> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/sso-connect-cloud/jp/device-approvals/automator/windows-service.md).

# Windowsサービス

本ページでは、Dockerを使用せずにWindowsサーバーでオートメーターサービスを実行する手順を取り扱います。

{% hint style="info" %}
SSL証明書がすでに用意できていることをご確認ください。用意できていない場合は、[SSL証明書作成](/sso-connect-cloud/jp/device-approvals/automator/custom-ssl-certificate.md)のページの手順をご参照ください。
{% endhint %}

#### 1. オートメーターサービスをインストール

オートメーターインスタンスで、以下のURLからKeeperオートメーターのインストーラーをダウンロードし、解凍して実行します。

<https://keepersecurity.com/automator/keeper-automator-windows.zip>

設定画面でJavaのチェックボックスをオンにして、Javaランタイムをインストールに含めます。現在はJava 17ランタイムが同梱されており、新バージョンのリリースに合わせて更新されます。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2F3D6Kh3n1ZpgdLU1uxKts%2FScreenshot%202023-04-05%20at%201.51.14%20PM.jpg?alt=media&#x26;token=309cabec-363b-47fe-90fb-1bc7a32ddfb3" alt=""><figcaption><p>インストーラーにJavaを組み込む</p></figcaption></figure>

Keeperオートメーターは、以下のフォルダにインストールされます。

`C:\Program Files\Keeper Security\Keeper Automator\`

構成と設定は、以下のフォルダに保存されます。

`C:\ProgramData\Keeper Automator\`

#### 2. configフォルダを作成

**C:\ProgramData\Keeper Automator**フォルダに `config` フォルダを作成します。

#### 3. 証明書ファイルとパスワードファイルをコピー

[SSL証明書作成](/sso-connect-cloud/jp/device-approvals/automator/custom-ssl-certificate.md)のページで作成した `ssl-certificate.pfx` ファイルを**C:\ProgramData\Keeper Automator\Config**に配置します。

`ssl-certificate.pfx` ファイルがパスフレーズで保護されている場合は、`ssl-certificate-password.txt` という名前のファイルも**C:\ProgramData\Keeper Automator\Config**に作成する必要があります。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FZDZgOUTIUpE5nzLAWmEq%2FScreen%20Shot%202022-08-02%20at%204.39.00%20PM.png?alt=media&#x26;token=0d8b5922-4740-42eb-b653-323b3096871d" alt=""><figcaption><p>SSL証明書ファイルとパスワードファイル</p></figcaption></figure>

#### 4. サービスを再起動

サービス画面でKeeperオートメーターを選択し、サービスを再起動します。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2F0OMd7BT7ReYmJ7w5iEB9%2FScreen%20Shot%202022-01-15%20at%203.07.54%20PM.png?alt=media&#x26;token=d838f40a-20dc-4981-8d25-69493a10898d" alt=""><figcaption><p>Keeperオートメーターサービスを起動</p></figcaption></figure>

ウェブブラウザでサービスが実行中であることを確認します (テストしている端末からポート443へアクセスできる必要があります)。\
\
この場合、URLは\*\*<https://automator.company.com/api/rest/status**です。>

自動ヘルスチェックには、以下のURLも使用できます。

**<https://automator.company.com/health>**

### **Windowsファイアウォール**

Defenderファイアウォールが実行されているWindowsにデプロイしている場合は、Windows Defenderファイアウォールでポート443 (または指定した任意のポート) を開く必要がある場合があります。以下の手順に従います。

**\[スタート]** メニューを開き、**\[Windows Defender ファイアウォール]** と入力して、結果の一覧から選択します。横のナビゲーションメニューで **\[詳細設定]** を選択し、**\[受信の規則]** を選択します。ポートを開くには、**\[新しい規則]** を選択して手順を完了します。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FRyNmSpVAueVx9lGdF1U7%2FScreen%20Shot%202021-10-14%20at%205.28.31%20PM%20(1).png?alt=media&#x26;token=db8ac5a9-156d-40a4-a0b7-bdfa9e047d53" alt=""><figcaption><p>「ポート」を選択</p></figcaption></figure>

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2F3xmtmBQNqY7p1xnihU9F%2Finbound.jpg?alt=media&#x26;token=58b6de6b-3f20-4df6-ba60-aa14e568ba33" alt=""><figcaption><p>ポート番号を入力</p></figcaption></figure>

### コマンダーでの最後の設定

サービスが実行中になったら、Keeperコマンダーを使用してオートメーターをご利用のKeeper環境に統合します。

5. **Keeperコマンダーをインストール** ご利用のワークステーション、サーバー、コンピュータなどにKeeperコマンダーCLIをインストールします。バイナリインストーラーを含むインストール手順については[こちら](/keeperpam/jp/commander-cli/commander-installation-setup.md)のページをご参照ください。
6. **Keeperコマンダーでオートメーターを有効化** Keeperコマンダーにログインし、`automator create` で始まる一連のコマンドを使用してオートメーターを有効化します。オートメーターには任意の名前を付けられます。

```
automator create --name="My Automator" --node="Azure Cloud"
```

