Sun ·Î°í      ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun ONE Messaging Server 6.0 °ü¸®ÀÚ ¼³¸í¼­

 4Àå
´ÜÀÏ »çÀÎ ¿Â(SSO) »ç¿ë

´ÜÀÏ »çÀÎ ¿Â(SSO)Àº ÃÖÁ¾ »ç¿ëÀÚ°¡ ÇÑ ¹øÀÇ ÀÎÁõ(»ç¿ëÀÚ ¾ÆÀ̵ð¿Í ºñ¹Ð¹øÈ£¸¦ »ç¿ëÇÏ¿© ·Î±×¿Â)À¸·Î ¿©·¯ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â ±â´ÉÀÔ´Ï´Ù. Sun One Identity Server´Â Sun ONE ¼­¹ö¿¡¼­ SSO¿¡ »ç¿ëÇÏ´Â °ø½Ä °ÔÀÌÆ®¿þÀÌÀÔ´Ï´Ù. Áï, »ç¿ëÀÚ°¡ ´Ù¸¥ SSO ±¸¼º ¼­¹ö¿¡ ¾×¼¼½ºÇÏ·Á¸é Identity Server¿¡ ·Î±×ÀÎÇØ¾ß ÇÕ´Ï´Ù.

¿¹¸¦ µé¾î, Á¦´ë·Î ±¸¼ºµÈ °æ¿ì »ç¿ëÀÚ´Â Sun One Identity Server ·Î±×ÀÎ È­¸é¿¡¼­ ¼­¸íÇÑ ÈÄ ´Ù¸¥ â¿¡¼­ ´Ù½Ã ¼­¸íÇÏÁö ¾Ê°íµµ Messenger Express¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ¸¶Âù°¡Áö·Î Sun ONE Calendar Server¸¦ Á¦´ë·Î ±¸¼ºÇÑ °æ¿ì »ç¿ëÀÚ´Â Sun One Identity Server ·Î±×ÀÎ È­¸é¿¡¼­ ¼­¸íÇÑ ÈÄ ´Ù¸¥ â¿¡¼­ ´Ù½Ã ¼­¸íÇÏÁö ¾Ê°íµµ ÇØ´ç Calendar¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ½À´Ï´Ù.

Messaging Server¿¡¼­´Â SSO¸¦ ¹èÆ÷ÇÏ´Â µÎ °¡Áö ¹æ¹ýÀ» Á¦°øÇÕ´Ï´Ù. ù ¹ø° ¹æ¹ýÀº Sun One Identity Server¸¦ ÅëÇÑ ¹èÆ÷ÀÌ°í µÎ ¹ø° ¹æ¹ýÀº Åë½Å ¼­¹öÀÇ ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø ±â¼úÀ» ÅëÇÑ ¹æ¹ýÀÔ´Ï´Ù. ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿øÀ» »ç¿ëÇÏ´Â °ÍÀº ·¹°Å½Ã SSO ±¸Çö ¹æ¹ýÀÔ´Ï´Ù. ÀÌ ¹æ¹ý¿¡´Â Identity Server SSO¿¡¼­´Â »ç¿ëÇÒ ¼ö ¾ø´Â ¿©·¯ ±â´ÉÀÌ ÀÖÁö¸¸ ÇâÈÄ ¸ðµç ±â´ÉÀÌ Identity Server¿¡ ¹èÆ÷µÉ ¶§±îÁö´Â »ç¿ëÇÏÁö ¾Ê´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÇÏÁö¸¸ ´ÙÀ½ Àý¿¡¼­´Â µÎ °¡Áö ¹æ¹ýÀ» ¸ðµÎ ¼³¸íÇÕ´Ï´Ù.


Sun ONE ¼­¹ö¿ë Identity Server SSO

ÀÌ Àý¿¡¼­´Â Identity Server¸¦ »ç¿ëÇÏ´Â SSO¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. ÀÌ ÀåÀº ´ÙÀ½ ³»¿ëÀ¸·Î ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.

SSO Á¦ÇÑ ¹× ¾Ë¸²

SSO¸¦ Áö¿øÇϵµ·Ï Messaging Server ±¸¼º

³× °³ÀÇ configutil ¸Å°³ º¯¼ö°¡ Messaging Server SSO¸¦ Áö¿øÇÕ´Ï´Ù. ÀÌ ³× °³ Áß local.webmail.sso.amnamingurl Çϳª¸¸ Messaging Server¿¡¼­ SSO¸¦ »ç¿ëÇÏ´Â µ¥ ÇÊ¿äÇÕ´Ï´Ù. SSO¸¦ »ç¿ëÇÏ·Á¸é ÀÌ ¸Å°³ º¯¼ö¸¦ Identity Server¿¡¼­ À̸§ ÁöÁ¤ ¼­ºñ½º¸¦ ½ÇÇàÇÏ´Â URL·Î ¼³Á¤ÇÕ´Ï´Ù. ÀϹÝÀûÀ¸·Î ÀÌ URLÀº http://server/amserver/namingserviceÀÔ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

configutil -o local.webmail.sso.amnamingurl -v http://sca-walnut:88/amserver/namingservice


ÁÖ

Identity Server SSO´Â ÀÌÀü SSO ±â¹ýÀ» »ç¿ëÇÏ´Â local.webmail.sso.enableÀ» È®ÀÎÇÏÁö ¾Ê½À´Ï´Ù. local.webmail.sso.enableÀ» off ¶Ç´Â ¼³Á¤µÇÁö ¾ÊÀº »óÅ·ΠµÎ¾î¾ß ÇÕ´Ï´Ù. ±×·¸Áö ¾ÊÀ¸¸é ÀÌÀü SSO ±â¹ý¿¡ ÇÊ¿äÇÑ ±¸¼º ¸Å°³ º¯¼ö°¡ ¾ø´Ù´Â °æ°í ¸ÞÀÏÀÌ ±â·ÏµË´Ï´Ù.


configutil ¸í·ÉÀ» »ç¿ëÇÏ¿© Ç¥ 4-3¿¡ Ç¥½ÃµÈ SSO ±¸¼º ¸Å°³ º¯¼ö¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.

