Docs Menu
Docs Home
/
MongoDB Ops Manager
/

SAML ์ธ์ฆ ์— ๋Œ€ํ•œ MongoDB Ops Manager ์‚ฌ์šฉ์ž ๊ตฌ์„ฑ MongoDB Ops Manager

์ด ํŽ˜์ด์ง€์˜ ๋‚ด์šฉ

  • ๊ณ ๋ ค ์‚ฌํ•ญ
  • ์ „์ œ ์กฐ๊ฑด
  • ์ ˆ์ฐจ

SAML(Security AssertionMarkup Language) ์„œ๋น„์Šค๋ฅผ ์‹คํ–‰ํ•˜๋Š” ID ์ œ๊ณต์ž(IdP)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Ops Manager ์‚ฌ์šฉ์ž ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ธ์ฆ๋œ ์„ธ์…˜ ์—†์ด Ops Manager๋กœ ์ด๋™ํ•˜๋ ค๊ณ  ํ•˜๋ฉด Ops Manager๋Š” ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ๋Š” IdP ๋กœ ์‚ฌ์šฉ์ž๋ฅผ ๋ณด๋ƒ…๋‹ˆ๋‹ค. ์ธ์ฆ์ด ์™„๋ฃŒ๋˜๋ฉด Ops Manager ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์œผ๋กœ ๋Œ์•„๊ฐ‘๋‹ˆ๋‹ค.

์ด ํŠœํ† ๋ฆฌ์–ผ์—์„œ๋Š” ๋‹ค์Œ ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

  • Ops Manager์— ๋Œ€ํ•œ SAML ์ธ์ฆ ๊ตฌ์„ฑ

  • SAML ๊ทธ๋ฃน์„ MongoDB Ops Manager ์กฐ์ง ์—ญํ•  ๋ฐ ํ”„๋กœ์ ํŠธ ์—ญํ• ์— ๋งคํ•‘ํ•ฉ๋‹ˆ๋‹ค.

SAML ์ธ์ฆ์„ ์‚ฌ์šฉํ•˜๋„๋ก Ops Manager ์ธ์Šคํ„ด์Šค๋ฅผ ๋ณ€๊ฒฝํ•˜๋ฉด ๋ชจ๋“  ์‚ฌ์šฉ์ž๋Š” ํ˜„์žฌ ์„ธ์…˜์— ๋กœ๊ทธ์ธ๋œ ์ƒํƒœ๋กœ ์œ ์ง€๋ฉ๋‹ˆ๋‹ค. ์ธ์ฆ ๋ณ€๊ฒฝ ํ›„ Ops Manager์— ๋กœ๊ทธ์ธํ•˜๋ ค๋Š” ์‚ฌ์šฉ์ž๋Š” SAML IdP ๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค.

SAML ์ธ์Šคํ„ด์Šค๋ฅผ ์„ค์ •ํ•  ๋•Œ ์ผ๋ถ€ ์ˆœํ™˜ ๋กœ์ง์ด ์ ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ž‘๋™ํ•˜๋Š” ํ†ตํ•ฉ์„ ๋งŒ๋“ค๋ ค๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•˜์„ธ์š”.

  • IdP ์—๋Š” ์„œ๋น„์Šค ์ œ๊ณต์ž์˜ ๊ฐ’์ด ํ•„์š”ํ•˜๋ฉฐ

  • ์„œ๋น„์Šค ์ œ๊ณต์ž๋Š” IdP ์˜ ๊ฐ’์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์ด ํ†ตํ•ฉ์„ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์ด ํŠœํ† ๋ฆฌ์–ผ์˜ ํ•„์ˆ˜ ๊ตฌ์„ฑ ์š”์†Œ์™€ ์ ˆ์ฐจ๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.

