Sun logo      ¤W¤@­¶      ¥Ø¿ý      ¯Á¤Þ      ¤U¤@­¶     

Sun ONE Portal Server, Secure Remote Access 6.2 ºÞ²z­û«ü«n

²Ä 2³¹
¹h¹D

¥»³¹»¡©ú»P¹h¹D¬ÛÃöªº·§©À¡A»P¶¶§Q°õ¦æ¹h¹D®É©Ò»Ýªº¸ê°T¡CÃö©ó°t¸m¹h¹Dªº¸ê°T¡A½Ð°Ñ¾\²Ä 9 ³¹¡A¡u°t¸m¹h¹D¡v¡C

¥»³¹²[»\¤U¦C¥DÃD¡G


¹h¹D²¤¶

¹h¹D¦b·½¦Ûºô»Úºô¸ôªº»·ºÝ¨Ï¥ÎªÌ¶¥¬q§@·~»P±zªº¥ø·~¤º³¡ºô¸ô¤§¶¡´£¨Ñ¤F¤¶­±»P¦w¥þ¬É½u¡C³z¹L³æ¤@¤¶­±µ¹»·ºÝ¨Ï¥ÎªÌ¡A¹h¹D¥i¸g¥Ñ¤º³¡ºô¸ô¦øªA¾¹©MÀ³¥Îµ{¦¡¦øªA¾¹¦w¥þ¦aÅã¥Ü¤º®e¡C


«Ø¥ß¹h¹D³]©wÀÉ

¹h¹D³]©wÀÉ¥]§t»P¹h¹D°t¸m¬ÛÃöªº©Ò¦³¸ê°T¡A¨Ò¦p¹h¹D¶ÉÅ¥ªº³s±µ°ð¡BSSL ¿ï¶µ»P¥N²z¦øªA¾¹¿ï¶µ¡C

·í±z¦w¸Ë¹h¹D®É¡A¦pªG±z¿ï¾Ü¹w³]­È¡A«h·|«Ø¥ß¦W¬°¡udefault¡vªº¹w³]¹h¹D³]©wÀÉ¡C»P¹w³]³]©wÀɹïÀ³ªº°t¸mÀÉ·|¥X²{¦b¡G

/etc/opt/SUNWps/platform.conf.default

¨ä¤¤ /etc/opt/SUNWps ¬O©Ò¦³ platform.conf.* Àɮתº¹w³]¦ì¸m¡C

½Ð°Ñ¾\¡u¤F¸Ñ platform.conf Àɮסv ¥H¨ú±o§ó¦hÃö©ó platform.conf Àɮפº®eªº¸ê°T¡C

±z¥i¥H¡G


ª`·N

¤£­n«ü©w¬Û¦Pªº³]©wÀɵ¹¦b¬Û¦P¾÷¾¹¤W°õ¦æªº¹h¹D¤£¦P¹ê¨Ò¡C³o±N·|³y¦¨½Ä¬ð¡A¦]¬°³s±µ°ð¸¹½X·|¤@¼Ë¡C

¤£­n¦b¤£¦Pªº³]©wÀÉ («Ø¥ßµ¹¬Û¦Pªº¹h¹D) ¤¤«ü©w¬Û¦Pªº³s±µ°ð¸¹½X¡C¥H¦P¼Ëªº³s±µ°ð°õ¦æ¬Û¦P¹h¹Dªº¦h­Ó¹ê¨Ò·|³y¦¨½Ä¬ð¡C


    «Ø¥ß¹h¹D³]©wÀÉ
  1. ¥HºÞ²z­ûªº¨­¥÷µn¤J Sun™ ONE Identity Server ºÞ²z¥D±±¥x¡C
  2. ¿ï¨ú¡uªA°È°t¸m¡v¼ÐÅÒ¡C
  3. «ö¤@¤U¡uSRA °t¸m¡v¤U¡u¹h¹D¡v®Çªº½bÀY¡C
  4. ¹h¹D­¶­±·|Åã¥Ü¦b¥kÃ䪺µ¡®æ¤¤¡C

  5. «ö¤@¤U¡u·s¼W¡v¡C
  6. «Ø¥ß·s¹h¹D³]©wÀÉ­¶­±·|Åã¥Ü¡C

  7. ¿é¤J·s¡u¹h¹D³]©wÀÉ¡v¦WºÙ¡C
  8. ¿ï¨ú±ý¨Ï¥Îªº³]©wÀÉ¡A¥H¦b¤U©Ô¦¡²M³æ¤¤«Ø¥ß·s³]©wÀÉ¡C
  9. ¦b¹w³]±¡ªp¤U¡A±z«Ø¥ßªº¥ô¦ó·s³]©wÀɳ£¬O¥H¹w¥ý«Ê¸Ëªº¹w³]³]©wÀɬ°°ò¦¡C¦pªG±z¤w¸g«Ø¥ß¦Û­qªº³]©wÀÉ¡A«h¥i¥H±q¤U©Ô²M³æ¤¤¿ï¾Ü¸Ó³]©wÀÉ¡C·sªº³]©wÀÉ·|Ä~©Ó©Ò¿ï³]©wÀɪº©Ò¦³ÄݩʡC

  10. «ö¤@¤U¡u«Ø¥ß¡v¡C
  11. ·|«Ø¥ß·sªº³]©wÀÉ¡A¦Ó±z·|¦^¨ì¡u¹h¹D¡v­¶­±¡A·sªº³]©wÀÉ·|¦C¦b¦¹³B¡C

  12. ¦pªG±z·Q­nÅýÅܧó¥Í®Ä¡A½Ð¨Ï¥Î·sªº¹h¹D³]©wÀɦWºÙ­«·s±Ò°Ê¹h¹D¡G
  13. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start

­Y­n°t¸m¹h¹D¡A½Ð°Ñ¾\²Ä 9 ³¹¡A¡u°t¸m¹h¹D¡v¡C


¤F¸Ñ platform.conf ÀÉ®×

platform.conf Àɮצì©ó¡G

/etc/opt/SUNWps

platform.conf ÀÉ®×¥]§t¹h¹D©Ò»Ýªº¸Ô²Ó¸ê°T¡C¥»¸`´£¨Ñ¤@­Ó½d¨Ò platform.conf ÀɮסA¨Ã»¡©ú©Ò¦³ªº¶µ¥Ø¡C

¦b°t¸mÀɤ¤¥]§t©Ò¦³¾÷¾¹¯S©w¸Ô²Ó¸ê®ÆªºÀuÂI¡A´N¬O¦@¥Îªº³]©wÀÉ¥i¥H³Q¦b¦h­Ó¾÷¾¹¤W°õ¦æªº¹h¹D¦@¨É¡C

½d¨Ò¦p¤U¡G

#

# Copyright 11/28/00 Sun Microsystems, Inc. All Rights Reserved.

# "@(#)platform.conf1.38 00/11/28 Sun Microsystems"

#

gateway.user=noaccess

gateway.jdk.dir=/usr/java_1.3.1_06

gateway.dsame.agent=http://pserv2.iportal.com:8080/sunportal/RemoteConfigS ervlet

portal.server.protocol=http

portal.server.host=pserv2.iportal.com

portal.server.port=8080

gateway.protocol=https

gateway.host=siroe.india.sun.com

gateway.port=333

gateway.trust_all_server_certs=true

gateway.trust_all_server_cert_domains=false

gateway.virtualhost=siroe1.india.sun.com 10.13.147.81

gateway.virtualhost.defaultOrg=o=root,dc=test,dc=com

gateway.notification.url=/notification

gateway.retries=6

gateway.debug=error

gateway.debug.dir=/var/opt/SUNWps/debug

gateway.logdelimiter=&&

gateway.external.ip=10.12.147.71

gateway.certdir=/etc/opt/SUNWps/cert/portal

gateway.allow.client.caching=true

gateway.userProfile.cacheSize=1024

gateway.userProfile.cacheSleepTime=60000

gateway.userProfile.cacheCleanupTime=300000

gateway.bindipaddress=10.12.147.71

gateway.sockretries=3

gateway.enable.accelerator=false

gateway.enable.customurl=false

gateway.httpurl=http://siroe.india.sun.com

gateway.httpsurl=https://siroe.india.sun.com

gateway.favicon=https://siroe.india.sun.com

gateway.logging.password=ALKJDF123SFLKJJSDFU

ªí 2-1 ¦C¥X¨Ã»¡©ú¦b platform.conf Àɤ¤©Ò¦³ªºÄæ¦ì¡C¦¹ªí®æ¨ã¦³¤T­ÓÄæ¡C ²Ä¤@Äæ¦C¥XÀɮפ¤ªº¶µ¥Ø¡A²Ä¤GÄæ´£¨Ñ¹w³]­È (¦pªG¦³ªº¸Ü)¡A²Ä¤TÄæ´£¨Ñ¸ÓÄæ¦ìªºÂ²³æ»¡©ú¡C

ªí 2-1 platform.conf ÀÉ®×ÄÝ©Ê

¶µ¥Ø

¹w³]­È

»¡©ú

gateway.user

noaccess

¹h¹D¥H¦¹¨Ï¥ÎªÌ°õ¦æ¡C

¹h¹D¥²¶·¥H®Ú¨Ï¥ÎªÌ±Ò©l¡A¦b¦w¸Ë«á·|¿ò¥¢®Ú¨Ï¥ÎªÌªº¯SÅv¦ÓÅܦ¨¦¹¨Ï¥ÎªÌ¡C

gateway.jdk.dir

 

³o¬O¹h¹D©Ò¨Ï¥Î¤§ JDK ¥Ø¿ýªº¦ì¸m¡C

gateway.dsame.agent

 

·í¹h¹D±Ò°Ê­n¨ú±o¨ä³]©wÀɮɡA³o¬O¹h¹D·|Ápµ¸ªºÃѧO¦øªA¾¹ URL¡C

portal.server.
protocol

portal.server.host

portal.server.port

 

³o¬O¹w³] Portal Server ¦w¸Ë¨Ï¥Îªº³q°T¨ó©w¡B¥D¾÷©M³s±µ°ð¡C

gateway.protocol
gateway.host
gateway.port

 

³o¬O¹h¹Dªº³q°T¨ó©w¡B¥D¾÷©M³s±µ°ð¡C³o¨Ç­È»P±z¦b¦w¸Ë®É©Ò«ü©wªº¼Ò¦¡©M³s±µ°ð¬Û¦P¡C³o¨Ç­È¥Î©ó«Ø¥ß³qª¾ URL¡C

gateway.trust_all_
server_certs

true

³oªí¥Ü¹h¹D¥²¶·¬Û«H©Ò¦³ªº¦øªA¾¹ÃҮѡA©Î¶È¬Û«H¦b¹h¹DÃÒ®Ñ¸ê®Æ®w¤¤ªº¦øªA¾¹ÃҮѡC

gateway.trust_all_
server_cert_domains

false

µL½×¦ó®É¦b¹h¹D©M¦øªA¾¹¤§¶¡³£·|¦³­Ó SSL ³q°T¡A¨Ã¥B·|´£¨Ñ¦øªA¾¹ÃҮѵ¹¹h¹D¡C¦b¹w³]±¡ªp¤U¡A¹h¹D·|Àˬd¦øªA¾¹¥D¾÷¦WºÙ¬O§_»P¦øªA¾¹ÃÒ®Ñ CN ¬Û¦P¡C

¦pªGÄݩʭȳ]©w¬° true¡A«h¹h¹D·|°±¥Î¥¦¦¬¨ì¤§¦øªA¾¹ÃҮѪººô°ì¦WºÙÀˬd¡C

gateway.virtualhost

 

¦pªG¹h¹D¾÷¾¹¦³°t¸m¦h­Ó¥D¾÷¦WºÙ¡A±z¥i¥H¦b¦¹Äæ¦ì«ü©w¤£¦Pªº¦WºÙ©MÃѧO´£¨ÑªÌ¦ì§}¡C

gateway.virtualhost.defaultOrg=org

 

³o·|«ü©w¹w³]ªº Org µ¹±Nµn¤Jªº¨Ï¥ÎªÌ¡C

¨Ò¦p°²³]µêÀÀ¥D¾÷Äæ¦ì¶µ¥Ø¦p¤U©Ò¥Ü¡G

gateway.virtualhost=test.com employee.test.com

Managers.test.com

§t¦³¹w³]ªº org ¶µ¥Ø¬°¡G

test.com.defaultOrg = o=root,dc=test,dc=com

employee.test.com.defaultOrg = o=employee,dc=test,dc=com

Manager.test.com.defaultOrg = o=Manager,dc=test,dc=com

¨Ï¥ÎªÌ¥i¥H¨Ï¥Î https://manager.test.com ¦Ó«Dhttps://test.com/o=Manager,dc=test,dc=com ¥Hµn¤JºÞ²z­ûªº org¡C

ª`·N¡Gvirtualhost ©M defaultOrg ¦b platform.conf file ¤¤°Ï¤À¤j¤p¼g¡A¦ý¥Î©ó URL ®É«h¨S¦³°Ï¤À¡C

gateway.
notification.url

 

¹h¹D¥D¾÷¡B³q°T¨ó©w©M³s±µ°ðªº²Õ¦X¡A¥Î©ó«Ø¥ß³qª¾ URL¡C¥Î©ó±q Identity Server ±µ¦¬¶¥¬q§@·~³qª¾¡C

½Ð½T©w³qª¾ URL ©M¥ô¦ó²Õ´ªº¦WºÙ¤£¬Û¦P¡C¦pªG³qª¾ URL ©M²Õ´¦WºÙ¬Û¦P¡A«h¨Ï¥ÎªÌ¦b¹Á¸Õ³sµ²¨ì¸Ó²Õ´®É·|¬Ý¨ìªÅ¥Õ­¶­±¦Ó«Dµn¤Jªº­¶­±¡C

gateway.retries

 

¦¹¼Æ¦r¬O¦b±Ò°Ê®É¡A¹h¹D¹Á¸Õ³sµ¸ Portal Server ªº¦¸¼Æ¡C

gateway.debug

error

³]©w¹h¹Dªº°£¿ù¼h¯Å¡C°£¿ùÀɮצì©ó debug-directory/files¡C°£¿ùÀɮצì¸m«ü©w¦b gateway.debug.dir ¶µ¥Ø¤¤¡C

