ååã¯èšŒææžãµãŒãã¹ãã€ã³ã¹ããŒã«ããèšŒææžã®çºè¡ã«å¿ èŠãªãã³ãã¬ãŒããæºåãããä»åã¯ãAD FSçšã®èšŒææžãçºè¡ããAD FSãµãŒãã¹ã®ã€ã³ã¹ããŒã«ãšã»ããã¢ãããè¡ãã
èšŒææžã®çºè¡
FS1ã«æ¥ç¶ãããããã®éããã°ãªã³ã«äœ¿çšããIDã¯ãã¡ã€ã³ã®ç®¡çè ïŒ<ãã¡ã€ã³å>\CloudAdminïŒã§ãªããã°ãªããªãããšã«æ³šæããããããã§ãªããšããã¡ã€ã³ã«å¯Ÿãã管çè æš©éãååŸã§ããªãã
ãã°ãªã³ãããããã¹ã¿ãŒãããã¿ã³ãå³ã¯ãªãã¯ããŠããã¡ã€ã«åãæå®ããŠå®è¡ããéžæãããã
å忬ã«ãMMCããšå ¥åããŠãOKããã¯ãªãã¯ããã
ã³ã³ãœãŒã«ãèµ·åãããããã¡ã€ã«ãã¡ãã¥ãŒãããã¹ãããã€ã³ã®è¿œå ãšåé€ããéžæã
ãã¹ãããã€ã³ã®è¿œå ãšåé€ããŠã£ã³ããŠãéãããããå©çšã§ããã¹ãããã€ã³ããããèšŒææžããéžæãã远å ããã¯ãªãã¯ããã
ãèšŒææžã¹ãããã€ã³ããŠã£ã³ããŠãéãã®ã§ãã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ãããéžæããŠã次ãžããã¯ãªãã¯ã
ãã³ã³ãã¥ãŒã¿ãŒã®éžæãç»é¢ã§ã¯ãããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒããéžæãããŠããããšã確èªããŠãå®äºããã¯ãªãã¯ãããã¹ãããã€ã³ã®è¿œå ãšåé€ãŠã£ã³ããŠã«æ»ã£ãããOKããã¯ãªãã¯ããã
ã³ã³ãœãŒã«ã«èšŒææžã¹ãããã€ã³ãèªã¿èŸŒãŸãããããä¿¡é Œãããã«ãŒãèšŒææ©é¢ãã®äžã«ãããèšŒææžããã¯ãªãã¯ããŠãçºè¡ãããèšŒææžäžèЧã®äžã«ãã¡ã€ã³ã®ã«ãŒãèšŒææžãååšããããšã確èªãããã以äžã®ãããªååã§çºè¡ãããŠããã¯ãã ããã®ã«ãŒãèšŒææžã¯DS1ã§èšŒææ©é¢ã®ã»ããã¢ãããããéã«äœæããããã®ã§ããã¡ã€ã³ã«åå ããŠããã³ã³ãã¥ãŒã¿ãŒã«ã¯èªåçã«é åžãããã
<ãã¡ã€ã³å>-DS1-CA
次ã«ãå人ããå³ã¯ãªãã¯ããŠããã¹ãŠã®ã¿ã¹ã¯ããããæ°ããèšŒææžã®èŠæ±ããéžæããã
- ãèšŒææžã®ç»é²ããŠã£ã¶ãŒããèµ·åããã®ã§ã次ãžããã¯ãªãã¯ã
- ãèšŒææžã®ç»é²ããªã·ãŒã®éžæããŠã£ã³ããŠãéãã®ã§ããActive Directoryç»é²ããªã·ãŒããéžæãããç¶æ ã§ã次ãžããã¯ãªãã¯ã
- ãèšŒææžã®èŠæ±ããŠã£ã³ããŠã§ã¯ååäœæããèšŒææžãã³ãã¬ãŒããSSL Certãããã§ãã¯ãããã®èšŒææžãç»é²ããã«ã¯æ å ±ãäžè¶³ããŠããŸããèšå®ãæ§æããã«ã¯ããããã¯ãªãã¯ããŠãã ããããã¯ãªãã¯ããã