SAML ํ†ตํ•ฉ์„ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด SAML IdP ์— ๋Œ€ํ•ด ๋‹ค์Œ ์กฐ์น˜๋ฅผ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  1. SAML IdP ๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

  2. Ops Manager ์ธ์Šคํ„ด์Šค๊ฐ€ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด IdP ์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  3. SAML IdP ์—์„œ ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

    1. Ops Manager ์ „์—ญ ์†Œ์œ ์ž์— ๋งคํ•‘๋˜๋Š” SAML ์‚ฌ์šฉ์ž๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

    2. Ops Manager Global Owner ์— ๋งคํ•‘ํ•  ์ˆ˜ ์žˆ๋Š” SAML ๊ทธ๋ฃน์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

    3. Global Owner SAML ์‚ฌ์šฉ์ž์—๊ฒŒ SAML ๊ทธ๋ฃน์„ ํ• ๋‹นํ•ฉ๋‹ˆ๋‹ค.

    4. Ops Manager๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” Ops Manager์šฉ ์ƒˆ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    5. ์ด ์ƒˆ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•œ ์ดˆ๊ธฐ Ops Manager SAML ๊ฐ’์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

      1. ๋‹ค์Œ ํ•„๋“œ์— ์ž๋ฆฌ ํ‘œ์‹œ์ž ๊ฐ’์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค:

        • SP Entity ID or Issuer

        • Audience URI

        • Assertion Consumer Service (ACS) URL

      2. IdP ์—์„œ ๋‹ค์Œ ํ•„๋“œ์— ์‹ค์ œ ๊ฐ’์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

        ํ•„๋“œ
        ๊ณตํ†ต ๊ฐ’

        Signature Algorithm

        IdP ์—๋Š” ๋‹ค์Œ ๊ฐ’ ์ค‘ ํ•˜๋‚˜ ์ด์ƒ์ด ์žˆ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

        • rsa-sha1

        • dsa-sha1

        • rsa-sha256

        • rsa-sha384

        • rsa-sha512

        Name ID

        Email Address

        Name ID Format

        urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified

      3. ๋‹ค์Œ ์†์„ฑ ๊ฐ’์— ๋Œ€ํ•ด ์†์„ฑ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•˜์—ฌ ์†์„ฑ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

        • ์ด๋ฉ”์ผ ์ฃผ์†Œ

        • ์ด๋ฆ„

        • ์„ฑ

        • ์‚ฌ์šฉ์ž ๊ทธ๋ฃน

      4. ์„œ๋ช…๋œ SAML ์‘๋‹ต ๋ฐ ์–ด์„ค์…˜์„ ์š”๊ตฌํ•˜๋„๋ก IdP ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

      5. ์ด ๊ฐ’์„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

SAML ์ธ์ฆ์„ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

1
2

IdP ์—์„œ Ops Manager ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  1. Ops Manager ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ๊ฐ’์„ ์ฐพ์Šต๋‹ˆ๋‹ค.

  2. ๋‹ค์Œ ๊ฐ’์„ ์ž„์‹œ ํŒŒ์ผ์— ๋ณต์‚ฌํ•ฉ๋‹ˆ๋‹ค.

    • SAML Login URL

    • SAML Logout URL

    • X.509 Certificate ( IdP ์˜ ๊ฒฝ์šฐ)

    • IdP Entity ID or Issuer

    • Signature Algorithm

3

Ops Manager ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์—ด๊ณ  Admin ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. General Ops Manager Config User Authentication.

4
5

๋‹ค์Œ SAML ํ•„๋“œ์— ๋Œ€ํ•ด IdP ์˜ ๊ฐ’์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

ํ•„๋“œ
ํ•„์š”์„ฑ
์ž‘์—…
๊ธฐ๋ณธ๊ฐ’

ID ์ œ๊ณต์ž URI

ํ•„์ˆ˜ ์‚ฌํ•ญ

์‹ฑ๊ธ€ ์‚ฌ์ธ์˜จ์„ ์กฐ์ •ํ•  ๋•Œ ์‚ฌ์šฉํ•  IdP ์˜ URI ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด URI ๋Š” SAML IdP ์˜ IdP Entity ID or Issuer ์ž…๋‹ˆ๋‹ค.