°£¿ù¼h¯Å¬°¡G

error - ¥u·|¦b°£¿ùÀɮפ¤°O¿ý´X­Ó¿ù»~¡C¦b¦¹ºØ¿ù»~µo¥Í®É¡A¹h¹D³q±`·|°±¤î¹B§@¡C

warning - ·|°O¿ýĵ§i°T®§¡C

message - ·|°O¿ý©Ò¦³ªº°£¿ù°T®§¡C

on - ·|¦b¥D±±¥xÅã¥Ü©Ò¦³ªº°£¿ù°T®§¡C

°£¿ùÀɮ׬°¡G

srapGateway.gateway-profile-name - ¥]§t¹h¹Dªº°£¿ù°T®§¡C

Gateway_to_from_server.gateway-profile-name - ¦b°T®§¼Ò¦¡¤U¡A¦¹ÀÉ®×¥]§t¹h¹D©M¤º³¡¦øªA¾¹¤§¶¡©Ò¦³ªº»Ý¨D©M¦^À³¼ÐÀY¡C

­n²£¥Í¦¹ÀɮסA½ÐÅܧó /var/opt/SUNWps/debug ¥Ø¿ýªº¼g¤JÅv­­¡C

Gateway_to_from_browser.gateway-profile-name - ¦b°T®§¼Ò¦¡¤U¡A¦¹ÀÉ®×¥]§t¹h¹D©M¤º³¡¦øªA¾¹¤§¶¡©Ò¦³ªº»Ý¨D©M¦^À³¼ÐÀY¡C

­n²£¥Í¦¹ÀɮסA½ÐÅܧó /var/opt/SUNWps/debug ¥Ø¿ýªº¼g¤JÅv­­¡C

gateway.debug.dir

 

³o¬O©Ò¦³°£¿ùÀɮײ£¥Íªº¥Ø¿ý¡C

¦¹¥Ø¿ý¥²¶·¦³¨¬°÷ªºÅv­­¡AÅý¦b gateway.user ¤¤´£¨ìªº¨Ï¥ÎªÌ¼g¤JÀɮסC

gateway.
logdelimiter

 

¥Ø«e¨S¦³¨Ï¥Î¡C

gateway.external.ip

 

¦pªG¦³¦h­Ó¦a§}ªº¹h¹D¾÷¾¹ (¤@­Ó¹h¹D¾÷¾¹¦³¦h­Ó IP ¦ì§}) ¡A±z»Ý­n¦b¦¹«ü©w¥~³¡ªº IP ¦ì§}¡C¦¹ IP ¥Î©ó Netlet ¥H°õ¦æ FTP¡C

gateway.certdir

 

¥¦«ü©wÃÒ®Ñ¸ê®Æ®wªº¦ì¸m¡C

gateway.allow.
client.caching

true

¤¹³\©Î©Úµ´¥Î¤áºÝ§Ö¨ú¡C

¦pªG¤¹³\¡A¥Î¤áºÝ¦øªA¾¹¥i¥H§Ö¨úÀRºA­¶­±©M¼v¹³¥H¨ú±o¸û¨Îªº®Ä¯à (ÂǥѴî¤Öªººô¸ô¬y¶q)¡C

¦pªG¤£¤¹³\¡A¦b¥Î¤áºÝªº¦w¥þ©Ê·|´£°ª¡A¹³¬O¨S¦³§Ö¨ú¤@¼Ë¡A¦ý¬O¦b¸û°ªºô¸ô­t¸üªº±¡ªp¤U®É®Ä¯à±N·|­°§C¡C

gateway.userProfile.cacheSize

 

³o¬O¦b¹h¹D¤W¨Ï¥ÎªÌ³]©wÀɶµ¥Ø³Q§Ö¨úªº¼Æ¥Ø¡C¦pªG¶µ¥Ø¼Æ¶q¶W¹L³o­Ó­È¡A±`¥Îªº¶µ¥Ø·|²M°£§Ö¨ú¡C

gateway.userProfile.cacheSleepTime

 

¥H¬í¬°³æ¦ì³]©w¥ð®§®É¶¡¡A¥H²M°£§Ö¨ú¡C

gateway.userProfile.cacheCleanupTime

 

¶W¹L¥H¬í¬°³æ¦ìªº³Ì¤j¼Æ¦rªº®É¶¡«á¡A·|²¾°£³]©wÀɶµ¥Ø¡C

gateway.
bindipaddress

 

¦b¦h¦a§}¹h¹D¾÷¾¹¤W¡A³o¬O¹h¹D³s±µ¨ä¦øªA¾¹´¡¼Ñªº IP ¦ì§}¡C

gateway.sockretries

3

¥Ø«e¨S¦³¨Ï¥Î¡C

gateway.enable.accelerator

false

¦pªG³]©w¬° true¡A«h¤¹³\¤ä«ù¥~³¡¥[³t¾¹¡C

gateway.enable.customurl

false

¦pªG³]©w¬° true¡A«h¤¹³\ºÞ²z­û«ü©w¤@­Ó¦Û­qªº URL Åý¹h¹D­«·s¼g¤J­¶­±¡C

gateway.httpurl

 

¿é¤J HTTP reverseproxy URL ¥H³]©w¦Û­qªº URL Åý¹h¹D­«·s¼g¤J­¶­±¡C

gateway.httpsurl

 

¿é¤J HTTPS reverseproxy URL ¥H³]©w¦Û­qªº URL Åý¹h¹D­«·s¼g¤J­¶­±¡C

gateway.favicon

 

¥¦«ü©w¹h¹D±N¬° favicon.ico ÀÉ­«·s¾É¦V»Ý¨Dªº URL¡C

¦¹¶µ¥Ø¥Î©ó Internet Explorer¡BNetscape 7.0 ©M§ó°ªªº³ß¦n³]©w©Î§Úªº³Ì·R¤¤ªº¡ufavorite icon¡v¡C

¦pªG¦¹¶µ¥Ø«O«ùªÅ¥Õ¡A¹h¹D·|¶Ç°e¤@­Ó¡u404 ­¶­±§ä¤£¨ì¡vªº°T®§µ¹ÂsÄý¾¹¡C

gateway.logging.password

 

¦¹Äæ¦ì¥]§t¨Ï¥ÎªÌ¡uamService-srapGateway¡vªº LDAP ±K½X¡A¹h¹D·|¨Ï¥Î¸Ó±K½X¥Î¥H«Ø¥ß¨äÀ³¥Îµ{¦¡¶¥¬q§@·~¡C

±K½X¥i¥H¬O¥[±K¤å¦r©Î¤@¯ë¤å¦r¡C

http.proxyHost

 

¥N²z¦øªA¾¹¥D¾÷·|¥Î©óÁpµ¸ Portal Server¡C

http.proxyPort

 

¥D¾÷³s±µ°ð·|¥Î©óÁpµ¸ Portal Server¡C

http.proxySet

 

­Y»Ý­n¥N²z¦øªA¾¹¡A«hÄݩʷ|³]©w¬° true¡C ­YÄݩʳ]©w¬° false¡A«h·|©¿²¤ http.proxyHost »P http.proxyPort¡C


±Ò°Ê©M°±¤î¹h¹D

¦b¹w³]±¡ªp¤U¡A¹h¹D¥H¨Ï¥ÎªÌ noaccess ±Ò°Ê¡C

   ±Ò°Ê¹h¹D
  1. ¦w¸Ë¹h¹D¨Ã«Ø¥ß»Ý­nªº³]©wÀÉ«á¡A°õ¦æ¤U­±ªº«ü¥O¥H±Ò°Ê¹h¹D¡G
  2. gateway-install-root/SUNWps/bin/gateway -n default start

    default ¬O¦b¦w¸Ë®É«Ø¥ßªº¹w³]¹h¹D³]©wÀÉ¡C±z¥i¥Hµy«á«Ø¥ß¦Û¤vªº³]©wÀÉ¡A¨Ã¥B¥Î·sªº³]©wÀÉ­«·s±Ò°Ê¹h¹D¡C½Ð°Ñ¾\¡u«Ø¥ß¹h¹D³]©wÀÉ¡v¡C

    ¦pªG±z¦³¦h¹h¹D¹ê¨Ò¡A½Ð¨Ï¥Î¡G

    gateway-install-root/SUNWps/bin/gateway start

¦¹«ü¥O·|±Ò°Ê©Ò¦³¦b¸Ó¯S©w¾÷¾¹¤W°t¸mªº¹h¹D¹ê¨Ò¡C


³Æµù

­«·s±Ò°Ê¦øªA¾¹ (§Y¬°±z¤w¸g°t¸m¹h¹D¹ê¨Ò©ó¨ä¤Wªº¾÷¾¹) ·|­«·s±Ò°Ê©Ò¦³¹h¹D¤w¸g°t¸mªº¹ê¨Ò¡C

½T©w¦b /etc/opt/SUNWps ¥Ø¿ý¤¤¨S¦³Âªº©Î³Æ¥÷ªº³]©wÀÉ¡C


  1. °õ¦æ¤U¦C«ü¥O¨ÓÀˬd¹h¹D¬O§_¦b«ü©wªº³s±µ°ð¤W°õ¦æ¡G
  2. netstat -a | grep port-number

    ¹w³]ªº¹h¹D³s±µ°ð¬O 443¡C

   °±¤î¹h¹D

¨Ï¥Î¤U­±ªº«ü¥O¥H°±¤î¹h¹D¡G

gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name stop

¦pªG±z¦³¦h¹h¹D¹ê¨Ò¡A½Ð¨Ï¥Î¡G

gateway-install-root/SUNWps/bin/gateway stop

¦¹«ü¥O·|°±¤î©Ò¦³¦b¸Ó¯S©w¾÷¾¹¤W¥¿¦b°õ¦æªº¹h¹D¹ê¨Ò¡C


­«·s±Ò°Ê¹h¹D

¤@¯ë¦Ó¨¥¡A±z¤£»Ý­n­«·s±Ò°Ê¹h¹D¡C¦ý¦pªG¤U¦C¨Æ¥óµo¥Í¡A±z´N»Ý­n­«·s±Ò°Ê¹h¹D¡G

   ¨Ï¥Î¤£¦Pªº³]©wÀÉ­«·s±Ò°Ê¹h¹D

­«·s±Ò°Ê¡u¹h¹D¡v¡G

gateway-install-root/SUNWps/bin/gateway -n new-gateway-profile-name start

   ­Y­n­«·s±Ò°Ê¹h¹D

¦b²×ºÝ¾÷µøµ¡¤¤¡A¥H®Ú¨Ï¥ÎªÌ¨­¤À³s±µ¨Ã°õ¦æ¤U¦C¨ä¤¤¤§¤@¡G

   °t¸m¹h¹DºÊµøµ{¦¡

±z¥i¥H°t¸mºÊµøµ{¦¡ºÊµø¹h¹Dª¬ºAªº®É¶¡¶¡¹j¡C®É¶¡¶¡¹j¹w³]¬° 60 ¬í¡C­Y­nÅܧó¡A¦b crontab ¤¤½s¿è¤U­±ªº¦æ¡G

0-59 * * * * gateway-install-root/SUNWps/bin/rwproxd/bin/checkgw /var/opt/SUNWps/.gw.5 > /dev/null 2>&1

½Ð°Ñ¾\ crontab ªº½u¤W»¡©ú¥H°t¸m crontab ¶µ¥Ø¡C


«ü©w¥N²z¦øªA¾¹¥HÁpµ¸ Identity Server

±z¥i¥H«ü©w¡u¹h¹D¡v¥Î¥HÁpµ¸ SRA ¤ä´© (RemoteConfigServlet) ªº¥D¾÷¥N²z¦øªA¾¹¡A¸Ó SRA ¤ä´©³¡¸p¦b Portal Server ¤W¡C¡u¹h¹D¡v¨Ï¥Î¦¹¥N²z¦øªA¾¹³sµ¸ Portal Server »P PIdentity Server¡C

   ­Y­n«ü©w¥N²z¦øªA¾¹
  1. ±q«ü¥O¦æ¤¤¡A½s¿è¤U¦CÀɮסG
  2. /etc/opt/bin/platform.conf.gateway-profile-name

  3. ·s¼W¤U¦C¶µ¥Ø¡G
  4. http.proxyHost=proxy-host

    http.proxyPort=proxy-port

    http.proxySet=true

  5. ¬°°w¹ï¸Ó¦øªA¾¹©Ò´£¥Xªº½Ð¨D­«·s±Ò°Ê¹h¹D¡A¥H¨Ï¥Î«ü©wªº¥N²z¦øªA¾¹¡G
  6. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start


¦b chroot Àô¹Ò¤¤°õ¦æ¹h¹D

­Y­n¦b chroot Àô¹Ò¤¤´£¨Ñ¸û°ª¦w¥þ©Ê¡Achroot ¥Ø¿ý¤º®e¥²¶·ºÉ¥i¯àÁY¤p¡C¨Ò¦p¡A¦pªG¦³¥ô¦óµ{¦¡¤¹³\¨Ï¥ÎªÌ­×§ï¦b chrooted ¥Ø¿ý¤ºªºÀɮסA¦b chroot ¾ð¤U chrooted ±N¤£·|«OÅ@¦øªA¾¹¤£³Q§ðÀ»ªÌ­×§ïÀɮסC¤£À³¸Ó¦b CGI µ{¦¡¤¤¼g¤J¸ÑĶ»y¨¥¡A¨Ò¦p bourne shell¡Bc-shell¡Bkorn shell ©Î perl¡A¦ý¬OÀ³¸Ó½sͤG¶i¦ì¥H¨Ï¸Ñ;¹¤£»Ý­n¦b chroot ¥Ø¿ý¾ð¤U¥X²{¡C


³Æµù

ºÊµøµ{¦¡¥\¯à¤£À³¸Ó¦s¦b©ó chroot Àô¹Ò¤¤¡C


   ¦w¸Ë chroot
  1. §@¬°®Ú¨Ï¥ÎªÌ¡A¦b²×ºÝµøµ¡¤¤½Æ»s¤U¦CÀɮרì¥~³¡¸ê·½¡A¨Ò¦p¦bºô¸ô¤Wªº¹q¸£¡B³Æ¥÷ºÏ±a©Î¬OºÏ¤ù¤¤¡C
  2. cp /etc/vfstab external-device

    cp /etc/nsswitch.conf external-device

    cp /etc/hosts external-device

  3. ±q mkchroot script °õ¦æ¡G
  4. portal-server-install-root/SUNWps/bin/chroot


    ³Æµù

    ¦b mkchroot script ¶}©l°õ¦æ«á¡A¤£¯à«ö Ctrl-C ¥[¥H²×¤î¡C

    ¦b°õ¦æ mkchroot script «á¡A¿ù»~¨Æ¥ó½Ð°Ñ¾\¡umkchroot Script °õ¦æ¥¢±Ñ¡v¡C


·|´£¥Ü±z¥t¤@­Ó®Ú¨Ï¥ÎªÌ¥Ø¿ý (new_root_directory) ¡Cµ{¦¡Àɫإߦ¹·sªº¥Ø¿ý¡C

¦b¤U¦Cªº¹ê¨Ò¤¤¡A/safedir/chroot ¬O new_root_directory¡C

mkchroot version 6.0

Enter the full path name of the directory which will be the chrooted tree:/safedir/chroot

Using /safedir/chroot as root.

