤Á¤Î¥Ñ¥¹Éôʬ¤Ç¤¹¡£
¡¡ Îã¡§ URL: https://sp.example.com/SugarCE/index.php ¥Ñ¥¹: /SugarCE

 

 

 

2. ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó

2.1 SAMLǧ¾Ú¤ÎÀßÄê 

"C:\opt\secioss\share\simplesamlphp\config\config.php"¤Î'baseurlpath'¤òIIS¤ÇÀßÄꤷ¤¿SAML¤Î¥¨¥¤¥ê¥¢¥¹¤Ë¡¢ 'default-saml20-idp'¤ò"<ǧ¾Ú¥µ¡¼¥Ð¤ÎURL>/<¥Æ¥Ê¥ó¥ÈID>"¡ÊÎã¡§ https://slink.secioss.com/secioss.co.jp¡Ë¤Ë¡¢SESSIONNAME¤ò¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥»¥Ã¥·¥ç¥ó¥¯¥Ã¥­¡¼Ì¾¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£

 

"C:\opt\secioss\share\simplesamlphp\metadata\saml20-idp-remote.php"¤Î'SingleSignOnService'¡¢'SingleLogoutService'¤Î¥Û¥¹¥È̾¤òǧ¾Ú¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾¤Ë¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£

¤Þ¤¿¡¢°Ê²¼¤ÎÃͤò"<ǧ¾Ú¥µ¡¼¥Ð¤ÎURL>/<¥Æ¥Ê¥ó¥ÈID>"¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£


        'https://slink.secioss.com' =>  array(


 

¼¡¤Ë¡¢"C:\opt\secioss\share\simplesamlphp\metadata\saml20-sp-hosted.php"¤Î"https://sp.example.com/path"¤ò¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¹Ô¤¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¡ÊURL¤Ï¥Ñ¥¹¤Þ¤Ç¤È¤·¤Æ¡¢¥Õ¥¡¥¤¥ë̾¤ÎÉôʬ¤Ï´Þ¤á¤Ê¤¤¤Ç²¼¤µ¤¤¡Ë¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£

¼¡¤Ë¡¢Ç§¾Ú¥µ¡¼¥Ð¤Î¸ø³«¸°"<ǧ¾Ú¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾>/public/PublicKey-idp.pem"¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¡¢°Ê²¼¤Î¾ì½ê¤Ë"C:\opt\secioss\share\simplesamlphp\cert"¤ËÃÖ¤¤¤Æ²¼¤µ¤¤¡£

 

¼¡¤ËSAMLǧ¾ÚÍѤÎÈëÌ©¸°¤È¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
°Ê²¼¤ÏLinux¾å¤ÇOpenSSL¤Ë¤è¤ëÈëÌ©¸°¤È¸ø³«¸°¤ÎºîÀ®¼ê½ç¤Ç¤¹¡£
­¡ ÈëÌ©¸°¤òºîÀ®¤·¤Þ¤¹¡£
# cd /etc/pki/tls/certs
# make test.key
ÈëÌ©¸°¤«¤é¥Ñ¥¹¥ï¡¼¥É¤òºï½ü¤·¤Þ¤¹¡£
# openssl rsa -in test.key -out test.key

­¢ ¸ø³«¸°¤òºîÀ®¤·¤Þ¤¹¡£
# make test.crt
Country Name (2 letter code) [GB]:JP¡¡←¡¡¹ñ̾
State or Province Name (full name) [Berkshire]:Tokyo¡¡←¡¡ÅÔÆ»Éܸ©Ì¾
Locality Name (eg, city) [Newbury]:Bunkyo¡¡←¡¡»Ô¶èĮ¼̾
Organization Name (eg, company) [My Company Ltd]:TEST, Inc¡¡←¡¡²ñ¼Ò̾
Organizational Unit Name (eg, section) []:¡¡←¡¡¶õENTER
Common Name (eg, your name or your server's hostname) []:sp.test.co.jp¡¡←¡¡¥Û¥¹¥È̾
Email Address []:admin@test.co.jp¡¡←¡¡´ÉÍý¼Ô¥á¡¼¥ë¥¢¥É¥ì¥¹

 

ÈëÌ©¸°¤Ï¡¢"C:\opt\secioss\share\simplesamlphp\cert\PrivateKey.pem"¤Ë¥³¥Ô¡¼¤·¤Æ²¼¤µ¤¤¡£

 

2.2 ÂåÍýǧ¾Ú¤ÎÀßÄê

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¼«Æ°¤Ç¥í¥°¥¤¥ó¤¹¤ë¤¿¤á¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£

ÀßÄê¥Õ¥¡¥¤¥ë¤Ï¡¢"C:\opt\secioss\var\www\conf\<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾¡ÊÁ´¤Æ¾®Ê¸»ú¡Ë>.ini"¤È¤·¤ÆºîÀ®¤·¤Æ²¼¤µ¤¤¡£
°Ê²¼¤ÏSugarCRMÍѤÎÀßÄêÎã¤Ç¤¹¡£


[url]
login = "https://sp.example.com/SugarCE/index.php?action=Login&module=Users"
back = "/SugarCE/"

 

[postName]
username = user_name
password = user_password

 

[postData]
module = Users
action = Authenticate
return_module = Users
return_action = Login
cant_login = ""
login_module = ""
login_action = ""
login_record = ""
login_theme = Sugar
login_language = ja
login_button = "  ¥í¥°¥¤¥ó  "


