çããããã«ã¡ã¯ãåœäºã§ãã
ããããADFSããã¹ãå
šæå
¬éãã£ã¬ã³ãžãæçµåã«ãªããŸããã
æçµåã¯ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«ã€ããŠè§£èª¬ããŸãã
â â â
![ã¹ã©ã€ã152 ã¹ã©ã€ã152]()
ADFS ã§ã¯ãèšå®é
ç®ãå€å²ã«ããããããèšå®ã誀ããªã©ããŠãã©ãã«ãçºçãããšããã©ãã«ã·ã¥ãŒãã£ã³ã°ãé£ãããªããŸããããã§ãããã§ã¯ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãå¹çããè¡ãããã«å©çšå¯èœãªããŒã«ã玹ä»ããŸãã
â ã€ãã³ããã°
ADFS ã§çºçããã¢ã¯ãã£ããã£ãŒã¯ Windows ã€ãã³ã ãã°ã«èšé²ãããŸããADFSé¢é£ã®ã€ãã³ããã°ã«ã¯ãADFS Admin ãã°ãADFS Debug ãã°ãã»ãã¥ãªã㣠ãã°ããããŸãã
â ããã©ãŒãã³ã¹ã¢ãã¿ãŒ
ããã©ãŒãã³ã¹ã¢ãã¿ãŒã§ã¯ãADFS ãžã®ã¢ã¯ã»ã¹æ°ãªã©ããªã¢ã«ã¿ã€ã ã§ç¢ºèªã§ããŸãã
![ã¹ã©ã€ã153 ã¹ã©ã€ã153]()
ADFS ãµãŒããŒã§è¡ãããã¢ã¯ãã£ããã£ãŒã®ãã¡ããµãŒãã¹ã®éå§ã»åæ¢ããã©ãã«ãçºçããç¹å®ã®ã¢ã¯ãã£ããã£ãŒã«ã€ããŠã¯ADFS Admin ãã°ããããã®å
容ã確èªã§ããŸãã
ç¹ã«ãADFS ã®æ§æãåé¡ã§ãWeb ã¢ããªã±ãŒã·ã§ã³ã«ãã ID 飿ºã«å€±æããå Žåããšã©ãŒã瀺ã Web ããŒãžã« åç
§çªå· (Activity ID) ã衚瀺ãããŸããåç
§çªå·ã¯ãã€ãã³ããã°ã«ãåæ§ã® ID ã衚瀺ããããããWeb ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ãããšãã«çºçãããã©ãã«ãã©ã®ã€ãã³ããã°ã«ãã£ãŠè¡šãããŠããã確èªã§ããŸãã
äžæ¹ãèšå€§ãªã€ãã³ããã°ã®äžããç¹å®ã®åç
§çªå·ãæã€ãã°ãæ¢ãåºãå Žåã«ã¯ããã£ã«ã¿ãŒã䜿çšããŠãã ãããã€ãã³ããã¥ãŒã¢ãŒã®ãã£ã«ã¿ãŒæ©èœã§ã¯ãXPath 圢åŒã®ã¯ãšãªãŒãèšè¿°ããããšãã§ããããã以äžã®ãããªã¯ãšãªãŒãèšè¿°ããããšã§ãç¹å®ã® åç
§çªå·ãæã€ãã°ã容æã«æ¢ãåºãããšãã§ããããã«ãªããŸãã
<QueryList>
<Query Id=â0â Path=âAD FS/Adminâ>
<Select Path=âAD FS/Adminâ>
*[System[Correlation[@ActivityID=â{ActivityID}â]]]
</Select>
</Query>
</QueryList>
![ã¹ã©ã€ã154 ã¹ã©ã€ã154]()
ADFS Debug ãã°ã¯ãADFS ã«é¢ããã¢ã¯ãã£ããã£ãŒã远跡ããããã«å©çšã§ãããã°ã§ããADFS Admin ãã°ãšã¯ç°ãªãããã©ãã«ã®æç¡ã«é¢ãããªãèšé²ããããããæå¹ã«ãããšèšå€§ãªãã°ãèšé²ãããŸãããã®ããããã©ãã«ã·ã¥ãŒãã£ã³ã°ãè¡ããªã©ãæç¢ºãªç®çããããšãã ãå©çšããŸãã
æ¢å®ã§ã¯ãDebug ãã°ã¯ç¡å¹ã«ãªã£ãŠãããããå©çšããå Žåã«ã¯æ¬¡ã®æ¹æ³ã§æå¹ã«ããŸãã
â ADFS Admin ãã°ãã [åæããã³ãããã° ãã°ã®è¡šç€º] ãæå¹ã«ãã
Admin ãã°ãå³ã¯ãªãã¯ãã[衚瀺] â [åæããã³ãããã° ãã°ã®è¡šç€º] ãã¯ãªãã¯ãããšãé
ç®ã衚瀺ãããŸãã
â ADFS debug ãã°ãã [ãã°ã®æå¹å] ãå®è¡ãã
Debug ãã°ãå³ã¯ãªãã¯ãã[ãã°ã®æå¹å] ãã¯ãªãã¯ãããšãã¬ãŒã¹ãã°ãæå¹ã«ãªããŸããDebugãã°ã¯ Admin ãã°ã«æ¯ã¹ãŠå€ãã®ãã°ãåºåããããããã©ãã«ã·ã¥ãŒãã£ã³ã°ãªã©ã®ç®çã§èšé²ããããšãã ãæå¹ã«ããŠãã ãããDebug ãã°ãç¡å¹ã«ãããšã㯠Debug ãã°ãå³ã¯ãªãã¯ãã[ãã°ã®ç¡å¹å] ãã¯ãªãã¯ããŸãã