Checking available disk space...done

/safedir/chroot is on a setuid mounted partition.

Creating filesystem structure...dev etc sbin usr var proc opt bin lib tmp etc/lib usr/platform usr/bin usr/sbin usr/lib usr/openwin/lib var/opt var/tmp dev/fd done

Creating devices...null tcp ticots ticlts ticotsord tty udp zero conslog done

Copying/creating etc files...group passwd shadow hosts resolv.conf netconfig nsswitch.conf

done

Copying binaries...................................done

Copying libraries.....................................done

Copying zoneinfo (about 1 MB)..done

Copying locale info (about 5 MB)..........done

Adding comments to /etc/nsswitch.conf ...done

Creating loopback mount for/safedir/chroot/usr/java1.2...done

Creating loopback mount for/safedir/chroot/proc...done

Creating loopback mount for/safedir/chroot/dev/random...done

Do you need /dev/fd (if you do not know what it means, press return)[n]:

Updating /etc/vfstab...done

Creating a /safedir/chroot/etc/mnttab file, based on these loopback mounts.

Copying SRAP related data ...

Using /safedir/chroot as root.

Creating filesystem structure...........done

mkchroot successfully done.

  1. ¨Ï¥Î¤U­±ªº«ü¥O¥H¤â°Ê¸Ë¸ü platform.conf Àɮפ¤´£¨ìªº Java ¥Ø¿ý¨ì chroot ¥Ø¿ý¡G
  2. mkdir -p /safedir/chroot/java-dir

    mount -F lofs java-dir /safedir/chroot/java-dir

    ¦b Solaris 9 «h°õ¦æ¤U¦C°Ê§@¡G

    mkdir -p /safedir/chroot/usr/lib/32

    mount -F lofs /usr/lib/32 /safedir/chroot/usr/lib/32

    mkdir -p /safedir/chroot/usr/lib/64

    mount -F lofs /usr/lib/64 /safedir/chroot/usr/lib/64

    ­Y­n¦b¨t²Î±Ò°Ê®É¸Ë¸ü¦¹¥Ø¿ý¡A«h·s¼W¹ïÀ³ªº¶µ¥Ø©ó /etc/vfstab¤¤¡G

    java-dir - /safedir/chroot/java-dir lofs - no -

    ¹ï©ó Solaris 9¡G

    /usr/lib/32 - /safedir/chroot/usr/lib/32 lofs - no -

    /usr/lib/64 - /safedir/chroot/usr/lib/64 lofs - no -

  3. Áä¤J¤U¦Cªº«ü¥O¥H­«·s±Ò°Ê¹h¹D¡G
  4. chroot /safedir/chroot ./gateway-install-root/SUNWps/bin/gateway start

    stopping gateway ... done.

    starting gateway ...

    done.

mkchroot Script °õ¦æ¥¢±Ñ

¦b°õ¦æ mkchroot script ®Éµo¥Í¿ù»~¨Æ¥ó¡Ascript ±N·|§âÀÉ®×´_­ì¦¨ªì©lªºª¬ºA¡C

¦b¤U­±ªº½d¨Ò¤¤¡A/safedir/chroot ¬O chroot ¥Ø¿ý¡C

¦pªG¹J¨ì¤U­±ªº¿ù»~°T®§¡G

Not a Clean Exit

  1. ½Æ»sµ{§Ç¦w¸Ë chroot ¨BÆJ 1 ¤¤ªº³Æ¤ÀÀɮר쥦­Ì­ì¨Óªº¦ì¸m¡A¨Ã°õ¦æ¤U¦C«ü¥O¡G
  2. umount /safedir/chroot/usr/java1.2

    umount /safedir/chroot/proc

    umount /safedir/chroot/dev/random

  3. ²¾°£ /safedir/chroot ¥Ø¿ý¡C


¦b chroot Àô¹Ò¤¤­«·s±Ò°Ê¹h¹D

¨C·í¹h¹D¾÷¾¹­«·s¶}¾÷®É¡A¦b chroot Àô¹Ò¤¤¿í´`¤U¦C¨BÆJ¥H±Ò°Ê¹h¹D¡C

   ¦b chroot Àô¹Ò¤¤­«·s±Ò°Ê¹h¹D
  1. ±q¡u/¡v¥Ø¿ý°±¤î¹h¹Dªº¹B§@¡C
  2. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name stop

  3. ±Ò°Ê¹h¹D¥H±q chroot ¥Ø¿ý°õ¦æ¡G
  4. chroot /safedir/chroot ./portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start


    ³Æµù

    »Ý­nºÞ²z /safedir/chroot/etc ÀÉ®× (¨Ò¦p passwd ©M hosts)¡A¹³ /etc Àɮפ@¼Ë¡A¦ý¶È¥]§t¦b chroot ¾ð¤¤°õ¦æµ{¦¡©Ò»Ý­nªº¥D¾÷©M±b¸¹¸ê°T¡C

    ¨Ò¦p¡A¦pªG±zÅܧó¤F¨t²ÎªºÃѧO´£¨ÑªÌ¦a§}¡A±z¦P®É¤]Åܧó¤F /safedir/chroot/etc/hosts ÀɮסC



«Ø¥ß¹h¹Dªº¦h­Ó¹ê¨Ò

¨Ï¥Î gwmultiinstance µ{¦¡ÀÉ¥H«Ø¥ß¹h¹Dªº·s¹ê¨Ò¡C³Ì¦n¦b«Ø¥ß¹h¹D³]©wÀɤ§«á°õ¦æ¦¹µ{¦¡ÀÉ¡C

  1. ¥H®Ú¨Ï¥ÎªÌ¨­¤Àµn¤J¨ÃÂsÄý¦Ü¤U­±ªº¥Ø¿ý¡G
  2. gateway-install-root/SUNWps/bin/

  3. °õ¦æ¦h¹ê¨Òµ{¦¡ÀÉ¡G
  4. ./gwmultiinstance

  5. ¿ï¾Ü¤U¦C¦w¸Ë¿ï¶µ¤§¤@¡G
  6. 1) Create a new gateway instance («Ø¥ß·sªº¹h¹D¹ê¨Ò)

    2) Remove a gateway instance (²¾°£¤@­Ó¹h¹D¹ê¨Ò)

    3) Remove all gateway instances (²¾°£©Ò¦³¹h¹D¹ê¨Ò)

    4) Exit (µ²§ô)

    ¦pªG±z¿ï¾Ü 1¡A«h½Ð¦^µª¤U¦C°ÝÃD¡G

    What is the name of the new gateway instance? (·s¹h¹D¹ê¨Òªº¦WºÙ¬°¦ó?)

    What protocol will the new gateway instance use? (¦¹·s¹h¹D¹ê¨Ò±N·|¨Ï¥Î­þ­Ó³q°T¨ó©w?)[https]

    What port will the new gateway instance listen on? (·s¹h¹D¹ê¨Ò±N·|¦b­þ­Ó³s±µ°ð¤W¶ÉÅ¥?)

    What is the fully qualified hostname of the portal server? (¦øªA¾¹ªº§¹¥þ¦X®æ¥D¾÷¦WºÙ¬°¦ó?)

    What port should be used to access the portal server? (À³¸Ó¨Ï¥Î­þ­Ó³s±µ°ð¥H¦s¨úPortal Server?)

    What protocol should be used to access the portal server? (À³¸Ó¨Ï¥Î­þ­Ó³q°T¨ó©w¥H¦s¨úPortal Server?)[http]

    What is the portal server deploy URI? (¤°»ò¬OPortal Server§G¸m URI?)

    What is the organization DN? (²Õ´ªº DN ¬°¦ó?)[dc=iportal,dc=com]

    What is the identity server URI? (ÃѧO¦øªA¾¹ URI ¬°¦ó?)[/amserver]

    What is the identity server password encryption key? (ÃѧO¦øªA¾¹±K½X¥[±Kª÷Æ_¬°¦ó?)

    Please provide the following information needed for creating a self-signed certificate: (½Ð´£¨Ñ¤U¦C©Ò»Ý¸ê°T¥H«Ø¥ß¦ÛñÃҮѡG)

    What is the name of your organization? (±zªº²Õ´¦WºÙ¬°¦ó?)

    What is the name of your division? (±zªº¤À³¡¦WºÙ¬°¦ó?)

    What is the name of your city or locality? (±zªº«°¥«©Î¦a°Ï¦WºÙ¬°¦ó?)

    What is the name of your state or province? (±zªº¦{¦W©Î¬Ù¦W¬°¦ó?)

    What is the two-letter country code? (±zªº¨â­Ó¦r¥À°ê½X¬°¦ó?)

    What is the password for the Certificate Database? Again? (ÃÒ®Ñ¸ê®Æ®wªº±K½X¬°¦ó? ¦A¸Õ¤@¦¸?)

    What is the password for the logging user?Again? (°O¿ý¨Ï¥ÎªÌªº±K½X¬°¦ó? ¦A¸Õ¤@¦¸?)

    Have you created the new gateway profile in the admin console? (±z¦bºÞ²z¥D±±¥x¬O§_¤w¸g«Ø¥ß·sªº¹h¹D³]©wÀÉ?)[y]/n

    Start the gateway after installation? (¦w¸Ë«á±Ò°Ê¹h¹D?)[y]/n

  7. ¥H·sªº¹h¹D³]©wÀɦWºÙ±Ò°Ê¹h¹Dªº·s¹ê¨Ò¡C
  8. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start

    ¨ä¤¤ gateway-profile-name ¬O·sªº¹h¹D¹ê¨Ò¡C


¨Ï¥Îºô¸ô¥N²z¦øªA¾¹

±z¥i¥H¨Ï¥Î¨ó¤O¼t°Óªººô¸ô¥N²z¦øªA¾¹¡A°t¸m¹h¹D¥HÁpµ¸ HTTP ¸ê·½¡Cºô¸ô¦øªA¾¹¦ì©ó«È¤áºÝ»Pºô»Úºô¸ô¤§¶¡¡C

ºô¸ô¥N²z¦øªA¾¹°t¸m

¤£¦Pªº¥N²z¦øªA¾¹¥i¯à¥Î©ó¤£¦Pªººô°ì©M¤lºô°ì¡C³o¨Ç¶µ¥Ø§i¶D¹h¹D¦b¯S©wªººô°ì¤¤¡AÀ³¸Ó¨Ï¥Î­þ­Ó¥N²z¦øªA¾¹¥HÁpµ¸¯S©wªº¤lºô°ì¡C«ü©w¦b¹h¹D¤¤ªº¥N²z¦øªA¾¹°t¸m¹B§@¤è¦¡¦p¤U¡G

­Y­n°t¸m¡u¨Ï¥Î¥N²z¦øªA¾¹¡v¿ï¶µ¡A½Ð°Ñ¾\¡u±Ò¥Îºô¸ô¥N²z¦øªA¾¹ªº¨Ï¥Î¡v¡C

¹Ï 2-1 Åã¥Ü¦b¹h¹DªA°È¤¤¡A¦p¦ó¦b¥N²z¦øªA¾¹°t¸mªº°ò¦¤U¸Ñ¨Mºô¸ô¥N²z¦øªA¾¹ªº°T®§¡C

¹Ï 2-1 ºô¸ô¥N²z¦øªA¾¹ºÞ²z

¥N²z¦øªA¾¹ºÞ²z¹Ï¤ù – ½Ð°Ñ¾\¤å¦r¸ÑÄÀ

¦b¹Ï 2-1 ¤¤¡A¦pªG¡u¨Ï¥Î¥N²z¦øªA¾¹¡v¬O±Ò¥Îªº¡A¥B­n¨Dªº URL ¦C©ó¡u½Ð¤Å¨Ï¥Îºô¸ô¥N²z¦øªA¾¹ URL¡v²M³æ¤¤¡A«h¹h¹D·|ª½±µ³s¨ì¥Øªº¦a¥D¾÷¡C

¦pªG¡u¨Ï¥Î¥N²z¦øªA¾¹¡v¬O±Ò¥Îªº¡A¥B­n¨Dªº URL ¥¼¦C©ó¡u½Ð¤Å¨Ï¥Îºô¸ô¥N²z¦øªA¾¹ URL¡v²M³æ¤¤¡A«h¹h¹D·|³z¹L«ü©wªº¥N²z¦øªA¾¹³s¨ì¥Øªº¦a¥D¾÷¡C¦¹¥N²z¦øªA¾¹ (¦pªG¦³«ü©w) ¥i¥H±q¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤¬d¬Ý¡C

¦pªG¡u¨Ï¥Î¥N²z¦øªA¾¹¡v°±¥Î¡A¥B½Ð¨Dªº URL ¦³¦C©ó¡u¨Ï¥Îºô¸ô¥N²z¦øªA¾¹¡v²M³æ¤¤¡A«h¹h¹D·|¨Ï¥Î¦C¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº¥N²z¦øªA¾¹¸ê°T³s±µ¥Øªº¦a¥D¾÷¡C

¦pªG¡u¨Ï¥Î¥N²z¦øªA¾¹¡v¬O°±¥Îªº¡A¥B­n¨Dªº URL ¥¼¦C©ó¡u½Ð¤Å¨Ï¥Îºô¸ô¥N²z¦øªA¾¹ URL¡v²M³æ¤¤¡A«h¹h¹D·|ª½±µ³s½u¨ì¥Øªº¦a¥D¾÷¡C

¦pªG±zªº±¡ªp¤£²Å¦X¤W­z¥ô¦ó¤@¶µ¡A¥BµLªk¨Ï¥Îª½±µ³s½u¡A¹h¹D·|Åã¥Ü¤@­Ó¿ù»~¡A»¡©ú³s½uµLªk¨Ï¥Î¡C


³Æµù

¦pªG±z¥¿³z¹L¤J¤fºô¯¸®à­±ªº¡u®ÑÅÒ³q¹D¡v¦s¨ú¸Ó URL¡A¥B±zªº±¡ªp¤£²Å¦X¤W­z¥ô¦ó¤@¶µ¡A¹h¹D·|¶Ç°e­«·s¾É¦Vµ¹ÂsÄý¾¹¡CÂsÄý¾¹·|¨Ï¥Î¦Û¤vªº¥N²z¦øªA¾¹³]©w¨Ó¦s¨ú¸Ó URL¡C


»yªk

domainname [web_proxy1:port1]|subdomain1 [web_proxy2:port2]|......

