title | date | tags | ||||
---|---|---|---|---|---|---|
蚌ææžèªèšŒã®ãã©ãã«ã·ã¥ãŒãã£ã³ã° |
2018-11-01 |
|
ããã«ã¡ã¯ãAzure & Identity ãµããŒãããŒã ã®ç«¹æã§ãã ä»åã¯ãå€ãã®ã客æ§ãããååããããã ã AD FS ã®ã¯ã©ã€ã¢ã³ã蚌ææžèªèšŒã®åé¡ã«ã€ããŠãæ¢ç¥ã®äºäŸã察å¿æ¹æ³ãã玹ä»ããŸãã
蚌ææžèªèšŒã®åé¡ã¯ã倧ãã 2 ã€ã®ãã¿ãŒã³ã«åããããŸãã
- (A) ã¯ã©ã€ã¢ã³ãã蚌ææžãéä¿¡ããªãã±ãŒã¹
- (B) ã¯ã©ã€ã¢ã³ããã蚌ææžãéžæããŠéä¿¡ãããã®ã®ãæ£åžžã«åäœããªãã±ãŒã¹
ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãé²ããéã«ã¯ããŸããã©ã¡ãã®ã±ãŒã¹ã«è©²åœãããã確èªããŸãã
蚌ææžèªèšŒã§ã¯ãèªèšŒãè©Šã¿ãéã«èšŒææžãéžæãããããã¢ããã衚瀺ãããŸãããããã IE ã«ã¯ãæå¹ãªèšŒææžã 1 ã€ããååšããªãå Žåã«ãèªåçã«éä¿¡ããæ©èœããããŸãã äžèŠ (A) ã®ã±ãŒã¹ã®ããã«èŠããŠããŠããå®éã«ã¯ããã¯ã°ã©ãŠã³ãã§èªåçã«èšŒææžãéä¿¡ããŠããå¯èœæ§ããããŸãã ã€ã³ã¿ãŒããã ãªãã·ã§ã³ã® ãã»ãã¥ãªãã£ã ã¿ãã§ãåãŸãŒã³ã® ãã¬ãã«ã®ã«ã¹ã¿ãã€ãºã ãã以äžã®èšå®ã確èªããŠãããŸãã ãã®èšå®ããç¡å¹ã«ãããã«ããŠããããšã§ãæå¹ãªèšŒææžã 1 ã€ããç¡ãå Žåã«ããããã¢ããããŠãŠãŒã¶ãŒãéžæããåäœã«ãªããŸãã®ã§ã確èªã容æã«ãªããŸãã
â» æ¢å®ã§ã¯ããããŒã«ã« ã€ã³ãã©ãããããŸãŒã³ã®ã¿æå¹ãšãªã£ãŠããŸããã念ã®ããåãŸãŒã³ã®èšå®ãã確èªãã ããã
次ã«ãããããã®ã±ãŒã¹ã«ããã代衚çãªåé¡ã«ã€ããŠèª¬æããŠè¡ããŸãã ãã§ã«ã¯ã©ã€ã¢ã³ãåŽã«èšŒææžã衚瀺ãããŠããå Žåã«ã¯ã(A) ã¯é£ã°ã㊠(B) ããã確èªãã ããã
ãã®ã±ãŒã¹ã®åé¡ã¯ãCTL (Certificate Trust List) ã«èµ·å ããŠããããšãã»ãšãã©ã§ãã CTL ã«é¢ãã詳现ã¯å²æããŸãããç°¡åã«èª¬æããŸããšã蚌ææžèªèšŒã§ã¯ãAD FS / WAP ãµãŒããŒåŽãä¿¡é ŒããŠãã蚌ææ©é¢ã®ãªã¹ã (CTL) ãã¯ã©ã€ã¢ã³ãã«éä¿¡ããŸããã¯ã©ã€ã¢ã³ãã¯ãã®ãªã¹ãã«ååšãã蚌ææ©é¢ããçºè¡ããã蚌ææžã®ã¿ããŠãŒã¶ãŒã«è¡šç€ºããéžæãããŸãã ã€ãŸããCTL ãæ£åžžã«ã¯ã©ã€ã¢ã³ãã«éä¿¡ãããªãã£ãããCTL ã®äžã«ã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã蚌ææ©é¢ãå«ãŸããªãå Žåãã¯ã©ã€ã¢ã³ãåŽã«èšŒææžã衚瀺ãããŸããã AD FS / WAP ã§ã¯ããã® CTL ãéä¿¡ããæ©èœãæ¢å®ã§æå¹ã§ãã 以äžã«ãæå¹ãªç¢ºèªãã€ã³ããåãåãæ¹æ³ãããã€ãã玹ä»ããŸãã
(1) 蚌ææžãåä¿¡ãããµãŒã㌠(å€éšæ¥ç¶ã®å Žå㯠WAP ãµãŒããŒã瀟å æ¥ç¶ã®å Žå㯠AD FS ãµãŒããŒ) ã§ã49443 ããŒããéæŸãããŠããããšã確èªããŸãã
çšã«èšŒææžãåä¿¡ããããŒããéæŸãããŠãããããããã¯ãŒã¯çã«èšŒææžèªèšŒã®èŠä»¶ãæºãããŠããªãã±ãŒã¹ããããŸãã 念ã®ãããã確èªãã ããã
(2) AD FS / WAP ã§ãããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ ã®ãä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«ãã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã蚌ææ©é¢ã®èšŒææžãå«ãŸããããšã確èªããŸãã