ãèšŒææžã®ããããã£ãç»é¢ãéããããããµããžã§ã¯ããã¿ãã§ä»¥äžã®éãèšå®ãè¡ããããµããžã§ã¯ãåãã§ãçš®é¡ããããå ±éåããéžæããå€ã«ãsts.<ãã¡ã€ã³å>.mydns.jpãïŒãã®äŸã§ã¯ sts.mynavi.mydns.jpïŒãæå®ãã远å ããã¯ãªãã¯ã
ãå¥åãã§ãçš®é¡ããããDNSããéžæããå€ã«ãsts.<ãã¡ã€ã³å>.mydns.jpãïŒãã®äŸã§ã¯ sts.mynavi.mydns.jpïŒãæå®ãã远å ããã¯ãªãã¯ã
å€ã®èšå®ã¯ãããããééããªãããã«ãå€ãééãããšAD FSã¯æ£ããåäœããªããèšå®ãå®äºããããOKããã¯ãªãã¯ãããåã³ãèšŒææžã®èŠæ±ãç»é¢ã«æ»ãã®ã§ããSSL Certãããã§ãã¯ãããŠããããšã確èªããŠãç»é²ããã¯ãªãã¯ããã
æ£ããèšŒææžãç»é²ããããšãèšŒææžãã®é äžã«ãsts.<ãã¡ã€ã³å>.mydns.jpããç»é²ãããŠããã¯ãã ã
ãã®èšŒææžã¯AD FSã ãã§ãªãPRX1ã§ã䜿çšãããããã§ãä»ç»é²ããèšŒææžããã¡ã€ã«ãšããŠãšã¯ã¹ããŒãããŠããããšã«ããã以äžã®æé ã«æ²¿ã£ãŠãšã¯ã¹ããŒããããã
- èšŒææžãå³ã¯ãªãã¯ããŠããã¹ãŠã®ã¿ã¹ã¯ãããããšã¯ã¹ããŒãããã¯ãªãã¯ããã
- ãèšŒææžã®ãšã¯ã¹ããŒããŠã£ã¶ãŒãããèµ·åããã®ã§ããæ¬¡ãžããã¯ãªãã¯ã
- ãç§å¯ããŒã®ãšã¯ã¹ããŒããç»é¢ã§ã¯ãã¯ããç§å¯ããŒããšã¯ã¹ããŒãããŸãããéžæããŠã次ãžãã
- ããšã¯ã¹ããŒããã¡ã€ã«ã®åœ¢åŒãã§ã¯èŠå®å€ã®ãŸãŸïŒ.PFXïŒã次ãžãã
- ãã»ãã¥ãªãã£ãç»é¢ã§ã¯ãã°ã«ãŒããŸãã¯ãŠãŒã¶ãŒåãããã§ãã¯ããäžèЧã«<ãã¡ã€ã³å>\cloudadmin ã衚瀺ãããã®ã確èªããŠã次ãžãã
- ããã¡ã€ã«åãã«ä¿åå ãšããŠãã¹ã¯ããããæå®ãããããã¡ã€ã«å㯠sts.pfx ã§ããã ããã
æåŸã«ãå®äºããã¯ãªãã¯ãããšããã¹ã¯ãããã« sts.pfx ãšãããã¡ã€ã«åãä¿åãããããã®ãã¡ã€ã«ã¯ããšã§äœ¿çšããã®ã§ãã®ãŸãŸã«ããŠãããã
ADFSã®ã€ã³ã¹ããŒã«
ãµãŒããŒãããŒãžã£ãŒã®ã管çãã¡ãã¥ãŒããã圹å²ãšæ©èœã®è¿œå ããéžæããããŠã£ã¶ãŒããèµ·åãããããµãŒããŒåœ¹å²ã®éžæãç»é¢ãŸã§ã次ãžããã¯ãªãã¯ããŠé²ãã圹å²ã®äžèЧãããActive Directory Federation Servicesããéžæãããããã€ã³ã¹ããŒã«ãªãã·ã§ã³ã®ç¢ºèªãç»é¢ãŸã§ã次ãžããã¯ãªãã¯ããŠé²ã¿ããã€ã³ã¹ããŒã«ããã¯ãªãã¯ããã