Debug ãã°ã¯æå€§ãã°ãµã€ãºã 50MB ã«èšå®ãããŠããããŸã 50MB ã«éããŠãå€ããã°ãäžæžãããŸããã50MB 以äžã®ãã°ãèšé²ã§ããããã«ããããã«ã¯ãdebug ãã°ã®ããããã£ããæå€§ãã°ãµã€ãºã倿ŽããŸãã
![ã¹ã©ã€ã155 ã¹ã©ã€ã155]()
ADFS ãå©çšãã ID 飿ºã§ãã©ãã«ãçºçããå Žåããã©ãã«ã®åå ã ADFS ã«ããã°ãã»ãšãã©ã®ã±ãŒã¹ã«ãã㊠Admin ãã°ã«ãã©ãã«ã®å
容ãèšé²ãããŸããããã§ã¯ãAdmin ãã°ã«èšé²ãããå
容ãäžå¿ã«ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãè¡ãæ¹æ³ã«ã€ããŠè§£èª¬ããŸãã
â ã€ãã³ã ID 364 ãèšé²ãããã
ã€ãã³ã ID 364 ã¯ããã·ã ãããã¡ã€ã«ãå©çšããŠã¯ã¬ãŒã ããŒã¹èªèšŒãè¡ãããšãããšãã«ãçºçãããšã©ãŒã衚ããŸãããã®ãšã©ãŒãçºçãããšãã«ã¯ãã€ãã³ã ID 133 ãç¶ããŠèšé²ãããŸãããæ ¹æ¬çãªåé¡ã®åå ã¯ã€ãã³ã ID 364 ã«ãããŸãããã®ãšã©ãŒãçºçããå Žåã以äžã®ãã©ãã«ã®å¯èœæ§ããããŸãã
ã»ADFS ãµãŒããŒã«èšŒææžãã€ã³ã¹ããŒã«ãããŠããªã
ã»èšŒææžãšããŠãã³ã³ãã¥ãŒã¿ãŒçšèšŒææžã§ã¯ãªãããŠãŒã¶ãŒçšèšŒææžãã€ã³ã¹ããŒã«ãããŠãã
ã»ãã©ã€ããŒãããŒãå«ãèšŒææžã«å¯Ÿãã ADFS ãµãŒãã¹ ã¢ã«ãŠã³ãã®ã¢ã¯ã»ã¹èš±å¯ããªã
ã»èšŒææžã倱å¹ããŠããããšã確èªããããã® CRL ã«ã¢ã¯ã»ã¹ã§ããªã
ã»èšŒææžã® CN ã SAN ã§ç€ºãããååãé©åã§ã¯ãªã
ãªã©
â ã€ãã³ã ID 342 ãèšé²ãããã(1)
ã€ãã³ã ID 342 ã¯ããŒã¯ã³ã®æ€èšŒã«å€±æããããšã衚ããŸããããŒã¯ã³ã®æ€èšŒã«å€±æããåå ãšããŠãèšŒææžã®æ£åœæ§ã®åé¡ãèããããŸããç¹ã«ã€ãã³ã ID 364 ãäžç·ã«çæãããå Žåã¯èšŒææžé¢é£ã®åé¡ã§ããããšãé«ãã§ãããã®å Žåã«ã¯ãèšŒææžã®ããããã£ãéããèšŒææžã«èšèŒãããŠããåå (CN ãªã©)ã«èª€ãããªãããèšŒææžã«èšèŒãããŠãã CRL ã«ã¢ã¯ã»ã¹ã§ãããããªã©ã確èªããŠãã ããã
â ã€ãã³ã ID 342 ãèšé²ãããã(2)
ã€ãã³ã ID 342 ã¯ããŒã¯ã³ã®æ€èšŒã«å€±æããããšã衚ããŸããããŒã¯ã³ã®æ€èšŒã«å€±æããåå ãšããŠãWindowsèªèšŒã®å€±æãèããããŸããç¹ã«ããã¡ã€ã³å\ãŠãŒã¶ãŒåã®åœ¢åŒã§ãŠãŒã¶ãŒåãå
¥åããªããã°ãªããªãã®ã«ããã¡ã€ã³åãå
¥åããŠããªããå
¥åãã¹ããã¡ã€ã³åãééããŠãããªã©ã確èªããŠãã ããã
â ã€ãã³ã ID 278 ãèšé²ãããã
ã€ãã³ã ID 278 㯠SAML ã¢ãŒãã£ãã¡ã¯ã ãããã¡ã€ã«ããµããŒããããµãŒããŒæ§æã§ãªããšãã«èšé²ãããŸããSAML ã¢ãŒãã£ãã¡ã¯ã ãããã¡ã€ã«ã¯ ADFS ãµãŒããŒã®ããŒã¿ããŒã¹ã« SQL Server ãå©çšããŠããããšãåæãšãªããããçµã¿èŸŒã¿ã®ããŒã¿ããŒã¹ã§ ADFS ãµãŒããŒãã€ã³ã¹ããŒã«ããŠããå Žåã¯å¿
ãåºåãããŸããSAML ã¢ãŒãã£ãã¡ã¯ã ãããã¡ã€ã«ãå©çšããªãéããåé¡ã«ã¯ãªããŸããã®ã§ãç¡èŠããŠãã ããã
â ã€ãã³ã ID 415 ãèšé²ãããã
