ãããããã«ç´°ãã説æããããã徿¥å¡ã®å¹³åçãªå°±æ¥æ¥ãèãã¦ã¿ã¾ããããã¾ããæã«SAMLã§ä¸åãã°ã¤ã³ãã¾ãããã®ãã°ã¤ã³ã«ãã£ã¦ãSAMLãã¼ã¹ã®ã¢ããªã±ã¼ã·ã§ã³ã®ã¹ã¤ã¼ãå
¨ä½ã«å¯¾ããã¢ã¯ã»ã¹æ¨©ãä»ä¸ããã¾ããã¦ã¼ã¶ã¼ãã¢ããªã±ã¼ã·ã§ã³éã§è¡ãæ¥ããããã«ããããªãæä½ã¯å¿
è¦ããã¾ããã
SAMLã¨OAuthã¯ãã¤ä½¿ãã¹ããï¼
SAMLã¨OAuthã¯ä¸¡æ¹ã¨ããSSOã®æ©ä¼ãå¯è½ã«ãã徿¥å¡ã®çç£æ§åä¸ã«ã¨ã£ã¦éè¦ã§ãã2ã¤ã¯ãäºãã代æ¿ããã¨ããããã¯ãä¸ç·ã«ä½¿ç¨ã§ãããã¯ããã¸ã¼ã§ããã¨èãããã¨ãã§ãã¾ãã
ãã¨ãã°ãMicrosoftç°å¢ã§ã¯ãOAuthãèªå¯ãå¦çããSAMLãèªè¨¼ãå¦çãã¾ãã2ã¤ãåæã«ä½¿ç¨ããå ´åãSAMLçµç±ã§ãã°ã¤ã³ãã¦ãOAuthçµç±ã§ä¿è·ããããªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ã許å¯ã§ãã¾ãã
ã¾ãããããã®ãã¼ã«ã両æ¹ã¨ãæé¤ãããã¨ãå¯è½ã§ãããã¨ãã°ãä¸é¨ã®Webãã¼ã¸ã¯èªè¨¼ã¨èªå¯ã®ã©ã¡ããå¿
è¦ã¨ãã¾ããã
ãããããã¸ã¿ã«ã·ã¹ãã ã使ç¨ããã»ã¨ãã©ã®ä¼æ¥ã¯ã广çã«æ©è½ããããã«ä½ããã®èªè¨¼/èªå¯ã·ã¹ãã ã使ç¨ããªããã°ãªãã¾ãããã¦ã¼ã¶ã¼ã¯ãæ¥ã
ã®æ¥åã«å¾äºããããã«ã伿¥ã®ã·ã¹ãã ã«ãµã¤ã³ã¤ã³ããã·ã¹ãã å
ã§ç§»åãã許å¯ãå¿
è¦ã¨ãã¾ãã
OpenID Connectï¼OIDCï¼ã¨ã¯ï¼ SAMLãOAuthã¨ã®é¢ä¿
ã¢ããªã±ã¼ã·ã§ã³ããã¼ã¿ã«ãªã©ã®æ¶è²»è
åãã»ã«ã³ããªãã¼ã«ãéçºãã¦ããå ´åã«ã¯ãOAuthãéè¦ã«ãªããã¨ãããã¾ããæ°ããã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã使ããã«ãã¼ã«ã«ã¢ã¯ã»ã¹ã§ããæ©ä¼ãæä¾ãããã¨ããå¸å ´ã«é«ãè©ä¾¡ãããå¯è½æ§ãããã¾ããã¾ãã徿¥å¡ãSAML以å¤ã®ãã¼ã«ã使ç¨ããå ´åããOAuthãå½¹ç«ã¡ã¾ãã
ããããSAMLã¨ã®çã®æ¯è¼ã®ããã«ã¯ãSAMLãOAuthãããã³OpenID Connectã®éãã確èªããå¿
è¦ãããã¾ãã
Oktaã¨ã®é£æº
Oktaã®SSOãµã¼ãã¹ã¯ãæ¥å¸¸çã«ä½¿ç¨ããã¢ããªã±ã¼ã·ã§ã³ãã·ã¼ã ã¬ã¹ã«èªè¨¼ã§ãããã¨ã§é«ãè©ä¾¡ããã¦ãã¾ããã»ãã¥ã¢ãªSSOã§ã¯ãå¤ãã®å ´åã«ãããã³ã«ã¨ãã¦SAMLã鏿ããã¾ãããOktaã¯ããã«ããµã¤ã³ã¤ã³ã¦ã£ã¸ã§ãããAuth SDKï¼JavaScriptãã¼ã¹ã®ã©ã¤ãã©ãªï¼ãã½ã¼ã·ã£ã«ãã°ã¤ã³ãä»»æã®ã¯ã©ã¤ã¢ã³ãåãã®èªè¨¼APIãªã©ã®ãªãã·ã§ã³ãæä¾ãã¾ãã
Oktaã®äºåæ§ç¯æ¸ã¿ã¢ã¤ãã³ãã£ãã£ã½ãªã¥ã¼ã·ã§ã³ã®è©³ç´°ã«ã¤ãã¦ã¯ããã¡ããã覧ãã ããã
åèæç®
A Survey on Single Sign-On Techniques. (2012). Procedia Technology.Â
Employees Switch Apps More Than 1,100 Times a Day, Decreasing Productivity. (December 2018). TechRepublic.Â
Stop Synching Your Contacts with Facebook. (August 2019). Mashable.Â
Authentication vs. Authorization. (September 2018). Medium.
Authentication vs. Authorization. (May 2020). Microsoft.Â
Why SAML? (Security Assertion Markup Language). (July 2018). Medium.
Understanding Authentication, Authorization, and Encryption. Boston University.
以ä¸ã®å
容ã¯ãåæï¼è±èªï¼ã®æ©æ¢°ç¿»è¨³ã§ãããåæã¨å
容ã«å·®ç°ãããå ´åã¯ãåæãåªå
ããã¾ãã