ãã¿ã㬠ïŒãã®èšäºã¯çŽç²ã«çè«çãªè³æã§ããããã®èšäºã«ã¯æ®µéçãªæé ã¯å«ãŸããŠããŸããã
ãã®ãããªåœ¹å²ãæ€èšããŠãã ããã äžã§èšã£ãããã«ããããã®4ã€ãããªãã¡ïŒ
- Active Directory蚌ææžãµãŒãã¹ãã€ãŸãActive Directory蚌ææžãµãŒãã¹ãAD CS ã äžèŠæš¡ããã³å€§èŠæš¡ã®çµç¹ã¯ããŠãŒã¶ãŒãããã€ã¹ããŸãã¯ãµãŒãã¹IDã察å¿ããç§å¯ããŒã«ãã€ã³ãããããžã¿ã«èšŒææžãçºè¡ããããã®èªèšŒå±ãäœæããããã«ãPKIå ¬éããŒã€ã³ãã©ã¹ãã©ã¯ãã£ã§AD CS蚌ææžãµãŒãã¹ããã¹ãããããšãã§ããŸãã ã€ãŸããAD CSã¯ã蚌ææžãç¬ç«ããŠçºè¡ãããã®çµæã蚌ææžã管çããããã®å¹ççã§å®å šãªæ¹æ³ãæäŸããŸãã
- Active Directory Rights ManagementãµãŒãã¹-Active Directory Rights ManagementãµãŒãã¹ ãã€ãŸãAD RMS ã ãšããã§ãå€ãã®äººãç¡èŠããŠãããã®ãµãŒããŒã®åœ¹å²ã®æ©èœã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®å¢çã®å åŽãšå€åŽã ãã§ãªãããããã¯ãŒã¯ãšãã®å€åŽã§ã®èš±å¯ããã䜿çšãšäžæ£ãªäœ¿çšãæå®ããæç¶å¯èœãªäœ¿çšããªã·ãŒã®ãã¿ãŒã³ãå®è£ ããããã«äœ¿çšã§ããæ å ±ä¿è·æè¡ãæäŸããŸã;
- Active Directoryãã§ãã¬ãŒã·ã§ã³ãµãŒãã¹ã¯ãè±èªã§ã¯Active Directoryãã§ãã¬ãŒã·ã§ã³ãµãŒãã¹ ããŸãã¯åã«AD FSã®ããã«èãããŸãã ãããã®ãµãŒãã¹ã«ãããçµç¹ã¯ãWindowsç°å¢ã ãã§ãªããäœããã®æ¹æ³ã§è€æ°ã®ãã©ãããã©ãŒã ã«ããã£ãŠIDããã³ã¢ã¯ã»ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ãæ¡åŒµããä¿¡é Œã§ããããŒãããŒã«ã»ãã¥ãªãã£å¢çå€ã®IDAä¿è·ãæäŸã§ããŸãã ãã§ãã¬ãŒã·ã§ã³ç°å¢ã§ã¯ãçµç¹ã«ã¯ç¬èªã®èå¥ãªããžã§ã¯ãããµããŒãããã³å¶åŸ¡ããæ©äŒãäžããããŸãã
- ã©ã€ããŠã§ã€ããã£ã¬ã¯ããªãµãŒãã¹ ãã€ãŸãActive Directoryã©ã€ããŠã§ã€ããã£ã¬ã¯ããªãµãŒãã¹ ããŸãã¯åã«AD LDS ã ãã®åœ¹å²ã¯ã倧ãŸãã«èšã£ãŠããã£ã¬ã¯ããªãªããžããªãžã®ã¢ã¯ã»ã¹ãå¿ èŠãšããã¢ããªã±ãŒã·ã§ã³ããŒã¿ã®ã¿ãæ ŒçŽããLDAPãã£ã¬ã¯ããªã§ããããã®æ å ±ã¯ãã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ã«è€è£œãããã¹ãã§ã¯ãããŸããã
ãããŠãèªã¿åãå°çšãã¡ã€ã³ã³ã³ãããŒã©ãŒã®å±éæ©èœããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ä»®æ³åãActive Directoryãä»ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã¢ã¯ãã£ããŒã·ã§ã³ãWindows PowerShellã³ãã³ãã¬ããã®å±¥æŽãªã©ã®æ°æ©èœãè¿œå ãããšãActive Directoryã®å¯èœæ§ã¯ã»ãŒç¡éã«ãããšçµè«ä»ããããšãã§ããŸãã ã ãã ããæ å ±ãžã®ã¢ã¯ã»ã¹ãã©ã®ããã«æäŸãããããèŠããšããã¹ãŠãå®å šã«æ²ãããšèšããŸãã å®éãNTFSããŒã¹ã®æš©å©ã§ã¯ãå³å¯ãªãã¡ã€ã«åé¡ã«åŸã£ãŠããã¥ã¡ã³ããžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããããšã¯ã§ããŸãããç¹å®ã®ããªã·ãŒã«åŸã£ãŠè©³çŽ°ãªç£æ»ãè¡ãããšã¯ã§ããŸããããã¢ã¯ã»ã¹èŠæ±ããçæããå¯èœæ§ã¯ãããŸããããäŸç¶ãšããŠããã€ãã®å¶éããããŸãã
