Security Assertion Markup Language (SAML) ã¯ãåœäºè éãç¹ã«ãµãŒãã¹ ãããã€ããŒãš ID ãããã€ããŒéã§ãŠãŒã¶ãŒèªèšŒããã³èªå¯ããŒã¿ã亀æããããã® XML ããŒã¹ã®æšæºã§ãããã®ãã¬ãŒã ã¯ãŒã¯ã¯ãææ°ã®ãŠãŒã¶ãŒèªèšŒãšã³ã·ã¹ãã ã«ãããŠæ¥µããŠéèŠãªæ©èœã§ããã·ã³ã°ã« ãµã€ã³ãªã³ (SSO) ãæå¹ã«ããäžã§éèŠãªåœ¹å²ãæããããŠãŒã¶ãŒã¯åäžã®è³æ Œæ å ±ã»ããã䜿çšããŠè€æ°ã®ç¬ç«ããã¢ããªã±ãŒã·ã§ã³ãã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã SAML ã¯ãæ§é åæ å ±æšæºæšé²æ©æ§ (OASIS) ã®ã»ãã¥ãªã㣠ãµãŒãã¹æè¡å§å¡äŒã«ãã£ãŠéçºããããã®çžäºéçšæ§ãšãã©ãããã©ãŒã ã«äŸåããªãæ§è³ªã®ãããã§ãæ¥çã®äž»èŠãªãã¯ãããž ãã³ããŒããµãŒãã¹ ãããã€ããŒã®éã§åºãæ¡çšããã䜿çšãããŠããŸããã
AppMasterno-codeãã©ãããã©ãŒã ã®ã³ã³ããã¹ãã§ã¯ãSAML ã¯ããŠãŒã¶ãŒããã©ãããã©ãŒã ã«ãã£ãŠçæããã Webãã¢ãã€ã«ãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ãšå¯Ÿè©±ãããšãã«ãŠãŒã¶ãŒãèªèšŒããã³æ¿èªããããã®å®å šãªã¢ãããŒããæäŸããŸãã AppMasterã¢ããªã±ãŒã·ã§ã³ã« SAML ãå®è£ ãããšããšã³ããŠãŒã¶ãŒãšéçºè ã®äž¡æ¹ã«åŒ·åãããã»ãã¥ãªãã£ãå©äŸ¿æ§ãæéç¯çŽã®ã¡ãªãããããããããŸãã
SAML ã®ã³ã¢ã³ã³ããŒãã³ããçè§£ãããšããŠãŒã¶ãŒèªèšŒã«ããã SAML ã®éèŠæ§ãããæ·±ãçè§£ããããšãã§ããŸãã SAML ã® 3 ã€ã®éèŠãªåŽé¢ãç¹å®ã§ããŸãã
- ã¢ãµãŒã·ã§ã³: ã¢ãµãŒã·ã§ã³ã¯ SAML ã®äžæ žã§ããããŠãŒã¶ãŒæ å ±ã衚ãå®éã®èªèšŒã屿§ãèªå¯ããŒã¿ãå«ãŸããŸããèªèšŒã¢ãµãŒã·ã§ã³ã¯ãŠãŒã¶ãŒããã€ã©ã®ããã«èªèšŒããããã瀺ãã屿§ã¢ãµãŒã·ã§ã³ã¯ååãé»åã¡ãŒã«ãããŒã«ãªã©ã®ãŠãŒã¶ãŒå±æ§ãèšè¿°ããèªå¯ã¢ãµãŒã·ã§ã³ã¯ãŠãŒã¶ãŒãç¹å®ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããæš©éãæã£ãŠãããã©ããã確èªããŸãã
- ãããã³ã«: SAML ãããã³ã«ã¯ãã¢ãµãŒã·ã§ã³ãèŠæ±ããã³åä¿¡ããããã®ã«ãŒã«ãå®çŸ©ããŸããæãäžè¬çãªãããã³ã«ã¯ SAML èªèšŒèŠæ±ãããã³ã« (SAML-P) ã§ãã¢ãµãŒã·ã§ã³ãååŸããããã®ãµãŒãã¹ ãããã€ããŒãš ID ãããã€ããŒã®éã®èŠæ±ããã³å¿çã¡ãã»ãŒãžãå®çŸ©ããŸãããã 1 ã€ã®äŸã¯ãSAML ã¢ãŒãã£ãã¡ã¯ã解決ãããã³ã«ã§ããããã¯ãSAML ã¢ãŒãã£ãã¡ã¯ããåä¿¡ããåŸãã¢ã€ãã³ãã£ã㣠ãããã€ããŒããå®éã® SAML ã¢ãµãŒã·ã§ã³ãèŠæ±ããããã«äœ¿çšãããŸãã
- ãã€ã³ãã£ã³ã°: ãã€ã³ãã£ã³ã°ã¯ãSSO ããã»ã¹ã«é¢äžããåœäºè (ãµãŒãã¹ ãããã€ããŒãšã¢ã€ãã³ãã£ã㣠ãããã€ããŒ) éã§ SAML ã¡ãã»ãŒãžãéä¿¡ããããã«äœ¿çšããããã©ã³ã¹ããŒã ã¡ã«ããºã ã§ããäžè¬ç㪠SAML ãã€ã³ãã£ã³ã°ã®äŸãšããŠã¯ãHTTP ãªãã€ã¬ã¯ããHTTP POSTãSOAP ãªã©ããããŸãã
