ãã®èšäºããå§ããŠãç§ã¯èªåèªèº«ãä¿®æ£ãããã®æè¡ã«ç²Ÿéããæ¹æ³ã«ã€ããŠèª¬æããŸãã éå§ããã«ã¯ãèšäºã®ã¿ã€ãã«ãããããããã«ãã¹ããŒãã¡ã³ã以å€ã®äœãããã«å®è¡ããå¿ èŠããããŸãïŒä»¥åã®èšäºã§æ¢ã«æžããããã«ãã¢ããªã±ãŒã·ã§ã³ãklimaãããã³ã¯ã¬ãŒã ã§çœ®ãæããããä»ã®åèªãšãåŒã°ããŸãïŒãåçã¢ã¯ã»ã¹å¶åŸ¡ã®äž»èŠã³ã³ããŒãã³ãã®1ã€ã ããã§ãçè«çãªè³æãã§ããéãå°ãªãããŠãã¹ããããã€ã¹ãããã®æé ã«ã»ãŒããã«é²ãããã«ããŸãã ããã§ã¯ããã®æ¯èŒçå°ããªèšäºããäœãåŠã¶ããšãã§ããŸããïŒ
ãã®èšäºã§ã¯ã次ã®ããšã説æããŸãã
- 声æãšã¯äœãããããŠãããã®å©ç¹ã¯äœãã
- ã¹ããŒãã¡ã³ãã®çš®é¡ã«ã€ããŠåŠã³ãŸãã
- æ¡ä»¶åŒãšæŒç®åã«ã€ããŠã
- ãããŠãæãéèŠãªããšãšããŠã Active DirectoryãµãŒããŒã®å šäœç®¡çãšWindows PowerShellã䜿çšããŠã¯ã¬ãŒã ã管çããæ¹æ³ãåŠã³ãŸãã
ããŠããã®èšäºã®å°å ¥éšåãå€§å¹ ã«é 延ãããªãããã«ãæåã®ã»ã¯ã·ã§ã³ã«ç®ãåããŸãã
ã¹ããŒãã¡ã³ããšã¯äœã§ããïŒ
ç§ã¯ééããç¯ãããšãæããŠããŸãããç§ãã¡ã®æ代ã«ã¯ãå°ãªããšã1åã¯èªåã®ãããªãã¯ãã©ã«ããžã®ã¢ã¯ã»ã¹ãæäŸããªãã£ããŠãŒã¶ãŒã¯ããããªãã§ãããã ç¹ã«ãã®ç®çã®ããã«ãWindows NTã®é ãæ代ã«ããã€ã¯ããœããã¯IDãšããŠãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«IDã®æŠå¿µãå°å ¥ããŸãããããã¯é·å¹Žã«ããã£ãŠãã£ãããšå®çããŠããŸãã ããã§ã¯ãã¹ãŠãæçœã§ããç§ã®èšäºã§è¿°ã¹ãããã«ããã¡ã€ã«ãšãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã¯ã»ãã¥ãªãã£èå¥åã«çŽæ¥åºã¥ããŠããŸããã ãŠãŒã¶ãŒãèªåã®è³æ Œæ å ±ã«åŸã£ãŠæ£åžžã«èªèšŒããããã©ããã«åºã¥ããŠããããªãã¯ãã¡ã€ã«ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæäŸãããããšãããããŸãã ãã¡ãããã»ãšãã©ã®å Žåããã®ãããªè³æ Œæ å ±ã¯ãã¢ã«ãŠã³ãã®ååãšãã®ãã¹ã¯ãŒãããŸãã¯ç¹å®ã®ã°ã«ãŒãã®ãŠãŒã¶ãŒã®ã¡ã³ããŒã·ããã§ããã èå¥ã®æŠå¿µã¯çãããåãã®ãšããã§ãããæ¹ããŠèª¬æããæå³ã¯ãããŸããã
ããããå®éã«ã¯ãããŸããŸãªã°ã«ãŒãã®ã¡ã³ããŒã·ããã«ãããå Žåã«ãã£ãŠã¯ïŒå€ãã®ãã®ãããªã±ãŒã¹ããããŸãïŒããŠãŒã¶ãŒãã¢ã¯ã»ã¹ãèš±å¯ãããŠããªããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã誀ã£ãŠèš±å¯ãããããšããããŸãã ãã®ãããªã±ãŒã¹ãåãé€ãããã«ãMicrosoftã®ææ°ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«æ°ããæŠå¿µãå°å ¥ãããŸããã ãããäœã§ããããæ€èšããŠãã ããã
çŸåšãæ°ããåèªãŸãã¯ç解ã§ããªãåèªãèã人å£ã®å€§å€æ°ã¯äœã§ããïŒ åœŒãã¯ãŠã£ãããã£ã¢ãèŠãŠããŸãã ãã®ä»¶ã«ã€ããŠäœãæžãããŠããŸããïŒ ãèšèªåŠã«ãããè¯å®ã¯ç¹å¥ãªåœ¢åŒã®æã§ãããè¯å®çãªåœ¢åŒã§ã¯ããçŸè±¡ã«é¢ãã仮説ãæ瀺ããŸããã ããã¯ééããªãããã§ã¯ãããŸããã
ä»ã«äœãèŠã€ãããŸããïŒ ãè«çã¹ããŒãã¡ã³ãã¯ãè«çæ¥ç¶è©ã䜿çšããŠä»ã®ã¹ããŒãã¡ã³ããã圢æãããã¹ããŒãã¡ã³ãã§ããã ãŸããé©åããŸããã ãããã°ã©ãã³ã°ã®ã¹ããŒãã¡ã³ãã¯ãããã°ã©ã ã«é 眮ãããè¿°èªã§ãããéçºè ã¯ããã®è¿°èªãããã°ã©ã ã®ãã®æç¹ã§åžžã«çã§ããããšãæå³ããããšã瀺ããŸããã ããããããã§ããããã¯çŸåšã®æèã§æ瀺ãããŠãããã®ã§ã¯ãªãããã§ãã