 

url

login

¥í¥°¥¤¥ó¤¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL

back

¥í¥°¥¤¥ó¸å¤Ëɽ¼¨¤¹¤ë²èÌ̤ÎURL

postName

username

¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥æ¡¼¥¶Ì¾¤ÎÊÑ¿ô̾

password

¥í¥°¥¤¥ó»þ¤ËPOST¤¹¤ë¥Ñ¥¹¥ï¡¼¥É¤ÎÊÑ¿ô̾

 

[postData]¤Ë¤Ï¡¢POST¤¹¤ë¥Ç¡¼¥¿¤ÎÊÑ¿ô̾¤ÈÃͤÎÁȤ߹ç¤ï¤»¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£   

 

 

2.3 Ç§¾Ú¥µ¡¼¥Ð¤ÎÀßÄê

https://<ǧ¾Ú¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾>/tenantadmin/¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Ç¥í¥°¥¤¥ó¤·¤Þ¤¹¡£
²èÌ̾åÉô¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò¥¯¥ê¥Ã¥¯¤·¤«¤é¡¢º¸Â¦¥á¥Ë¥å¡¼¤Î”SAML ¥µ¡¼¥Ó¥¹¥×¥í¥Ð¥¤¥À”¤ò¥¯¥ê¥Ã¥¯¤·¤Æ²¼¤µ¤¤¡£
”¿·µ¬ÅÐÏ¿”¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢SP¤ÎÀßÄê¤òÅÐÏ¿¤·¤Þ¤¹¡£
¡¦¥µ¡¼¥Ó¥¹¡§¡¡¥µ¡¼¥Ó¥¹ID¤òÁªÂò¤·¤Æ²¼¤µ¤¤¡£
¡¦¥µ¡¼¥Ó¥¹Ì¾¡§¡¡SP¤Î¥µ¡¼¥Ó¥¹Ì¾¡ÊǤ°Õ¤ÎÃ͡ˤòÀßÄꤷ¤Æ²¼¤µ¤¤¡£
¡¦URL¡§¡¡2.1¹à¤ÇÀßÄꤷ¤¿¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£
¡¦¥æ¡¼¥¶ID¤Î°À­¡§¡¡SP¤ËÅϤ¹¥æ¡¼¥¶ID¤Î°À­¤òÁªÂò¤·¤Æ²¼¤µ¤¤¡£
¡¦°Å¹æ²½ÍѸø³«¸°¡§¡¡2.1¹à¤ÇºîÀ®¤·¤¿¸ø³«¸°¤òÅÐÏ¿¤·¤Æ²¼¤µ¤¤¡£

 

SPÅÐÏ¿

 

 

3. IDƱ´ü

3.1  IDƱ´ü¤ÎÀßÄê

Identity Suite Cloud¤Ï¡¢LISM¤Ë¤è¤Ã¤ÆÄê´üŪ¤ËÅý¹çID´ÉÍý¥µ¡¼¥Ð¤«¤é¹¹¿·¥Ç¡¼¥¿¤ò¼èÆÀ¤·¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤äLDAP¤Î¥¢¥«¥¦¥ó¥È¤ò¹¹¿·¤·¤Þ¤¹¡£

 

ºÇ½é¤Ë¡¢"C:\opt\secioss\etc\lism-sp.conf¤Î°Ê²¼¤ÎÃͤò´Ä¶­¤Ë¹ç¤ï¤»¤ÆÊѹ¹¤·¤Æ²¼¤µ¤¤¡£
¡¦slink.secioss.com¡§ Åý¹çID´ÉÍý¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾
¡¦TENANTID¡§¡¡¥Æ¥Ê¥ó¥ÈID
¡¦SERVICEID¡§¡¡2.3¹à¤Î¥µ¡¼¥Ó¥¹ID¡Ê¥Æ¥Ê¥ó¥ÈID¤Ï½ü¤¯¡Ë
¡¦ADMINID¡§¡¡Åý¹çID´ÉÍý¥µ¡¼¥Ð¤ËÀܳ¤¹¤ë´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È̾
¡¦ADMINPW¡§¡¡´ÉÍý¼Ô¥¢¥«¥¦¥ó¥È¤Î¥Ñ¥¹¥ï¡¼¥É
¤Þ¤¿¡¢IDƱ´üÂоݤΥ¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥æ¡¼¥¶ID¤Ë»ÈÍѤ¹¤ë°À­¤Ë¹ç¤ï¤»¤Æ¡¢°Ê²¼¤ÎÊѹ¹¤ò¹Ô¤Ã¤Æ²¼¤µ¤¤¡£
¡¦¥æ¡¼¥¶ID¡§ "<!-- id ... -->"¤Î¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤·¤Æ¤¯¤À¤µ¤¤¡£
¡¦¥æ¡¼¥¶ID@¥Æ¥Ê¥ó¥ÈID¡§ Êѹ¹¤¹¤ëɬÍפϤ¢¤ê¤Þ¤»¤ó¡£
¡¦¥á¡¼¥ë¥¢¥É¥ì¥¹¡§ "<!-- attribute ... -->"¤Î¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤·¤Æ¡¢ATTRIBUTE¤òmail¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£
¡¦¼Ò°÷Èֹ桧 "<!-- attribute ... -->"¤Î¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤·¤Æ¡¢ATTRIBUTE¤òemployeeNumber¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£
¡¦¥µ¡¼¥Ó¥¹¸ÄÊÌ¤Î¥í¥°¥¤¥óID¡§ "<!-- attribute ... -->"¤Î¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤·¤Æ¡¢ATTRIBUTE¤òseciossLoginId;x-sys-<¥µ¡¼¥Ó¥¹ID>@<¥Æ¥Ê¥ó¥ÈID>

