ããã«ã¡ã¯ã Azure Identity ãµãã¼ã ãã¼ã ã®å°åºã§ãã æ¬è¨äºã¯ã 2022 å¹´ 1 æ 25 æ¥ã«ç±³å½ã® ITOps Talk Blog ã§å ¬éããã Deep dive: How Azure AD Kerberos works ãæè¨³ãããã®ã«ãªãã¾ããã䏿ç¹ãªã©ãããã¾ãããããµãã¼ã ãã¼ã ã¾ã§ãåãåãããã ããã Active Directory (AD DS) 㨠Azure Active Directory (Azure AD) ã®éãã調ã¹ããã¨ãããã°ãActive Directory 㯠Kerberos èªè¨¼ãããã³ã«ããµãã¼ããã¦ãã䏿¹ãAzure Active Directory ã§ã¯ãµãã¼ããã¦ããªããã¨ã«æ°ãã¤ãã¯ãã§ãã Kerberos ã¯ãActive Directory ãã¡ã¤ã³ ã³ã³ããã¼ã©ã¼ã§ã¢ã«ã¦ã³ããèªè¨¼ããããã«ä½¿ç¨ã
ã¯ããã«ããã«ã¡ã¯ãTIG ã®å岡ã§ããç§ã®ããã°é±é 10 æ¬ç®ã®æç¨¿ã§ãã 2022å¹´ã® 5 æã« Apple, Google, Microsoft ãã㦠FIDO Alliance ã ãã«ãããã¤ã¹å¯¾å¿FIDOèªè¨¼è³æ ¼æ å ± ãçºè¡¨ãã¦ããããã¹ã¯ã¼ãã¬ã¹æè¡ã«å¯¾ããæ³¨ç®ãé«ã¾ã£ã¦ãã¾ãã1 ãã¹ã¯ã¼ãã¬ã¹ã®æ¦è¦ã«ã¤ãã¦èª¿æ»ãã¦ã¾ã¨ãã¦ã¿ã¾ããã ç®æ¬¡ ç§ãã¡ã¨ãã¹ã¯ã¼ã ãã¹ã¯ã¼ãã®æ±ããåé¡ ãã¹ã¯ã¼ãããã¼ã¸ã£ å ¬é鵿å·ã®æ´»ç¨ ãã¹ã¯ã¼ãã¬ã¹ã¨ FIDO Alliance FIDO v1.0 FIDO2 FIDO ã®èªè¨¼ããã¼ Passkeys ãã¹ã¯ã¼ãã¬ã¹ãªæªæ¥ ç§ãã¡ã¨ãã¹ã¯ã¼ã仿¥ãç§ãã¡ã®ãã¸ã¿ã«ã¢ã¤ãã³ãã£ãã£ã¯ãã¹ã¯ã¼ãã«æ¯ãããã¦ãã¾ããç§ãã¡ã¯æ¥ã Google ã§æ¤ç´¢ããNetflix ã観ã¦ãTwitter ã§ã¤ã¶ãããAmazon ã§è²·ãç©ããã¾ãã
GTAæ°ä½ãªã¼ã¯ã«ä½¿ãããâå¤è¦ç´ èªè¨¼ç²ãâæ»æã¨ã¯ã1æé以ä¸éç¥æ»ãã徿¥å¡ã®æ ¹è² ãçãï¼ãã®é ãã»ãã¥ãªãã£çé㧠人æ°ã²ã¼ã ãã°ã©ã³ãã»ã»ããã»ãªã¼ããï¼GTAï¼ãªã©ãææããã²ã¼ã ã¡ã¼ã«ã¼ã®ç±³Rockstar Gamesãç±³Uber Technologiesã®ãããã¯ã¼ã¯ã䏿£ä¾µå ¥ãåããæ å ±ãæµåºããäºä»¶ãç¸æ¬¡ãã ãåããããªè¢«å®³ã¯éå»ã«MicrosoftãCiscoãTwitterãªã©ã®å¤§æã§ãçºçãã¦ãããå社ã¨ããããããä¾µå ¥ãé²ãããã«å¤è¦ç´ èªè¨¼ãè¨å®ãã¦å¾æ¥å¡ã®ã¢ã«ã¦ã³ããä¿è·ãã¦ããããæ»æè ã¯ãMFA Fatigueï¼å¤è¦ç´ èªè¨¼ç²ãï¼ãæ»æã¨å¼ã°ããæå£ã使ã£ã¦MFAï¼å¤è¦ç´ èªè¨¼ï¼ãçªç ´ãã¦ããã å¤è¦ç´ èªè¨¼ã§å®ãããã¢ã«ã¦ã³ãã¯ãã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ããå ¥åãã¦ãã°ã¤ã³ãããã¨ããã¨ãç»é²ããã端æ«ã«é»è©±ãããããããã·ã¥éç¥ãéä¿¡ãããããæ¹æ³ã§ããã®ãã°ã¤ã³