์ด URI ๋Š” SAML ์‘๋‹ต์˜ Issuer URI ์™€ ๋™์ผํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

none

SSO ์—”๋“œํฌ์ธํŠธ URL

ํ•„์ˆ˜ ์‚ฌํ•ญ

IdP ์˜ ์‹ฑ๊ธ€ ์‚ฌ์ธ์˜จ URL ์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด URL ์€ IdP ์˜ SAML Login URL ์ž…๋‹ˆ๋‹ค.

none

SLO ์—”๋“œํฌ์ธํŠธ URL

์˜ต์…˜

Ops Manager ์‚ฌ์šฉ์ž๊ฐ€ Ops Manager์—์„œ ๋กœ๊ทธ์•„์›ƒํ•  ๋•Œ Ops Manager ์‚ฌ์šฉ์ž๊ฐ€ IdP ์—์„œ ๋กœ๊ทธ์•„์›ƒํ•˜๋„๋ก ํ•˜๋ ค๋ฉด ํ˜ธ์ถœํ•  SAML IdP URL ์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ IdP ์˜ SAML Logout URL ์ž…๋‹ˆ๋‹ค.

none

ID ์ œ๊ณต์ž X509 ์ธ์ฆ์„œ

ํ•„์ˆ˜ ์‚ฌํ•ญ

์ด ํ•„๋“œ์— IdP ์˜ X.509 ์ธ์ฆ์„œ๋ฅผ ๋ถ™์—ฌ๋„ฃ์Šต๋‹ˆ๋‹ค. IdP ๋Š” PEM ํ˜•์‹์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. -----BEGIN CERTIFICATE----- ํฌํ•จํ•˜์—ฌ ์‹œ์ž‘ํ•˜๊ณ  -----END CERTIFICATE----- ํฌํ•จํ•˜๊ณ  ๋๋‚˜๋Š” ์ „์ฒด ์ธ์ฆ์„œ ๋‚ด์šฉ์„ ํฌํ•จํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Ops Manager๋Š” ์ด ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ IdP ๋กœ ์ž์ฒด๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ IdP ์˜ X.509 Certificate ์ž…๋‹ˆ๋‹ค.

์ด๋Š” SAML ์‘๋‹ต ๋ฐ ์–ด์„ค์…˜์— ์„œ๋ช…ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ๊ณผ ๋™์ผํ•œ X.509 Certificate ์ด์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

none

ID ์ œ๊ณต์ž ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜

ํ•„์ˆ˜ ์‚ฌํ•ญ

IdP ์™€ ์ฃผ๊ณ ๋ฐ›๋Š” ์„œ๋ช…์„ ์•”ํ˜ธํ™”ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ํ—ˆ์šฉ๋˜๋Š” ๊ฐ’์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • rsa-sha1

  • dsa-sha1

  • rsa-sha256

  • rsa-sha384

  • rsa-sha512

์ด ๊ฐ’์€ IdP ์˜ Signature Algorithm ์ž…๋‹ˆ๋‹ค.

none

์•”ํ˜ธํ™”๋œ ์–ด์„ค์…˜ ํ•„์š”

์˜ต์…˜

IdP ๊ฐ€ Ops Manager๋กœ ์ „์†ก๋˜๋Š” ์–ด์„ค์…˜์„ ์•”ํ˜ธํ™”ํ• ์ง€ ์—ฌ๋ถ€๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