æ¢å®ã§ãµãŒããŒåŽ (AD FS / WAP) 㯠CTL ã«èªèº«ã®ãä¿¡é Œãããã«ãŒã蚌ææ©é¢ããå«ããŸãã ãããã£ãŠããä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«ã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã蚌ææ©é¢ãå«ãŸããŠããªããšãã¯ã©ã€ã¢ã³ãåŽã§ã¯èšŒææžã衚瀺ãããŸããã
(3) AD FS / WAP ã§ãããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ ã®ãä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«ããã«ãŒã蚌ææžãã§ãªããã®ãå«ãŸããŠããªããã©ããã確èªããŸãã
ãµãŒããŒåŽã§ CTL ãäœæããéã«ããä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«å«ãŸãããã®ããªã¹ãããŸããããã®éã«ãã«ãŒã蚌ææžã以å€ãååšããããšãæ€ç¥ãããšãCTL ãæ£åžžã«çæã§ãããçµæãšããŠã¯ã©ã€ã¢ã³ãåŽã§èšŒææžã衚瀺ãããªãã±ãŒã¹ããããŸãã ãã«ãŒã蚌ææžãã¯ããçºè¡å (ãµããžã§ã¯ã)ã ãšãçºè¡è ããäžèŽããŠãã蚌ææžã§ãã®ã§ããã以å€ã®èšŒææžãä¿¡é Œãããã«ãŒã蚌ææ©é¢ã¹ãã¢ã«å«ãŸããŠããªãã確èªããŸãã
ã«ãŒã蚌ææ©é¢ã®ã¹ãã¢ã¯æ¬¡ã®æé ã§ç¢ºèªããŸãã
- AD FS / WAP ãµãŒããŒã§ "ãã¡ã€ã«åãæå®ããŠå®è¡" ãã "certlm.msc" ãèµ·åããŸãã
- å·Šãã€ã³ã« [蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ] ãšè¡šç€ºãããŠããããšã確èªã®ããããä¿¡é Œãããã«ãŒã蚌ææ©é¢ã - ã蚌ææžã ãå±éããçºè¡å ãšçºè¡è ãäžèŽããªããã®ãå«ãŸããªãã確èªããŸãã
ãµãŒããŒåŽã®èšå®ã§ãCTL ã®éä¿¡ãç¡å¹ã«ããããšãã§ããŸãã ããç¡å¹ã«ããããšã§èšŒææžãã¯ã©ã€ã¢ã³ãã«è¡šç€ºãããå Žåãæããã« CTL ã®åé¡ã«èµ·å ããŠããããšã確èªã§ãã調æ»ã察å¿ããã®äžç¹ã«ãã©ãŒã«ã¹ãããããšãã§ããŸãã®ã§ãæå¹ãªåãåãã§ããäžèšã® (1) ã (2) ã®ç¢ºèªãå®æœããåã«ãã®åãåããå®æœããŠããŸãã®ãæå¹ã§ãã (ãã ãåèµ·åãå¿ èŠãªã®ã§ãã®ç¹ã«ã€ããŠã¯ã泚æãã ãã) CTL ã®éä¿¡ãç¡å¹ã«ããã«ã¯ããµãŒããŒåŽã§ä»¥äžã®ã¬ãžã¹ããªå€ã 0 ã«èšå®ããåèµ·åããŸãã
ã¬ãžã¹ã㪠ã㌠: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\Schannel
åå: SendTrustedIssuerList
å: REG_DWORD
å€: 0 (ç¡å¹) / 1 (æå¹)
ãªããè€æ°ã® AD FS / WAP ãµãŒããŒãååšããå Žåãåãåãã®éã«ã¯ãhosts ãã¡ã€ã«ãªã©ã§æ¥ç¶å ã® AD FS / WAP ãåºå®ããŠç¢ºèªããããšãã奚ãããŸãã (æ¥ç¶å ã®ãµãŒããŒãåºå®ããããšãã§ããªãå Žåã«ã¯ãã©ã®ãµãŒããŒã«æ¥ç¶ããããåãããŸããã®ã§ããã¹ãŠã®ãµãŒããŒã§èšå®ããå¿ èŠããããŸã)
æ¢å® (CTL ã¹ãã¢ã®èšå®ã null ã®ç¶æ ) ã§ã¯ãäžè¿°ã®ãšãããä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«å«ãŸãã蚌ææ©é¢ã CTL ã«ãªã¹ããããŸãã ããããCTL ã¹ãã¢ã¯åå¥ã«èšå®ããããšãå¯èœã§ãã CTL ã¹ãã¢ã®èšå®ç¶æ³ã¯ã以äžã® netsh ã³ãã³ãã§ç¢ºèªããããšãã§ããŸãã