Ç¥ 4-1 Identity Server ´ÜÀÏ »çÀÎ ¿Â(SSO) ¸Å°³ º¯¼ö

¸Å°³ º¯¼ö

¼³¸í

local.webmail.sso.amnamingurl

Identity Server°¡ À̸§ ÁöÁ¤ ¼­ºñ½º¸¦ ½ÇÇàÇÏ´Â URLÀÔ´Ï´Ù. Identity Server¸¦ ÅëÇØ ´ÜÀÏ »çÀÎ ¿Â(SSO)Çϱâ À§ÇØ ÇʼöÀûÀÎ º¯¼öÀÔ´Ï´Ù. ÀϹÝÀûÀ¸·Î ÀÌ URLÀº http://<server>/amserver/namingserviceÀÔ´Ï´Ù.

±âº»°ª: ¼³Á¤ ¾È ÇÔ

local.webmail.sso.amcookiename

Identity Server ÄíÅ° À̸§ÀÔ´Ï´Ù. Identity Server°¡ ´Ù¸¥ ÄíÅ° À̸§À» »ç¿ëÇϵµ·Ï ±¸¼ºµÈ °æ¿ì Messaging Server¿¡¼­ ´ÜÀÏ »çÀÎ ¿Â(SSO) ¼öÇà ½Ã È®ÀÎÇÒ ´ë»óÀ» ¾Ë ¼ö ÀÖµµ·Ï Messaging Server¿¡¼­ ÇØ´ç À̸§À» local.webmail.sso.amcookienameÀ¸·Î ±¸¼ºÇØ¾ß ÇÕ´Ï´Ù. ±âº»°ªÀº iPlanetDirectoryProÀ̸ç Identity Server°¡ ±âº» ±¸¼ºÀ¸·Î ±¸¼ºµÈ °æ¿ì ÀÌ °ªÀ» º¯°æÇÒ ¼ö ¾ø½À´Ï´Ù.

±âº»°ª: iPlanetDirectoryPro

local.webmail.sso.amloglevel

AMSDK ·Î±ë ¼öÁØÀÔ´Ï´Ù. Messaging Server¿¡ »ç¿ëµÇ´Â SSO ¶óÀ̺귯¸®¿¡´Â Messaging Server¿Í´Â º°µµ·Î ÀÚü ·Î±ë ±â¹ýÀÌ ÀÖ½À´Ï´Ù. msg_svr_base/logÀÇ http_sso¶ó´Â ÆÄÀÏ¿¡ ¸ÞÀÏÀÌ ±â·ÏµË´Ï´Ù. ±âº»ÀûÀ¸·Î info ÀÌ»óÀÇ ·Î±ë ¼öÁØÀ» °¡Áø ¸ÞÀϸ¸ ±â·ÏµÇÁö¸¸ ·Î±ë ¼öÁØÀ» 1ºÎÅÍ 5±îÁöÀÇ °ª(1 = errors, 2 = warnings, 3 = info, 4 = debug, 5 = maxdebug)À¸·Î ¼³Á¤ÇÏ¿© ·Î±ë ¼öÁØÀ» ³ôÀÏ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¶óÀ̺귯¸®¿¡´Â Messaging Server¿Í µ¿ÀÏÇÑ ¸ÞÀÏ Áß¿äµµ °³³äÀÌ ¾øÀ¸¹Ç·Î ¼öÁØÀ» info·Î ¼³Á¤ÇÏ¸é ¸¹Àº ÀÇ¹Ì ¾ø´Â µ¥ÀÌÅÍ°¡ »ý¼ºµÉ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ http_sso ·Î±× ÆÄÀÏÀÌ ÀÏ¹Ý Messaging Server ·Î±ë Äڵ忡 ÀÇÇØ °ü¸®µÇÁö ¾ÊÀ¸¸ç Á¤¸® ¶Ç´Â ·Ñ¿À¹öµÇÁö ¾Ê½À´Ï´Ù. ·Î±× ¼öÁØÀ» ±âº»°ªº¸´Ù ³ô°Ô ¼³Á¤ÇÏ´Â °æ¿ì Á¤¸® ÀÛ¾÷Àº ½Ã½ºÅÛ °ü¸®ÀÚÀÇ Ã¥ÀÓÀÔ´Ï´Ù.

