Dec , IS p. 1/60

Similar documents
"CAS を利用した Single Sign On 環境の構築"

"CAS を利用した Single Sign On 環境の構築"

"CAS を利用した Single Sign On 環境の構築"

Plan of Talk CAS CAS 2 CAS Single Sign On CAS CAS 2 CAS Aug. 19, 2005 NII p. 2/32

main.dvi

CAS Yale Open Source software Authentication Authorization (nu-cas) Backend Database Authentication Authorization Powered by A

1: 3 CAS[3] uportal[4] (Web ) 3.1 CAS CAS[3] Yale JA-SIG [5] CAS 1. 2(1) CAS Web (2)CAS ID LDAP 2. 2(3) CAS Web CAS Ticket (4)Web Ticket 3. Ticket Web

Oracle Identity Managementの概要およびアーキテクチャ

Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

Oracle Secure Enterprise Search 10gを使用したセキュアな検索

1. PKI (EDB/PKI) (Single Sign On; SSO) (PKI) ( ) Private PKI, Free Software ITRC 20th Meeting (Oct. 5, 2006) T. The University of Tokush

Web ( ) [1] Web Shibboleth SSO Web SSO Web Web Shibboleth SAML IdP(Identity Provider) Web Web (SP:ServiceProvider) ( ) IdP Web Web MRA(Mail Retrieval

PowerPoint プレゼンテーション

内閣官房情報セキュリティセンター(NISC)

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

_‚Ofl¼

,,, J-SOX ISMS PCIDSS,, IM/VoIP/VoD Copyright 2008 Juniper Networks, Inc. 2

BIG‑IP Access Policy Manager | F5 Datasheet

untitled

Encryption Security

橡CoreTechAS_OverView.PDF

iPhone/iPad/Android(TM) とベリサイン アイデンティティプロテクション(VIP)エンタープライズゲートウェイとの組み合わせによるL2TP+IPsecのワンタイムパスワード設定例

LDAP - LDAP OpenLDAP - postfix qpopper - LDAP heartbeat mon

Web Web ( (SOAP (SOAP/http (WSDL UDDI 1. 2.XML 3. (XDoS http, https SOAP XML Web/App ( App

25 About what prevent spoofing of misusing a session information

untitled

Epson Print Admin

shio_ PDF

untitled

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

XMLアクセス機能説明書

Oracle Calendar Oracle Collaboration Suite 2(9.0.4) Creation Date: Jun 04, 2003 Last Update: Nov 18, 2003 Version:

FileMaker Server 9 Getting Started Guide

Web STEPS Web Web Form Cookie HTTP STEPS Web



Oracle Application Server 10g(9

Epson Print Admin

<Insert Picture Here> Oracle Business Intelligence 2006/6/27

OpenAM(OpenSSO) のご紹介

<Documents Title Here>

SAML

第2回_416.ppt

<Documents Title Here>

Aventail EX-2500/1600/750 STv(Ver.8.9) Sep 2007 c 2007 SonicWALL,Inc. All rights reserved.

Oracle Application Server 10g( )インストール手順書

組織変更ライブラリ

All Rights Reserved, Copyright FUJITSU LIMITED All Rights Reserved, Copyright FUJITSU LIMITED

ppt

FileMaker Server Getting Started Guide

FileMaker Server Help

FileMaker Server Getting Started Guide

FileMaker Server Getting Started Guide

ohp.mgp

オープンソース・ソリューション・テクノロジ株式会社

untitled

Computer Infrastructure System 1 set main Revision : 1.5 abst Revision : 1.4 tetsuzuki Revision : 1.4 func-common Revision : 1.

FileMaker Server 8 Advanced Web Publishing Installation Guide

wp_integrating_AD_10.9_16JAN2014

NAC(CCA)4.x: LDAP を使用して、ユーザを特定のロールにマッピングする設定例

Mac OS X Server Windows NTからの移行

<Documents Title Here>

Windows2000 Edge Components V Edge Components V Java Edge Components

wp_integrating_active_directory_ml

はじめに

スライド 1

NAC(CCA): ACS 5.x 以降を使用した Clean Access Manager での認証の設定

Oracle Application Server 10g(9

2011年11月10日 クラウドサービスのためのSINET 学認説明会 九州地区説明会 九州大学キャンパス クラウドシステムの導入 伊東栄典 情報基盤研究開発センター 1

IC API

FileMaker Server 8 Administrator’s Guide

FileMaker Help-M2 Template Guide

FileMaker Server 16 インストールおよび構成ガイド

Web Web Web Web i

XML ( ) XML XML jedit XML XPath XSLT jedit JAVA VM jedit Slava Pestov GNU GPL ( ) jedit jedit ( jedit XML jed

Vol. 9 No. 2 DNS. DNS IP.... leopard.loc. DNS. Mac OS X Server. Web Mac OS X Server Mac OS X Server.. DNS DNS DNS example.com DNS