½d¨Ò

sesta.com wp1:8080|red wp2:8080|yellow|* wp3:8080

* ¬O²Å¦X©Ò¦³¸ê®Æªº¸U¥Î¦r¤¸

¨ä¤¤¡A

sesta.com ¬Oºô°ì¦WºÙ¦Ó wp1 ¬O¦b 8080 ³s±µ°ð¤W³s±µªº¥N²z¦øªA¾¹¡C

red ¬O¤lºô°ì¦WºÙ¦Ó wp2 ¬O¦b 8080 ³s±µ°ð¤W³s±µªº¥N²z¦øªA¾¹¡C

yellow ¬O¤lºô°ì¡C¥Ñ©ó¨S¦³«ü©w¥N²z¦øªA¾¹¡A¦]¦¹·|¨Ï¥Î«ü©wµ¹ºô°ìªº¥N²z¦øªA¾¹¡A§Y¬°¦b 8080 ³s±µ°ð¤Wªº wp1¡C

* ªí¥Ü©Ò¦³¨ä¥L¤lºô°ì wp3 ¥²¶·¦b 8080 ³s±µ°ð¤W¨Ï¥Î¡C


³Æµù

¦pªG±z¨S¦³«ü©w³s±µ°ð¡A¹w³]¬O¨Ï¥Î³s±µ°ð 8080¡C


³B²zºô¸ô¥N²z¦øªA¾¹¸ê°T

·í«È¤áºÝ¹Á¸Õ¦s¨ú¯S©wªº URL ®É¡A¦b URL ¤¤ªº¥D¾÷¦WºÙ²Å¦X¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº¶µ¥Ø¡C²Å¦X½Ð¨D¥D¾÷¦WºÙ¤§³Ìªø«áºóªº¶µ¥Ø·|³Q¦Ò¼{¡C¨Ò¦p¡A¦Ò¼{½Ð¨Dªº¥D¾÷¦WºÙ¬O host1.sesta.com

¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤¦Ò¼{¤U¦C¶µ¥Ø¡G

com p1| host1 p2 | host2 | * p3

sesta.com p4 | host5 p5 | * p6

florizon.com | host6

abc.sesta.com p8 | host7 p7 | host8 p8 | * p9

host6.florizon.com p10

host9.sesta.com p11

siroe.com | host12 p12 | host13 p13 | host14 | * p14

siroe.com | host15 p15 | host16 | * p16

* p17

¹h¹D¦b¤º³¡¹ï¬Mªº¶µ¥ØÅã¥Ü©óªí 2-2 ¤¤¡C

ªí 2-2 ¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº¹ï¬M¶µ¥Ø

¸¹½X

¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº¶µ¥Ø

¥N²z¦øªA¾¹

»¡©ú

1

com

p1

«ü©w©ó²M³æ¤¤¡C

2

host1.com

p2

«ü©w©ó²M³æ¤¤¡C

3

host2.com

p1

¥Ñ©ó¨S¦³«ü©w¥N²z¦øªA¾¹µ¹ host2¡A·|¨Ï¥Î¥D¾÷ªº¥N²z¦øªA¾¹¡C

4

*.com

p3

«ü©w©ó²M³æ¤¤¡C

5

sesta.com

p4

«ü©w©ó²M³æ¤¤¡C

6

host5.sesta.com

p5

«ü©w©ó²M³æ¤¤¡C

7

*.sesta.com

p6

«ü©w©ó²M³æ¤¤¡C

8

florizon.com

ª½±µ

¸Ô²Ó¸ê®Æ¡A½Ð°Ñ¾\²Ä 14 ­Ó¶µ¥Øªº»¡©ú¡C

9

host6.florizon.com

 

¸Ô²Ó¸ê®Æ¡A½Ð°Ñ¾\²Ä 14 ­Ó¶µ¥Øªº»¡©ú¡C

10

abc.sesta.com

p8

«ü©w©ó²M³æ¤¤¡C

11

host7.abc.sesta.com

p7

«ü©w©ó²M³æ¤¤¡C

12

host8.abc.sesta.com

p8

«ü©w©ó²M³æ¤¤¡C

13

*.abc.sesta.com

p9

«ü©w©ó²M³æ¤¤¡C¦b abc.sesta.com ºô°ì¤U¡A°£¤F host7 ©M host8 ¤§¥~ªº¥D¾÷¡Ap9 ·|¥Î§@¥N²z¦øªA¾¹¡C

14

host6.florizon.com

p10

»P²Ä 9 ­Ó¶µ¥Ø¬Û¦P¡C²Ä 9 ­Ó¶µ¥Øªí¥Üª½±µ³s½u¡A¦Ó¦¹¶µ¥Øªí¥ÜÀ³¸Ó¨Ï¥Î¥N²z¦øªA¾¹ p10¡C­Y¹J¨ì¹³³o¼Ë¦³¨â­Ó¶µ¥Øªº±¡ªp¡A§t¦³¥N²z¦øªA¾¹¸ê°Tªº¶µ¥Øµø¬°¬O¤@­Ó¦³®Äªº¶µ¥Ø¡C½Ð©¿²¤¥t¤@­Ó¶µ¥Ø¡C

15

host9.sesta.com

p11

«ü©w©ó²M³æ¤¤¡C

16

siroe.com

ª½±µ

¥Ñ©ó¨Ã¨S¦³«ü©w¥N²z¦øªA¾¹µ¹ siroe.com¡A¦]¦¹·|¹Á¸Õª½±µ³s½u¡C

17

host12.siroe.com

p12

«ü©w©ó²M³æ¤¤¡C

18

host13.siroe.com

p13

«ü©w©ó²M³æ¤¤¡C

19

host14.siroe.com

ª½±µ

¥Ñ©ó¨Ã¨S¦³«ü©w¥N²z¦øªA¾¹µ¹ host14 ©Îµ¹ siroe.com¡A¦]¦¹·|¹Á¸Õª½±µ³s½u¡C

20

*.siroe.com

p14

½Ð°Ñ¾\²Ä 23 ­Ó¶µ¥Øªº»¡©ú¡C

21

host15.siroe.com

p15

«ü©w©ó²M³æ¤¤¡C

22

host16.siroe.com

ª½±µ

¥Ñ©ó¨Ã¨S¦³«ü©w¥N²z¦øªA¾¹µ¹ host16 ©Mµ¹ siroe.com¡A¦]¦¹·|¹Á¸Õª½±µ³s½u¡C

23

*.siroe.com

p16

»P²Ä 20 ­Ó¶µ¥ØÃþ¦ü¡C¦ý¬O«ü©wªº¥N²z¦øªA¾¹¤£¦P¡C³oºØ±¡§Î¤U¡AµLªkª¾¹D¹h¹Dªº¹ê»Ú¹B§@¤è¦¡¡C¥i¯à·|¨Ï¥Î¨â­Ó¥N²z¦øªA¾¹¡C

24

*

p17

¦pªG¨S¦³¨ä¥Lªº¶µ¥Ø²Å¦X½Ð¨Dªº URL¡A´N·|¨Ï¥Î p17 §@¬°¥N²z¦øªA¾¹¡C


³Æµù

¨ú¥N¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤¤À¶}¥N²z¦øªA¾¹¶µ¥Ø¡A¦b²M³æ¤¤¦³­Ó§Oªº¶µ¥Ø¬O¤ñ¸û²³æªº¡C¨Ò¦p¡A¨ú¥N¦p¤Uªº¶µ¥Ø¡G

sesta.com p1 | red p2 | * p3

±z¥i¥H±N¨ä«ü©w¬°¡G

sesta.com p1

red.sesta.com p2

*.sesta.com p3

¦p¦¹·|²¤Æ³´¤J­«½Æ¶µ¥Ø©Î¥ô¦ó¨ä¥L§t½kªº±¡ªp¡C


¥H¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¬°°ò¦Âмg

¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº¶µ¥Ø¤]·|³Q Rewriter ¨Ï¥Î¡Cºô°ì²Å¦X¦C¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ºô°ìªº©Ò¦³ URL¡ARewriter ·|­«·s¼g¤J¡C


ª`·N

¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº * ¶µ¥Ø¤£·|¦Ò¼{­«·s¼g¤J¡C¨Ò¦p¡A¦b½d¨Òªí 2-2 ¤¤²Ä 24 ­Ó¶µ¥Ø´N¤£³Q¦Ò¼{¡C


½Ð°Ñ¾\²Ä 3 ³¹¡A¡uRewriter¡v ¥H¨ú±o§ó¦hÃö©ó Rewriter ªº¸ê°T¡C

¹w³]ºô°ì»P¤lºô°ì

·í¦b URL ¤¤ªº¥Øªº¦a¥D¾÷¤£¬O§¹¾ã­­©wªº¥D¾÷¦WºÙ¡A·|¨Ï¥Î¹w³]ªººô°ì©M¤lºô°ì¥H¨Ï¨ä¦³§¹¾ã¦X®æªº¦WºÙ¡C

°²³]ºÞ²z¥D±±¥x¤¤¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡vÄæ¦ì¤ºªº¶µ¥Ø¬O¡G

red.sesta.com


³Æµù

¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤±z¥²¶·­n¦³¹ïÀ³ªº¶µ¥Ø¡C


¦b¤W­±ªº½d¨Ò¤¤¡Asesta.com ¬O¹w³]ªººô°ì¦Ó red ¬O¹w³]ªº¤lºô°ì¡C

¦pªG­n¨Dªº URL ¬O host1¡A«h¨Ï¥Î¹w³]ªººô°ì©M¤lºô°ì¥H¸Ñ¨M host1.red.sesta.com¡CµM«á·|¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤¬d¸ß host1.sesta.com¡C


¨Ï¥Î¥N²z¦øªA¾¹¦Û°Ê°t¸m

­Y­n©¿²¤¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº¸ê°T¡A½Ð±Ò¥Î¡u¥N²z¦øªA¾¹¦Û°Ê°t¸m¡v(PAC) ¥\¯à¡C­Y­n°t¸m PAC¡A½Ð°Ñ¾\¡u±Ò¥Î¥N²z¦øªA¾¹¦Û°Ê°t¸m (PAC) ¤ä´©¡v¡C

¨Ï¥Î PAC Àɮ׮ɽЪ`·N¤U¦C´XÂI¡G

¨Ï¥Î½d¨Ò PAC ÀÉ®×

¤U¦C½d¨ÒÅã¥Ü¦C¦b¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡v²M³æ¤¤ªº URL ©M¹ïÀ³ªº PAC ÀɮסC

§t¦³¶Ç¦^ DIRECT ©Î NULL ªº½d¨Ò

¨Ï¥Îºô°ì©M¤lºô°ìªº³o¨Ç¥N²z¦øªA¾¹¡G

intranet1.com

intranet2.com.proxy.intranet1.com:8080

the corresponding PAC file is:

// Start of the PAC File

function FindProxyForURL(url, host) {

if (dnsDomainIs(host, ".intranet1.com")) {

return "DIRECT";

}

if (dnsDomainIs(host, ".intranet2.com")) {

return "PROXY proxy.intranet1.com:8080";

}

return "NULL";

}

//End of the PAC File

§t¦³¶Ç¦^ STARPROXY ªº½d¨Ò

¨Ï¥Îºô°ì©M¤lºô°ìªº³o¨Ç¥N²z¦øªA¾¹¡G

the corresponding PAC file is:

// Start of the PAC File

function FindProxyForURL(url, host) {

if (dnsDomainIs(host, ".intranet1.com")) {

return "DIRECT";

}

if (dnsDomainIs(host, ".intranet2.com")) {

return "PROXY proxy.intranet1.com:8080;" +

"PROXY proxy1.intranet1.com:8080";

}

return "STARPROXY internetproxy.intranet1.com:80";

}

//End of the PAC File

¦b³o­Ó±¡ªp¤U¡A¦pªG¬O¦ì©ó .intranet2.com ºô°ì¡A«h¹h¹D·|³sµ¸ proxy.intranet1.com:8080¡C¦pªG proxy.intranet1.com:8080 ¥N²z¦øªA¾¹µLªk¨Ï¥Î¡A½Ð¨D·|¥¢±Ñ¡C¹h¹D¤£·|­×´_¿ù»~©M³sµ¸ proxy1.intranet1.com:8080¡C