±âº»°ª: 3

local.webmail.sso.singlesignoff

Messaging Server¿¡¼­ Identity Server·ÎÀÇ ´ÜÀÏ »çÀÎ ¿ÀÇÁÀÔ´Ï´Ù. Identity Server´Â Áß¾Ó ÀÎÁõ ±â°üÀÌ¸ç ´ÜÀÏ »çÀÎ ¿ÀÇÁ´Â Ç×»ó Identity Server·ÎºÎÅÍ Messaging Server·Î »ç¿ëµË´Ï´Ù. ÀÌ ¿É¼ÇÀ» »ç¿ëÇÏ¸é »çÀÌÆ®¿¡¼­ »ç¿ëÀÚ°¡ À¥ ¸ÞÀÏÀÇ ·Î±×¾Æ¿ô ¹öÆ°À» ´­·¯ Identity Server¿¡¼­µµ ·Î±×¾Æ¿ôÇÒÁö ¿©ºÎ¸¦ ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù(ÀϺΠ»ç¿ëÀÚ Á¤ÀÇ ÀÛ¾÷ »ý·«). ÀÌ ¿É¼ÇÀº ±âº»ÀûÀ¸·Î »ç¿ëµË´Ï´Ù. ÀÌ ¿É¼ÇÀ» »ç¿ëÇÏÁö ¾Ê´Â °æ¿ì¿¡´Â ·Î±×¾Æ¿ôÀÌ ·çÆ® ¹®¼­¸¦ ÂüÁ¶ÇÏ°í ÇØ´ç ·çÆ® ¹®¼­´Â Identity Server ÄíÅ°°¡ Á¸ÀçÇÏ°í À¯È¿ÇÑ ÀÌ»ó ¹ÞÀº ¸ÞÀÏÇÔ µð½ºÇ÷¹À̸¦ ÂüÁ¶Çϱ⠶§¹®¿¡ »ç¿ëÀÚ°¡ ±âº» À¥ ¸ÞÀÏ Å¬¶óÀ̾ðÆ®¿¡¼­ ·Î±×¾Æ¿ôÇϸé ÀÚµ¿À¸·Î ´Ù½Ã ·Î±×Àε˴ϴÙ. µû¶ó¼­, »çÀÌÆ®¿¡¼­ ÀÌ ¿É¼ÇÀ» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼±ÅÃÇϸé À¥ ¸ÞÀÏ ·Î±×¾Æ¿ô½Ã ¹ß»ýµÇ´Â ³»¿ëÀ» »ç¿ëÀÚ Á¤ÀÇÇØ¾ß ÇÕ´Ï´Ù.

±âº»°ª: ¿¹

SSO ¹®Á¦ ÇØ°á

SSO¿¡ ¹®Á¦°¡ ÀÖ´Â °æ¿ì óÀ½ ¼öÇàÇÒ ÀÛ¾÷Àº ¿À·ù¿¡ ´ëÇÑ À¥ ¸ÞÀÏ ·Î±× ÆÄÀÏ msg_svr_base/log/http¸¦ °Ë»çÇÏ´Â °ÍÀÔ´Ï´Ù. ·Î±ë ¼öÁØÀ» ³ôÀÌ´Â °Íµµ À¯¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù(configutil -o logfile.http.loglevel -v debug). ÀÌ ÀÛ¾÷ÀÌ µµ¿òÀÌ µÇÁö ¾Ê´Â °æ¿ì msg_svr_base/log/http_sso¿¡¼­ amsdk ¸ÞÀÏÀ» °Ë»çÇÑ ´ÙÀ½ amsdk ·Î±ë ¼öÁØÀ» ³ôÀÔ´Ï´Ù(configutil -o local.webmail.sso.amloglevel -v 5). »õ ·Î±ë ¼öÁØÀ» Àû¿ëÇÏ·Á¸é ¼­¹ö¸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.

SSO¿¡ ¿©ÀüÈ÷ ¹®Á¦°¡ ÀÖÀ» °æ¿ì ·Î±×ÀÎÇÏ´Â µ¿¾È Identity Server¿Í Messaging Server ¸ðµÎ¿¡¼­ Á¤±ÔÈ­µÈ È£½ºÆ® À̸§À» »ç¿ëÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ÄíÅ°´Â µ¿ÀÏÇÑ µµ¸ÞÀÎÀÇ ¼­¹ö °£¿¡¸¸ °øÀ¯µÇ¸ç ºê¶ó¿ìÀú´Â ·ÎÄà ¼­¹ö À̸§¿¡ ´ëÇÑ µµ¸ÞÀÎÀÌ ¹«¾ùÀÎÁö ¾ËÁö ¸øÇϹǷΠºê¶ó¿ìÀú¿¡¼­ Á¤±ÔÈ­µÈ À̸§À» »ç¿ëÇØ¾ß SSO°¡ ÀÛµ¿ÇÕ´Ï´Ù.


½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO (·¹°Å½Ã)

ÀÌ Àý¿¡¼­´Â ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. ÀÌÈÄÀÇ ¸ðµç °³¹ß¿¡¼­ Identity Server¸¦ »ç¿ëÇÏ°Ô µÉ °ÍÀ̹ǷΠÀÌ SSO ¹æ¹ýÀ» »ç¿ëÇÏÁö ¾Ê´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ±×·¯³ª ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ´Â ±â´É Áß ÀϺδ ÇöÀç Identity Server SSO¿¡¼­ »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù. ÀÌ ÀýÀº ´ÙÀ½ ³»¿ëÀ¸·Î ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.

½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO °³¿ä ¹× Á¤ÀÇ

SSO¸¦ ¹èÆ÷Çϱâ Àü¿¡ ´ÙÀ½ ¿ë¾î¿¡ ´ëÇØ Àß ¾Ë°í ÀÖ¾î¾ß ÇÕ´Ï´Ù.

½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO ÀÀ¿ë ÇÁ·Î±×·¥

SSO¸¦ ±¸ÇöÇϱâ Àü¿¡ ¸ÕÀú ÀÌ ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø¿¡ ¼ÓÇÏ´Â ÀÀ¿ë ÇÁ·Î±×·¥À» °í·ÁÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø¿¡ Æ÷Ç﵃ ¼ö ÀÖ´Â ÀÀ¿ë ÇÁ·Î±×·¥Àº Messenger Express (Messenger Express Multiplexor »ç¿ë ¶Ç´Â »ç¿ë ¾È ÇÔ), Calendar Express ¹× ÀÌÀü iPlanet Delegated Administrator for Messaging (Sun ONE LDAP Schema, v.1¸¸ Áö¿øÇϹǷΠ±ÇÀåµÇÁö ¾ÊÀ½)ÀÔ´Ï´Ù.

