ã»ãã¥ãªãã£ã¬ãã¼ãã«å¯¾ããOktaã®è¦è§£
2022å¹´7æ19æ¥ãããã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãä¼ç¤¾ããOktaãµã¼ãã¹ã®ç¹å®ã®æ©è½ã®ã»ãã¥ãªãã£ã«é¢é£ãã主張ãããã°è¨äºã§å ¬éãã¾ãããããã°è¨äºã®å ¬éã«å ç«ã¡ããã®ã»ãã¥ãªãã£èª¿æ»ä¼ç¤¾ã¯Oktaã«é£çµ¡ãã調æ»çµæã®æè¡çãªè©³ç´°ãå ±æãã¾ãããå¼ç¤¾ã®å¾¹åºçãªæ¤è¨¼ã®çµæã社å ã®è£½åãã¼ã ããã³ã»ãã¥ãªãã£ãã¼ã ã¯ãææãããæ¸å¿µäºé ã¯èå¼±æ§ã§ã¯ãªããã¨ã確èªãã¾ããã以ä¸ã«ãã»ãã¥ãªãã£ã«é¢ãããã¹ããã©ã¯ãã£ã¹ã®æ¨å¥¨äºé ãè¨è¼ãã¾ãã
ç§ãã¡ã®ç®æ¨ã¯ãã客æ§ãå¿ è¦ã¨ãããããããã¯ããã¸ã¼ã«ç¢ºå®ã«æ¥ç¶ã§ãããããã客æ§ã®è¦ä»¶ãçµ±åãèæ ®ããªãããã客æ§ããµãã¼ããããã¨ã§ãã解決ããªããã°ãªããªãç¬èªã®èª²é¡ãæã¤å¤ãã®ã客æ§ãæ±ãã¦ãããããå¹ åºãæ§æãªãã·ã§ã³ããµãã¼ããã¦ãã¾ãããããã®è¨å®ãªãã·ã§ã³ã®ä¸ã«ã¯ãHTTPSã®ä»£ããã«HTTPãæå¹ã«ãããªã©ãå®å ¨æ§ãä½ããã®ãããã¾ããã¾ãã移è¡ã·ããªãªãã·ã¹ãã çµ±åãæ¡å¼µæ§ããµãã¼ãããããã«ãã¯ãªã¢ããã¹ãã®èªè¨¼æ å ±ã®ä½¿ç¨ãå«ãåææ©è½ãæä¾ããã客æ§ãè¤éãªã¦ã¼ã¹ã±ã¼ã¹ã解決ãããã¨ãå¯è½ã«ãã¦ãã¾ãããªããä¿åãããã¯ã¬ãã³ã·ã£ã«ã¯ãã¹ã¦ãã客æ§åºæã®æå·éµãç¨ãã¦æå·åããã¾ãã
Oktaã®ã客æ§ã®å ´åãä½ããã¹ãã
Oktaã®ã客æ§ã«ã¯ã以ä¸ã®ãã¹ããã©ã¯ãã£ã¹ãæ¨å¥¨ãã¦ãã¾ããã客æ§ã®ç¹å®ã®æ§æã«ç §ããåããã¦ãæ¤è¨ãã ããã
- 常ã«HTTPSã使ç¨ãã¦ããã¼ã¿ã®å®å ¨ãªä¼éã確ä¿ããã
- ãã¹ã¦ã®ã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã§MFAãæå¹ã«ããã管çè ã¢ã«ã¦ã³ãã®MFAã¯è²ããªããã®ã§ãããOktaã®ããã©ã«ãã§æå¹ã«ãªã£ã¦ãã¾ããOktaã§ã¯ã管çè ã ãã§ãªãããã¹ã¦ã®ã¦ã¼ã¶ã¼ãèªåã®ã¢ã«ã¦ã³ãã§MFAãè¦æ±ãããã¨ãæ¨å¥¨ãã¦ãã¾ãã
- 管çè ãã¼ã«ã®å²ãå½ã¦ã«ã¤ãã¦ã®ã¢ã¯ã»ã¹ã¬ãã¥ã¼ãå®æçã«å®æ½ãã管çè ã¢ã¯ã»ã¹ã許å¯ãããæ å½è ã«éå®ããã¦ãããã¨ã確èªããã