false

์ „์—ญ ์—ญํ•  ์†Œ์œ ์ž ๊ทธ๋ฃน

ํ•„์ˆ˜ ์‚ฌํ•ญ

๋ชจ๋“  ๊ทธ๋ฃน์— ๋Œ€ํ•œ ์ „์ฒด ์•ก์„ธ์Šค ๊ถŒํ•œ ๋ฐ ๋ชจ๋“  ๊ด€๋ฆฌ ๊ถŒํ•œ์„ ํฌํ•จํ•˜์—ฌ ์ด ๋ฐฐํฌ์„œ๋ฒ„์— ๋Œ€ํ•œ ์ „์ฒด ๊ถŒํ•œ์„ ๊ฐ€์ง„ ๊ทธ๋ฃน์˜ ์ด๋ฆ„์„ SAML ๊ทธ๋ฃน ๋ฉค๋ฒ„ ์†์„ฑ์— ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ทธ๋ฃน์€ ์ด Ops Manager ์ธ์Šคํ„ด์Šค์— ๋Œ€ํ•ด Global Owner ์—ญํ• ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•„์ˆ˜ ๊ตฌ์„ฑ ์š”์†Œ์˜ ์ผ๋ถ€๋กœ ์ด ๊ทธ๋ฃน์„ IdP ์„ค์ •์— ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ SAML ์‘๋‹ต์— ์ „์†ก๋œ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์†์„ฑ ๊ฐ’๊ณผ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Azure AD ๋ฅผ IdP ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๊ทธ๋ฃน ์ด๋ฆ„ ๋Œ€์‹  ๊ทธ๋ฃน์˜ ๊ฐ์ฒด ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์‚ฌ์šฉ์ž ์ด๋ฆ„์— ๋Œ€ํ•œ SAML ์†์„ฑ

ํ•„์ˆ˜ ์‚ฌํ•ญ

์‚ฌ์šฉ์ž ์ด๋ฆ„์ด ํฌํ•จ๋œ SAML ์†์„ฑ์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์‚ฌ์šฉ์ž ์„ฑ์— ๋Œ€ํ•œ SAML ์†์„ฑ

ํ•„์ˆ˜ ์‚ฌํ•ญ

์‚ฌ์šฉ์ž์˜ ์„ฑ์ด ํฌํ•จ๋œ SAML ์†์„ฑ์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์‚ฌ์šฉ์ž ์ด๋ฉ”์ผ์˜ SAML ์†์„ฑ

ํ•„์ˆ˜ ์‚ฌํ•ญ

์‚ฌ์šฉ์ž์˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ๊ฐ€ ํฌํ•จ๋œ SAML ์†์„ฑ์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

SAML ๊ทธ๋ฃน ๋ฉค๋ฒ„ ์†์„ฑ

ํ•„์ˆ˜ ์‚ฌํ•ญ

Ops Manager๊ฐ€ ํ”„๋กœ์ ํŠธ ๋ฐ ์กฐ์ง์— ์—ญํ• ์„ ๋งคํ•‘ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•˜๋Š” ๊ทธ๋ฃน ๋ชฉ๋ก์ด ํฌํ•จ๋œ SAML ์†์„ฑ์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

groups

6

๋‹ค์Œ SAML ํ•„๋“œ์— ๋Œ€ํ•ด IdP ์˜ ๊ฐ’์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

ํ•„๋“œ
ํ•„์š”์„ฑ
์ž‘์—…
๊ธฐ๋ณธ๊ฐ’

SP ์ธ์ฆ์„œ PEM ํ‚ค ํŒŒ์ผ์˜ ๊ฒฝ๋กœ

์˜ต์…˜

์„œ๋น„์Šค ์ œ๊ณต์ž๊ฐ€ ์š”์ฒญ์— ์„œ๋ช…ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•˜๋Š” PEMํ˜•์‹์˜ ์ธ์ฆ์„œ์˜ ์ ˆ๋Œ€ ํŒŒ์ผ ๊ฒฝ๋กœ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค. ์ด ์ธ์ฆ์„œ์—๋Š” ๊ฐœ์ธ ํ‚ค์™€ ๊ณต๊ฐœ ํ‚ค๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

์ด ํ•„๋“œ๋ฅผ ๋น„์›Œ ๋‘˜ ๊ฒฝ์šฐ:

  • Ops Manager๋Š” IdP ์— ๋Œ€ํ•œ SAML ์ธ์ฆ ์š”์ฒญ์— ์„œ๋ช…ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • SAML ์–ด์„ค์…˜์€ ์•”ํ˜ธํ™”ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

none

SP ์ธ์ฆ์„œ PEM ํ‚ค ํŒŒ์ผ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ

์กฐ๊ฑด๋ถ€

SP PEM ํŒŒ์ผ์˜ ๊ฐœ์ธ ํ‚ค๋ฅผ ์•”ํ˜ธํ™”ํ•œ ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์ „์—ญ ์ž๋™ํ™” ๊ด€๋ฆฌ์ž ์—ญํ• 

