{"id":17023,"date":"2022-12-28T02:11:25","date_gmt":"2022-12-28T02:11:25","guid":{"rendered":"https:\/\/44.225.35.201\/testrail\/docs\/801\/user-guide\/enterprise\/configure-single-sign-on\/adfs-sso-configuration\/"},"modified":"2023-09-11T11:38:18","modified_gmt":"2023-09-11T02:38:18","slug":"adfs-sso-con","status":"publish","type":"page","link":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/user-guide\/enterprise\/configure-single-sign-on\/adfs-sso-con\/","title":{"rendered":"ADFS SSO \u8a2d\u5b9a"},"content":{"rendered":"<p>TestRail \u306e SSO \u6a5f\u80fd\u3092\u5229\u7528\u3059\u308b\u3068\u3001SAML 2.0\u3001OAuth 2.0 \u304a\u3088\u3073 OpenID Connect \u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3059\u308b\u4efb\u610f\u306e SSO ID \u30d7\u30ed\u30d0\u30a4\u30c0\u30fc (IDP) \u3068 TestRail \u3092\u7d71\u5408\u3067\u304d\u307e\u3059\u3002SSO \u8a2d\u5b9a\u3092\u6709\u52b9\u306b\u3057\u305f\u3089\u3001\u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u9078\u629e\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30ac\u30a4\u30c9\u3067\u306f\u3001\u7279\u306b SAML 2.0 &#8211; ADFS \u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u8a2d\u5b9a\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3059\u3002\u6b21\u306e\u624b\u9806\u306b\u5f93\u3063\u3066\u3001ADFS for SSO \u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol class=\"list-colored\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ADFS Management \u3067<\/span> <strong>[Trust Relationships] &gt; [Relying Party Trust]<\/strong> <span style=\"font-weight: 400;\">\u30a8\u30ea\u30a2\u306b\u79fb\u52d5\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u53f3\u30d1\u30cd\u30eb \u30a6\u30a3\u30f3\u30c9\u30a6\u3067<\/span> [<strong>Add Relying Party Trust <\/strong>] <span style=\"font-weight: 400;\">\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">[Start] \u3092\u30af\u30ea\u30c3\u30af\u3057<\/span>\u3001[<strong>Enter data about relying party manually<\/strong>] \u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">[Next] \u3092\u30af\u30ea\u30c3\u30af\u3057<\/span>\u3001[<strong>Display Name<\/strong>] \u306b\u5165\u529b\u3057\u307e\u3059\u3002<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">[<strong>Configure Certificate Page<\/strong>] <span style=\"font-weight: 400;\">\u3067 [Next] \u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">[<strong>Enable Support for SAML 2.0 WebSSO Protocol <\/strong>] <span style=\"font-weight: 400;\">\u3092\u9078\u629e\u3057\u3001TestRail SSO \u8a2d\u5b9a\u30da\u30fc\u30b8\u306e\u30b7\u30f3\u30b0\u30eb \u30b5\u30a4\u30f3 \u30aa\u30f3 URL \u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">[Next] \u3092\u30af\u30ea\u30c3\u30af\u3057\u3001[<strong>Relying Party Trust Identifier<\/strong>] \u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u304a\u3088\u3073 index.php \u30ea\u30f3\u30af\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u4ed6\u306e\u3059\u3079\u3066\u306e\u30da\u30fc\u30b8\u3067 [Next] \u3092\u30af\u30ea\u30c3\u30af\u3057\u3001\u8981\u4ef6\u306b\u5408\u308f\u305b\u3066\u8a2d\u5b9a\u3092\u884c\u3044\u3001[Finish] \u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Relying Party Trust \u306b Following Edit Claim Rules \u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/span>\n<ol class=\"list-colored\">\n<li style=\"font-weight: 400;\" aria-level=\"1\"><strong>\u30eb\u30fc\u30eb 1:<\/strong>\n<ul class=\"list-colored\">\n<li aria-level=\"2\">\u8981\u6c42\u30eb\u30fc\u30eb \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u300c<strong>LDAP \u5c5e\u6027\u3092\u8981\u6c42\u3068\u3057\u3066\u9001\u4fe1<\/strong>\u300d\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/li>\n<li aria-level=\"2\">\u30eb\u30fc\u30eb\u540d\u3092\u5165\u529b\u3057\u3001\u5c5e\u6027\u30b9\u30c8\u30a2\u3068\u3057\u3066 <strong>Active Directory<\/strong> \u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/li>\n<li aria-level=\"2\">\u6b21\u306e\u3088\u3046\u306b LDAP \u5c5e\u6027\u3092\u51fa\u529b\u65b9\u5411\u306e\u8981\u6c42\u306b\u30de\u30c3\u30d4\u30f3\u30b0\u3057\u307e\u3059 (Active Directory Users \u304a\u3088\u3073 Computers \u3067\u3001\u30e6\u30fc\u30b6\u30fc\u306b\u5bfe\u3057\u3066\u8868\u306e\u3059\u3079\u3066\u306e\u8a73\u7d30\u304c\u5165\u529b\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059)\u3002<br \/>\n<table class=\"table table--hover\" style=\"border-collapse: collapse; width: 100%; height: 132px;\">\n<thead>\n<tr style=\"height: 22px;\">\n<th style=\"height: 22px;\">LDAP \u5c5e\u6027<\/th>\n<th style=\"height: 22px;\">\u51fa\u529b\u65b9\u5411\u306e\u8981\u6c42\u30bf\u30a4\u30d7<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 22px;\">\n<td style=\"height: 22px;\">User-Principal-Name<\/td>\n<td style=\"height: 22px;\">UPN<\/td>\n<\/tr>\n<tr style=\"height: 22px;\">\n<td style=\"height: 22px;\">Given-Name<\/td>\n<td style=\"height: 22px;\">Given Name<\/td>\n<\/tr>\n<tr style=\"height: 22px;\">\n<td style=\"height: 22px;\">Surname<\/td>\n<td style=\"height: 22px;\">Surname<\/td>\n<\/tr>\n<tr style=\"height: 22px;\">\n<td style=\"height: 22px;\">E-Mail-Addresses<\/td>\n<td style=\"height: 22px;\">E-Mail Address<\/td>\n<\/tr>\n<tr style=\"height: 22px;\">\n<td style=\"height: 22px;\">Display-Name<\/td>\n<td style=\"height: 22px;\">Name<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/li>\n<li aria-level=\"2\">\u30eb\u30fc\u30eb\u3092\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<\/li>\n<li aria-level=\"2\"><strong>\u30eb\u30fc\u30eb 2:<\/strong>\n<ol class=\"list-colored\">\n<li aria-level=\"2\"><span style=\"font-weight: 400;\">\u8981\u6c42\u30eb\u30fc\u30eb \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8 -&gt;<\/span><strong>\u5165\u529b\u65b9\u5411\u306e\u8981\u6c42\u3092\u5909\u63db\u3059\u308b<\/strong>\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002<\/li>\n<li aria-level=\"2\">\u8981\u6c42\u30eb\u30fc\u30eb\u540d\u3092\u5165\u529b\u3057\u307e\u3059\u3002<\/li>\n<li aria-level=\"2\">\u30eb\u30fc\u30eb \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u306b\u4ee5\u4e0b\u306e\u5024\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002\n<ul>\n<li><strong>Incoming Claim Type<\/strong> : UPN<\/li>\n<li><strong>Incoming Name ID Format<\/strong> : Unspecified<\/li>\n<li><strong>Outgoing Claim Type<\/strong> : Name ID<\/li>\n<li><strong>Outgoing Name ID Format<\/strong> : Email<\/li>\n<\/ul>\n<\/li>\n<li>[<strong>\u3059\u3079\u3066\u306e\u8981\u6c42\u306e\u5024\u306e\u30d1\u30b9\u30b9\u30eb\u30fc<\/strong>] \u3092\u30aa\u30f3\u306b\u3057\u3001<span style=\"font-weight: 400;\">\u30eb\u30fc\u30eb\u3092\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-weight: 400;\">[Primary Authentication] -&gt; [Global Setting] \u306e [<strong>Authentication Policy<\/strong>] <span style=\"font-weight: 400;\">\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002Authentication Method \u3092\u7de8\u96c6\u3057\u3001<\/span>[<strong>Extranet<\/strong>]<span style=\"font-weight: 400;\"> \u304a\u3088\u3073 <\/span>[<strong>Intranet<\/strong>] \u306e\u4e21\u65b9\u306b <strong>Forms Authentication<\/strong><span style=\"font-weight: 400;\"> \u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/span><\/span><\/li>\n<li><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><\/span><\/span><span style=\"font-weight: 400;\">TestRail \u306b\u30e6\u30fc\u30b6\u30fc\u3092\u8ffd\u52a0\u3057\u3001SSO for ADFS \u3092\u6709\u52b9\u306b\u3057\u307e\u3059\u3002<\/span>\n<ul start=\"10\">\n<li style=\"font-weight: 400;\" aria-level=\"1\">[<strong>\u30e6\u30fc\u30b6\u30fc\u3068\u30ed\u30fc\u30eb<\/strong>]<span> \u3067\u65b0\u898f\u30e6\u30fc\u30b6\u30fc\u3092\u8ffd\u52a0\u3057\u3001ADFS \u30b5\u30fc\u30d0\u30fc\u5074\u3068\u540c\u3058\u96fb\u5b50\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Single Sign-on (SSO) Authentication \u3092\u6709\u52b9\u306b\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">[Service] -&gt; [Certificate select] \u3067<\/span> [<strong>Token-Signing Certificate<\/strong>] \u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u8a3c\u660e\u66f8\u3092\u53f3\u30af\u30ea\u30c3\u30af\u3057\u3066\u8868\u793a\u3057\u3001\u8a73\u7d30\u30bf\u30d6\u306e <\/span>[<strong>Copy to File<\/strong>] <span style=\"font-weight: 400;\">\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u8a3c\u660e\u66f8\u3092\u4efb\u610f\u306e\u5834\u6240\u306b\u4fdd\u5b58\u3057\u3001\u8a3c\u660e\u66f8\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u304c <\/span><strong>Base-64 encoded X.509 (.CER)<\/strong> \u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TestRail \u306b\u8a3c\u660e\u66f8\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u30b5\u30fc\u30d0\u30fc\u306e FQDN \u5024\u3092 <\/span>[<strong>IDP Issuer URL<\/strong>] <span style=\"font-weight: 400;\"> \u306b\u30b3\u30d4\u30fc\u3057\u3001\/adfs\/ls \u3092\u4ed8\u52a0\u3057\u307e\u3059\u3002<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h2><strong>SAML Assertion Encryption \u306e\u8a2d\u5b9a<\/strong><\/h2>\n<ol class=\"list-colored\">\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u8a2d\u5b9a\u3055\u308c\u305f\u79d8\u5bc6\u9375\u306b\u5bfe\u5fdc\u3059\u308b\u516c\u958b\u9375\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u516c\u958b\u9375\u306f X.509 \u8a3c\u660e\u66f8\u30d5\u30a1\u30a4\u30eb\u306b .cer \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3067\u4fdd\u5b58\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Relying Party Trust \u306e\u6697\u53f7\u5316\u30bf\u30d6\u306b\u8a3c\u660e\u66f8\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TestRail \u306e SSO \u8a2d\u5b9a\u3067\u6697\u53f7\u5316\u30a2\u30b5\u30fc\u30b7\u30e7\u30f3\u3092\u6709\u52b9\u5316\u3057\u307e\u3059\u3002<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u624b\u9806 1 \u3067\u53d6\u5f97\u3057\u305f\u79d8\u5bc6\u9375\u3092\u30b3\u30d4\u30fc\u3057\u307e\u3059\u3002<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>TestRail \u306e SSO \u6a5f\u80fd\u3092\u5229\u7528\u3059\u308b\u3068\u3001SAML 2.0\u3001OAuth 2.0 \u304a\u3088\u3073 OpenID Connect \u30d7\u30ed\u30c8\u30b3\u30eb\u3092\u4f7f\u7528\u3059\u308b\u4efb\u610f\u306e SSO ID \u30d7\u30ed\u30d0\u30a4\u30c0\u30fc (IDP) \u3068 TestRail \u3092\u7d71\u5408 [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":14692,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"class_list":["post-17023","page","type-page","status-publish","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/pages\/17023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/comments?post=17023"}],"version-history":[{"count":15,"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/pages\/17023\/revisions"}],"predecessor-version":[{"id":23425,"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/pages\/17023\/revisions\/23425"}],"up":[{"embeddable":true,"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/pages\/14692"}],"wp:attachment":[{"href":"https:\/\/docs.testrail.techmatrix.jp\/testrail\/docs\/9\/wp-json\/wp\/v2\/media?parent=17023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}