å®éãå ¬åŒçšèªã«ãããšã ã¯ã¬ãŒã ã¯ãActive Directoryãã¡ã€ã³ãµãŒãã¹ã«æ ŒçŽãããŠãããã®ã¢ã«ãŠã³ãã®å±æ§ã§æäŸãããæ¿èªãå®è¡ããããšããã¢ã«ãŠã³ãã«é¢ããä¿¡é Œã§ããæ å ±æºã§ãã ããŸããŸãªã¢ãµãŒã·ã§ã³ã«ã¯ããŠãŒã¶ãŒãŸãã¯åœŒã®ã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£èå¥åããŠãŒã¶ãŒãåãããšãã§ãããŠãããã圌ã®éšå±çªå·ã圌ãäœãã§ããéœåžãªã©ãå€ãã®ããããã£ãå«ãŸããŸãã ããã«ãè€æ°ã®ã¹ããŒãã¡ã³ãã1ã€ã®ã¬ã³ãŒãã«æ ŒçŽã§ãããšããäºå®ã«æ³šæãæã䟡å€ããããŸããããã«ãããã»ãŒãã¹ãŠã®å¯èœæ§ãæºããåçã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãæè»ã«èšå®ã§ããŸãã
ãã®æ®µéã§ãããªãã¯éåžžã«è«ççãªè³ªåããããããããŸããïŒãããã®ã¹ããŒãã¡ã³ãã¯ç§ãã¡ã«äœãäžãããããã®ãã€ã³ãã¯äœã§ããïŒ ã¯ã¬ãŒã ã䜿çšããŠããã¡ã€ã«ãšãã©ã«ããŒã®äž¡æ¹ãžã®ã¢ã¯ã»ã¹ãå¶éã§ããŸãã ãŸããã¯ã¬ãŒã ã«é¢ããŠæã䟡å€ãããã®ã¯ãäœæããããã¹ãŠã®ã¯ã¬ãŒã ãActive Directoryã«çŽæ¥å ¬éãããããšã§ãã ããã«ããã®æè¡ã«é¢ãã以åã®èšäºã§è¿°ã¹ãããã«ãäžè¬çãªåçã¢ã¯ã»ã¹å¶åŸ¡ããã³ç¹ã«ã¹ããŒãã¡ã³ãã®å®å šãªæ©èœã«ã€ããŠã¯ãçµç¹ã®ãã¡ã€ã³ãŸãã¯ãã©ã¬ã¹ãã®æ©èœã¬ãã«ã«å¶éã¯ãããŸããã
ãã®ã·ãªãŒãºã®ååã®èšäºã§çŽ¹ä»ããKerberosãããã¯ãŒã¯èªèšŒãããã³ã«ã«é¢ããèšäºã®1ã€ã§ãKerberosãšã¯ã¬ãŒã ãšã®é¢ä¿ã«ã€ããŠè©³ãã説æããã®ã§ãããã«æ¬¡ã®ãããªãããã¯ã«é²ã¿ãŸãã
ã¯ã¬ãŒã ã¿ã€ã
å ¬åŒã®å®çŸ©ã«ããã°ãWindows Server 2012ã®ã¯ã¬ãŒã ã®çš®é¡ã¯ãé¢é£ä»ããããŠãããªããžã§ã¯ãã«é¢ããæ€èšŒã¹ããŒãã¡ã³ãã§ãã ããããæ¢ã«æšæž¬ãããŠããããã«ãæ¿èªã®çš®é¡ã¯Active Directoryå±æ§ã«åºã¥ããŠãããäžå åãããã¢ã¯ã»ã¹ã«ãŒã«ãéçºãããšãã«ã¢ã¯ã»ã¹èš±å¯ã決å®ããããã«äœ¿çšãããŸãã Windows Server 2012ã§ã¯ã次ã®3çš®é¡ã®ã¯ã¬ãŒã ã®ããããã䜿çšã§ããŸãã
- ãŠãŒã¶ãŒã¹ããŒãã¡ã³ã ã ãã®çš®é¡ã®ã¯ã¬ãŒã ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ãã«é¢é£ããå±æ§å€ã«é¢é£ä»ããããŠããŸãã åœç¶ãWindows Server 2012ãå®è¡ããŠãããã¡ã€ã³ã³ã³ãããŒã©ãŒã§ã¯ããã®çš®é¡ã®èŠæ±ã«å¯ŸããŠActive Directoryã§å©çšå¯èœãªãŠãŒã¶ãŒã¢ã«ãŠã³ãå±æ§ã®æ倧æ°ã䜿çšã§ããŸãã
- ããã€ã¹ã®æ¿èª ã åæ§ã«ããã®çš®é¡ã®ã¯ã¬ãŒã ã¯ãã¯ã¬ãŒã ã§æäŸãããæ å ±ãæ åœããŸããããã¯ãActive Directoryãã¡ã€ã³ãµãŒãã¹ã§ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ããšããŠè¡šãããããã€ã¹ã«é¢é£ããŠããŸãã åœç¶ããã®ã¿ã€ãã®ã¹ããŒãã¡ã³ãã§ã¯ããã®ã¿ã€ãã®ã»ãã¥ãªãã£ããªã³ã·ãã«ã§äœ¿çšå¯èœãªå±æ§ã®ã»ãšãã©ã䜿çšããããšãã§ããŸãã
- å€æã¹ããŒãã¡ã³ã ã æåŸã®çš®é¡ã®ã¯ã¬ãŒã ã¯ãæ¿èªå€æããªã·ãŒã䜿çšããŠãã¡ã€ã³ã³ã³ãããŒã©ãŒã«ãã£ãŠçºè¡ãããã¯ã¬ãŒã ã§ãã ãã®ã·ãªãŒãºã®æåã®èšäºã§è¿°ã¹ãããã«ãWindows Server 2012ãå®è¡ããŠãããã¡ã€ã³ã³ã³ãããŒã©ãŒã䜿çšãããšãä¿¡é Œããããã©ã¬ã¹ããŸãã¯ä¿¡é Œããããã©ã¬ã¹ãã«å ¥ãã¯ã¬ãŒã ãå€æã§ããŸãã ãã®çš®ã®äž»åŒµã¯ããã®æè¡ã«é¢ããä»åŸã®èšäºã§è°è«ãããŸãã