์˜ต์…˜

๊ตฌ์„ฑ์›์—๊ฒŒ Global Automation Admin ์—ญํ• ์ด ์žˆ๋Š” ๊ทธ๋ฃน์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ SAML ์‘๋‹ต์— ์ „์†ก๋œ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์†์„ฑ ๊ฐ’๊ณผ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Azure AD ๋ฅผ IdP ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๊ทธ๋ฃน ์ด๋ฆ„ ๋Œ€์‹  ๊ทธ๋ฃน์˜ ๊ฐ์ฒด ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์ „์—ญ ๋ฐฑ์—… ๊ด€๋ฆฌ์ž ์—ญํ• 

์˜ต์…˜

๊ตฌ์„ฑ์›์—๊ฒŒ Global Backup Admin ์—ญํ• ์ด ์žˆ๋Š” ๊ทธ๋ฃน์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ SAML ์‘๋‹ต์— ์ „์†ก๋œ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์†์„ฑ ๊ฐ’๊ณผ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Azure AD ๋ฅผ IdP ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๊ทธ๋ฃน ์ด๋ฆ„ ๋Œ€์‹  ๊ทธ๋ฃน์˜ ๊ฐ์ฒด ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์ „์—ญ ๋ชจ๋‹ˆํ„ฐ๋ง ๊ด€๋ฆฌ์ž ์—ญํ• 

์˜ต์…˜

๊ตฌ์„ฑ์›์—๊ฒŒ Global Monitoring Admin ์—ญํ• ์ด ์žˆ๋Š” ๊ทธ๋ฃน์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ SAML ์‘๋‹ต์— ์ „์†ก๋œ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์†์„ฑ ๊ฐ’๊ณผ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Azure AD ๋ฅผ IdP ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๊ทธ๋ฃน ์ด๋ฆ„ ๋Œ€์‹  ๊ทธ๋ฃน์˜ ๊ฐ์ฒด ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์ „์—ญ ์‚ฌ์šฉ์ž ๊ด€๋ฆฌ์ž ์—ญํ• 

์˜ต์…˜

๊ตฌ์„ฑ์›์—๊ฒŒ Global User Admin ์—ญํ• ์ด ์žˆ๋Š” ๊ทธ๋ฃน์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ SAML ์‘๋‹ต์— ์ „์†ก๋œ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์†์„ฑ ๊ฐ’๊ณผ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Azure AD ๋ฅผ IdP ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๊ทธ๋ฃน ์ด๋ฆ„ ๋Œ€์‹  ๊ทธ๋ฃน์˜ ๊ฐ์ฒด ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

์ „์—ญ ์ฝ๊ธฐ ์ „์šฉ ์—ญํ• 

์˜ต์…˜

๊ตฌ์„ฑ์›์—๊ฒŒ Global Read Only ์—ญํ• ์ด ์žˆ๋Š” ๊ทธ๋ฃน์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์€ SAML ์‘๋‹ต์— ์ „์†ก๋œ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์†์„ฑ ๊ฐ’๊ณผ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. Azure AD ๋ฅผ IdP ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ด ํ•„๋“œ์— ๊ทธ๋ฃน ์ด๋ฆ„ ๋Œ€์‹  ๊ทธ๋ฃน์˜ ๊ฐ์ฒด ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

none

7
8

Ops Manager SAML Global Role Owner ํ•„๋“œ์— ์ง€์ •๋œ SAML ๊ทธ๋ฃน์˜ ์ผ๋ถ€์ธ ์‚ฌ์šฉ์ž๋กœ Ops Manager์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด Ops Manager๊ฐ€ ํ”„๋กœ์ ํŠธ ํŽ˜์ด์ง€๋ฅผ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.

