Microsoft AD FS
Keeper SSO Connect CloudใMicrosoft AD FSใจ้ฃๆบใใใฆใในใ ใผใบใงๅฎๅ จใชSAML 2.0่ช่จผใๅฎ็พ
ๆๅใซ็ฎก็ใณใณใฝใผใซใฎ่จญๅฎใฎๆ้ ใๅฎไบใใฆใใ ใใใ
Microsoft AD FS
ใใงใใฌใผใทใงใณใกใฟใใผใฟXMLใๅๅพ
AD FS็ฎก็ใขใใชใฑใผใทใงใณๅ ใงใใใงใใฌใผใทใงใณใกใฟใใผใฟxmlใใกใคใซใ็นๅฎใใพใใAD FS > Service (ใตใผใใน) > Endpoint (ใจใณใใใคใณใ) ใใฏใชใใฏใใฆใใใใMetadataใ (ใกใฟใใผใฟ) ใปใฏใทใงใณใงURLใฎใในใๆขใใฆ็ขบ่ชใใพใใใในใฏ้ๅธธไปฅไธใซ่ฆใใใใใใซใ/FederationMetadata/2007-06/FederationMetadata.xmlใจใชใใพใใ


ใกใฟใใผใฟใใใฆใณใญใผใ
ใกใฟใใผใฟใใกใคใซใใใฆใณใญใผใใใใซใฏ้ๅธธใตใผใใผไธใงใใฉใฆใถใซURLใใญใผใใใพใใ ไปฅไธใฏใใฎไพใงใใ https://localhost/FederationMetadata/2007-06/FederationMetadata.xml ใใฎใใกใคใซใใใฆใณใญใผใใใฆใใณใณใใฅใผใฟใซไฟๅญใใพใใ

ใใงใใฌใผใทใงใณใกใฟใใผใฟใใคใณใใผใ
Keeper็ฎก็ใณใณใฝใผใซใฎSSOใฏใฉใฆใ่จญๅฎ็ป้ขใงใIdPใฟใคใใจใใฆ[ADFS]ใ้ธๆใใๅใฎๆ้ ใงไฟๅญใใใใงใใฌใผใทใงใณใกใฟใใผใฟใใกใคใซใใคใณใใผใใใพใใ

Keeperใกใฟใใผใฟใใจใฏในใใผใ
ใใญใใธใงใใณใฐ็ป้ขใซๆปใใ[่กจ็คบ]ใใฏใชใใฏใใพใใ

ๆฌกใซใๅพใปใฉ่จผๆๆธๅฉ็จ่ ไฟก้ ผ (Relying Party Trust) ใฆใฃใถใผใใงใคใณใใผใใใใใใKeeperใกใฟใใผใฟใใกใคใซใใใฆใณใญใผใใใพใใKeeper SSO Connect Cloudโขใฎใใญใใธใงใใณใฐใฎ[่กจ็คบ]ใใฏใชใใฏใใพใใ

[ใกใฟใใผใฟใใจใฏในใใผใ]ใใฟใณใใฏใชใใฏใใฆใconfig.xmlใใกใคใซใใใฆใณใญใผใใใพใใ

AD FSใฎ่จญๅฎใๅฎไบ
KeeperใฎCloud SSO SP่จผๆๆธใฎๆๅนๆ้ใฏ1ๅนด้ใฎใฟใงใใๆฏๅนดใ็ฎก็ใณใณใฝใผใซใใๆๆฐใฎKeeper SP่จผๆๆธใใใฆใณใญใผใใใฆใAD FSใฎRelying Party Trust (่จผๆๆธๅฉ็จ่ ไฟก้ ผ) ใฎ่จญๅฎใซใขใใใญใผใใใๅฟ ่ฆใใใใพใใ
่จผๆๆธใฎๆๅนๆ้ใ่ฟซใฃใฆใใ้ใซใฏใKeeperใใใในใฆใฎใฆใผใถใผใซใ็ฅใใใใพใใ
่จผๆๆธๅฉ็จ่
ไฟก้ ผ (Relying Party Trust) ใไฝๆ
Keeper SSO Connectใ่จผๆๆธๅฉ็จ่ ไฟก้ ผใจใใฆไฝๆใใพใใ