¨Ï¥Î Netlet ¥N²z¦øªA¾¹

Netlet «Ê¥]¦b¹h¹D¬O¸Ñ±Kªº¡A¨Ã·|¶Ç°e¨ì¥Øªº¦a¦øªA¾¹¡CµM¦Ó¡A¹h¹D»Ý­n³z¹L«D­x¨Æ°Ï (DMZ) ©M¥ø·~¤º³¡ºô¸ô¤§¶¡ªº¨¾¤õÀð¡A¦s¨ú©Ò¦³ªº Netlet ¥Øªº¦a¥D¾÷¡C³o»Ý­n¦b¨¾¤õÀ𤤶}±Ò¤j¶qªº³s±µ°ð¡CNetlet ¥N²z¦øªA¾¹¥i¥Î¥H³Ì¤p¤Æ¦b¥N²z¦øªA¾¹¤¤¶}±Òªº³s±µ°ð¡C

Âǥѩµ¦ù¥Î¤áºÝªº¦w¥þ³q¹D¡A³z¹L¹h¹D¨ì¦s¦b©ó¥ø·~¤º³¡ºô¸ôªº Netlet ¥N²z¦øªA¾¹¡ANetlet ±j¤Æ¹h¹D©M¥ø·~¤º³¡ºô¸ô¤§¶¡ªº¦w¥þ©Ê¡C¨Ï¥Î¥N²z¦øªA¾¹¡ANetlet «Ê¥]·|¥Ñ¥N²z¦øªA¾¹¸Ñ±K¡A¤§«á·|¶Ç°e¦Ü¥Øªº¦a¦øªA¾¹¡C

¤U¦C­ì¦]¥i»¡©ú Netlet ¥N²z¦øªA¾¹«D±`¦³¥Î¡G

±z¥i¥H¡G

¹Ï 2-2 Åã¥Ü¦b¦³©M¨S¦³¦w¸Ë Netlet ¥N²z¦øªA¾¹ªº±¡ªp¤U¡A¹h¹D©M Portal Server ªº¤T­Ó½d¨Ò¹ê§@¡C¤¸¥ó¥]§t¤@­Ó¥Î¤áºÝ¡B¨â­Ó¨¾¤õÀð¡B¦ì©ó¨â­Ó¨¾¤õÀ𤧶¡ªº¹h¹D¡BPortal Server ©M Netlet ¥Øªº¦a¦øªA¾¹¡C

²Ä¤@­Ó¤è®×Åã¥Ü¨S¦³¦w¸Ë Netlet ¥N²z¦øªA¾¹ªº¹h¹D©M Portal Server¡C¦¹³B¸ê®Æ¥[±K¶È±q¥Î¤áºÝ©µ¦ù¨ì¹h¹D¡C¦b²Ä¤G­Ó¨¾¤õÀ𤤶}±Ò¤@­Ó³s±µ°ðµ¹¨C­Ó Netlet ³s½u½Ð¨D¡C

²Ä¤G­Ó¤è®×Åã¥Ü¦b Portal Server ¤W¦w¸Ë Netlet ¥N²z¦øªA¾¹ªº¹h¹D©M Portal Server¡C¦b¦¹±¡ªp¤¤¡A¸ê®Æ¥[±K±q¥Î¤áºÝ¤@ª½©µ¦ù¨ì Portal Server¡C¥Ñ©ó©Ò¦³ªº Netlet ³s½u³£³z¹L Netlet ¥N²z¦øªA¾¹¸ô¥Ñ¡A¶È»Ý­n¦b²Ä¤G­Ó¨¾¤õÀ𤤶}±Ò¤@­Ó³s±µ°ðµ¹ Netlet ½Ð¨D¡C

²Ä¤T­Ó¤è®×Åã¥Ü¦³¦b­Ó§O¸`ÂI¤W¦w¸Ë Netlet ¥N²z¦øªA¾¹ªº¹h¹D©M Portal Server¡C¦b­Ó§O¸`ÂI¤W¦w¸Ë Netlet ¥N²z¦øªA¾¹·|´î¤Ö Portal Server ¸`ÂI¤Wªº­t¸ü¡C¦P¼Ëªº¡A¦b²Ä¤G­Ó¨¾¤õÀ𤤶Ȼݭn¶}±Ò¨â­Ó³s±µ°ð¡C¨ä¤¤¤@­Ó³s±µ°ð´£¨Ñµ¹ Portal Server ¨Ï¥Î¡A¥t¤@­Ó³s±µ°ð«h¸ô¥Ñ Netlet ½Ð¨D¨ì Netlet ¥N²z¦øªA¾¹¦øªA¾¹¡C

¹Ï 2-2 Netlet ¥N²z¦øªA¾¹ªº¹ê§@

¦¹¹Ï¤ù»¡©úÃö©ó Netlet ¥N²z¦øªA¾¹ªº¥i¯à°t¸m¡A¨Ã´y­z³]¦³ Netlet ¥N²z¦øªA¾¹ªºÀuÂI¡C½Ð°Ñ¾\¹Ï¤ù¤U¤èªº»¡©ú¥H¨ú±o¸Ô²Ó¸ê®Æ¡C

«Ø¥ß Netlet ¥N²z¦øªA¾¹ªº¹ê¨Ò

¨Ï¥Î nlpmultiinstance µ{¦¡ÀÉ¥H¦b Portal Server ©Î­Ó§O¸`ÂI¤W¡A«Ø¥ß Netlet ¥N²z¦øªA¾¹ªº·s¹ê¨Ò¡C³Ì¦n¦b«Ø¥ß¹h¹D³]©wÀɤ§«á°õ¦æ¦¹µ{¦¡ÀÉ¡G

  1. ¥H®Ú¨Ï¥ÎªÌ¨­¤Àµn¤J¨ÃÂsÄý¦Ü¤U­±ªº¥Ø¿ý¡G
  2. netlet-install-dir/SUNWps/bin

  3. °õ¦æ¦h¹ê¨Òµ{¦¡ÀÉ¡G
  4. ./nlpmultiinstance

  5. ¦^µª nlpmultiinstance µ{¦¡ÀɩҰݪº°ÝÃD¡G
    • What is the name of the new netlet proxy instance? (·s netlet ¥N²z¦øªA¾¹¹ê¨Òªº¦WºÙ¬°¦ó?)
    • ¦pªG±z¦³ Rewriter ¥N²z¦øªA¾¹¥B¬O¦b¦¹¸`ÂI¤W¥H¦P¼Ëªº¦WºÙ°t¸m¡A¨t²Î·|°Ý±z¬O§_­n¨Ï¥Î¬Û¦Pªº°t¸mµ¹¦¹ proxy ¥N²z¦øªA¾¹¹ê¨Ò¡C
    • ¦pªG±zªº¦^µª¬°¬O¡A½Ð¦^µª³o¨â­Ó°ÝÃD¡G
      • What port will the new netlet proxy instance listen on? (·sªº Netlet ¥N²z¦øªA¾¹¹ê¨Ò±N·|¨Ï¥Î­þ­Ó³s±µ°ð¶ÉÅ¥?)
      • Start the netlet proxy after installation? (¦w¸Ë«á±Ò°Ê Netlet ¥N²z¦øªA¾¹?)
    • ¦pªG±zªº¦^µª¬°§_¡A«h½Ð¦^µª¤U¦C°ÝÃD¡G
      • What protocol will the new netlet proxy instance use? (·sªº Netlet ¥N²z¦øªA¾¹¹ê¨Ò·|¨Ï¥Î¤°»ò³q°T¨ó©w?)
      • What port will the new netlet proxy instance listen on? (·sªº Netlet ¥N²z¦øªA¾¹¹ê¨Ò±N·|¨Ï¥Î­þ­Ó³s±µ°ð¶ÉÅ¥?)
      • What is the name of your organization? (±zªº²Õ´¦WºÙ¬°¦ó?)
      • What is the name of your division? (±zªº¤À³¡¦WºÙ¬°¦ó?)
      • What is the name of your city or locality? (±zªº«°¥«©Î¦a°Ï¦WºÙ¬°¦ó?)
      • What is the name of your state or province? (±zªº¦{¦W©Î¬Ù¦W¬°¦ó?)
      • What is the two-letter country code? (±zªº¨â­Ó¦r¥À°ê½X¬°¦ó?)
      • What is the password for the certificate Database? (±zÃÒ®Ñ¸ê®Æ®wªº±K½X¬°¦ó?)
      • What is the password for the logging user? (°O¿ý¨Ï¥ÎªÌªº±K½X¬°¦ó?)
      • Have you created the new netlet proxy profile in the admin console? (±z¬O§_¤w¸g¦bºÞ²z¥D±±¥x¤¤«Ø¥ß·sªº Netlet ¥N²z¦øªA¾¹³]©wÀÉ?)
      • If you answered yes, start the netlet proxy after installation? (¦pªG±zªº¦^µª¬°¬O¡A­n¦b¦w¸Ë«á±Ò°Ê Netlet ¥N²z¦øªA¾¹?)
  6. ¥H½Ð¨Dªº¹h¹D³]©wÀɦWºÙ±Ò°Ê netlet ¥N²z¦øªA¾¹ªº·s¹ê¨Ò¡G
  7. netlet-proxy-install-root/SUNWps/bin/netletd -n gateway-profile-name start

    ¨ä¤¤ gateway-profile-name ¬O¹ïÀ³¨ì©Ò»Ý¹h¹D¹ê¨Òªº³]©wÀɦWºÙ¡C

±Ò¥Î Netlet ¥N²z¦øªA¾¹

¦b Identity Server ºÞ²z¥D±±¥x¤¤ªº SRA °t¸m¤U¡A³z¹L¹h¹DªA°È±Ò°Ê Netlet ¥N²z¦øªA¾¹¡C½Ð°Ñ¾\¡u±Ò¥Î¨Ã«Ø¥ß Netlet ¥N²z¦øªA¾¹²M³æ¡v¡C

­«·s±Ò°Ê Netlet ¥N²z¦øªA¾¹

¨C¦¸¥N²z¦øªA¾¹·N¥~µ²§ô®É ±z¥i¥H°t¸m Netlet ¥N²z¦øªA¾¹¥H­«·s±Ò°Ê¡C±z¥i¥H±Æµ{¤@­ÓºÊµøµ{¦¡µ{§Ç¥HºÊµø Netlet ¥N²z¦øªA¾¹¡A¦pªG®Ä¯à­°§C´N­«·s±Ò°Ê¡C

±z¤]¥i¥H¤â°Ê­«·s±Ò°Ê Netlet ¥N²z¦øªA¾¹¡C

   ­«·s±Ò°Ê Netlet ¥N²z¦øªA¾¹

¦b²×ºÝ¾÷µøµ¡¤¤¡A¥H®Ú¨Ï¥ÎªÌ¨­¤À³s±µ¨Ã°õ¦æ¤U¦C¨ä¤¤¤§¤@¡G

   °t¸m Netlet ¥N²z¦øªA¾¹ºÊµøµ{¦¡

±z¥i¥H°t¸mºÊµøµ{¦¡ºÊµø Netlet ¥N²z¦øªA¾¹ª¬ºAªº®É¶¡¶¡¹j¡C®É¶¡¶¡¹j¹w³]¬° 60 ¬í¡C­Y­n°õ¦æ¦¹¨BÆJ¡A¦b crontab ¤¤½s¿è¤U­±ªº¦æ¡G

0-59 * * * * netlet-install-dir/bin/checkgw /var/opt/SUNWps/.gw 5 > /dev/null 2>&1


¨Ï¥Î Rewriter ¥N²z¦øªA¾¹

Rewriter ¥N²z¦øªA¾¹¦w¸Ë¦b¥ø·~¤º³¡ºô¸ô¤¤¡C¨ú¥N¹Á¸Õª½±µÂ^¨ú¸ê®Æ¤º®e¡A¹h¹D·|¶Ç°e©Ò¦³½Ð¨Dµ¹ Rewriter ¥N²z¦øªA¾¹¡A¦Ó Rewriter ¥N²z¦øªA¾¹·|Àò¨ú¨Ã¶Ç¦^¤º®eµ¹¹h¹D¡C

¨Ï¥Î Rewriter ¥N²z¦øªA¾¹¦³¨â­ÓÀuÂI¡G

¦pªG±z¨S¦³«ü©w Rewriter ¥N²z¦øªA¾¹¡A·í¨Ï¥ÎªÌ¹Á¸Õ¦s¨ú¥ø·~¤º³¡ºô¸ôªº¨ä¤¤¤@¥x¹q¸£¡A¹h¹D¤¸¥ó·|ª½±µ³s½u¦Ü¥ø·~¤º³¡ºô¸ôªº¹q¸£¡C

­n±Ò¥Î Rewriter ¥N²z¦øªA¾¹¡A½Ð°Ñ¾\¡u±Ò¥Î¨Ã«Ø¥ß Rewriter ¥N²z¦øªA¾¹²M³æ¡v¡C

«Ø¥ß Rewriter ¥N²z¦øªA¾¹ªº¹ê¨Ò

¨Ï¥Î rwpmultiinstance µ{¦¡ÀÉ¥H¦b Portal Server ¸`ÂI¤W«Ø¥ß Rewriter ¥N²z¦øªA¾¹ªº·s¹ê¨Ò¡C³Ì¦n¦b«Ø¥ß¹h¹D³]©wÀɤ§«á°õ¦æ¦¹µ{¦¡ÀÉ¡C

  1. ¥H®Ú¨Ï¥ÎªÌ¨­¤Àµn¤J¨ÃÂsÄý¤U­±ªº¥Ø¿ý¡G
  2. rewriter-proxy-install-root/SUNWps/bin