Ç¥ 4-2¿¡¼­´Â SSO¸¦ ÅëÇØ ¼­·Î ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â ÀÀ¿ë ÇÁ·Î±×·¥À» º¸¿© ÁÝ´Ï´Ù. »ç¿ëÀÚÀÇ °üÁ¡¿¡¼­ ù ¹ø° ¿­ÀÇ ÀÀ¿ë ÇÁ·Î±×·¥ Áß Çϳª¿¡ ·Î±×ÀÎÇÑ ´ÙÀ½ »ç¿ëÀÚ ¾ÆÀ̵ð¿Í ºñ¹Ð¹øÈ£¸¦ ´Ù½Ã ÀÔ·ÂÇÏÁö ¾Ê°í ¸Ç À§ÀÇ Çà¿¡ ÀÖ´Â ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù¸é SSO°¡ Àû¿ëµÇ´Â °ÍÀÔ´Ï´Ù.

Ç¥ 4-2 SSO »óÈ£ ¿î¿ë¼º

                           ´ë»ó:

 

½ÃÀÛ:

Calendar Express

Messenger Express

Messenger Express Multiplexor

Delegated Administrator

Calendar Express

SSO

SSO

SSO

SSO

Messenger Express

SSO

ÇØ´ç ¾øÀ½

ÇØ´ç ¾øÀ½

SSO

Messenger Express Multiplexor

SSO

ÇØ´ç ¾øÀ½

ÇØ´ç ¾øÀ½

SSO

Delegated Administrator

SSO

SSO

SSO

ÇØ´ç ¾øÀ½

½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO Á¦ÇÑ

½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO ¹èÆ÷ ½Ã³ª¸®¿À ¿¹

°¡Àå ´Ü¼øÇÑ SSO ¹èÆ÷ ½Ã³ª¸®¿À´Â Messenger Express¿Í iPlanet Delegated Administrator for MessagingÀ¸·Î¸¸ ±¸¼ºµË´Ï´Ù. µ¿ÀÏÇÑ ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø ³»¿¡ Æ÷ÇԵǵµ·Ï µ¿ÀÏÇÑ SSO Á¢µÎ¾î¸¦ »ç¿ëÇÏ¿© µ¿ÀÏÇÑ ½Ã½ºÅÛÀ̳ª ´Ù¸¥ ½Ã½ºÅÛ¿¡ Calendar Express¸¦ Ãß°¡ÇÏ¿© º¸´Ù º¹ÀâÇÑ ½Ã³ª¸®¿À¸¦ ¸¸µé ¼ö ÀÖ½À´Ï´Ù. ÀÌ ½Ã³ª¸®¿À´Â ±×¸² 4-1¿¡ ³ª¿Í ÀÖ½À´Ï´Ù.

±×¸² 4-1 ´Ü¼øÇÑ SSO ¹èÆ÷

´ÜÀÏ SSO Á¢µÎ¾î ¾Æ·¡¿¡¼­ ¼¼ °³ÀÇ ÀÀ¿ë ÇÁ·Î±×·¥À» °¡Áø ´Ü¼ø SSO ¹èÆ÷¸¦ º¸¿© ÁÖ´Â ±×·¡ÇÈÀÔ´Ï´Ù.

º¸´Ù º¹ÀâÇÑ ¹èÆ÷¿¡´Â Messenger Express Multiplexors¿Í ·Îµå ¹ë·±¼­°¡ ÀÖ½À´Ï´Ù.

±×¸² 4-2 º¹ÀâÇÑ SSO ¹èÆ÷

7°³ÀÇ ¼­¹ö ÀÀ¿ë ÇÁ·Î±×·¥À» °¡Áø º¹ÀâÇÑ SSO ¹èÆ÷¸¦ º¸¿© ÁÖ´Â ±×·¡ÇÈÀÔ´Ï´Ù.

½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø SSO ¼³Á¤

ÀÌ Àý¿¡¼­´Â Messenger Express, iPlanet Delegated Administrator for Messaging ¹× Calendar Manager¿¡ ´ëÇÑ SSO ¼³Á¤¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù.

  1. SSO¿¡ ´ëÇØ Messenger Express¸¦ ±¸¼ºÇÕ´Ï´Ù.
    1. ÀûÀýÇÑ SSO configutil ¸Å°³ º¯¼ö¸¦ ¼³Á¤ÇÕ´Ï´Ù.
    2. Delegated Administrator°¡ ÀÖ´Â Messenger Express¿¡ ´ëÇØ ´ÜÀÏ »çÀÎ ¿Â(SSO)À» »ç¿ëÇÏ·Á¸é ±¸¼º ¸Å°³ º¯¼ö¸¦ ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇÕ´Ï´Ù(±âº» µµ¸ÞÀÎÀ» siroe.comÀ¸·Î °¡Á¤). ÀÌ·¯ÇÑ ¸Å°³ º¯¼ö´Â Ç¥ 4-3¿¡ ¼³¸íµÇ¾î ÀÖ½À´Ï´Ù. ·çÆ® »ç¿ëÀÚ°¡ µÇ¾î¾ß ÇÕ´Ï´Ù(cd instance_root).

