ADFS์˜ ์ •์˜

Active Directory Federation Services(ADFS)๋Š” Microsoft์—์„œ ๊ฐœ๋ฐœํ•œ SSO(Single Sign-On) ์†”๋ฃจ์…˜์ž…๋‹ˆ๋‹ค. Windows Server ์šด์˜ ์ฒด์ œ์˜ ๊ตฌ์„ฑ์š”์†Œ๋กœ์„œ, ์‚ฌ์šฉ์ž์—๊ฒŒ Active Directory(AD)๋ฅผ ํ†ตํ•ด Integrated Windows Authentication(IWA)๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ธ์ฆ์„ ๋ฐ›์•„ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ADFS๋Š” ์œ ์—ฐ์„ฑ์„ ๋ชฉ์ ์œผ๋กœ ๊ฐœ๋ฐœ๋˜์–ด ๊ธฐ์—…์ด ์ง์› ๊ณ„์ •์„ ๊ด€๋ฆฌํ•˜๋Š” ๋™์‹œ์— ์‚ฌ์šฉ์ž ๊ฒฝํ—˜๊นŒ์ง€ ๊ฐ„์†Œํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ง์›๋“ค์€ SSO๋ฅผ ํ†ตํ•ด ์—ฌ๋Ÿฌ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์•ก์„ธ์Šคํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ž๊ฒฉ ์ฆ๋ช… ์„ธํŠธ ํ•˜๋‚˜๋งŒ ๊ธฐ์–ตํ•˜๋ฉดโ€ฆ

SAML์˜ ์ •์˜์™€ ์›๋ฆฌ

Security Assertion Markup Language์˜ ์ค„์ž„๋ง์ธ SAML์€ ์•„์ด๋ดํ‹ฐํ‹ฐ ๊ณต๊ธ‰์—…์ฒด(IdP)์—์„œ ์„œ๋น„์Šค ๊ณต๊ธ‰์—…์ฒด(SP)๋กœ ๊ถŒํ•œ ์ธ์ฆ ์ž๊ฒฉ ์ฆ๋ช…์„ ์ „๋‹ฌํ•  ๋•Œ ์‚ฌ์šฉ๋˜๋Š” ๊ฐœ๋ฐฉํ˜• ํ‘œ์ค€์ž…๋‹ˆ๋‹ค. ์‰ฝ๊ฒŒ ๋งํ•ด์„œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๊ฐ„ ์ปค๋ฎค๋‹ˆ์ผ€์ด์…˜์ด ์•ˆ์ „ํ•˜๊ฒŒ ์ด๋ฃจ์–ด์ง€๋ฏ€๋กœ ์‚ฌ์šฉ์ž๊ฐ€ ํ•œ ๊ฐœ์˜ ์ž๊ฒฉ ์ฆ๋ช… ์„ธํŠธ๋งŒ์œผ๋กœ๋„ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. SAML์˜ ์šฉ๋„์™€ ์›๋ฆฌ, ๊ทธ๋ฆฌ๊ณ  SAML์„ ์‚ฌ์šฉํ•˜๋Š” ๊ธฐ์—…์˜ ์ด์ ์— ๋Œ€ํ•ด ์ž์„ธํžˆ ์•Œ์•„๋ณด๊ธฐ์— ์•ž์„œ, ์ด๋Ÿฌํ•œ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ง€์›ํ•˜๋Š” SAML ๊ณต๊ธ‰์—…์ฒด์˜ ์œ ํ˜•๋ถ€ํ„ฐ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ๊ณต๊ธ‰์—…์ฒด์˜ ์œ ํ˜•์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. SAML ๊ณต๊ธ‰์—…์ฒด ์œ ํ˜• SAML์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์•„์ด๋ดํ‹ฐํ‹ฐ ๊ณต๊ธ‰์—…์ฒด์™€ ์„œ๋น„์Šคโ€ฆ

SCIM๋ž€?

SCIM(System for Cross-domain Identity Management)์€ ์‚ฌ์šฉ์ž ํ”„๋กœ๋น„์ €๋‹์„ ์ž๋™ํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐœ๋ฐฉํ˜• ํ‘œ์ค€์œผ๋กœ, ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ ๊ธฐ์ˆ ์˜ ๋„๋ž˜๊ฐ€ ๊ตฌ์ฒดํ™”๋˜๋˜ 2011๋…„์— ๊ฐœ๋ฐœ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. SCIM์€ ์•„์ด๋ดํ‹ฐํ‹ฐ ๊ณต๊ธ‰์—…์ฒด(์˜ˆ: ๋‹ค์ˆ˜์˜ ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž๊ฐ€ ์žˆ๋Š” ํšŒ์‚ฌ)์™€ ์‚ฌ์šฉ์ž ์•„์ด๋ดํ‹ฐํ‹ฐ ์ •๋ณด๊ฐ€ ํ•„์š”ํ•œ ์„œ๋น„์Šค ๊ณต๊ธ‰์—…์ฒด(์˜ˆ: ๊ธฐ์—… SaaS ์•ฑ) ๊ฐ„์— ์‚ฌ์šฉ์ž ์•„์ด๋ดํ‹ฐํ‹ฐ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. SCIM์„ ์‚ฌ์šฉํ•˜๋Š” ์ด์œ  ํ•œ ๋งˆ๋””๋กœ, SCIM์€ ์‚ฌ์šฉ์ž ์•„์ด๋ดํ‹ฐํ‹ฐ ์ˆ˜๋ช… ์ฃผ๊ธฐ ๊ด€๋ฆฌ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ž๋™ํ™”ํ•˜์—ฌ ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ์˜ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ณ  ์‚ฌ์šฉ์ž ๊ฒฝํ—˜์„ ๋‹จ์ˆœํ™”ํ•ฉ๋‹ˆ๋‹ค. ํšŒ์‚ฌ๊ฐ€ ์„ฑ์žฅ๊ณผ ํ˜์‹ ์„ ๊ฑฐ๋“ญํ•˜๋ฉด์„œ ์ง์› ์ด์ง๋ฅ ์ด ๋†’์•„์ง€๋‹คโ€ฆ

Introducing the Okta Secure Identity Commitment

Earlier today, Okta CEO Todd McKinnon sent the following email to Okta employees.  Hi Everyone, Last month Okta celebrated its 15th birthday. As Iโ€™ve reflected on this milestone, Iโ€™m incredibly proud of the progress weโ€™ve made together and the strides weโ€™ve taken to establish Okta as an iconic company. We power every Identity use case, we supportโ€ฆ

Tags

Archive

์šฐ๋ฆฌ๋ฅผ ๋”ฐ๋ฅด๋ผ
Share on Linkedin Share on Youtube