  3. °õ¦æ¦h¹ê¨Òµ{¦¡ÀÉ¡G
  4. ./rwpmultiinstance

  5. ¦^µª nlpmultiinstance µ{¦¡ÀɩҰݪº°ÝÃD¡G
    • What is the name of the new rewriter proxy instance? (·s Rewriter ¥N²z¦øªA¾¹¹ê¨Òªº¦WºÙ¬°¦ó?)
    • ¦pªG±z¦³ Rewriter ¥N²z¦øªA¾¹¥B¬O¦b¦¹¸`ÂI¤W¥H¦P¼Ëªº¦WºÙ°t¸m¡A¨t²Î·|°Ý±z¬O§_­n¨Ï¥Î¬Û¦Pªº°t¸mµ¹¦¹ Rewriter ¥N²z¦øªA¾¹¹ê¨Ò¡C)
    • ¦pªG±zªº¦^µª¬°¬O¡A½Ð¦^µª³o¨â­Ó°ÝÃD¡G
      • What port will the new rewriter proxy instance listen on? (·sªº rewriter ¥N²z¦øªA¾¹¹ê¨Ò±N·|¨Ï¥Î­þ­Ó³s±µ°ð¶ÉÅ¥?)
      • Start the rewriter proxy after installation? (¦w¸Ë«á±Ò°Ê rewriter ¥N²z¦øªA¾¹?)
    • ¦pªG±zªº¦^µª¬°§_¡A«h½Ð¦^µª¤U¦C°ÝÃD¡G
      • What protocol will the new rewriter proxy instance use? (·sªº rewriter ¥N²z¦øªA¾¹¹ê¨Ò·|¨Ï¥Î¤°»ò³q°T¨ó©w?)
      • What port will the new rewriter proxy instance listen on? (·sªº rewriter ¥N²z¦øªA¾¹¹ê¨Ò±N·|¨Ï¥Î­þ­Ó³s±µ°ð¶ÉÅ¥?)
      • What is the name of your organization? (±zªº²Õ´¦WºÙ¬°¦ó?)
      • What is the name of your division? (±zªº¤À³¡¦WºÙ¬°¦ó?)
      • What is the name of your city or locality? (±zªº«°¥«©Î¦a°Ï¦WºÙ¬°¦ó?)
      • What is the name of your state or province? (±zªº¦{¦W©Î¬Ù¦W¬°¦ó?)
      • What is the two-letter country code? (±zªº¨â­Ó¦r¥À°ê½X¬°¦ó?)
      • What is the password for the certificate Database? (±zÃÒ®Ñ¸ê®Æ®wªº±K½X¬°¦ó?)
      • What is the password for the logging user? (°O¿ý¨Ï¥ÎªÌªº±K½X¬°¦ó?)
      • Have you created the new rewriter proxy profile in the admin console? (±z¬O§_¤w¸g¦bºÞ²z¥D±±¥x¤¤«Ø¥ß·sªº rewriter ¥N²z¦øªA¾¹³]©wÀÉ?)
      • If you answered yes, start the rewriter proxy after installation? (¦pªG±zªº¦^µª¬°¬O¡A­n¦b¦w¸Ë«á±Ò°Ê rewriter ¥N²z¦øªA¾¹?)
  6. ¥H½Ð¨Dªº¹h¹D³]©wÀɦWºÙ±Ò°Ê Rewriter ¥N²z¦øªA¾¹ªº·s¹ê¨Ò¡G
  7. rewriter-proxy-install-root/SUNWps/bin/rwproxyd -n gateway-profile-name start

    ¨ä¤¤ gateway-profile-name ¬O¹ïÀ³¨ì©Ò»Ý¹h¹D¹ê¨Òªº³]©wÀɦWºÙ¡C

±Ò¥Î Rewriter ¥N²z¦øªA¾¹

¦b Identity Server ºÞ²z¥D±±¥x¤¤¡A¦b¡uSRA °t¸m¡v¤U³z¹L¹h¹DªA°È±Ò¥Î Rewriter ¥N²z¦øªA¾¹¡C½Ð°Ñ¾\¡u±Ò¥Î¨Ã«Ø¥ß Rewriter ¥N²z¦øªA¾¹²M³æ¡v¡C

­«·s±Ò°Ê Rewriter ¥N²z¦øªA¾¹

¨C¦¸¥N²z¦øªA¾¹·N¥~µ²§ô®É ±z¥i¥H°t¸m Rewriter ¥N²z¦øªA¾¹¥H­«·s±Ò°Ê¡C±z¥i¥H±Æµ{¤@­Ó ºÊµøµ{¦¡µ{§Ç¥HºÊµø Rewriter ¥N²z¦øªA¾¹¡A¦pªG®Ä¯à­°§C´N­«·s±Ò°Ê¡C

±z¤]¥i¥H¤â°Ê­«·s±Ò°Ê Rewriter ¥N²z¦øªA¾¹¡C

   ­«·s±Ò°Ê Rewriter ¥N²z¦øªA¾¹

¦b²×ºÝ¾÷µøµ¡¤¤¡A¥H®Ú¨Ï¥ÎªÌ¨­¤À³s±µ¨Ã°õ¦æ¤U¦C¨ä¤¤¤§¤@¡G

   ­Y­n°t¸m Rewriter ¥N²z¦øªA¾¹ºÊµøµ{¦¡

±z¥i¥H°t¸mºÊµøµ{¦¡ºÊµø Rewriter ¥N²z¦øªA¾¹ª¬ºAªº®É¶¡¶¡¹j¡C®É¶¡¶¡¹j¹w³]¬° 60 ¬í¡C­Y­n°õ¦æ¦¹¨BÆJ¡A¦b crontab ¤¤½s¿è¤U­±ªº¦æ¡G

0-59 * * * * rewriter-proxy-install-root/bin/checkgw /var/opt/SUNWps/.gw 5 > /dev/null 2>&1


¨Ï¥Î§t¦³¹h¹Dªº¤Ï¦V¥N²z¦øªA¾¹

¥N²z¦øªA¾¹·|¶Ç°eºô»Úºô¸ô¤º®e¦Ü¥ø·~¤º³¡ºô¸ô¡A¦Ó¤Ï¦V¥N²z¦øªA¾¹«h¶Ç°e¥ø·~¤º³¡ºô¸ô¤º®e¦Üºô»Úºô¸ô¡C¬Y¨Ç¤Ï¦V¥N²z¦øªA¾¹ªº³¡¸p·|°t¸m¬°¶Ç°eºô»Úºô¸ô¤º®e¥H¹F¦¨¸ü¤J¥­¿Å»P§Ö¨úªº®ÄªG¡C

­Y¦b¹h¹D«e­±³¡¸p¨ã¦³¨ó¤O¼t°Ó¤Ï¦V¥N²z¦øªA¾¹¡A«h¦^À³¥²¶·¥H¤Ï¦V¥N²z¦øªA¾¹ªº URL ( «D¹h¹Dªº URL) ­«·s¼g¤J¡C ¦]¦¹»Ý­n¤U¦C°t¸m¡C

   ­Y­n±Ò¥Î¤Ï¦V¥N²z¦øªA¾¹
  1. ¥H®Ú¨Ï¥ÎªÌ¨­¤Àµn¤J¨Ã½s¿è©Ò»Ý¹h¹D¹ê¨Òªº platform.conf ÀÉ¡G
  2. /etc/opt/SUNWps/platform.conf.gateway-profile-name

  3. ·s¼W¤U¦C¶µ¥Ø¡G
  4. gateway.virtualhost=fully-qualified-gateway-host gateway-ip-address fully- qualified-reverse-proxyhost

    gateway.enable.customurl=true (¦¹­Èªº¹w³]­È³]©w¬° false¡C)

    gateway.httpurl=http reverse-proxy-URL

    gateway.httpsurl=https reverse-proxy-URL

    gateway.httpurl ±N¥Î©óÂмg¦b³s±µ°ð±µ¦¬ªº¦^À³¡A¨ä¤¤³s±µ°ð¦b¹h¹D³]©wÀÉ·|¦C¥Ü¬° HTTP ³s±µ°ð¡C

    gateway.httpsurl ±N¥Î©óÂмg¦b³s±µ°ð±µ¦¬ªº¦^À³¡A¨ä¤¤³s±µ°ð¦b¹h¹D³]©wÀÉ·|¦C¥Ü¬° HTTPS ³s±µ°ð¡C

  5. ­«·s±Ò°Ê¡u¹h¹D¡v¡G
  6. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start

¦pªG¤£«ü©w¦¹­È¡A«h¹h¹D·|¹w³]¦^¤@¯ëªº¹B§@¤è¦¡¡C


¨ú±o¥Î¤áºÝ¸ê°T

·í¹h¹DÂà±H¥Î¤áºÝ½Ð¨D¨ì¥ô¦ó¤º³¡¦øªA¾¹®É¡A¹h¹D·|·s¼W HTTP ¼ÐÀY¨ì HTTP ½Ð¨D¡C±z¥i¥H¨Ï¥Î³o¨Ç¼ÐÀY¥H¨ú±oÃB¥~ªº¥Î¤áºÝ¸ê°T¨Ã°»´ú¹h¹Dªº¥X²{ª¬ºA¡C

­Y­nÀ˵ø HTTP ¼ÐÀY¡A½Ð³]©w platform.conf Àɮתº¶µ¥Ø¬° gateway.error=message¡AµM«á¨Ï¥Î servlet API ¤¤ªº request.getHeader()¡C

²Ä¤@Äæ¦C¥X¼ÐÀY¼ÐÅÒ¡A²Ä¤GÄæ«ü©w¼ÐÀYªº»yªk¡A²Ä¤TÄæ«h¬O¼ÐÀY¼ÐÅÒªº»¡©ú¡C

ªí 2-3 HTTP ¼ÐÀY¤¤ªº°T®§

¼ÐÀY

»yªk

»¡©ú

PS-GW-PDC

PS-GW-PDC:true/false

«ü¥X¹h¹D¤Wªº PDC ¬O§_±Ò¥Î¡C

PS-Netlet

PS-Netlet:enabled=true/false

«ü¥X¹h¹D¤Wªº Netlet ¬O§_¤w¸g±Ò¥Î©Î°±¥Î¡C

¦pªG¤w¸g±Ò¥Î¡A«h¥[±K¿ï¶µ·|´Ó¤J¡A«ü¥X¹h¹D¥H HTTPS (encryption=ssl) ©Î¥H HTTP ¼Ò¦¡ (encryption=plain) °õ¦æ¡C

¨Ò¦p¡G

PS-Netlet:enabled=false

Netlet ¬O°±¥Îªº¡C

PS-Netlet:enabled=true; encryption=ssl

Netlet ¨Ï¥Î¦b SSL ¼Ò¦¡¤¤°õ¦æªº¹h¹D±Ò¥Î¡C

·í Netlet ¨S¦³±Ò¥Î®É¡Aencryption=ssl/plain ¨Ã¤£·|´Ó¤J¡C

PS-GW-URL

PS-GW-URL:http(s)://gatewayURL(:port)

«ü¥X¥Î¤áºÝ­n³s±µªº URL¡C

¦pªG¬O«D¼Ð·Çªº³s±µ°ð (¤]´N¬O»¡¡A¹h¹D¦b HTTP/HTTPS ¼Ò¦¡¤¤¥B³s±µ°ð¤£¬O 80/443)¡A«h¸Ó¡u³s±µ°ð¡v¤]·|³Q´Ó¤J¡C

PS-GW-Rewriting-URL

PS-GW-URL:http(s)://gatewayURL(:port)/[SessionInfo]

 

«ü¥X¹h¹D­«·s¼g¤J©Ò¦³­¶­±ªº URL¡C

1. ·íÂsÄý¾¹¤ä´© cookie ®É¡A¦¹¼ÐÀYªº­È·|©M PS-GW-URL ¼ÐÀYªº­È¤@¼Ë¡C

2. ·íÂsÄý¾¹¤£¤ä´© cookies¡G

  • ¨Ã¥B¦pªG¥Øªº¦a¥D¾÷¦b¡uÂà±H Cookie URL¡v²M³æ¤¤¡A«h­È¬O¹h¹D­«·s¼g¤J­¶­± (§t¦³½s½X SessionID ¸ê°T) ¨ì URL ªº ¹ê»Ú URL¡C
  • ©Î¡A¦pªG¥Øªº¦a¥D¾÷¤£¦b¡uÂà±H Cookie URL¡v²M³æ¤¤¡A¦Ó SessionInfo ¦r¦ê¬O "$SessionID"

ª`·N¡G¦b¦^À³³¡¤À¡A¦pªG¨Ï¥ÎªÌªº Identity Server seeionID Åܧó (¦p¨Ó¦Û»{ÃÒ­¶­±ªº¦^À³)¡A«h·|¥H¸Ó­È­«·s¼g¤J³o¨Ç­¶­± (¦¹­È¨Ã«D¬O¥ý«e©Ò«ü¦b¼ÐÀY¤¤ªº­È)¡C

¨Ò¦p¡G

  • ¦pªGÂsÄý¾¹¤ä´© cookies¡G

PS-GW-Rewriting-URL:
https://siroe.india.sun.com:10443/

  • ¦pªGÂsÄý¾¹¤£¤ä´© cookies ¦ý¬O²×ºÝ¦øªA¾¹¦b¡uÂà±H Cookie URL¡v²M³æ¤¤¡C

PS-GW-Rewriting-URL:
https://siroe.india.sun.com:10443/SessIDValCustomEncodedValue/

  • ¦pªGÂsÄý¾¹¤£¤ä´© cookies ¦ý¬O²×ºÝ¦øªA¾¹¤£¦b¡uÂà±H Cookie URL¡v²M³æ¤¤¡C

PS-GW-Rewriting-URL:
https://siroe.india.sun.com:10443/$SessionID

PS-GW-CLientIP

 

PS-GW-CLientIP: IP

³o¬O¹h¹D±q recievedSocket.getInetAddress().getHostAddress() ©Ò¨ú±oªº IP

¦pªGª½±µ³s¨ì¹h¹Dªº¸Ü¡A·|´£¨Ñ¥Î¤áºÝªº IP¡C

ª`·N¡G¥Ñ©ó¦³ JSS/NSS ¿ù»~¡A¥Ø«e³o³¡¤À¤£´£¨Ñ¡C


¨Ï¥Î»{ÃÒÃì±µ

¦b»{ÃÒªº¤@¯ë¾÷¨î¤W¡A»{ÃÒÃì±µ´£¨Ñ¸û°ªªº¦w¥þ©Ê¡C±z¥i¥HÅý¨Ï¥ÎªÌ»{ÃÒ¤@­Ó¥H¤Wªº»{ÃÒ¾÷¨î¡C

¦¹³Bªºµ{§Ç»¡©ú¶È¾A¥Î©ó»P¦b¹h¹D¤Wªº PDC »{ÃÒ¦P®É±Ò¥Î»{ÃÒÃì±µ¡CÃö©ó¦b¹h¹D¤W¨S¦³ PDC »{ÃÒªº»{ÃÒÃìµ²¡A½Ð°Ñ¦Ò Sun ONE Identity Server ºÞ²z­û«ü«n¡C

