§£ §â§Ñ§Ù§Õ§Ö§Ý§Ö §¡§Õ§Þ§Ú§ß§Ú§ã§ä§â§Ú§â§à§Ó§Ñ§ß§Ú§Ö ¡ú §¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §Þ§à§Ø§ß§à §Ù§Ñ§Õ§Ñ§ä§î §Ô§Ý§à§Ò§Ñ§Ý§î§ß§í§Û §Þ§Ö§ä§à§Õ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §Ó Áú»¢¶Ä²© §Ú §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ §Ü §á§Ñ§â§à§Ý§ð. §¥§à§ã§ä§å§á§ß§í §ã§Ý§Ö§Õ§å§ð§ë§Ú§Ö §Þ§Ö§ä§à§Õ§í §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú: §Ó§ß§å§ä§â§Ö§ß§ß§Ú§Û, HTTP, LDAP §Ú SAML.
§±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð Áú»¢¶Ä²© §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä §Ó§ß§å§ä§â§Ö§ß§ß§ð§ð §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð Áú»¢¶Ä²© §Õ§Ý§ñ §Ó§ã§Ö§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û. §®§à§Ø§ß§à §Ú§Ù§Þ§Ö§ß§Ú§ä§î §Þ§Ö§ä§à§Õ §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §ß§Ñ LDAP §Õ§Ý§ñ §Ó§ã§Ö§Û §ã§Ú§ã§ä§Ö§Þ§í §Ú§Ý§Ú §Ó§Ü§Ý§ð§é§Ú§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð LDAP §ä§à§Ý§î§Ü§à §Õ§Ý§ñ §Ü§à§ß§Ü§â§Ö§ä§ß§í§ç §Ô§â§å§á§á §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û.
§¹§ä§à§Ò§í §å§ã§ä§Ñ§ß§à§Ó§Ú§ä§î LDAP §Ó §Ü§Ñ§é§Ö§ã§ä§Ó§Ö §Þ§Ö§ä§à§Õ§Ñ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §Õ§Ý§ñ §Ó§ã§Ö§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û, §á§Ö§â§Ö§Û§Õ§Ú§ä§Ö §Ü §Ó§Ü§Ý§Ñ§Õ§Ü§Ö LDAP §Ú §ß§Ñ§ã§ä§â§à§Û§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú, §Ù§Ñ§ä§Ö§Þ §Ó§Ö§â§ß§Ú§ä§Ö§ã§î §ß§Ñ §Ó§Ü§Ý§Ñ§Õ§Ü§å §¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §Ú §å§ã§ä§Ñ§ß§à§Ó§Ú§ä§Ö §á§Ö§â§Ö§Ü§Ý§ð§é§Ñ§ä§Ö§Ý§î §¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §Ó §á§à§Ý§à§Ø§Ö§ß§Ú§Ö LDAP.
§°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §Þ§Ö§ä§à§Õ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §Þ§à§Ø§ß§à §ä§à§é§ß§à §ß§Ñ§ã§ä§â§à§Ú§ä§î §ß§Ñ §å§â§à§Ó§ß§Ö §Ô§â§å§á§á §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û. §¥§Ñ§Ø§Ö §Ö§ã§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§î§ß§à §ß§Ñ§ã§ä§â§à§Ö§ß§Ñ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ LDAP, §ß§Ö§Ü§à§ä§à§â§í§Ö §Ô§â§å§á§á§í §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §á§à-§á§â§Ö§Ø§ß§Ö§Þ§å §Þ§à§Ô§å§ä §á§â§à§ç§à§Õ§Ú§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð §ã§â§Ö§Õ§ã§ä§Ó§Ñ§Þ§Ú Áú»¢¶Ä²©. §µ §ï§ä§Ú§ç §Ô§â§å§á§á §Õ§à§ã§ä§å§á §Ü §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§å §Õ§à§Ý§Ø§Ö§ß §Ò§í§ä§î §Ó§í§ã§ä§Ñ§Ó§Ý§Ö§ß §Ü§Ñ§Ü §£§ß§å§ä§â§Ö§ß§ß§Ú§Û. §ª §ß§Ñ§à§Ò§à§â§à§ä, §Ö§ã§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§î§ß§à §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä§ã§ñ §Ó§ß§å§ä§â§Ö§ß§ß§ñ§ñ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ, §á§à§Õ§â§à§Ò§ß§à§ã§ä§Ú §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú LDAP §Þ§à§Ø§ß§à §å§Ü§Ñ§Ù§Ñ§ä§î §Ú §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Õ§Ý§ñ §Ü§à§ß§Ü§â§Ö§ä§ß§í§ç §Ô§â§å§á§á §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û, §é§Ö§Û §Õ§à§ã§ä§å§á §Ü §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§å §ß§Ñ§ã§ä§â§à§Ö§ß §Ü§Ñ§Ü LDAP. §¦§ã§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §Ó§ç§à§Õ§Ú§ä §ç§à§ä§ñ §Ò§í §Ó §à§Õ§ß§å §Ô§â§å§á§á§å §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §ã §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ö§Û LDAP, §ä§à §ï§ä§à§ä §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §ß§Ö §ã§Þ§à§Ø§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Þ§Ö§ä§à§Õ §Ó§ß§å§ä§â§Ö§ß§ß§Ö§Û §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú.
§®§Ö§ä§à§Õ§í §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú HTTP §Ú SAML 2.0 §Þ§à§Ô§å§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î§ã§ñ §Ó §Õ§à§á§à§Ý§ß§Ö§ß§Ú§Ö §Ü §Þ§Ö§ä§à§Õ§Ñ§Þ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð.
§£§Ü§Ý§Ñ§Õ§Ü§Ñ §¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §á§à§Ù§Ó§à§Ý§ñ§Ö§ä §à§á§â§Ö§Õ§Ö§Ý§Ú§ä§î §ß§Ñ§ã§ä§â§Ñ§Ú§Ó§Ñ§Ö§Þ§í§Ö §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ §Ü §ã§Ý§à§Ø§ß§à§ã§ä§Ú §á§Ñ§â§à§Ý§ñ §Õ§Ý§ñ §Ó§ß§å§ä§â§Ö§ß§ß§Ú§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û Áú»¢¶Ä²©.