netsh http show sslcert
管çè æš©éã§äžèšã®ã³ãã³ããã³ãã³ãããã³ããããå®è¡ãããšãããã€ã SSL ã®ãã€ã³ãã®æ å ±ã衚瀺ãããããšæããŸãã ãã®äžã§ã蚌ææžèªèšŒã«å©çšãã ããã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã: 49443 ã®æ å ±ã確èªããŸãã
(AD FS 2016 以éã§ã¯ãç°å¢ã«ãã£ãŠã¯ 49443 ããŒãã§ã¯ãªããcertauth.ããã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã® FQDNã: 443 ã§ããå¯èœæ§ããããŸãã)
以äžã¯ããã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã sts.test.com ã§ããå Žåã®å®è¡çµæäŸã§ãã
netsh http show sslcert
Hostname:port : sts.test.com:49443 â
<<< ããŒã49443 ã«é¢ããèšå®ã§ãããã¡ãã確èªããŸãã
Certificate Hash : 47b90e1e818ba8cf431d404fff232f1ba17bf078 â
<<< SSL ãµãŒããŒèšŒææžã«å¯ŸããŠäžæã§ãç°å¢ã«ãã£ãŠç°ãªããŸãã
Application ID : {5d89a20c-beab-4389-9447-324788eb944a} â
<<< AD FS ãµãŒãã¹ã瀺ããã®ã§ãå
šç°å¢ã§åäžã§ãã
Certificate Store Name : MY
Verify Client Certificate Revocation : Enabled
Verify Revocation Using Cached Client Certificate Only : Disabled
Usage Check : Enabled
Revocation Freshness Time : 0
URL Retrieval Timeout : 0
Ctl Identifier : (null)
Ctl Store Name : (null) â
<<< æ¢å®ã§ã¯ null ã§ãã443 ããŒãã©åæ§ã« AdfsTrustedDevices ãªã©ãèšå®ãããŠããå Žåãnull ã«æ»ãå¿
èŠããããŸãã
DS Mapper Usage : Disabled
Negotiate Client Certificate : Enabled
ãã® CTL ã¹ãã¢ãåå¥ã«æå®ããŠãã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã蚌ææ©é¢ã®ã¿ãå«ããããšã§ãä»ã®èšŒææ©é¢ã®èšŒææžã®åœ±é¿ãåãé€ãããšãã§ããŸãã 以äžã«ãèšå®æé ãã玹ä»ããŸãã
- 管çè æš©éã§ã³ãã³ãããã³ãããèµ·åãã以äžã®ããã«å®è¡ããŸãã
certutil -f -addstore <ä»»æã®èšŒææžã¹ãã¢å> <ã¯ã©ã€ã¢ã³ã蚌ææžã®ã«ãŒã蚌ææž>
(äŸ)
certutil -f -addstore adfsclient c:\temp\rootca.cer
â» c:\temp\rootca.cer ã¯ãã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ããã«ãŒã CA ã®èšŒææžããšã¯ã¹ããŒããã .cer ãã¡ã€ã«ã§ãã â» ãã®ã³ãã³ãã«ãããadfsclient ãšããååã®ã¹ãã¢ãäœæãããã«ãŒã CA ã®èšŒææžãã€ã³ããŒããããŸãã
- ç¶ããŠä»¥äžã®ã³ãã³ããå®è¡ããäœæããã¹ãã¢å ã«ã«ãŒã CA ã®èšŒææžãååšããããšã確èªããŸãã
certutil -store adfsclient
- ç¶ããŠä»¥äžã®ã³ãã³ããå®è¡ããçŸç¶ã® 49443 ããŒãã® SSL ãã€ã³ããäžæŠåé€ããŸãã
netsh http delete sslcert hostnameport=sts.test.com:49443