æ¡ä»¶åŒãšæŒç®å
ãã£ãããšãããèå³æ·±ãéšåã«é²ã¿ãŸãã ããæ£ç¢ºã«èšããšãã¯ã¬ãŒã ã«åºã¥ããŠæ¿èªãµããŒããå®è£ ã§ããããã«ãWindows Server 2012ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«å ·äœçã«ç»å ŽããOSã»ãã¥ãªãã£ãµãã·ã¹ãã ã«é¢é£ããæ¡ä»¶åŒãæ€èšããŸãã
ãããã®æ¡ä»¶åŒã¯ã¹ããŒãã¡ã³ãã«é¢é£ããŠããŸããïŒ å®éããããã®æ¡ä»¶åŒã¯ããŒã«åŒãŸãã¯è«çåŒã§ãããéåžžãç¹å¥ãªæŒç®åã§åºåããã2ã€ã®ãªãã©ã³ããå«ãŸããŸãã æ¡ä»¶åŒã®çµæã¯åžžã«2ã€ã®å€ã®ã¿ããŸãã¯ããæ£ç¢ºã«ã¯ããããã¯TRUEãšFALSEã«ãªããŸãã ãŸããACEåŒã¯èš±å¯ã®å Žåãšã¢ã¯ã»ã¹ç£æ»äžã®äž¡æ¹ã§è©äŸ¡ããããããæåãš2çªç®ã®ã±ãŒã¹ã§ã¯åãåŒã䜿çšã§ããããšã«æ³šæãã䟡å€ããããŸãã
ãããããããã®åŒã¯ã©ããªããŸããïŒ LSAãµãã·ã¹ãã ãPACããå¿ èŠãªæ å ±ãèªã¿åããã¢ã¯ã»ã¹ããŒã¯ã³ãäœæããããšã以åã«æžããŸããã ãã®åŸããŠãŒã¶ãŒããæäŸãããæ å ±ã«åºã¥ããŠã¢ã¯ã»ã¹ãã§ãã¯ãå®è¡ãããã»ãã¥ãªãã£ããŒã¯ã³ã§å²ãåœãŠãããã¢ã¯ã»ã¹èš±å¯ã«åºã¥ããŠããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ããšã³ããŠãŒã¶ãŒã«èš±å¯ããããæåŠããããã決å®ãããŸãã ããã¯ãã¹ãŠæããã§ãã ãã ããKerberosããªã³ã·ãã«æ å ±ã®ã¢ãµãŒã·ã§ã³ã®åºçŸã«ãããã»ãã¥ãªãã£ããªã³ã·ãã«ã®SIDã«å ããŠããããã®æ¡ä»¶åŒã§èŠã€ããè¿œå æ å ±ãå«ããããšãã§ããŸãã
ã¹ããŒãã¡ã³ãèªäœã¯ãã¹ããŒãã¡ã³ãã®ã¿ã€ããã¹ããŒãã¡ã³ãã®ååãªã©ã®ãšã³ãã£ãã£ã®ã³ã¬ã¯ã·ã§ã³ã§ãããããªãªãã§åºåãå¿ èŠããããŸãïŒä»¥äžãåç §ïŒã åã®ã»ã¯ã·ã§ã³ã§èª¬æããããã«ãæåã®éšåã¯ã¹ããŒãã¡ã³ãã®çš®é¡ã決å®ããããã«çŽæ¥äœ¿çšãããããšã¯æããã§ããã ãŠãŒã¶ãŒãŸãã¯ããã€ã¹ãšããŠæ©èœã§ããŸãã ã¹ããŒãã¡ã³ãã®ã¿ã€ãã«èšåããåã«ã @èšå·ã瀺ãããã®åŸã«ã¿ã€ãèªäœãæå®ããå¿ èŠããããŸãã ã¹ããŒãã¡ã³ãã®ååãæã€éšåã¯ããã®ãããªã¹ããŒãã¡ã³ããäœæãããšãã«ä»ããããšãã§ããååã§ãã
ã¹ããŒãã¡ã³ãã®å·ŠåŽãšå³åŽã®éšåã¯ç¹å¥ãªæŒç®åã§æ¯èŒããå¿ èŠããããå³åŽã®ãªãã©ã³ãã¯ãªãã©ã«å€ã«ããããšãã§ããŸããããã¯å·ŠåŽã®ãªãã©ã³ãã®å€ã®ãã©ã°ã¡ã³ãã«ããããšãã§ããŸãã
åèšã§ã13ã®ãªãã¬ãŒã¿ãŒãåºå¥ã§ããŸããããã¯ãããããä»ã®ãœãããŠã§ã¢è£œåã®æäœã«ãã§ã«æ £ããŠããã¯ãã§ãã ãã®ãããªæŒç®åã«ã€ããŠã¯è©³ãã説æããŸããããåã«ãã®æå³ã説æããŸãã ãã®æŒç®åã¯ã ïŒ == ïŒã çãããªã ïŒ ïŒ= ïŒã ãã倧ãã ïŒ > ïŒã ããå°ãã ïŒ < ïŒã ä»¥äž ïŒ > = ïŒã ä»¥äž ïŒ <= ïŒãã§ã¯ãªã ïŒ ïŒ ïŒã ããã³ ïŒ && ïŒ ã ãŸãã¯ ïŒ || ïŒã contains ïŒ Contains ïŒãã€ãŸãããã®ãããªæŒç®åã䜿çšããå Žåãå·Šãªãã©ã³ãã«ã¯å³ãªãã©ã³ãã®ãã©ã°ã¡ã³ããå«ãŸããŠããå¿ èŠããããŸãã ïŒ Any_Of ïŒã®ãããã ããã®ç®çã¯ãå³ãªãã©ã³ãã®å€ã®ãã©ã°ã¡ã³ãã®ã¿ãå€ãšããŠæ©èœã§ããããšãé€ããŠãåã®æŒç®åãšãããã䌌ãŠããŸãã ã°ã«ãŒãã¡ã³ããŒ ïŒ MemberOf ïŒ- å«ãŸããŠãããã®ãšã»ãŒåãããªãã©ã³ãã®ã¿ãSIDã§ããã ã¡ã³ããŒã°ã«ãŒãæŒç®åïŒ MemberOF_Any ïŒãæŒç®åã®ãããããšæ¯èŒã§ããŸãã
