Active Directoryã¨Hudson/Javaã®çµ±å
Active Directoryã¨Javaã®ãå¯ãé¢ä¿ã«ã¤ãã¦ãã¾ãHudsonãcom4jã使ããã¨ã§ã©ããã£ã¦ã¼ãã»ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ã®Active Directoryçµ±åãå®ç¾ããã®ãã以åã«æ¸ãã¾ãããããã¯Windowsä¸ã§Hudsonã使ã£ã¦ããã¦ã¼ã¶ã¼ã«ã¯å¤§å¤ä¾¿å©ã ã£ãã®ã§ãããä¸æ¹ããã®å¾ãActive Directoryã§ç®¡çããã¦ãããã¡ã¤ã³ã®ä¸ã§åãã¦ããUnixãã·ã³ä¸ã§ãHudsonã使ã£ã¦ãã人ãæå¤ã«å¤ããã¨ãåããã¾ãããUnixã§ã¯COMã¯ä½¿ããªãã®ã§ã¾ã£ããç°ãªãã¢ããã¼ããå®è£ ããå¿ è¦ãããã¾ããããå æ¥ãããã£ã¨Hudsonã®Active Directoryãã©ã°ã¤ã³ãUnixã§ãåãããã«ãã¦å ¬éãããã¨ãã§ãã¾ããããã¡ãã¯æ®å¿µãªããã¼ãã»ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ã§ã¯ãªãã®ã§ãããå ¥åãããã£ã¼ã«ãã¯Active Directoryãã¡ã¤ã³åã®ä¸ã¤ã ãã§ãã
ã°ã¼ã°ã«å çã«ããã¨ãæ§ã ãªã¢ããªã±ã¼ã·ã§ã³ã§æªã ã«Active Directoryãçµ±åããã®ã«è¦å´ãã¦ãã人éãå¤ãããããã§ãããããã«å ±éã®çç¶ã¯ãæ±ç¨ã®LDAPãããã¯JNDIèªè¨¼ã使ããã¨ãã¦ãè¨å®é ç®ã®å¤ãã®ãã¾ãã«ã©ããã§ééãããã¨ãããã¿ã¼ã³ã§ããããã¯ãHTTPãTCP/IPã使ã£ã¦ããããã¨ãã£ã¦HTTPã³ãã³ããæã§å ¥åãããããªãä¸è¬ã®ã¦ã¼ã¶ã¼ã«ã¨ã£ã¦ã¯ãæ ¹æ¬çã«ééã£ãã¢ããã¼ãã§ãã
ããã§ãJavaããActive Directoryã§èªè¨¼ãè¡ãããã®ããã°ã©ã ãããå¤ãæ¸ãããããã«ã¨ããã®æé ãã¾ã¨ãã¦ã¿ã¾ããã
ãã®ï¼ï¼LDAPãµã¼ããçºè¦ãã
ã¾ããã_ldap._tcp.DOMAINNAME.ãã«å¯¾ãã¦DNS SRVã¬ã³ã¼ããåå¾ãã¦ãã¡ã¤ã³å ã®LDAPãµã¼ããçºè¦ãã¾ããããActive Directoryå ã®DNSããã£ã¦ãããã®æã®è¿½å ã¨ã³ããªã«é¢ãã¦ã¯ãã®MSDNè¨äºãåç §ãã¦ãã ãããã¾ããJavaSEã®ããã¥ã¡ã³ãã«ã¯JNDIçµç±ã§DNSã¨å¯¾è©±ããæ¹æ³ãæ¸ããã¦ãã¾ãã
ããã«ãããã¦ã¼ã¶ã¼ã¯LDAPãµã¼ãã¼ããã¼ãã³ã¼ãããå¿ è¦ããªããªãã¾ãããã¡ã¤ã³ã³ã³ããã¼ã©ã追å ããããéå½¹ããããã¦ã大ä¸å¤«ã§ãããé害対çã«è¤æ°ã®LDAPãµã¼ããåãã¦ãããããªç°å¢ã§ãæ£ãããã§ã¤ã«ãªã¼ãã¼ãè¡ãã¾ãã
ãã®ï¼ï¼èªè¨¼ãã