ããããWindows Server 2012ãªã©ã®Microsoftã®ãµãŒããŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãªãªãŒã¹ã§ã¯ã ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ ïŒ ãã€ãããã¯ã¢ã¯ã»ã¹ïŒãšåŒã°ããæè¡ãç»å Žãããããã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ããã€ãŸãACLãä»ããŠããããã¹ãŠã®ãã¡ã€ã«ã¢ã¯ã»ã¹å¶éãå¿ããããšãã§ããŸãControl ïŒãããã«ãããç¹å®ã®å±æ§ãŸãã¯ç¹å®ã®åºæºã«åºã¥ããŠæ å ±ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ã§ããŸãã ãã®èšäºããå§ããŠããã®çŽ æŽããããã¯ãããžãŒã«ã€ããŠèª¬æããŸãããããã©ã®ããã«äœ¿çšã§ããããããŸããŸãªã·ããªãªãã¹ããŒãã¡ã³ãã¯äœã§ãããïŒè±èªã§ã¯ãã¢ããªã±ãŒã·ã§ã³ãŸãã¯klimaãšåŒã°ããããšããããŸãïŒ ã¯ã¬ãŒã ãšããŠïŒååšãããªãœãŒã¹ããããã£ã ãŸããäžå åãããã¢ã¯ã»ã¹ããªã·ãŒãšã«ãŒã«ããã®ãããªäžå åãããã¢ã¯ã»ã¹ããªã·ãŒãæ£ç¢ºã«å ¬éããã³é©çšããæ¹æ³ãããŸããŸãªãã¡ã€ã«ãšãã©ã«ããŒã®åé¡ãåçã¢ã¯ã»ã¹å¶åŸ¡ã®åé¡ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãããã³ä»ã®å€ãã®ããšã«ã€ããŠã
åœç¶ãå ã»ã©æžããããããã¹ãŠã®ãã€ã³ããèŠããšããã®æè¡ã«ã€ããŠã®1ã€ã®èšäºã§ã¯å¯Ÿå¿ã§ããªãããšã¯ããã«æããã§ãããããã£ãŠãæ¯figçã«èšãã°ããã®æè¡ã6ã10ã®èšäºã§å®å šã«å ¬éããŸããèããããã·ããªãªããã®ãã¯ãããžã®åŸ®åŠãªç¹ãããã³Active DirectoryãµãŒããŒã®å šäœç®¡çãšWindows PowerShellããŒã«ã®äœ¿çšã«åºã¥ãäŸãéèŠã§ãã
åçã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã®ãã¯ãããžãŒã«é¢ãããã®æåã®èšäºãããæ£ç¢ºã«äœãåŠã¶ããšãã§ããŸããïŒ ãŸãããã®èšäºããã次ã®ç¹ã«ã€ããŠããã«åŠç¿ããŸãã
- ãã®ãã¯ãããžãŒã®ç®çã«ã€ããŠã
- ãã®ãã¯ãããžãŒãACLã«åºã¥ããŠã¢ã¯ã»ã¹ãæäŸãããããåªããŠããçç±ã«ã€ããŠã
- çŸåšã®æè¡ã®å©ç¹ãšå¶éã«ã€ããŠåŠã³ãŸãã
- ãŸããåçã¢ã¯ã»ã¹å¶åŸ¡ãšéäžåã¢ã¯ã»ã¹ããªã·ãŒã䜿çšãããšäŸ¿å©ãªããã€ãã®ã·ããªãªã«ã€ããŠã説æããŸãã
ãããå§ããŸãããã
ACLããã®åçã¢ã¯ã»ã¹å¶åŸ¡ã®ç®çãšéã
ãã®æè¡ã®æåã®èšäºã®å€§éšåã§æ¢ã«è¿°ã¹ãããã«ãåçã¢ã¯ã»ã¹å¶åŸ¡ã«ãããäž»ã«Windows Server 2012ãå®è¡ããŠãããã¡ã€ã³ã³ã³ãããŒã©ãŒãšãã¡ã€ã«ãµãŒããŒã«ããäŒæ¥ãªãœãŒã¹ãžã®å ±æã¢ã¯ã»ã¹ãæäŸããã¡ã«ããºã ãå確èªã§ããŸããããã§ã¯ããªãã¢ã¯ã»ã¹ã®æäŸãæ¹ããŠèŠçŽãããšãã§ãããªãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ããããã»ã©äžå¿«ãªã®ã§ããããïŒ
ãŸãããã®è¬ããããã¯ãããžãŒã®ãªãªãŒã¹åã«ããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãã©ã®ããã«æäŸãããŠããããæãåºããŸãããã
ã¢ã¯ã»ã¹èš±å¯ã¯ä»¥åã©ã®ããã«å²ãåœãŠãããŠããŸãããïŒ