ããã§ãåçã¢ã¯ã»ã¹å¶åŸ¡ã·ããªãªãå®è£ ãããšãã«ã¹ããŒãã¡ã³ãã§äœ¿çšã§ããæ¡ä»¶åŒã®äŸãæ€èšããŠã¿ãŸãããã ããšãã°ã次ã®åŒã䜿çšããŸãã
@ User.Department ==â Marketingâ &&ïŒ@ User.Title ==â Financierâ || @ User.Title ==â MarketingâïŒ
ãã®åŒã¯æ¡ä»¶ä»ãã§3ã€ã®éšåã«åå²ã§ããåéšåã¯ã¹ããŒãã¡ã³ãã䜿çšããæ¬åŒ§å ã®2çªç®ãš3çªç®ã®éšåãåæã«åŠçãããŸãã ããã§ãããå°ã詳ãããéšåçã«èª¬æããŸãã
æ¡ä»¶åŒã®åªå 床ã«åºã¥ããŠãæåã«å®è¡ãããã®ã¯æ¬åŒ§å ã«ããåŒã§ãã ãã®æ¬åŒ§å ã«ã¯ã2ã€ã®æŒç®å==ãš||ããããŸãã ç¹°ãè¿ããŸãããåªå é äœãèŠããšã==æŒç®åãåžžã«æåã«åŠçããå¿ èŠããããŸãã ãããã£ãŠãåŒã¯å·Šããå³ã«åŠçãããŸãã
ããã§ãåŸæ¥å¡ã®å°äœãæ åœããUser .Titleã¯ããŠãŒã¶ãŒã®æ¿èªã®ã¿ã€ãã§ãã ããã¯ãããã£ãã³ã·ã§ãã®äœçœ®ããŠãŒã¶ãŒã®äœçœ®ã§ãããã©ããã確èªããããšãæå³ããŸãã ãŠãŒã¶ãŒãããŒã±ãã£ã³ã°æ åœè ã§ãããšããŸããã€ãŸããæåã®åŒã§ã¯ãå€ã¯FALSEãã€ãŸãfalseã«ãªããŸãã ãã ãã2ã€ã®åŒã®éã«ã¯||æŒç®åããããè«çãORããæå³ããŸãã ããã¯ã2çªç®ã®åŒãçã®å Žåã巊端ã®æ¡ä»¶åŒããã§ãã¯ãããããšãæå³ããŸãã
ãã®å ŽåããŠãŒã¶ãŒã¯ããŒã±ãã£ã³ã°æ åœè ã§ãããããæ¬åŒ§å ã®2çªç®ã®æ¡ä»¶åŒã¯å€TRUEãåããŸããããã¯ãæ¡ä»¶ãããã«ç¢ºèªã§ããããšãæå³ããŸãã ãã®æ®µéã§ã¯ã次ã®åŒããããŸãã
@ User.Department ==âããŒã±ãã£ã³ã°â &&ïŒFALSE || TRUEïŒ
ããã¯ãåŒãããã«æ¬¡ã®ããã«çž®å°ã§ããããšãæå³ããŸãã
@ User.Department ==âããŒã±ãã£ã³ã°â && TRUE
ãã®åŸã巊端ã®æ¡ä»¶åŒããã§ãã¯ãããŸãã ããã§ã¯ããã¹ãŠãæ確ã ãšæããŸãã ãŠãŒã¶ãŒã®éšçœ²ããããŒã±ãã£ã³ã°ããã©ããã確èªããŸãã ãŠãŒã¶ãŒã¯ããŒã±ãã£ã³ã°æ åœè ã§ããããã圌ã®éšéãããŒã±ãã£ã³ã°éšéã§ãããšä»®å®ããŸããããã¯ãè¡šçŸãæ£ããããšãæå³ããŸãã 次ã®ãã®ãåŸãããŸãã
TRUE && TRUE
&&æŒç®åã¯è«çANDã§ãããããããã¯äž¡æ¹ã®æ¡ä»¶ãçã§ãªããã°ãªããªãããšãæå³ããŸãã ç§ãã¡ã®å Žåãããã§ãã ãããã£ãŠãæ¡ä»¶ã¯çã§ãããã¢ã¯ã»ã¹ãèš±å¯ãããŸãã ããã§FALSEã衚瀺ãããå Žåã&&æŒç®åã䜿çšãããšåªå ãããæçµçã«FALSEã®çµæãåŸãããŸãã
ã€ãŸãã次ã®å³ã«ç€ºãåŒãåŸãããŸãã
å³ 1.ãã©ã«ããŒã®èš±å¯ããã¯ã¹å ã®æ¡ä»¶åŒã®äŸ
äžå¯§ãªèªè ãžã®è³ªåïŒæ¬¡ã®æ¡ä»¶åŒãšã¯äœã§ããïŒãŸããäžã§èª¬æããåããŠãŒã¶ãŒãæ±ã£ãŠããå Žåã®ãã§ãã¯ã®å®è¡æ¹æ³ïŒ
ïŒ@ User.Title ==â Accountantâ || @ User.Title ==â FinancierâïŒ|| @ User.DepartmentïŒ=ãã«ã¹ã¿ããŒãµããŒãã
ãŸããã¹ããŒãã¡ã³ãèªäœã®ãªããžã§ã¯ãã¯äœã§ããïŒ
ãåç¥ã®ããã«ãActive Directoryã¹ããŒãã§ã¯ãActive Directoryãã¡ã€ã³ãµãŒãã¹ã§äœ¿çšã§ãããã¹ãŠã®ãªããžã§ã¯ãã®èª¬æãèŠã€ããããšãã§ããŸãã ãããŠãåçã¢ã¯ã»ã¹å¶åŸ¡æè¡ã®ãªããžã§ã¯ãã¯æ±ºããŠäŸå€ã§ã¯ãããŸããã ãããŸã§ã®ãšãããçŸåšã®ãã¯ãããžãŒãšäœããã®é¢ä¿ããããã¹ãŠã®ãªããžã§ã¯ãã説æããçç±ã¯ãããŸãããããã®ãããªãªããžã§ã¯ãã¯9åãããŸãïŒãã¡ãããã»ãŒ3åã®å±æ§ããããŸãïŒãããã®æ®µéã§èæ ®ãããã¹ããŒãã¡ã³ãã®å Žåãã€ãŸãã次ã®2ã€ã®ãªããžã§ã¯ãã®ã¿ãåºå¥ã§ããŸãã