ã€ãã³ã ID 415 㯠Workplace Join æ©èœãå©çšããŠãADFS ãµãŒããŒçµç±ã§ããã€ã¹ç»é²ãè¡ãããã«å¿
èŠãªæ§æã§ã¯ãªããšãã«èšé²ãããŸããADFS ãµãŒããŒã§ããã€ã¹ç»é²ãè¡ãããã«ã¯ ADFS ãµãŒããŒã«å®è£
ãããèšŒææžã® SAN ã« enterpriseregistrationïœã§å§ãŸãååãå«ãŸããŠããå¿
èŠããããŸãããå®éã«å®è£
ãããŠããèšŒææžã«ã¯å«ãŸããŠããªãããšãåå ã§ãããã ããADFS ãµãŒããŒçµç±ã§ããã€ã¹ç»é²ãè¡ãå¿
èŠããªãå Žåã¯åé¡ã«ã¯ãªããŸããã®ã§ãç¡èŠããŠãã ããã
â ã€ãã³ã ID 184 ãèšé²ãããã
ã€ãã³ã ID 184 ã¯èšŒææžã«é¢ãããšã©ãŒã衚ããŸãããã®ãšã©ãŒãçºçãããšãã®ç¹åŸŽã¯ããã©ãŠã¶ãŒããã¢ã¯ã»ã¹ãããšãã«ããã©ãŠã¶ãŒç»é¢ã«X.509 Certificateã«é¢ãããšã©ãŒç»é¢ã衚瀺ãããããšãšãã€ãã³ã ID 364 ãåŸç¶ãããšã©ãŒãã°ãšããŠèšé²ãããç¹ã§ãããã®ãšã©ãŒãçºçãããšãã¯ãèšŒææžã®çºè¡æ¹æ³ã«åé¡ããããšèããããŸãã®ã§ãèšŒææžã®ã€ã³ã¹ããŒã«ãåèšå®ããŠãã ããããŸããèªèšŒå±ãADFS ãµãŒããŒã®ä¿¡é Œãããã«ãŒãèšŒææ©é¢ã«ç»é²ãããŠããããšãåæã«ç¢ºèªããŠãã ããã
â ã€ãã³ã ID 102 ãèšé²ãããã
ã€ãã³ã ID 102 ã¯ãµãŒãã¹èµ·åã«é¢ãããšã©ãŒã衚ããŸããåå ã¯æ§ã
ã§ãããå®è£
çŽåŸã«èããããåå ãšããŠã¯ ADFS ãµãŒããŒã«å¯Ÿå¿ãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãæ§æãããŠããªãããšãåå ã§ãšã³ããã€ã³ãã®æå¹åã«å€±æããããšãèããããŸããADFS ãµãŒããŒã¯èµ·åæã«ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãæ§æããã®ã§ããµãŒãã¹ãåèµ·åããŠãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãäœæãããããšã確èªãããšããã§ãããã
â ã€ãã³ã ID 133 ãèšé²ãããã
ã€ãã³ã ID 133 ã¯ããŒã¯ã³ã«ã¢ã¯ã»ã¹ã§ããªããšã©ãŒã衚ããŸãããã ãã宿
ã¯èšŒææžã«é¢é£ãããã©ãã«ãã»ãšãã©ã§ãããã®ãšã©ãŒãçºçãããšãã«ã¯ãã€ãã³ã ID 102 ãš 364 ãç¶ããŠèšé²ãããŸãããæ ¹æ¬çãªåé¡ã®åå ã¯ã€ãã³ã ID 133 ã«ãããŸãããã®ãšã©ãŒãçºçããå Žåã以äžã®ãã©ãã«ã®å¯èœæ§ããããŸãã
ã»ãã©ã€ããŒãããŒãå«ãèšŒææžã«å¯Ÿãã ADFS ãµãŒãã¹ ã¢ã«ãŠã³ãã®ã¢ã¯ã»ã¹èš±å¯ããªã
ã»èšŒææžãšããŠãã³ã³ãã¥ãŒã¿ãŒçšèšŒææžã§ã¯ãªãããŠãŒã¶ãŒçšèšŒææžãã€ã³ã¹ããŒã«ãããŠãã
ã»ãã©ã€ããŒãããŒãå«ãèšŒææžã«å¯Ÿãã ADFS ãµãŒãã¹ ã¢ã«ãŠã³ãã®ã¢ã¯ã»ã¹èš±å¯ããªã
ã»èšŒææžãšããŠãpfx ãã¡ã€ã«ã§ã¯ãªããcer ãã¡ã€ã«ãã€ã³ããŒãããã
â ã€ãã³ã ID 325 ãèšé²ãããã
ã€ãã³ã ID 325 㯠RP ã®èªå¯ã«å€±æããããšã衚ããã°ã§ããèªå¯ã«é¢ããŠã¯ [çºè¡æ¿èªèŠå] ã§å®çŸ©ãããŠããã®ã§ããã®èŠåã§èš±å¯ãããªãã¯ã¬ãŒã ãããŒã¯ã³å
ã«æã£ãŠããå Žåã«èªå¯ã«å€±æããŸãããã®ã»ããçºè¡æ¿èªèŠåã§èªå¯ã®åºæºãšãªãæ
