ID ã«é¢ããçšèª
åŠç¿ã®ç®ç
ãã®ã¢ãžã¥ãŒã«ãå®äºãããšã次ã®ããšãã§ããããã«ãªããŸãã
- ID ããã³ã¢ã¯ã»ã¹ç®¡çã«äœ¿çšãããæ¥çæšæºãèå¥ããã
- SAML ãš XML ãã©ãé¢é£ããããçè§£ããã
- ID ãããã€ããŒãšãµãŒãã¹ãããã€ããŒã®éããçè§£ããã
ID ã®æšæºãšãããã³ã«
å€éš Web ãµã€ããã¢ããªã±ãŒã·ã§ã³ã«ãµã€ã³ã€ã³ããã«ãŠãŒã¶ãŒã® ID ãå®å šã«ä¿è·ã§ãããšã¯ä¿¡ããããã§ãã? å€ãã®äŒæ¥ã®è£œåããç«¶åãã補åãå«ããŠã飿ºã§ããã®ã¯ã©ãããŠãªã®ã§ããã?
ãã®çãããID ããã³ã¢ã¯ã»ã¹ç®¡çã®ããã®æ¥çæšæºãšãããã³ã«ã§ããé£ãããã«èãããŸããããããªããšã¯ãããŸãããæšæºãšã¯ãåºãç¯å²ã®æ¥çã¡ã³ããŒãããã«åŸãããšã«åæããŠããäžé£ã®æ £è¡ã§ããæšæºã«ã¯ãã·ã¹ãã ãæ å ±ã亀æããæ¹æ³ãæå®ããããããã³ã«ãå«ãŸããŠããããšããããŸãã
æ¬¡ã«æããã®ã¯ãSalesforce ãä»ã® ID ãã³ããŒã ID ãœãªã¥ãŒã·ã§ã³ãå®è£ ããéã«åŸã£ãŠãã 3 ã€ã®ãããã³ã«ã§ãã
- SAML
- OAuth 2.0
- OpenID Connect
SAML ãããã³ã«
ãŠãŒã¶ãŒãç¹°ãè¿ããã°ã€ã³ããã« Salesforce çµç¹ãšã¢ããªã±ãŒã·ã§ã³ã®éãã·ãŒã ã¬ã¹ã«ç§»åã§ããããã«ããã«ã¯ãã·ã³ã°ã«ãµã€ã³ãªã³ (SSO) ãèšå®ããŸããSecurity Assertion Markup Language (SAML) ã¯ãSSO ãå¯èœã«ãããããã³ã«ã§ãã
SAML ãæ©èœããäŸãšããŠæ¬¡ã®ãããªãã®ããããŸãã
- Salesforce ã«ãã°ã€ã³ããã¢ããªã±ãŒã·ã§ã³ã©ã³ãã£ãŒãã¯ãªãã¯ã㊠Gmail ã®åä¿¡ãã¬ã€ãçŽæ¥è¡šç€ºããå ŽåãSAML ãæ©èœããŠããŸãã
- ãã§ã«å¥ã®ã¢ããªã±ãŒã·ã§ã³ã«ãã°ã€ã³ããŠãããŠãŒã¶ãŒãåã³ãã°ã€ã³ããã« Salesforce çµç¹ã«ãã°ã€ã³ã§ããå ŽåãSAML ãæ©èœããŠããŸãã
SAML ã¢ãµãŒã·ã§ã³
SAML ã®åäœã®æµãã説æãããšããŸã ãŠãŒã¶ãŒããµãŒãã¹ã«ã¢ã¯ã»ã¹ããããšããŸãããµãŒãã¹ãããã€ããŒã¯ãããã®ãŠãŒã¶ãŒããã¡ãã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããããããããã©ã倧äžå€«?ããšå°ããèŠæ±ã ID ãããã€ããŒã«éä¿¡ããŸããID ãããã€ããŒã¯ããŒã¿ããŒã¹ããã§ãã¯ããããã®ãŠãŒã¶ãŒã¯èªèšŒæžã¿ã§ãããããããã®æ å ±ã§ããããšå¿ç (ã¢ãµãŒã·ã§ã³) ãè¿ããŠãŠãŒã¶ãŒã®èº«å ã«åœãããªãããšã確èªããŸãã
ããŠãããã§è³ªåã§ããID ãããã€ããŒãšãµãŒãã¹ãããã€ããŒã¯äœãéãã®ã§ããããåºæ¬çã«ãID ãããã€ããŒã¯ãŠãŒã¶ãŒãèªèšŒããŸãããµãŒãã¹ãããã€ããŒã¯èªèšŒããã ID ãèŠæ±ããŸããID ãããã€ããŒãšãµãŒãã¹ãããã€ããŒã«ã€ããŠã¯ããã®åå ã®åŸã§è©³ããåãäžããŸãã