- ããç´°ãã権éãä»ä¸ããããã«ãã«ã¹ã¿ã 管çè ãã¼ã«ãã¬ã¼ã ã¯ã¼ã¯ã使ç¨ããå§ä»»ç®¡çã·ããªãªã®ä½¿ç¨ãæ¤è¨ããã
- åOkta管çã³ã³ã½ã¼ã«ã®ãã°è¨é²ãã©ãããã©ã¼ã ã§ããOkta System Logã«è¨é²ããã管çè ãè¡ã£ãã¢ã¯ã·ã§ã³ãç£è¦ããå®æçã«ã¬ãã¥ã¼ããã
- Sync Passwordï¼ãã¹ã¯ã¼ãã®åæï¼æ©è½ãå¿ è¦ãªå ´åã®ã¿æå¹ã«ãªã£ã¦ãããã¨ã確èªããããã®æ©è½ã¯ãä¸æµã·ã¹ãã ã«ãã¹ã¯ã¼ããããã·ã¥ãã¦Oktaã¨åæãããæ©è½ãæä¾ãããã®ã§ãç¸äºéç¨æ§ã¨ãã¤ããªããIDå±éã®ããã®ç¹å¥ãªã±ã¼ã¹ã§ã®ã¿ä½¿ç¨ããã¾ããããã¯ãApps APIã¨Roles APIã§èªååã§ãã¾ãã
- Federated IDãããã¤ãã使ç¨ããã客æ§ã¯ãRegEx Filterã確èªãããããæå³ããã¦ã¼ã¶ã¼ã®ãµãã»ããã«èªè¨¼ãé©åã«å¶éãã¦ãããã¨ã確èªãã¦ãã ããã
- Hub & Spoke ã¢ã¼ããã¯ãã£ï¼Org2Org ã¨ãå¼ã°ããï¼ã使ç¨ãã¦ããã客æ§ã®å ´åã¯ä»¥ä¸ãã確èªãã ããã
- æ§æããã¦ããã¢ã¤ãã³ãã£ãã£ãããã¤ãã確èªããããããä¿¡é ¼ã§ãããã®ã§ãããã¨ã確èªããã
- SpokeãHubå
ã§ã¦ã¼ã¶ã¼ãä½æã§ãããã©ãããå¶å¾¡ããååéè¤æ©è½ã®ä½¿ç¨ã確èªãã¾ãããã®æ©è½ããªãã«ããã«ã¯ã[æ¢åã¦ã¼ã¶ã¼ã®å±æ§ãæ´æ°ãã]ãªãã·ã§ã³ãç¡å¹ã«ãã¾ãã
Â
ã»ãã¥ãªãã£ã¸ã®ç¶ç¶çãªåãçµã¿
ç§ãã¡ã¯ã製åã®æ©è½ã¨æ§è½ãç¶ç¶çã«æ¹åããã客æ§ããã¼ããã¼ãã»ãã¥ãªãã£ç 究è ãããã«ã¯ç¤¾å¡ãªã©ããã¾ãã¾ãªã°ã«ã¼ãããã®ãã£ã¼ãããã¯ã«åºã¥ãã¦ã製åã®ç¶ç¶çãªå¼·åã®æ©ä¼ãæ¢ã£ã¦ãã¾ãã
以ä¸ã«ãæè¿ã®è£½åã¸ã®æè³ãããã¤ããç´¹ä»ãã¾ããããããã¯ãããå¤æ§ã§å ç¢ãªã»ãã¥ãªãã£ç®¡çã¨ããè¯ãããã©ã«ããæä¾ããããã®å½ç¤¾ã®åãçµã¿ã示ããã®ã§ãã
Okta Identity Engine
2022å¹´3æãå½ç¤¾ã¯Okta Identity Engineï¼OIEï¼ãããã¹ã¦ã®æ°è¦ã®ã客æ§ãããã©ã«ãã§å©ç¨ã§ããããã«ãã¾ãããOIEã«ã¯ãææ°ã®å®å ¨ãªã¢ã¤ãã³ãã£ãã£ã¨ã¢ã¯ã»ã¹ä½é¨ãæ§ç¯ããããã®ä»¥ä¸ã®ãããªä¸»è¦æ©è½ãå«ã¾ãã¦ãã¾ãã