9

์ฐธ๊ณ 

์ƒˆ ํ”„๋กœ์ ํŠธ๋ฅผ ์ƒ์„ฑํ•˜๋ ค๋ฉด ์ „์—ญ ์—ญํ• ์„ ๊ฐ€์ง€๊ณ  ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  1. Admin > General > Projects๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  2. Create a New Project๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. Project Name์— ์ƒˆ Ops Manager ํ”„๋กœ์ ํŠธ์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

  4. ๊ฐ ํ”„๋กœ์ ํŠธ ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” SAML ๊ทธ๋ฃน์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

    ์ค‘์š”

    ๊ฐ ๊ทธ๋ฃน์— ๋Œ€ํ•ด ์ •๊ทœํ™”๋œ ๊ณ ์œ  ์ด๋ฆ„์„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ LDAP ๋˜๋Š” SAML ๊ทธ๋ฃน์ด ๋™์ผํ•œ ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” ๊ฒฝ์šฐ ์„ธ๋ฏธ์ฝœ๋ก  2๊ฐœ(;;)๋กœ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ์—ญํ• ์˜ ํ•„๋“œ์—์„œ ๊ทธ๋ฃน์„ ์ œ๊ฑฐํ•˜์—ฌ ํ•ด๋‹น ์—ญํ• ์— ๋Œ€ํ•œ ๊ทธ๋ฃน์˜ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์ทจ์†Œํ•ฉ๋‹ˆ๋‹ค.

  5. Add Project๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  1. Admin > General > Projects๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  2. ํ”„๋กœ์ ํŠธ์˜ Actions ์—ด์—์„œ ์„ ํด๋ฆญํ•œ ๋‹ค์Œ Edit SAML Settings์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. ๊ฐ ํ”„๋กœ์ ํŠธ ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” SAML ๊ทธ๋ฃน์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

    ์ค‘์š”

    ๊ฐ ๊ทธ๋ฃน์— ๋Œ€ํ•ด ์ •๊ทœํ™”๋œ ๊ณ ์œ  ์ด๋ฆ„์„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ LDAP ๋˜๋Š” SAML ๊ทธ๋ฃน์ด ๋™์ผํ•œ ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” ๊ฒฝ์šฐ ์„ธ๋ฏธ์ฝœ๋ก  2๊ฐœ(;;)๋กœ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ์—ญํ• ์˜ ํ•„๋“œ์—์„œ ๊ทธ๋ฃน์„ ์ œ๊ฑฐํ•˜์—ฌ ํ•ด๋‹น ์—ญํ• ์— ๋Œ€ํ•œ ๊ทธ๋ฃน์˜ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์ทจ์†Œํ•ฉ๋‹ˆ๋‹ค.

  4. Save Changes๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

10

์ฐธ๊ณ 

์ƒˆ ์กฐ์ง์„ ์ƒ์„ฑํ•˜๋ ค๋ฉด ์ „์—ญ ์—ญํ• ์„ ๊ฐ€์ง€๊ณ  ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  1. Admin > General > Organizations๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  2. Create a New Organization๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. Organization Name์— ์ƒˆ Ops Manager ์กฐ์ง์˜ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

  4. ๊ฐ ์กฐ์ง ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” SAML ๊ทธ๋ฃน์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

    ์ค‘์š”

    ๊ฐ ๊ทธ๋ฃน์— ๋Œ€ํ•ด ์ •๊ทœํ™”๋œ ๊ณ ์œ  ์ด๋ฆ„์„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ LDAP ๋˜๋Š” SAML ๊ทธ๋ฃน์ด ๋™์ผํ•œ ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” ๊ฒฝ์šฐ ์„ธ๋ฏธ์ฝœ๋ก  2๊ฐœ(;;)๋กœ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ์—ญํ• ์˜ ํ•„๋“œ์—์„œ ๊ทธ๋ฃน์„ ์ œ๊ฑฐํ•˜์—ฌ ํ•ด๋‹น ์—ญํ• ์— ๋Œ€ํ•œ ๊ทธ๋ฃน์˜ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์ทจ์†Œํ•ฉ๋‹ˆ๋‹ค.