â» hostnameport ã«ã¯ãã客æ§ã®ç°å¢ã§ç¢ºèªããå€ãæå®ããŸãã
- ç¶ããŠä»¥äžã®ã³ãã³ããå®è¡ããCTL ã¹ãã¢ãäœæãããã®ã«æå®ããSSL ãã€ã³ããèšå®ããŸãã
netsh http add sslcert hostnameport=sts.testcom:49443 certhash=47b90e1e818ba8cf431d404fff232f1ba17bf078 appid={5d89a20c-beab-4389-9447-324788eb944a} certstorename=MY sslctlstorename=adfsclient clientcertnegotiation=enable
â» hostnameportãcerthash ã«ã¯ãã客æ§ã®ç°å¢ã§ç¢ºèªããå€ãæå®ããŸãã
- ç¶ããŠä»¥äžã®ã³ãã³ããå®è¡ããCTL ã¹ãã¢ãæŽæ°ãããŠããããšãã確èªãã ããã
netsh http show sslcert
Hostname:port : sts.test.com:49443
Certificate Hash : 47b90e1e818ba8cf431d404fff232f1ba17bf078
Application ID : {5d89a20c-beab-4389-9447-324788eb944a}
Certificate Store Name : MY
Verify Client Certificate Revocation : Enabled
Verify Revocation Using Cached Client Certificate Only : Disabled
Usage Check : Enabled
Revocation Freshness Time : 0
URL Retrieval Timeout : 0
Ctl Identifier : (null)
Ctl Store Name : adfsclient â
<<< åå¥ã«äœæããã¹ãã¢ãèšå®ãããŠããŸãã
DS Mapper Usage : Disabled
Negotiate Client Certificate : Enabled
ã¯ã©ã€ã¢ã³ãåŽã«èšŒææžã衚瀺ãããªãã±ãŒã¹ã¯ãäžèšã®å¯Ÿå¿ã§è§£æ±ºã§ããããšãå€ãã®ã§ãåèã«ãªãã°å¹žãã§ãã
(B) ã¯ã©ã€ã¢ã³ããã蚌ææžãéžæããŠéä¿¡ãããã®ã®ãæ£åžžã«åäœããªãã±ãŒã¹
ãã®ã±ãŒã¹ã§ã®åå ã¯ãWAP ãµãŒããŒãããã㯠AD FS ãµãŒããŒã§å€±å¹ç¢ºèªã«å€±æããŠããã±ãŒã¹ãã»ãšãã©ã§ããããã以å€ãå«ããŠä»¥äžã«ãããã€ã確èªã®ãã€ã³ããã玹ä»ããŸãã
(1) 蚌ææžãåä¿¡ãããµãŒã㌠(å€éšæ¥ç¶ã®å Žå㯠WAP ãµãŒããŒã瀟å æ¥ç¶ã®å Žå㯠AD FS ãµãŒããŒ) ã§ã49443 ããŒããéæŸãããŠããããšã確èªããŸãã
çšã«èšŒææžãåä¿¡ããããŒããéæŸãããŠãããããããã¯ãŒã¯çã«èšŒææžãåãåããªãã±ãŒã¹ããããŸãã 念ã®ãããã確èªãã ããã
(2) 蚌ææžã®ãµããžã§ã¯ã代æ¿åã«èªèšŒãŠãŒã¶ãŒã® UPN ãèšå®ãããŠããããšã確èªããŸãã
AD FS ã®èšŒææžèªèšŒã§ã¯ããµããžã§ã¯ã代æ¿åã«èªèšŒãŠãŒã¶ãŒã® UPN ãèšå®ãããŠããå¿ èŠããããŸãã (ãµããžã§ã¯ã代æ¿åã«èšå®ãååšããªãå Žåã«ã¯ããµããžã§ã¯ãã«èªèšŒãŠãŒã¶ãŒã® DN ãèšå®ãããŠããå¿ èŠããããŸããWindows ã§ã¯ãµããžã§ã¯ã代æ¿åãåªå ããã®ã§ãäžè¬çã«ã¯ãµããžã§ã¯ã代æ¿åã« UPN ãã»ãããã蚌ææžãå©çšããŸã) ãã¡ããã念ã®ããã確èªãã ããã
(3) ã«ãŒã CA ã®èšŒææžãäžé CA ã®èšŒææž (ååšããå Žå) ããé©åã«ã€ã³ããŒããããŠããããšã確èªããŸãã