      configutil -o local.webmail.sso.enable -v 1
      configutil -o local.webmail.sso.prefix -v ssogrp1
            ssogrp1 is the default SSO Prefix used by iDA, although you can choose a different prefix,
            using the default would save a little typing when configuring iDA and iCS.
      configutil -o local.webmail.sso.id -v ims5
            ims5 is a name you pick to identify Messenger Express (ME) to other applications.
      configutil -o local.webmail.sso.cookiedomain -v “.siroe.com”
            The above domain must match the domain used by the ME/browser client to connect to
            the servers. Thus, although the hosted domain on this server may be called xyz.com, we
            must use a real domain in the DNS. This value must start with a period.
      configutil -o local.webmail.sso.singlesignoff -v 1
      configutil -o local.sso.
      ApplicationID.verifyurl -v \
            “http://ApplicationHost:port/verifySSO?”
            ApplicationID is a name we give to the SSO application (example: ida for Delegated
            Administrator, ics50 for Calendar Server). ApplicationHost:port is the host and port number of the
            application. You will have one of these lines for each non-Messaging Server applcation. Example:
            configutil -o local.sso.ida.verifyurl -v \
               “http://siroe.com:8080/verifySSO?”

    3. ±¸¼ºÀ» º¯°æÇÑ ÈÄ Messenger Express http ¼­¹ö¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
    4. cd instance_root
      ./stop-msg http
      ./start-msg http

  2. SSO¿¡ ´ëÇØ Directory Server¸¦ ±¸¼ºÇÕ´Ï´Ù.
    1. µð·ºÅ丮¿¡ ÇÁ·Ï½Ã »ç¿ëÀÚ °èÁ¤À» ¸¸µì´Ï´Ù.
    2. ÇÁ·Ï½Ã »ç¿ëÀÚ °èÁ¤À» »ç¿ëÇϸé Delegated Administrator¿¡¼­ ÇÁ·Ï½Ã ÀÎÁõÀ» À§ÇØ Directory Server¿¡ ¹ÙÀεåÇÒ ¼ö ÀÖ½À´Ï´Ù. ´ÙÀ½ LDIF ÄÚµå(proxy.ldif)¸¦ »ç¿ëÇϸé ldapadd¸¦ ÅëÇØ ÇÁ·Ï½Ã »ç¿ëÀÚ °èÁ¤ Ç׸ñÀ» ¸¸µé ¼ö ÀÖ½À´Ï´Ù.

      dn: uid=proxy, ou=people, o=siroe.com, o=isp
      objectclass: top
      objectclass: person
      objectclass: organizationalperson
      objectclass: inetorgperson
      uid: proxy
      givenname: Proxy
      sn: Auth
      cn: Proxy Auth
      userpassword: proxypassword

      ldapadd -h mysystem.siroe.com -D "cn=Directory Manager" -w password -v -f proxy.ldif

    3. ÇÁ·Ï½Ã »ç¿ëÀÚ °èÁ¤ ÀÎÁõÀ» À§ÇØ ÇØ´ç ACI¸¦ ¸¸µì´Ï´Ù.
    4. ldapmodify À¯Æ¿¸®Æ¼¸¦ »ç¿ëÇÏ¿© Delegated Administrator¸¦ ¼³Ä¡ÇÒ ¶§ ¸¸µç °¢ Á¢¹Ì¾î¿¡ ´ëÇÑ ACI¸¦ ¸¸µì´Ï´Ù.

      osiroot - »ç¿ëÀÚ µ¥ÀÌÅ͸¦ ÀúÀåÇϱâ À§ÇØ ÀÔ·ÂÇÑ Á¢¹Ì¾îÀÔ´Ï´Ù. ±âº»°ªÀº o=ispÀÔ´Ï´Ù. osiroot´Â Á¶Á÷ Æ®¸®ÀÇ ·çÆ®ÀÔ´Ï´Ù.

      dcroot - µµ¸ÞÀÎ Á¤º¸¸¦ ÀúÀåÇϱâ À§ÇØ ÀÔ·ÂÇÑ Á¢¹Ì¾îÀÔ´Ï´Ù. ±âº»°ªÀº o=internetÀÔ´Ï´Ù.

      osiroot - ±¸¼º Á¤º¸¸¦ ÀúÀåÇϱâ À§ÇØ ÀÔ·ÂÇÑ Á¢¹Ì¾îÀÌ¸ç »ç¿ëÀÚ µ¥ÀÌÅ͸¦ ÀúÀåÇϱâ À§ÇØ ÀÔ·ÂÇÑ °ª°ú µ¿ÀÏÇØ¾ß ÇÕ´Ï´Ù.

      ´ÙÀ½Àº ¾Õ¿¡¼­ ÀÛ¼ºÇÑ ÇÁ·Ï½Ã »ç¿ëÀÚÀÇ osiroot¿¡ ´ëÇÑ ACI Ç׸ñ(aci1.ldif)ÀÇ ¿¹ÀÔ´Ï´Ù.

      dn: o=isp
      changetype: modify
      add: aci
      aci: (target="ldap:///o=isp")(targetattr="*")(version 3.0; acl
      "proxy";allow (proxy) userdn="ldap:///uid=proxy, ou=people,
      o=siroe.com, o=isp";)

      ldapmodify -h siroe.com -D "cn=Directory Manager" -w password -v -f aci1.ldif

      ´ÙÀ½°ú °°ÀÌ dcroot¿¡ ´ëÇØ ºñ½ÁÇÑ ACI Ç׸ñ(aci2.ldif)À» ¸¸µì´Ï´Ù.

      dn: o=internet
      changetype: modify
      add: aci
      aci: (target="ldap:///o=internet")(targetattr="*")(version 3.0; acl "proxy";allow (proxy) userdn="ldap:///uid=proxy, ou=people, o=siroe.com, o=isp";)

      ldapmodify -h siroe.com -D "cn=Directory Manager" -w password -v -f aci2.ldif

  3. Delegated Administrator¸¦ ±¸¼ºÇÕ´Ï´Ù.
    1. Delegated Administrator resource.properties ÆÄÀÏ¿¡ ÄÁÅؽºÆ®¿¡ ´ëÇÑ ÇÁ·Ï½Ã »ç¿ëÀÚ ÀÚ°Ý Áõ¸í°ú ÄíÅ° À̸§À» Ãß°¡ÇÕ´Ï´Ù.
    2. Delegated Administrator iDA_server_root/nda/classes/netscape/nda/
      servlet/resource.properties ÆÄÀÏ¿¡¼­ ´ÙÀ½ Ç׸ñ¿¡ ´ëÇÑ ÁÖ¼® 󸮸¦ Ãë¼ÒÇÏ°í ¼öÁ¤ÇÕ´Ï´Ù.

