å éšãŠãŒã¶ãŒã®ã·ã³ã°ã«ãµã€ã³ãªã³ã®èšå®
åŠç¿ã®ç®ç
ãã®ã¢ãžã¥ãŒã«ãå®äºãããšã次ã®ããšãã§ããããã«ãªããŸãã
- çµ±å ID ãäœæããã
- ãµãŒãããŒã㣠ID ãããã€ããŒããã®ã·ã³ã°ã«ãµã€ã³ãªã³ãèšå®ããã
- SAML èŠæ±ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«äœ¿çšããããŒã«ãèªèããã
ã·ã³ã°ã«ãµã€ã³ãªã³
[ç§ã®ãã¡ã€ã³] ã®ãã°ã€ã³ URL ãããã°ãå®å šã§èŠãããã URL ã䜿çšããŠåŸæ¥å¡ã Salesforce çµç¹ã«ç°¡åã«ãã°ã€ã³ã§ããŸããÂ
ããã«ç°¡ç¥åããŠããŠãŒã¶ãŒã®ãã°ã€ã³ãäžåäžèŠã«ããããšãã§ããŸãããã®å Žåã¯ãã·ã³ã°ã«ãµã€ã³ãªã³ (SSO) ãèšå®ããŸãã
SSO ã«ã¯å€ãã®ã¡ãªããããããŸãã
- ãã¹ã¯ãŒãã®ç®¡çã«è²»ããæéãæžå°ããã
- åŸæ¥å¡ã Salesforce ã«æåã§ãã°ã€ã³ããå¿
èŠããªããã°ãåŸæ¥å¡ã®æéãç¯çŽãããããŠãŒã¶ãŒããªã³ã©ã€ã³ã¢ããªã±ãŒã·ã§ã³ã«ãã°ã€ã³ãããŸã§ã« 5 ïœ 20 ç§ããã£ãŠããããšããåç¥ã§ããã? 塵ãç©ããã°å±±ãšãªããŸãã
- Salesforce ã®å©çšè
ãå¢ããããŠãŒã¶ãŒã¯ Salesforce ã¬ã³ãŒãããã³ã¬ããŒããžã®ãªã³ã¯ãéä¿¡ã§ããåä¿¡è
ã¯ã¯ã³ã¯ãªãã¯ã§éãããšãã§ããŸãã
- æ©å¯æ
å ±ãžã®ã¢ã¯ã»ã¹ã 1 ãæã§ç®¡çã§ããã
ãã®åå ã§ã¯ããŠãŒã¶ãŒãå¥ã®ãšãã (ãªã³ãã¬ãã¹ã¢ããªã±ãŒã·ã§ã³ãªã©) ã§ãã°ã€ã³ãããã®åŸ Salesforce ã«ãã°ã€ã³ãªãã§ã¢ã¯ã»ã¹ãããã€ã³ããŠã³ã SSO ã®èšå®æ¹æ³ã«ã€ããŠèª¬æããŸãããŸãããŠãŒã¶ãŒã Salesforce ã«ãã°ã€ã³ãããã®åŸä»ã®ãµãŒãã¹ã«å床ãã°ã€ã³ããããšãªãã¢ã¯ã»ã¹ãããã¢ãŠãããŠã³ã SSO ãèšå®ã§ããŸãã
MFA ã®æ³šæäºé
æåã®åå ã§åãäžãã MFA èŠä»¶ãèŠããŠããŸãã? SSO ãŠãŒã¶ãŒã«ããã®èŠä»¶ãé©çšãããŸããåŸæ¥å¡ããªã³ãã¬ãã¹ã¢ããªã±ãŒã·ã§ã³ã SSO ID ãããã€ããŒã䜿çšã㊠Salesforce ã«ã¢ã¯ã»ã¹ããå Žåããæåã« MFA ãå®äºããå¿ èŠããããŸãã
ããã§ã¯ãSSO ãŠãŒã¶ãŒã« MFA ãé©çšããæ¹æ³ã«ã€ããŠèª¬æããŸããããç°¡åã«å®è¡ããæ¹æ³ããããŸããSalesforce ã«ä»å±ã® MFA ãµãŒãã¹ã SSO èšå®ã«äœ¿çšããå Žåã¯ãSalesforce ãã«ãã®ãSSO ã§ã® Salesforce MFA ã®äœ¿çšããåç §ããŠãã ããããŸããSSO ãããã€ããŒã® MFA ãµãŒãã¹ãå©çšããå Žåã¯ããŠãŒã¶ãŒã Salesforce ã«ã¢ã¯ã»ã¹ãããšãã§ã¯ãªãããããã€ããŒã«ãã°ã€ã³ãããšãã« MFA ãå¿ é ã«ããããšãã§ããŸãã
ãµãŒãããŒã㣠ID ãããã€ããŒã䜿çšããã€ã³ããŠã³ã SSO ã®èšå®
ãµãŒãããŒã㣠ID ãããã€ããŒã䜿çšããã€ã³ããŠã³ã SSO ã®èšå®ãå§ããŸãããã