ã€ã³ã¹ããŒã«ã¯1åçšåºŠã§å®äºããã
AD FSã®ã»ããã¢ãã
AD FSã®ã€ã³ã¹ããŒã«ãå®äºãããã»ããã¢ãããè¡ããããªãã¿ãšãªã£ãäœæ¥ã ãããµãŒããŒãããŒãžã£ãŒã®æå°ãã¯ãªãã¯ããŠããã®ãµãŒããŒã«ãã§ãã¬ãŒã·ã§ã³ãµãŒãã¹ãæ§æããŸãããã¯ãªãã¯ããã
æ§æãŠã£ã¶ãŒããèµ·åããããããã§ãã¬ãŒã·ã§ã³ãµãŒããŒãã¡ãŒã ã«æåã®ãã§ãã¬ãŒã·ã§ã³ãµãŒããŒãäœæããŸãããéžæãããŠããããšã確èªããŠã次ãžãã
ãActive Directory ãã¡ã€ã³ãµãŒãã¹ãžã®æ¥ç¶ãç»é¢ã§ã¯ãã¡ã€ã³ã³ã³ãããŒã©ã«å¯ŸããŠç®¡çè æš©éãæã£ãŠãããŠãŒã¶ãŒãæå®ãããæ¢å®ã§çŸåšã®ãŠãŒã¶ãŒãæå®ãããŠããã®ã§ãã®ãŸãŸã次ãžããã¯ãªãã¯ããããããµãŒãã¹ã®ããããã£ã®æå®ãç»é¢ã衚瀺ãããã以äžã®éãèšå®ããã
- ãSSLèšŒææžãã§ã¯å ã»ã©äœæããèšŒææž sts.mynavi.mydns.jp ãéžæã
- ãã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã¯æ¢å®å€ã®ãŸãŸã§OKã
- ãã§ãã¬ãŒã·ã§ã³ãµãŒãã¹è¡šç€ºåã¯é©åœãªæååãæå®ãããããã§ã¯ãMYNAVIããšæå®ããã
ããµãŒãã¹ ã¢ã«ãŠã³ãã®æå®ãç»é¢ã§ã¯AD FSãåäœãããããã®ãµãŒãã¹ã¢ã«ãŠã³ããæå®ãããããã§ã¯ååã®æŒç¿ã§äœæãã FsGMSA ãæå®ããããæ¢å®ã®ãã¡ã€ã³ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããŸãã¯ã°ã«ãŒã管çããããµãŒãã¹ã¢ã«ãŠã³ãã䜿çšããŠãã ããããéžæãããéžæããã¯ãªãã¯ã㊠FsGMSA ã¢ã«ãŠã³ããæ€çŽ¢ããæå®ããã
ãæ§æããŒã¿ããŒã¹ã®æå®ãã§ã¯æ¢å®å€ã®ãŸãŸã次ãžããæ¢å®ã§ã¯Windows Server ãæšæºã§æã£ãŠãã Internal Database ã䜿çšãããã
ããªãã·ã§ã³ã®ç¢ºèªãç»é¢ã§å 容ã確èªããããæ¬¡ãžããã¯ãªãã¯ããããã®åŸããåææ¡ä»¶ã®ç¢ºèªãããŒãžã§ç¹ã«ãšã©ãŒãç¡ããã°ãæ§æããã¯ãªãã¯ããŠã»ããã¢ãããå®äºããããã€ã³ã¹ããŒã«ã¯5åçšåºŠãèŠããã
æ§æãå®äºããã FS1 äžã§IE ãèµ·åãã以äžã®URLã«ã¢ã¯ã»ã¹ããŠã¿ããããªãããã®æŒç¿ã§ã¯ãã¡ã€ã³å㯠mynavi ã䜿çšããŠããã