äžè¬çã«ãã¢ã¯ã»ã¹å¶åŸ¡èš±å¯ã¯å ±æãªããžã§ã¯ããšActive Directoryãªããžã§ã¯ãã«å²ãåœãŠãããããŸããŸãªãŠãŒã¶ãŒãåãªããžã§ã¯ãã䜿çšããæ¹æ³ã決å®ããŸãã 誰ããç¥ã£ãŠããããã«-管çè ã ãã§ãªããéåžžã®PCãŠãŒã¶ãŒã- å ±æãªããžã§ã¯ããŸãã¯å ±æãªãœãŒã¹ã¯ããããã¯ãŒã¯äžã®1人以äžã®ãŠãŒã¶ãŒã®äœ¿çšã䌎ããªããžã§ã¯ãã§ãã ãã¡ããããã®ãããªãªããžã§ã¯ãã¯ããã¡ã€ã«ãããªã³ã¿ãŒããã©ã«ããŒãããã³ãµãŒãã¹ã§ãã Active Directoryã§ã¯ããã«ã¢ã¯ã»ã¹ãæžã蟌ã¿ãèªã¿åããã¢ã¯ã»ã¹ãªããªã©ãããŸããŸãªã¢ã¯ã»ã¹ã¬ãã«ãŸãã¯ã¢ã¯ã»ã¹èš±å¯ã®ãªããžã§ã¯ããèšå®ããããšã«ããããªããžã§ã¯ãã¬ãã«ã§ã¢ã¯ã»ã¹å¶åŸ¡ãå®è¡ãããŸããã å ±æãªããžã§ã¯ããšActive Directoryãªããžã§ã¯ãã®äž¡æ¹ã®ã¢ã¯ã»ã¹å¶åŸ¡èš±å¯ã¯ãã»ãã¥ãªãã£èšè¿°åã«ä¿åãããŸãã
ã»ãã¥ãªãã£èšè¿°åã«ã¯ãåãªããžã§ã¯ãã®ã»ãã¥ãªãã£æ å ±ã®å²ãåœãŠãšå¶åŸ¡ã«äœ¿çšããã2ã€ã®ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ã ïŒACLïŒãå«ãŸããŠããŸãã ãã¡ãããããã¯éžæã¢ã¯ã»ã¹å¶åŸ¡ããŒãã«ïŒDACLïŒãšã·ã¹ãã ã¢ã¯ã»ã¹å¶åŸ¡ããŒãã«ïŒSACLïŒã§ãã
- éæã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒDACLïŒ ã å ¬åŒãœãŒã¹ãããããããã«ãDACLã¯ãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãæ瀺çã«èš±å¯ãŸãã¯æåŠãããŠãããŠãŒã¶ãŒãšã°ã«ãŒãããªã¹ãããŸãã æãããªçç±ã«ãããã¡ã³ããŒã§ããç¹å®ã®ãŠãŒã¶ãŒãŸãã¯ã°ã«ãŒããDACLã§æ瀺çã«æå®ãããŠããªãå Žåããã®ãŠãŒã¶ãŒã¯ãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãæåŠãããŸãã ããã©ã«ãã§ã¯ãDACLã¯ãªããžã§ã¯ãã®ææè ãŸãã¯ãªããžã§ã¯ããäœæãããŠãŒã¶ãŒã«ãã£ãŠå¶åŸ¡ããããªããžã§ã¯ããžã®ãŠãŒã¶ãŒã¢ã¯ã»ã¹ãå®çŸ©ããã¢ã¯ã»ã¹ å¶åŸ¡ãšã³ããª ïŒ ACE ïŒãå«ãŸããŠããŸãã
- ã·ã¹ãã ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒSACLïŒã 次ã«ãSACLã«ã¯ããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹è©Šè¡ã®æåããã³å€±æãç£æ»ãããŠãŒã¶ãŒãšã°ã«ãŒãããªã¹ããããŸãã ç£æ»ã¯ãã·ã¹ãã ãŸãã¯ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã«é¢é£ããã€ãã³ããç£èŠããã»ãã¥ãªãã£ã·ã¹ãã ã®æ¬ é¥ãæ€åºããæ害ã®ç¯å²ãšå Žæãå€æããããã«äœ¿çšãããŸãã ããã©ã«ãã§ã¯ãDACLãšåæ§ã«ãSACLã¯ãªããžã§ã¯ãã®ææè ãŸãã¯ãªããžã§ã¯ããäœæãããŠãŒã¶ãŒã«ãã£ãŠç®¡çãããŸãã SACLã«ã¯ããã®ã¢ã¯ã»ã¹èš±å¯ïŒãã«ã³ã³ãããŒã«ãèªã¿åããªã©ïŒã䜿çšãããŠãŒã¶ãŒã«ãããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹è©Šè¡ã®æåãŸãã¯å€±æãèšé²ããå¿ èŠããããã©ããã決å®ããã¢ã¯ã»ã¹å¶åŸ¡ã¬ã³ãŒããå«ãŸããŠããŸãã
æ¢å®ã§ã¯ãDACLããã³SACLã¯åActive Directoryãªããžã§ã¯ãã«é¢é£ä»ããããŠããããµã€ããŒç¯çœªè ãã©ã³ãã ãã¡ã€ã³ãŠãŒã¶ãŒãšã©ãŒã«ãããããã¯ãŒã¯æ»æã®å¯èœæ§ãäœæžããŸãã ãã ããæ»æè ãActive Directory管çè æš©éãæã€ã¢ã«ãŠã³ãã®ååãšãã¹ã¯ãŒããèŠã€ããå Žåããã®ãã©ã¬ã¹ãã¯æ»æã«å¯ŸããŠè匱ã«ãªããŸãã
ãŸããæ¢å®ã§ã¯ãActive Directoryãªããžã§ã¯ãã¯èŠªã³ã³ãããŒãªããžã§ã¯ãã®ã»ãã¥ãªãã£èšè¿°åããACEãç¶æ¿ããããšã«æ³šæããŠãã ããã ç¶æ¿ã䜿çšãããšãActive Directoryã³ã³ãããªããžã§ã¯ãã«åºæã®ã¢ã¯ã»ã¹å¶åŸ¡æ å ±ããä»ã®ã³ã³ãããšãã®ãªããžã§ã¯ããå«ãäžäœãªããžã§ã¯ãã®ã»ãã¥ãªãã£èšè¿°åã«é©çšã§ããŸãã ããã«ãããæ°ããååãªããžã§ã¯ãã«ã¢ã¯ã»ã¹èš±å¯ãé©çšããå¿ èŠããªããªããŸãã å¿ èŠã«å¿ããŠãç¶æ¿ãããæš©éãå€æŽã§ããŸãã ãã ããActive Directoryãªããžã§ã¯ãã®æ¢å®ã®ã¢ã¯ã»ã¹èš±å¯ãšç¶æ¿èšå®ãå€æŽããªãããšããå§ãããŸãã