-
ã¢ããªã¬ãã«ããªã·ã¼
- ãµã¤ã³ãªã³ããªã·ã¼ã®ããã©ã«ã
- ãã¹ã¯ã¼ãã¬ã¹ãµã¤ã³ã¤ã³ä½é¨ã¨ããã¤ã¹ã³ã³ããã¹ã
- æè»ãªã¢ã«ã¦ã³ã復æ§
1. ã¢ããªã¬ãã«ããªã·ã¼
ã¢ããªã¬ãã«ããªã·ã¼ã¯ãçµç¹ãæ¥çã§èªãããããã¸ã¿ã«ã¢ã¤ãã³ãã£ãã£ã®ãã¹ããã©ã¯ãã£ã¹ï¼NISTã®æ¦è¦ï¼ã«åºã¥ãã¦ãã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£ææãã¢ãã«åã§ããããã«ããæ°ããããªã·ã¼ãã¬ã¼ã ã¯ã¼ã¯ã§ããOIEã¯ãèªè¨¼æ¹æ³ãèªè¨¼åã«æ´çããèªè¨¼åã®ç¨®é¡ã¨å ·ä½çãªç¹æ§ãå ¬éãããã¨ã§ã管çè ãã¢ããªèªè¨¼ã®ã»ãã¥ãªãã£è¦ä»¶ã«åè´ããèªè¨¼ä¿è¨¼ããªã·ã¼ãä½æã§ããããã«ãã¦ãã¾ãã
é«ãã¬ãã«ã§ã¯ãã¢ããªã¬ãã«ããªã·ã¼ã«ããã管çè ã¯ä»¥ä¸ã®ããã«ãµã¤ã³ãªã³ããªã·ã¼ãè¨å®ãããã¨ãã§ãã¾ãã
- FOR [æå®ãããã¢ããªã±ã¼ã·ã§ã³]
- IF [ç¹å®ã®ã¦ã¼ã¶ã¼ã³ã³ããã¹ãï¼½
- THEN [ç¹å®ã®èªè¨¼ãé©ç¨]
IF + THEN ã®ã³ã³ãã¯ãç¹å®ã®ä¿è¨¼ã¬ãã«ãä½æãã¾ããé常ãä¸é£ã®æ½è±¡çãªã¬ãã«ï¼ä½ãä¸ãé«ãªã©ï¼ãå®ç¾©ããã¢ããªã±ã¼ã·ã§ã³ã®æ度ã¨ã»ãã¥ãªãã£è¦ä»¶ã«åºã¥ãã¦ããããã®ã¬ãã«ã«ã¢ããªã±ã¼ã·ã§ã³ããããã³ã°ãããã¨ãæ¨å¥¨ããã¾ãã
è¦ç´ããã¨ãã¢ããªã¬ãã«ããªã·ã¼ã¯ãçµç¹ãã¢ããªåä½ã§ã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£çµæãã¢ãã«åãããã¨ãå¯è½ã«ããæ°ããææ°ã®ãã¬ã¼ã ã¯ã¼ã¯ã§ããèªè¨¼æ©è½ã®ä¿è¨¼ã¯ãã¢ããªã¬ãã«ããªã·ã¼ã®åºç¤ã¨ãªããã®ã§ããã¢ããªã¬ãã«ããªã·ã¼ã®è©³ç´°ãªããã¥ã¡ã³ãã¯ãã¡ãã§ã覧ããã ãã¾ãã
2. ãµã¤ã³ãªã³ããªã·ã¼ã®ããã©ã«ã
ããã©ã«ãã§å®å ¨ãªç£æ»ã®ä¸ç°ã¨ãã¦ãã¢ã«ã¦ã³ãä¹ã£åãã®ãªã¹ã¯ãé«ããä¸è¬çãªèª¤è¨å®ã«å¯¾å¦ããããããµã¤ã³ã¤ã³ããªã·ã¼ã®ã¨ã¯ã¹ããªã¨ã³ã¹ãã¢ããã°ã¬ã¼ããã¾ããããã®åãçµã¿ã®ä¸ç°ã¨ãã¦ããªã¹ã¯ã®é«ãMFAæ§æãè¨å®ãããã¨ãã«ç®¡çè ã«éç¥ããæ°ããHealthInsightã»ãã¥ãªãã£ã¿ã¹ã¯ãæä¾ãã¦ãã¾ãããã®æ©è½ã«é¢ãã詳細ãªããã¥ã¡ã³ãã¯ãã¡ãã§ã覧ããã ãã¾ãã