å ±ãã¯ã¬ãŒã ã§æã£ãŠããªãå Žå (emailaddress屿§ãããšã«èªå¯ãè¡ãã®ã«ãããŒã¯ã³ã«ã¯emailaddress屿§ãå«ãŸããŠããªããªã©) ã«ãåæ§ã®ãšã©ãŒãšãªããŸãããã®ãããã€ãã³ã ID 325 ãèšé²ãããæã«ã¯ãåŸç¶ã®ãã°ã«ã€ãã³ã ID 501 ãèšé²ãããã®ã§ãã€ãã³ã ID 501 ã®ãã°ããçºè¡ãããããŒã¯ã³ã®å
容ã確èªããçºè¡æ¿èªèŠåã§å¿
èŠãšãã屿§ãããŒã¯ã³ãšã㊠CP ã§çºè¡ãããŠããã確èªããŠãã ããã
â ã€ãã³ã ID 315 ãèšé²ãããã
ã€ãã³ã ID 315 ã¯ããŒã¯ã³èšŒæèšŒææžã§äœ¿ãããèšŒææžãã§ãŒã³ã®æ€èšŒã«å€±æããããšã衚ããŸããç°ãªãçµç¹éã§ ID 飿ºãå±éããå ŽåãRP ã®çµç¹ãã CP ã®çµç¹ã§å±éããèªèšŒå±ãžã®ã¢ã¯ã»ã¹ (CDP ãš AIA) ãå¿
é ã«ãªããŸããCP ã®çµç¹ã®èªèšŒå±ãã€ã³ãã©ãããå
ã§å±éãããå€éšããã®ã¢ã¯ã»ã¹ãèš±å¯ãããŠããªãå Žåã«ã¯ãSet-ADFSClaimsProviderTrust ã³ãã³ãã¬ããã§ãæ€èšŒãè¡ããªãããã«èšå®ããŠãã ããã
â ã€ãã³ã ID 218/276/394 ãèšé²ãããã
ã€ãã³ã ID 218/276/394/422 㯠Web ã¢ããªã±ãŒã·ã§ã³ ãããã·ã ADFS ãã§ãã¬ãŒã·ã§ã³ ãµãŒããŒãšã®ä¿¡é Œé¢ä¿ã確èªã§ããªãã£ããšãã«ãWeb ã¢ããªã±ãŒã·ã§ã³ãããã·ã®ã€ãã³ã ãã¥ãŒã¢âã§èšé²ãããŸããåå ã¯ã©ã®ãããªã€ãã³ã ID ãèšé²ããããã«ãã£ãŠåé¡ããããšãã§ããŸãã
ã€ãã³ã ID 218 ãèšé²ãããå ŽåãADFS ãµãŒããŒã§å
¥ãæ¿ããèšŒææžã Web ã¢ããªã±ãŒã·ã§ã³ ãããã·ã«å®è£
ãããŠããªãããšã«ãããã©ãã«ããADFS ãµãŒããŒãš Web ã¢ããªã±ãŒã·ã§ã³ ãããã·ã®æå»ããããŠããããšãèããããŸããç¹ã«ãæå»ããããŠããå Žåã«ã¯ Web ã¢ããªã±ãŒã·ã§ã³ ãããã·ãåæ§æããããšãæ€èšããŠãã ããã
ã€ãã³ã ID 276 ãèšé²ãããå ŽåãADFS ãµãŒããŒã§ Web ã¢ããªã±ãŒã·ã§ã³ãããã·ãšã®ä¿¡é Œã倱å¹ããããšã衚ããŸãããã®å Žåã«ã¯ Web ã¢ããªã±ãŒã·ã§ã³ ãããã·ã®åæ§æãå¿
é ã«ãªããŸãããªããä¿¡é Œã倱å¹ããŠããå ŽåãWeb ã¢ããªã±ãŒã·ã§ã³ ãããã·åŽããã¯ã€ãã³ã ID 422 ã§ç¢ºèªã§ããŸãã
ã€ãã³ã ID 422 ãèšé²ãããå ŽåãADFS ãµãŒããŒãš Web ã¢ããªã±ãŒã·ã§ã³ãããã·ã®éã§ç©ççã«æ¥ç¶ã§ããªãããšãèããããŸãããã®ã€ãã³ãã衚瀺ãããå Žåã«ã¯ãŸãç©ççãªæ¥ç¶ã確ç«ãããŠããããšã DNS ã Hosts ãã¡ã€ã«ã«ããååè§£æ±ºãæ£ããè¡ããŠããããšã確èªããŠãã ãããADFS ãµãŒããŒãš Web ã¢ããªã±ãŒã·ã§ã³ ãããã·ã®éã§ã®åæã¯ 1 åããã«è¡ããããããæåã®ãšã©ãŒãã°ãåç
§ããããšã§ããã©ãã«ãå§ãŸã£ããããããã®æ¥æãç¹å®ããããšãå¯èœã§ãã
å¯ŸåŠæ¹æ³ãšããŠã¯ Install-WebApplicationProxyã³ãã³ãã¬ãããå®è¡ããæ¹ã㊠ADFS ãµãŒããŒãš Web ã¢ããªã±ãŒã·ã§ã³ãããã·ã®éã§ä¿¡é Œé¢ä¿ãèšå®ããŠãã ããã
ãŸãã以äžã®ãã©ãã«ã ADFS 2.x ãµãŒããŒã§çºçããå Žåãã€ãã³ã ID 394 ã§ç¢ºèªã§ããŸãã
â ã€ãã³ã ID 376 ãèšé²ãããã
ã€ãã³ã ID 376 ã¯ å±æ§ã¹ãã¢ãšããŠãActive Directory 以å€ã®ãã®ãå©çšããŠããéãèŠæ±èŠåã«èšèŒãããŠããæ