Faronics Core User Guide

付加情報をもったファイル共有システム

FileMaker Server 10 ヘルプ

...5 VMware Workspace ONE Workspace ONE...14 Workspace ONE AirWatch VMware Identity Mana

FileMaker Server Help

橡CoreTechDS_Overview.PDF

P2P技術を用いたチャットの研究

2008

Testing XML Performance

untitled

証明書検証サーバ

FileMaker Server 15 入門ガイド

i

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

Wi-Fi Wi-Fi Wi-Fi Wi-Fi SAS SAS-2 Wi-Fi i

<Documents Title Here>

LDAP サーバと統合するための ISE の設定

PowerPoint Presentation

untitled

¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

JP1/Integrated Management - Service Support 操作ガイド

AirMac ネットワーク構成の手引き

Oracle Application Server 10gリリース2( )Oracle HTTP Serverの概要

22 (266) / Web PF-Web Web Web Web / Web Web PF-Web Web Web Web CGI Web Web 1 Web PF-Web Web Perl C CGI A Pipe/Filter Architecture Based Software Gener

Transcription:

Dec 08 2007, IS p. 1/60

Dec 08 2007, IS p. 2/60

Plan of Talk (LDAP) (CAS) (IdM) Dec 08 2007, IS p. 3/60

Dec 08 2007, IS p. 4/60

.. Dec 08 2007, IS p. 5/60

Dec 08 2007, IS p. 6/60

Dec 08 2007, IS p. 7/60

(Authentication) ID, (Directory Service) (Authorization) Dec 08 2007, IS p. 8/60

Authentication Authentication + Directory Service UNIX Login UserID + Password UserID UserID Password UidNumber, GidNumber, Home Directory Dec 08 2007, IS p. 9/60

UNIX LDAP Directory Server CAS LDAP Radius Dec 08 2007, IS p. 10/60

LDAP Sun Microsystems Directory Server IdM Dec 08 2007, IS p. 11/60

(1) WebCT IP Dec 08 2007, IS p. 12/60

(2) Dec 08 2007, IS p. 13/60

LDAP LDAP = Light weight Directory Access Protocol Unix like ( MacOSX) OpenLDAP Apache Directory Project Sun Microsystems Directory Server (20 ) Dec 08 2007, IS p. 14/60

LDAP Dec 08 2007, IS p. 15/60

LDAP dn: nagoyaunivid=,ou=user,o=nagoya-u nagidno: NagoyaUnivID: ZengakuID: fullname;lang-ja;phonetic: fullname;lang-en: fullname:: adepartmentnumber: section;lang-ja: Dec 08 2007, IS p. 16/60

LDAP 1. 2. Bind User ldapsearch -h ldaphost -D BIND-USER-DN \ -b search-base (nagoyaunivid=userid) 3. Bind User BIND ldapsearch -h ldaphost -D USER-DN \ -b search-base \ -w password (nagoyaunivid=userid) 4. BIND Dec 08 2007, IS p. 17/60

LDAP Unique LDAP Search Filter ( (nagoyaunivid=userid)(zengakuid=userid)) ( (nagoyaunivid=userid)(mail=userid)) LDAP search filter Dec 08 2007, IS p. 18/60

LDAP (ACL) Bind User Bind User LDAP Sun Directory Server ACL OpenLDAP Dec 08 2007, IS p. 19/60

DIT (UNIX/MacOSX) LDAP uidnumber, gidnumber, homedirectory, loginshell DIT DIT Dec 08 2007, IS p. 20/60

DIT ou=system-n,o=otherhosts uidnumber, gidnumber, homedirectory, loginshell userpassword parentdn DIT userpassword Dec 08 2007, IS p. 21/60

UNIX LDAP UNIX (Linux/BSD) pam-ldap, nss-ldap (?) MacOSX Directory Service LDAPv3 LDAP uid cn Windows LDAP Active Directory... Dec 08 2007, IS p. 22/60

MacOSX Server LDAP naito@math.nagoya-u.ac.jp naito-math cn: naito-math, naito@math.nagoya-u.ac.jp uid: naito-math Dec 08 2007, IS p. 23/60

Dec 08 2007, IS p. 24/60

LDAP LDAP Search Socket socket close Dec 08 2007, IS p. 25/60

CAS 2 CAS = Central Authentication Service Single Sign On (Yale University) JA-SIG CAS 2 = Central Authentication and Authorization Service CAS Authorization Dec 08 2007, IS p. 26/60

CAS Single Sign On SSL LDAP BIND USER LDAP close LDAP Dec 08 2007, IS p. 27/60

CAS 2 (1) Login Window Web Browser 1. Access 2a. Redirection 2b. Login Window Web Application https://app.foo/ CAS Server LDAP Server Cookie one-time ticket ST Web Application Web Browser 4. Redirection with TGC/ST TGC CAS Server 3a. Input User ID/Password 3b. Authentication 3c. Result LDAP Server Dec 08 2007, IS p. 28/60

CAS 2 (2) one-time ticket verify one-time ticket Web Browser 6. Response Web Application 5a. Send ST ST 5b. Validation Result CAS Server LDAP Server Dec 08 2007, IS p. 29/60