IT éšéã® Sean Sollo éšé·ãããSalesforce ãŠãŒã¶ãŒã« SSO ãèšå®ããJedeye ãããã¯ãŒã¯ã®ãã°ã€ã³æ å ±ã䜿çšã㊠Salesforce çµç¹ã«ãã°ã€ã³ã§ããããã«ããããšãæ瀺ãããŸããããã§ã¯ãJedeye Tech ã®æ°å ¥ç€Ÿå¡ã§ãã Sia Thripio ã® SSO ãèšå®ããæé ãèŠãŠãããŸããAxiom Heroku Web ã¢ããªã±ãŒã·ã§ã³ã ID ãããã€ããŒãšããŠã€ã³ããŠã³ã SSO ãèšå®ããŸãã
é£ãããã§ãã? ãããªããšã¯ãããŸããã现ããã¹ãããã«åå²ããŠèŠãŠãããŸãããã
- åãŠãŒã¶ãŒã®çµ±å ID ãäœæããŸãã
- Salesforce 㧠SSO ã®èšå®ãè¡ããŸãã
- SSO ãããã€ããŒã§ Salesforce ã®èšå®ãè¡ããŸãã
- ãã¹ãŠãæ©èœããããšã確èªããŸãã
ã¹ããã 1: çµ±å ID ãäœæãã
SSO ãèšå®ããå ŽåãåãŠãŒã¶ãŒãèå¥ããäžæã®å±æ§ã䜿çšããŸãããã®å±æ§ãšãªãã®ããSalesforce ãŠãŒã¶ãŒããµãŒãããŒã㣠ID ãããã€ããŒã«é¢é£ä»ãããªã³ã¯ã§ãããŠãŒã¶ãŒåããŠãŒã¶ãŒ IDãçµ±å ID ã®ããããã䜿çšã§ããŸããããã§ã¯çµ±å ID ã䜿çšããŸãã
çµ±å ID ãšãã£ãŠããçµ±åãããçµç¹ã® ID ã§ã¯ãããŸãããåºæ¬çã«ãID æ¥çãäžæã®ãŠãŒã¶ãŒ ID ã«å¯ŸããŠçšããçšèªã§ãã
éåžžã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããèšå®ãããšãã«çµ±å ID ãå²ãåœãŠãŸããæ¬çªç°å¢ã« SSO ãèšå®ãããšãã¯ãSalesforce ããŒã¿ããŒããŒãªã©ã®ããŒã«ã䜿çšããŠäžåºŠã«å€æ°ã®ãŠãŒã¶ãŒã«çµ±å ID ãå²ãåœãŠãããšãã§ããŸããããã§ã¯ãJedeye Technologies ã®æ°å ¥ç€Ÿå¡ã§ãã Sia Thripio ã®ã¢ã«ãŠã³ããèšå®ããããšã«ããŸãã
- [Setup (èšå®)] ããã[Quick Find (ã¯ã€ãã¯æ€çŽ¢)] ããã¯ã¹ã«
Users
(ãŠãŒã¶ãŒ) ãšå ¥åãã[Users (ãŠãŒã¶ãŒ)] ãéžæããŸãã
- Sia ã®ååã®æšªã«ãã [Edit (ç·šé)] ãã¯ãªãã¯ããŸãã
- [Single Sign On Information (ã·ã³ã°ã«ãµã€ã³ãªã³æ
å ±)] ã§ã[Federation ID (çµ±å ID)] ã«
sia@jedeye-tech.com
ãšå ¥åããŸãããã³ã: çµ±å ID ã¯ãçµç¹å ã®ãŠãŒã¶ãŒããšã«äžæã§ãªããã°ãªããŸããããŠãŒã¶ãŒåã䟿å©ãªã®ã¯ãã®ããã§ãããã ãããŠãŒã¶ãŒãè€æ°ã®çµç¹ã«å±ããŠããå Žåã¯ãåçµç¹ã§ãŠãŒã¶ãŒã«åãçµ±å ID ã䜿çšããŸããÂ
-
[Save (ä¿å)] ãã¯ãªãã¯ããŸãã
ã¹ããã 2: Salesforce ã« SSO ãããã€ããŒãèšå®ãã
ãµãŒãã¹ãããã€ããŒã¯ ID ãããã€ããŒãèªèããå¿ èŠããããID ãããã€ããŒããµãŒãã¹ãããã€ããŒãèªèããå¿ èŠããããŸãããã®ã¹ãããã§ã¯ãSalesforce åŽã« ID ãããã€ã㌠(ãã®å Žå㯠Axiom) ã«é¢ããæ å ±ãæå®ããŸãã次ã®ã¹ãããã§ã¯ãAxiom ã« Salesforce ã«é¢ããæ å ±ãæå®ããŸãã