èªå¯ããã»ã¹ã¯ãŠãŒã¶ãŒã«ãšã£ãŠã¯åäžã®ã€ãã³ãã®ããã«èŠããŸããã2ã€ã®éšåã§æ§æãããŠããŸãã
ãŠãŒã¶ãŒã¯ã¢ã¯ã»ã¹ãã©ã¡ãŒã¿ïŒéåžžã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãïŒãæäŸããAD DSããŒã¿ããŒã¹ã§æ€èšŒãããŸãã ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããããŒã¿ããŒã¹ã«ä¿åãããŠããæ å ±ãšäžèŽããå ŽåããŠãŒã¶ãŒã¯æ¿èªããããã¡ã€ã³ã³ã³ãããŒã©ãŒããã±ãããåãåãããã®ãã±ãããçºè¡ãããŸãã ãã®æç¹ã§ããŠãŒã¶ãŒã¯ãããã¯ãŒã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸããã
ã»ã«ã³ããªããã¯ã°ã©ãŠã³ãããã»ã¹ã¯ã確èªã®ããã«ãã±ããããã¡ã€ã³ã³ã³ãããŒã©ãŒã«æž¡ããããŒã«ã«ãã·ã³ãžã®ã¢ã¯ã»ã¹ãèŠæ±ããŸãã ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ãŠãŒã¶ãŒã«ãµãŒãã¹ãã±ãããçºè¡ãããŠãŒã¶ãŒã¯ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒãšå¯Ÿè©±ã§ããŸãã ããã»ã¹ã®ãã®æç¹ã§ããŠãŒã¶ãŒã¯AD DSã§æ¿èªãããããŒã«ã«ãã·ã³ã«ç»é²ãããŸãã
ãã®åŸããŠãŒã¶ãŒããããã¯ãŒã¯äžã®å¥ã®ã³ã³ãã¥ãŒã¿ãŒãšã®æ¥ç¶ã確ç«ããããšãããšãã»ã«ã³ããªããã»ã¹ãåã³éå§ããããã±ãããååŸããããã®ãã±ããã¯ãæ€èšã®ããã«æãè¿ããã¡ã€ã³ã³ã³ãããŒã©ãŒã«æž¡ãããŸãã ãã¡ã€ã³ã³ã³ãããŒã©ãŒããµãŒãã¹ãã±ãããè¿ããšããŠãŒã¶ãŒã¯ãããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒã«ã¢ã¯ã»ã¹ãããã®ã³ã³ãã¥ãŒã¿ãŒã§æ¿èªã€ãã³ããçæããŸãã
ãã¡ã€ã³ã«æ¥ç¶ãããã³ã³ãã¥ãŒã¿ãŒã¯ãèµ·åæã«AD DSã«ããã°ã€ã³ããŸããããã¯ãã°ãã°èŠèœãšãããã¡ã§ãã ã³ã³ãã¥ãŒã¿ãŒãActive Directoryãã¡ã€ã³ãµãŒãã¹ã§ã®æ¿èªã«ã¢ã«ãŠã³ãåãšãã¹ã¯ãŒãã䜿çšããå Žåããã©ã³ã¶ã¯ã·ã§ã³ã¯è¡šç€ºãããŸããã èªèšŒåŸãã³ã³ãã¥ãŒã¿ãŒã¯æ¿èªããããŠãŒã¶ãŒã®ã°ã«ãŒãã®ã¡ã³ããŒã«ãªããŸãã ã³ã³ãã¥ãŒã¿ãŒã®æ¿èªããã»ã¹ã®ã°ã©ãã£ã«ã«ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ã«ã¯èŠèŠçãªç¢ºèªã¯ãããŸãããããã®ã¢ã¯ãã£ããã£ãèšé²ããã€ãã³ããããã³ã«ãããããšãèŠããŠãã䟡å€ããããŸãã ããã«ãç£æ»ãã¢ã¯ãã£ãã«ãªã£ãŠããå Žåãã€ãã³ããã¥ãŒã¢ãŒã»ãã¥ãªãã£ãã°ã§è¡šç€ºã§ããã€ãã³ããå¢ããŸãã
ãããŠãåçã¢ã¯ã»ã¹å¶åŸ¡ãããåªããŠãããã®ã¯äœã§ããïŒ
å®éãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãã«åºã¥ããŠã¢ã¯ã»ã¹ãèš±å¯ããæ§æèŠçŽ ã«åºã¥ããŠããã®æ¹æ³ã䜿çšãããšãç¹å®ã®ã°ã«ãŒãã®ã¿ãŒã²ããã®ã¡ã³ããŒã·ããã®ã¿ã«åºã¥ããŠèš±å¯ãèš±å¯ããããšããçµè«ã«éããããšãã§ããŸãã ãµãŒãããŒãã£ã®ç¹æ§ã«åºã¥ããŠãç¹å®ã®ãŠãŒã¶ãŒããã€ã¹ãžã®ã¢ã¯ã»ã¹ãå¶éããããéã«èš±å¯ãããããããšã¯ã§ããŸããããŸããéæšæºã®ã·ããªãªãããã«å¿ããããšãã§ããŸãã