§®§à§Ø§ß§à §ß§Ñ§ã§ä§â§à§Ú§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í §á§à§Ý§Ú§ä§Ú§Ü§Ú §á§Ñ§â§à§Ý§Ö§Û:
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|
§®§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§Ñ§ñ §Õ§Ý§Ú§ß§Ñ §á§Ñ§â§à§Ý§ñ (Minimum password length) |
§±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§Ñ§ñ §Õ§Ý§Ú§ß§Ñ §á§Ñ§â§à§Ý§ñ §å§ã§ä§Ñ§ß§à§Ó§Ý§Ö§ß§Ñ §ß§Ñ 8. §±§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§Ö§Þ§í§Û §Õ§Ú§Ñ§á§Ñ§Ù§à§ß: 1-70. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §á§Ñ§â§à§Ý§Ú §Õ§Ý§Ú§ß§ß§Ö§Ö 72 §ã§Ú§Þ§Ó§à§Ý§à§Ó §Ò§å§Õ§å§ä §å§ã§Ö§é§Ö§ß§í. |
§±§Ñ§â§à§Ý§î §Õ§à§Ý§Ø§Ö§ß §ã§à§Õ§Ö§â§Ø§Ñ§ä§î (Password must contain) |
§°§ä§Þ§Ö§ä§î§ä§Ö §à§Õ§Ú§ß §Ú§Ý§Ú §ß§Ö§ã§Ü§à§Ý§î§Ü§à §æ§Ý§Ñ§Ø§Ü§à§Ó, §é§ä§à§Ò§í §ä§â§Ö§Ò§à§Ó§Ñ§ä§î §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§ñ §Ó §á§Ñ§â§à§Ý§Ö §å§Ü§Ñ§Ù§Ñ§ß§ß§í§ç §ã§Ú§Þ§Ó§à§Ý§à§Ó: - §á§â§à§á§Ú§ã§ß§Ñ§ñ §Ú §ã§ä§â§à§é§ß§Ñ§ñ §Ý§Ñ§ä§Ú§ß§ã§Ü§Ñ§ñ §Ò§å§Ü§Ó§Ñ - §è§Ú§æ§â§Ñ - §ã§á§Ö§è§Ú§Ñ§Ý§î§ß§í§Û §ã§Ú§Þ§Ó§à§Ý §¯§Ñ§Ó§Ö§Õ§Ú§ä§Ö §å§Ü§Ñ§Ù§Ñ§ä§Ö§Ý§î §Þ§í§ê§Ú §ß§Ñ §Ó§à§á§â§à§ã§Ú§ä§Ö§Ý§î§ß§í§Û §Ù§ß§Ñ§Ü, §é§ä§à§Ò§í §å§Ó§Ú§Õ§Ö§ä§î §á§à§Õ§ã§Ü§Ñ§Ù§Ü§å §ã§à §ã§á§Ú§ã§Ü§à§Þ §ã§Ú§Þ§Ó§à§Ý§à§Ó §Õ§Ý§ñ §Ü§Ñ§Ø§Õ§à§Ô§à §Ó§Ñ§â§Ú§Ñ§ß§ä§Ñ. |
§ª§Ù§Ò§Ö§Ô§Ñ§ä§î §Ý§Ö§Ô§Ü§à §å§Ô§Ñ§Õ§í§Ó§Ñ§Ö§Þ§í§ç §á§Ñ§â§à§Ý§Ö§Û (Avoid easy-to-guess passwords) |
§¦§ã§Ý§Ú §à§ä§Þ§Ö§é§Ö§ß§à, §á§Ñ§â§à§Ý§î §Ò§å§Õ§Ö§ä §á§â§à§Ó§Ö§â§ñ§ä§î§ã§ñ §ß§Ñ §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ú§Ö §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ§Þ: - §ß§Ö §Õ§à§Ý§Ø§Ö§ß §ã§à§Õ§Ö§â§Ø§Ñ§ä§î §Ú§Þ§ñ, §æ§Ñ§Þ§Ú§Ý§Ú§ð §Ú§Ý§Ú §Ú§Þ§ñ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ - §ß§Ö §Õ§à§Ý§Ø§Ö§ß §Ò§í§ä§î §à§Õ§ß§Ú§Þ §Ú§Ù §à§Ò§ë§Ö§å§á§à§ä§â§Ö§Ò§Ú§ä§Ö§Ý§î§ß§í§ç §Ú§Ý§Ú §Ü§à§ß§ä§Ö§Ü§ã§ä§ß§à-§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§ç §á§Ñ§â§à§Ý§Ö§Û. §³§á§Ú§ã§à§Ü §à§Ò§ë§Ö§å§á§à§ä§â§Ö§Ò§Ú§ä§Ö§Ý§î§ß§í§ç §Ú §Ü§à§ß§ä§Ö§Ü§ã§ä§ß§à-§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§ç §á§Ñ§â§à§Ý§Ö§Û §Ô§Ö§ß§Ö§â§Ú§â§å§Ö§ä§ã§ñ §Ñ§Ó§ä§à§Þ§Ñ§ä§Ú§é§Ö§ã§Ü§Ú §Ú§Ù §ã§á§Ú§ã§Ü§Ñ NCSC ?100?000 §á§à§á§å§Ý§ñ§â§ß§í§ç §á§Ñ§â§à§Ý§Ö§Û?, §ã§á§Ú§ã§Ü§Ñ SecList ?1?§Þ§Ú§Ý§Ý§Ú§à§ß §á§à§á§å§Ý§ñ§â§ß§í§ç §á§Ñ§â§à§Ý§Ö§Û? §Ú §ã§á§Ú§ã§Ü§Ñ §Ü§à§ß§ä§Ö§Ü§ã§ä§ß§à-§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§ç §á§Ñ§â§à§Ý§Ö§Û Áú»¢¶Ä²©. §£§ß§å§ä§â§Ö§ß§ß§Ú§Þ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ§Þ §ß§Ö §Ò§å§Õ§Ö§ä §â§Ñ§Ù§â§Ö§ê§Ö§ß§à §å§ã§ä§Ñ§ß§Ñ§Ó§Ý§Ú§Ó§Ñ§ä§î §á§Ñ§â§à§Ý§Ú, §Ó§Ü§Ý§ð§é§×§ß§ß§í§Ö §Ó §ï§ä§à§ä §ã§á§Ú§ã§à§Ü, §á§à§ã§Ü§à§Ý§î§Ü§å §ä§Ñ§Ü§Ú§Ö §á§Ñ§â§à§Ý§Ú §ã§é§Ú§ä§Ñ§ð§ä§ã§ñ §ã§Ý§Ñ§Ò§í§Þ§Ú §Ú§Ù-§Ù§Ñ §Ú§ç §é§Ñ§ã§ä§à§Ô§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§ñ. |
§ª§Ù§Þ§Ö§ß§Ö§ß§Ú§ñ §Ó §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ§ç §Ü §ã§Ý§à§Ø§ß§à§ã§ä§Ú §á§Ñ§â§à§Ý§ñ §ß§Ö §á§à§Ó§Ý§Ú§ñ§ð§ä §ß§Ñ §ã§å§ë§Ö§ã§ä§Ó§å§ð§ë§Ú§Ö §á§Ñ§â§à§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û, §ß§à §Ö§ã§Ý§Ú §ã§å§ë§Ö§ã§ä§Ó§å§ð§ë§Ú§Û §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §â§Ö§ê§Ú§ä §Ú§Ù§Þ§Ö§ß§Ú§ä§î §á§Ñ§â§à§Ý§î, §ä§à §ß§à§Ó§í§Û §á§Ñ§â§à§Ý§î §Õ§à§Ý§Ø§Ö§ß §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§à§Ó§Ñ§ä§î §ä§Ö§Ü§å§ë§Ú§Þ §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ§Þ. §±§à§Õ§ã§Ü§Ñ§Ù§Ü§Ñ §ã§à §ã§á§Ú§ã§Ü§à§Þ §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§Û §Ò§å§Õ§Ö§ä §à§ä§à§Ò§â§Ñ§Ø§Ñ§ä§î§ã§ñ §â§ñ§Õ§à§Þ §ã §á§à§Ý§Ö§Þ §±§Ñ§â§à§Ý§î §Ó §á§â§à§æ§Ú§Ý§Ö §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ §Ú §Ó §Õ§Ú§Ñ§Ý§à§Ô§Ö §ß§Ñ§ã§ä§â§à§Û§Ü§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ, §Õ§à§ã§ä§å§á§ß§à§Þ §Ú§Ù §Þ§Ö§ß§ð §¡§Õ§Þ§Ú§ß§Ú§ã§ä§â§Ú§â§à§Ó§Ñ§ß§Ú§Ö¡ú§±§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ú.