Salesforce åŽã§ãSAML èšå®ãè¡ããŸããSAML ã¯ãSalesforce Identity ã SSO ã®å®è£ ã«äœ¿çšãããããã³ã«ã§ãã
ãã³ã: Salesforce éçºçµç¹ãš Axiom ã¢ããªã±ãŒã·ã§ã³ã®äž¡æ¹ã§äœæ¥ããŸãããã® 2 ã€ãããããå¥ã®ãã©ãŠã¶ãŒãŠã£ã³ããŠã§éããç¶æ ã«ããŠãäž¡è éã§ã³ããŒã¢ã³ãããŒã¹ãã§ããããã«ããŸãã
- æ°ãããã©ãŠã¶ãŒãŠã£ã³ããŠã§ãhttps://axiomsso.herokuapp.com ã«ã¢ã¯ã»ã¹ããŸãã
-
[SAML ID ãããã€ããŒãšãã¹ã¿ãŒ] ãã¯ãªãã¯ããŸãã
-
[ID ãããã€ããŒã®èšŒææžãããŠã³ããŒã] ãã¯ãªãã¯ããŸãããã®èšŒææžã¯åŸã§ Salesforce çµç¹ã«ã¢ããããŒããããããä¿åå
ãèŠããŠãããŸãã
- Salesforce çµç¹ã§ã[Setup (èšå®)] ã® [Quick Find (ã¯ã€ãã¯æ€çŽ¢)] ããã¯ã¹ã«
Single
ãšå ¥åãã[Single Sign-On Settings (ã·ã³ã°ã«ãµã€ã³ãªã³èšå®)] ãéžæããŸãã
-
[Edit (ç·šé)] ãã¯ãªãã¯ããŸãã
-
[SAML ãæå¹å] ãéžæããŸãã
-
[Save (ä¿å)] ãã¯ãªãã¯ããŸãã
- [SAML ã·ã³ã°ã«ãµã€ã³ãªã³èšå®] ã§ã
-
[New (æ°èŠ)] ãã¯ãªãã¯ããŸãã
- 次ã®å€ãå
¥åããŸãã
- Name (åå):
Axiom Test App
- Issuer (çºè¡è
):
https://axiomsso.herokuapp.com
- ID ãããã€ããŒã®èšŒææž: ã¹ããã 3 ã§ããŠã³ããŒããããã¡ã€ã«ãéžæããŸãã
- 眲åèŠæ±ã¡ãœãã: [RSA-SHA1] ãéžæããŸãã
- SAML ID çš®å¥: [ã¢ãµãŒã·ã§ã³ã«ã¯ããŠãŒã¶ãŒãªããžã§ã¯ãã®çµ±å ID ãå«ãŸããŸã] ãéžæããŸãã
- SAML ID ã®å Žæ: [ID ã¯ãSubject ã¹ããŒãã¡ã³ãã® NameIdentifier èŠçŽ ã«ãããŸã] ãéžæããŸãã
- ãµãŒãã¹ãããã€ããŒã®èµ·åèŠæ±ãã€ã³ã: [HTTP ãªãã€ã¬ã¯ã] ãéžæããŸãã
- ãšã³ãã£ã㣠ID: [ç§ã®ãã¡ã€ã³] ã® URL ãå
¥åããŸãããã㯠[ç§ã®ãã¡ã€ã³] ã® [èšå®] ããŒãžã«è¡šç€ºãããŠããŸãããšã³ãã£ã㣠ID ã«ã¯ãhttpsããå«ãŸããŠãããSalesforce ãã¡ã€ã³ãåç
§ããŠããããšã確èªããŠãã ãããhttps://mydomain-dev-ed.develop.my.salesforce.com ã®ããã«ãªããŸãã
-
[Save (ä¿å)] ãã¯ãªãã¯ãããã©ãŠã¶ãŒã®ããŒãžã¯éãããŸãŸã«ããŸãã
ã¹ããã 3: ID ãããã€ããŒã Salesforce ã«ãªã³ã¯ãã
Salesforce ã ID ãããã€ã㌠(Axiom) ãèªèã§ããããã«èšå®ããããä»åºŠã¯ ID ãããã€ããŒããµãŒãã¹ãããã€ã㌠(Salesforce) ãç¹å®ã§ããããã«ããŸãã
以äžã® Axiom ãã©ãŒã ã®æ°é ç®ã«å€ãå ¥åããŸããç°¡åã§ããããSalesforce ã® SSO èšå®ãæå®ããŠãããããSalesforce çšãš Axiom çšã® 2 ã€ã®ãã©ãŠã¶ãŒãŠã£ã³ããŠãéãããŸãŸã«ããŸãã