      LDAPDatabaseInterface-ldapauthdn=Proxy_Auth_DN
      LDAPDatabaseInterface-ldapauthpw=Proxy_Auth_Password
      NDAAuth-singleSignOnId=SSO_Prefix-
      NDAAuth-applicationId=
      DelAdminID

      ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

      LDAPDatabaseInterface-ldapauthdn=  
         uid=proxy, ou=people, o=siroe.com, o=isp
      LDAPDatabaseInterface-ldapauthpw=proxypassword
      NDAAuth-singleSignOnId=ssogrp1-
      NDAAuth-applicationId=ida

    3. Âü¿©ÇÏ´Â ¼­¹öÀÇ È®ÀÎ URLÀ» Ãß°¡ÇÕ´Ï´Ù.
    4. ¼ö½ÅÇÏ´Â ´ÜÀÏ »çÀÎ ¿Â(SSO) ÄíÅ°¸¦ È®ÀÎÇÏ·Á¸é Delegated Administrator¿¡¼­ ¿¬°áÇÒ »ç¶÷À» ¾Ë°í ÀÖ¾î¾ß ÇÕ´Ï´Ù. ¾Ë·ÁÁø ¸ðµç Âü¿© ¼­¹ö¿¡ ´ëÇÑ È®ÀÎ URLÀ» Á¦°øÇØ¾ß ÇÕ´Ï´Ù.

      ´ÙÀ½ ¿¹¿¡¼­´Â Messenger Express¸¦ ¼³Ä¡ÇÏ°í ÇØ´ç ÀÀ¿ë ÇÁ·Î±×·¥ ¾ÆÀ̵𰡠msg5¶ó°í °¡Á¤ÇÕ´Ï´Ù. Delegated Administrator iDA_server_root/nda/
      classes/netscape/nda/servlet/resource.properties
      ÆÄÀÏÀ» ÆíÁýÇÏ°í ´ÙÀ½ Ç׸ñÀ» Ãß°¡ÇÕ´Ï´Ù.

      verificationurl-ssogrp1-msg5=http://webmail_hostname:port/VerifySSO?
      verificationurl-ssogrp1-ida=http://
      iDA_hostname:port/VerifySSO?
      verificationurl-ssogrp1-ics50=http://
      iCS_hostname:port/VerifySSO?

  4. Delegated Administrator ´ÜÀÏ »çÀÎ ¿Â(SSO) ÄíÅ° Á¤º¸¸¦ Ãß°¡ÇÏ°í UTF8 ¸Å°³ º¯¼ö ÀÎÄÚµùÀ» »ç¿ëÇÕ´Ï´Ù.
    1. Delegated Administrator¿¡ ´ëÇÑ ÄÁÅؽºÆ® ½Äº°ÀÚ¸¦ Á¤ÀÇÇÕ´Ï´Ù.

      Web_Server_Root/https-instancename/config/servlets.properties¸¦ ÆíÁýÇÏ°í servlet.*.context=ims50 ÅؽºÆ®¿¡ Æ÷ÇÔµÈ ¸ðµç ÇàÀÇ ÁÖ¼®À» Ãë¼ÒÇÕ´Ï´Ù. ¿©±â¼­ *´Â ¸ðµç ¹®ÀÚ¿­ÀÔ´Ï´Ù.

    1. Enterprise Server ±¸¼º¿¡¼­ ÇØ´ç ÄÁÅؽºÆ®¿¡ ´ëÇÑ ÄíÅ° À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.

      Enterprise Server ÆÄÀÏ Web_Server_Root/https-instancename/config/
      contexts.properties
      ¸¦ ÆíÁýÇÏ°í ÆÄÀÏÀÇ ¸Ç ¾Æ·¡ÂÊ¿¡ ÀÖ´Â #IDACONF-Start Çà ¾Õ¿¡ ´ÙÀ½À» Ãß°¡ÇÕ´Ï´Ù.

      context.ims50.sessionCookie=ssogrp1-ida

    1. ims5 ÄÁÅؽºÆ®¿¡ ´ëÇØ UTF8 ¸Å°³ º¯¼ö ÀÎÄÚµùÀ» »ç¿ëÇÕ´Ï´Ù.

      Enterprise Server ±¸¼º¿¡¼­ ims5 ÄÁÅؽºÆ®¿¡ ´ëÇØ UTF8 ¸Å°³ º¯¼ö ÀÎÄÚµùÀ» »ç¿ëÇÏ·Á¸é Enterprise Server WebServer_Root/https-instancename/config/
      contexts.properties
      ÆÄÀÏ¿¡ ´ÙÀ½ Ç׸ñÀ» Ãß°¡ÇÕ´Ï´Ù.

      context.ims50.parameterEncoding=utf8

  5. Messenger Express¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  6. ´Ü°è 1a¿¡¼­ 2c¿¡ ¼³¸íµÈ ´ë·Î ±¸¼ºÀ» º¯°æÇÑ ÈÄ¿¡´Â Messenger Express¸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß º¯°æ ³»¿ëÀÌ Àû¿ëµË´Ï´Ù.

