OpenAM 13ã®æ°æ©è½ã試ãã¦ã¿ã(1) - 2段éèªè¨¼
ä»å¹´ã®Q4ã«ãªãªã¼ã¹ãäºå®ããã¦ããOpenAM 13ã§ãããNightly Buildçã§æ°æ©è½ã試ããããªç¶æ
ã ã£ãã®ã§åä½ã確èªãã¦ã¿ã¾ããã
ãªããæ°æ©è½ã«ã¤ãã¦ã¯SNAPSHOT版のリリースノートã«ä¸è¦§ãæ¸ããå§ãã¦ãã¾ãã
ä»åã®ã¨ã³ããªã§ã¯2段éèªè¨¼(Two Step Verification) ã®æ°æ©è½ã«ã¤ãã¦ç°¡åã«ç´¹ä»ã
â»2015/10/06æç¹ã®Nightly Buildçã§ç¢ºèªãã¦ãã¾ãã
2段éèªè¨¼(Two Step Verification) ã®æ°æ©è½
OpenAM 12ã§ããOTPã使ã£ãèªè¨¼ã¢ã¸ã¥ã¼ã«ã¨çµã¿åããããã¨ã§2段éèªè¨¼èªä½ã¯å¯è½ã§ãããOpenAM 13ããã¯ãããã¤ã¹ç»é²ã®æ©è½ãçµã¿è¾¼ã¾ããããã§ãã詳細ã¯SNAPSHOT版のマニュアルã«æ¸ããã¦ãã¾ãããååãã°ã¤ã³ï¼QRã³ã¼ãã§ããã¤ã¹ç»é²ï¼ããã¤ã¹ã§OTPçºè¡ãã¦ãã°ã¤ã³ ã¨ããããããåæç»é²ã®ããã¼ãOpenAMåä½ã§ã§ããããã«ãªã£ã¦ãã¾ãã
Nightly Buildçã§åä½ç¢ºèª
Nightly Buildçããã¦ã³ãã¼ããã¦ã¤ã³ã¹ãã¼ã«ããProcedure 2.10. To Create an Authentication Chain for Two Step Verificationã®éãã«è¨å®ãã¦ãã¾ã åä½ããã
ã¨ã©ã¼æ å ±ã¨ã½ã¼ã¹ããã°ããçºããã¨ã¡ããã¨å¤æ´ããã°åä½ãããã ã£ãã®ã§è©¦ãã¦ã¿ããçµè«ããè¨ãã¨ãããã¤ã¹ç»é²ã¨OTPã«ãããã°ã¤ã³ã®ããã¼ãåä½ããããã¨ã¯ã§ãã¾ããã
åä½ç¢ºèª
OTPçºè¡ã«ã¯Androidçã®Google Authenticatorãå©ç¨ãã¦ç¢ºèªãã¾ããã
- äºåã«ä½æãã¦ãããã¢ã«ã¦ã³ã(test1)ã§ãã°ã¤ã³ãã
- OTPå ¥åã®ç»é¢ã«é·ç§»ãã¾ãããã¾ã ããã¤ã¹æªç»é²ãªã®ã§ãã㧠REGISTER DEVICE ãã¯ãªãã¯
- QRã³ã¼ãã表示ãããã®ã§ãGoogle Authenticatorã§ãã£ããã£ãã¦è¨å®ãè¡ã
- 次ã«é²ã¿ãç»é²ããGoogle Authenticatorã§çºè¡ãããOTPãå ¥åãã¦SUBMIT
- ãã°ã¤ã³ãå®äºãã¦ã¼ã¶ã®ãããã£ã¼ã«ãã¼ã¸ã«ç¡äºã«é·ç§»
è¨å®æã®æ³¨æç¹
Procedure 2.10. To Create an Authentication Chain for Two Step Verificationéããªã®ã ããèªè¨¼ã¢ã¸ã¥ã¼ã«ã¯ ForgeRock Authenticator (OATH) ãé¸ã¶ãã¨(OATHã ã¨é§ç®)ã
ãã®ä»æ³¨æç¹
- XUIã®ãã°ã¤ã³ç»é¢ã¯ã©ããã¾ã å®å®ãã¦ããªãã¦ãç¹ã«ã¬ã«ã ã使ãã¨ãã©ã¦ã¶ããã®REST APIå¼ã³åºãã§ã¨ã©ã¼ãåºã¾ããã¾ãã試ãå ´åã¯ãããã©ã«ãã®ãããã¬ãã«ã®ã¬ã«ã (/)ã使ã£ãã»ããè¯ãã§ãã
- 2段éèªè¨¼ããããã¬ãã«ã¬ã«ã ã®ããã©ã«ãã®èªè¨¼é£éã«è¨å®ããã¨ãamadminã§ãã°ã¤ã³ããéã«ãOTPãæ±ããã管çã³ã³ã½ã¼ã«ã«ãã°ã¤ã³ã§ããªããªãã¾ãããã®å ´åã¯ä¸è¨URLã®ããã«DataStoreã¢ã¸ã¥ã¼ã«ãç´æ¥æå®ãã¦ãã°ã¤ã³ç»é¢ãéãã°OKã
Nightly Buildçã§åä½ãããããã®ä¿®æ£ç¹
Nightly Buildçã§åä½ãããããã®å¤æ´å 容ã«ã¤ãã¦ãæ¸ãã¦ããã¾ããHTMLãã¡ã¤ã«ãç½®ãã ãã§ããã®ã§ãOpenAMã®ãã«ãã¯ä¸è¦ã§ããæ£å¼ãªãªã¼ã¹ã¾ã§ã«ã¯ãã£ã¨ç´ãã¯ãã
- (OPENAM_WAR)/XUI/templates/openam/authn/ 以ä¸ã« AuthenticatorOATH2.html ãä½æã
<div class="container" id="oath-container"> {{#if reqs.header}} <div class="page-header"> <h1 class="text-center">{{reqs.header}}</h1> </div> {{/if}} <form action="" method="post" class="form col-sm-6 col-sm-offset-3" autocomplete="off"> <fieldset> {{#each reqs.callbacks}} <div class="form-group"> {{callbackRender}} </div> {{/each}} </fieldset> </form> </div>
- åãå 容ã§ãAuthenticatorOATH4.htmlãAuthenticatorOATH5.htmlãAuthenticatorOATH7.htmlãåãã©ã«ãã«ä½æã