> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/sso-connect-on-prem/jp/identity-provider-setup/aws-sso-configuration.md).

# AWS SSOの設定

Amazon AWS SSOとのKeeperオンプレミスSSOコネクト連携設定

{% hint style="info" %}
AWSとの完全なクラウドベースの統合については、[KeeperクラウドSSOコネクト](https://docs.keeper.io/sso-connect-cloud/jp/)をご参照ください
{% endhint %}

### AWS SSO

AWSにログインし、 **\[AWS Single Sign-On]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-658acd5843eada7b352e6961026fa767e48a5c7c%2Fsso-step-162b.png?alt=media" alt=""><figcaption></figcaption></figure>

SSOダッシュボードで、 **\[Configure SSO access to your cloud applications]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-8c415d72d5c8432d29033e2a3ac40a7dce81f4fb%2Fsso-step-163b.png?alt=media" alt=""><figcaption></figcaption></figure>

**\[Applications]** メニューで、 **\[Add a new application]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-a411776b2c87b14bd956e0ef6ba422d5e5f5d6e5%2Fsso-step-164b.png?alt=media" alt=""><figcaption></figcaption></figure>

次に、**Keeper Security**を選択し、 **\[Add]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-6c5d187fe744fd5b340392f11962dbb2ec7bbf39%2Fsso-step-165b.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Keeperは、AWSとアプリケーションコネクタを共同開発しています。**
{% endhint %}

**\[Details]** セクションで **\[Display name]** と **\[Description]** (任意) を入力します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-db0bfc08397536fa9f37e3a41a95e95a5973739c%2Fsso-step-166b.png?alt=media" alt=""><figcaption></figcaption></figure>

**\[AWS SSO metadata]** セクションで **\[Download]** を選択して、AWS SSO SAMLメタデータファイルをエクスポートします。このファイルは、設定画面の **\[SSO Connect IdP Metadata]** セクションでインポートします。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-c070bbc36d8acd11fe9d6e1cae9364e4415c4ad2%2Fsso-step-167b.png?alt=media" alt=""><figcaption></figcaption></figure>

このファイルをKeeper SSOコネクトサーバーにコピーし、以下の設定画面にドラッグアンドドロップして、Keeper SSOコネクトにアップロードします。\
\
**\[保存]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-bf288441cf2bc39c4f48310915cde0ebde747e2b%2Fsso-step-168b.png?alt=media" alt=""><figcaption></figcaption></figure>

Keeper SSOコネクトサーバー側の残りの手順は、Keeperの `sso_connect.xml` メタデータファイルをダウンロードして、AWSアプリケーションにアップロードすることです。\
\
Keeper SSOコネクトで **\[メタデータをエクスポート]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-475ba8415ce6c622f87960155b52980ab7693d69%2FConfig_1_D.png?alt=media" alt=""><figcaption></figcaption></figure>

`sso_connect.xml` ファイルをアプリケーション設定画面の **\[Application metadata]** セクションにインポートします。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-8304009b5ddd0c31a334806bdbeca6686a19ee8c%2Fsso-step-170b.png?alt=media" alt=""><figcaption></figcaption></figure>

変更を保存すると、**Configuration for Keeper Password Manager has been saved**という成功メッセージが表示されます。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-bd0dc59bc66101a57b59a4b2beab5e1b155b1d40%2Fsso-step-171b.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**Keeper SSL証明書は、2048Kを超えることはできません。超えると、以下のエラーが表示されます。**
{% endhint %}

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-f290d2544070626017dd4d8c6a2e14bc3f8f7f24%2Fsso-step-172b.png?alt=media" alt=""><figcaption></figcaption></figure>

* より小さいSSL証明書を生成するか、メタデータファイルを再エクスポートしてインポートするか、またはAWS SSOアプリケーションの設定でACS URLとAudience URLを手動で設定してください。

次に、AWS SSOにマッピングするKeeperアプリケーションの属性が正しいことを確認します (デフォルトで設定されているはずです)。 **\[Attribute mappings]** タブを選択します。\
\
AWSの文字列値を `${user:subject}` に、形式を空白または `unspecified` にします。\
\
Keeper属性を以下のように設定します。

| Keeper属性 | AWS SSO文字列値        | 形式          |
| -------- | ------------------ | ----------- |
| Email    | ${user:email}      | unspecified |
| First    | ${user:givenName}  | unspecified |
| Last     | ${user:familyName} | unspecified |

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-8c38530e27368cc2f33ee51f344318202dbfdcd5%2Fsso-step-173b.png?alt=media" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-66bcac95b600436d9148d20fc7be1ca819bf7b2b%2Fsso-step-174b.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
**AWSのメールがAD UPNにマッピングされている場合 (ユーザーの実際のメールアドレスではない可能性があります)、ユーザーのADプロファイルに関連付けられているメールアドレスに再マッピングできます。**
{% endhint %}

この変更を行うには、AWS SSOページの **\[Connected Directory]** に移動します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-febafcd3bd61aa23ba73efe8d994699d1c516665%2Fsso-step-175b.png?alt=media" alt=""><figcaption></figcaption></figure>

**\[Edit attribute mappings]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-d62c317776fa6c05caf841f568082375c1559f1e%2Fsso-step-176b.png?alt=media" alt=""><figcaption></figcaption></figure>

AWS SSOの**email**属性を `${dir:windowsUpn}` から `${dir:email}` に変更します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-66fc4bc6c3e86bee6d7a5551f127f910f5ed0476%2Fsso-step-177b.png?alt=media" alt=""><figcaption></figcaption></figure>

**\[Assigned users]** タブを選択してから、 **\[Assign users]** を選択して、アプリケーションを割り当てるユーザーまたはグループを選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-eef92edd06b60a9dc255560df939666aecd76bec%2Fsso-step-178b.png?alt=media" alt=""><figcaption></figcaption></figure>

**\[Assign users]** ウィンドウで、以下の操作を行います。

* グループまたはユーザーを選択
* グループまたはユーザーの名前を入力
* **\[Search connected directory]** を選択して、検索を開始します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-6dc155e44fa730d836162731f5e276e9b7f9fc4d%2Fsso-step-179b.png?alt=media" alt=""><figcaption></figcaption></figure>

ディレクトリ検索の結果は、検索ウィンドウの下に表示されます。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-77845108259b0d185a5ceded6aaf69311c300f01%2Fsso-step-180b.png?alt=media" alt=""><figcaption></figcaption></figure>

アプリケーションにアクセスする必要のあるユーザー/グループを選択し、 **\[Assign users]** を選択します。

<figure><img src="https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2Fgit-blob-80abd11261a4126ca6e939ad9818ced44f3efcb6%2Fsso-step-181b.png?alt=media" alt=""><figcaption></figcaption></figure>

**Keeper SSOコネクトは、SAMLレスポンスが署名されていることを想定しています。IDプロバイダがSAMLレスポンスに署名するように設定されていることをご確認ください。**

これでKeeper SSOコネクトの設定は完了です。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/sso-connect-on-prem/jp/identity-provider-setup/aws-sso-configuration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