ã¢ãµãŒã·ã§ã³ã¯éä¿¡ãããæ å ±ã§ããã¢ãµãŒã·ã§ã³ã«ã¯ããŠãŒã¶ãŒã«é¢ããè©³çŽ°ãªæ å ±ãå«ããããšãã§ããŸããæ°åãé£çµ¡å æ å ±ãããã«åœ¹è·ãªã©ããŠãŒã¶ãŒã«é¢ãã屿§ãå«ããããšãã§ããŸãã
SAML ã¯ããã¯ã°ã©ãŠã³ãã§åäœããŸãããŠãŒã¶ãŒã®ç®ã«ã¯è§ŠããŸããããŠãŒã¶ãŒãã¢ã€ã³ã³ãŸãã¯ãªã³ã¯ãã¯ãªãã¯ããã ãã§ã远å ã®æ å ±ãå ¥åããããåã³ãã°ã€ã³ãããããªããŠãå¥ã®ã¢ããªã±ãŒã·ã§ã³ãéããŸãã察象ã«ã¢ã¯ã»ã¹ãããšããã§ã«ãŠãŒã¶ãŒã«é¢ããæ å ± (ãŠãŒã¶ãŒå±æ§) ãèªèãããŠããããšããããŸãã
SAML ãš XML
SAML 㯠XML ããŒã¹ã®ãããã³ã«ã§ããã€ãŸãã亀æãããæ å ±ã®ããã±ãŒãžã¯ XML ã§èšè¿°ãããŠããŸããXML 㯠(ã»ãšãã©ã®å Žå) 人éãèªã¿åãããããäœãèµ·ãã£ãŠããã®ãææ¡ã§ããŸããæ£ããåäœããŠãããè§£æããããšããå Žåãããã¯äŸ¿å©ã§ãã
次ã®å³ã¯ãSAML ã¢ãµãŒã·ã§ã³ã®äžéšã瀺ããŠããŸããæå³äžæã«èŠããŸãã? ããäžåºŠèŠãŠã¿ãŸããããå°ãããããããããŸããããŠãŒã¶ãŒã®ãŠãŒã¶ãŒåãé»è©±çªå·ãåã«é¢ããæ å ±ãå«ãŸããŠããŸãã

ãã®äŸã§ã¯ãSalesforce çµç¹ã¯ãŠãŒã¶ãŒã®æ å ±ãå¥ã®ã¢ããªã±ãŒã·ã§ã³ã«æž¡ããŸããã¢ããªã±ãŒã·ã§ã³ã¯ãã®æ å ±ã䜿çšããŠãŠãŒã¶ãŒãæ¿èªãããŠãŒã¶ãŒã®ãšã¯ã¹ããªãšã³ã¹ãããŒãœãã©ã€ãºã§ããŸããã ãããæãéèŠãªã®ã¯ããŠãŒã¶ãŒãåã³ãµã€ã³ã€ã³ããã«ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããšã§ãã
OAuth 2.0 ãããã³ã«
OAuth (ãªãŒãã³èªèšŒ) 2.0 ã¯ãã¢ããªã±ãŒã·ã§ã³éã®ã»ãã¥ã¢ãªããŒã¿å ±æãå¯èœã«ããããã«äœ¿çšãããªãŒãã³ãããã³ã«ã§ãããŠãŒã¶ãŒã¯ãäžæ¹ã®ã¢ããªã±ãŒã·ã§ã³ã§äœæ¥ããããäžæ¹ã®ã¢ããªã±ãŒã·ã§ã³ããããŒã¿ã衚瀺ã§ããŸããããšãã°ãSalesforce ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã«ãã°ã€ã³ããSalesforce çµç¹ããããŒã¿ã衚瀺ã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³ã¯ããã¯ã°ã©ãŠã³ãã§äžçš®ã®ãã³ãã·ã§ã€ã¯ãå®è¡ããŠããããŠãŒã¶ãŒã«ãã®ããŒã¿å ±æãæ¿èªããããã«èŠæ±ããŸããéçºè ãã¢ããªã±ãŒã·ã§ã³ã Salesforce ã«çµ±åããå Žåã¯ãOAuth API ã䜿çšããŸãã
ããšãã°ã次ã®ãããªäŸããããŸãã
- Salesforce çµç¹ããååŒå
責任è
ãåã蟌ãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã¯ OAuth ã䜿çšããŸãã
- å¥ã®ãµãŒãã¹ããååŒå
責任è
ãååŸãã Salesforce çµç¹ã OAuth ã䜿çšããŸãã