AD FS ãµãŒããŒãWAP ãµãŒããŒãã¯ã©ã€ã¢ã³ã端æ«ããããã§ãããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒã®ãä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã¹ãã¢ã«ã«ãŒã CA ã®èšŒææžãæ£ããã€ã³ããŒããããŠããããšã確èªããŸãã ãŸããäžé CA ãååšããå Žåã«ã¯ãåæ§ã«ãäžé蚌ææ©é¢ãã¹ãã¢ã«äžé CA ã®èšŒææžãæ£ããã€ã³ããŒããããŠããããšã確èªããŠãã ããã 蚌ææžãã§ãŒã³ãæ£åžžã«æ€èšŒã§ããå¿ èŠããããŸãã
ãŸããAD FS ãµãŒããŒã«ãããŠã¯ãNT Auth ã¹ãã¢ã«ã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã CA ã®èšŒææž (ã«ãŒã CA ã®èšŒææžããããã¯äžé CA ããçºè¡ããŠããå Žåã«ã¯äžé CA ã®èšŒææž) ãã€ã³ããŒããããŠããå¿ èŠããããŸãã AD CS ã®ãšã³ã¿ãŒãã©ã€ãº CA ãå©çšããŠããå Žåãæ¢å®ã§ NT Auth ã¹ãã¢ã« CA ã®èšŒææžãã€ã³ããŒããããŸãããä»ãã¡ã€ã³ã® CA ãå ¬çãªèšŒææ©é¢ããçºè¡ãã蚌ææžã䜿çšããå Žåãæ瀺çã«ã€ã³ããŒãããå¿ èŠããããŸãã NT Auth ã¹ãã¢ã«èšŒææžãã€ã³ããŒãããã«ã¯ããã¡ã€ã³ã®ç®¡çè æš©éã§ã³ãã³ãããã³ãããèµ·åãã以äžã®ã³ãã³ããå®è¡ããŸãã AD FS ãµãŒããŒãªã©ãDC ã«æ¥ç¶ã§ãããµãŒããŒäžã§å®è¡ããŸãã
certutil -dspublish -f <ã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã CA ã®èšŒææž (xxxx.cer) ã®ãã«ãã¹> NTAuthCA
NT Auth ã¹ãã¢ã«ã€ã³ããŒããããŠãã蚌ææžã確èªããå Žåã«ã¯ã以äžã®ã³ãã³ããå®è¡ããŸãã
certutil -store -enterprise ntauth
(4) AD FS / WAP ã§ãããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ ã®ãä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«ããã«ãŒã蚌ææžãã§ãªããã®ãå«ãŸããŠããªããã©ããã確èªããŸãã
ãµãŒããŒåŽã§ CTL ãäœæããéã«ããä¿¡é Œãããã«ãŒã蚌ææ©é¢ãã«å«ãŸãããã®ããªã¹ãããŸããããã®éã«ãã«ãŒã蚌ææžã以å€ãååšããããšãæ€ç¥ãããšãCTL (ä¿¡é Œãã CA ã®ãªã¹ã) ãæ£åžžã«çæã§ãããçµæãšããŠèšŒææžèªèšŒã«å€±æããããšãããããŸãã ãã«ãŒã蚌ææžãã¯ããçºè¡å (ãµããžã§ã¯ã)ã ãšãçºè¡è ããäžèŽããŠãã蚌ææžã§ãã®ã§ããã以å€ã®èšŒææžãä¿¡é Œãããã«ãŒã蚌ææ©é¢ã¹ãã¢ã«å«ãŸããŠããªãã確èªããŸãã
ã«ãŒã蚌ææ©é¢ã®ã¹ãã¢ã¯æ¬¡ã®æé ã§ç¢ºèªããŸãã
- AD FS / WAP ãµãŒããŒã§ "ãã¡ã€ã«åãæå®ããŠå®è¡" ãã "certlm.msc" ãèµ·åããŸãã
- å·Šãã€ã³ã« [蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ] ãšè¡šç€ºãããŠããããšã確èªã®ããããä¿¡é Œãããã«ãŒã蚌ææ©é¢ã - ã蚌ææžã ãå±éããçºè¡å ãšçºè¡è ãäžèŽããªããã®ãå«ãŸããªãã確èªããŸãã
(5) AD FS ãµãŒããŒãWAP ãµãŒããŒãã CDP (倱å¹ãªã¹ãé åžãã€ã³ã) ã«ã¢ã¯ã»ã¹ã§ããããšã確èªããŸãã
ã¯ã©ã€ã¢ã³ã蚌ææžã® ã詳现ã ã¿ãããã蚌ææžã® CDP ã確èªããããšãã§ããŸãã
蚌ææžã® CDP ã確èªããADFS / WAP ãµãŒããŒäžã§ IE ãèµ·åãã該åœã® URL ã«ã¢ã¯ã»ã¹ã§ãããã©ããã確èªããŸãã IE ããæ£åžžã«ã¢ã¯ã»ã¹ã§ããå Žåã§ããå®éã®å€±å¹ç¢ºèªã®åäœæã«ã¯ WinHTTP ãããã·ãçµç±ããããã WinHTTP ãããã·ãæ§æãããŠããªãããšã§ CDP ãžã®ã¢ã¯ã»ã¹ã«å€±æããŠããå¯èœæ§ããããŸãã
