{"id":675,"date":"2020-09-13T20:06:33","date_gmt":"2020-09-13T11:06:33","guid":{"rendered":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2020\/09\/13\/sso-saml-multiple-idp"},"modified":"2020-09-13T20:06:33","modified_gmt":"2020-09-13T11:06:33","slug":"sso-saml-multiple-idp","status":"publish","type":"post","link":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/blog\/2020\/09\/13\/sso-saml-multiple-idp\/","title":{"rendered":"\u3010SAMLSSO\u3011SAMLResponse\u306e\u4e2d\u8eab\u306fIdP\u6b21\u7b2c\u3067\u4e00\u90e8\u7570\u306a\u308b\u5834\u5408\u304c\u3042\u308b"},"content":{"rendered":"
<\/p>\n
\u4eca\u56de\u306fSAMLSSO(\u30b7\u30f3\u30b0\u30eb\u30b5\u30a4\u30f3\u30aa\u30f3)\u6642\u306eIdP(Identity Provider)\u306b\u3064\u3044\u30661\u70b9\u5171\u6709\u3057\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n
\u3068\u3042\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u5916\u90e8IDaaS\u3092\u524d\u63d0\u3068\u3057\u305fSSO\u304c\u6709\u52b9\u5316\u3055\u308c\u3066\u3044\u308b\u5834\u5408\u3001
\n\u305d\u306eIdP\u3068\u3057\u3066\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u69d8\u3005\u306a\u30af\u30e9\u30a6\u30c9\u30b5\u30fc\u30d3\u30b9\u3092\u5229\u7528\u3067\u304d\u307e\u3059\u3002<\/p>\n
etc...<\/p>\n
\u3053\u306e\u969b\u3001\u305d\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u5229\u7528\u3059\u308b\u30c6\u30ca\u30f3\u30c8\u3054\u3068\u306b\u7570\u306a\u308bIdP\u304c\u5229\u7528\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n
SAMLSSO\u3092\u958b\u59cb\u3059\u308b\u3068\u3001IdP\u304b\u3089SAMLResponse\u304c\u8fd4\u3055\u308c\u307e\u3059\u3002
\n\u3053\u306e\u969b\u3001\u5229\u7528\u3059\u308bIdP\u6b21\u7b2c\u3067SAMLResponse\u306e\u4e2d\u8eab\u304c\u4e00\u90e8\u7570\u306a\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n
\u4f8b\u3048\u3070\u3001\u540c\u5185\u5bb9\u306eSAMLRequest\u3092OneLogin\u3068Auth0\u306b\u6e21\u3057\u305f\u5834\u5408\u3001
\nSAMLResponse\u306eNameID\u8981\u7d20\u306f\u305d\u308c\u305e\u308c\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n
OneLogin<\/p>\n
<saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">example@example.com<\/saml:NameID><\/code><\/pre>\nAuth0<\/p>\n
<saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">auth0|7eha60c21bc1ac0k1778a251<\/saml:NameID><\/code><\/pre>\n\n- Onelogin\u306f\u30e6\u30fc\u30b6\u30fc\u306e\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9<\/li>\n
- Auth0\u306fuser_id<\/li>\n<\/ul>\n
\u304c\u5165\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n
IdP\u6b21\u7b2c\u3067\u500b\u5225\u306e\u5bfe\u5fdc\u304c\u5fc5\u8981<\/h2>\n
\u4eee\u306bSAMLResponse\u304b\u3089\u30e6\u30fc\u30b6\u30fc\u306e\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u53d6\u5f97\u3057\u305f\u3044\u5834\u5408\u3001
\n\u5229\u7528\u3059\u308bIdP\u6b21\u7b2c\u3067\u500b\u5225\u306e\u5bfe\u5fdc\u304c\u5fc5\u8981\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n
\u4eca\u56de\u306e\u30b1\u30fc\u30b9\u306e\u89e3\u6c7a\u6cd5\u3068\u3057\u3066\u306f\u3001<\/p>\n
\n- SAMLRequest\u3067SAMLResponse\u306eNameID\u8981\u7d20\u306e\u5024\u3092\u6307\u5b9a\u3059\u308b<\/li>\n
- IdP\u5074\u3067SAMLResponse\u306eNameID\u8981\u7d20\u306e\u5024\u3092\u8a2d\u5b9a\u3059\u308b<\/li>\n
- SAMLResponse\u5185\u306e\u5225\u8981\u7d20(\u4f8b\u3048\u3070Attribute\u8981\u7d20)\u304b\u3089\u5024\u3092\u53d6\u5f97\u3059\u308b<\/li>\n<\/ul>\n
\u3068\u3044\u3063\u305f\u624b\u6bb5\u304c\u8003\u3048\u3089\u308c\u307e\u3059\u3002<\/p>\n
\u307e\u3068\u3081<\/h2>\n
SAMLResponse\u306e\u4e2d\u8eab\u306fIdP\u6b21\u7b2c\u3067\u4e00\u90e8\u7570\u306a\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002
\n\u8907\u6570\u306eIdP\u306bSAMLSSO\u5bfe\u5fdc\u3059\u308b\u969b\u306b\u306f\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"
\u4eca\u56de\u306fSAMLSSO(\u30b7\u30f3\u30b0\u30eb\u30b5\u30a4\u30f3\u30aa\u30f3)\u6642\u306eIdP(Identity Provider)\u306b\u3064\u3044\u30661\u70b9\u5171\u6709\u3057\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002 \u8907\u6570\u306eIdP\u306b\u5bfe\u5fdc\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u5f97\u308b \u3068\u3042\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u5916\u90e8IDaaS\u3092\u524d\u63d0\u3068\u3057\u305fSSO\u304c\u6709\u52b9\u5316\u3055\u308c\u3066\u3044\u308b\u5834\u5408\u3001 \u305d\u306eIdP\u3068\u3057\u3066\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u69d8\u3005\u306a\u30af\u30e9\u30a6\u30c9\u30b5\u30fc\u30d3\u30b9\u3092\u5229\u7528\u3067\u304d\u307e\u3059\u3002 CloudGate UNO Okta AzureAD OneLogin Auth0 e […]<\/p>\n","protected":false},"author":10,"featured_media":684,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[264],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/675"}],"collection":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/comments?post=675"}],"version-history":[{"count":0,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/posts\/675\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/media?parent=675"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/categories?post=675"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/p-corporate-blog-cms.mmmcorp.co.jp\/wp-json\/wp\/v2\/tags?post=675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}