§¥§Ý§ñ §á§â§à§Ó§Ö§â§Ü§Ú §Ú§Þ§×§ß §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ú §á§Ñ§â§à§Ý§Ö§Û §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð §ß§Ñ §à§ã§ß§à§Ó§Ö HTTP §Ú§Ý§Ú §Ó§Ö§Ò-§ã§Ö§â§Ó§Ö§â§Ñ (§ß§Ñ§á§â§Ú§Þ§Ö§â: §Ò§Ñ§Ù§à§Ó§Ñ§ñ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ, NTLM/Kerberos). §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §ä§Ñ§Ü§Ø§Ö §Õ§à§Ý§Ø§Ö§ß §ã§å§ë§Ö§ã§ä§Ó§à§Ó§Ñ§ä§î §Ó Áú»¢¶Ä²©; §à§Õ§ß§Ñ§Ü§à, §Ö§Ô§à §á§Ñ§â§à§Ý§î Áú»¢¶Ä²© §ß§Ö §Ò§å§Õ§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î§ã§ñ.
§¢§å§Õ§î§ä§Ö §à§ã§ä§à§â§à§Ø§ß§í! §±§Ö§â§Ö§Õ §á§Ö§â§Ö§Ü§Ý§ð§é§Ö§ß§Ú§Ö§Þ §ß§Ñ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð §Ó§Ö§Ò-§ã§Ö§â§Ó§Ö§â§Ñ §å§Ò§Ö§Õ§Ú§ä§Ö§ã§î, §é§ä§à §à§ß§Ñ §ß§Ñ§ã§ä§â§à§Ö§ß§Ñ §Ú §â§Ñ§Ò§à§ä§Ñ§Ö§ä §á§â§Ñ§Ó§Ú§Ý§î§ß§à.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§í §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú:
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|
§¡§Ü§ä§Ú§Ó§Ñ§è§Ú§ñ HTTP §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú (Enable HTTP authentication) |
§°§ä§Þ§Ö§ä§î§ä§Ö §æ§Ý§Ñ§Ø§à§Ü, §é§ä§à§Ò§í §Ó§Ü§Ý§ð§é§Ú§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð HTTP. §±§â§Ú §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ú§Ú §å§Ü§Ñ§Ù§Ñ§ä§Ö§Ý§ñ §Þ§í§ê§Ú §ß§Ñ ![]() |
§¥§Ú§Ñ§Ý§à§Ô §Ó§ç§à§Õ§Ñ §Ó §ã§Ú§ã§ä§Ö§Þ§å §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð (Default login form) |
§µ§Ü§Ñ§Ø§Ú§ä§Ö, §ã§Ý§Ö§Õ§å§Ö§ä §Ý§Ú §ß§Ñ§á§â§Ñ§Ó§Ý§ñ§ä§î §ß§Ö§Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§è§Ú§â§à§Ó§Ñ§ß§ß§í§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §ß§Ñ: §¥§Ú§Ñ§Ý§à§Ô §Ó§ç§à§Õ§Ñ §Ó §ã§Ú§ã§ä§Ö§Þ§å Áú»¢¶Ä²© ¡ª §ã§ä§Ñ§ß§Õ§Ñ§â§ä§ß§å§ð §ã§ä§â§Ñ§ß§Ú§è§å §Ó§ç§à§Õ§Ñ Áú»¢¶Ä²©. HTTP §Õ§Ú§Ñ§Ý§à§Ô §Ó§ç§à§Õ§Ñ §Ó §ã§Ú§ã§ä§Ö§Þ§å ¡ª §ã§ä§â§Ñ§ß§Ú§è§å §Ó§ç§à§Õ§Ñ HTTP. §²§Ö§Ü§à§Þ§Ö§ß§Õ§å§Ö§ä§ã§ñ §Ó§Ü§Ý§ð§é§Ñ§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð §ß§Ñ §à§ã§ß§à§Ó§Ö §Ó§Ö§Ò-§ã§Ö§â§Ó§Ö§â§Ñ §ä§à§Ý§î§Ü§à §Õ§Ý§ñ §ã§ä§â§Ñ§ß§Ú§è§í index_http.php . §¦§ã§Ý§Ú §Õ§Ý§ñ §¥§Ú§Ñ§Ý§à§Ô§Ñ §Ó§ç§à§Õ§Ñ §Ó §ã§Ú§ã§ä§Ö§Þ§å §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §å§ã§ä§Ñ§ß§à§Ó§Ý§Ö§ß§à §Ù§ß§Ñ§é§Ö§ß§Ú§Ö ?HTTP §Õ§Ú§Ñ§Ý§à§Ô §Ó§ç§à§Õ§Ñ §Ó §ã§Ú§ã§ä§Ö§Þ§å?, §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §Ò§å§Õ§Ö§ä §Ó§ç§à§Õ§Ú§ä§î §Ó §ã§Ú§ã§ä§Ö§Þ§å §Ñ§Ó§ä§à§Þ§Ñ§ä§Ú§é§Ö§ã§Ü§Ú, §Ö§ã§Ý§Ú §Þ§à§Õ§å§Ý§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §Ó§Ö§Ò-§ã§Ö§â§Ó§Ö§â§Ñ §å§ã§ä§Ñ§ß§à§Ó§Ú§ä §Õ§Ö§Û§ã§ä§Ó§Ú§ä§Ö§Ý§î§ß§í§Û §Ý§à§Ô§Ú§ß §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ §Ó §á§Ö§â§Ö§Þ§Ö§ß§ß§à§Û $_SERVER .§±§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§Ö§Þ§í§Ö §Ü§Ý§ð§é§Ú $_SERVER : PHP_AUTH_USER , REMOTE_USER , AUTH_USER . |
§µ§Õ§Ñ§Ý§Ö§ß§Ú§Ö §Ú§Þ§Ö§ß§Ú §Õ§à§Þ§Ö§ß§Ñ (Remove domain name) |
§³§á§Ú§ã§à§Ü §Õ§à§Þ§Ö§ß§ß§í§ç §Ú§Þ§Ö§ß §é§Ö§â§Ö§Ù §Ù§Ñ§á§ñ§ä§å§ð, §Ü§à§ä§à§â§í§Ö §ã§Ý§Ö§Õ§å§Ö§ä §å§Õ§Ñ§Ý§Ú§ä§î §Ú§Ù §Ú§Þ§Ö§ß§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ. §¯§Ñ§á§â§Ú§Þ§Ö§â: comp,any - §Ö§ã§Ý§Ú §Ú§Þ§ñ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ ?Admin@any? §Ú§Ý§Ú ?comp\Admin?, §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §Ó§à§Û§Õ§Ö§ä §Ó §ã§Ú§ã§ä§Ö§Þ§å §Ü§Ñ§Ü ?Admin?; §Ö§ã§Ý§Ú §Ú§Þ§ñ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ ?notacompany\Admin?, §Ó§ç§à§Õ §Ò§å§Õ§Ö§ä §Ù§Ñ§á§â§Ö§ë§×§ß. |
§²§Ö§Ô§Ú§ã§ä§â§à§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§Û §Ó§ç§à§Õ (Case sensitive login) |
§³§ß§Ú§Þ§Ú§ä§Ö §æ§Ý§Ñ§Ø§à§Ü, §é§ä§à§Ò§í §à§ä§Ü§Ý§ð§é§Ú§ä§î §Õ§Ý§ñ §Ú§Þ§Ö§ß §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ó§ç§à§Õ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ (§Ó§Ü§Ý§ð§é§×§ß§ß§í§Û §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð). §°§ä§Ü§Ý§ð§é§Ö§ß§Ú§Ö §Ó§ç§à§Õ§Ñ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ §á§à§Ù§Ó§à§Ý§ñ§Ö§ä, §ß§Ñ§á§â§Ú§Þ§Ö§â, §Ó§à§Û§ä§Ú §Ó §ã§Ú§ã§ä§Ö§Þ§å §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Þ ?admin?, §Õ§Ñ§Ø§Ö §Ö§ã§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Þ Áú»¢¶Ä²© §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ ?Admin? §Ú§Ý§Ú ?ADMIN?. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §Ö§ã§Ý§Ú §Ó§ç§à§Õ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ §à§ä§Ü§Ý§ð§é§×§ß §Ú §ã§å§ë§Ö§ã§ä§Ó§å§Ö§ä §ß§Ö§ã§Ü§à§Ý§î§Ü§à Áú»¢¶Ä²© §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §ã §á§à§ç§à§Ø§Ú§Þ§Ú §Ú§Þ§Ö§ß§Ñ§Þ§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û (§ß§Ñ§á§â§Ú§Þ§Ö§â, Admin §Ú admin), §Ó§ç§à§Õ §Õ§Ý§ñ §ï§ä§Ú§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ó§ã§Ö§Ô§Õ§Ñ §Ò§å§Õ§Ö§ä §Ù§Ñ§á§â§Ö§ë§×§ß §ã§à §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §ã§à§à§Ò§ë§Ö§ß§Ú§Ö§Þ §à§Ò §à§ê§Ú§Ò§Ü§Ö: ?Authentication failed: supplied credentials are not unique (§¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §ß§Ö §å§Õ§Ñ§Ý§Ñ§ã§î: §á§â§Ö§Õ§à§ã§ä§Ñ§Ó§Ý§Ö§ß§ß§í§Ö §å§é§×§ä§ß§í§Ö §Õ§Ñ§ß§ß§í§Ö §ß§Ö §å§ß§Ú§Ü§Ñ§Ý§î§ß§í)?. |
§¥§Ý§ñ §Ó§ß§å§ä§â§Ö§ß§ß§Ú§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û, §Ü§à§ä§à§â§í§Ö §ß§Ö §Þ§à§Ô§å§ä §Ó§à§Û§ä§Ú §Ó §ã§Ú§ã§ä§Ö§Þ§å §ã §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ö§Þ §å§é§×§ä§ß§í§ç §Õ§Ñ§ß§ß§í§ç HTTP (§ã §å§ã§ä§Ñ§ß§à§Ó§Ý§Ö§ß§ß§í§Þ §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð §Õ§Ú§Ñ§Ý§à§Ô§à§Þ §Ó§ç§à§Õ§Ñ HTTP), §é§ä§à §á§â§Ú§Ó§à§Õ§Ú§ä §Ü §à§ê§Ú§Ò§Ü§Ö 401, §Ó§í §Þ§à§Ø§Ö§ä§Ö §Õ§à§Ò§Ñ§Ó§Ú§ä§î §ã§ä§â§à§Ü§å ?ErrorDocument 401 /index.php?form=default
? §Ü §à§ã§ß§à§Ó§ß§í§Þ §Õ§Ú§â§Ö§Ü§ä§Ú§Ó§Ñ§Þ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú, §é§ä§à §á§Ö§â§Ö§ß§Ñ§á§â§Ñ§Ó§Ú§ä §ß§Ñ §à§Ò§í§é§ß§í§Û §Õ§Ú§Ñ§Ý§à§Ô §Ó§ç§à§Õ§Ñ §Ó Áú»¢¶Ä²©.
§£§ß§Ö§ê§ß§ð§ð §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð LDAP §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Õ§Ý§ñ §á§â§à§Ó§Ö§â§Ü§Ú §Ú§Þ§×§ß §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ú §á§Ñ§â§à§Ý§Ö§Û. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §ä§Ñ§Ü§Ø§Ö §Õ§à§Ý§Ø§Ö§ß §ã§å§ë§Ö§ã§ä§Ó§à§Ó§Ñ§ä§î §Ó Áú»¢¶Ä²©, §à§Õ§ß§Ñ§Ü§à §Ö§Ô§à §á§Ñ§â§à§Ý§î Áú»¢¶Ä²© §ß§Ö §Ò§å§Õ§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î§ã§ñ.
§¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ Áú»¢¶Ä²© LDAP §â§Ñ§Ò§à§ä§Ñ§Ö§ä §Ü§Ñ§Ü §Þ§Ú§ß§Ú§Þ§å§Þ §ã Microsoft Active Directory §Ú OpenLDAP.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§í §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú:
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|
§¡§Ü§ä§Ú§Ó§Ñ§è§Ú§ñ LDAP §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú (Enable LDAP authentication) |
§±§à§ã§ä§Ñ§Ó§î§ä§Ö §æ§Ý§Ñ§Ø§à§Ü, §é§ä§à§Ò§í §Ó§Ü§Ý§ð§é§Ú§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð LDAP. |
§·§à§ã§ä LDAP (LDAP host) |
§ª§Þ§ñ §ã§Ö§â§Ó§Ö§â§Ñ LDAP. §¯§Ñ§á§â§Ú§Þ§Ö§â: ldap://ldap.zabbix.com §¥§Ý§ñ §Ù§Ñ§ë§Ú§ë§×§ß§ß§à§Ô§à §ã§Ö§â§Ó§Ö§â§Ñ LDAP §Ú§ã§á§à§Ý§î§Ù§å§Û§ä§Ö §á§â§à§ä§à§Ü§à§Ý ldaps. ldaps://ldap.zabbix.com §¥§Ý§ñ OpenLDAP 2.x.x §Ú §Ò§à§Ý§Ö§Ö §á§à§Ù§Õ§ß§Ú§ç §Ó§Ö§â§ã§Ú§Û §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §á§à§Ý§ß§í§Û URI LDAP §Ó §æ§à§â§Þ§Ö ldap://§Ú§Þ§ñ§ç§à§ã§ä§Ñ:§á§à§â§ä §Ú§Ý§Ú ldaps://§Ú§Þ§ñ§ç§à§ã§ä§Ñ:§á§à§â§ä. |
§±§à§â§ä (Port) |
§±§à§â§ä §ã§Ö§â§Ó§Ö§â§Ñ LDAP. §±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð ¡ª 389. §¥§Ý§ñ §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§Ô§à §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ LDAP §ß§à§Þ§Ö§â §á§à§â§ä§Ñ §à§Ò§í§é§ß§à §â§Ñ§Ó§Ö§ß 636. §¯§Ö §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä§ã§ñ §á§â§Ú §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ú §á§à§Ý§ß§í§ç URI LDAP. |
§¢§Ñ§Ù§Ñ §Õ§Ý§ñ §á§à§Ú§ã§Ü§Ñ (Base DN) | §¢§Ñ§Ù§à§Ó§í§Û §á§å§ä§î §Õ§Ý§ñ §á§à§Ú§ã§Ü§Ñ §å§é§×§ä§ß§í§ç §Ù§Ñ§á§Ú§ã§Ö§Û: ou=Users,ou=system (§Õ§Ý§ñ OpenLDAP), DC=company,DC=com (§Õ§Ý§ñ Microsoft Active Directory) |
§¡§ä§â§Ú§Ò§å§ä §á§à§Ú§ã§Ü§Ñ (Search attribute) |
§¡§ä§â§Ú§Ò§å§ä §å§é§×§ä§ß§à§Û §Ù§Ñ§á§Ú§ã§Ú LDAP, §Ú§ã§á§à§Ý§î§Ù§å§Ö§Þ§í§Û §Õ§Ý§ñ §á§à§Ú§ã§Ü§Ñ: uid (§Õ§Ý§ñ OpenLDAP), sAMAccountName (§Õ§Ý§ñ Microsoft Active Directory) |
