ã·ãã¬ã¹(Shibboleth)SPç¨ã®ã¡ã¿ãã¼ã¿(metadata)ãä½æããã¨ãã«ã誤ã£ã¦XMLã¹ãã¼ããå¤æ´ããã¨ã©ã¼ãçºçãããã¨ãããã®ã§ãã¡ã¿ãã¼ã¿ã®çæãæ¯æ´ãããã¼ã«ãä½ãã¾ãããã¡ã¿ãã¼ã¿ã®å½¢å¼ã¯ãUPKI-å¦è¡èªè¨¼ãã§ãã¬ã¼ã·ã§ã³1)ã«å¯¾å¿ãã¦ãã¾ãï¼å¦èª:Gakunin対å¿ï¼ã ï¼ï¼ãâ ã®ãåºæ¬ï¼µï¼²ï¼¬ãã¨â¡ã®ãæ©é¢ã»æå±åããå ¥åãã¦ããèªåè¨å®ããã¿ã³ãã¯ãªãã¯ããã¨ãä¸é¨ã®å±æ§ãæ¨æºçãªè¨å®ã«ãªãã¾ãããèªåçã«å ¥åããã¾ãã ï¼ï¼ã次ã«ãåå±æ§æ å ±ãä¿®æ£ãã¦ãã ãããç¹ã«ãX.509ã®è¨¼ææ¸ã¨é£çµ¡å ã®Emailã¯ãèªåçæããã¾ããã®ã§ãã注æãã ããã ï¼ï¼ãçæã»ï¼¸ï¼ï¼¬ãã¦ã³ãã¼ãããã¿ã³ãã¯ãªãã¯ããã¨ãã¡ã¿ãã¼ã¿ãçæããããã¦ã³ãã¼ãã§ãã¾ãã ï¼ï¼æå¾ã«ããã¦ã³ãã¼ãããXMLãã¡ã¤ã«ã確èªãã¦ãã ããããã°ãªã©ãããã¾ãããããå ±åãããã ãã¾ãã¨
Build SP Metadata Build the XML metadata of a SAML Service Provider providing some information: EntityID, Endpoints (Attribute Consume Service Endpoint, Single Logout Service Endpoint), its public X.509 cert, NameId Format, Organization info and Contact info. This metadata XML can be signed providing a public X.509 cert and the private key.
SP Metadata 以ä¸ã®ä¾1,2ãè¦ã¤ãã£ãã®ã§ãã¡ã¢ã¨ãã¦èªåã®ããã°ã¨ã£ã¦ããããã¨æãã¾ããã å ã«SAML2.0ãããã³ã«ã®ä½¿ãã¿ã¡ãèªç±ã«ãªã£ã¦ãããä½ãã©ã対å¿ãããé£ããã§ããããã å人çã«ããã¾ãæ©ããã¨ããã¾ãã®ã§ãè£è¶³ãã¦æ¸ãã¦ããããã¨æãã¾ãã ä¾:1 <EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://SP-HostName/shibboleth-sp"> â ãã¹ãå <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol"> <Extensions> <idpdis