https://sts.<ãã¡ã€ã³å>.mydns.jp/FederationMetadata/2007-06/FederationMetadata.xml
以äžã®ãããªç»é¢ã衚瀺ãããã ããããæååãåããŠããã®ã¯æ°ã«ããå¿ èŠã¯ãªããããã¯AD FSãäœæããã¡ã¿ããŒã¿ã§AD FSãµãŒãã¹ãèå¥ããããã®åçš®èšå®ã®éãŸãã ã
ããã«ã以äžã®URLã«ãã¢ã¯ã»ã¹ããŠã¿ãŠããã ãããã
https://sts.<ãã¡ã€ã³å>.mydns.jp/adfs/ls/idpinitiatedsignon.aspx
以äžã®ç»é¢ã衚瀺ããããããµã€ã³ã€ã³ããã¯ãªãã¯ããã
ãã°ãªã³çšã®ãã€ã¢ãã°ããã¯ã¹ã衚瀺ãããã®ã§ã管çè ã®IDãšãã¹ã¯ãŒããå ¥åãããOKããã¯ãªãã¯ããã
以äžã®ããã«ãµã€ã³ã€ã³ããããµã€ã³ã¢ãŠããã«å€ããã°æ£ãããµã€ã³ã€ã³ãããã
ä»åºŠã¯ãDS1ããäžèšURLã«ã¢ã¯ã»ã¹ã§ãããã確èªããŠããããæã ãFirewallã®èšå®ã«å€±æããŠããããšãããããã ãããããµãŒããŒãèŠã€ãããªãããªã©ã®çç±ã§æ¥ç¶ã§ããªãå Žåã¯ã以äžã®æé ã§Firewallã®èšå®ã確èªããå¿ èŠãããã
- FS1ã§ãããã¡ã€ã«åãæå®ããŠå®è¡ããããMMCããèµ·åããã
- ãã¹ãããã€ã³ã®è¿œå ãšåé€ããããã»ãã¥ãªãã£ã匷åããã Windows ãã¡ã€ã¢ãŠã©ãŒã«ããéžæããŠã远å ãããã
- ãåä¿¡ã®èŠåããå³ã¯ãªãã¯ããŠãæ°ããèŠåããéžæã
ãäºåå®çŸ©ããéžæããŠããã«ããŠã³ãããAD FSããéžæãããæ¬¡ãžããã¯ãªãã¯ããã
èŠåããã¹ãŠãã§ãã¯ããŠã次ãžããã¯ãªãã¯ããã
ãæ¥ç¶ãèš±å¯ããããéžæãããŠããããšã確èªããŠãå®äºããã¯ãªãã¯ãããåä¿¡ã®èŠåç»é¢ã§ä»¥äžã®ããã«AD FSã®ã¢ã¯ã»ã¹ã«ãŒã«ãèšå®ãããŠããã°OKã
以äžã§AD FSã®èšå®ã¯å®äºããã
次åã¯AD FSãå€éšã«å ¬éããããã®ãªããŒã¹ãããã·ãŒãWeb Application Proxyãã®ã»ããã¢ãããè¡ãã䜿çšãããµãŒãã¯PRX1ã ã
ç·šéåå:ãŠããŸã³
å®çŽ é äž
æ¥æ¬ãã€ã¯ããœãã ãã¯ãã«ã« ãšãã³ãžã§ãªã¹ã
äž»ã«ã€ã³ãã©ç³»ãã¯ãããžãŒã®æ¥æ¬åžå Žãžã®èšŽæ±ãæ åœãè¿å¹Žã¯ãããªãã¯ã¯ã©ãŠãäžã®ã¢ã€ãã³ãã£ãã£ã»ãããã€ããŒã§ããAzure Active DirectoryãæŽ»çšããã»ãã¥ãªãã£åºç€ã®ãã¶ã€ã³ãå®è£ æ¹æ³ãªã©ãã¡ã€ã³ã®ãã£ãŒã«ãã§ããã
Technetã§å人ããã°ãããŸããŸãªæè¡æ å ±ãçºä¿¡ããŠããã


