APIã¯ãã¡ãããã覧ããã ãã¾ãï¼ https://developer.okta.com/docs/reference/api/policy/#global-session-policy
3. ãã¹ã¯ã¼ãã¬ã¹ãµã¤ã³ã¤ã³ä½é¨ã¨ããã¤ã¹ã³ã³ããã¹ã
Okta FastPassã¯ãããã¤ã¹ãã¾ããã§ä»äºãããããã«å¿ è¦ãªãã¹ã¦ã®ãã®ã«ãã¹ã¯ã¼ãã¬ã¹èªè¨¼ãå¯è½ã«ãã¾ããOkta FastPassã®4ã¤ã®ä¸»ãªå©ç¹ã¯æ¬¡ã®ã¨ããã§ãã
- 常ã«ãã¹ã¯ã¼ãã¬ã¹ãå®ç¾ï¼ããããããã¤ã¹ãå ´æãããOktaã管çããããããã¢ããªã«ãã¹ã¯ã¼ãã¬ã¹ã§èªè¨¼ã»ãã°ã¤ã³ã
- ããããããã¤ã¹ç®¡çãã¼ã«ã«å¯¾å¿ï¼Active Directoryãç¹å®ã®EMMï¼ã¨ã³ã¿ã¼ãã©ã¤ãºã¢ããªãã£ç®¡çï¼/MDMï¼ã¢ãã¤ã«ããã¤ã¹ç®¡çï¼ãããã¤ãã«ä¾åããªããã¹ã¯ã¼ãã¬ã¹ãã°ã¤ã³ã
- ããã¤ã¹ã¬ãã«ã®çä½èªè¨¼ã¨ã®çµã¿åããï¼çä½èªè¨¼ããµãã¼ãããããã¤ã¹ã§ã¯ãã¨ã³ããã¼ã¨ã³ãï¼ãã°ã¤ã³ããã¢ããªã¸ã®ã¢ã¯ã»ã¹ã¾ã§ï¼ã§ãã¹ã¯ã¼ãã¬ã¹ï¼çä½èªè¨¼ã§ããã¤ã¹ã«ãã°ã¤ã³ããOkta管çã¢ããªã«ã¢ã¯ã»ã¹ããéã«è¿½å ã®ããã³ããã表示ãããªãï¼ã
- Device Trustããã§ãã¯ï¼ãªãã·ã§ã³ã§ãDevice Trustã¨Okta FastPassãçµã¿åããã管çãããæºæ ããã¤ã¹ã«ã®ã¿ãã¹ã¯ã¼ãã¬ã¹ãæä¾ã
4. æè»ãªã¢ã«ã¦ã³ã復æ§
OIEã«ãããOktaã¯ã¨ã³ãã¦ã¼ã¶ã¼ãèªè¨¼æ å ±ããªã»ããã¾ãã¯å復ããããã«ä½¿ç¨ã§ããè¦ç´ ã®é¸æè¢ãåºããOkta Verify Pushãå«ãããã¨ãã§ãã¾ããæè»ãªã¢ã«ã¦ã³ã復æ§ã¯ã3ã¤ã®ãµãæ©è½ã§æ§æããã¦ãã¾ãã
- ãã¹ã¯ã¼ãã®å¤æ´
- ãã¹ã¯ã¼ãã®ãªã»ããï¼ãã¹ã¯ã¼ããå¿ããå ´åï¼
- ã¢ã«ã¦ã³ãã®ããã¯è§£é¤ï¼ã¢ã«ã¦ã³ããªã«ããªã¼ï¼
Okta Verify Pushãæè»ãªã¢ã«ã¦ã³ã復æ§ã«æ´»ç¨ããå ´åãã客æ§ã¯ã¨ã³ãã¦ã¼ã¶ã¼ã«å¯¾ãã¦ã2ã¤ã®è¦ç´ ã使ç¨ãã¦ãã¹ã¯ã¼ãã®å¤æ´ã¾ãã¯ãªã»ãããã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã®ããã¯è§£é¤ãè¦æ±ãããã¨ãã§ãã¾ããããã«ãããã客æ§ã¯æ¬è³ªçã«å®å