WinHTTP ãããã·ã®èšå®ç¶æ³ã«ã€ããŠã¯ã次ã®ã³ãã³ãã§ç¢ºèªãå¯èœã§ãã
netsh winhttp show proxy
çŸåšã® WinHTTP ãããã·èšå®:
çŽæ¥ã¢ã¯ã»ã¹ (ãããã· ãµãŒããŒãªã)ã
ã€ã³ã¿ãŒãããæ¥ç¶ã«ãããã·ãå¿ èŠãªç°å¢ã§ã¯ãé©åã«ãããã·ãèšå®ããŠããå¿ èŠããããŸãã IE ã®ã€ã³ã¿ãŒããã ãªãã·ã§ã³ã®èšå®ãåãããããã«ã¯ã以äžã®ã³ãã³ããå®è¡ããŸãã
netsh winhttp import proxy source=ie
çŸåšã® WinHTTP ãããã·èšå®:
ãããã· ãµãŒããŒ: proxy_address:8080
ãã€ãã¹äžèŠ§ : test.com;*.test.com;sts.federation.com;<local>
蚌ææ©é¢ãšã㊠Windows ã® AD CS ã§æ§æãããšã³ã¿ãŒãã©ã€ãº CA ãå©çšããŠããå ŽåãCDP ã¯èšŒææ©é¢ã®èšå®ã§è¡ããŸãããæ¢å®ã§ã¯ AD äžã«æ ŒçŽãããLDAP ã®ãã¹ã«ãªããŸãã ãã®æ¢å®ã®ç¶æ ã§ããšãAD FS ã¯å¿ ããã¡ã€ã³ ã¡ã³ããŒã«ãªããŸãã®ã§åé¡ã¯ãããŸããããWAP ãµãŒããŒããã¡ã€ã³ã«åå ãããŠããªãæ§æã§ã¯ããã® LDAP ã®ãã¹ã«ã¯ã¢ã¯ã»ã¹ããããšãã§ããŸããã
WAP ãµãŒããŒããã¡ã€ã³ã«åå ããŠããªãå Žåã«ã¯ãhttp ã§ã CDP ã«ã¢ã¯ã»ã¹ã§ããããã«æ§æããŠããå¿ èŠããããŸãã å ·äœçã«ã¯æ¬¡ã®ãšãããã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ãã蚌ææ©é¢ã®ããããã£ã® ãæ¡åŒµæ©èœãã¿ãã§èšå®ããŸãã
泚æç¹ãšããŠããã®èšå®ãè¡ãåã«çºè¡ããã蚌ææžã«ã¯ãããã§èšå®ãã http ã® CDP ãå«ãŸããŠããŸããã èšå®å€æŽãè¡ã£ãåŸã«ãå床ã¯ã©ã€ã¢ã³ã蚌ææžãçºè¡ããå¿ èŠããããŸãã
ãšã³ã¿ãŒãã©ã€ãº CA ã§ã¯ãªããå ¬çæ©é¢ããçºè¡ããã蚌ææžãå©çšããå Žå
ãšã³ã¿ãŒãã©ã€ãº CA ããçºè¡ããã蚌ææžã®å Žåã«ã¯ãæ¢å®ã®ç¶æ ã§ããã° AD FS ã¯ãã¡ã€ã³ ã¡ã³ããŒã®ããã LDAP 㧠CDP ã«ã¢ã¯ã»ã¹ã§ããŸãã ããããå ¬çæ©é¢ããçºè¡ããã蚌ææžãå©çšããå Žåãäžè¬çã« CDP ã«ã¢ã¯ã»ã¹ããããã«ã¯ã€ã³ã¿ãŒãããæ¥ç¶ãå¿ èŠã§ãã ãã®éãAD FS 㯠WinHTTP Proxy 以å€ã«ããAD FS ãµãŒãã¹ã¢ã«ãŠã³ãã® WinINET Proxy ãå©çšããŸãã CDP ã AD äžã§ã¯ãªããã€ã³ã¿ãŒãããæ¥ç¶ãå¿ èŠã«ãªãå ŽåãAD FS ãµãŒãã¹ã¢ã«ãŠã³ãã®ã³ã³ããã¹ã㧠IE ã®ã€ã³ã¿ãŒããããªãã·ã§ã³ãã Proxy ãé©åã«èšå®ããŠãã ããã
äžèšã確èªããŠãåäœãå€ãããªãå ŽåãäžæŠ WAP ãµãŒããŒã§å€±å¹ç¢ºèªãç¡å¹åããããšã¯æå¹ãªåãåãã§ãã ããç¡å¹åããŠåäœããããã«ãªã£ãå Žåã«ã¯ãæããã«å€±å¹ç¢ºèªãåé¡ã§ããããšã確èªã§ãã調æ»ã察å¿ã倱å¹ç¢ºèªã®åäœã«çµãããšãã§ããŸãã ç¹ã«ãAD CS ã®ãšã³ã¿ãŒãã©ã€ãº CA ãå©çšããŠããå Žåã«ã¯ã WAP ãµãŒããŒã§å€±å¹ç¢ºèªã倱æãããã (CDP ã LDAP ãã¹ã«èšå®ãããŠãããã倱æããŠããã±ãŒã¹ãå€ã) ã®ã§ãæåã« WAP ãµãŒããŒã§ç¡å¹åããããšãã奚ãããŸãã (A) ã®å¯Ÿå¿ã§ãã玹ä»ããŸãããã倱å¹ç¢ºèªã¯ netsh ã³ãã³ãã§ç¢ºèªãç¡å¹å (æå¹å) ããããšãã§ããŸãã