¨Ò¦p¡A¦pªG±z¨ú±o PDC¡BUnix ©M Radius »{ÃÒ¼Ò²Õ¡A¨Ï¥ÎªÌ±N¥²¶·»{ÃÒ³o¤T­Ó¼Ò²Õ¥H¦s¨ú¤J¤fºô¯¸®à­±¡C


³Æµù

¦pªG PDC ±Ò¥Îªº¸Ü¡A¥¦¥Ã»·³£¬O²Ä¤@­ÓÅã¥Ü¦b¨Ï¥ÎªÌ­±«eªº»{ÃÒ¼Ò²Õ¡C


    ·s¼W»{ÃÒ¼Ò²Õ¨ì²{¦³ªº PDC ¹ê¨Ò
  1. ¥HºÞ²z­ûªº¨­¥÷µn¤J Identity Server ºÞ²z¥D±±¥x¡C
  2. ¿ï¾Ü²Õ´¡C
  3. ±q¡uÀ˵ø¡v¥\¯àªí¤¤¿ï¨ú¡uªA°È¡v¡C
  4. ¦¹ªA°È·|Åã¥Ü©ó¥ªµ¡®æ¤¤¡C

  5. «ö¤@¤U¡u»{ÃÒ°t¸m¡v®ÇÃ䪺½bÀY¡C
  6. Åã¥Ü¡uªA°È¹ê¨Ò²M³æ¡v¡C

  7. «ö¤@¤U gatewaypdc¡C
  8. ·|Åã¥Ü Gatewaypdc Äݩʭ¶­±¡C

  9. «ö¤@¤U¡u»{ÃÒ°t¸m¡v«e­±ªº¡u½s¿è¡v¡C
  10. ·|Åã¥Ü¡u·s¼W¼Ò²Õ¡v¡C

  11. ¿ï¾Ü¡u¼Ò²Õ¦WºÙ¡v¨Ã³]©w¡uºX¼Ð¡v¬°¡u»Ý­n¡v¡C¿ï¶µ·|¬OªÅ¥Õªº¡C
  12. «ö¤@¤U¡u½T©w¡v¡C
  13. ·s¼W¤@­Ó©Î¦h­Ó¼Ò²Õ«á«ö¤@¤U¡uÀx¦s¡v¡C
  14. ¦b gatewaypdc Äݩʭ¶­±¤¤«ö¤@¤U¡uÀx¦s¡v¡C
  15. ­Y­n¨ÏÅܧó¥Í®Ä¡A­«·s±Ò°Ê¹h¹D¡G
  16. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start


¨Ï¥Î¸U¦³¦r¤¸ÃÒ®Ñ

¸U¥Î¦r¤¸ÃҮѱµ¨ü§t¦³¸U¥Î¦r¤¸ªº³æ¤@ÃҮѡA¸ÓÃҮѥ²¶·¦ì©ó¾Ö¦³§¹¥þ¦X®æ DNS ¦WºÙªº¥D¾÷¤¤¡C

³o¤¹³\ÃҮѦb¬Û¦Pºô°ì¤¤ºûÅ@¦h­Ó¥D¾÷ªº¦w¥þ©Ê¡C¨Ò¦p¡A*.domain.com ªºÃҮѥi¥H¥Î©ó abc.domain.com ©M abc1.domain.com¡C¨Æ¹ê¤W¡A¦¹ÃҮѹï©ó¦b domain.com ºô°ì¤¤ªº¥ô¦ó¥D¾÷³£¦³®Ä¡C

±z»Ý­n¦b§¹¥þ¦X®æªº¥D¾÷¦WºÙ¤¤«ü©w¤@­Ó *¡C¨Ò¦p¡A¦pªG§¹¥þ¦X®æªº¥D¾÷¦WºÙ¬O abc.florizon.com¡A«h±N¤§«ü©w¬° *.florizon.com¡C²{¦b¡A²£¥ÍªºÃҮѹï©Ò¦³¦b florizon.com ºô°ì¤¤ªº©Ò¦³¥D¾÷¦WºÙ³£¦³®Ä¡C


°±¥ÎÂsÄý¾¹§Ö¨ú

·í¹h¹D¤¸¥ó¶È¨Ï¥Îºô¸ôÂsÄý¾¹±q¥ô¦ó¦a¤è´£¨Ñ¦w¥þ¦s¨ú¨ì«áºÝ¤½¥q¸ê®Æ®É¡A¥Î¤áºÝ¦b¥»¾÷¤£¯à§Ö¨ú¥i¯à¬O¥²»Ý±ø¥ó¡C

±z¥i¥H­×§ï«ü©w¹h¹D¦b platform.conf ¤¤ÀɮתºÄݩʡA¥H°±¥Î³z¹L¹h¹D§Ö¨ú­«·s¾É¦Vªº­¶­±¡C

°±¥Î¦¹¿ï¶µ¹ï¹h¹D®Ä¯à¦³¼vÅT¡C¨C¦¸¤J¤f®à­±§ó·s®É¡A¹h¹D¥²¶·Â^¨ú¨C­Ó°Ñ·Ó¨ì­¶­±ªºªF¦è¡A¨Ò¦p¥ý«eÂsÄý¾¹¤w¸g§Ö¨ú¹Lªº¼v¹³¡CµM¦Ó¡A±Ò¥Î³o­Ó¥\¯à«á¡A»·ºÝ¦s¨ú¦w¥þªº¤º®e±N¤£·|¦b¥Î¤áºÝ¯d¤U§Ö¨ú¹Lªº¨¬¸ñ¡C¦pªG¥ø·~ºô¸ô¬O±qºô¸ô©@°ØÀ]©ÎÃþ¦üªº»·ºÝ¦ì¸m (¤£¬O¦b¥ø·~ IT ªº±±¨î¤U)¡A³o­Ó¥\¯à·|¤ñ®Ä¯àÃö«Y§ó¬°­«­n¡C

    °±¥ÎÂsÄý¾¹§Ö¨ú
  1. ¥H®Ú¨Ï¥ÎªÌ¨­¤Àµn¤J¨Ã½s¿è©Ò»Ý¹h¹D¹ê¨Òªº platform.conf ÀÉ¡G
  2. /etc/opt/SUNWps/platform.conf.gateway-profile-name

  3. ½s¿è¤U­±ªº¦æ¡G
  4. gateway.allow.client.caching=true

    ¦¹­Èªº¹w³]­È³]©w¬° true¡CÅܧ󦹭Ȭ° false ¥H°±¤îÂsÄý¾¹¦b¥Î¤áºÝ§Ö¨ú¡C

  5. ­«·s±Ò°Ê¡u¹h¹D¡v¡G
  6. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start


¦Û­q¹h¹DªA°È¨Ï¥ÎªÌ¤¶­±

¥»¸`°Q½×¥i¥H½s¿èªº´X­ÓÄÝ©ÊÀɮסC±z¥i¥H¦bºÞ²z¥D±±¥x¤W½s¿è¹h¹DªA°Èªº¼ÐÅÒ¡B¿ù»~°T®§©Î°O¿ý¸ê°Tªº¶¶§Ç¡C¦pªG±z¹Á¸Õ¬°¤£¦Pªº¥»¾÷¦Û­q²£«~¡A³o¬O«D±`¦³¥Îªº¡C

±z¥i¥H¦Û­q¤U¦CÀɮסG

portal-server-install-root/SUNWam/locale/srapGatewayAdminConsole.properties

portal-server-installl-dir/SUNWps/locale/srapGateway.properties

portal-server-install-root/SUNWps/web-src/WEB-INF/classes/srapgwadminmsg.properties


³Æµù

¦pªG±z¦³¤£¦Pªº¥»¾÷³]©w¡A±z»Ý­n¤À§O¬°³o¨ÇÀÉ®×Àx¦s³Æ¥÷¦b­Ó§Oªº locale ¥Ø¿ý¡C


srapGatewayAdminConsole.properties ÀÉ®×

½s¿è³o­ÓÀɮסA¥HÅܧó¥X²{¦bºÞ²z¥D±±¥x¤W¹h¹DªA°ÈªºÄæ¦ì¦WºÙ¡C

srapGateway.properties ÀÉ®×

½s¿è³o­ÓÀÉ®×¥H¡G

srapgwadminmsg.properties ÀÉ®×

½s¿è³o­ÓÀÉ®×¥H¡G


¨Ï¥ÎÁp¦XºÞ²z

Áp¦XºÞ²z¤¹³\¨Ï¥ÎªÌ»E¶°¥L­Ìªº¥»¾÷ÃѧO¡A¥H¨Ï¥L­Ì¦³¤@­Óºô¸ôÃѧO¡CÁp¦XºÞ²z¨Ï¥Îºô¸ôÃѧO¥H¤¹³\¨Ï¥ÎªÌµn¤JªA°È´£¨ÑªÌªººô¯¸¡A¨Ã¥B¤£»Ý­n­«·s»{ÃÒ¥L­ÌªºÃѧO§Y¥i¦s¨ú¨ä¥LªA°È´£¨ÑªÌªººô¯¸¡C³oºÙ¬°³æ¦¸µn¤J¡C

¥i¥H¦b Portal Server ¤W¥H¶}±Ò¼Ò¦¡©M¦w¥þ¼Ò¦¡°t¸mÁp¦XºÞ²z¡CSun ONE Portal ServerºÞ²z­û«ü«n»¡©ú¦p¦ó¦b¶}±Ò¼Ò¦¡¤U°t¸mÁp¦XºÞ²z¡C©ó¦w¥þ¼Ò¦¡¤¤°t¸mÁp¦XºÞ²z¤§«e¡A½Ð¨Ï¥Î¦w¥þ»·ºÝ¦s¨ú¡A¥H½T©wÁp¦XºÞ²z¥i¦b¶}±Ò¼Ò¦¡¤¤¹B§@¡C¦pªG±z·Q­n±zªº¨Ï¥ÎªÌ¦P®É¥H¶}±Ò¼Ò¦¡©M¦w¥þ¼Ò¦¡¦b¬Û¦PªºÂsÄý¾¹¤¤¨Ï¥ÎÁp¦XºÞ²z¡A¥L­Ì¥²¶·±qÂsÄý¾¹²M°£ cookie ©M§Ö¨ú¡C

½Ð°Ñ¾\ Sun ONE Identity Server Customization and API Guide ¥HÁA¸Ñ¦³ÃöÁp¦XºÞ²zªº¸Ô²Ó¸ê°T¡C

Áp¦XºÞ²z¤è®×

¨Ï¥ÎªÌ»{ÃÒ¨ì¤@­Óªì©lªºªA°È´£¨ÑªÌ¡CªA°È¨Ï¥ÎªÌ¬O°Ó·~¥Î³~©Î¬O´£¨Ñ¥Hºô¸ô¬°¥D¤§ªA°Èªº«DÀç§Q²Õ´¡C¦¹¼sªxªººØÃþ¥i¥H¥]¬Aºô»Úºô¸ô¤J¤fºô¯¸¡B¹B¿é´£¨ÑªÌ¡Bª÷¿Ä¾÷ºc¡B®T¼Ö¨Æ·~¤½¥q¡B¹Ï®ÑÀ]¡B¤j¾Ç©M¬F©²¦æ¬F¾÷ºc¡C

ªA°È´£¨ÑªÌ¥i¥H¨Ï¥Î cookie ¥HÀx¦s¨Ï¥ÎªÌ¦b¥Î¤áºÝÂsÄý¾¹ªº¶¥¬q§@·~¸ê°T¡CCookie ¤]¥]§t¨Ï¥ÎªÌªºÃѧO´£¨ÑªÌ¡C

ÃѧO´£¨ÑªÌ¬O¦b´£¨Ñ»{ÃÒªA°È¤¤«ü©wªºªA°È´£¨ÑªÌ¡C°µ¬°ÃѧOªººÞ²zªA°È¡A¥¦­Ì¦P®É¤]ºû«ù¨ÃºÞ²z»{ÃÒ¸ê°T¡CÃѧO´£¨ÑªÌ©Ò§¹¦¨ªº»{ÃÒ¡A¨ü¨ìÁõÄݩ󥦪º©Ò¦³¦øªA¾¹´£¨ÑªÌ©Ò»{¥i¡C

·í¨Ï¥ÎªÌµ{¦¡¦s¨ú¤£ÁõÄÝ©ó¸ÓÃѧO´£¨ÑªÌªºªA°È®É¡A¦¹ÃѧO´£¨ÑªÌ·|±N¸Ó cookie Âà±Hµ¹¿W¥ßªºªA°È´£¨ÑªÌ¡C¦¹ªA°È´£¨ÑªÌ¤§«á«K¥i¦s¨ú¦b cookie ¤¤©I¥sªºÃѧO´£¨ÑªÌ¡C

µM¦Ó¡AµLªk¦b¤£¦P DNS ªººô°ì¶¡Åª¨ú cookie¡C¦]¦¹¨Ï¥Î¡u¦@¥Îºô°ì Cookie ªA°È¡v¥H­«·s¾É¦VªA°È´£¨ÑªÌ¨ì¥¿½TªºÃѧO´£¨ÑªÌ¡A¦]¦¹¨Ï¥ÎªÌ´N¥i¥H±Ò¥Î³æ¦¸µn¤J¡C

°t¸mÁp¦XºÞ²z¸ê·½

Áp¦X¸ê·½¡BªA°È´£¨ÑªÌ¡BÃѧO´£¨ÑªÌ©M¦@¦Pºô°ì Cookie ªA°È (CDCS) ¦b¨ä©Ò¦s¦bªº¹h¹D¤¤³]©wÀɤ¤°t¸m¡C³o³¡¤À»¡©ú¦p¦ó°t¸m¤T­Ó¤è®×¡G