S03_ã¾ãã¯ããããï¼Microsoft 365 E3 ã§ã»ãã¥ãªãã£ã®ç¬¬ä¸æ©ãè¸ã¿åºã [Microsoft Japan Digital Days]
7payãä¸ã®ä¸ãé¨ããã¦ã2段éèªè¨¼ã¨ããè¨èããããã¯ã¼ãã¨ãªã£ãããã¦ã¾ãããããããæ±ºæ¸ãµã¼ãã¹ã®ã»ãã¥ãªãã£ãå®ãã«ã¯ãå¤è¦ç´ èªè¨¼ã(Multi-Factor Authentication)ã大åã§ããâ¦â¦ã¨ããã§å¤è¦ç´ èªè¨¼ã£ã¦ãªãã§ããã£ãï¼ Twitteræç¥¨ã§ã¯ã¤ãºãåºãã¦ã¿ãã¨ããâ¦â¦ï¼
ããã«ã¡ã¯ã仿¥ã¯è¶£åãå¤ãã¦å代ç°åºç«å³æ¸é¤¨ã«æ¥ã¦ã¿ã¾ããã www.library.chiyoda.tokyo.jp 峿¸é¤¨ã¯æ®æ®µããã¾ãè¡ããªãã®ã§ãå°å ã®å³æ¸é¤¨ã¨ã®éãã«é©ãã§ããã é½å ã®å³æ¸é¤¨ã£ã¦åºãã綺éºã§ããã 乿®µä¸ããå²ã¨è¿ããç½®ãã¦ããèµæ¸ã®ã¸ã£ã³ã«ãå¤ããå¸ã®ã¸ã£ã³ã«å¤ããç¡ç·Wifiããã黿ºãããã§ããªã使ããããã£ãã§ãã éãã§è½ã¡çããé°å²æ°ã§éãããããæ°ããã¾ãããç¡é³ãªã®ã§ç¬ãè¨ãå¤ãäººã¯æ°ãã¤ãã¦ãã ããã ãã¦ãååã®è¨äºã«ã¤ãã¦@okeee0315ãããããããªã³ã¡ã³ããã èªè¨¼åãã¯å¤§äºãADã®åã«èªè¨¼ã¨èªå¯ãå¿ è¦ãã / ADãªã«ãããããããªã(æ³£) - ã©ãã¾ããã®ãã¿å¸³ https://t.co/MEFI6o5qNAâ okeee (@okeee0315) 2016å¹´5æ3æ¥ ã»ã»ããADã¯ã¾ã ç¾å³ãããªãã£ãã®ã§ãæãã«å¾ãèªè¨¼å¨ã
GoogleãMozillaããã¤ã¯ãã½ããããWebAuthnãã®å®è£ ãéå§ãããã«ãã£ã¦ãFIDO2ãã®æ®åãæå¾ ãããWebãã©ã¦ã¶ããæç´èªè¨¼ãé¡èªè¨¼ãªã©ã§ç°¡åã«Webãµã¤ãã¸ã®ãã°ã¤ã³ãæ¯æãã®æ¿èªã¨ãã£ãæä½ãå®ç¾ããããã ã ITã¸ã£ã¼ããªã¹ãï¼Publickeyããã¬ã¼ã大å¦ã§UNIXãå¦ã³ãæ ªå¼ä¼ç¤¾ã¢ã¹ãã¼ã«å ¥ç¤¾ããã¼ã¿ãã¼ã¹ã®ãã¯ãã«ã«ãµãã¼ããæåã¢ã¹ãã¼NTç·¨éé¨ å¯ç·¨éé·ãªã©ãçµã¦1998å¹´é社ãããªã¼ã©ã³ã¹ã©ã¤ã¿ã¼ã«ã2000å¹´ãæ ªå¼ä¼ç¤¾ã¢ãããã¼ã¯ã»ã¢ã¤ãã£è¨ç«ã«åç»ããªã³ã©ã¤ã³ã¡ãã£ã¢é¨éã®å½¹å¡ã¨ãã¦2007å¹´ã«IPOãå®ç¾ã2008å¹´ã«é社ãåã³ããªã¼ã©ã³ã¹ã¨ãã¦ç¬ç«ãã2009å¹´ã«ããã°ã¡ãã£ã¢Publickeyãéå§ãç¾å¨ã«è³ãã å¤ãã®Webã¢ããªã±ã¼ã·ã§ã³ã¯ãã¦ã¼ã¶ã¼ã®èªè¨¼ã«ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã®çµã¿åãããç¨ãã¦ãã¾ãã ãããã¦ã¼ã¶ã¼åã¨ãã¹