 

LISM¤ÎÀßÄê¥Õ¥¡¥¤¥ë/opt/secioss/etc/lism.conf¤Ë¡¢¹¹¿·ÂоݤΥǡ¼¥¿¥Ù¡¼¥¹¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£
LISM¤ÎÀßÄêÊýË¡¤Ë¤Ä¤¤¤Æ¤Ï¡¢LISM¤Î¥µ¥¤¥È¤ò¤´Í÷²¼¤µ¤¤¡£  

SugarCRM¤òÎã¤È¤·¤ÆLISM¤ÎÀßÄê¤òÎ㼨¤·¤Þ¤¹¡£ 

 

lism.conf


<config>
  <sync>
    <data name="SP">
      <object name="User">
        <syncdn>ou=People</syncdn>
        <syncfilter>(&amp;(!(seciossAccountStatus=deleted))(&amp;(objectClass=inetOrgPerson)(|(seciossAllowedService=sugarcrm-secioss.co.jp)(seciossAllowedService;x-perm-group=sugarcrm-secioss.co.jp))))</syncfilter>
        <syncattr>
          <name>sn</name>
        </syncattr>
        <syncattr>
          <name>givenName</name>
        </syncattr>
        <syncattr>
          <name>sn;lang-ja;phonetic</name>
        </syncattr>
        <syncattr>
          <name>givenName;lang-ja;phonetic</name>
        </syncattr>
      </object>
    </data>
  </sync>
  <data name="SP">
    <container>
      <oc>organizationalUnit</oc>
      <rdn>o=SP</rdn>
    </container>
    <handler name="Rewrite">
      <rewrite context="request" match="createtimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="createtimestamp: %1-%2-%3 %4:%5:%6"/>
      <rewrite context="searchResult" match="createtimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="createtimestamp: %1%2%3%4%5%6Z"/>
      <rewrite context="request" match="modifytimestamp: *([0-9]{4})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})([0-9]{2})Z" substitution="modifytimestamp: %1-%2-%3 %4:%5:%6"/>
      <rewrite context="searchResult" match="modifytimestamp: *([0-9]{4})-([0-9]{2})-([0-9]{2}) ([0-9]{2}):([0-9]{2}):([0-9]{2})" substitution="modifytimestamp: %1%2%3%4%5%6Z"/>
    </handler>
    <storage name="SQL" hash="MD5:hex">
      <libload>LISM/Utils/lism_util.pl</libload>
      <libload>LISM/Utils/lism_sugarcrm.pl</libload>
      <dsn>DBI:mysql:sugarcrm:localhost</dsn>
      <admin>admin</admin>
      <passwd>secret</passwd>
      <initquery>set names utf8</initquery>
      <noop>delete</noop>
      <object name="User">
        <container>
          <rdn>ou=People</rdn>
          <oc>organizationalUnit</oc>
        </container>
        <table>users</table>
        <id>
          <column>id</column>
        </id>
        <oc>Person</oc>
        <oc>inetOrgPerson</oc>
        <oc>seciossIamAccount</oc>
        <rdn>uid</rdn>
        <attr name="uid">
          <column>user_name</column>
        </attr>
        <attr name="cn">
          <selexpr>ifnull(concat(last_name, ' ', first_name), last_name)</selexpr>
        </attr>
        <attr name="sn">
          <column>last_name</column>
        </attr>
        <attr name="givenname">
          <column>first_name</column>
        </attr>
        <attr name="title">
          <column>title</column>
        </attr>
        <attr name="department">
          <column>department</column>
        </attr>
        <attr name="userpassword">
          <column>user_hash</column>
        </attr>
        <attr name="homephone">
          <column>phone_home</column>
        </attr>
        <attr name="telephonenumber">
          <column>phone_work</column>
        </attr>
        <attr name="mobile">
          <column>phone_mobile</column>
        </attr>
        <attr name="facsimiletelephonenumber">
          <column>phone_fax</column>
        </attr>
        <attr name="ipphone">
          <column>phone_other</column>
        </attr>
        <attr name="street">
          <column>address_street</column>
        </attr>
        <attr name="l">
          <column>address_city</column>
        </attr>
        <attr name="st">
          <column>address_state</column>
        </attr>
        <attr name="c">
          <column>address_country</column>
        </attr>
        <attr name="postalcode">
          <column>address_postalcode</column>
        </attr>
        <attr name="createtimestamp">
          <column>date_entered</column>
        </attr>
        <attr name="modifytimestamp">
          <column>date_modified</column>
        </attr>
        <attr name="description">
          <column>description</column>
        </attr>
        <strginfo>
          <column>id</column>
          <value type="function">createGuid()</value>
        </strginfo>
        <strginfo>
          <column>status</column>
          <value type="constant">Active</value>
          <delproc>update users set status = 'Inactive' where id = '%o'</delproc>
        </strginfo>
      </object>
    </storage>
  </data>
</config>


 

¼¡¤Ë¡¢"C:\opt\secioss\var\www\cgi-bin\lismapi.conf"¤ÎADMINID¡¢ADMINPW¤ò¤½¤ì¤¾¤ì´ÉÍý¼Ô¤Î¥¢¥«¥¦¥ó¥È̾¡¢¥Ñ¥¹¥ï¡¼¥É¤ËÊѹ¹¤·¤Æ²¼¤µ¤¤¡£

 

 