netsh http show sslcert
管çè æš©éã§äžèšã®ã³ãã³ããã³ãã³ãããã³ããããå®è¡ãããšãããã€ã SSL ã®ãã€ã³ãã®æ å ±ã衚瀺ãããããšæããŸãã ãã®äžã§ã蚌ææžèªèšŒã«å©çšãã ããã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã:49443 ã®æ å ±ã確èªããŸãã
(AD FS 2016 以éã§ã¯ãç°å¢ã«ãã£ãŠã¯ 49443 ããŒãã§ã¯ãªããcertauth.ããã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã® FQDNã:443ãã§ããå¯èœæ§ããããŸãã)
以äžã¯ããã§ãã¬ãŒã·ã§ã³ãµãŒãã¹åã sts.test.com ã§ããå Žåã®å®è¡çµæäŸã§ãã
netsh http show sslcert
Hostname:port : sts.test.com:49443 â
<<< ããŒã49443 ã«é¢ããèšå®ã§ãããã¡ã確èªããŸãã
Certificate Hash : 47b90e1e818ba8cf431d404fff232f1ba17bf078 â
<<< SSL ãµãŒããŒèšŒææžã«å¯ŸããŠäžæã§ãç°å¢ã«ãã£ãŠç°ãªããŸãã
Application ID : {5d89a20c-beab-4389-9447-324788eb944a} â
<<< AD FS ãµãŒãã¹ã瀺ããã®ã§ãå
šç°å¢ã§åäžã§ãã
Certificate Store Name : MY
Verify Client Certificate Revocation : Enabled â
<<< æ¢å®ã§ã¯ãã¯ã©ã€ã¢ã³ã蚌ææžã®å€±å¹ç¢ºèªãæå¹ (Enabled) ã«ãªã£ãŠããŸãã
Verify Revocation Using Cached Client Certificate Only : Disabled
Usage Check : Enabled
Revocation Freshness Time : 0
URL Retrieval Timeout : 0
Ctl Identifier : (null)
Ctl Store Name : (null)
DS Mapper Usage : Disabled
Negotiate Client Certificate : Enabled
倱å¹ç¢ºèªãç¡å¹åããæé ãã以äžã«ã玹ä»ããŸãã
- 管çè æš©éã§ã³ãã³ãããã³ãããèµ·åããçŸç¶ã® 49443 ããŒãã® SSL ãã€ã³ããäžæŠåé€ããŸãã
netsh http delete sslcert hostnameport=sts.test.com:49443
â» hostnameport ã«ã¯ãã客æ§ã®ç°å¢ã§ç¢ºèªããå€ãæå®ããŸãã
- ç¶ããŠä»¥äžã®ã³ãã³ããå®è¡ãã倱å¹ç¢ºèªãç¡å¹åã㊠SSL ãã€ã³ããèšå®ããŸãã
netsh http add sslcert hostnameport=sts.testcom:49443 certhash=47b90e1e818ba8cf431d404fff232f1ba17bf078 appid={5d89a20c-beab-4389-9447-324788eb944a} certstorename=MY verifyclientcertrevocation=disable clientcertnegotiation=enable
â» hostnameportãcerthash ã«ã¯ãã客æ§ã®ç°å¢ã§ç¢ºèªããå€ãæå®ããŸãã
- ç¶ããŠä»¥äžã®ã³ãã³ããå®è¡ããã¯ã©ã€ã¢ã³ã蚌ææžã®å€±å¹ç¢ºèªãç¡å¹åãããŠããããšã確èªããŸãã
netsh http show sslcert
Hostname:port : sts.test.com:49443
Certificate Hash : 47b90e1e818ba8cf431d404fff232f1ba17bf078
Application ID : {5d89a20c-beab-4389-9447-324788eb944a}