- Axiom Web ã¢ããªã±ãŒã·ã§ã³ã«æ»ããŸãããã®ã¢ããªã±ãŒã·ã§ã³ããã©ãŠã¶ãŒãŠã£ã³ããŠã§éããŠããªãå Žåã¯ãhttps://axiomsso.herokuapp.com ã«ã¢ã¯ã»ã¹ããŸãã
-
[SAML ID ãããã€ããŒãšãã¹ã¿ãŒ] ãã¯ãªãã¯ããŸãã
-
[SAML ã¬ã¹ãã³ã¹ãçæ] ãã¯ãªãã¯ããŸãã
- 次ã®å€ãå
¥åããŸããä»ã®é
ç®ã¯ãã®ãŸãŸã«ããŸãã
- SAML ããŒãžã§ã³: 2.0
- ãŠãŒã¶ãŒåãŸãã¯çµ±å ID: Sia ã® Salesforce ãŠãŒã¶ãŒããŒãžããååŸããçµ±å ID
- Issuer (çºè¡è
):
https://axiomsso.herokuapp.com
- åä¿¡ URL: Salesforce SAML ã® [ã·ã³ã°ã«ãµã€ã³ãªã³èšå®] ããŒãžããååŸãã URLãã©ãã«ãããããããŸãã? ããŒãžäžéš (ã® [ãšã³ããã€ã³ã] ã»ã¯ã·ã§ã³) ã« [ãã°ã€ã³ URL] ãšãã衚瀺ã©ãã«ããããŸãã
- Entity Id (ãšã³ãã£ã㣠ID): Salesforce ã® [SAML Single Sign-On Settings (SAML ã·ã³ã°ã«ãµã€ã³ãªã³èšå®)] ããŒãžããååŸãããšã³ãã£ã㣠IDã
çµäºãããšãAxiom ã®èšå®ããŒãžã次ã®ããã«ãªããŸãã
ã¹ããã 4: æ£åžžã«æ©èœããããšã確èªãã
ãã¹ãŠã®èšå®ãå®äºãããããã®èšå®ãæ©èœããããšã確èªããŸããæ©èœããŠããã°ãæ£åžžã«ãã°ã€ã³ã§ããŸãã
- Axion èšå®ã®ãã©ãŠã¶ãŒãŠã£ã³ããŠã§ã[SAML ã¬ã¹ãã³ã¹ãèŠæ±] ãã¯ãªãã¯ããŸãã(ãã®ãã¿ã³ã¯ããªãäžã®æ¹ã«ãããŸã)ã
- Axiom ã«ãã XML ã® SAML ã¢ãµãŒã·ã§ã³ãçæãããŸããç æŒ ã®åºå°ã«ããæ°Žåèžçºåšãšã®ããããéä¿¡ã«äœ¿ãããèšèªã®ããã§ãã? ããäžåºŠèŠãŠãã ããããã¹ãŠãäžå¯è§£ãªã³ãŒãã§ã¯ãªãããšãããããŸããXML ãã¹ã¯ããŒã«ããŠãå¿
èŠãªæ
å ±ãèŠã€ããŸããÂ
-
[ãã°ã€ã³] ãã¯ãªãã¯ããŸãã
æ£åžžã«æ©èœããŠããå Žåã¯ãSalesforce ããŒã ããŒãžã§ Sia ãšããŠãã°ã€ã³ããŠããŸããAxiom ã¢ããªã±ãŒã·ã§ã³ãããå²ãåœãŠãããçµ±å ID ã䜿çšããŠãSalesforce çµç¹ã«ãŠãŒã¶ãŒãšããŠãã°ã€ã³ã§ããŸãã
ãç²ãããŸã§ãããå¥ã®ã¢ããªã±ãŒã·ã§ã³ãã Salesforce ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã® Salesforce SSO ãèšå®ããŸããã
ãªãœãŒã¹
- Salesforce ãã«ã: SAML SSO ãããŒ
- Salesforce ãã«ã: SAML ã·ã³ã°ã«ãµã€ã³ãªã³ã䜿çšãããµãŒãã¹ãããã€ããŒãšã㊠Salesforce ãèšå®
- Salesforce åç»: Configure SAML Single Sign-on with Salesforce as the Identity Provider (Salesforce ã ID ãããã€ããŒãšããŠäœ¿çšãã SAML ã·ã³ã°ã«ãµã€ã³ãªã³ã®èšå®)