4. ưºî³Îǧ

4.1 IDƱ´ü¤Î³Îǧ

SeciossLink¤«¤éID¤Î¹¹¿·¥Ç¡¼¥¿¤ò¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËƱ´ü¤·¤Þ¤¹¡£
¡¡# perl C:\opt\secioss\sbin\idsync sp

 

¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ¹¤ë¥Ç¡¼¥¿¤Î¹¹¿·¤Ï¹Ô¤ï¤º¤Ë¡¢¹¹¿·¥Ç¡¼¥¿¤Î³Îǧ¤Î¤ß¤·¤¿¤¤¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ¡¢"C:\opt\secioss\var\lib\csv\user.csv"¤ÎÆâÍÆ¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£
¡¡# perl C:\opt\secioss\sbin\idsync -n sp

 

¤Þ¤¿¡¢º¹Ê¬¥Ç¡¼¥¿¤Î¥Á¥§¥Ã¥¯¤Î¤ß¹Ô¤¦¾ì¹ç¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
¡¡# perl C:\opt\secioss\sbin\idsync -r sp

 

Àµ¾ï¤Ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤ÆID¤ÎƱ´ü¤¬¹Ô¤¨¤ë¤³¤È¤ò³Îǧ¤Ç¤­¤¿¤é¡¢¥¿¥¹¥¯¤Ë1»þ´Ö¤Ë1²ó "perl C:\opt\secioss\sbin\idsync sp"¤ò¼Â¹Ô¤¹¤ë¤è¤¦¤ËÀßÄꤷ¤Æ²¼¤µ¤¤¡£

 

4.2 ¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Î³Îǧ

"<¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎURL>/sso/autologin.php?sso_app=<2.2¹à¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó̾>"¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¹¤ë¤³¤È¤ò³Îǧ¤·¤Æ²¼¤µ¤¤¡£

¥ª¡¼¥×¥ó¥½¡¼¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¡ÖSecioss Access Manager Community Edition¡×

¶áǯ¡¢´ë¶È¤Ë¤ª¤±¤ëÆâÉôÅýÀ©¤Î½ÅÍ×À­¤¬Èó¾ï¤Ë¹â¤Þ¤Ã¤Æ¤ª¤ê¡¢¤½¤ì¤Ëȼ¤¤¡¢´ë¶ÈÆâ¤Î¥·¥¹¥Æ¥à¤ä¥Ç¡¼¥¿¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤òÀµ¤·¤¯´ÉÍý¤¹¤ë»ÅÁȤߤ¬É¬ÍפȤµ¤ì¤Æ¤¤¤Þ¤¹¡£¥¢¥¯¥»¥¹¤Î´ÉÍý¤Ë¤Ï¡¢¥¢¥¯¥»¥¹¤·¤Æ¤¤¤ëID¤¬ÍøÍѼÔËܿͤǤ¢¤ë¤³¤È¤òÊݾڤ¹¤ë¤È¤È¤â¤Ë¡¢¥·¥¹¥Æ¥à¤ä¥Ç¡¼¥¿¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¸¢¸Â¤ò¤­¤Á¤ó¤ÈÀßÄꤹ¤ë¤³¤È¤¬É¬ÍפȤʤê¤Þ¤¹¡£

 

¥»¥·¥ª¥¹¤Ç¤Ï¡¢OpenLDAP¡¢Shibboleth¡¢mod_auth_tktÅù¤Î¥ª¡¼¥×¥ó¥½¡¼¥¹¥½¥Õ¥È¥¦¥§¥¢¤ò³èÍѤ·¤¿¥ª¡¼¥×¥ó¥½¡¼¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥½¥ê¥å¡¼¥·¥ç¥ó¡ÖSecioss Access Manager Community Edition¡×¤ò¤´Ä󶡤¤¤¿¤·¤Þ¤¹¡£

Secioss Access Manager Community Edition¤Ï¡¢GPL¤È¾¦Íѥ饤¥»¥ó¥¹¤Î¥Ç¥å¥¢¥ë¥é¥¤¥»¥ó¥¹¡ÊShibbolethÅù¼ýÏ¿¤·¤Æ¤¤¤ë¥½¥Õ¥È¥¦¥§¥¢¤Î¥é¥¤¥»¥ó¥¹¤Ï¤½¤ì¤¾¤ì¤Î¤â¤Î¤Ë½àµò¤·¤Þ¤¹¡Ë¤Ç¡¢°Ê²¼¤«¤é¥À¥¦¥ó¥í¡¼¥É¤Ç¤­¤Þ¤¹¡£
¡¦¥À¥¦¥ó¥í¡¼¥É¡§ http://sourceforge.jp/projects/secioss-auth/releases/

 

¥¯¥¤¥Ã¥¯¥¹¥¿¡¼¥È¥¬¥¤¥É¤ò¤´Í÷ĺ¤¯¤È¡¢´Êñ¤ËGoogle Apps¤ÈSalesforce¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ò´Ä¶­¤ò¹½ÃÛ¤¤¤¿¤À¤±¤Þ¤¹¡£

 

¥ª¡¼¥×¥ó¥½¡¼¥¹¤ò³èÍѤ¹¤ë¤³¤È¤Ç¡¢ ¥·¥ó¥×¥ë¤«¤Ä¥«¥¹¥¿¥Þ¥¤¥ºÀ­¤Î¹â¤¤¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¥×¥é¥Ã¥È¥Õ¥©¡¼¥à¤ò¼Â¸½¤¤¤¿¤·¤Þ¤¹¡£ ¤ªµÒÍͤÎÍ×˾¤Ë¹ç¤ï¤»¤Æ¡¢´ë¶È¥·¥¹¥Æ¥à¤Ø¤ÎƳÆþ¤ä¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ø¤ÎÁȤ߹þ¤ß¤Ë½ÀÆð¤ËÂбþ¤·¡¢¥»¥­¥å¥ê¥Æ¥£¤Î¶¯²½¤ä¥æ¡¼¥¶¤ÎÍøÊØÀ­¸þ¾å¤Ë¹×¸¥¤¤¤¿¤·¤Þ¤¹¡£