- msDS-ClaimTypePropertyBase ã ãã®Active Directoryã¯ã©ã¹ã¯ã msDS-ClaimTypeã¯ã©ã¹ãªããžã§ã¯ãã®å ±éå±æ§ãšmsDS-ResourcePropertyã®äºåå®çŸ©ã«ãã䜿çšãããæœè±¡ã¯ã©ã¹ãªããžã§ã¯ãã§ããã次ã®èšäºã§åŠç¿ããŸãã ãã®ãªããžã§ã¯ãã«é¢é£ä»ãããã3ã€ã®å±æ§ããããŸãã æå¹ ïŒèª¬æãªãã§ãã¹ãŠãã¯ãªã¢ïŒã msDS-ClaimPossibleValues ïŒãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ã§æåŸ ãããå€ãå®çŸ©ããæååUnicodeå€ãéåžžããã®å€ã¯XMLãã¡ã€ã«ã«æ ŒçŽãããŸãïŒããã³msDS-ClaimsSharesPossibleValuesWith ïŒ msDS-ClaimTypeãªããžã§ã¯ãã®èå¥åãåãå ¥ããmsDS-ResourcePropertyãªããžã§ã¯ãã®msDS-ClaimPossibleValuesã®å€ã決å®ããå±æ§ãšããŠäœ¿çšãããŸãã
- msDS-ClaimType ã ãã ãããã®Active Directoryã¯ã©ã¹ã¯ãçµç¹ã®ã»ãã¥ãªãã£ããªã³ã·ãã«ã䜿çšããã¹ããŒãã¡ã³ããè¡šãããã«äœ¿çšããããªããžã§ã¯ãã®æ§é ã¯ã©ã¹ãšããŠæ©èœããŸãã ãã®ãªããžã§ã¯ãã«ã¯ã msDS-ClaimAttributeSource ïŒæ¿èªãœãŒã¹ãšããŠäœ¿çšãããå±æ§å®çŸ©ã¹ããŒã ã®èå¥åãå«ãïŒã msDS-ClaimIsSingleValued ïŒã¹ããŒãã¡ã³ãã«å«ãŸãããã©ããã決å®ããããŒã«å€ãè¡šãïŒãå«ãå€æ°ã®å±æ§ãæ¢ã«å«ãŸããŠããŸãããŸãã¯ãã¹ããŒãã¡ã³ãã¿ã€ãã¯1ã€ã®å€ã®ã¿ïŒã msDS-ClaimIsValueSpaceRestricted ïŒåã³ãçŸåšã®ã¯ã©ã¹ãªããžã§ã¯ããmsDS-ClaimPossibleValueså±æ§ã§å®çŸ©ãããå€ãšç°ãªãå€ãåãå ¥ããããšãã§ãããã©ããã決å®ããããŒã«å€ãå«ãïŒã msDS-Cla imSource ïŒãã®ãããªå±æ§ã¯ã msDS-ClaimTypeãªããžã§ã¯ãã®éå±æ§ãœãŒã¹ãããšãã°èšŒææžãªã©ã«è²¬ä»»ããããŸãïŒã msDS-ClaimSourceType ïŒæ¿èªã¿ã€ãã®ãœãŒã¹ã«è²¬ä»»ãããå±æ§ïŒã msDS-ClaimTypeAppliesToClass ïŒã¯ã©ã¹ã¹ããŒã ãå®çŸ©ããå±æ§ïŒã¹ããŒãã¡ã³ãã®çºè¡å ã®ã»ãã¥ãªãã£ããªã³ã·ãã«ãªããžã§ã¯ãïŒã msDS-ClaimValueType ïŒäžæã®å€ãé·æŽæ°ãšããŠãã€ã³ãããå±æ§ïŒã
次ã®å³ã«ã msDS-ClaimTypeã¯ã©ã¹ãªããžã§ã¯ãã瀺ããŸãã
å³ 2.ã¯ã©ã¹msDS-ClaimTypeã®ãªããžã§ã¯ã
ã¯ã¬ãŒã 管ç
Microsoftã®ææ°ã®ãµãŒããŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯ãéçºè ãActive Directory管çã»ã³ã¿ãŒãWindows PowerShellã³ãã³ãã·ã§ã«ãªã©ã®ããŒã«ã«ç¹å¥ãªæ³šæãåããããšãããããæåãŸãã¯2çªç®ã®ããããã䜿çšããŠã¯ã¬ãŒã ã¿ã€ãã管çã§ããŸããæå³ããŸãã 1ã€ã®ããŒã«ã®ã¿ãæ€èšããã®ã¯äžå ¬å¹³ã§ããããã次ã®ã»ã¯ã·ã§ã³ã§ã¯ããããã®ç®¡çããŒã«ã®äž¡æ¹ã䜿çšããŠã¯ã¬ãŒã ãåŠçããæ¹æ³ã瀺ããŸãã ãããŠãåœç¶ãç§ãã¡ã¯
Active DirectoryãµãŒããŒã®å šäœç®¡çã®ã¯ã¬ãŒã 管ç
ååãšããŠãçŽç²ã«çè«çãªéšåã¯é·ãéåŒãåºãããŠããã®ã§ãäžå¿ èŠãªåå¥æ²ãªãã«ããããããã®ç¹ã«ç§»ããŸãã ãã®ãããActive DirectoryãµãŒããŒã®å šäœç®¡çã䜿çšããŠããã®åŸã®éäžã¢ã¯ã»ã¹ããªã·ãŒã«äœ¿çšãããã¢ãµãŒã·ã§ã³ãäœæããã«ã¯ã次ã®æé ãå®è¡ããå¿ èŠããããŸãã