次ã®äŸã§ã¯ãã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒã« OAuth 2.0 ã䜿çšããŠæ å ±ã«ã¢ã¯ã»ã¹ããèš±å¯ãèŠæ±ããŠããŸãã

OpenID Connect ãããã³ã«
OpenID Connect ãããã³ã«ã§ã¯ããŠãŒã¶ãŒæ å ±ãå®å šã«äº€æã§ããããã«ãOAuth 2.0 äžã«èªèšŒã¬ã€ã€ãŒã远å ããŸããOpenID Connect ã 1 ã€ã®ãµãŒãã¹ããå¥ã®ãµãŒãã¹ã« ID æ å ±ãéä¿¡ããç¹ã¯ SAML ãšåãã§ããã SAML ãšã®éãã¯ãOpenID Connect ã仿¥ã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ç°å¢çšã«æ§ç¯ãããŠããããšã§ããæ°ããã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãããšãã«ãGoogle ã¢ã«ãŠã³ãã§ãã°ã€ã³ããŸãã?ããšããã¡ãã»ãŒãžã衚瀺ãããããšã¯ãããŸããã? ãã®ã¢ããªã±ãŒã·ã§ã³ã¯ OpenID Connect ãããã³ã«ã䜿çšããŠããŸããGoogle ã§ãµã€ã³ã€ã³ãããšãã«ã¯ãã¢ã«ãŠã³ããå¥ã®ãã¹ã¯ãŒããäœæããŸããããã®æ å ±ãä¿æããŠããã®ã¯ Google ã ãã§ãã

ã¢ããªã±ãŒã·ã§ã³éçºè 㯠OpenID Connect ãããã³ã«ã䜿çšããŠãœãŒã·ã£ã«ãµã€ã³ãªã³ãæå¹ã«ããŸãã
ããšãã°ãGoogle ãå¥ã®ãµãŒãã¹ã«ä»£ãã£ãŠãŠãŒã¶ãŒã® ID ãæ€èšŒãããšããGoogle ããŠãŒã¶ãŒãèªèšŒããŸããããã§ã¯ãGoogle 㯠ID ãããã€ããŒã§ãã
Salesforce ã«ã¯ãGoogleãFacebookãLinkedIn ãªã©ãè€æ°ã®äž»èŠãªãœãŒã·ã£ã« ID ãããã€ããŒã®ãµããŒããçµã¿èŸŒãŸããŠããŸãããããã€ããŒãæšæºã§ãµããŒããããŠããªãå Žåã§ããAmazon ã PayPal ã®ããã«ãããã€ããŒã OpenID Connect ãããã³ã«ãå®è£ ããŠããã°äœ¿çšã§ããŸãã
ãŠãŒã¶ãŒã«ãšã£ãŠ OpenID Connect ãããã³ã«ã«ã¯ãå¥ã ã®ã¢ã«ãŠã³ãããŠãŒã¶ãŒåããã¹ã¯ãŒãã®æ°ãæžããããšããã¡ãªããããããŸããäžæ¹ã§ãéçºè ã¯ããã¹ã¯ãŒããã¡ã€ã«ãææããŠç®¡çããããšãªããè€æ°ã® Web ãµã€ããã¢ããªã±ãŒã·ã§ã³ã«ãŸããã£ãŠãŠãŒã¶ãŒãèªèšŒã§ããŸãããã®ããã»ã¹ã«ãããããã«ãŒã«ãããŠãŒã¶ãŒã¢ã«ãŠã³ãã®äŸµå®³ãã¯ããã«é£ãããªããŸãã
ãµãŒãã¹ãããã€ããŒãš ID ãããã€ããŒ
ãŠãŒã¶ãŒèªèšŒããã»ã¹ã§ãSAML 㯠ID æ å ±ã ID ãããã€ã㌠(IDP) ãšåŒã°ããæ å ±ä¿æè ãšãµãŒãã¹ãããã€ããŒãšåŒã°ããç®çã®ãµãŒãã¹ã®éã§äº€æããŸãã
ãŠãŒã¶ãŒã Salesforce ã«ãã°ã€ã³ããŠãã Gmail ã«ã¢ã¯ã»ã¹ããå ŽåãSalesforce ã ID ãããã€ããŒã§ Google ããµãŒãã¹ãããã€ããŒã§ããSalesforce ã¯ãµãŒãã¹ãããã€ããŒãš ID ãããã€ããŒã®ã©ã¡ãã«ããªããŸãã