 

¤µ¤é¤Ë¡¢ÊÀ¼Ò¤ÎÅý¹çID´ÉÍý¥½¥ê¥å¡¼¥·¥ç¥ó¡ÖSecioss Identity Manager¡×¤ÈÁȤ߹ç¤ï¤»¤Æ¤¤¤¿¤À¤¯¤³¤È¤Ç¡¢ID¤ä¥¢¥¯¥»¥¹¸¢¸Â¤Î°ì¸µ´ÉÍý¤¬²Äǽ¤È¤Ê¤ê¡¢¤è¤ê¶¯¸Ç¤Ê¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó´Ä¶­¤ò¹½ÃÛ¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

 

¥·¥¹¥Æ¥à¹½À®

system.JPG

 

 

Secioss Access Manager Community Edition

¼ÒÆâ¤Î¥·¥¹¥Æ¥à¤ËÂФ¹¤ëWeb¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤È¥°¥ë¡¼¥×¤Ë¤è¤ë¥¢¥¯¥»¥¹À©¸æ¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£Web¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ç¤Ï¡¢¥·¥¹¥Æ¥à¤Ë¥í¥°¥¤¥ó½èÍý¤¬É¬Íפʾì¹ç¤Ç¤â¡¢ÂåÍýǧ¾Úµ¡Ç½¤Ë¤è¤Ã¤ÆSecioss Access Manager Community Edition¤¬¼«Æ°Åª¤Ë¥í¥°¥¤¥ó¤ò¹Ô¤¤¤Þ¤¹¡£¤Þ¤¿¡¢Åý¹çWindowsǧ¾Úµ¡Ç½¤ò»ÈÍѤ¹¤ë¤³¤È¤Ç¡¢Windows¤Î¥í¥°¥¤¥ó¤È¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤òÏ¢·È¤µ¤»¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

ÆÃħ

  • Secioss Access Manager Community Edition¤Ø¥í¥°¥¤¥ó¤¹¤ë¤À¤±¤Ç¡¢³Æ¥·¥¹¥Æ¥à¤Ø¤Î¥¢¥¯¥»¥¹¤¬²Äǽ¤Ç¤¹¡£

  • ¥ê¥Ð¡¼¥¹¥×¥í¥­¥·Êý¼°¡¢¥¨¡¼¥¸¥§¥ó¥ÈÊý¼°¤Ë²Ã¤¨¤Æ¡¢Shibboleth¡¢SAML¤äOpenID¤Ë¤è¤ë¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£ 

  • ID¡¦¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤Î¾¤ËÅý¹çWindowsǧ¾Ú¡¢¥¯¥é¥¤¥¢¥ó¥È¾ÚÌÀ½ñ¡¢¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¡¢·ÈÂÓÅÅÏäθÄÂμ±ÊÌÈÖ¹æÇ§¾Ú¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¡£

  • Åý¹çWindowsǧ¾Ú¤Ë¤è¤êWindows¥Þ¥·¥ó¤Ë¥í¥°¥¤¥ó¤¹¤ë¤À¤±¤Ç¡¢¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤¬²Äǽ¤È¤Ê¤ê¤Þ¤¹¡£

  • ·ÈÂÓÅÅÏ䫤饷¥¹¥Æ¥à¤Ø¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥ó¤Ë¤âÂбþ¤·¤Æ¤¤¤Þ¤¹¡£

  • ¥·¥¹¥Æ¥à¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤ò¡¢ÆÃÄê¤Î¥°¥ë¡¼¥×¤Ë½ê°¤¹¤ë¥æ¡¼¥¶¤ËÀ©¸Â¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

 

¸ú²Ì

  • ¥·¥¹¥Æ¥à¤Ø¥í¥°¥¤¥ó¤¹¤ë¼ê´Ö¤ò¾Ê¤¯¤³¤È¤Ç¡¢¥æ¡¼¥¶¤ÎÀ¸»ºÀ­¤¬¸þ¾å¤·¤Þ¤¹¡£

  • ¥æ¡¼¥¶¤Ï¥Ñ¥¹¥ï¡¼¥É¤ò£±¤Ä´ÉÍý¤¹¤ì¤Ð¤è¤¯¡¢¥Ñ¥¹¥ï¡¼¥É˺¤ì¤Ë¤è¤ë¥Ñ¥¹¥ï¡¼¥É¤ÎºÆÈ¯¹Ô¤òºï¸º¤Ç¤­¤Þ¤¹¡£

  • ǧ¾Ú¤ä¥¢¥¯¥»¥¹À©¸æ¤ò°ì¸µÅª¤Ë´ÉÍý¤·¡¢¼ÒÆâ¥·¥¹¥Æ¥à¤ËÅý°ìŪ¤Ê¥»¥­¥å¥ê¥Æ¥£¥Ý¥ê¥·¡¼¤òŬÍѤǤ­¤Þ¤¹¡£

 

 

ÂбþOS

  • Red Hat Enterprise Linux 5

  • CentOS 5

 

 