å ±ã«åºã¥ããŠæ£ããããŒã¿ãååŸã§ããªãéã«èšé²ãããŸãããã®ã€ãã³ã ID ã§ã¯ã屿§ã¹ãã¢ã® SQL æ¥ç¶æååã®åé¡ãSQL 屿§ã¹ãã¢ã«æ¥ç¶ã§ããªããããŒã¿ããŒã¹ãšã¯ãšãªãŒã®æ£åœæ§ã®åé¡ãã®ãããããåå ã§ããã€ãã³ã ID 376 ã§ã¯ããã°å
ã«è©³çްãªãšã©ãŒé¢é£æ
å ±ãèšé²ãããã®ã§ãã€ãã³ããã°ã®å
容ã確èªããã®ã¯ããšãŠãæå¹ãªææ®µã§ãã
â ã€ãã³ã ID 377 ãèšé²ãããã
ã€ãã³ã ID 377 ã¯ èŠæ±èŠåã«èšè¿°ãããã¯ã¬ãŒã ã«ãŒã«ã®å
容ã«åé¡ããããšãã«èšé²ãããŸãããã®ã€ãã³ã ID ãèšé²ãããæã«ã¯ãã¯ã¬ãŒã ã«ãŒã«ã®å
容ãå確èªããŠãã ããã
â ã¢ããªã±ãŒã·ã§ã³ãã° : ã€ãã³ã ID 1309 ãèšé²ãããã
ã€ãã³ã ID 1309 ã¯ASP.NETã®åŠçã§ãšã©ãŒãçºçãããšãã«èšé²ããããã°ã§ãããã®å ŽåãASP.NET ã®åŠçãã€ããã©ãããã»ã¹ã§ãã w3wp.exe ã匷å¶çµäºããŠãã ããããŸãããã°ã®è©³çްã¡ãã»ãŒãžã§ãäŸå€ã¡ãã»ãŒãž ID3206 SignInResponseã¡ãã»ãŒãžã¯ãçŸåšã® Web ã¢ããªã±ãŒã·ã§ã³å
ã§ã®ã¿ãªãã€ã¬ã¯ããããŸãããšè¡šç€ºãããå Žåã«ã¯ãURL ã®æåŸã« / (ã¹ã©ãã·ã¥) ãæããŠããããšãåå ãšããŠèããããŸãã®ã§ãã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒã®ãã©ãŠã¶ãŒç»é¢ã§ãURL ã確èªããŠãã ããã
ADFS ã®åŠçã«é¢ããŠããã®ä»ã®ã€ãã³ã ID ãèšé²ããããšã©ãŒãçºçããå Žåããã€ã¯ããœãã TechNet Web ãµã€ããåç
§ããŠãã ããã
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ff641746(v=ws.10)?redirectedfrom=MSDN
![ã¹ã©ã€ã156 ã¹ã©ã€ã156]()
ADFS ã§ã¯ãããã©ãŒãã³ã¹ã¢ãã¿ãŒãå©çšããŠADFSã«ããããŒã¯ã³çºè¡ã®ã¢ã¯ãã£ããã£ãŒããªã¢ã«ã¿ã€ã ã§ç¢ºèªã§ããŸããããŒã¯ã³çºè¡ã«é¢ããããã©ãŒãã³ã¹ã確èªããå Žåãããã©ãã«ã·ã¥ãŒãã£ã³ã°ãè¡ããšãã«åœ¹ç«ãŠãããšãå¯èœã§ãã
![ã¹ã©ã€ã157 ã¹ã©ã€ã157]()
ADFS ã§ã¯ãå®è£
ããããã«è¡ããªããã°ãªããªãé
ç®ãå€ããããèšå®ãã¹ã«ãããã©ãã«ãçºçããããšããããŸãããããããã©ãã«ãçºçãããšãã«ã¯ãäžè¬çãªãã©ãã«ã·ã¥ãŒãã£ã³ã°ãšåããããã©ãã«ã®åãåããè¡ãããšãéèŠã«ãªããŸãã
SAML Tracer ããŒã«ã¯ãFirefox ã®ã¢ããªã³ããã°ã©ã ã§ãHTTP ã®ããããŒããªã¢ã«ã¿ã€ã ã§è¡šç€ºããŸããããããŒã®å
容ãåç
§ããªããéä¿¡äžã«éåä¿¡ããã SAML ããŒã¯ã³ã®å
容ã確èªããããšã§ããã©ãã«ã·ã¥ãŒãã£ã³ã°ããããããããã©ãã«ã®åå ãèŠã€ãããããã广ããããŸãã
SAML Tracer ããŒã«ã¯ã€ã³ã¹ããŒã«ãããšãã¡ãã¥ãŒãã [SAML Tracer] ã¢ã€ã³ã³ãã¯ãªãã¯ããããšã§ãå¥ãŠã£ã³ããŠã衚瀺ããããŠã£ã³ããŠå
ã§ Firefox å
ã§ã®éä¿¡ã®æ§åã確èªã§ããŸãã
ãŸããHTTP ããããŒå
ã«è¡šç€ºããããã§ãã¬ãŒã·ã§ã³ ãããã³ã«ã®å
容㯠[Parameters] ã¿ããã¯ãªãã¯ããŠç¢ºèªã§ããŸãã
![ã¹ã©ã€ã158 ã¹ã©ã€ã158]()
SAML Tracer ã§ HTTP ããããŒã®è¿œè·¡ãè¡ãããã©ãã«ã·ã¥ãŒãã£ã³ã°ãè¡ãããã«ã¯ããŸãæ£åžžãªéä¿¡ã§çºçããããããŒã«ã€ããŠç¥ãå¿