LDAPãµã¼ãã®ãã¹ãåã¨ãã¼ãçªå·ãããã£ãããLDAPãµã¼ãã¨ããã¨ããããæéã§ããããã«ããJNDIã使ãã¾ããLDAPã§ã¯ããã¹ã¯ã¼ããæ£ãããã©ããã¯ããã®ãã¹ã¯ã¼ãã使ã£ã¦LDAPãµã¼ãã«æ¥ç¶ã試ã¿ããã¨ã§è¡ããã¾ããã¨ãããæ®å¿µãªäºã«ãæ±ç¨ã®LDAPèªè¨¼ã³ãã¯ã¿(ããã¨ã)ã¯ãããªãåããã©ãæ¹æ³ã使ã£ã¦ããããã¾ããã¾ãåãã«ä¸åº¦LDAPã¨æ¥ç¶ãã¦ãããããèªè¨¼ãããã¨ãã¦ããã¦ã¼ã¶ã¼ã®ä¸æãªååãå¾ã¾ãï¼CN=Kohsuke Kawaguchi,DN=sun,DN=comã¿ãããªï¼ãããããä»åº¦ã¯ãã®ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã使ã£ã¦æ¥ç¶ãããªããã¾ãããããæåããã°ãã¹ã¯ã¼ãã¯ãã£ã¦ããã®ã§èªè¨¼ãæåããã¨è¦ãªãã失æããã°ãã¹ã¯ã¼ãã¯ééã£ã¦ããã®ã§èªè¨¼ã¯å¤±æã§ãããããå¿ è¦ãªã®ã¯LDAPãµã¼ãã«ã¨ã£ã¦ã®ã¦ã¼ã¶ã¼åã¯ãã®ä¸æãªååã§ããå¿ è¦ããã£ã¦ãããããUnixã¦ã¼ã¶ã¼IDã®ãããªå½¢å¼ã¯ä½¿ããªãããã§ãã
Active Directoryã«ã¨ã£ã¦ã¯ããããããã®æ¹æ³ã¯é常ã«æªãããæ¹ã§ããã¨ããã®ããActive Directoryã¯ãã£ãã©ã«ãã§ã¯å¿åã§ã®æ¥ç¶ããµãã¼ããã¦ããªãã®ã§ãèªè¨¼ãè¡ãããã°ã©ã ã¯å°ãªãã¨ãä¸ã¤ã®æå¹ãªã¦ã¼ã¶ã¼åã»ãã¹ã¯ã¼ããæã£ã¦ããªãã¨ãæåã®ãã¦ã¼ã¶ã¼ã®ä¸æãªååãå¾ããã¹ããããã§ããªãã®ã§ãããã®ãããèªè¨¼ããã¢ããªã±ã¼ã·ã§ã³ã«ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ããè¨å®ãã¦ããå¿ è¦ãããã¾ããæªã§ãããããããActive Directoryã®LDAPãµã¼ãã¯å¥ã®æ¹æ³ã§èªè¨¼ãå¯è½ã§ããã¦ã¼ã¶ã¼ã®ä¸æãªååãå¾ããããã«ãåã«ã[email protected]ãã®ããã«å®å ¨ä¿®é£¾ãããã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã ãã§æ¥ç¶ã§ãã¦ãã¾ãã®ã§ããActive Directoryå°ç¨ã«ã³ã¼ããæ¸ãã°ããã®ããã«èªè¨¼ãããã¨ã§ããããããããã¼ã¸ã£ã¼DN/passwordãã¨å¼ã°ãããã¼ãã³ã¼ãããããã¹ã¯ã¼ããå¿ è¦ãªããªãã¾ãã
ãã¦ãLDAPæ¥ç¶ã«ä¸æ¦æåããããã¦ã¼ã¶ã¼ã»ã°ã«ã¼ãã¡ã³ãã¼ã·ããã®æ
å ±ããé»åã¡ã¼ã«ã¢ãã¬ã¹ãªã©ã使ããæ
å ±ããã£ã±ãã§ããã©ã®ãããªæ
å ±ããããã®è©³ç´°ã¯ãMSDNã®è¨äºã詳ããã§ããã¾ããä½ããã®LDAPãã©ã¦ã¶ãããã¨éçºã«ä¾¿å©ã§ãã
ã¾ã¨ã
ãã詳細ã§å ·ä½çãªæ¹æ³ã«ã¤ãã¦ã¯ãã½ã¼ã¹ã³ã¼ããåç §ãã¦ãã ããããããããªãã®ã使ãã®ãã¼ã«ãLDAPæ¥ç¶ãè¨å®ãã¦Active Directoryã¨çµ±åãããã¨æ¸ãã¦ãã£ãããããããçµ±åãè¦æ±ãã¾ãããã
ã»ãã¥ãªãã£é¢ä¿ã®æ¬¡ãªãç®æ¨ã¯ãIntegrated Windows Authenticationã®ãµãã¼ãã§ãããããã§ããã°ãHudsonã¯Windowsã®ã·ã³ã°ã«ã»ãµã¤ã³ãªã³ã«å¯¾å¿ã§ãããã¨ã«ãªãã¾ãããã®æ©è½ã¯Hudson以å¤ã®ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã«ã¨ã£ã¦ã大å¤æç¨ã§ãããã