Certificate Store Name : MY
Verify Client Certificate Revocation : Disabled â
<<< 倱å¹ç¢ºèªãç¡å¹åãããŠããŸãã
Verify Revocation Using Cached Client Certificate Only : Disabled
Usage Check : Enabled
Revocation Freshness Time : 0
URL Retrieval Timeout : 0
Ctl Identifier : (null)
Ctl Store Name : (null)
DS Mapper Usage : Disabled
Negotiate Client Certificate : Enabled
ãããã®ç¶æ ã§èšŒææžèªèšŒãåäœããããã«ãªã£ãå ŽåããµãŒããŒã®å€±å¹ç¢ºèªã«å€±æããŠããç¶æ³ãšæ確ã«å€æããããšãã§ããŸãã
倱å¹ãªã¹ãã®æå¹æéãåããŠãããããµãŒããŒäžã® CRL ãã£ãã·ã¥ãå€ããæ£åžžã«åäœããªãã±ãŒã¹ããããŸãã CDP ã«ã¢ã¯ã»ã¹ã§ããããšã確èªããŠããå Žåã«ã¯ã倱å¹ãªã¹ãã®æŽæ°ããã£ãã·ã¥ã®åé€ããè©Šããã ããã AD CS ã®ãšã³ã¿ãŒãã©ã€ãº CA ã§ã¯ã以äžã® ã倱å¹ãã蚌ææžã ã® ããã¹ãŠã®ã¿ã¹ã¯ã ããå ¬éããããšãã§ããŸãã
äžèšæé 㧠CRL ãå ¬éããŸããããAD FSãWAP ãµãŒããŒäžã§ CRL ã®ãã£ãã·ã¥ãåé€ããŸãã CRL ãã£ãã·ã¥ã«ã¯ãã¹ãã¬ãŒãžäžã«ä¿åããããã®ãã¡ã¢ãªå ã«ä¿æããããã®ã® 2 çš®é¡ããããããããåé€ããæ¹æ³ã以äžã«ã玹ä»ããŸãã
ã¹ãã¬ãŒãžäžã®ãã£ãã·ã¥ãåé€ããããã«ã¯ã以äžã®åãã©ã«ããŒå ã®ãã¡ã€ã«ãåé€ããŠãã ããã ãã©ã«ããŒã¯åé€ããªãããã«ããŠãã ããã
C:\Windows\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetFlushCache\MetaData
C:\Windows\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Windows\ServiceProfiles\NetworkService\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetFlushCache\MetaData
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetFlushCache\MetaData
â» ãã¡ã€ã«ãååšããªãå Žåããã©ã«ããŒãååšããªãå Žåã¯ã察å¿äžèŠã§ãã
次ã«ã¡ã¢ãªå ã«ä¿æããããã£ãã·ã¥ã¯ã以äžã®ã³ãã³ãã§åé€ããŸãã
certutil -setreg chain\ChainCacheResyncFiletime @now
â» ã³ãã³ããå®è¡ããããã«ã¯ãããŒã«ã«ç®¡çè æš©éãå¿ èŠã§ãã â» ã³ãã³ããå®è¡ããåŸã« CertSvc ãµãŒãã¹ã®åèµ·åãæ±ããããŸãããå®éã«ã¯äžèŠã§ãããµãŒãã¹åèµ·åã®å¿ èŠã¯ãããŸããã
ãããã§ããã§ããããã
AD FS ã®èšŒææžèªèšŒããã©ãã«ã·ã¥ãŒãã£ã³ã°ããã±ãŒã¹ã§ã¯ãäžèšã®ãšããæ§ã ãªç¢ºèªèŠ³ç¹ãããããã¹ãŠã®èŠ³ç¹ã確èªããããã®è³æãäžãŸãšãã«ååŸããããšãããšãéåžžã«å€§å€ã§ãã ä»åã玹ä»ãã確èªãã€ã³ããåãåããå®æœããŠããã ãããšã§ã解決ã«è³ã£ããã調æ»ã®ãã€ã³ããçµã蟌ãããšãã§ããŸãã®ã§ããã²æŽ»çšããã ããã°å¹žãã§ãã
äžèšå 容ãå°ãã§ãåèãšãªããŸããšå¹žãã§ãã
補ååäœã«é¢ããæ£åŒãªèŠè§£ãåçã«ã€ããŠã¯ãã客æ§ç°å¢ãªã©ãååã«ææ¡ããããã§ãµããŒãéšéããæäŸãããŠããã ããŸãã®ã§ããã²åŒç€ŸãµããŒã ãµãŒãã¹ããå©çšãã ããã