ノード名 (この場合は「Azure Cloud」) は、以下に示すように管理コンソールのUIに表示されます。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FNdYz9XWKABSVqtIAV5Ff%2FScreen%20Shot%202021-09-10%20at%203.59.58%20PM.png?alt=media&#x26;token=3c897624-3ae2-465e-9749-c4357015dacc" alt=""><figcaption><p>オートメーターの作成</p></figcaption></figure>

コマンドの出力には、IDプロバイダから取得したメタデータを含むオートメーターの設定が表示されます。

```
                    Automator ID:1477468749950
                            Name:My Automator
                             URL:
                         Enabled:No
                     Initialized:No
                          Skills:Device Approval                          
```

URLはまだ設定されていません。以下のように `automator edit` コマンドを実行します。これによりURLとスキルが設定されます (`team`、 `team_for_user`、`device`)。

{% code overflow="wrap" %}

```
automator edit --url https://<application URL> --skill=team --skill=team_for_user --skill=device "My Automator"
```

{% endcode %}

続いてキーを交換します。オートメーター公開キーで暗号化されたエンタープライズ秘密キーがオートメーターへ渡されます。

```
automator setup "My Automator"
```

{% hint style="info" %}
この手順でエラーが発生した場合は、Windowsサービスを停止してから開始し、ポートが使用可能であることを確認してください。
{% endhint %}

続いて、以下のコマンドを使用して新しい設定でオートメーターを初期化します。

```
automator init "My Automator"
```

最後に、以下のコマンドでオートメーターサービスを有効にします。

```
automator enable "My Automator"
```

この時点で設定は完了です。

#### AD FSを使用した環境の場合

IDプロバイダとしてAD FSを使用してKeeperオートメーターを有効にする場合、以下の手順に従ってKeeper証明書を更新するまでログインできません。

* Keeper管理コンソールへログインします。
* **\[管理者]** > **SSOノード** > **\[プロビジョニング]** に移動し、クラウドSSOコネクト設定を確認します。
* **\[SP証明書をエクスポート]** をクリックします。
* AD FS管理コンソールで、KeeperクラウドSSO証明書利用者信頼プロパティを選択します。
* **\[暗号化]** タブで、古い証明書をこの新しい証明書に置き換えます。
* **\[署名]** タブで、新しいSP証明書をこの新しい証明書に置き換えます。

### ユーザー体験のテスト

Keeperオートメーターをデプロイしたら、エンドユーザー体験をテストできます。ユーザーがSSOのIDプロバイダーで認証したあとは、承認を求めるプロンプトは表示されません。

最も簡単なテスト方法は、ブラウザのシークレットウィンドウからKeeperウェブボルトを開き、クラウドSSOコネクトでログインすることです。デバイス承認を求めるプロンプトは表示されません。

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FnAGBNvh99hgIOnNOuJdv%2FScreen%20Shot%202021-09-10%20at%205.17.42%20PM.png?alt=media&#x26;token=e8222ad6-49b4-4b22-9e5b-bde5fd35beb0" alt=""><figcaption><p>ログイン画面</p></figcaption></figure>

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FbqTOKRYMbSo5HTGpHTQX%2FScreen%20Shot%202021-09-10%20at%205.18.15%20PM.png?alt=media&#x26;token=73817b67-9c8b-4e42-b585-3e73d0a6b437" alt=""><figcaption><p>SSOログイン</p></figcaption></figure>

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2F2ePvTbVgjp70enV5sTmc%2FScreen%20Shot%202021-09-10%20at%205.30.15%20PM.png?alt=media&#x26;token=ed4aff69-cdc9-494c-bcc3-29523f8cc65a" alt=""><figcaption><p>デバイス承認</p></figcaption></figure>

<figure><img src="https://1914737032-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mfd2v-YT48Ljtykb8qm%2Fuploads%2FhKfNZnzP0MelaFgtnj7s%2FScreen%20Shot%202021-09-10%20at%205.32.12%20PM.png?alt=media&#x26;token=7fb689ee-343e-4117-825b-beaeff2e9409" alt=""><figcaption><p>ボルト復号化</p></figcaption></figure>

## サービスの更新

Keeperオートメーターサービスを再設定する際は、Keeperコマンダーを使用してサービスエンドポイントを再初期化する必要があります。

```
automator setup "My Automator"
automator init "My Automator"
automator enable "My Automator"
```

## トラブルシューティング

#### サービスが始まらない

Keeperオートメーターのログを確認してください。通常これで問題がわかります。Windowsの場合、ログは**C:\ProgramData\Keeper Automator\logs**にあります。

#### 常に承認のプロンプトが表示される

Keeperオートメーターサービスを再インストールする際、Keeperコマンダーを使用してサービスエンドポイントを再初期化する必要がある場合があります。Keeperコマンダーについては[こちら](/keeperpam/jp/commander-cli/overview.md)のページをご参照ください。

Keeperコマンダーでオートメーターインスタンスを再初期化するのに必要なコマンドは以下のとおりです。

```
$ keeper shell

My Vault> automator list
288797895952179 My Automator True https://something.company.com 

(find the Name corresponding to your Automator)

My Vault> automator setup "My Automator"
My Vault> automator init "My Automator"
My Vault> automator enable "My Automator"
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/sso-connect-cloud/jp/device-approvals/automator/windows-service.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