Âбþ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó

¼¡¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¤ÎÏ¢·È¤¬²Äǽ¤Ç¤¹¡£
¤½¤Î¾¤ÎWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¤Ä¤¤¤Æ¤âÂбþ²Äǽ¤Ç¤¹¤Î¤Ç¡¢¤´ÁêÃ̲¼¤µ¤¤¡£

  • ¥°¥ë¡¼¥×¥¦¥§¥¢
    ¡¡¡¦Aipo
    ¡¡¡¦¥µ¥¤¥Ü¥¦¥º¥¬¥ë¡¼¥ó£²

  • ¶ÐÂÕ´ÉÍý
    ¡¡¡¦MosP

  • SaaS¥µ¡¼¥Ó¥¹
    ¡¡¡¦Salesforce
    ¡¡¡¦Google Apps

  • ¥Ý¡¼¥¿¥ë
    ¡¡¡¦NetCommons
    ¡¡¡¦XOOPS Cube

  • ¥Ö¥í¥°
    ¡¡¡¦MovableType

  • CRM
    ¡¡¡¦SugarCRM

  • ¥¢¥ó¥±¡¼¥È¥·¥¹¥Æ¥à
    ¡¡¡¦LimeSurvey

 

 

¥µ¥Ý¡¼¥È

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤òÄ󶡤·¤Æ¤¤¤Þ¤¹¡£ 

¥µ¥Ý¡¼¥È¡¦¥µ¡¼¥Ó¥¹¤ÎÆâÍÆ¤Ï°Ê²¼¤Ë¤Ê¤ê¤Þ¤¹¡£

  • À½ÉʤΥ¤¥ó¥¹¥È¡¼¥ëÊýË¡¡¢ÀßÄêÊýË¡¡¢µ¡Ç½¤Ë´Ø¤¹¤ë¥á¡¼¥ë¤Ë¤è¤ë¥Þ¥Ë¥å¥¢¥ë¥ì¥Ù¥ë¤ÎÌ䤤¹ç¤ï¤»Âбþ

  • ¥á¡¼¥ë¤Ç¤Î¥ª¥Õ¥µ¥¤¥È¾ã³²Ä´ºº 

  • À½ÉʤΥС¼¥¸¥ç¥ó¥¢¥Ã¥×ÈǤÎÄó¶¡

 

 

Ìä¹ç¤»

ËÜ¥½¥Õ¥È¥¦¥§¥¢¤Ë´Ø¤¹¤ë¤ªÌä¹ç¤»¤Ï¤³¤Á¤é¤«¤é¤ª´ê¤¤¤·¤Þ¤¹¡£

Secioss OTP

·ÈÂÓÅÅÏäò»ÈÍѤ·¤¿¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¥½¥Õ¥È¥¦¥§¥¢Secioss OTP¤Î¥¤¥ó¥¹¥È¡¼¥ë¼ê½ç¤Ë¤Ä¤¤¤Æ²òÀ⤷¤Þ¤¹¡£
Secioss OTP¤Ï¡¢»þ¹ïƱ´ü¼°¤Î¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¤Ç¡¢¥¢¥ë¥´¥ê¥º¥à¤ËRFCɸ½à¤ÎHOTP¤òºÎÍѤ·¤Æ¤¤¤Þ¤¹¡£

 

Secioss OTP¤Î¥½¥Õ¥È¥¦¥§¥¢¤È¥Þ¥Ë¥å¥¢¥ë¤Ï°Ê²¼¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¤¯¤À¤µ¤¤¡£

¥½¥Õ¥È¥¦¥§¥¢¡§
¡¦32bitÈÇ¡§secioss-otp-2.0.2-i386.tgz
¡¦64bitÈÇ¡§secioss-otp-2.0.2-x86_64.tgz
¥Þ¥Ë¥å¥¢¥ë¡§SeciossOTPmanual.pdf

 

Secioss OTP¤Î¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤Ï¡¢¥ª¡¼¥×¥ó¥½¡¼¥¹¤È¤·¤Æ¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£
¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¡§http://sourceforge.jp/projects/seciossotp/

 

ǧ¾Ú¥µ¡¼¥Ð¤Î¥¤¥ó¥¹¥È¡¼¥ë

´Ä¶­

  • OS: CentOS 5  ¤Þ¤¿¤ÏRedHat Enterprise Linux 5

  • Web¥µ¡¼¥Ð: Apache 2.2.3

  • LDAP¥µ¡¼¥Ð: OpenLDAP 2.3.43

 

ɬÍפʥ½¥Õ¥È¥¦¥§¥¢¤Î¥¤¥ó¥¹¥È¡¼¥ë

¼¡¤Î¥½¥Õ¥È¥¦¥§¥¢¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£

  # yum install php-pear
  # yum install php-ldap
  # yum install php-xml
  # yum install perl-LDAP
  # yum install perl-DBI
  # yum install perl-Digest-SHA1 

 

ionCube loader¤òhttp://www.asial.co.jp/ioncube/encoder/download_loaders.php¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¡¢¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£

 

Secioss OTPǧ¾Ú¥µ¡¼¥Ð¤Î¥¤¥ó¥¹¥È¡¼¥ë

Secioss OTPǧ¾Ú¥µ¡¼¥Ð¥À¥¦¥ó¥í¡¼¥É¤·¤Æ²¼¤µ¤¤¡£ ¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥Õ¥¡¥¤¥ë¤òŸ³«¤·¤Æ¡¢¥¤¥ó¥¹¥È¡¼¥ë¥¹¥¯¥ê¥×¥È¤ò¼Â¹Ô¤·¤Æ²¼¤µ¤¤¡£
°Ê²¼¤Ï32bitÈǤξì¹ç¤Ç¤¹¡£