¨ã§ãªãã»ãã¥ãªãã£è³ªåã使ç¨ããã«æ¸ãããã«ãªãã¾ããæè»ãªã¢ã«ã¦ã³ã復æ§ã®è¨å®æ¹æ³ã«é¢ãã詳細ãªããã¥ã¡ã³ãã¯ããã¡ããã覧ãã ããã
Â
ã«ã¹ã¿ã 管çè ãã¼ã«
ä»å¹´åããç§ãã¡ã¯æ°ããã«ã¹ã¿ã 管çè ãã¼ã«ãã¬ã¼ã ã¯ã¼ã¯ã«ãã£ã¦ãå§ä»»ç®¡çã·ããªãªã®ããã®éè¦ãªæ°ãããã©ãããã©ã¼ã æ©è½ãä¸è¬ã«å ¬éãã¾ããï¼GAï¼ããã®æ©è½ã¯ãä½åãã®ã客æ§ã«æ¡ç¨ãããéå°ãªæ¨©éãæã¤ç®¡çè ã®æ°ãæ¸ããã®ã«å½¹ç«ã£ã¦ãã¾ããOktaã®è£½åãã¼ã ã¯ããã®æ°æ©è½ãæ´»ç¨ãã¦ãæ¢åã®è£½åæ©è½ã«ããããç´°ãã権éã段éçã«å°å ¥ãã¦ãã¾ããä¾ãã°ãæè¿ãèªè¨¼ãµã¼ããã«ã¹ã¿ãã¤ãºã®ããã®æ¨©éã追å ãã¾ããã
管çè ã®å½¹å²ã¨æ¨©éãç°¡åã«ç£æ»ã§ããã¬ãã¼ããä½æããéå°ãªæ¨©éãæã¤ã¢ã«ã¦ã³ãã®ç¹å®ã容æã«ãã¾ãã
APIã¯ãã¡ãããã覧ããã ãã¾ãï¼ https://developer.okta.com/docs/reference/api/roles/
ãªãªã¸ã³ãã¼ã¹ã®IFrameåãè¾¼ã¿è¨±å¯
ã客æ§ã¯ãOktaãiFrameã¨ãã¦ã¬ã¬ã·ã¼ã½ãªã¥ã¼ã·ã§ã³ã«åãè¾¼ãæ©è½ãæã£ã¦ãã¾ãããã®æ©è½ã¯ã»ãã¥ãªãã£ã«å¤§ããªå½±é¿ãä¸ãããããè¨å®ã«ã¯Webã»ãã¥ãªãã£ã¢ãã«ã¸ã®æ·±ãç解ãå¿ è¦ã§ããç§ãã¡ã¯ãæè¿ããã®ã°ãã¼ãã«ãªæ©è½ããä¿¡é ¼ã§ãããªãªã¸ã³ããã¬ã¼ã ã¯ã¼ã¯ã«ç§»è¡ããã客æ§ããã®æ¨©éãç¹å®ã®ãªãªã¸ã³ã«ç´°ããè¨å®ã§ããããã«ããå½±é¿ç¯å²ï¼blast radiusï¼ãåçã«ç¸®å°ãã¾ããã
APIã¯ããã¡ãï¼https://developer.okta.com/docs/reference/api/trusted-origins/ï¼ããå ¥æã§ãã¾ãã
æå¾ã«ãã»ãã¥ãªãã£è¨å®ã¨æ§æãå®æçã«è¦ç´ããã¨ããè å¨ãå åãããããã®éè¦ãªãã¤ã³ãã§ããçµç¹ã®ã»ãã¥ãªãã£ãå¼·åãããOktaã®ã客æ§ã¯ãå½ç¤¾ã®ãªã³ã©ã¤ã³è£½åããã¥ã¡ã³ããæ´»ç¨ãã¦ãæãå®å ¨ãªè¨å®ãé©ç¨ãããã¨ãã§ãã¾ãã