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒã§ãã Active Directory管çã»ã³ã¿ãŒ ããŠã£ã³ããŠãéããŸãããªã¹ããšãªã¢ã§ã ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ ãããŒããéžæããã ã¯ã¬ãŒã ã¿ã€ã ãããŒããéžæããŸãïŒ ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ > ã¯ã¬ãŒã ã¿ã€ã ïŒã
- 衚瀺ãããããŒãã§ã詳现ãã€ã³ãå³ã¯ãªãã¯ãã次ã®å³ã«ç€ºãããã«ãã³ã³ããã¹ãã¡ãã¥ãŒãã[ æ°èŠããã³ã¯ã¬ãŒã ã®çš®é¡ ]ãéžæãããã[Active DirectoryãµãŒããŒã®å
šäœç®¡ç]ããŒãžã®åçãã£ã¬ã¯ããªã«ç§»åããŸããã¢ã¯ã»ã¹å¶åŸ¡ããã³Active Directoryã¢ã¯ã·ã§ã³ã°ã«ãŒãã§ãã¯ã¬ãŒã ã¿ã€ãã®äœæãšåŒã°ããæåã®ã¢ã¯ã·ã§ã³ãéžæããŸãã æåãš2çªç®ã®äž¡æ¹ã®ã±ãŒã¹ã§ãæ°ããã¿ã€ãã®ã¹ããŒãã¡ã³ããäœæããããã®ãã€ã¢ãã°ããã¯ã¹ãéããŸãã
å³ 3.æ°ããã¯ã¬ãŒã ã¿ã€ããäœæããããã®ãã€ã¢ãã°ããã¯ã¹ãéã - [ æ¿èªã¿ã€ãã®äœæ ]ãã€ã¢ãã°ããã¯ã¹ã衚瀺ãããããã¯ã¬ãŒã ã¿ã€ãã®äœæã«åºã¥ããŠã[ ãœãŒã¹å±æ§ ]ã»ã¯ã·ã§ã³ã§ãœãŒã¹å±æ§ãšè¿œå ã®æ§æèŠçŽ ã決å®ã§ããŸãã 次ã®å³ãããããããã«ãçŸåšã®ãã€ã¢ãã°ããã¯ã¹ãéããšããã«ç®ãåŒãã®ã¯ãå€ãã®ããŸããŸãªå±æ§ãå«ãã ãœãŒã¹å±æ§ ãã®å€§ããªãªã¹ãã§ãããããäœæããããœãŒã¹å±æ§ãéžæã§ããŸãæ¿èªã ãã®ãããªãªã¹ãã¯ã Userã¯ã©ã¹ã Computerã¯ã©ã¹ã inetOrgPersonã¯ã©ã¹ã ManagerServiceAccountã°ã«ãŒã ã GroupManagerServiceAccountã¯ã©ã¹ãããã³ãªããžã§ã¯ãã®è£å©ã¯ã©ã¹ãå«ãããªããžã§ã¯ãã®å€ãã®ã¯ã©ã¹ãã圢æãããŸãã å±æ§ãéžæããéã¯ãUnicodeãããŒã«å€ã倧ããªæŽæ°ãå«ãæŽæ°ãOIDããã³SIDæååãªã©ã®æååå€ãæã€å±æ§ã®ã¿ãçŸåšã®ãªã¹ãã«è¡šç€ºãããããšã«æ³šæããŠãã ããã ãŸãããã¡ãããã¬ããªã±ãŒããããªãå±æ§ããããã¯ãããå±æ§ãããã³èªã¿åãå°çšãã¡ã€ã³ã³ã³ãããŒã©ãŒïŒã€ãŸãRODCïŒã§å©çšã§ããªãå±æ§ã¯ããã®ãªã¹ãã«è¡šç€ºãããŸããã ããšãã°ããã®å Žåã éšéå±æ§ãéžæãããŸãããå±æ§ãéžæããåã«ãåŸç¶ã®éäžåã¢ã¯ã»ã¹ããªã·ãŒã®ããã«ã¯ã¬ãŒã ã®æ§é ãææå°æ©ã«èšç»ããããšã«æ³šæããŠãã ããã
å³ 4.äœæãããã¯ã¬ãŒã ã¿ã€ãã®ã»ã¯ã·ã§ã³ããœãŒã¹å±æ§ã - ããã«ãã¢ãµãŒã·ã§ã³ã¿ã€ããäœæããããã®ãã€ã¢ãã°ããã¯ã¹ã®ãã®ã»ã¯ã·ã§ã³ã«ã¯ãä»ã®ãã©ã¡ãŒã¿ãŒããããŸãã
- 衚瀺å ã ããã¯ãäœæããã¯ã¬ãŒã ã®çš®é¡ã«å²ãåœãŠãããäžæã®è¡šç€ºåãå«ãããã¹ãããã¯ã¹ã§ãã ãã®ãããªååã¯åŸç¶ã®æäœã§è¡šç€ºããããããå°æ¥ãã®ãããªååãšããŠèªã¿ãããç解ããããååã䜿çšããã®ãæé©ã§ãã åœç¶ãäœæãããæ¿èªã¿ã€ãã®ååã«ã¯ãè±æ°åãšè±æ°åã®å€ã䜿çšã§ããŸãã
- 説æ äœæããŠããã¯ã¬ãŒã ã®ã¿ã€ãã«é¢ããã³ã¡ã³ãçšã®ãã£ãŒã«ããè¡šããŸãã ãã®ãã£ãŒã«ãã®æåæ°ã¯1024æåã«å¶éãããŠããŸãã ãããã£ãŠãã³ã¡ã³ããè¿œå ããäœæãããã¿ã€ãã®ã¹ããŒãã¡ã³ãã䜿çšããç®çãããå Žåã¯ãç°¡æœã«ããå¿ èŠããããŸãã