  # tar zxvf secioss-otp-2.0.x-i386.tgz
  # cd secioss-otp-2.0.x-i386
  # ./install.sh install

 

OpenLDAP¤ÎÀßÄê

OpenLDAP¤ÎÀßÄê¥Õ¥¡¥¤¥ë"/etc/openldap/slapd.conf"¤Ë¼¡¤ÎÀßÄê¤òÄɲ䷤Ʋ¼¤µ¤¤¡£


include /etc/openldap/schema/ppolicy.schema
include /etc/openldap/schema/secioss.schema


 

¥æ¡¼¥¶¾ðÊó¤ÎÅÐÏ¿¤ò¹Ô¤¤¤Þ¤¹¡£ 


dn: uid=user01,ou=People,...
objectClass: inetOrgPerson
uid: user01
cn: user01
sn: user01
userPassword: password01


 

Secioss OTPǧ¾Ú¥µ¡¼¥Ð¤ÎÀßÄê

"/var/www/conf/config.ini"¤ò´Ä¶­¤Ë¹ç¤ï¤»¤ÆÊѹ¹¤·¤Æ²¼¤µ¤¤¡£


[password]
storage = "LDAP"
uri = <LDAP¥µ¡¼¥Ð¤ÎURI>
binddn = <LDAP¥µ¡¼¥Ð¤ËÀܳ¤¹¤ë¥æ¡¼¥¶¤ÎDN>
bindpw = <LDAP¥µ¡¼¥Ð¤ËÀܳ¤¹¤ë¥Ñ¥¹¥ï¡¼¥É>
basedn = <¥æ¡¼¥¶¤ò¸¡º÷¤¹¤ë¥Ù¡¼¥¹DN>
keyfile = "/var/www/conf/auth_tkt.conf"


 

¼¡¤Ë"/var/www/conf/auth_tkt.conf"¤Ë°Å¹æ²½¥­¡¼¤ÎÀßÄê¤ò¹Ô¤¤¤Þ¤¹¡£Secioss OTP¤Ï¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¤ÎPIN¤È¥·¡¼¥¯¥ì¥Ã¥È¤ò°Å¹æ²½¤·¤ÆLDAP¥µ¡¼¥Ð¤ËÊݸ¤·¤Þ¤¹¤Î¤Ç¡¢¤½¤ÎºÝ¤Î°Å¹æ²½¤Ë¤³¤Î¥­¡¼¤ò»ÈÍѤ·¤Þ¤¹¡£


TKTAuthSecret    <Ǥ°Õ¤Îʸ»úÎó>


 

PIN¤ÎÅÐÏ¿

»öÁ°¤ËPIN¤ò¥æ¡¼¥¶¤Ë¥á¡¼¥ë¤ÇÄÌÃΤ¹¤ë¤¿¤á¤Î¥á¡¼¥ë¥µ¡¼¥Ð¤È¥á¡¼¥ë¤Îʸ¾Ï¤òÀßÄꤷ¤Þ¤¹¡£
ÀßÄê¥Õ¥¡¥¤¥ë"/var/www/conf/mail-config.ini"¤Ë¥á¡¼¥ë¥µ¡¼¥Ð¤Î¾ðÊó¤òÀßÄꤷ¤Æ²¼¤µ¤¤¡£


postmaster = <Á÷¿®¸µ¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹>
smtp = <¥á¡¼¥ë¥µ¡¼¥Ð>:<¥Ý¡¼¥ÈÈÖ¹æ>
smtpauth_user = <SMTPǧ¾Ú¤Î¥æ¡¼¥¶>
smtpauth_pass = <SMTPǧ¾Ú¤Î¥Ñ¥¹¥ï¡¼¥É>


 

"/var/www/conf/mail-config.ini"¤Ë¥á¡¼¥ë¤Îʸ¾Ï¤òµ­½Ò¤·¤Þ¤¹¡£
${id}¡¢${name}¡¢${pin}¤Ï¡¢¤½¤ì¤¾¤ì¥æ¡¼¥¶ID¡¢»á̾¡¢PIN¤ËÃÖ´¹¤µ¤ì¤Þ¤¹¡£


Subject: PINÄÌÃÎ
${id} ${name}¤µ¤ó
¤¢¤Ê¤¿¤ÎPIN¤Ï¡¢${pin}¤Ç¤¹¡£


 

PIN¤òȯ¹Ô¤¹¤ë¥æ¡¼¥¶¤Î¥æ¡¼¥¶ID¤ÈPIN¤òÅÐÏ¿¤·¤¿CSV¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¤Þ¤¹¡£1¹Ô¤Ë1¥æ¡¼¥¶¤òµ­½Ò¤·¤Þ¤¹¡£


<¥æ¡¼¥¶ID>,<PIN>


°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤¹¤ë¤È¡¢LDAP¤Ë¥æ¡¼¥¶¤ÎPIN¤¬ÅÐÏ¿¤µ¤ì¡¢¤½¤ÎPIN¤¬¥á¡¼¥ë¤Ç¥æ¡¼¥¶¤ËÄÌÃΤµ¤ì¤Þ¤¹¡£
  # /opt/secioss/sbin/otpadd add <CSV¥Õ¥¡¥¤¥ë> <¥¨¥é¡¼½ÐÎÏ¥Õ¥¡¥¤¥ë>

 