  1. ·í©Ò¦³¸ê·½¦ì¦b¥ø·~¤º³¡ºô¸ô®É¡C
  2. ·í©Ò¦³¸ê·½¨S¦³¦ì©ó¥ø·~¤º³¡ºô¸ô¡A©ÎÃѧO´£¨ÑªÌ¦ì©óºô»Úºô¸ô¡C
  3. ·í©Ò¦³¸ê·½¨S¦³¦ì©ó¥ø·~ºô¸ô¡A©Î·í¥ø·~´£¨ÑªÌ¨ü¨ì¹h¹D«OÅ@¡A¥BÃѧO´£¨ÑªÌ¬O¨ó¤O¼t°Ó¨Ã¦ì©óºô»Úºô¸ô¡C

°t¸m 1

¦b¦¹°t¸m¤¤¡AªA°È´£¨ÑªÌ¡BÃѧO´£¨ÑªÌ©M¡u¦@¥Îºô°ì Cookie ªA°È¡v³£³¡¸p¦b¬Û¦Pªº¥ø·~¤º³¡ºô¸ô¤¤¡A¦ÓÃѧO´£¨ÑªÌ¨Ã¥¼µo§G¨ìºô»Úºô¸ôºô°ì¦WºÙ¦øªA¾¹ Domain Name Server (DNS) ¤¤¡CCDCS ¬°¿ï¶ñ¶µ¥Ø¡C

¦b¦¹°t¸m¤¤¡A¹h¹D«ü¦VªA°È´£¨ÑªÌ¡A¤]´N¬O Portal Server¡C¦¹°t¸m¹ï Portal Server ªº¦h­Ó¹ê¨Ò³£¦³®Ä¡C

  1. ¥HºÞ²z­ûªº¨­¥÷µn¤J Identity Server ºÞ²z¥D±±¥x¡C
  2. ¿ï¨úºÞ²z¥D±±¥x¤¤ªº¡uªA°È°t¸m¡v¼ÐÅÒ¡C
  3. «ö¤@¤U¡uSRA °t¸m¡v¤U¡u¹h¹D¡v®Çªº½bÀY¡C
  4. ±NÅã¥Ü¡u¹h¹D¡v­¶¡C

  5. «ö¤@¤U±z·Q­n³]©w¨äÄݩʤ§¡u¹h¹D³]©wÀÉ¡v®ÇÃ䪺¡u½s¿è ¡K¡v¡C
  6. «K·|Åã¥Ü¡u½s¿è¹h¹D³]©wÀÉ¡v­¶­±¡C

  7. «ö¤@¤U¡u®Ö¤ß¡v¼ÐÅÒ¡C
  8. ¿ï¨ú¡u±Ò¥Î Cookie ºÞ²z¡v®Ö¨ú¤è¶ô¥H±Ò¥Î cookie ºÞ²z¡C
  9. ±²°Ê¦Ü¡uPortal Server ²M³æ¡vÄæ¦ì¨Ã¿é¤JPortal Server¦WºÙ¡A¦p¦¹±z¥i¥H¨Ï¥Î¬Û¹ï URL¡A¹³¬O¦C©ó¡u¥¼»{ÃÒ URL¡v²M³æ¤¤ªº /amserver ©Î /portal/dt¡C¨Ò¦p¡G
  10. http://idp-host:port/amserver/js

    http://idp-host:port/amserver/UI/Login

    http://idp-host:port/amserver/css

    http://idp-host:port/amserver/SingleSignOnService

    http://idp-host:port/amserver/UI/blank

    http://idp-host:port/amserver/postLogin

    http://idp-host:port/amserver/login_images

  11. ±²°Ê¨ì¡uPortal Server ²M³æ¡vÄæ¦ì¨Ã¿é¤J Portal Server ¦WºÙ¡C¨Ò¦p /amserver¡C
  12. «ö¤@¤U¡uÀx¦s¡v¡C
  13. «ö¤@¤U¡u¦w¥þ©Ê¡v¼ÐÅÒ¡C
  14. ±²°Ê¨ì¡u¥¼»{ÃÒ URL¡v²M³æ¨Ã·s¼W¡uÁp¦X¸ê·½¡v¡C¨Ò¦p¡G
  15. /amserver/config/federation

    /amserver/IntersiteTransferService

    /amserver/AssertionConsumerservice

    /amserver/fed_images

    /amserver/preLogin

    /portal/dt

  16. «ö¤@¤U¡u·s¼W¡v¡C
  17. «ö¤@¤U¡uÀx¦s¡v¡C
  18. ¦pªG»Ý­nºô¸ô¥N²z¦øªA¾¹¥H³s¦Ü¦b¡u¥¼»{ÃÒ URL¡v²M³æ¤¤ªº URL¡A«ö¤@¤U¡u¥N²z¦øªA¾¹¡v¼ÐÅÒ¡C
  19. ±²°Ê¨ì¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡vÄæ¦ì¨Ã¿é¤J©Ò»Ýªººô¸ô¥N²z¦øªA¾¹¡C
  20. «ö¤@¤U¡u·s¼W¡v¡C
  21. «ö¤@¤U¡uÀx¦s¡v¡C
  22. ±q²×ºÝ¾÷µøµ¡¤¤¡A­«·s±Ò°Ê¹h¹D¡G
  23. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start

°t¸m 2

¦b¦¹°t¸m¤¤ÃѧO´£¨ÑªÌ¡BÃѧO´£¨ÑªÌ©M¦@¦Pºô°ì Cookie ´£¨ÑªÌ (CDCP) ¨S¦³³¡¸p©ó¥ø·~¤º³¡ºô¸ô¡A©ÎÃѧO´£¨ÑªÌ¬O¦ì©óºô»Úºô¸ô¤Wªº¨ó¤O¼t°Ó¡C

¦b¦¹°t¸m¤¤¡A¹h¹D«ü¦VªA°È´£¨ÑªÌ¡A¤]´N¬O Portal Server¡C¦¹°t¸m¹ï Portal Server ªº¦h­Ó¹ê¨Ò³£¦³®Ä¡C

  1. ¥HºÞ²z­ûªº¨­¥÷µn¤J Identity Server ºÞ²z¥D±±¥x¡C
  2. ¿ï¨úºÞ²z¥D±±¥x¤¤ªº¡uªA°È°t¸m¡v¼ÐÅÒ¡C
  3. «ö¤@¤U¡uSRA °t¸m¡v¤U¡u¹h¹D¡v®Çªº½bÀY¡C
  4. ±NÅã¥Ü¡u¹h¹D¡v­¶¡C

  5. «ö¤@¤U±z·Q­n³]©w¨äÄݩʤ§¡u¹h¹D³]©wÀÉ¡v®ÇÃ䪺¡u½s¿è ¡K¡v¡C
  6. «K·|Åã¥Ü¡u½s¿è¹h¹D³]©wÀÉ¡v­¶­±¡C

  7. «ö¤@¤U¡u®Ö¤ß¡v¼ÐÅÒ¡C
  8. ¿ï¨ú¡u±Ò¥Î Cookie ºÞ²z¡v®Ö¨ú¤è¶ô¥H±Ò¥Î cookie ºÞ²z¡C
  9. ±²°Ê¦Ü¡uPortal Server²M³æ¡vÄæ¦ì¨Ã¿é¤JªA°È´£¨ÑªÌPortal Server¦WºÙ¡A¦p¦¹±z¥i¥H¨Ï¥Î¬Û¹ï URL¡A¹³¬O¦C©ó¡u¥¼»{ÃÒ URL¡v²M³æ¤¤ªº /amserver ©Î /portal/dt¡C
  10. http://idp-host:port/amserver/js

    http://idp-host:port/amserver/UI/Login

    http://idp-host:port/amserver/css

    http://idp-host:port/amserver/SingleSignOnService

    http://idp-host:port/amserver/UI/blank

    http://idp-host:port/amserver/postLogin

    http://idp-host:port/amserver/login_images

  11. «ö¤@¤U¡uÀx¦s¡v¡C
  12. «ö¤@¤U¡u¦w¥þ©Ê¡v¼ÐÅÒ¡C
  13. ±²°Ê¨ì¡u¥¼»{ÃÒ URL¡v²M³æ¨Ã·s¼W¡uÁp¦X¸ê·½¡v¡C¨Ò¦p¡G
  14. /amserver/config/federation

    /amserver/IntersiteTransferService

    /amserver/AssertionConsumerservice

    /amserver/fed_images

    /amserver/preLogin

    /portal/dt

  15. «ö¤@¤U¡u·s¼W¡v¡C
  16. «ö¤@¤U¡uÀx¦s¡v¡C
  17. ¦pªG»Ý­nºô¸ô¥N²z¦øªA¾¹¥H³s¦Ü¦b¡u¥¼»{ÃÒ URL¡v²M³æ¤¤ªº URL¡A«ö¤@¤U¡u¥N²z¦øªA¾¹¡v¼ÐÅÒ¡C
  18. ±²°Ê¨ì¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡vÄæ¦ì¨Ã¿é¤J©Ò»Ýªººô¸ô¥N²z¦øªA¾¹¡C
  19. «ö¤@¤U¡u·s¼W¡v¡C
  20. «ö¤@¤U¡uÀx¦s¡v¡C
  21. ±q²×ºÝ¾÷µøµ¡¤¤¡A­«·s±Ò°Ê¹h¹D¡G
  22. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start

°t¸m 3

¦b¦¹°t¸m¤¤ÃѧO´£¨ÑªÌ¡BÃѧO´£¨ÑªÌ©M¦@¦Pºô°ì Cookie ´£¨ÑªÌ (CDCP) ¨S¦³³¡¸p©ó¥ø·~¤º³¡ºô¸ô¡A©ÎªA°È´£¨ÑªÌ¬O¦ì©óºô»Úºô¸ô¤Wªº¨ó¤O¼t°Ó¡A¥BÃѧO´£¨ÑªÌ¨ü¨ì¹h¹D«OÅ@¡C

¦b¦¹°t¸m¤¤¡A¹h¹D«ü¦VÃѧO´£¨ÑªÌ¡A¤]´N¬O Portal Server¡C

¦¹°t¸m¹ï Portal Server ªº¦h­Ó¹ê¨Ò³£¦³®Ä¡C¦¹°t¸m¦bºô¸ô¤W¬O¤£¤Ó¥i¯àµo¥Íªº¡AµM¦Ó¡A¤@¨Ç¥ø·~ºô¸ô¦b¨ä¥ø·~¤º³¡ºô¸ô¥i¯à·|¦³³o¼Ëªº°t¸m¡A¤]´N¬O»¡¡AÃѧO´£¨ÑªÌ¥i¯à¦ì©ó¥Ñ¨¾¤õÀð«OÅ@ªº¤lºô¸ô¤¤¡A¦Ó¦øªA¾¹´£¨ÑªÌ¥i¥H¦b¥ø·~ºô¸ô¤¤ª½±µ¦s¨ú¡C

  1. ¥HºÞ²z­ûªº¨­¥÷µn¤J Identity Server ºÞ²z¥D±±¥x¡C
  2. ¿ï¨úºÞ²z¥D±±¥x¤¤ªº¡uªA°È°t¸m¡v¼ÐÅÒ¡C
  3. «ö¤@¤U¡uSRA ²ÕºA¡v¤U¡u¹h¹D¡v®Çªº½bÀY¡C
  4. ±NÅã¥Ü¡u¹h¹D¡v­¶¡C

  5. «ö¤@¤U±z·Q­n³]©w¨äÄݩʤ§¡u¹h¹D³]©wÀÉ¡v®ÇÃ䪺¡u½s¿è ¡K¡v¡C
  6. «K·|Åã¥Ü¡u½s¿è¹h¹D³]©wÀÉ¡v­¶­±¡C

  7. «ö¤@¤U¡u®Ö¤ß¡v¼ÐÅÒ¡C
  8. ¿ï¨ú¡u±Ò¥Î Cookie ºÞ²z¡v®Ö¨ú¤è¶ô¥H±Ò¥Î cookie ºÞ²z¡C
  9. ±²°Ê¦Ü¡uPortal Server²M³æ¡vÄæ¦ì¨Ã¿é¤JÃѧO´£¨ÑªÌPortal Server¡A¦p¦¹±z¥i¥H¨Ï¥Î¬Û¹ï URL¡A¹³¬O¦C©ó¡u¥¼»{ÃÒ URL¡v²M³æ¤¤ªº /amserver ©Î /portal/dt¡C
  10. http://idp-host:port/amserver/js

    http://idp-host:port/amserver/UI/Login

    http://idp-host:port/amserver/css

    http://idp-host:port/amserver/SingleSignOnService

    http://idp-host:port/amserver/UI/blank

    http://idp-host:port/amserver/postLogin

    http://idp-host:port/amserver/login_images

  11. «ö¤@¤U¡uÀx¦s¡v¡C
  12. «ö¤@¤U¡u¦w¥þ©Ê¡v¼ÐÅÒ¡C
  13. ±²°Ê¨ì¡u¥¼»{ÃÒ URL¡v²M³æ¨Ã·s¼W¡uÁp¦X¸ê·½¡v¡C¨Ò¦p¡G
  14. /amserver/config/federation

    /amserver/IntersiteTransferService

    /amserver/AssertionConsumerservice

    /amserver/fed_images

    /amserver/preLogin

    /portal/dt

  15. «ö¤@¤U¡u·s¼W¡v¡C
  16. «ö¤@¤U¡uÀx¦s¡v¡C
  17. ¦pªG»Ý­nºô¸ô¥N²z¦øªA¾¹¥H³s¦Ü¦b¡u¥¼»{ÃÒ URL¡v²M³æ¤¤ªº URL¡A«ö¤@¤U¡u¥N²z¦øªA¾¹¡v¼ÐÅÒ¡C
  18. ±²°Ê¨ì¡uºô°ì©M¤lºô°ìªº¥N²z¦øªA¾¹¡vÄæ¦ì¨Ã¿é¤J©Ò»Ýªººô¸ô¥N²z¦øªA¾¹¡C
  19. «ö¤@¤U¡u·s¼W¡v¡C
  20. «ö¤@¤U¡uÀx¦s¡v¡C
  21. ±q²×ºÝ¾÷µøµ¡¤¤¡A­«·s±Ò°Ê¹h¹D¡G
  22. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start



¤W¤@­¶      ¥Ø¿ý      ¯Á¤Þ      ¤U¤@­¶     


Copyright 2003 Sun Microsystems, Inc. «O¯d©Ò¦³Åv§Q¡C