Keeperใกใฟใใผใฟใใคใณใใผใ
ไปฅไธใซ่ฆใใใใใใซใ่จผๆๆธๅฉ็จ่ ไฟก้ ผ (Relying Party Trust) ใฆใฃใถใผใใๅฎไบใใฆใKeeper SSO Connect Cloudใฎ่กจ็คบ็ป้ขใใๅใใฃใฆใจใฏในใใผใใใKeeperใกใฟใใผใฟใใกใคใซใใคใณใใผใใใพใใ
Welcome (ใใใใ) ็ป้ขใง[Claim aware] (่ฆๆฑใซๅฏพๅฟใใ) ใ้ธๆใใKeeperใใไฟๅญใใใกใฟใใผใฟใใกใคใซใ้ธๆใใพใใ




ใญใฐใขใฆใใจใฉใผใ้ฒใใซใฏใ่จผๆๆธๅฉ็จ่ ไฟก้ ผ (Relying Party Trust) ใฎSAMLใญใฐใขใฆใใจใณใใใคใณใใhttps://<ใๅฉ็จใฎADFSใตใผใใผใฎใใกใคใณๅ>/adfs/ls/?wa=wsignout1.0ใซๅคๆดใใพใใ


่ฆๆฑ็บ่กใใชใทใผ่ฆๅใไฝๆ
AD FSใจKeeperใฎ้ใงๅฑๆงใใใใใณใฐใใใซใฏใ[LDAP ๅฑๆงใ่ฆๆฑใจใใฆ้ไฟกใใ] (Send LDAP Attributes as Claims) ใง่ฆๆฑ็บ่กใใชใทใผใไฝๆใใLDAPใฎๅฑๆงใKeeper Connectใฎๅฑๆงใซใใใใณใฐใใๅฟ ่ฆใใใใพใใ





ใญใฐใขใฆใใฎใตใใผใ็จใซใใใใซ2ใคใฎ่ฆๆฑ็บ่กใใชใทใผ่ฆๅใ่ฟฝๅ ใใๅฟ ่ฆใใใใพใใ


่ฆๆฑ่ฆๅใซ่ฟฝๅ ใใๆงๆใใณใใผใใใซใฏใไปฅไธใฎใใญในใใใณใใผใใฆใซในใฟใ ่ฆๅใซ่ฒผใไปใใพใใ
c1:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"]
&& c2:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant"]
=> add(store = "_OpaqueIdStore", types = ("http://mycompany/internal/sessionid"), query = "{0};{1};{2};{3};{4}", param = "useEntropy", param = c1.Value, param = c1.OriginalIssuer, param = "", param = c2.Value);




ๅ ฅๅๆนๅใฎ่ฆๆฑใฎ็จฎ้ก (Incoming claim type): http://mycompany/internal/sessionid ้ไฟกๆนๅใฎ่ฆๆฑใฎ็จฎ้ก (Outgoing claim type) : Name ID (ๅๅID) ้ไฟกใใใๅๅIDใฎๅฝขๅผ (Outgoing name ID format) : Transient Identifier (ไธๆ่ญๅฅๅญ)

SAML็ฝฒๅใฎ่จญๅฎ
a. AD FSใตใผใใผใง็ฎก็่ ใจใใฆPowershellใ้ใใพใใ b. ไปฅไธใฎใณใใณใใๅฎ่กใใฆSSO Connect Relying Party Trust Identifier (่จผๆๆธๅฉ็จ่ ไฟก้ ผใฎ่ญๅฅๅญ) ใฎๆๅญๅใ็นๅฎใใพใใ
Get-ADFSRelyingPartyTrust
ใใฎใณใใณใใๅฎ่กใใใจใ้ทใๅบๅใชในใใ็ๆใใใพใใSSO Connectใปใฏใทใงใณใจใ่ญๅฅๅญใ(Identifier) ใฎๆๅญๅใๆขใใพใใ ใใฎๆๅญๅใฏไปฅไธใฎใใใซใชใใพใใ https://keepersecurity.com/api/rest/sso/saml/459561502484
c.ไปฅไธใฎใณใใณใใๅฎ่กใใ<Identifier>ใๆ้ (b)ใง่ฆใคใใๆๅญๅใซ็ฝฎใๆใใพใใ
Set-ADFSRelyingPartyTrust -TargetIdentifier <Identifier> -samlResponseSignature MessageAndAssertion
Get-ADFSRelyingPartyTrustใๅๅบฆๅฎ่กใใใจใSamlResponseSignatureใปใฏใทใงใณใใMessageAndAssertionใใซ่จญๅฎใใใฆใใใใจใ็ขบ่ชใงใใพใใ
AD FSใตใผใในใๅ่ตทๅ
ใตใผใในใใใผใธใฃใใใAD FSใตใผใในใๅ่ตทๅใใพใใ