- ãã®ã¿ã€ãã®ã¯ã¬ãŒã ã¯ã次ã®ã¯ã©ã¹ã«å¯ŸããŠçºè¡ã§ããŸã ã ã¯ã¬ãŒã ãç¹å®ã®çš®é¡ã®ã»ãã¥ãªãã£ããªã³ã·ãã«ïŒããšãã°ããŠãŒã¶ãŒã®ã¿ãŸãã¯ã³ã³ãã¥ãŒã¿ãŒã®ã¿ïŒã«ã®ã¿é©çšããããäž¡æ¹ã®ãã§ãã¯ããã¯ã¹ãéžæããããšã«ãããäž¡æ¹ã®çš®é¡ã®ã¢ã«ãŠã³ãã«å¯ŸããŠçŸåšã®çš®é¡ã®ã¯ã¬ãŒã ã®äœ¿çšãæå¹ã«ããããéžæã§ããå¶åŸ¡èŠçŽ ã
- ä¿¡é Œã«é¢é£ä»ãããããã©ã¬ã¹ãã§ã®ã¯ã¬ãŒã ã®äœ¿çšãç°¡çŽ åããããã«ãä¿¡é Œããããã©ã¬ã¹ãã§èå¥åãæå³çã«åäžã®ã¯ã¬ãŒã ã«å²ãåœãŠãŸã ïŒ ä¿¡é Œããããã©ã¬ã¹ãã§æå³çã«åäžã®ã¯ã¬ãŒã ã¿ã€ãã«IDãèšå®ããŸã ïŒã ããã¯ãæ¿èªã¿ã€ãèå¥åã®äœææ¹æ³ã決å®ããããã«èšèšããããã©ã°ã§ãã ãã®ãã©ã°ãèšå®ãããŠããªãå ŽåãActive DirectoryãµãŒããŒã®å
šäœç®¡çã¯ãã®ãããªèå¥åãèªåçã«å²ãåœãŠãŸãã 圌ã¯ã©ã®ããã«èŠããŸããïŒ ãã®èå¥åã¯å°æåã®adã§å§ãŸãããã®åŸã«ã³ãã³ã2ã€ã®ã¹ã©ãã·ã¥ã extãããã³ãã1ã€ã®ã¹ã©ãã·ã¥ïŒ adïŒ// ext / ïŒãç¶ããŸã ã ããã¯ãèå¥åã®æšæºçãªå§ãŸãã§ãã ãã®åŸããµãŒããŒã®å
šäœç®¡çã«ãã£ãŠéžæããå±æ§ã®ååãè¿œå ãããã³ãã³ã®åŸã«16é²åœ¢åŒã®å€ãã©ã³ãã ã«è¿œå ãããŸããããã¯éåžžã®GUIDã§ããçšåºŠæãåºãããšãã§ããŸãã ã€ãŸããæçµçã«ããã®äŸã®èå¥åã¯æ¬¡ã®ããã«ãªããŸãã
adïŒ// ext / departmentïŒ88d0094e632018a6
次ã«ãä¿¡é Œã«é¢é£ä»ãããããã©ã¬ã¹ãã®ã¯ã¬ãŒã ã®çš®é¡ãäœæãããšãåã¯ã¬ãŒã ã®çš®é¡ã®ã¡ã¿ããŒã¿ã¯æ¢å®ã§ãã©ã¬ã¹ãããšã«äžæã«ãªãããã®çµæãä¿¡é Œãããã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ä¿¡é Œããããã©ã¬ã¹ãããã®ã¯ã¬ãŒã ãåŠçã§ããªããªããŸãã ãã®ãããäœæãããã¯ã¬ãŒã ã®çš®é¡ã®èå¥åããä¿¡é Œããããã©ã¬ã¹ããšä¿¡é Œããããã©ã¬ã¹ãã®éã§æå³çã«åäžã§ããããšã確èªããå¿ èŠããããŸãã ãããã£ãŠããã®ãã©ã°ã¯äžèšã®å Žåã«ã®ã¿èšå®ããå¿ èŠããããŸãã ãã¡ãããèå¥åãæåã§æå®ããå Žåã¯ãå°ãåã«èšåããããŒãã³ã°ã³ã³ããã¹ãã«æºæ ããå¿ èŠããããŸãã ext /ã32æå以äžã§ããããšã瀺ãå¿ èŠããããç¹æ®æåãå«ãŸããã¹ã©ãã·ã¥ã§çµããå¿ èŠãããå Žåãåèå¥åã®éå§æ¹æ³ãå¿ããªãã§ãã ããã ãããã¯åææ¡ä»¶ã§ãã ãã¡ããããã®ãããªèå¥åã¯äžæã§ãªããã°ãªããªãããšãå¿ããªãã§ãã ããã - 誀ã£ãåé€ã«å¯Ÿããä¿è· ïŒ èª€ã£ãåé€ ããä¿è·ãã ïŒã Active Directoryã§æ¢ã«ç¥ãããŠããæäœã®å Žåã®ããã«ãäœæãããã¯ã¬ãŒã ã¿ã€ãã誀ã£ãŠåé€ãããªãããã«ãããã©ã°ã æ¢å®ã§ã¯ã管çè ã®ã¿ãæ¢å®ã§ã¯ã¬ãŒã ã®çš®é¡ãäœæãå€æŽãããã³åé€ã§ãããšããäºå®ã«ãããããããå Žåã«ãã£ãŠã¯ããã®ãªãã·ã§ã³ã圹ç«ã€ããšããããŸãã
- æšå¥šå€ãšåŒã°ããã»ã¯ã·ã§ã³ã¯ãæ¡ä»¶åŒã§ã¹ããŒãã¡ã³ãã¿ã€ãã䜿çšãããšãã«éžæã§ããéžæå¯èœãªå€ãäºåå®çŸ©ããŸãã 次ã®å³ã§ãããããã«ãããã§ã¯æ¬¡ã®å€ã®éžæã§åæ¢ã§ããŸãã
å³ 5.äœæãããã¯ã¬ãŒã ã¿ã€ãã®[æšå¥šå€]ã»ã¯ã·ã§ã³
- å€ã¯ææ¡ãããŸãã ã ä»»æã®çš®é¡ã®ã¯ã¬ãŒã ãäœæãããšãã«ããã©ã«ãã§èšå®ããããã©ã¡ãŒã¿ãŒã ã¹ããŒãã¡ã³ãã®ã¿ã€ãã®å€ããªãŒããŒã©ã€ãããªãããšãåæãšãããã®ãããªå€ã¯ãæ¡ä»¶åŒèªäœãäœæãããšãã«æåã§å ¥åãããŸãã