§ª§Þ§ñ §Õ§Ý§ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ (Bind DN) | §µ§é§×§ä§ß§Ñ§ñ §Ù§Ñ§á§Ú§ã§î LDAP §Õ§Ý§ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ §Ú §á§à§Ú§ã§Ü§Ñ §ß§Ñ §ã§Ö§â§Ó§Ö§â§Ö LDAP, §á§â§Ú§Þ§Ö§â§í: uid=ldap_search,ou=system (§Õ§Ý§ñ OpenLDAP), CN=ldap_search,OU=user_group ,DC=company,DC=com (§Õ§Ý§ñ Microsoft Active Directory) §¡§ß§à§ß§Ú§Þ§ß§à§Ö §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§Ö §ä§Ñ§Ü§Ø§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§Ö§ä§ã§ñ. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §Ñ§ß§à§ß§Ú§Þ§ß§à§Ö §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§Ö §á§à§ä§Ö§ß§è§Ú§Ñ§Ý§î§ß§à §à§ä§Ü§â§í§Ó§Ñ§Ö§ä §Õ§à§ã§ä§å§á §Ü §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Õ§à§Þ§Ö§ß§Ñ §ß§Ö§Ñ§Ó§ä§à§â§Ú§Ù§à§Ó§Ñ§ß§ß§í§Þ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ§Þ (§Ú§ß§æ§à§â§Þ§Ñ§è§Ú§ñ §à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ§ç, §Ü§à§Þ§á§î§ð§ä§Ö§â§Ñ§ç, §ã§Ö§â§Ó§Ö§â§Ñ§ç, §Ô§â§å§á§á§Ñ§ç, §ã§Ý§å§Ø§Ò§Ñ§ç §Ú §ä. §Õ.). §ª§Ù §ã§à§à§Ò§â§Ñ§Ø§Ö§ß§Ú§Û §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§Ú §à§ä§Ü§Ý§ð§é§Ú§ä§Ö §Ñ§ß§à§ß§Ú§Þ§ß§í§Ö §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ §ß§Ñ §ç§à§ã§ä§Ñ§ç LDAP §Ú §Ú§ã§á§à§Ý§î§Ù§å§Û§ä§Ö §Ó§Þ§Ö§ã§ä§à §ï§ä§à§Ô§à §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§è§Ú§â§à§Ó§Ñ§ß§ß§í§Û §Õ§à§ã§ä§å§á. |
§²§Ö§Ô§Ú§ã§ä§â§à§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§Û §Ó§ç§à§Õ (Case sensitive login) |
§³§ß§Ú§Þ§Ú§ä§Ö §æ§Ý§Ñ§Ø§à§Ü, §é§ä§à§Ò§í §à§ä§Ü§Ý§ð§é§Ú§ä§î §Õ§Ý§ñ §Ú§Þ§Ö§ß §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ó§ç§à§Õ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ (§Ó§Ü§Ý§ð§é§×§ß§ß§í§Û §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð). §°§ä§Ü§Ý§ð§é§Ö§ß§Ú§Ö §Ó§ç§à§Õ§Ñ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ §á§à§Ù§Ó§à§Ý§ñ§Ö§ä, §ß§Ñ§á§â§Ú§Þ§Ö§â, §Ó§à§Û§ä§Ú §Ó §ã§Ú§ã§ä§Ö§Þ§å §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Þ ?admin?, §Õ§Ñ§Ø§Ö §Ö§ã§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Þ Áú»¢¶Ä²© §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ ?Admin? §Ú§Ý§Ú ?ADMIN?. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §Ö§ã§Ý§Ú §Ó§ç§à§Õ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ §à§ä§Ü§Ý§ð§é§×§ß §Ú §ã§å§ë§Ö§ã§ä§Ó§å§Ö§ä §ß§Ö§ã§Ü§à§Ý§î§Ü§à Áú»¢¶Ä²© §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §ã §á§à§ç§à§Ø§Ú§Þ§Ú §Ú§Þ§Ö§ß§Ñ§Þ§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û (§ß§Ñ§á§â§Ú§Þ§Ö§â, Admin §Ú admin), §Ó§ç§à§Õ §Õ§Ý§ñ §ï§ä§Ú§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ó§ã§Ö§Ô§Õ§Ñ §Ò§å§Õ§Ö§ä §Ù§Ñ§á§â§Ö§ë§×§ß §ã§à §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §ã§à§à§Ò§ë§Ö§ß§Ú§Ö§Þ §à§Ò §à§ê§Ú§Ò§Ü§Ö: ?Authentication failed: supplied credentials are not unique (§¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §ß§Ö §å§Õ§Ñ§Ý§Ñ§ã§î: §á§â§Ö§Õ§à§ã§ä§Ñ§Ó§Ý§Ö§ß§ß§í§Ö §å§é§×§ä§ß§í§Ö §Õ§Ñ§ß§ß§í§Ö §ß§Ö §å§ß§Ú§Ü§Ñ§Ý§î§ß§í)?. |
§±§Ñ§â§à§Ý§î §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ (Bind password) | §±§Ñ§â§à§Ý§î LDAP §å§é§×§ä§ß§à§Û §Ù§Ñ§á§Ú§ã§Ú §Õ§Ý§ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ §Ú §á§à§Ú§ã§Ü§Ñ §ß§Ñ §ã§Ö§â§Ó§Ö§â§Ö LDAP. |
§´§Ö§ã§ä §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú (Test authentication) |
§©§Ñ§Ô§à§Ý§à§Ó§à§Ü §ã§Ö§Ü§è§Ú§Ú §Õ§Ý§ñ §ä§Ö§ã§ä§Ú§â§à§Ó§Ñ§ß§Ú§ñ |
§£§ç§à§Õ §Ó §ã§Ú§ã§ä§Ö§Þ§å (Login) |
§ª§Þ§ñ §ä§Ö§ã§ä§à§Ó§à§Ô§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ (§Ü§à§ä§à§â§í§Û §Ó §Õ§Ñ§ß§ß§í§Û §Þ§à§Þ§Ö§ß§ä §Ù§Ñ§â§Ö§Ô§Ú§ã§ä§â§Ú§â§à§Ó§Ñ§ß §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö Áú»¢¶Ä²©). §¿§ä§à §Ú§Þ§ñ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ §Õ§à§Ý§Ø§ß§à §ã§å§ë§Ö§ã§ä§Ó§à§Ó§Ñ§ä§î §ß§Ñ §ã§Ö§â§Ó§Ö§â§Ö LDAP. Áú»¢¶Ä²© §ß§Ö §Ò§å§Õ§Ö§ä §Ñ§Ü§ä§Ú§Ó§Ú§â§à§Ó§Ñ§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð LDAP, §Ö§ã§Ý§Ú §à§ß §ß§Ö §ã§Þ§à§Ø§Ö§ä §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§è§Ú§â§à§Ó§Ñ§ä§î §ä§Ö§ã§ä§à§Ó§à§Ô§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ. |
§±§Ñ§â§à§Ý§î §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ (User password) |
§±§Ñ§â§à§Ý§î LDAP §ä§Ö§ã§ä§à§Ó§à§Ô§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ. |
§£ §ã§Ý§å§é§Ñ§Ö §á§â§à§Ò§Ý§Ö§Þ §ã §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú, §é§ä§à§Ò§í §à§Ò§Ö§ã§á§Ö§é§Ú§ä§î §â§Ñ§Ò§à§ä§å §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§Ô§à §ã§à§Ö§Õ§Ú§ß§Ö§ß§Ú§ñ LDAP (ldaps), §Ó§Ñ§Þ §Þ§à§Ø§Ö§ä §á§à§ä§â§Ö§Ò§à§Ó§Ñ§ä§î§ã§ñ §Õ§à§Ò§Ñ§Ó§Ú§ä§î §ã§ä§â§à§Ü§å TLS_REQCERT allow
§Ó §æ§Ñ§Û§Ý §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú /etc/openldap/ldap.conf
. §¿§ä§à §Þ§à§Ø§Ö§ä §ã§ß§Ú§Ù§Ú§ä§î §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§î §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ §Ü §Ü§Ñ§ä§Ñ§Ý§à§Ô§å LDAP.