    WebServer_Root/https-iinstance_name/stop
    WebServer_Root/https-instancename/start

  7. ÀÌ SSO ±×·ì¿¡¼­ Calendar¸¦ ¹èÆ÷ÇÏ·Á¸é Calendar Server¸¦ ±¸¼ºÇÕ´Ï´Ù.
  8. ics.conf¸¦ ÆíÁýÇÏ°í ´ÙÀ½À» Ãß°¡ÇÕ´Ï´Ù.

    sso.appid = "ics50"
    sso.appprefix = "ssogrp1"
    sso.cookiedomain = ".red.iplanet.com"
    sso.enable = "1"
    sso.singlesignoff = "true"
    sso.userdomain = "mysystem.red.iplanet.com"
    sso.ims5.url="http://mysystem.red.iplanet.com:80/VerifySSO?"
    sso.ida.url=http://mysystem.red.iplanet.com:8080/VerifySSO?

  9. Calendar Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  10. start-cal

  11. Messenger Express http ¼­¹ö¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  12. msg_svr_base/sbin/stop-msg http
    msg_svr_base/sbin/start-msg http

Messenger ExpressÀÇ ½Å·ÚÇÒ ¼ö ÀÖ´Â SSO ±¸¼º ¸Å°³ º¯¼ö

Ç¥ 4-3¿¡ Ç¥½ÃµÈ °Íó·³ configutil ¸í·ÉÀ» »ç¿ëÇÏ¿© Messenger Express¿¡ ´ëÇÑ ´ÜÀÏ »çÀÎ ¿Â(SSO) ±¸¼º ¸Å°³ º¯¼ö¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. configutil¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Messaging Server Reference ManualÀ» ÂüÁ¶ÇϽʽÿÀ.

Ç¥ 4-3 ½Å·ÚÇÒ ¼ö ÀÖ´Â ¿ø ´ÜÀÏ »çÀÎ ¿Â(SSO) ¸Å°³ º¯¼ö

¸Å°³ º¯¼ö

¼³¸í

local.webmail.sso.enable

·Î±×ÀÎ ÆäÀÌÁö¸¦ °¡Á®¿Ã ¶§ Ŭ¶óÀ̾ðÆ®°¡ Ç¥½ÃÇÑ SSO ÄíÅ° Çã¿ë ¹× È®ÀÎ, ·Î±×Àο¡ ¼º°øÇÑ °æ¿ì Ŭ¶óÀ̾ðÆ®¿¡ SSO ÄíÅ° ¹Ýȯ ¹× ÄíÅ° È®ÀÎÀ» À§ÇØ ´Ù¸¥ SSO ÆÄÆ®³ÊÀÇ ¿äû¿¡ ȸ½Å µîÀ» Æ÷ÇÔÇÏ¿© ¸ðµç ´ÜÀÏ »çÀÎ ¿Â(SSO) ±â´ÉÀ» »ç¿ëÇϰųª »ç¿ëÇÏÁö ¾Ê½À´Ï´Ù.

0ÀÌ ¾Æ´Ñ °ªÀ» ¼³Á¤ÇÏ¸é ¼­¹ö¿¡¼­ ¸ðµç SSO ±â´ÉÀ» ¼öÇàÇÕ´Ï´Ù.

0À» ¼³Á¤ÇÏ¸é ¼­¹ö¿¡¼­ ÀÌ·¯ÇÑ SSO ±â´ÉÀ» ¼öÇàÇÏÁö ¾Ê½À´Ï´Ù.

±âº»°ªÀº 0ÀÔ´Ï´Ù.

local.webmail.sso.prefix

Messenger Express HTTP ¼­¹ö¿¡¼­ ¼³Á¤ÇÑ SSO ÄíÅ°ÀÇ ¼­½ÄÀ» ÁöÁ¤ÇÒ ¶§ ÀÌ ¸Å°³ º¯¼ö ¹®ÀÚ¿­ °ªÀÌ Á¢µÎ¾î °ªÀ¸·Î »ç¿ëµË´Ï´Ù. ÀÌ Á¢µÎ¾î°¡ ÀÖ´Â SSO ÄíÅ°¸¸ ¼­¹ö¿¡ ÀÎ½ÄµÇ¸ç ´Ù¸¥ SSO ÄíÅ°´Â ¸ðµÎ ¹«½ÃµË´Ï´Ù.

ÀÌ ¸Å°³ º¯¼ö¿¡ null °ªÀ» ¼³Á¤ÇÏ¸é ¼­¹ö¿¡¼­ ¸ðµç SSO ±â´ÉÀ» È¿°úÀûÀ¸·Î ºñÈ°¼ºÈ­ÇÒ ¼ö ÀÖ½À´Ï´Ù.

±âº»°ªÀº nullÀÔ´Ï´Ù.

ÀÌ ¹®ÀÚ¿­Àº ÈÄÇà -°¡ ¾ø´Â resource.properties ÆÄÀÏ¿¡¼­ iPlanet Delegated Administrator for Messaging¿¡ »ç¿ëµÈ ¹®ÀÚ¿­°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

NDAAuth-singleSignOnID=ssogrp1-

ÀÌ °ªÀ» ssogrp1·Î ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù.

local.webmail.sso.id

Messenger Express HTTP ¼­¹ö¿¡¼­ ¼³Á¤ÇÑ SSO ÄíÅ°ÀÇ ¼­½ÄÀ» ÁöÁ¤ÇÒ ¶§ ÀÌ ¸Å°³ º¯¼ö ¹®ÀÚ¿­ °ªÀÌ ÀÀ¿ë ÇÁ·Î±×·¥ ¾ÆÀ̵𠰪À¸·Î »ç¿ëµË´Ï´Ù. ±âº»°ªÀº nullÀÔ´Ï´Ù.