èŠããããŸããããã§ã¯ãOffice 365ãžãã©ãŠã¶ãŒããã·ã³ã°ã«ãµã€ã³ãªã³ã¢ã¯ã»ã¹ããéã«çºçãããHTTP ããããŒã«ã€ããŠç¢ºèªããŸãã
â GET /
Office 365 ã®ãµã€ãã«ã¢ã¯ã»ã¹ããŸãããã®ãšããã¢ã¯ã»ã¹ããŒã¯ã³ãæããªãç¶æ
ã§ã¢ã¯ã»ã¹ããŠãããããAzure AD ãµã€ãã«ãªãã€ã¬ã¯ããããŸãã
â¡ GET /login.srf?wa=wsignin1.0&âŠ
Azure AD ãµã€ãã«ãªãã€ã¬ã¯ãããããšãã«æåã«ã¢ã¯ã»ã¹ããããŒãžã login.srf ããŒãžã§ãããã®åŸããã©ãŠã¶ãŒç»é¢ã§ã¯ããµã€ã³ã€ã³ããŒãžã衚瀺ãããŸãã
⢠GET /common/userrealm/?user=âŠ
ãµã€ã³ã€ã³ããŒãžã§ããŠãŒã¶ãŒåãå
¥åãããšããã®ãµã€ã³ã€ã³ãŠãŒã¶ãŒãã·ã³ã°ã«ãµã€ã³ãªã³çšãã¡ã€ã³ãå©çšããŠããããšã確èªããADFS ãµãŒããŒãžãªãã€ã¬ã¯ãããŸãããã® URL ã¯ãŠãŒã¶ãŒåãå
¥åããåŸã«æåã«ã¢ã¯ã»ã¹ãã URL ã§ãã
⣠GET /adfs/ls/wia?lc=1041&username=âŠ&wa=wsignin1.0&wtrealm=urnâŠ
ADFS ãµãŒããŒã«ã¢ã¯ã»ã¹ãããšãããŒã¯ã³çºè¡ã®ããã®ããåããå§ãŸããŸãããã® URL ã§ã¯ãµã€ã³ã€ã³ããŒãžã§å
¥åãããŠãŒã¶ãŒå (username=éšå) ã ADFS ãµãŒããŒã«åŒãæž¡ããŠãããŒã¯ã³çºè¡åŠçãéå§ããŠããŸãããªãããŠãŒã¶ãŒåããã©ãŠã¶ãŒã§ãã£ãã·ã¥ãããŠãããšããªã©ã¯ããã® URL ã«ã¢ã¯ã»ã¹ããªãå ŽåããããŸãã
†POST /login.srf
ADFS ãµãŒããŒã§ããŒã¯ã³ãçºè¡ããããšãAzure AD ã«ããŒã¯ã³ãæã£ãŠã¢ã¯ã»ã¹ããŸãããã®ãšãã«æåã«ã¢ã¯ã»ã¹ããããŒãžã login.srf ããŒãžã§ããlogin.srf ããŒãžã§ã¯ããŒã¯ã³ã Azure AD ã«åŒãæž¡ããããPOST ã¡ãœããã䜿ã£ãŠã¢ã¯ã»ã¹ããŠããŸãã
⥠POST /landing.aspx?target=%2fdefault.aspx&wa=wsignin1.0
Azure AD ã§ã®èªå¯ããã»ã¹ãå®äºãããšãOffice 365 ã«ã¢ã¯ã»ã¹ããããã®ããŒã¯ã³ãçºè¡ãããŸããã¢ã¯ã»ã¹ããŒã¯ã³ãæã£ãŠ Office365ã«ã¢ã¯ã»ã¹ããéã«å©çšããããŒãžã landing.aspx ããŒãžã§ãã
以äžã®ããŒãžä»¥å€ã«ãå®éã®éä¿¡ã§ã¯æ§ã
ãªãã±ãããéåä¿¡ãããŸãããããã以äžã®ãããŸããªæµããçè§£ããŠããããšã§ããã©ãã«ãçºçããéã«ã©ããŸã§ã®éä¿¡ãã§ããŠããããææ¡ããæ¬¡ã«è¡ãã¹ãã¢ã¯ã·ã§ã³ããèªèº«ã§å€æã§ããããã«ãªããŸãã
![ã¹ã©ã€ã159 ã¹ã©ã€ã159]()
SAML Tracer ã¢ããªã³ããåç
§å¯èœãª HTTP ããããŒã«ã¯ãïŒä»¥éã®éšåã«æ§ã
ãªãã©ã¡ãŒã¿ãŒãèšè¿°ãããŠããŸãããããã®ãã©ã¡ãŒã¿ãŒã¯ãã§ãã¬ãŒã·ã§ã³ãããã³ã«ã§å®çŸ©ããããã®ãèšè¿°ããŠããããããã³ã«çš®é¡ã«ãã£ãŠèšè¿°ãã¹ãé
ç®ã¯ç°ãªããŸããããã§ã¯ãããããã®ãããã³ã«ã§äœ¿çšãããäž»ãªãã©ã¡ãŒã¿ãŒã«ã€ããŠè§£èª¬ããŸãã
â WS-FederationïŒwa=
wa= ã¯ã¢ã¯ã·ã§ã³ã衚ããŸããäŸãã°ãwsignin=1.0 ãšèšè¿°ãããŠããå Žåããããããµã€ã³ã€ã³ãè¡ãããšã衚ããŸãã
â WS-FederationïŒwtrealm=
wtrealm= ã¯ã¬ã«ã ã衚ããŸããã¬ã«ã 㯠STS ä¿¡é Œãçµã¶çžæã衚ããŸãã®ã§ãOffice365ã«ã¢ã¯ã»ã¹ããŠããå Žåã§ã¯ãã¬ã«ã ãšã㊠Azure AD ã衚ãæ