SAML ããŒã¹ã® SSO ããã»ã¹ã説æããããã«ããŠãŒã¶ãŒã SSO ã§ä¿è·ããã Web ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããããšããŠããå ŽåãèããŠã¿ãŸããããã¢ããªã±ãŒã·ã§ã³ã® URL ã«ç§»åãããšããŠãŒã¶ãŒã¯èªèšŒã®åŠçãæ åœãã ID ãããã€ããŒã«ãªãã€ã¬ã¯ããããŸããæ¬¡ã«ãID ãããã€ããŒã¯ãè³æ Œæ å ± (ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããªã©) ãèŠæ±ããããšã«ãã£ãŠãŠãŒã¶ãŒã® ID ã確èªããŸããèªèšŒãæåãããšãã¢ã€ãã³ãã£ã㣠ãããã€ããŒã¯ã¢ãµãŒã·ã§ã³ãå«ã SAML å¿çããµãŒãã¹ ãããã€ããŒã«éä¿¡ããŸãããµãŒãã¹ ãããã€ããŒã¯ã¢ãµãŒã·ã§ã³ãæ€èšŒãããŠãŒã¶ãŒæ å ±ãæœåºãããã®æ å ±ã«åºã¥ããŠã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãŸãã¯æåŠããŸãããã®ããã»ã¹å šäœãéããŠãSAML ã䜿çšããããšã§ããŠãŒã¶ãŒã®è³æ Œæ å ±ãå®å šã«ä¿ããããµãŒãã¹ ãããã€ããŒã®ãã¡ã€ã³ããåé¢ãããããšãä¿èšŒãããŸãã
SAML ããŒã¹ã® SSO ãå®è£ ãããšã AppMasterã¢ããªã±ãŒã·ã§ã³ã«ããã€ãã®å©ç¹ãããããããŸãã
- ã»ãã¥ãªãã£ã®åäž: ãŠãŒã¶ãŒã®è³æ Œæ å ±ã¯ã¢ã€ãã³ãã£ã㣠ãããã€ããŒã«ãã£ãŠã®ã¿åŠçãããããããµãŒãã¹ ãããã€ããŒã®ç°å¢å ã§ã®äžæ£ã¢ã¯ã»ã¹ãè³æ Œæ å ±ã®çé£ã®ãªã¹ã¯ãå€§å¹ ã«æžå°ããŸãã
- ãŠãŒã¶ãŒã®è² æ ã®è»œæž: SSO ã¯ããŠãŒã¶ãŒãåäžã®è³æ Œæ å ±ã»ããã§è€æ°ã®ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ããããšã§ãèªèšŒããã»ã¹ãç°¡çŽ åããè€æ°ã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããèšæ¶ããå¿ èŠæ§ãæžãããããåçåããããŠãŒã¶ãŒ ãã¬ã³ããªãŒãªãšã¯ã¹ããªãšã³ã¹ãå®çŸããŸãã
- æšæºå: SAML ã®çžäºéçšæ§ãšãã©ãããã©ãŒã ã®ç¬ç«æ§ã¯ãåºç€ãšãªããã¯ãããžãŒ ã¹ã¿ãã¯ã«é¢ä¿ãªããã¢ããªã±ãŒã·ã§ã³ãšã·ã¹ãã å šäœã§äžè²«ããèªèšŒããã³èªå¯ã¡ã«ããºã ã確ç«ããã®ã«åœ¹ç«ã¡ãŸãã
- ãŠãŒã¶ãŒç®¡çã®ç°¡çŽ å: SAML ã䜿çšã㊠SSO ãå®è£ ãããšããŠãŒã¶ãŒç®¡çãéäžåããããŠãŒã¶ãŒ ã¢ã«ãŠã³ãã®äœæãæŽæ°ãåé€ãããã³ã¢ããªã±ãŒã·ã§ã³å šäœã«ããããŠãŒã¶ãŒã®æš©éãšã¢ã¯ã»ã¹æš©ã®ç®¡çãããå¹ççã«ãªããŸãã
çµè«ãšããŠãSecurity Assertion Markup Language (SAML) ã¯ããµãŒãã¹ ãããã€ããŒãš ID ãããã€ããŒã®éã§ãŠãŒã¶ãŒèªèšŒããã³èªå¯ããŒã¿ã亀æããããã«äžå¯æ¬ 㪠XML ããŒã¹ã®ãã¬ãŒã ã¯ãŒã¯ã§ãã AppMasterã®ã³ã³ããã¹ãã§ã¯ããã©ãããã©ãŒã ã® Webãã¢ãã€ã«ãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ã« SAML ããŒã¹ã®èªèšŒãçµã¿èŸŒãããšã§ãã»ãã¥ãªãã£ã匷åããããŠãŒã¶ãŒç®¡çãç°¡çŽ åããããŠãŒã¶ãŒ ãšã¯ã¹ããªãšã³ã¹ãåäžããŸãã SAML æšæºã¯ãçžäºéçšæ§ã䜿ãããããèªèšŒãåŠçããããã®æšæºåãããã¡ã«ããºã ãä¿é²ãããŠãŒã¶ãŒã®èªèšŒãšèªå¯ã«éç¹ã眮ããææ°ã®ã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠäžå¯æ¬ ãªã³ã³ããŒãã³ããšãªã£ãŠããŸãã