§²§Ö§Ü§à§Þ§Ö§ß§Õ§å§Ö§ä§ã§ñ §ã§à§Ù§Õ§Ñ§ä§î §à§ä§Õ§Ö§Ý§î§ß§å§ð §å§é§×§ä§ß§å§ð §Ù§Ñ§á§Ú§ã§î LDAP (Bind DN) §Õ§Ý§ñ §Ó§í§á§à§Ý§ß§Ö§ß§Ú§ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ §Ú §á§à§Ú§ã§Ü§Ñ §ß§Ñ §ã§Ö§â§Ó§Ö§â§Ö LDAP §ã §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§í§Þ§Ú §á§â§Ú§Ó§Ú§Ý§Ö§Ô§Ú§ñ§Þ§Ú §Ó LDAP §Ó§Þ§Ö§ã§ä§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§ñ §å§é§×§ä§ß§í§ç §Ù§Ñ§á§Ú§ã§Ö§Û §â§Ö§Ñ§Ý§î§ß§í§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û (§Ü§à§ä§à§â§í§Ö §á§à§Õ§Ü§Ý§ð§é§Ñ§ð§ä§ã§ñ §Ü §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§å Áú»¢¶Ä²©).
§´§Ñ§Ü§à§Û §á§à§Õ§ç§à§Õ §à§Ò§Ö§ã§á§Ö§é§Ú§Ó§Ñ§Ö§ä §Ò§à§Ý§î§ê§å§ð §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§î §Ú §ß§Ö §ä§â§Ö§Ò§å§Ö§ä §Ú§Ù§Þ§Ö§ß§Ö§ß§Ú§ñ §±§Ñ§â§à§Ý§ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ (Bind password), §Ü§à§Ô§Õ§Ñ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §Þ§Ö§ß§ñ§Ö§ä §ã§Ó§à§Û §á§Ñ§â§à§Ý§î §ß§Ñ §ã§Ö§â§Ó§Ö§â§Ö LDAP.
§£ §ä§Ñ§Ò§Ý§Ú§è§Ö §Ó§í§ê§Ö §ï§ä§Ñ §å§é§×§ä§ß§Ñ§ñ §Ù§Ñ§á§Ú§ã§î §Ú§Þ§Ö§Ö§ä §Ú§Þ§ñ ldap_search.
§¥§Ý§ñ §Ó§ç§à§Õ§Ñ §Ó Áú»¢¶Ä²© §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð SAML 2.0. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î §Õ§à§Ý§Ø§Ö§ß §ã§å§ë§Ö§ã§ä§Ó§à§Ó§Ñ§ä§î §Ó Áú»¢¶Ä²©, §à§Õ§ß§Ñ§Ü§à §Ö§Ô§à §á§Ñ§â§à§Ý§î Áú»¢¶Ä²© §ß§Ö §Ò§å§Õ§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î§ã§ñ. §¦§ã§Ý§Ú §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §á§â§à§ê§Ý§Ñ §å§ã§á§Ö§ê§ß§à, Áú»¢¶Ä²© §ã§à§á§à§ã§ä§Ñ§Ó§Ú§ä §Ý§à§Ü§Ñ§Ý§î§ß§à§Ö §Ú§Þ§ñ §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ §ã §Ñ§ä§â§Ú§Ò§å§ä§à§Þ §Ú§Þ§Ö§ß§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ, §Ó§à§Ù§Ó§â§Ñ§ë§Ñ§Ö§Þ§í§Þ SAML.
§¦§ã§Ý§Ú §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ SAML §Ó§Ü§Ý§ð§é§Ö§ß§Ñ, §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ú §ã§Þ§à§Ô§å§ä §Ó§í§Ò§Ú§â§Ñ§ä§î §Þ§Ö§Ø§Õ§å §Ó§ç§à§Õ§à§Þ §Ó §ã§Ú§ã§ä§Ö§Þ§å §Ý§à§Ü§Ñ§Ý§î§ß§à §Ú§Ý§Ú §é§Ö§â§Ö§Ù §ã§Ú§ã§ä§Ö§Þ§å §Ö§Õ§Ú§ß§à§Ô§à §Ó§ç§à§Õ§Ñ SAML.
§¥§Ý§ñ §â§Ñ§Ò§à§ä§í §ã Áú»¢¶Ä²©, §á§à§ã§ä§Ñ§Ó§ë§Ú§Ü§Ñ §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§à§ß§ß§í§ç §Õ§Ñ§ß§ß§í§ç SAML (, , §Ú §ä.§Õ.) §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à §ß§Ñ§ã§ä§â§à§Ú§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
&±ô³Ù;§á§å§ä§î³å§Ü³å§Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§å³å³ú²¹²ú²ú¾±³æ&²µ³Ù;/¾±²Ô»å±ð³æ³å²õ²õ´Ç.±è³ó±è?²¹³¦²õ
&±ô³Ù;§á§å§ä§î³å§Ü³å§Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§å³å³ú²¹²ú²ú¾±³æ&²µ³Ù;/¾±²Ô»å±ð³æ³å²õ²õ´Ç.±è³ó±è?²õ±ô²õ
§±§â§Ú§Þ§Ö§â§í &±ô³Ù;§á§å§ä§Ú³å§Ü³å§Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§å³å³ú²¹²ú²ú¾±³æ&²µ³Ù;
: <https://example.com/zabbix/ui>,<http://another.example.com/zabbix>,<http://><any\_public\_ip\_address>/zabbix
§¦§ã§Ý§Ú §Ó§í §ç§à§ä§Ú§ä§Ö §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð SAML §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö, §ä§à §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à §å§ã§ä§Ñ§ß§à§Ó§Ú§ä§î php-openssl.
§¥§Ý§ñ §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§ñ §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú SAML Áú»¢¶Ä²© §Õ§à§Ý§Ø§Ö§ß §Ò§í§ä§î §ß§Ñ§ã§ä§â§à§Ö§ß §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
1. §©§Ñ§Ü§â§í§ä§í§Û §Ü§Ý§ð§é (private key) §Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Õ§à§Ý§Ø§ß§í §ç§â§Ñ§ß§Ú§ä§î§ã§ñ §Ó ui/conf/certs/, §Ö§ã§Ý§Ú §ä§à§Ý§î§Ü§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î§ã§Ü§Ú§Ö §á§å§ä§Ú §ß§Ö §å§Ü§Ñ§Ù§Ñ§ß§í §Ó §æ§Ñ§Û§Ý§Ö zabbix.conf.php.