å ± (urn:federation:MicrosoftOnline) ãèšè¿°ãããŠããŸãã
â WS-FederationïŒwctx=
wctx= ã¯çžæã® STS ã«äŒãã URL ãªã©ã®ã»ãã·ã§ã³æ
å ±ãå
¥ããŸãã
â WS-FederationïŒwct=
wct= ã¯æå»ã®æ
å ±ãå
¥ããŸãã
â SAMLïŒSAMLRequest=
SAMLRequest= ã«ã¯ SAML ããŒã¯ã³ã®æ
å ±ã Base64 圢åŒã§ãšã³ã³ãŒãããã圢ã§å
¥ããŸãããšã³ã³ãŒããããããŒã¿ã¯ SAML Debugger ãµã€ããªã©ãéããŠãã³ãŒãããåç
§ããããšãã§ããŸãã
â SAMLïŒRelayState=
RelayState= ã«ã¯çžæã® STS ã«äŒããã»ãã·ã§ã³æ
å ±ãå
¥ããŸãã
â SAMLïŒSigAlg=
SigAlg= ã«ã¯åŸç¶ã®ããŒã¿ã§æ ŒçŽããã眲åããŒã¿ã®çœ²åã¢ã«ãŽãªãºã ã®æ
å ±ãå
¥ããŸãã
â SAMLïŒSignature=
Signature= ã«ã¯ SAMLRequest ã®ããžã¿ã«çœ²åãå
¥ããŸãã
![ã¹ã©ã€ã160 ã¹ã©ã€ã160]()
Office 2016 ããã³ Office 2013 ã§ã¯ ADAL (Active Directory Authentication Library) ã«å¯Ÿå¿ããOffice ã¢ããªã±ãŒã·ã§ã³ããã§ãå€èŠçŽ èªèšŒãå©çšã§ããããã«ãªããŸãããããããäžéšã®ããŒãžã§ã³ã®Office 2013 ã§ã¯ ADAL ããå©çšãã Windows çµ±åèªèšŒã« WS-Trust 1.3ã®
/adfs/services/trust/13/windowstransport ãšã³ããã€ã³ããå©çšããŸã (é垞㯠WS-Trust 2005 ã®ãšã³ããã€ã³ãã䜿çš)ããã®ãšã³ããã€ã³ã㯠ADFS ãµãŒããŒæ¢å®ã®èšå®ã§ç¡å¹ã«ãªã£ãŠããããã®ããšãåå ã§ç€Ÿå
ãã ADAL ã¢ããªãå©çšããŠèªèšŒãè¡ããšãšã©ãŒã«ãªãå ŽåããããŸãããã®ãããªã±ãŒã¹ã§ã¯ã/adfs/services/trust/13/windowstransport ãšã³ããã€ã³ããæå¹åããADAL ã¢ããªãããèªèšŒã»èªå¯ãã§ããããã«æ§æããŠãã ããã
![ã¹ã©ã€ã161 ã¹ã©ã€ã161]()
iPhone ã Android ãªã©ã®ãã¡ã€ã³åå ãè¡ããªãããã€ã¹ã¯ãOffice 365 ãžã®ãµã€ã³ã€ã³ã«ãŠãŒã¶ãŒå/ãã¹ã¯ãŒããå
¥åããèªèšŒãå¿
èŠãšããŸããããããæ¢å®ã§ã¯ Web ã¢ããªã±ãŒã·ã§ã³ãããã·ãçµç±ããªãèªèšŒã«ã¯ãã©ãŒã èªèšŒã§ã¯ãªããWindows çµ±åèªèšŒãå©çšãããããWindows çµ±åèªèšŒããµããŒãããªãiPhone ã Android ãªã©ã®ããã€ã¹ã瀟å
ãããã¯ãŒã¯ããèªèšŒããããšãããšãšã©ãŒã«ãªããŸãã
ãã®å Žåã瀟å
ãããã¯ãŒã¯ããã§ããã©ãŒã èªèšŒãå©çšã§ãããããADFS 管çããŒã«ãã [èªèšŒããªã·ãŒ] ãå³ã¯ãªãã¯ãã[ã°ããŒãã« ãã©ã€ããªèªèšŒã®ç·šé] ãã¯ãªãã¯ããŠã[ã€ã³ãã©ããã] æ¬ã® [ãã©ãŒã èªèšŒ] ãæå¹ã«ããŠãã ããã
![ã¹ã©ã€ã162 ã¹ã©ã€ã162]()
ADFS ãµãŒããŒã§ã¯ãActive Directory ã®èªèšŒæ
å ±ãããŒã¹ã«ããŒã¯ã³ãçºè¡ããŸãããã®ãããèªèšŒã»èªå¯ã«é¢ãããµãŒããŒã Kerberos ã®ä»æ§ã«åºã¥ããŠåäœããªããã°ãªããŸãããäžã§ã泚æããªããã°ãªããªãç¹ã¯ Kerberos ã®æå»ã«é¢ãã仿§ã§ãã