  5. Add Organization๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  1. Admin > General > Organizations๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  2. Edit Org ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. ๊ฐ ์กฐ์ง ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” SAML ๊ทธ๋ฃน์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

    ์ค‘์š”

    ๊ฐ ๊ทธ๋ฃน์— ๋Œ€ํ•ด ์ •๊ทœํ™”๋œ ๊ณ ์œ  ์ด๋ฆ„์„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ LDAP ๋˜๋Š” SAML ๊ทธ๋ฃน์ด ๋™์ผํ•œ ์—ญํ• ์— ํ•ด๋‹นํ•˜๋Š” ๊ฒฝ์šฐ ์„ธ๋ฏธ์ฝœ๋ก  2๊ฐœ(;;)๋กœ ๊ตฌ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ์—ญํ• ์˜ ํ•„๋“œ์—์„œ ๊ทธ๋ฃน์„ ์ œ๊ฑฐํ•˜์—ฌ ํ•ด๋‹น ์—ญํ• ์— ๋Œ€ํ•œ ๊ทธ๋ฃน์˜ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์ทจ์†Œํ•ฉ๋‹ˆ๋‹ค.

  4. Save Changes๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

12

SAML ๊ตฌ์„ฑ์„ ์ €์žฅํ•˜๋ฉด Download the Metadata XML File ๋งํฌ๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.

์ด ๋งํฌ๋ฅผ ํด๋ฆญํ•˜์—ฌ SAMLSP ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ XML ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

์ด ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ํŒŒ์ผ์€ ๋‹ค์Œ ์˜ˆ์‹œ์™€ ์œ ์‚ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

1<?xml version="1.0"?>
2<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" validUntil="2019-09-13T20:36:00Z" cacheDuration="PT604800S" entityID="http://ec2-3-88-178-252.compute-1.amazonaws.com:8080" ID="ONELOGIN_f95ad815-e8da-4ab3-a799-3c581484cd6a">
3 <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
4 <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="http://ec2-3-88-178-252.compute-1.amazonaws.com:8080/saml/logout"/>
5 <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
6 <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="http://ec2-3-88-178-252.compute-1.amazonaws.com:8080/saml/assert" index="1"/>
7 </md:SPSSODescriptor>
8</md:EntityDescriptor>
13

IdP ๊ฐ€ ์˜ต์…˜์„ ์ œ๊ณตํ•˜๋Š” ๊ฒฝ์šฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ IdP ๋กœ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. Ops Manager๋Š” IdP ์— ๋Œ€ํ•œ ์„œ๋น„์Šค ์ œ๊ณต์ž(SP) ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

๋ฉ”ํƒ€๋ฐ์ดํ„ฐ XML ํŒŒ์ผ์˜ ๋‹ค์Œ ๊ฐ’์„ IdP ์— ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

ํ•„๋“œ
๊ณตํ†ต ๊ฐ’

SP Entity ID or Issuer

<OpsManagerHost>:<Port>

Audience URI

<OpsManagerHost>:<Port>

Assertion Consumer Service (ACS) URL

<OpsManagerHost>:<Port>/saml/assert

Single Logout URL

<OpsManagerHost>:<Port>/saml/logout

์ด๋Ÿฌํ•œ ๊ฐ’ ์ค‘ ํ•˜๋‚˜ ์ด์ƒ์ด ๋ˆ„๋ฝ๋œ ๊ฒฝ์šฐ ์ด์ „ ํ‘œ์— ๋‚˜์—ด๋œ ์ง€์นจ์„ ์‚ฌ์šฉํ•˜์—ฌ ํ•ด๋‹น ๊ฐ’์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฐ’์„ IdP ์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

14
  1. ๋น„๊ณต๊ฐœ ๋ธŒ๋ผ์šฐ์ € ์ฐฝ์—์„œ Ops Manager ์ธ์Šคํ„ด์Šค๋กœ Goํ•ฉ๋‹ˆ๋‹ค.

    IdP ๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค.

  2. IdP ๋กœ ์ธ์ฆํ•ฉ๋‹ˆ๋‹ค.

    ๊ทธ๋Ÿฐ ๋‹ค์Œ Ops Manager ์ธ์Šคํ„ด์Šค๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค.

๋Œ์•„๊ฐ€๊ธฐ

LDAP ๊ตฌ์„ฑ

์ด ํŽ˜์ด์ง€์˜ ๋‚ด์šฉ