åçã¢ã¯ã»ã¹å¶åŸ¡ã«ããããããã®å¶éãåé€ãããããŸããŸãªåºæºã«åŸã£ãŠã¢ã¯ã»ã¹ãæäŸã§ãããã詳现ãªã«ãŒã«ãäœæã§ããŸãã èšãæããã°ããŸã第äžã«ããã®ãã¯ãããžãŒã¯éäžåã»ãã¥ãªãã£ããªã·ãŒãäœæããããšã§ãã¡ã€ã«ãããŒã¿ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããæ©èœãæäŸãããšããäºå®ã«æ³šæãæã䟡å€ããããŸãã ã€ãŸããããžãã¹ã®æŠç¥ãæãããåæ ããèŠå¶èŠä»¶ãå®å šã«éµå®ãããããªããªã·ãŒãäœæã§ããŸãã ããã«ãæåã¢ãŒããšèªåã¢ãŒãã®äž¡æ¹ã§ãã¡ã€ã«åé¡ã䜿çšãããšãã«ããã®ãããªæ å ±ãç¹å®ã§ããŸãã ACLã䜿çšããå Žåãããã2ã€ã®ãªãã·ã§ã³ã®ã¿ãå³åº§ã«å¶åŸ¡ã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã ããããã ãã§ã¯ãããŸããã ã¢ã¯ã»ã¹ãããæãäžè¬çãªããŒã¿ã¿ã€ãã¯ãOfficeããã¥ã¡ã³ããã€ãŸããMicrosoft Office補åã䜿çšããŠç®¡çã§ãããã¡ã€ã«ã§ãã 以åã¯ãç¹å®ã®ãŠãŒã¶ãŒãŸãã¯ã°ã«ãŒãã«ããã¥ã¡ã³ãã®æå·åã«ããäžæã®ã¢ã¯ã»ã¹èš±å¯ãä»äžããããã«ãActive Directory Rights ManagementãµãŒãã¹ãã€ãŸãAD RMSãåããã¥ã¡ã³ãã«äœ¿çšãããŠããŸããã ãã®æè¡ã¯ååã«èšŒæãããŠããããã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ã®åºçŸã«ãããç¹å®ã®åºæºã«åºã¥ããèªåæå·åã䜿çšããŠRMSä¿è·ãé©çšããæ©äŒãäžããããŸããã
ä»æ¥ãå€ãã®äŒæ¥ã®æã貎éãªè³ç£ã®1ã€ã¯æ å ±ãã®ãã®ã«ä»ãªããŸãããæ å ±èªäœã¯çµç¹ãè¶ ããŠã¯ãªããŸããã ãã®ãããªæ å ±ã®èª€çšã¯ãäŒç€Ÿå šäœã®éåœã«æªåœ±é¿ãäžããå¯èœæ§ããããŸãã ãã®ãã¯ãããžãŒã®äžå åãããç£æ»ããªã·ãŒã®ãããã§ããã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãããã«ç£æ»ããããã®ã¬ããŒããäœæããããç·æ¥ã®å Žåã¯æ³å»åŠåæãäœæãããã§ããŸãã ã€ãŸãããµãŒãããŒãã£ã®ã¢ããªã±ãŒã·ã§ã³ããœãããŠã§ã¢è£œåã䜿çšããå¿ èŠã¯ãããŸããã
ãã以å€ã«åŒ·èª¿è¡šç€ºã§ãããã®ã¯äœã§ããïŒ ãŸããActive Directoryã¹ããŒã ã«å€æŽãå ããããšãªããè¿œå ã®ããŒã«ãç¹å®ã®ãœãããŠã§ã¢ãå±éããããšãªããäžè¬çã«ãããã«äœ¿çšã§ãããçŸåšã®ãã¯ãããžã䜿çšã§ããããšã匷調ã§ããŸãã ããã«ãç¹ã«ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšããå¯èœæ§ã®ããã«ãWindowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã çšã«æ°ããæ¿èªããã³ç£æ»ã¡ã«ããºã ãéçºãããKerberosèªèšŒæ©èœçšã«ããã€ãã®é©æ°ãå®è£ ãããŸãããããã«ã€ããŠã¯ã Kerberosãããã¯ãŒã¯èªèšŒãããã³ã«ããŸãã¯ã¯ã¬ãŒã ãå¿ èŠãªçç± ãã
圌ã«ã¯å¶éããããŸããïŒ
æ®å¿µãªãããäºæ³ãããããã«ããã®ãã¯ãããžãŒã«ã¯ããã€ãã®å¶éããããŸãã ãŸããçµç¹ã«Active Directoryãã¡ã€ã³ãµãŒãã¹ãå±éããå¿ èŠããããŸãã ã€ãŸããã¯ãŒã¯ã°ã«ãŒãã®äžéšã§ããã³ã³ãã¥ãŒã¿ãŒã«åçã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšããå ŽåãæåããŸããã 第äºã«ãåçã¢ã¯ã»ã¹å¶åŸ¡ã¯åãªãç¬ç«ããæ©èœã§ã¯ãããŸããã ãã®ãã¯ãããžã¯ãWindows Server 2012ã€ã³ãã©ã¹ãã©ã¯ãã£ã«åºã¥ããŠæ§ç¯ããããã¡ã€ã«ãµãŒããŒãœãªã¥ãŒã·ã§ã³ã§ãããçŽæ¥ã®Kerberosã¯ã¬ãŒã ã®ãµããŒãããªãœãŒã¹ããããã£ãæ ŒçŽããããã®Active DirectoryãµããŒãããŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãŒã®ã¯ã¬ãŒã ãéäžã¢ã¯ã»ã¹ããªã·ãŒãæ ŒçŽããããã®Active DirectoryãµããŒããå®è£ ãªã©ãå«ãŸããŸãã°ã«ãŒãããªã·ãŒã®æ©èœãªã©ã䜿çšããããã®ãããªäžå åãããã¢ã¯ã»ã¹ããªã·ãŒã®é åžã