Active Directory (Kerberos) ã§ã¯ãæ¢å®ã§ ãã¡ã€ã³ã³ã³ãããŒã©ãŒãšã³ã³ãã¥ãŒã¿ãŒã®éã§ 5å以äžã®æå»ã®ãºã¬ããããšãKerberos èªèšŒã»èªå¯ãè¡ãã®ã«ãµãããããªãçžæãšå€æããåŠçãäžæ¢ããŸãããã¡ã€ã³åå ããŠããã³ã³ãã¥ãŒã¿ãŒã®å Žåã«ã¯ Active Directory ã®æ©èœã«ããããã¡ã€ã³ã³ã³ãããŒã©ãŒãšèªåçã«æå»ãåæããŸãããWeb ã¢ããªã±ãŒã·ã§ã³ ãããã·ã®ããã«ãDMZ ã«ãµãŒããŒãé
眮ãããŠããå Žåã«ã¯ãã¡ã€ã³åå ããŠããªãããšãå€ããããæå»ã®ãºã¬ãçºçããå¯èœæ§ããããŸãã
ãããå
éšãããã¯ãŒã¯ããã®ã·ã³ã°ã«ãµã€ã³ãªã³ã¯æåããã«ãããããããå€éšãããã¯ãŒã¯ããã®ã·ã³ã°ã«ãµã€ã³ãªã³ã«å€±æããå Žåã«ã¯ãWeb ã¢ããªã±ãŒã·ã§ã³ãããã·ã®æå»ã確èªããŠãã ããã
![ã¹ã©ã€ã163 ã¹ã©ã€ã163]()
ADFS ãµãŒããŒã§ã¯ãActive Directory ã§èªèšŒãããŠãŒã¶ãŒã®æ
å ±ã LSA ã«ãã£ãã·ã¥ããŸããå
·äœçã«ã¯ããŠãŒã¶ãŒã®ååãš SID ã®ãããã³ã°æ
å ±ããã£ãã·ã¥ããSID ã«å¯Ÿå¿ããååãæ¯å Active Directory ãåç
§ããªããŠãããããã«ããŠããŸãã
ããããActive Directory ã§ãŠãŒã¶ãŒã®åå (sAMAccountName ãŸã㯠UPN) ã倿ŽããŠãããã£ãã·ã¥ã«ã¯ãã®å€æŽããã°ããã®éãåæ ãããŸããããã®ãããååã倿ŽããŠã倿Žåã®ååãã¯ã¬ãŒã ã«ã»ãããããŠããŸããŸãããã®ãããªåé¡ã解決ããã«ã¯ã以äžã®æ¹æ³ã§å¯ŸåŠããŸãã
â ADFS ãµãŒãã¹ãåèµ·åãã
ADFS ãµãŒãã¹ãåèµ·åããããšã«ãã£ãŠããã£ãã·ã¥ã¯ãã¹ãŠåé€ãããADFS ãµãŒããŒã¯æ°ãããŠãŒã¶ãŒã®ååãååŸããŸãã
â ãã£ãã·ã¥ãµã€ãºã倿Žãã
ãã£ãã·ã¥ã¯ã¬ãžã¹ããªã§å®çŸ©ãããŠããŸããã¬ãžã¹ããªã®èšå®ãçŽæ¥ç·šéããããšã§ããã£ãã·ã¥ããªãããã«èšå®ããããšãå¯èœã§ãã
ã¬ãžã¹ã㪠HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA ã®
LsaLookupCacheMaxSize (DWORDå€) ã®å€ã 0 ã«èšå®ããããšã§ããã£ãã·ã¥ãããªãããã«å®çŸ©ã§ããŸãã
ç·šéåŸèš
ã€ãã«341ããŒãžãã£ãããã¹ãããã¹ãŠå
¬éå®äºããŸããã
ãADFSãç¥ã£ãŠãããããããšããäžå¿ã§æ¡ç®ãšã床å€èŠã§ããã¹ãã®éçºã«ã¯å€ãã®æéãè²»ãããŠããŸããã
2012幎ãããã®ãã¬ãŒãã³ã°ãå§ããŠçŸåšã¯Azure ADã®ãã¬ãŒãã³ã°ã«åŒãç¶ããããŸã§ã
8幎ã«ããã£ãŠã·ã³ã°ã«ãµã€ã³ãªã³ã®è©±ããç¶ããããã§ããã
çµæçã«ãããã£ã䞻匵ããã¡ãã¡ã§èŠãããããã«ãªã£ãããšã¯
(èªåãSAMLãæµè¡ãããããã§ãå
šããªããã©)æ¬åœã«ããããæããŸãã
â ãªãWebãµãŒãã¹ã®éžå®ã«ãããŠSAML/SSOãéèŠãªã®ã
https://oka-lab.jp/importance-of-saml-sso-in-web-services
ADFSã®ããã¹ãèªäœã¯æžäŸ¡ååŽãçµãã£ãããä»ã§ã誰ãã®åœ¹ã«ç«ã€ãªããšæããå
¬éããããšã«ããŸããããã®ããã¹ãå
¬éã¯ç§ã«ãšã£ãŠADFSããã®åæ¥ã¿ãããªãã®ã§ã忥ããŠãã£ããäœããããšããã®ãããããªããã©ãç¥ã£ãŠããããšã¯å
šéšæžããšããŸãããã ããADFSã®è³ªåã¯ããç§ã«ããªãã§ãã ããw
ããã
The post
ADFSãã¬ãŒãã³ã°ããã¹ãå
šæå
¬éãã£ã¬ã³ãžãæçµåã- ãã©ãã«ã·ã¥ãŒãã£ã³ã° first appeared on
Always on the clock.