§±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð, Áú»¢¶Ä²© §Ò§å§Õ§Ö§ä §Ú§ã§Ü§Ñ§ä§î §Ó §ã§Ý§Ö§Õ§å§ð§ë§Ú§ç §Þ§Ö§ã§ä§Ñ§ç:
2. §£§ã§Ö §ß§Ñ§Ú§Ò§à§Ý§Ö§Ö §Ó§Ñ§Ø§ß§í§Ö §ß§Ñ§ã§ä§â§à§Û§Ü§Ú §Þ§à§Ô§å§ä §Ò§í§ä§î §ã§Õ§Ö§Ý§Ñ§ß§í §é§Ö§â§Ö§Ù §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã Áú»¢¶Ä²©. §°§Õ§ß§Ñ§Ü§à, §Ó §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§à§ß§ß§à§Þ §æ§Ñ§Û§Ý§Ö §Þ§à§Ø§ß§à §å§Ü§Ñ§Ù§Ñ§ä§î §Õ§à§á§à§Ý§ß§Ú§ä§Ö§Ý§î§ß§í§Ö §ß§Ñ§ã§ä§â§à§Û§Ü§Ú.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§í §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú, §Õ§à§ã§ä§å§á§ß§í§Ö §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö Áú»¢¶Ä²©:
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|
§£§Ü§Ý§ð§é§Ú§ä§î SAML §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð (Enable SAML authentication) |
§°§ä§Þ§Ö§ä§î§ä§Ö §æ§Ý§Ñ§Ø§à§Ü, §é§ä§à§Ò§í §Ó§Ü§Ý§ð§é§Ú§ä§î §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ð SAML. |
IDP entity ID | §µ§ß§Ú§Ü§Ñ§Ý§î§ß§í§Û §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â §á§à§ã§ä§Ñ§Ó§ë§Ú§Ü§Ñ §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§à§ß§ß§í§ç §Õ§Ñ§ß§ß§í§ç SAML. |
URL §Ö§Õ§Ú§ß§à§Ô§à §Ó§ç§à§Õ§Ñ (SSO service URL) |
URL, §ß§Ñ §Ü§à§ä§à§â§í§Û §Ò§å§Õ§å§ä §á§Ö§â§Ö§ß§Ñ§á§â§Ñ§Ó§Ý§Ö§ß§í §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ú §á§â§Ú §Ó§ç§à§Õ§Ö §Ó §ã§Ú§ã§ä§Ö§Þ§å. |
URL §Ö§Õ§Ú§ß§à§Ô§à §Ó§í§ç§à§Õ§Ñ (SLO Service URL) |
URL, §ß§Ñ §Ü§à§ä§à§â§í§Û §Ò§å§Õ§å§ä §á§Ö§â§Ö§ß§Ñ§á§â§Ñ§Ó§Ý§Ö§ß§í §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ú §á§â§Ú §Ó§í§ç§à§Õ§Ö §Ú§Ù §ã§Ú§ã§ä§Ö§Þ§í. §¦§ã§Ý§Ú §ï§ä§à §á§à§Ý§Ö §à§ã§ä§Ñ§Ó§Ú§ä§î §á§å§ã§ä§í§Þ, §ã§Ý§å§Ø§Ò§Ñ SLO §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î§ã§ñ §ß§Ö §Ò§å§Õ§Ö§ä. |
§¡§ä§â§Ú§Ò§å§ä §Ú§Þ§Ö§ß§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ (Username attribute) |
§¡§ä§â§Ú§Ò§å§ä SAML, §Ú§ã§á§à§Ý§î§Ù§å§Ö§Þ§í§Û §Ó §Ü§Ñ§é§Ö§ã§ä§Ó§Ö §Ú§Þ§Ö§ß§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ñ§á§â§Ú §Ó§ç§à§Õ§Ö §Ó Áú»¢¶Ä²©. §³§á§Ú§ã§à§Ü §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§Ö§Þ§í§ç §Ù§ß§Ñ§é§Ö§ß§Ú§Û §à§á§â§Ö§Õ§Ö§Ý§ñ§Ö§ä§ã§ñ §á§à§ã§ä§Ñ§Ó§ë§Ú§Ü§à§Þ §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§à§ß§ß§í§ç §Õ§Ñ§ß§ß§í§ç. §±§â§Ú§Þ§Ö§â§í: uid userprincipalname samaccountname username userusername urn:oid:0.9.2342.19200300.100.1.1 urn:oid:1.3.6.1.4.1.5923.1.1.1.13 urn:oid:0.9.2342.19200300.100.1.44 |
ID §à§Ò§ì§Ö§Ü§ä§Ñ SP (SP entity ID) |
§µ§ß§Ú§Ü§Ñ§Ý§î§ß§í§Û §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â §á§à§ã§ä§Ñ§Ó§ë§Ú§Ü§Ñ §å§ã§Ý§å§Ô SAML. |
§¶§à§â§Þ§Ñ§ä ID §à§Ò§ì§Ö§Ü§ä§Ñ SP (SP name ID format) |
§©§Ñ§á§â§à§ã§Ú§ä§î §à§á§â§Ö§Õ§Ö§Ý§×§ß§ß§í§Û §æ§à§â§Þ§Ñ§ä §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â§Ñ §Ú§Þ§Ö§ß§Ú §Ó §à§ä§Ó§Ö§ä§Ö. §±§â§Ú§Þ§Ö§â§í: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified urn:oasis:names:tc:SAML:2.0:nameid-format:transient |
§£§à§Û§ä§Ú (Sign) |
§°§ä§Þ§Ö§ä§î§ä§Ö §æ§Ý§Ñ§Ø§Ü§Ñ§Þ§Ú §à§Ò§ì§Ö§Ü§ä§í, §Õ§Ý§ñ §Ü§à§ä§à§â§í§ç §Õ§à§Ý§Ø§ß§Ñ §Ò§í§ä§î §Ó§Ü§Ý§ð§é§Ö§ß§Ñ §á§à§Õ§á§Ú§ã§î SAML: §³§à§à§Ò§ë§Ö§ß§Ú§ñ (Messages) §¥§Ö§Ü§Ý§Ñ§â§Ñ§è§Ú§Ú (Assertions) §©§Ñ§á§â§à§ã§í AuthN (AuthN requests) §©§Ñ§á§â§à§ã§í §ß§Ñ §Ó§í§ç§à§Õ §Ú§Ù §ã§Ú§ã§ä§Ö§Þ§í (Logout requests) §°§ä§Ó§Ö§ä§í §ß§Ñ §Ó§í§ç§à§Õ §Ú§Ù §ã§Ú§ã§ä§Ö§Þ§í (Logout responses) |
§º§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö (Encrypt) |
§°§ä§Þ§Ö§ä§î§ä§Ö §æ§Ý§Ñ§Ø§Ü§Ñ§Þ§Ú §à§Ò§ì§Ö§Ü§ä§í, §Õ§Ý§ñ §Ü§à§ä§à§â§í§ç §Õ§à§Ý§Ø§ß§à §Ò§í§ä§î §Ó§Ü§Ý§ð§é§Ö§ß§à §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö SAML: §¥§Ö§Ü§Ý§Ñ§â§Ñ§è§Ú§Ú (Assertions) ID §Ú§Þ§Ö§ß§Ú (Name ID) |
§²§Ö§Ô§Ú§ã§ä§â§à§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§Û §Ó§ç§à§Õ (Case sensitive login) |