ãããã£ãŠããããã®ãã¹ãŠã®èŠä»¶ã«åŸã£ãŠã次ã®çµè«ãå°ãåºãããšãã§ããŸããWindowsServer 2012ãå®è¡ãããã¡ã€ã³ã³ã³ãããŒã©ãŒãå°ãªããšã1ã€çµç¹ã«å±éããå¿ èŠããããŸãããŸãããã©ã¬ã¹ãã«è€æ°ã®ãã¡ã€ã³ãå±éãããŠããå Žåããã®ãããªãã¡ã€ã³ã¯ãWindows Server 2012ã§å°ãªããšã1ã€ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãšå ±ã«å±éããå¿ èŠããããŸããããã¯ãä¿¡é Œé¢ä¿ã確ç«ãããŠãããã¡ã€ã³éã§ã¯ã¬ãŒã ã䜿çšããå¯èœæ§ã®ããã«ç¹ã«è¡ãããŸãã ããã«ãåè¿°ããããã«ãWindows Server 2012ã§ã¯ãKDCãµãŒãã¹ã¯ãKerberosãã±ããå ã®ã¯ã¬ãŒã ãåŠçããããã«ç¹ã«æ¹åãããŸããã
ãã¡ã€ã«ãµãŒããŒäžã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯åœç¶Windows Sever 2012ã§ããå¿ èŠããããŸãããŠãŒã¶ãŒãå ±æãã©ã«ããŒã«æ¥ç¶ãããšããã¡ã€ã«ãµãŒããŒã¯çä¿¡æ¥ç¶ã®è³æ Œæ å ±ã䜿çšããŠãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã確èªããŸãã ããã¯ããã¡ã€ã«ãµãŒããŒãå ±æãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã決å®ããããšãæå³ããŸãã ãŸãããã¡ã€ã«ãµãŒããŒäžã®ããŸããŸãªã³ã³ããŒãã³ãããLSAãKerberosã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãªã©ã®ã¯ã¬ãŒã ããµããŒãããå¿ èŠãããããšãæå³ããŸãã ãŠãŒã¶ãŒãããŒã¿ã«ã¢ã¯ã»ã¹ãããã¡ã€ã«ãµãŒããŒã¯ãKerberosãã±ããããããã€ã¹ã®ã¯ã¬ãŒã ãšæ¿èªããŒã¿ãèªã¿åãããããã®ã»ãã¥ãªãã£èå¥åïŒSIDïŒãšãã±ããæ¿èªãèªèšŒããŒã¯ã³ã«å€æããæ¿èªããŒã¿ãæ¯èŒã§ããå¿ èŠãããããšãããããŸãã»ãã¥ãªãã£èšè¿°åã«æ¡ä»¶ãå«ãŸããããŒã¯ã³å ã ã€ãŸããOSã®å€ãããŒãžã§ã³ã¯çµæãšããŠæ©èœããŸããã
ããŠãæå®ãããããã€ã¹ã«å¯ŸããèŠæ±ãããå ŽåãWindows 8ãŸãã¯Windows Server 2012ãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒã®ã¿ãã¯ã©ã€ã¢ã³ããšããŠäœ¿çšã§ããŸããã€ãŸãããã®å¶éã¯ãã¯ã©ã€ã¢ã³ãã8ã«ç§»è¡ããæ£åœãªçç±ãšèšããŸãã
ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšããããã®äž»ãªã·ããªãª
次ã«ããã掻æ°ã®ããç¬é-ã·ããªãªèªäœã«ã€ããŠãåçã¢ã¯ã»ã¹å¶åŸ¡ãé©çšããããšããå§ãããŸãã æŠããŠãå€ãã®ã·ããªãªãã·ãã¥ã¬ãŒãã§ããŸãããäž»ã«æ¬¡ã®7ã€ã®ã·ããªãªãåºå¥ã§ããŸãã
- èªå¯ããªã·ãŒã®éäžå±é ã ãŸãããã®ãã¯ãããžãŒã®äž»ãªã¿ã¹ã¯ã®1ã€ã¯ãäŒæ¥ãã¡ã€ã«ã®éäžã¢ã¯ã»ã¹ããªã·ãŒãäœæããç¹å®ã®æ¡ä»¶ã«åºã¥ããŠãŠãŒã¶ãŒãŸãã¯ãŠãŒã¶ãŒã®ããã€ã¹ããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããããã«ããããšã§ãã ãããã¯åç¹å®ã®äŒæ¥ã®ããŒãºã«åºã¥ããŠã®ã¿äœæãããããããã®æè¡ã¯ç¹ã«äŸ¡å€ããããŸãã ãã®ã·ããªãªã®å®è£
æ¹æ³ïŒ