ใใฉใใซใทใฅใผใใฃใณใฐ
ใในใ็ฎ็ใพใใฏๅ ้จPKI่จผๆๆธใฎใใใซใIdPใงใฎ่จผๆๆธใฎๆๅนๆง็ขบ่ชใ็กๅนใซใใๅฟ ่ฆใใใๅ ดๅใฏใไปฅไธใฎPowershellใณใใณใใใไฝฟ็จใใ ใใใ < Identifier>ใไธ่จใฎใSAML็ฝฒๅใฎ่จญๅฎใ ใฎๆ้ ใง็นๅฎใใๆๅญๅใซ็ฝฎใๆใใพใใ
Set-ADFSRelyingPartyTrust -TargetIdentifier
<Identifier> -EncryptionCertificateRevocationCheck None
Set-ADFSRelyingPartyTrust -TargetIdentifier
<Identifier> -SigningCertificateRevocationCheck None
ๅ่: ็ฝฒๅ่จญๅฎใซไฝใใใฎๅคๆดใๅ ใใใจใIdPใจSSO Connectใฎ้ใงXMLใกใฟใใผใฟใฎไบคๆใๅฟ ่ฆใซใชใๅ ดๅใใใใพใใ
ๆขๅญใฎใฆใผใถใผ/ๅๆ็ฎก็่
ใSSO่ช่จผใซ็งป่ก
ใซใผใใใผใ (ๆไธไฝ) ใงไฝๆใใใใฆใผใถใผใฏใSSOใ่จญๅฎใใใใตใใใผใใซ็งป่กใใๅฟ ่ฆใใใใพใใใฆใผใถใผใใซใผใใใผใใซๆฎใฃใฆใใๅ ดๅใใใซใใ็ฎก็ใณใณใฝใผใซใซใขใฏใปในใใ้ใซใในใฟใผใในใฏใผใใฎๅ ฅๅใๆฑใใใใพใใ
็ฎก็่ ใฏใSSOใๆๅนใซใชใฃใฆใใใใผใใซ่ชๅ่ช่บซใ็งปๅใงใใพใใใใใฎๆไฝใ่กใใซใฏๅฅใฎ็ฎก็่ ใๅฟ ่ฆใจใชใใพใใ
ใฆใผใถใผใSSOๅฏพๅฟใใผใใซ็งปๅใใๅพใๆๅใซ[ๆณไบบSSOใญใฐใคใณ]ใฎใใซใใฆใณใใSSO็ตฑๅใง่จญๅฎใใๆณไบบใใกใคใณใๅ ฅๅใใKeeperใใซใใซใญใฐใคใณใใๅฟ ่ฆใใใใพใใใพใใใในใฟใผใในใฏใผใๅ ฅๅใซใใ็ขบ่ชใๆฑใใใใๅ ดๅใใใใพใใ

SSOใง่ช่จผใใใใจใใใไปฅ้ใฏใกใผใซใขใใฌในใ ใใงSSO่ช่จผใ้ๅงใงใใพใใ

ๆณไบบใใกใคใณใๅ ฅๅใใๅฟ ่ฆใฏใใใพใใใใกใผใซใขใใฌในใๅ ฅๅใใฆ[ๆฌกใธ]ใใฏใชใใฏใใฆใ็ฎ็ใฎSSOใซใซใผใใฃใณใฐใใใชใๅ ดๅใฏใKeeper SSO่จญๅฎใงใธใฃในใใคใณใฟใคใ ใใญใใธใงใใณใฐใๆๅนใซใชใฃใฆใใใใจใจใใกใผใซใใกใคใณใKeeperใซใใฃใฆไบ็ดใใใฆใใใใจใ็ขบใใซใใพใใ ใซใผใใฃใณใฐใจใใกใคใณไบ็ดใฎ่ฉณ็ดฐใซใคใใฆใฏใใใกใใใ่ฆงใใ ใใใ
ๆ็ตๆดๆฐ
ๅฝนใซ็ซใกใพใใใ๏ผ