ããã«ã¡ã¯ãSlashãã¼ã ã®æ¸¡è¾ºã§ãã Slashãã¼ã ã§ã¯ãã¦ã¼ã¶ã¼ç®¡çãèªè¨¼å¨ããªã©ã®ãcybozu.comã®åãµã¼ãã¹ã«å ±éããæ©è½ãéçºãã¦ãã¾ããä»åã¯ã3æã«ãªãªã¼ã¹ããããSAMLèªè¨¼ãç¨ããã·ã³ã°ã«ãµã¤ã³ãªã³æ©è½1ã«ã¤ãã¦ã話ããã¦é ãã¾ããcybozu.comã§ã®SAMLèªè¨¼ã®æ¦è¦ã«ãããã¦ããããã®æ©è½ãã©ã®ããã«è¨è¨ã»å®è£ ãã¦ãã£ãããã¨ãã誰ãèå³ãªãããããªè©±é¡ãæ±ãã¾ãã SAML2 ã£ã¦ï¼ ãSAMLãªãã¦èãããã¨ç¡ããã©ãªãã¨ãªãèå³ããããï¼ï¼ãã¨ããç©å¥½ããªæ¹ã®ããã«ãSAMLã®æ¦è¦ã¨cybozu.comã§ã®å©ç¨ã«ã¤ãã¦ãç°¡åã«èª¬æãã¾ãããããªãã®ã¯æ¢ã«ç¥ã£ã¦ããã¨ããSAMLçè ãªæ¹ã¯èªã¿é£ã°ãã¦é ãã¦æ§ãã¾ããã SAMLã¯Security Assertion Markup Languageã®ç¥ã§ãOASIS3ã«ãã£ã¦çå®ããããç°ãªãã»ãã¥ãª
åæ© Java, C++ â Scalaã¨ãã£ã¦ãã¦ãæ°ã¥ãããã¨ã¯JavaããScalaã«åãç¶ãããã®ã¯JVMã¨ãã¦ã®ä¾¿å©ãã ãã§ãããé¢æ°åè¨èªçè¦ç´ ã¯ãããHaskellããåãç¶ããã¦ããã¨ãããã¨ã ããã£ãã調æ»çã¯Yodobashiã§ä»¥ä¸ãè³¼å ¥ããã ãããHaskellãã®ããå¦ã¼ãï¼ ä½è : Miran Lipovacaåºç社/ã¡ã¼ã«ã¼: ãªã¼ã 社çºå£²æ¥: 2012/09/21ã¡ãã£ã¢: Kindleçè³¼å ¥: 4人 ã¯ãªãã¯: 9åãã®ååãå«ãããã°ãè¦ã ããã°ã©ãã³ã°è¨èªã«ãããå¦ç¿ã§ã¯æ°ããæ¦å¿µãç¥ããã¨ã大äºã ã¨æã£ã¦ããã®ã§ï¼â¦ãã¡ããã¢ã«ã´ãªãºã ãéè¦ã ããã¢ã«ã´ãªãºã ã¯æ¦å¿µã«ããããªãå¤åããï¼ãæ°ããèãæ¹ã ã¨æãããã¨ãä¸å¿ã«ã¡ã¢ããã èªã¿é²ããã¨ãã«ã¯ã以ä¸ãè¦ãªããã ã¨é¢ç½ã Scalaã³ã¬ã¯ã·ã§ã³ã¡ã½ããã¡ã¢(Hishidama's Scala
SAMLèªè¨¼ã«é¢ããããã°ã©ãã³ã°ããã£ã¨ç¶ãã¦ããã®ã§ããããã§å°ãããããããã¾ã¨ãã¨èå¯ãæ¸ãããã ç¨èªèª¬æ SP-initiated SAML IdP-initiated SAML SAMLã®XMLã®ä¸èº« <AuthnRequest> <Response> 誰ãã®ï¼ç§ã®ããã«ï¼æéãããã°ãã 便å©ãªãã¼ã«ãããã¥ã¡ã³ããªã© ã¾ããSAMLã¯ã ãããï¼ç¨®é¡ã«åãããããSP-initiated SAMLã¨IdP-initiated SAMLã ã ç¨èªèª¬æ SPã¨ã¯Service Providerã®ç¥ã§WEBãµã¼ãã¹ã®æä¾å´ãæã(ä¾ï¼Cybozu, Dropboxï¼ IdPã¨ã¯Identity Providerã®ç¥ã§IDãIDã®ãã¤æ å ±ã®æ£å½æ§ãä¿è¨¼ããå´ãæã(ä¾ï¼AWS, Google, Salesforce ãããã¯OpenAM, CA SiteMinderã®ãããªIdPã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}