- ãŸããããžãã¹ã®æ¹åæ§ãè©äŸ¡ãããã®ãããªããªã·ãŒãã©ã®ããã«æ©èœããããå€æããå¿ èŠããããŸãã ã€ãŸãããŸãæåã«ãäžè¬ã«éäžåã¢ã¯ã»ã¹ããªã·ãŒãå¿ èŠãªçç±ãå€æããå¿ èŠããããŸããã€ãŸããå°æ¥ãã®ãããªããªã·ãŒãé©çšããããªãœãŒã¹ãããŒã«ã©ã€ãºããå¿ èŠããããŸãã ãã®åŸãç°å¢ã«é©çšãããã¹ãŠã®ããªã·ãŒã®ãªã¹ããäœæãããŸãã ããã»ã©ãããŸãã§ã¯ãªãããæ¡ä»¶ã«å¿ããŠãã¡ã€ã«ãªãœãŒã¹ãéšéãç¹å®ã®ã«ããŽãªã«åå²ããŸããå€æ°ã®ãã©ã³ãã®å Žåãç©ççãªå Žæã«å¿ããŠã¢ã¯ã»ã¹ãå¶éããæ¹ãåçæ§ãé«ãæ¹æ³ãæ€èšããŠããŸãã
- 次ã«ããµãŒããŒãç解ã§ãã圢åŒã§ãWindows Serverã®æ§é ã³ã³ããŒãã³ãã«ã¢ã¯ã»ã¹ããªã·ãŒåŒãå®è£ ããŸãã ãã®äžé£ã®åèªã¯ã©ãããæå³ã§ããïŒ ãŸãããã®ã·ããªãªã®å®è£ ã®2çªç®ã®ã¹ãããã¯ãå¿ èŠãªã¢ã¯ã»ã¹ããªã·ãŒãæ£ããåŒã«å€æããããšã§ãã ãã®ãããªããªã·ãŒã¯ãäžè¬ã«ã誰ã«ãšã£ãŠãç解ã§ããéåžžã®åœ¢åŒãããã»ãã¥ãªãã£ããªã³ã·ãã«ã«æ¿èªãæäŸããããã«å¿ èŠãªèšèªã«éåžžã«ç°¡åã«å€æãããŸãã ã€ãŸãããã®ãããªã¢ã¯ã»ã¹ããªã·ãŒã«ã¯ãé©çšå¯èœæ§ ã ã¢ã¯ã»ã¹æ¡ä»¶ ãããã³äŸå€ã® ã«ãŒã«ããããŸã ã ããªããšç§ã¯ããã®çããµã€ã¯ã«ã®ä»¥äžã®èšäºã®ããããã§ããã詳现ã«æ€èšããŸãã
- ãã®åŸãã¿ã¹ã¯3ã¯ããŠãŒã¶ãŒã°ã«ãŒãããªãœãŒã¹ããããã£ãããã³å¿ èŠãªã¹ããŒãã¡ã³ããèå¥ããããšã§ãã ã€ãŸããåéäžã¢ã¯ã»ã¹ããªã·ãŒã«å¯ŸããŠäœæãããã¹ããŒãã¡ã³ããã©ã®ç¹å®ã®ãªãœãŒã¹ããã³ã©ã®ã»ãã¥ãªãã£ããªã³ã·ãã«ã«é©çšãããããåæããå¿ èŠããããŸãã
- ãããŠãæããã«ãæåŸã®ãã€ã³ãã¯ããã®ãããªéäžåã¢ã¯ã»ã¹ããªã·ãŒãé©çšããããµãŒããŒã®å®çŸ©ã§ãã ããšãã°ããã®ãããªããªã·ãŒãäžåºŠã«ãã¹ãŠã®ãã¡ã€ã«ãµãŒããŒã«é åžããããšããå ã®ç®çã«å¿ããŠãµãŒããŒã«é åžããããšãã§ããŸãã
- ãã©ã¬ã¹ãéã§ã¯ã¬ãŒã ãå®è£
ãã ã Windows Server 2012ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãåãã©ã¬ã¹ãã§ããããã¯ã¬ãŒã ãã£ã¯ã·ã§ããªã䜿çšã§ããããã«èšèšãããŠããããããã¯ãã¹ãŠActive Directoryãã¡ã€ã³ãµãŒãã¹ã¬ãã«ã§çŽæ¥å®çŸ©ãããŸãã åºæ¬çãªã·ããªãªã¯ãã¯ã©ã€ã¢ã³ããã¢ã¯ã»ã¹ã®æ¿èªãååŸããå¿
èŠãããç¶æ³ã§ãããäœããã®æ¹æ³ã§ä¿¡é Œã®å¢çããã€ãã¹ããŸãã
æããã«ãã¯ã¬ãŒã ã¯ãé¢é£ä»ããããŠãããªããžã§ã¯ãã«é¢é£ããŠãããåActive Directoryãã©ã¬ã¹ãã«å¯ŸããŠãç¬èªã®çš®é¡ã®ã¯ã¬ãŒã ãå®çŸ©ãããŠããŸãã ãã©ã¬ã¹ãéã¯ã¬ãŒã ã®å€æã«ãããä¿¡é Œã§ãããã©ã¬ã¹ãããã³ä¿¡é Œã§ãããã©ã¬ã¹ãã§ããããèªèããã³é©çšã§ããŸãã å°ãæ確ã«ããããã«ïŒ
ä¿¡é Œããããã©ã¬ã¹ãã䜿çšããŠã¯ã¬ãŒã ãå€æããç¹å®ã®å€ã«åŸã£ãŠåä¿¡ã¯ã¬ãŒã ããã£ã«ã¿ãªã³ã°ããããšã«ãããææ Œããç¹æš©ã«é¢é£ããæ»æãåé¿ã§ããŸãã ãŸããä¿¡é Œããããã©ã¬ã¹ããç¹å®ã®ã¢ãµãŒã·ã§ã³ããµããŒãããªãããŸãã¯çºè¡ããªãå Žåãä¿¡é Œå¢çãè¶ããŠããªã³ã·ãã«ã«å¯ŸããŠã¢ãµãŒã·ã§ã³ãçºè¡ããŸãã
次ã«ãä¿¡é Œããããã©ã¬ã¹ãã¯ã¢ãµãŒã·ã§ã³å€æã䜿çšããŠãç¹å®ã®çš®é¡ã®ã¯ã¬ãŒã ãé²æ¢ããç¹å®ã®ãã©ã¡ãŒã¿ãŒãæã€ã¯ã¬ãŒã ãä¿¡é Œã§ãããã©ã¬ã¹ãã«å ¥ãã®ãé²ããŸãã