ÀÌ °ªÀº ÀÓÀÇÀÇ ¹®ÀÚ¿­ÀÔ´Ï´Ù. ÀÌ °ªÀº resource.properties ÆÄÀÏ¿¡¼­ Delegated Administrator¿¡ ´ëÇØ ÁöÁ¤ÇÑ °ª°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù. resource.propertiesÀÇ ÇØ´ç Ç׸ñÀº ´ÙÀ½°ú °°½À´Ï´Ù.

Verifycationurl-XXX-YYY=http://webmailhost:webmailport/VerifySSO?

¿©±â¼­ XXX´Â À§¿¡¼­ ¼³Á¤ÇÑ local.webmail.sso.prefix °ªÀÌ°í YYY´Â ¿©±â¼­ ¼³Á¤ÇÑ local.webmail.sso.id °ªÀÔ´Ï´Ù.

local.webmail.sso.
cookiedomain

ÀÌ ¸Å°³ º¯¼öÀÇ ¹®ÀÚ¿­ °ªÀº Messenger Express HTTP ¼­¹ö¿¡¼­ ¼³Á¤ÇÑ ¸ðµç SSO ÄíÅ°ÀÇ ÄíÅ° µµ¸ÞÀÎ °ªÀ» ¼³Á¤ÇÏ´Â µ¥ »ç¿ëµË´Ï´Ù. ±âº»°ªÀº nullÀÔ´Ï´Ù.

ÀÌ µµ¸ÞÀÎÀº Messenger Express ºê¶ó¿ìÀú¿¡¼­ ¼­¹ö¿¡ ¾×¼¼½ºÇÏ´Â µ¥ »ç¿ëÇÑ DNS µµ¸ÞÀΰú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù. È£½ºÆ®µÈ µµ¸ÞÀÎ À̸§ÀÌ ¾Æ´Õ´Ï´Ù.

local.webmail.sso.
singlesignoff

0ÀÌ ¾Æ´Ñ °ªÀ¸·Î ¼³Á¤ÇÑ °æ¿ì ÀÌ ¸Å°³ º¯¼öÀÇ Á¤¼ö °ªÀº Ŭ¶óÀ̾ðÆ®°¡ ·Î±×¾Æ¿ôÇÒ ¶§ local.webmail.sso.prefix¿¡ ±¸¼ºµÈ °ª°ú ÀÏÄ¡ÇÏ´Â Á¢µÎ¾î °ªÀ» °®´Â Ŭ¶óÀ̾ðÆ®ÀÇ ¸ðµç SSO ÄíÅ°¸¦ Áö¿ó´Ï´Ù.

0À¸·Î ¼³Á¤Çϸé Messenger Express´Â Ŭ¶óÀ̾ðÆ®°¡ ·Î±×¾Æ¿ôÇÒ ¶§ ÇØ´ç Ŭ¶óÀ̾ðÆ®ÀÇ SSO ÄíÅ°¸¸ Áö¿ó´Ï´Ù.

±âº»°ªÀº 0ÀÔ´Ï´Ù.

local.sso.appid.verifyurl

ÇǾî SSO ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ´ëÇÑ È®ÀÎ URL °ªÀ» ¼³Á¤ÇÕ´Ï´Ù. appid´Â ÇØ´ç SSO ÄíÅ°¸¦ ¼ö¶ôÇÏ´Â ÇǾî SSO ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ ÀÀ¿ë ÇÁ·Î±×·¥ ¾ÆÀ̵ðÀÔ´Ï´Ù. ¿¹¸¦ µé¾î, Delegated Administrator¿¡ ´ëÇÑ ±âº» appid´Â nda45ÀÌ°í ½ÇÁ¦ °ªÀº Delegated Administrator resource.properties ÆÄÀÏ Ç׸ñ NDAAuth-applicationID¿¡ ÀÇÇØ ÁöÁ¤µË´Ï´Ù.

½Å·ÚÇÒ ¼ö ÀÖ´Â °¢ ÇǾî SSO ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ´ëÇØ Á¤ÀÇµÈ ÇϳªÀÇ ¸Å°³ º¯¼ö°¡ ÀÖ¾î¾ß ÇÕ´Ï´Ù. È®ÀÎ URLÀÇ Ç¥ÁØ Çü½ÄÀº ´ÙÀ½°ú °°½À´Ï´Ù.

http://nda-host:port/VerifySSO?

¿©·¯ Messenger Express Multiplexors ¹× Message Store ¼­¹ö(Messenger Express ½ÇÇà) ¶Ç´Â Calendar ÇÁ·±Æ® ¿£µå ¾Õ¿¡ ·Îµå ¹ë·±¼­¸¦ »ç¿ëÇÒ °æ¿ì verifyurl¿¡ ½ÇÁ¦ È£½ºÆ® À̸§À» »ç¿ëÇÏ¿© °¢ ¹°¸®Àû ½Ã½ºÅÛ¿¡ ´ëÇØ ¼­·Î ´Ù¸¥ appid¸¦ ÁöÁ¤ÇØ¾ß ÇÕ´Ï´Ù. ±×·¸°Ô Çϸé ÄíÅ°¸¦ È®ÀÎÇÏ´Â µ¥ ¿Ã¹Ù¸¥ ½Ã½ºÅÛÀÌ »ç¿ëµË´Ï´Ù.



ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


Copyright 2003 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.