LISM Administrator¤òƳÆþ¤¹¤ë¤È¡¢¥³¥Þ¥ó¥É¥é¥¤¥ó¤Ç¤Ï¤Ê¤¯¡¢Web¤«¤é¥æ¡¼¥¶¤Î´ÉÍý¤«¤éPIN¤Îȯ¹Ô¤Þ¤Ç¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£LISM Administrator¤Ë¤Ä¤¤¤Æ¤Ï¡¢LISM Administrator¤Î¥Þ¥Ë¥å¥¢¥ë¤ò¤´Í÷²¼¤µ¤¤¡£

 

¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤Î¥¤¥ó¥¹¥È¡¼¥ë

http://www.secioss.co.jp/otp/¤«¤é·ÈÂÓÅÅÏä˥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¡¢¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ²¼¤µ¤¤¡£
iPhone¤Î¥½¥Õ¥È¥¦¥§¥¢¥È¡¼¥¯¥ó¤Ë¤Ä¤¤¤Æ¤Ï¡¢App Store¤«¤é"Secioss OTP"¤ò¸¡º÷¤·¤Æ¡¢¥À¥¦¥ó¥í¡¼¥É¤·¤Æ²¼¤µ¤¤¡£

 

¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¤éSecioss OTP¤òµ¯Æ°¤·¡¢¤Þ¤º¤ÏLDAP¤ËÅÐÏ¿¤·¤¿¥æ¡¼¥¶¤ÎPIN¤òÆþÎϤ·¤Æ¡¢²èÌ̤λؼ¨¤Ë½¾¤¤¡¢¥¨¥¤¥ê¥¢¥¹¤ÎÀßÄê¤È¿·¤·¤¤¥·¡¼¥¯¥ì¥Ã¥È¤ÎÀ¸À®¤ò¹Ô¤¤¤Þ¤¹¡£

·ÈÂÓÅÅÏäβèÌ̤Ëɽ¼¨¤µ¤ì¤Æ¤¤¤Æ¤¤¤ë¥·¡¼¥¯¥ì¥Ã¥È¤ò”https://<Secioss OTPǧ¾Ú¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾>/user/index.php”¤«¤é¡¢LDAP¤ËÅÐÏ¿¤·¤¿¥æ¡¼¥¶¤Ç¥í¥°¥¤¥ó¤·¤ÆÅÐÏ¿¤·¤Æ²¼¤µ¤¤¡£

 

 

Web¤«¤é¥·¡¼¥¯¥ì¥Ã¥È¤ÎÅÐÏ¿¤¬´°Î»¤·¤Þ¤·¤¿¤é¡¢·ÈÂÓÅÅÏäΥ·¡¼¥¯¥ì¥Ã¥È¤Îɽ¼¨²èÌ̤μ¡¤Ë¿Ê¤à¤È¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¤¬É½¼¨¤µ¤ì¤Þ¤¹¡£
¼¡²ó°Ê¹ß¤Ï¡¢PINÆþÎϸ塢¥¨¥¤¥ê¥¢¥¹¤òÁªÂò¤¹¤ì¤Ð¡¢¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¤¬É½¼¨¤µ¤ì¤Þ¤¹¡£

 

¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú

Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤«¤é¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤ò¹Ô¤¦¤Ë¤Ï¡¢°Ê²¼¤ÎÊýË¡¤Çǧ¾Ú¥µ¡¼¥Ð¤Ë¥æ¡¼¥¶ID¤È¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É¤òÁ÷¿®¤·¤Æ²¼¤µ¤¤¡£

¡¦URL¡§¡¡https://<ǧ¾Ú¥µ¡¼¥Ð¤Î¥Û¥¹¥È̾>/pub/otp.php?userid=<¥æ¡¼¥¶ID>
¡¦POST¥Ç¡¼¥¿
¡¡- password¡§¡¡¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥É

 

¥ì¥¹¥Ý¥ó¥¹¤Ï¡¢°Ê²¼¤ÎXML·Á¼°¤Ë¤Ê¤ê¤Þ¤¹¡£


<?xml version="1.0" encoding="UTF-8"?>
<response>
   <code>¥¨¥é¡¼¥³¡¼¥É</code>
   <message>¥á¥Ã¥»¡¼¥¸</message>
</response>


¥¨¥é¡¼¥³¡¼¥É¤Ï¡¢°Ê²¼¤ÎÃͤò¼è¤ê¤Þ¤¹¡£
¡¦0¡§¡¡Ç§¾ÚÀ®¸ù
¡¦1¡§¡¡Ç§¾Ú¼ºÇÔ
¡¦2¡§¡¡Æ±°ì¤Î¥Ñ¥¹¥ï¡¼¥É¤ÇÊ̤Υ桼¥¶¤¬¥í¥°¥¤¥óºÑ¤ß
¡¦-1¡§¡¡ÆâÉô¥¨¥é¡¼

 

¤Þ¤¿¡¢OpenVPN¤ò»ÈÍѤ·¤¿SSL-VPN¤ÈFreeRADIUS¤ò»ÈÍѤ·¤¿RADIUSǧ¾Ú¤Ç¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤ò»ÈÍѤ¹¤ëÊýË¡¤¬¡¢Secioss OTP¤Î¥Þ¥Ë¥å¥¢¥ë¤Î”6. ¥·¥¹¥Æ¥à¤È¤ÎÏ¢·È”¤ÇÀâÌÀ¤µ¤ì¤Æ¤¤¤Þ¤¹¤Î¤Ç¡¢¤½¤Á¤é¤ò»²¹Í¤Ë¥ï¥ó¥¿¥¤¥à¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú¤ò»î¤·¤Æ¤ß¤Æ²¼¤µ¤¤¡£