調æ»ä¼ç¤¾IDC Japanã®ã¬ãã¼ãã«ããã°ãã¯ã©ã¦ãã»ãµã¼ãã¹ããã§ã«å©ç¨ãã¦ãã伿¥ã¦ã¼ã¶ã¼ã®56ï¼ ä»¥ä¸ãããã®é¸æçç±ã¨ãã¦ã©ã³ãã³ã°ã»ã³ã¹ãã¨åæå°å ¥ã³ã¹ããæããã¨ã®ãã¨ã ï¼IDC Japanã®ãå½å ã¯ã©ã¦ããµã¼ãã¹å¸å ´ã¦ã¼ã¶ã¼åå調æ»çµæãçºè¡¨ãï¼ããã®ããã«ã¯ã©ã¦ãã»ãµã¼ãã¹ã¯ãæ¨ä»ã®å³ããçµæ¸æ å¢ã«ããã伿¥ITã·ã¹ãã ã®ã³ã¹ãã忏ããæ¹çã¨ãã¦æ³¨ç®ãéãã¦ããã ã¨ã¯ãã£ã¦ãããããªãç¾è¡ã®ç¤¾å ã·ã¹ãã ãã¹ã¦ãã¯ã©ã¦ãã«ç§»è¡ã§ããããã§ã¯ãªãã代æ¿ã§ãããã®ã¯ã¯ã©ã¦ãã»ãµã¼ãã¹ã«ç§»è¡ãã¤ã¤ãå¿ è¦ãªãµã¼ãã¹ã¯ç¤¾å ã·ã¹ãã ã«ã¨ã©ããã®ãç¾å®ã ããã 社å ã·ã¹ãã ã¨ã¯ã©ã¦ãã»ãµã¼ãã¹ãä½µç¨ããéã®èª²é¡ã®1ã¤ã¨ãã¦ãã¦ã¼ã¶ã¼ã»ã¢ã«ã¦ã³ããã¯ããã¨ããã¦ã¼ã¶ã¼æ å ±ã®åãæ±ããæãããããã¨ã³ãã¦ã¼ã¶ã¼ã«ã¨ã£ã¦ã¯ã社å ã·ã¹ãã ã¨ã¯ã©ã¦ãã»ãµã¼ãã¹ãå¥ã ã®ã¦ã¼ã¶ã¼ã»ã¢ã«ã¦ã³ãã§å©ç¨ã
Linuxã§ç¨¼åããã¦ããApacheã«ã¦èªè¨¼ãå¿ è¦ãªWebãµã¼ãã¹ã«ãWindowsãã¡ã¤ã³(Active Directory)ã®èªè¨¼æ å ±ã使ã£ã¦ãã·ã³ã°ã«ãµã¤ã³ãªã³ãå®ç¾ãããã¾ã§ã®æé ãåå¿é²ã¨ãã¦æ®ãã¦ããã¾ãã ä»åããã©ã¦ã¶ã¯ãIEã¨Firefoxã«ã¦åä½ç¢ºèªãè¡ãã¾ããã Windowsãã¡ã¤ã³ãã°ãªã³ããã¦ããã¯ã©ã¤ã¢ã³ããããä¸è¨2種é¡ã®ãã©ã¦ã¶ã使ãã¨ãNTLMèªè¨¼â»ãå©ç¨ãã¦ããWebãµã¼ãã¹ã«ã¯ãèªè¨¼æ¸ã¿ã®ãã¡ã¤ã³ãã°ãªã³ã®æ å ±ãå©ç¨ãããã¨ãã§ããã¦ã¼ã¶åããã¹ã¯ã¼ããå ¥åããå¿ è¦ã®ç¡ãã·ã³ã°ã«ãµã¤ã³ãªã³ç°å¢ãå®ç¾ã§ãã¾ãã â»NTLMèªè¨¼ï¼NT LAN Manager authenticationï¼ã¨ã¯ - ITç¨èªè¾å ¸ e-Words åæ ä»åå©ç¨ããæ§æã¯ä»¥ä¸ã®ãããªæãã Webãµã¼ã CentOS 5 Apache 2.2 + mod_auth_ntl
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}