- 次ã®å€ãææ¡ãããŸãã ãã®å Žåãæ¡ä»¶åŒã®åŸç¶ã®äœæäžã«å¯Ÿå¿ãããªã¹ãããéžæã§ãã1ã€ãŸãã¯è€æ°ã®å€ãäœæã§ããŸãã ãããã£ãŠããã®ãããªå€ãæäœããã«ã¯ãäœæãããã¯ã¬ãŒã ã¿ã€ãã®ããããã£ã®ãã€ã¢ãã°ããã¯ã¹ã®çŸåšã®ã»ã¯ã·ã§ã³ã«ãã[ è¿œå ]ã[ å€æŽ ] ãããã³[åé€]ãã¿ã³ã䜿çšã§ããŸãã ãããã®å€ã¯ã©ã®ãããæ£ç¢ºã«äœæãããŸããïŒ
[ è¿œå ]ãã¿ã³ãã¯ãªãã¯ãããšã[ æšå¥šå€ã®è¿œå ]ãã€ã¢ãã°ããã¯ã¹ã衚瀺ãããŸãããã®ãã€ã¢ãã°ããã¯ã¹ã«ã¯ã3ã€ã®ããã¹ããã£ãŒã«ãããããŸãã [ å€ ]ã¯ãæ¡ä»¶åŒã®å¯Ÿå¿ããããã¹ããã£ãŒã«ãã®æšå¥šå€ãçŸåšã®å€ãæ åœãããã®ãããªå€ãéžæãããšãã«è¡šç€ºãããååãšããã®ãããªå€ã®ä»»æã®èª¬æãæ åœããDescription ã
:
å³ 6.
- . ã§ãã
, , : . , . , « » ( Disable ).
Windows PowerShell
PowerShell , , . , Microsoft , , .
, , , Active Directory Windows PowerShell. PowerShell, , , , . , , , Active Directory.
, ( ), , . :
, New-ADClaimType . 21 , . , . :
New-ADClaimType âAppliesToClasses:@('user') âDescription:â divisionâ -DisplayName:âdivisionâ âIssingkeValued:$true âServer:âDC.biopharmaceutic.localâ âProtectedFromAccedentialDeletion:$true âSourceAttribute:âCN=Division,CN=Schema,CN=Configuration,DC=biopharmaceutic,DC=localâ
. , âAppliesToClasses : @, . , . , . , âID , , -ID:ad://ext/division:88d00962e3d07cd1 .
, . , ããŒã±ãã£ã³ã°æ åœè ãäŒèšå£«ãæè³å®¶ïŒ
New-ADClaimType -AppliesToClasses:@('user') -Description:" " -DisplayName:"title" -IsSingleValued:$true -Server:"DC.biopharmaceutic.local" -ProtectedFromAccidentalDeletion:$true -SourceAttribute:"CN=Title,CN=Schema,CN=Configuration,DC=biopharmaceutic,DC=local" -SuggestedValues:@((New-Object Microsoft.ActiveDirectory.Management.ADSuggestedValueEntry("", "", " ")), (New-Object Microsoft.ActiveDirectory.Management.ADSuggestedValueEntry("", "", " ")), (New-Object Microsoft.ActiveDirectory.Management.ADSuggestedValueEntry("", "", " ")))
, . , . âSuggestedValues , , . , . , @ , New-Object , Microsoft Active Directory Management ADSuggestedValueEntry , . . - .
, . , , . Set-ADClaimType , , - Enabled . , :
Set-ADClaimType -Identity "CN=ad://ext/division:88d00968ab6e025f,CN=Claim Types,CN=Claims Configuration,CN=Services,CN=Configuration,DC=biopharmaceutic,DC=local" -Enabled:$false
, â Identity distinguishedName . , , .
Windows PowerShell :
å³ 7. ,
, , Active Directory , . :
å³ 8. Active Directory
?
, . , , , , , « Active Directory » Windows PowerShell.
, , , , . , .