ãšããã§ãã¯ã¬ãŒã å€æããªã·ãŒã®äœæã«ã¯ãã¯ã¬ãŒã å€æããªã·ãŒãªããžã§ã¯ããšå€æåç §ã®2ã€ã®ã³ã³ããŒãã³ããé¢ä¿ããŠããããšãç解ããããšãéåžžã«éèŠã§ãã ãããã®ãã€ã³ããããã³ç¹ã«ã·ããªãªã«ã€ããŠã¯ããã®ãã¯ãããžãŒã«é¢ãã察å¿ããèšäºã§ããã«è©³ãã説æããŸãã - ã¢ã¯ã»ã¹ãæåŠããããŠãŒã¶ãŒã®ãµããŒãã®æ¹å ã ååãšããŠãéåžžã®ç¶æ³ïŒãŠãŒã¶ãŒNã¯ä»äºã«æ¥ãŠããã¡ã€ã«ãµãŒããŒã«ããç¹å®ã®æ
å ±ã«é¢é£ããã¿ã¹ã¯ãåãåããŸããããã®ãããªãŠãŒã¶ãŒã«ã¯ã¢ã¯ã»ã¹ãæäŸãããŸããã 次ã«äœãèµ·ãããïŒåããŠãŒã¶ãŒNã¯å
±æãã©ã«ããŒã«ã¢ã¯ã»ã¹ããããšããŸãããå
±æãã©ã«ããŒãéãããšãããšããã¢ã¯ã»ã¹ãæåŠãããŸããããšããå¯äžã®çããè¿ãããŸãã ãã®åŸããŠãŒã¶ãŒã¯ãµããŒããµãŒãã¹ã«é£çµ¡ããå®è·µã瀺ãããã«ããã®ãŠãŒã¶ãŒã®ã¿ãç解ã§ãã圢åŒã§ãã©ã®ããã¥ã¡ã³ãã«ã¢ã¯ã»ã¹ããå¿
èŠãããã®ãââããªãå¿
èŠãªã®ãããã®ãããªããã¥ã¡ã³ããããå Žæãªã©ã説æããããšããŸãã
åçã¢ã¯ã»ã¹å¶åŸ¡ã䜿çšããå©ç¹ã¯äœã§ããïŒ , , , .
. , , . . Microsoft? , , :
- , . , , , . , - . , ;
- , , , ;
- , ;
- , . , , ;
- , . - .
- . , â , , , , . , - , , . , , ( DFS-R), , . , , - , .
Windows Server 2012 , , , , . , , , . , , . :
- , . ? , , ;
- , , - , . , , , , , , , . .
- Microsoft Office . AD RMS⊠. , , . . Active Directory. , Windows Server 2012, , Microsoft Office, , , . :
- , , . , , . - , . , . , . , , , , , ;
- , . , , , , AD RMS. , . -, , , . , , . ;
- , , , , - .
- . , : ? , « , , ». , . , , . , -, - , . , , , , , Microsoft. , , , - . , , :
- , , , , . , ;
- , , . , , .
- . , , . ? , , . : ? , , , , , .
? -, . : , , . -, , . , , , , , , , , , . , , - , - , , , .
, , , , .
?
ç§èªèº«ããç¹ã«å€ãã®è³æãããã«æ瀺ãããå Žåã¯ãçŽç²ã«çè«çãªéšåãéåžžã«ã€ãŸããªãå Žåãããããšãããç¥ã£ãŠããŸãããã ããçè«çæ ¹æ ã®ãªãå®è·µã¯ãææãç 究ããããã®ééã£ãã¢ãããŒãã§ãããã®ãµã€ã¯ã«ã®ä»¥äžã®èšäºã§ã¯ãåè¿°ããããã«ãã¹ããŒãã¡ã³ããã©ã®ãããªãã®ã§ãããã©ã®ããã«äœæããããã®ããã»ã¹äžã«çºçããå¯èœæ§ã®ããèœãšãç©Žã«ã€ããŠåŠç¿ããŸãããªãœãŒã¹ã®ããããã£ã«ã€ããŠåŠç¿ããŸããéäžåã¢ã¯ã»ã¹ããªã·ãŒãšã«ãŒã«ã®äœæã«ãããããŸããŸãªãã¥ã¢ã³ã¹ã«ã€ããŠè©³ãã説æããŸãããã¡ããããã®ãããªéäžåã¢ã¯ã»ã¹ããªã·ãŒãã©ã®ããã«å ¬éããã³é©çšã§ãããã«ã€ããŠã説æããŸããäžèšã®ããã€ãã®æ®µèœã§ç°¡åã«èšåããããã¹ãŠã®ã·ããªãªãèæ ®ãããŸããç£æ»ã«ã€ããŠåŠç¿ããããŸããŸãªãã¡ã€ã«ãšãã©ã«ããŒã®åé¡ã«ã€ããŠã説æããŸããããã«ãåçã¢ã¯ã»ã¹å¶åŸ¡ã«é¢é£ããå¯èœæ§ã®ããåé¡ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«ãå¿ ãå¥ã®èšäºãæ§ããŸãã
äžè¬ã«ããã®èšäºãããªãã«ãšã£ãŠããŸãã«ãç²ããªãããšããããŠãã®æè¡ã®äœ¿çšã«ã€ããŠãã£ãšç¥ããããšãã欲æ±ã倱ã£ãŠããªãããšãé¡ã£ãŠããŸããåæ§ã«ã次ã®èšäºã«ã¯åœç¶ãçè«çãªè³æãè±å¯ã«ãªããããäž»ã«ã·ããªãªãããŸããŸãªæé ãããã³ãã®ãã¯ãããžã®äœ¿çšã®æ®µéçãªäŸãæ€èšããŸãã