Salesforce ããµãŒãã¹ãããã€ããŒã®å Žå
èªèšŒããããŠãŒã¶ãŒã¯å€éš ID ãããã€ããŒãã Salesforce ã«ã¢ã¯ã»ã¹ã§ããŸãããã®å ŽåãSalesforce ããµãŒãã¹ãããã€ããŒã§ãããŠãŒã¶ãŒã¯ãã®ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹æš©ãååŸããå¿ èŠããããID ãããã€ããŒããããèš±å¯ããŸããäŒç€Ÿã§ãã§ã« ID ãããã€ããŒã䜿çšãããŠããããšãå€ãããããã®ãã㪠Salesforce èšå®ã¯äžè¬çã§ããID ãããã€ããŒãšããŠã¯ãMicrosoft ã® Active Directory ãã§ãã¬ãŒã·ã§ã³ãµãŒãã¹ (ADFS)ããPing Identity ã® PingFederateããªãŒãã³ãœãŒã¹ã® ShibbolethãForgeRock ã® OpenAM ãªã©ãåžå Žã«ããæ¢åã®ãããã€ããŒã®ãããããèããããŸãã
ãŠãŒã¶ãŒã¯ ID ãããã€ããŒãããã°ã€ã³ããSalesforce (ãµãŒãã¹ãããã€ããŒ) ã«ãªãã€ã¬ã¯ããããŸããå¥ã®ã¢ãžã¥ãŒã«ã§ã¯ãSalesforce ããµãŒãã¹ãããã€ããŒããµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ãå€éš ID ãããã€ããŒãšã㊠SSO ãèšå®ããŸãã
Salesforce ã ID ãããã€ããŒã®å Žå
èªèšŒããããŠãŒã¶ãŒã¯ Salesforce ããä»ã®ã¯ã©ãŠããã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãããã®å ŽåãSalesforce 㯠ID ãããã€ããŒãšããŠæ©èœããSSO ãæäŸããŠããŠãŒã¶ãŒãå¥ã®ãµãŒãã¹ãããã€ããŒã«æ¥ç¶ããããšãå¯èœã«ããŸãã
SSO ã® SAML ãããŒ
åèãŸã§ã«ã次ã®å³ã¯ SSO ããã»ã¹äžã® SAML éä¿¡ãããŒã瀺ããŸããããã¯ã°ã©ãŠã³ãã§ã¯ãã®ãããªããšãè¡ãããŠããŸããèå³ããããªããŠãå¿é ãããŸããããã¹ãã«ã¯åºãŸããã
SSO ããã»ã¹ã¯ç®ã«ããšãŸãã¬éãã§å®è¡ãããŸãããå®ã¯è€æ°ã®åŠçãè¡ãããŠããŸãã
- ãŠãŒã¶ãŒã Salesforce ãžã®ã¢ã¯ã»ã¹ã詊ã¿ãã
- Salesforce ã SSO èŠæ±ãèªèããSAML èŠæ±ãçæããã
- Salesforce ã SAML èŠæ±ãå
ã®ãã©ãŠã¶ãŒã«ãªãã€ã¬ã¯ãããã
- ãã©ãŠã¶ãŒã SAML èŠæ±ãå€éš ID ãããã€ããŒã«ãªãã€ã¬ã¯ãããã
- ID ãããã€ããŒããŠãŒã¶ãŒã® ID ãæ€èšŒãããŠãŒã¶ãŒèªèšŒãå«ã SAML ã¢ãµãŒã·ã§ã³ãããã±ãŒãžåããã
- ID ãããã€ããŒã SAML ã¢ãµãŒã·ã§ã³ããã©ãŠã¶ãŒã«éä¿¡ããã
- ãã©ãŠã¶ãŒãã¢ãµãŒã·ã§ã³ã Salesforce ã«ãªãã€ã¬ã¯ãããã
- Salesforce ãã¢ãµãŒã·ã§ã³ãæ€èšŒããã
- ãŠãŒã¶ãŒã®ãµã€ã³ã€ã³ãèš±å¯ãããSalesforce ã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã

ID çšèªã®æ©èŠè¡š
ID ãããã³ã«ã«é¢ããéç¿ã³ãŒã¹ã¯ãããã§ããã? çšèªã®é¿ãã䌌ãŠããŠéãã埮åŠãªå Žåãæ£ããèŠããŠããã®ã¯é£ãããããããŸãããããã§ãæ©èŠè¡šãçšæããŸããããã²æŽ»çšããŠãã ããã
Salesforce ã®çšèª |
ééããããçšèª |
|---|---|
èªèšŒãšã¯ãã誰ã§ããããã確èªããããšã§ããæè¿ã§ã¯ããæ¿èªãšèªèšŒããççž®ããŠãèªèšŒãã䜿çšãããå€ãã§ãã |
æ¿èªãšã¯ããããç¹å®ã®æš©éãæã£ãŠããããã確èªããããšã§ãã |
ãããã³ã«ãšã¯ãã·ã¹ãã ãæ å ±ã亀æããããã®ã«ãŒã«ã»ãããæããŸããäžè¬çã«ãããããã³ã«ããšãæšæºããšããçšèªã¯ã»ãšãã©å矩ã§ãã |
æšæºãšã¯ããã³ããŒããµããŒãããããšã«åæããæ¥çæ £è¡ã®ä»æ§ã§ããæšæºã«ã¯ãäŒæ¥ãæšæºãå®è£ ããæ¹æ³ãæå®ããããã«ãããã³ã«ãå«ãŸããããšããããããŸãã |
ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã¯ããŠãŒã¶ãŒãã·ã¹ãã ã«ãã°ã€ã³ããããã«æå®ãããã®ã§ãã |
ãã°ã€ã³æ å ±ãã»ãšãã©åãæå³ã§ãã |
ã·ã³ã°ã«ãµã€ã³ãªã³ (SSO) ã䜿çšãããšããŠãŒã¶ãŒã¯ 1 åãã°ã€ã³ããã°ãåã³ãã°ã€ã³ããããšãªãä»ã®ã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã |
ãœãŒã·ã£ã«ãµã€ã³ãªã³ã䜿çšãããšããŠãŒã¶ãŒã¯ Google ãªã©ã®ãœãŒã·ã£ã«ã¢ã«ãŠã³ãã§ç¢ºç«ããããã°ã€ã³æ å ±ã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ã«ãã°ã€ã³ã§ããŸãããã®ã¢ããªã±ãŒã·ã§ã³ã¯ Google ãã°ã€ã³æ å ±ãåãå ¥ãããŠãŒã¶ãŒã¯å¥ã®ã¢ã«ãŠã³ããšãã¹ã¯ãŒããäœæããå¿ èŠããããŸããã |
ID ãããã€ããŒã¯ããŠãŒã¶ãŒãåã³ãã°ã€ã³ããã« Web ãµã€ãããµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ããä¿¡é ŒããããµãŒãã¹ã§ãã |
ãµãŒãã¹ãããã€ããŒã¯ãã¢ããªã±ãŒã·ã§ã³ããã¹ããã Web ãµã€ãããµãŒãã¹ã§ãID ãããã€ããŒããã® ID ãåãå ¥ããŸãã |
次ã®ã¹ããã
ID ã¢ã¯ã»ã¹ãšç®¡çã®æ¥çæšæºãé§ãè¶³ã§èŠãŠããŸããããŸã é ã®äžã§æŽçãã€ããŠããªããŠã倧äžå€«ã§ããçŸæç¹ã§ã¯ãSalesforce Identity ããããã³ã«ã䜿çšããŠæ©èœãå®è£ ããããšã ããèŠããŠãããŠãã ããã
ãæ¥œãã¿ã¯ããããã§ããæŠå¿µãšå®çŸ©ã¯ããååã§ããããããŸã§ã«åŠãã ããšãå®è·µããŠã¿ãŸãããããã®ãã¬ã€ã«ã§ã¯ãåŸã§ Salesforce éçºçµç¹ã«ã»ãã¥ãªãã£æ©èœãèšå®ããŸãã
ãªãœãŒã¹
- Salesforce ãã«ã: SAML SSO ãããŒ
- Salesforce ãã«ã: ãŠãŒã¶ãŒã®èå¥ããã³ã¢ã¯ã»ã¹æš©ã®ç®¡ç