§³§ß§Ú§Þ§Ú§ä§Ö §æ§Ý§Ñ§Ø§à§Ü, §é§ä§à§Ò§í §à§ä§Ü§Ý§ð§é§Ú§ä§î §Õ§Ý§ñ §Ú§Þ§Ö§ß §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ó§ç§à§Õ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ (§Ó§Ü§Ý§ð§é§×§ß§ß§í§Û §á§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð). §°§ä§Ü§Ý§ð§é§Ö§ß§Ú§Ö §Ó§ç§à§Õ§Ñ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ §á§à§Ù§Ó§à§Ý§ñ§Ö§ä, §ß§Ñ§á§â§Ú§Þ§Ö§â, §Ó§à§Û§ä§Ú §Ó §ã§Ú§ã§ä§Ö§Þ§å §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Þ ?admin?, §Õ§Ñ§Ø§Ö §Ö§ã§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Þ Áú»¢¶Ä²© §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ ?Admin? §Ú§Ý§Ú ?ADMIN?. §°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §Ö§ã§Ý§Ú §Ó§ç§à§Õ §ã §å§é§×§ä§à§Þ §â§Ö§Ô§Ú§ã§ä§â§Ñ §à§ä§Ü§Ý§ð§é§×§ß §Ú §ã§å§ë§Ö§ã§ä§Ó§å§Ö§ä §ß§Ö§ã§Ü§à§Ý§î§Ü§à Áú»¢¶Ä²© §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §ã §á§à§ç§à§Ø§Ú§Þ§Ú §Ú§Þ§Ö§ß§Ñ§Þ§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û (§ß§Ñ§á§â§Ú§Þ§Ö§â, Admin §Ú admin), §Ó§ç§à§Õ §Õ§Ý§ñ §ï§ä§Ú§ç §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§Ö§Û §Ó§ã§Ö§Ô§Õ§Ñ §Ò§å§Õ§Ö§ä §Ù§Ñ§á§â§Ö§ë§×§ß §ã§à §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §ã§à§à§Ò§ë§Ö§ß§Ú§Ö§Þ §à§Ò §à§ê§Ú§Ò§Ü§Ö: ?Authentication failed: supplied credentials are not unique (§¡§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §ß§Ö §å§Õ§Ñ§Ý§Ñ§ã§î: §á§â§Ö§Õ§à§ã§ä§Ñ§Ó§Ý§Ö§ß§ß§í§Ö §å§é§×§ä§ß§í§Ö §Õ§Ñ§ß§ß§í§Ö §ß§Ö §å§ß§Ú§Ü§Ñ§Ý§î§ß§í)?. |
§¥§à§á§à§Ý§ß§Ú§ä§Ö§Ý§î§ß§í§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í SAML §Þ§à§Ø§ß§à §ß§Ñ§ã§ä§â§à§Ú§ä§î §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ñ Áú»¢¶Ä²© (zabbix.conf.php):
Áú»¢¶Ä²© §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä §Ò§Ú§Ò§Ý§Ú§à§ä§Ö§Ü§å (§Ó§Ö§â§ã§Ú§Ú 3.4.1). §³§ä§â§å§Ü§ä§å§â§Ñ §ã§Ö§Ü§è§Ú§Ú $SSO['SETTINGS'] §Õ§à§Ý§Ø§ß§Ñ §Ò§í§ä§î §Ñ§ß§Ñ§Ý§à§Ô§Ú§é§ß§Ñ §ã§ä§â§å§Ü§ä§å§â§Ö, §Ú§ã§á§à§Ý§î§Ù§å§Ö§Þ§à§Û §ï§ä§à§Û §Ò§Ú§Ò§Ý§Ú§à§ä§Ö§Ü§à§Û. §¥§Ý§ñ §à§á§Ú§ã§Ñ§ß§Ú§ñ §á§Ñ§â§Ñ§Þ§Ö§ä§â§à§Ó §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú, §ã§Þ§à§ä§â§Ú§ä§Ö §à§æ§Ú§è§Ú§Ñ§Ý§î§ß§å§ð §Ò§Ú§Ò§Ý§Ú§à§ä§Ö§Ü§Ú.
§£ §â§Ñ§Þ§Ü§Ñ§ç $SSO['SETTINGS'] §Þ§à§Ø§ß§à §Ù§Ñ§Õ§Ñ§ä§î §ä§à§Ý§î§Ü§à §ã§Ý§Ö§Õ§å§ð§ë§Ú§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í:
§£§ã§Ö §à§ã§ä§Ñ§Ý§î§ß§í§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í §Ò§å§Õ§å§ä §Ó§Ù§ñ§ä§í §Ú§Ù §Ò§Ñ§Ù§í §Õ§Ñ§ß§ß§í§ç §Ú §ß§Ö §Þ§à§Ô§å§ä §Ò§í§ä§î §á§Ö§â§Ö§à§á§â§Ö§Õ§Ö§Ý§Ö§ß§í. §°§á§è§Ú§ñ debug §Ò§å§Õ§Ö§ä §Ú§Ô§ß§à§â§Ú§â§à§Ó§Ñ§ä§î§ã§ñ.
§¬§â§à§Þ§Ö §ä§à§Ô§à, §Ö§ã§Ý§Ú §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î§ã§Ü§Ú§Û §Ú§ß§ä§Ö§â§æ§Ö§Û§ã Áú»¢¶Ä²© §ß§Ñ§ç§à§Õ§Ú§ä§ã§ñ §Ù§Ñ §á§â§à§Ü§ã§Ú-§ã§Ö§â§Ó§Ö§â§à§Þ §Ú§Ý§Ú §Ò§Ñ§Ý§Ñ§ß§ã§Ú§â§à§Ó§ë§Ú§Ü§à§Þ §ß§Ñ§Ô§â§å§Ù§Ü§Ú, §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§î§ã§Ü§å§ð §à§á§è§Ú§ð use_proxy_headers:
§¦§ã§Ý§Ú §Ó§í §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä§Ö §Ò§Ñ§Ý§Ñ§ß§ã§Ú§â§à§Ó§ë§Ú§Ü §ß§Ñ§Ô§â§å§Ù§Ü§Ú §Õ§Ý§ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ §Ü §ï§Ü§Ù§Ö§Þ§á§Ý§ñ§â§å Áú»¢¶Ä²©, §Ô§Õ§Ö §Ò§Ñ§Ý§Ñ§ß§ã§Ú§â§à§Ó§ë§Ú§Ü §ß§Ñ§Ô§â§å§Ù§Ü§Ú §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä TLS/SSL, §Ñ Áú»¢¶Ä²© ¡ª §ß§Ö§ä, §Ó§í §Õ§à§Ý§Ø§ß§í §å§Ü§Ñ§Ù§Ñ§ä§î §á§Ñ§â§Ñ§Þ§Ö§ä§â§í ?baseurl?, ?strict? §Ú ?use_proxy_headers? §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
$SSO['SETTINGS'] = [
'strict' => false,
'baseurl' => 'https://zabbix.example.com/zabbix/',
'use_proxy_headers' => true
];
§±§â§Ú§Þ§Ö§â §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú:
$SSO['SETTINGS'] = [
'security' => [
'signatureAlgorithm' => 'http://www.w3.org/2001/04/xmldsig-more#rsa-sha384'
'digestAlgorithm' => 'http://www.w3.org/2001/04/xmldsig-more#sha384',
// ...
],
// ...
];
§®§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §æ§Ñ§Û§Ý §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ñ Áú»¢¶Ä²© (zabbix.conf.php), §é§ä§à§Ò§í §ß§Ñ§ã§ä§â§à§Ú§ä§î SSO §ã §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ö§Û Kerberos §Ú ADFS:
$SSO['SETTINGS'] = [
'security' => [
'requestedAuthnContext' => [
'urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos',
],
'requestedAuthnContextComparison' => 'exact'
]
];
§£ §ï§ä§à§Þ §ã§Ý§å§é§Ñ§Ö, §Ó §ß§Ñ§ã§ä§â§à§Û§Ü§Ñ§ç SAML §Ó §á§à§Ý§Ö ID §à§Ò§ì§Ö§Ü§ä§Ñ SP (SP name ID) §Ù§Ñ§Õ§Ñ§Û§ä§Ö: