We've put together a glossary of identity terms for newcomers and seasoned developers, alike. Hopefully this helps put any identity terminology confusion to rest.
ãã°ã€ã³è©Šè¡ãä¿¡é Œæ§ã®äœããã°ã€ã³ã§ãããšå€æãããå Žåã«ã®ã¿ããŠãŒã¶ãŒã«å¯ŸããŠããªã¬ãŒãããå€èŠçŽ èªèšŒïŒMFAïŒãAuth0ã¯Adaptive MFAã䜿çšããŠãæ£åœãªãŠãŒã¶ãŒã®ãã°ã€ã³ãšã¯ã¹ããªãšã³ã¹ãå€ããã«ç¶æããªãããäžæ£è ã«å¯ŸããŠã»ãã¥ãªãã£ã匷åããå¿ èŠãããå Žåã«ã®ã¿MFAãããªã¬ãŒããŸãã
Auth0ã®ãã©ã€ããªç®¡çè ã€ã³ã¿ãŒãã§ã€ã¹ã§ãã¢ããªã±ãŒã·ã§ã³ãŸãã¯APIãç»é²ãããŠãŒã¶ãŒã¹ãã¢ãŸãã¯å¥ã®IDãããã€ããŒã«æ¥ç¶ããŠãAuth0ãµãŒãã¹ãæ§æã§ããŸãã
åã ã®ãŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³å ã®ç¹å®ã®ãªããžã§ã¯ããŸãã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ããAuth0ã®SaaS補åã
ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®ãã®ã§ã¯ãªããã¯ã©ã€ã¢ã³ãèªäœã察象ãšããè³æ Œæ å ±ãã¯ã©ã€ã¢ã³ããè§£æããã³æ€èšŒã§ããåºå®åœ¢åŒã§ãã
ããžã¿ã«IDãä¿åããã³ç®¡çãããµãŒãã¹ãAuth0ã¯ãä¿¡é Œã§ãããœãŒã·ã£ã«IDãããã€ããŒããšã³ã¿ãŒãã©ã€ãºIDãããã€ããŒãããã³æ³çIDãããã€ããŒããµããŒãããŠããŸããAuth0ã¯ãã¢ããªã±ãŒã·ã§ã³ã®IDãããã€ããŒãšããŠãæ©èœããŸãã
äºè éã®ã¯ã¬ãŒã ãå®å šã«è¡šçŸããããã®ããªãŒãã³ãã€æ¥çæšæºã®RFC 7519æ¹æ³ãAuth0ã§ã¯ãIDããŒã¯ã³ã¯åžžã«JWT圢åŒã§è¿ãããã¢ã¯ã»ã¹ããŒã¯ã³ãå€ãã®å ŽåãJWT圢åŒã§è¿ãããŸããJWT.ioã§æŽåœ¢åŒã®JWTããã³ãŒãããŠãã¯ã¬ãŒã ã衚瀺ã§ããŸãã
ãŠãŒã¶ãŒãèªèšŒããããã®Auth0ã®UIãŠã£ãžã§ãããããã¯ãã®ãŸãŸäœ¿çšã§ããã¯ã©ã·ãã¯ãŠãããŒãµã«ãã°ã€ã³ãšã¯ã¹ããªãšã³ã¹ã®ããã©ã«ãã®é¡ã§ããLockã䜿çšãããšã现ããåäœãå€èгã®ãªãã·ã§ã³ãã«ã¹ã¿ãã€ãºã§ããŸããããã®äž»ãªç®çã¯äœ¿ããããã§ãã
Auth0ãµãŒãã¹ã管çããããã°ã©ã ã«åŸã£ãŠç®¡çã¿ã¹ã¯ãå®è¡ããããã®Auth0ã®APIã
èªèšŒãããã³ã«ã§çºè¡ãããä»»æã®æ°å€ïŒå€ãã®å Žåãä¹±æ°ãŸãã¯æ¬äŒŒä¹±æ°ïŒã§ãæ§åŒã®éä¿¡ã䜿çšãããªãã¬ã€æ»æã®æ€åºãšè»œæžã«äœ¿çšã§ããŸããnonceã¯1åããçºè¡ãããªããããæ»æè ãå¥ã®nonceã䜿çšããŠãã©ã³ã¶ã¯ã·ã§ã³ãåå®è¡ããããšãããšããã®èª€ã£ããã©ã³ã¶ã¯ã·ã§ã³ãããç°¡åã«æ€åºã§ããŸãã
èªå¯ãããã³ã«ãšã¯ãŒã¯ãããŒãå®çŸ©ããèªå¯ãã¬ãŒã ã¯ãŒã¯ãOAuth 2.0ã¯ãããŒã«ãèªå¯ä»äžïŒãŸãã¯ã¯ãŒã¯ãããŒïŒãèªå¯èŠæ±ãšå¿çãããã³ããŒã¯ã³åŠçãå®çŸ©ããŸãããŠãŒã¶ãŒIDãæ€èšŒããOpenID ConnectïŒOIDCïŒãããã³ã«ã«ãã£ãŠãOAuth 2.0ãæ¡åŒµã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒã®ãã°ã€ã³æ å ±ãåéããã³ä¿åããããšãªãïŒãããã£ãŠããŠãŒã¶ãŒã®ãã°ã€ã³æ å ±ã«ã€ããŠè²¬ä»»ãè² ããã«ïŒããŠãŒã¶ãŒãæ¬äººã§ããããšã確èªã§ããèªèšŒçšã®ãªãŒãã³æšæºã
B2B顧客ããšã³ããŠãŒã¶ãŒãåé¡ããç¹å®ã®ããŒã«ããã°ã€ã³ãšã¯ã¹ããªãšã³ã¹ãããã³ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå®çŸ©ã§ããããã«ããAuth0補åã
ãã¹ã¯ãŒãã䜿çšããã«äºè éã§èªèšŒæ å ±ã亀æã§ããXMLããŒã¹ã®æšæºåãããã³ã«ã
WS-Trustã䜿çšããŠä¿¡é Œã確ç«ãããŠããã·ã¹ãã ããã¡ã€ã³ãããã³IDãããã€ããŒã®éã§ãŠãŒã¶ãŒIDã管çããããã®ãããã³ã«ããã®ãããã³ã«ã¯äž»ã«Microsoft補åã«äœ¿çšããããã§ãã¬ãŒã·ã§ã³ã¡ã¿ããŒã¿ã®å ±ææ¹æ³ã«é¢ããããªã·ãŒãå®çŸ©ããŸãã
è³æ Œæ å ±ã1åæäŸããã ãã§ããŠãŒã¶ãŒãè€æ°ã®ãªãœãŒã¹ãã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ãè€æ°ã®ãã©ãããã©ãŒã éã§ãŠãŒã¶ãŒã¢ã«ãŠã³ããæ¥ç¶ããããšã
Auth0å®è¡äžã®ç¹å®ã®æç¹ã§å®è¡ããããNode.jsã§èšè¿°ãããå®å šãªé¢æ°ãããã¯ããã³ãåºæã§ãããããŒãžã§ã³ç®¡çãããŠããŸããã¢ã¯ã·ã§ã³ã¯ãã«ã¹ã¿ã ããžãã¯ã§Auth0ã®æ©èœãã«ã¹ã¿ãã€ãºããã³æ¡åŒµããããã«äœ¿çšãããŸãã
ã¢ããªã±ãŒã·ã§ã³ãAPIã«ã¢ã¯ã»ã¹ããããã«äœ¿çšã§ããè³æ Œæ å ±ãããã¯ãããŒã¯ã³ã®ãã¢ã©ãŒãAPIã«ã¢ã¯ã»ã¹ããä»äžãããã¹ã³ãŒãã§æå®ãããç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ããèš±å¯ãåŸãŠããããšãAPIã«éç¥ããŸããã¢ã¯ã»ã¹ããŒã¯ã³ã¯ä»»æã®åœ¢åŒã«ã§ããŸãããäžè¬çãª2ã€ã®ãªãã·ã§ã³ãšããŠãäžéæãªæååãšJSON WebããŒã¯ã³ïŒJWTïŒããããŸãããããã¯ãHTTPèªå¯ããããŒå ã®Bearerè³æ Œæ å ±ãšããŠAPIã«éä¿¡ãããå¿ èŠããããŸãã
èªèšŒãšID管çãè¡ãããã«Auth0ã«äŸåãããœãããŠã§ã¢ãAuth0ã¯ãã·ã³ã°ã«ããŒãžãéåžžã®Webããã€ãã£ããããã³ãã·ã³ããŒãã·ã³ã®ã¢ããªã±ãŒã·ã§ã³ããµããŒãããŠããŸãã
çºè¡ãããããŒã¯ã³ã«å¯ŸãããªãŒãã£ãšã³ã¹ã衚ãäžæã®èå¥åã§ãJSON WebããŒã¯ã³å
ã§audã¯ã¬ãŒã ãšããŠç¹å®ããããã®ããªãŒãã£ãšã³ã¹å€ã¯ãIDããŒã¯ã³ã®å Žåã¯ã¢ããªã±ãŒã·ã§ã³ïŒClient ID
ïŒãã¢ã¯ã»ã¹ããŒã¯ã³ã®å Žåã¯åŒã³åºãããAPIïŒAPI Identifier
ïŒã®ããããã§ããAuth0ã§ã¯ãã¢ã¯ã»ã¹ããŒã¯ã³ã®èŠæ±ã§éä¿¡ããããªãŒãã£ãšã³ã¹å€ã«ãã£ãŠãããŒã¯ã³ãäžéæåœ¢åŒã§è¿ããããJWT圢åŒã§è¿ãããããæ±ºãŸããŸãã
ç¹æ®ãªååããŸãã¯ãããã£åãæã€ãµãŒãããŒãã£ã®ãã¡ã€ã³ãCNAMEãšãåŒã°ããŸãã
ç»é²åŸã«ã¢ããªã±ãŒã·ã§ã³ã«å²ãåœãŠãããèå¥å€ããã®å€ã¯ä»ã®ãµãŒãããŒãã£ãŒãµãŒãã¹ãšçµã¿åãããŠäœ¿çšãããAuth0 Dashboard > Application SettingsïŒã¢ããªã±ãŒã·ã§ã³èšå®ïŒïŒœã§ç¢ºèªã§ããŸãã
ã¯ã©ã€ã¢ã³ãïŒã¢ããªã±ãŒã·ã§ã³ïŒãèªå¯ãµãŒããŒã§èªèšŒããããã«äœ¿çšããã·ãŒã¯ã¬ãããããã¯ã¯ã©ã€ã¢ã³ããšèªå¯ãµãŒããŒã ããç¥ã£ãŠãããã®ã§ãããæšæž¬ã§ããªãããã«ååã«ã©ã³ãã ã§ããå¿ èŠããããŸãã
ã»ãã¥ãªãã£ããŒã¯ã³ã«ããã±ãŒãžåããã屿§ã§ãããŒã¯ã³ã®ãããã€ããŒããšã³ãã£ãã£ã«é¢ããŠè¡ã£ãŠããã¯ã¬ãŒã ã衚ããŸãã
1人以äžã®ãŠãŒã¶ãŒã®ã»ãããAuth0èªå¯æ¡åŒµæ©èœã§ã¯ãã°ã«ãŒãã䜿çšããŠãäžåºŠã«å€ãã®ãŠãŒã¶ãŒã«ã¢ã¯ã»ã¹ãèš±å¯ããŸãã
èªèšŒåŸã«Auth0ãå¿çãéä¿¡ããå ã®URLãå€ãã®å ŽåãèªèšŒåŸã«ãŠãŒã¶ãŒããªãã€ã¬ã¯ããããURLãšåãã§ãã
åããã³ãã§äœ¿çšã§ããæ©èœãå²ãåœãŠãå®çŸ©ããå¥çŽãAuth0ã«ã¯ãããŸããŸãªéçºè ãçµç¹ã®ããŒãºãæºããããã«è€æ°ã®ãµãã¹ã¯ãªãã·ã§ã³ã¬ãã«ããããŸãã
å¯Ÿè±¡ã®æ©èœãŸãã¯åäœããã©ãããã©ãŒã ããåé€ãããããšã瀺ã補åãªãªãŒã¹æ®µéããã®æ©èœãŸãã¯åäœãç¶ããŠäœ¿çšãããšããããããšã©ãŒãçºçããŸããæ°ããåäœã¯ãç§»è¡æéäžã«ãªããã€ã³ããªãã£ãããã³ãã«å¯ŸããŠèªåçã«æå¹ã«ãªããŸãã
æ©èœãŸãã¯åäœãžã®ã¢ã¯ã»ã¹ããã©ãããã©ãŒã ããåé€ãããæ¥ä»ããµããŒãçµäºæ¥ã¯ããã©ã³ã®ã¿ã€ãã«ãã£ãŠç°ãªãå ŽåããããŸãã
ãªã¢ãŒãã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããå¿ èŠããããŠãŒã¶ãŒãåå¥ã«ãããŒã«ã«ãã£ã¬ã¯ããªãããªã¢ãŒããã£ã¬ã¯ããªã«æåã§ããããžã§ãã³ã°ããïŒå®è³ªçã«å ã®ã¢ã«ãŠã³ãã®ã³ããŒãããªãã¡ã·ã£ããŒãäœæããïŒãç¶ç¶ããã®ãå°é£ãªæ¹æ³ã
ãŠãŒã¶ãŒã1ã€ã®ã¢ããªã±ãŒã·ã§ã³ã«ãã°ã€ã³ããåŸããã®ãŠãŒã¶ãŒã䜿çšããŠãããã©ãããã©ãŒã ããã¯ãããžãŒããã¡ã€ã³ã«é¢ä¿ãªãããã®ãŠãŒã¶ãŒãä»ã®ã¢ããªã±ãŒã·ã§ã³ã«èªåçã«ãã°ã€ã³ããããµãŒãã¹ããŠãŒã¶ãŒã¯1åã ããµã€ã³ã€ã³ããŸãïŒããããã®æ©èœã®ååã®ç±æ¥ã§ãïŒãåæ§ã«ãã·ã³ã°ã«ãã°ã¢ãŠãïŒSLOïŒã¯ããŠãŒã¶ãŒã1ã€ã®ã¢ããªã±ãŒã·ã§ã³ãããã°ã¢ãŠãããåŸããã°ã€ã³ããŠããåã¢ããªã±ãŒã·ã§ã³ãŸãã¯ãµãŒãã¹ãããã°ã¢ãŠãããããšãã«çºçããŸããSSOãšSLOã¯ã»ãã·ã§ã³ã䜿çšããããšã§å¯èœã«ãªããŸãã
ã¢ããªã±ãŒã·ã§ã³ãå®è¡ã§ããç¹å®ã®ã¢ã¯ã·ã§ã³ããŸãã¯ãŠãŒã¶ãŒã«ä»£ãã£ãŠã¢ããªã±ãŒã·ã§ã³ãèŠæ±ã§ããæ å ±ãå®çŸ©ããã¡ã«ããºã ãå€ãã®å Žåãã¢ããªã±ãŒã·ã§ã³ã¯ããªã³ã©ã€ã³ãªãœãŒã¹ã§ãã§ã«äœæãããŠããæ å ±ãå©çšããããšããŸãããã®ããã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã¯ãŠãŒã¶ãŒã«ä»£ãã£ãŠãã®æ å ±ã«ã¢ã¯ã»ã¹ããããã®èªå¯ãæ±ããå¿ èŠããããŸããã¢ããªãèªå¯ãµãŒããŒçµç±ã§ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹èš±å¯ãèŠæ±ããå Žåããã®ã¢ããªã¯ã¹ã³ãŒããã©ã¡ãŒã¿ãŒã䜿çšããŠå¿ èŠãªã¢ã¯ã»ã¹ãæå®ããèªå¯ãµãŒããŒã¯ã¹ã³ãŒããã©ã¡ãŒã¿ãŒã䜿çšããŠå®éã«ä»äžãããã¢ã¯ã»ã¹ã§å¿çããŸãã
ãŠãŒã¶ãŒãæ£åžžã«èªèšŒãããããšã蚌æããããã«äœ¿çšããããããžã¿ã«çœ²åãããã¢ãŒãã£ãã¡ã¯ãã
åä¿¡ããŠããããŒã¯ã³ã眲åãããæå¹ã§ãããä¿¡é Œã§ãããœãŒã¹ïŒIDãããã€ããŒïŒããã®ãã®ã§ããããšãããã«ãŠã§ã¢ã確èªããåŸã«ãããã«ãŠã§ã¢ã«ãã£ãŠçºè¡ããããšã³ãã£ãã£ããã®ãšã³ãã£ãã£ã¯ãIDãããã€ããŒã«ããèªèšŒãæåãããšããäºå®ã衚ããŸããã¯ãããŒãååšããéããŠãŒã¶ãŒãèªèšŒãããŠãããšã¿ãªããããããããŒã¯ã³ã䜿çšãããã®ããã»ã¹ãç¶ç¶çã«ç¹°ãè¿ãå¿ èŠããªããªããŸãã
ãŠãŒã¶ãŒã®äžå€®ãªããžããªïŒæãããç¥ãããŠããã®ã¯Active DirectoryïŒãè³æ Œæ å ±ãšå±æ§ãäžå 管çã§ãããããåã¢ããªã±ãŒã·ã§ã³ãããããç¬èªã®ããŒã«ã«IDèšå®ããŠãŒã¶ãŒã®ããŒã«ãæã€å¿ èŠããªããªããŸããåããŠãŒã¶ãŒãã£ã¬ã¯ããªã䜿çšãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããã·ã³ã°ã«ãµã€ã³ãªã³ã§ããŸãã
ç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠæäŸãããæ©èœã®ã³ã³ããã¹ãã§ç¹å®ã®ãŠãŒã¶ãŒãå®çŸ©ãã屿§ã®ã»ããã
ããŒã¯ã³å ã®æ å ±ãæ¹ããããä¿è·ããæå·åãããæååããããã®æ å ±ã倿ŽãŸãã¯æ¹ããããããšã眲åã¯æ€èšŒã§ããªããªããæåŠãããŸãã
Auth0ã§ã¯ãåäžã®ãœãããŠã§ã¢ã€ã³ã¹ã¿ã³ã¹ã«å¯ŸããŠç¹å®ã®æš©éãããã¢ã¯ã»ã¹ãå ±æãããè«ççã«åé¢ããããŠãŒã¶ãŒã®ã°ã«ãŒãã®ããšãè€æ°ã®ããã³ããåããã·ã³äžã§å®è¡ããŠããå Žåã§ãããã®äžã®1ã€ã®ããã³ããå¥ã®ããã³ãã®ããŒã¿ã«ã¢ã¯ã»ã¹ããããšã¯ã§ããŸãããäžè¬ã«ãããã³ãã¯ããœãããŠã§ã¢ãã«ãããã³ãã¢ãŒããã¯ãã£ããåçšãããçšèªã§ãã
ããã°ã©ã ã«åŸã£ãŠããŒã¯ã³ãèŠæ±ããããã«äœ¿çšãããèªå¯ãµãŒããŒäžã®ãšã³ããã€ã³ãã
ãŠãŒã¶ãŒã®ãã°ã€ã³ãªã©ã®ç¹å®ã®æäœãå®è¡æã«çºçãããšãã«ãã¢ã¯ã·ã§ã³ãèªåçã«åŒã³åºãã€ãã³ããè€æ°ã®ããªã¬ãŒãåæã«å®è¡ãããé¢äžãããããŒããããã¯ãããã®ããããŸãããåæã«ã¯å®è¡ãããªããã®ããããŸãã
æåã®èŠçŽ ããã¹ã¯ãŒãã§ã¯ãªãèªèšŒã®åœ¢åŒã代ããã«ãã¡ãŒã«ãSMSãããã·ã¥éç¥ããŸãã¯çäœèªèšŒã»ã³ãµãŒã§åä¿¡ããã¯ã³ã¿ã€ã ãã¹ã¯ãŒãã䜿çšã§ããŸãããã¹ã¯ãŒãã¬ã¹ã§ã¯ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãã䜿çšãããããããŠãŒã¶ãŒã¯åŸæ¥ã®ãŠãŒã¶ãŒå/ãã¹ã¯ãŒãã«ãããã°ã€ã³ã«æ¯ã¹ãŠãäžè¬çãªãã¹ã¯ãŒãããŒã¹ã®æ»æïŒèŸæžãè³æ Œæ å ±ã®ã¹ã¿ããã£ã³ã°ãªã©ïŒã®åœ±é¿ãåãã«ãããªããŸãã
ãµãŒãããŒãã£ã®Webãµã€ããŸãã¯ã¢ããªã§ã®ããŒã¿æŒæŽ©ã§äŸµå®³ããããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®çµã¿åããããŠãŒã¶ãŒã䜿çšããå Žåã«ãAuth0ããŠãŒã¶ãŒã«éç¥ããæ»æé²åŸ¡ã®åœ¢åŒã
OAuth 2.0ãããã³ã«ã«ãããšãã¯ã©ã€ã¢ã³ãïŒã¢ããªã±ãŒã·ã§ã³ïŒã¯ãè³æ Œæ å ±ïŒã¯ã©ã€ã¢ã³ãIDãã·ãŒã¯ã¬ãããªã©ïŒãå®å šã«ä¿æã§ãããã©ããã«å¿ããŠãæ©å¯ãŸãã¯ãããªãã¯ã«åé¡ã§ããŸãããããªãã¯ã¯ã©ã€ã¢ã³ãã¯è³æ Œæ å ±ãå®å šã«ä¿æã§ããªããããã¯ã©ã€ã¢ã³ãã·ãŒã¯ã¬ããã®äœ¿çšãå¿ èŠãšããªãä»äžã¿ã€ãã®ã¿ã䜿çšããå¿ èŠããããŸãããããªãã¯ã¯ã©ã€ã¢ã³ãã«çºè¡ãããIDããŒã¯ã³ã¯ãç§å¯éµïŒRS256ïŒã䜿çšããŠé察称ã«çœ²åãããããŒã¯ã³ã®çœ²åã«äœ¿çšãããç§å¯éµã«å¯Ÿå¿ããå ¬ééµã䜿çšããŠæ€èšŒãããå¿ èŠããããŸãã
ã¢ã¯ã·ã§ã³ã䜿çšããŠæ¡åŒµã§ããããã»ã¹ãåãããŒã¯ãããã1ã€ä»¥äžã®ããªã¬ãŒã§æ§æãããAuth0æé ã®åäžãã€ã³ãäžã«æ å ±ãç§»åããè«çãã€ãã©ã€ã³ã衚ããŸãã
äžè¬æäŸïŒGAïŒçã«å ç«ã£ãŠãå¯Ÿè±¡ã®æ©èœãŸãã¯åäœããµãã¹ã¯ã©ã€ããŒã«æäŸãããæçµçãªãã£ãŒãããã¯ãæäŸããªããæ°è£œåã®æ©èœãåå³ããŠå°å ¥ããæéãäžããã補åãªãªãŒã¹æ®µéãæ©èœé¢ã§ã¯ãå®å šãªã³ãŒãã䜿ãããå®å®ããŠãããããŸããŸãªã·ããªãªã§åœ¹ç«ã¡ãŸãããŸããGAçã«ãããåè³ªã®æåŸ ã«å¿ããŠããããŸãã¯ã»ãŒå¿ããŠãããšèããããŸããããŒã¿çã¯ãéžã°ããäžæ¡ãã®ãµãã¹ã¯ã©ã€ããŒã«å¶éããããšãïŒãã©ã€ããŒãïŒããã¹ãŠã®ãµãã¹ã¯ã©ã€ããŒã«æäŸããããšãã§ããŸãïŒãããªãã¯ïŒã
Auth0ããã°ã€ã³ããã»ã¹äžã«CAPTCHAãæå¹ã«ããããšã§ãçãããããããã©ãã£ãã¯ããããã¯ããæ»æé²åŸ¡ã®åœ¢åŒã
ç°å¢èšå®ããããã¡ã€ã«èšå®ãªã©ããŠãŒã¶ãŒãæŽæ°ã§ããæ å ±ãã¡ã¿ããŒã¿ã¯IDããŒã¯ã³ã«è¿œå ããããŠãŒã¶ãŒãããã¡ã€ã«ã«ä¿åã§ããŸãã
èŠæ±å ã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãåé€ãŸãã¯åŸ©å ããããšãAuth0ã®æ»æé²åŸ¡ã¹ã€ãŒãã®æ©èœïŒäŸµå®³ããããã¹ã¯ãŒãã®æ€åºããã«ãŒããã©ãŒã¹ä¿è·ãäžå¯©ãªIPã®ã¹ããããªã³ã°ïŒãæããŸããåãµãŒãã¹ã¯ãã°ã€ã³/ãµã€ã³ã¢ããã®åŸåãè©äŸ¡ããçãããã¢ã¯ãã£ããã£ã«é¢é£ä»ããããIPã¢ãã¬ã¹ããããã¯ããŸãã
Auth0ã«ããèªèšŒãããŒã®å®è£ ã§ãããã¯èªå¯ãµãŒããŒã®äž»èŠãªæ©èœã§ãããŠãŒã¶ãŒã®æ¬äººèšŒæãå¿ èŠã«ãªããã³ã«ãã¢ããªã±ãŒã·ã§ã³ã¯ãŠãããŒãµã«ãã°ã€ã³ã«ãªãã€ã¬ã¯ããããAuth0ããŠãŒã¶ãŒã®ã¢ã€ãã³ãã£ãã£ãä¿èšŒããããã«å¿ èŠãªåŠçãè¡ããŸãã
ä¿è·ããããªãœãŒã¹ããã¹ããããµãŒããŒããªãœãŒã¹ãµãŒããŒã¯ä¿è·ããããªãœãŒã¹ã®èŠæ±ãåãå ¥ããå¿çããŸãã
ä¿è·ããããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ã§ãããšã³ãã£ãã£ïŒãŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãªã©ïŒã
æŽæ°ãããã¢ã¯ã»ã¹ããŒã¯ã³ãååŸããããã«äœ¿çšã§ããç¹æ®ãªããŒã¯ã³ãããã¯ããŠãŒã¶ãŒã«å床ãã°ã€ã³ã匷ããããšãªããæéåãã«ãªãã¢ã¯ã»ã¹ããŒã¯ã³ãæŽæ°ããå Žåã«äŸ¿å©ã§ãããªãã¬ãã·ã¥ããŒã¯ã³ã䜿çšãããšããªãã¬ãã·ã¥ããŒã¯ã³ããããã¯ãªã¹ãã«ç»é²ããããŸã§ããã€ã§ãæ°ããã¢ã¯ã»ã¹ããŒã¯ã³ãèŠæ±ã§ããŸãã
è匱æ§ãæå°éã«æããããã«ãªãã¬ãã·ã¥ããŒã¯ã³ãé »ç¹ã«çœ®ãæããæŠç¥ããªãã¬ãã·ã¥ããŒã¯ã³ã®ããŒããŒã·ã§ã³ã䜿çšãããšãã¢ããªã±ãŒã·ã§ã³ããªãã¬ãã·ã¥ããŒã¯ã³ã亀æããŠæ°ããã¢ã¯ã»ã¹ããŒã¯ã³ãååŸãããã³ã«ãAuth0ãæ°ãããªãã¬ãã·ã¥ããŒã¯ã³ãè¿ããŸãã
æ°ãããŠãããŒãµã«ãã°ã€ã³ãšã¯ã¹ããªãšã³ã¹ããµããŒããããŠããèšèªã§ã¬ã³ããªã³ã°ã§ããæ©èœã
ãŠãŒã¶ãŒãã·ã¹ãã ã«å¯ŸããŠå¿ èŠãšããã¢ã¯ã»ã¹ã®ã¬ãã«ã瀺ãããŠãŒã¶ãŒã«å²ãåœãŠããããŠãŒã¶ãŒã¢ã€ãã³ãã£ãã£ã®ã¢ã¹ãã¯ããããŒã«ã¯åºæ¬çã«æš©éã®éåã§ãã
å¯Ÿè±¡ã®æ©èœãŸãã¯åäœãå®å šã«æ©èœããïŒäŸ¡æ Œã¬ãã«ã«ãã£ãŠå¶éãããïŒãã¹ãŠã®ãµãã¹ã¯ã©ã€ããŒãæ¬çªç°å¢ã§äœ¿çšã§ãã補åãªãªãŒã¹æ®µéãæ°ãããªãªãŒã¹ãæ¢åã®æ©èœã眮ãæããå ŽåãAuth0ã¯åŒç€Ÿã®å»æ¢ããªã·ãŒã«åŸã£ãŠäžäœäºææ§ã®æéãæäŸããæ°ãããªãªãŒã¹ã®å°å ¥æéã確ä¿ã§ãããããã客æ§ã«éç¥ããŸãã
éåžžã«å€ãã®ã¢ã«ãŠã³ããã¿ãŒã²ããã«ãããåäžIPã¢ãã¬ã¹ããã®äžå¯©ãªãã°ã€ã³ããããã³ããä¿è·ããæ»æé²åŸ¡ã®åœ¢åŒã
è åšã¢ã¯ã¿ãŒãšãåŒã°ããŸãã害ãåãŒãæå³ããã£ãŠããžãã¹ãŸãã¯ç°å¢ã«è åšãäžãããšã³ãã£ãã£ïŒå人ãŸãã¯ã°ã«ãŒãïŒãããŒã¿ã»ã³ã¿ãŒãžã®äŸµå ¥ãããçãŸããè³æ Œæ å ±ã«ããã·ã¹ãã ãžã®ãããã³ã°ãŸã§ã被害ã«ã¯ç©ççããã³ãµã€ããŒäžã®æå®³ãå«ãŸããå¯èœæ§ããããŸãã
IDãããã€ããŒãèªèšŒå±ããŠãŒã¶ãŒã«ã€ããŠèšåããããšããªãœãŒã¹ãååãã«ä¿¡ããå Žåããã®ãªãœãŒã¹ã¯ãã®IDãããã€ããŒãŸãã¯èªèšŒå±ãä¿¡é ŒããŠããŸãã
ãã£ã¬ã¯ããªããã®ãã¹ãŠã®ãŠãŒã¶ãŒãããã³ãã®ãã£ã¬ã¯ããªã䜿çšãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ãå²ãäžé£ã®å¢çãäžéšã®å®è£ ã§ã¯ããã®å¢çã¯ç©ççãªå ŽæãæããŸãããŸããVPNãä»ããŠæ¥ç¶ãããäžé£ã®ãããã¯ãŒã¯ãŸãã¯ããã€ã¹ãæãå ŽåããããŸãã
è€æ°ã®èŠçŽ ãèæ ®ããèªèšŒããã»ã¹ãéåžžãAuth0ã§ã¯ãæåã®èŠçŽ ã¯æšæºã®ãŠãŒã¶ãŒå/ãã¹ã¯ãŒã亀æã§ããã2çªç®ã®èŠçŽ ã¯ã¡ãŒã«ãŸãã¯SMSçµç±ã®ã³ãŒããŸãã¯ãªã³ã¯ãAuthyãGoogle Authenticatorãªã©ã®ã¢ããªçµç±ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããããã¯GuardianãDuoãªã©ã®é»è©±ã¢ããªçµç±ã®ããã·ã¥éç¥ã§ããè€æ°ã®èŠçŽ ã䜿çšããããšã§ããã¹ã¯ãŒããä»äººã®æã«æž¡ã£ãããæºåž¯é»è©±ãçãŸããããããªã©ãããããã®èŠçŽ ã誰ãã«ååŸãããå Žåã§ããã¢ã«ãŠã³ãã®å®å šæ§ãä¿ã€ããšãã§ããŸãã
å¯Ÿè±¡ã®æ©èœãŸãã¯åäœãæ°èŠãµãã¹ã¯ã©ã€ããŒã«ãã䜿çšããµããŒãããŠããªãããšã«å ããç©æ¥µçãªåŒ·åãè¡ãããããããã€æå°éã®ã¡ã³ããã³ã¹ããè¡ãããŠããªãããšã瀺ã補åãªãªãŒã¹æ®µéã廿¢ã®æç¹ã§ãã®æ©èœãŸãã¯åäœã䜿çšããŠããããã³ãã¯ãåŒãç¶ãã¢ã¯ã»ã¹ã§ããŸãã
Auth0ãšãã¢ããªã±ãŒã·ã§ã³ã®ãŠãŒã¶ãŒã®ãœãŒã¹ãšã®é¢ä¿ãäŸãšããŠãIDãããã€ããŒïŒGoogleãActive Directoryãªã©ïŒããã¹ã¯ãŒãã¬ã¹èªèšŒæ¹æ³ããŠãŒã¶ãŒããŒã¿ããŒã¹ãªã©ããããŸãã
ãã«ãŒããã©ãŒã¹ä¿è·ãäžå¯©ãªIPã®ã¹ããããªã³ã°ã䟵害ããããã¹ã¯ãŒãã®æ€åºããããæ€ç¥ãAdaptive Multi-factor Authenticationãªã©ãæ»æãæ€åºããŠè»œæžããããã«Auth0ãæäŸããæ©èœã
å¯Ÿè±¡ã®æ©èœãåäœãéãããæ°ã®ãµãã¹ã¯ã©ã€ããŒãŸãã¯é¡§å®¢éçºããŒãããŒïŒCDPïŒã«æäŸããããããã®ãµãã¹ã¯ã©ã€ããŒãŸãã¯CDPããã¹ããè¡ããä»åŸã®æ©èœã«é¢ãããã£ãŒãããã¯ãè¿ãããšãã§ãã補åãªãªãŒã¹æ®µéããã®æ®µéã§ã¯ãæ©èœããŸã 宿ããŠããªãå¯èœæ§ããããŸãããæ€èšŒã¯ã§ããŸãã
ãªãœãŒã¹ããŠãŒã¶ãŒã®ã¢ã€ãã³ãã£ãã£ã確èªã§ããããã«ããããŠãŒã¶ãŒãšãªãœãŒã¹ã®éã§åæãããå ±æã·ãŒã¯ã¬ãããŸãã¯äžé£ã®æ å ±ã
OAuth 2.0ãããã³ã«ã«ãããšãã¯ã©ã€ã¢ã³ãïŒã¢ããªã±ãŒã·ã§ã³ïŒã¯ãè³æ Œæ å ±ïŒã¯ã©ã€ã¢ã³ãIDãã·ãŒã¯ã¬ãããªã©ïŒãå®å šã«ä¿æã§ãããã©ããã«å¿ããŠãæ©å¯ãŸãã¯ãããªãã¯ã«åé¡ã§ããŸããæ©å¯ã¯ã©ã€ã¢ã³ãã¯ãè³æ Œæ å ±ãç¡èš±å¯ã®åœäºè ã«å ¬éããããšãªãå®å šãªæ¹æ³ã§ä¿æã§ãããã®ããã«ã¯ä¿¡é Œã§ããããã¯ãšã³ããµãŒããŒãå¿ èŠã§ãããããã®ã¯ã©ã€ã¢ã³ãã¯ãããŒã¯ã³ãšã³ããã€ã³ããåŒã³åºããšãã«ã¯ã©ã€ã¢ã³ãIDãšã·ãŒã¯ã¬ãããæå®ããŠèªèšŒããªããã°ãªããªãä»äžã¿ã€ãã䜿çšã§ãã察称ãŸãã¯é察称ã«çœ²åãããããŒã¯ã³ãçºè¡ãããããšãã§ããŸãã
ã¯ã©ã€ã¢ã³ããéå§ããããã¯ãã£ãã«èªèšŒãããŒã§ããŠãŒã¶ãŒããµãŒãã¹ãå©çšããã®ã«åœ¹ç«ã€ããã€ã¹ã
æ»æè ãã¯ã©ã€ã¢ã³ããŸãã¯ãµãŒãã¹ãéšããŠã¢ã¯ã·ã§ã³ãå®è¡ãããç¶æ³ã
Auth0ãç¥ãç¯å²ã§ãAuth0ãã©ãããã©ãŒã ãšé¡§å®¢ã¢ããªã±ãŒã·ã§ã³ã®çžäºéçšã«é害ãããããAuth0ãã©ãããã©ãŒã ãžã®å€æŽã
顧客ãç¹å®ã®æ©èœãåäœããé¢ããããã»ã¹ãç§»è¡ã¯ã補åãªãªãŒã¹ã®å»æ¢æ®µéã§è¡ãå¿ èŠããããŸãã
åäžã®IPã¢ãã¬ã¹ããçºçããåäžã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããã¿ãŒã²ãããšããç·åœããæ»æããä¿è·ããæ»æé²åŸ¡ã®åœ¢åŒã
ããŒã¯ã³ãäžæ£è ã«ãã£ãŠæ¹ãããããªãããã«ãããŒã¯ã³ã«ããžã¿ã«çœ²åããããã®ããã·ã¥ã¢ã«ãŽãªãºã ã
Auth0ãè£œåæ©èœãã©ã®ããã«èšç»ããªãªãŒã¹ã廿¢ãããã説æãããã§ãŒãºãè£œåæ©èœã¯ãã¹ãŠã®ãªãªãŒã¹æ®µéãçµãŠé²è¡ãããšã¯éãããåæ®µéã®æéã¯æ©èœã®ã¹ã³ãŒãã圱é¿åã«ãã£ãŠç°ãªããŸãã
ãŠãŒã¶ãŒãèªèšŒããããã«ãµãŒãããŒãã£ãŒã®IDãããã€ããŒã«äŸåãããšã³ãã£ãã£ïŒãµãŒãã¹ãã¢ããªã±ãŒã·ã§ã³ãªã©ïŒã
èªå¯ãµãŒããŒã«ãã£ãŠçæãããèªå¯å¿çã®äžéšãšããŠã¢ããªã±ãŒã·ã§ã³ã«è¿ãããã©ã³ãã ãªæååãèªå¯ã³ãŒãã®æå¹æéã¯æ¯èŒççããèªå¯ã³ãŒããããŒã®äœ¿çšæã«ïŒProof Key for Code ExchangeïŒPKCEïŒã®æç¡ã«ãããããïŒããŒã¯ã³ãšã³ããã€ã³ãã§ã¢ã¯ã»ã¹ããŒã¯ã³ãšäº€æãããŸãã
ãŠãŒã¶ãŒã«ããã¢ã¯ã»ã¹ã®éçãå®çŸ©ããããã«äœ¿çšãããéäžç®¡çåãµãŒããŒãããšãã°ãèªå¯ãµãŒããŒã¯ããŠãŒã¶ãŒãå©çšã§ããããŒã¿ãã¿ã¹ã¯ãæ©èœãå¶åŸ¡ã§ããŸããèªå¯ãµãŒããŒã«ãã£ãŠãŠãŒã¶ãŒãèªèšŒãããããšã¯ãããŸããããŠãŒã¶ãŒã®èº«å ã確èªããã®ã¯èªèšŒãµãŒããŒã®åœ¹å²ã§ãã
OAuth 2.0ã§æŠèª¬ãããŠããèªå¯ä»äžã®å¥åãèªå¯ãããŒã¯ããªãœãŒã¹ïŒã¢ããªã±ãŒã·ã§ã³ãŸãã¯APIïŒãèŠæ±å ã«ã¢ã¯ã»ã¹ãèš±å¯ããããã«äœ¿çšããã¯ãŒã¯ãããŒã§ãããã¯ãããžãŒã®ã¿ã€ãïŒããšãã°ãã¢ããªã±ãŒã·ã§ã³ãã¯ã©ã€ã¢ã³ãã·ãŒã¯ã¬ãããä¿åã§ããå ŽåïŒãšèŠæ±å ã®ã¿ã€ãã«åºã¥ããŠããªãœãŒã¹ææè ã¯èªå¯ã³ãŒããããŒãProof of Key Code ExchangeïŒPKCEïŒãResource Owner Password CredentialïŒROPGïŒãæé»ãããŒããŸãã¯ã¯ã©ã€ã¢ã³ãã®è³æ Œæ å ±ã䜿çšã§ããŸãã
ãŠãŒã¶ãŒã®ã¢ã€ãã³ãã£ãã£ã確èªãŸãã¯æåŠãããµãŒããŒãèªèšŒãµãŒããŒã«ãã£ãŠããŠãŒã¶ãŒãå©çšã§ããã¢ã¯ã·ã§ã³ããªãœãŒã¹ãå¶éãããããšã¯ãããŸããïŒãã ãããã®ç®çã§ã³ã³ããã¹ããæäŸããããšã¯å¯èœïŒã
ã¯ã©ã€ã¢ã³ããéå§ããããã¯ãã£ãã«èªèšŒãããŒå ã