CAS 2 (3) Cookie one-time ticket Web Browser TGC ST 2. Redirection with ST Web Application CAS Server 1a. Authorization 1b. Result CAS-ACL Access Denied Page redirect one-time ticket Web Browser TGC 1. Access Invalid ST Web Application 5. Redirection 2. Send ST Invalid ST 4. Invalid CAS Server 3a. Authorization 3b. Result CAS-ACL Dec 08 2007, IS p. 30/60

CAS 2 LDAP Server SSL CAS 2 server Java Servlet http redirection cookie Java script (redirect) Dec 08 2007, IS p. 31/60

CAS 2 CAS-ACL (Access Control List) cn=www,ou=cas,o=nagoya-u cas-attributes: uid,mail cas-service: https://www\.nagoya\-u\.ac\.jp/.* cas-allow: (&(uid=naito)(datetime<200801010000) (IP=133.6.0.0/16)) URL cas-service cas-allow TRUE,, Dec 08 2007, IS p. 32/60

CAS 2 Directory Service CAS-ACL (Access Control List) cn=www,ou=cas,o=nagoya-u cas-attributes: uid,mail cas-service: https://www\.nagoya\-u\.ac\.jp/.* cas-allow: (&(uid=naito)(datetime<200801010000) (IP=133.6.0.0/16)) URL cas-service, cas-attributes Dec 08 2007, IS p. 33/60

CAS 2 active-stand by Dec 08 2007, IS p. 34/60

CAS 2 cas client module Java Servlet CasClient cas = new CasClient(CAS_SERVICE_URL, CAS_LOGIN_URL) ; if (!cas.casperform(request, response)) return ; Map r = cas.getresult() ; casperform ticket verify r Perl, PHP Dec 08 2007, IS p. 35/60

CAS 2, CAS 2 CAS 2 BUG LDAP server index LDAP server Socekt tomcat CAS 2 LDAP socket Dec 08 2007, IS p. 36/60

LDAP, CAS 2 LDAP CAS 2 2003 5 5, WebCT, 2004 4 4 8 CAS 2., CAS 2 2005 3 4 7 DB, CAS 2 2006 3 3 6 CAS 2 15 11 26 (2007) (2) (2) (4) LDAP, CAS 2, 25. Dec 08 2007, IS p. 37/60

VPN radius, VPN LDAP server CAS 2 server Dec 08 2007, IS p. 38/60

Dec 08 2007, IS p. 39/60

IC (2008/04) (2007/11) (2008/04) PKI IdM (Identity Management) Dec 08 2007, IS p. 40/60

PKI SSO PKI PKI SSO PKI SSO PKI PKI Dec 08 2007, IS p. 41/60

PKI PKI (?) subscriber ID Dec 08 2007, IS p. 42/60

CAS 2 CAS 2 PKI (X.509) Web Browser AuthN by X.509 Access granded Access granted Web Application with Security Level 2 Web Application with Security Level 1 Web Browser AuthN by PIN Access denied Access granted Web Application with Security Level 2 Web Application with Security Level 1 Dec 08 2007, IS p. 43/60

CAS 2 CAS 2 PKI (X.509) Web Browser TGC with Level 2 ST 2. Redirection 1. Access with client certificate Web Application with Security Level 2 CAS Server PKI Web Browser TGC with Level 1 1. Access 2. Redirection to obtain client certification Web Application with Security Level 2 CAS Server Dec 08 2007, IS p. 44/60

IdM, Role,... (Provision) (Properfate) (Use) (Maintain) (Deprovision) Dec 08 2007, IS p. 45/60

IdM Dec 08 2007, IS p. 46/60

IdM Establishing Identity + Provisioning,, Authentication Authorization Single Sign On Enterprise Directory, Federated Identity Dec 08 2007, IS p. 47/60

IdM Dec 08 2007, IS p. 48/60

LDAP search filter (uid=%s) ( (nagoyaunivid=%s)(zengakuid=%s)) CAS LDAP lookup filter, Dec 08 2007, IS p. 49/60

(RA/TA), Dec 08 2007, IS p. 50/60

IC Dec 08 2007, IS p. 51/60

44000 37000 11000 6000 Dec 08 2007, IS p. 52/60

,, DB Dec 08 2007, IS p. 53/60

IdM α Provisioning Dec 08 2007, IS p. 54/60

Provisioning, Dec 08 2007, IS p. 55/60

Windows CP932 Unicode Dec 08 2007, IS p. 56/60

LDAP (encoding: UTF-8) CP932 Unicode ASCII ISO-8859-15 Unicode MacOSX, Windows Vista Dec 08 2007, IS p. 57/60

Unicode Point 9089 glyph id = 14243 Unicode Point 909A glyph id = 14237 Dec 08 2007, IS p. 58/60

IdM IdM IdM, Dec 08 2007, IS p. 59/60

LDAP SSO CAS 2 PKI, IdM PKI SSO IdM Dec 08 2007, IS p. 60/60