NetScaler ADCアプライアンスを使用したAPI認証
トークンの種類
OAuth による API アクセス
set aaaparameter -APITokenCache <ENABLED>
API アクセス用仮想サーバー
Add lb vserver lb-api-access SSL <IP> 443 -authn401 On -AuthnVsName auth-api-access
Bind ssl vserver lb-api-access -certkeyName <ssl-cert-entity>
Add authentication vserver auth-api-access SSL
ID トークンの OAuth 設定
Add authentication OAuthAction oauth-api-access -clientid <your-client-id> -clientsecret <your-client-secret> -authorizationEndpoint <URL to which users would be redirected for login> -tokenEndpoint <endpoint at which tokens could be obtained> -certEndpoint <uri at which public keys of IdP are published>
-
クライアント ID :SP を識別する一意の文字列。承認サーバーは、このIDを使用してクライアントの構成を推測します。最大文字数:127。
-
Client Secret - ユーザーと承認サーバーによって確立されたシークレット文字列。最大長:239
-
AuthorizationEndpoint -ユーザーが通常ログインする URL (インタラクティブクライアントを使用している場合)。
-
TokenEndpoint -トークン/コードが取得/交換される承認サーバー上の URL
-
CerTendPoint -認証サーバーがトークンの署名に使用される公開鍵を公開するURL。承認サーバーは複数のキーを公開し、そのうちの 1 つを選択してトークンに署名できます。
不透明アクセストークンのOAuth設定
set oauthAction oauth-api-acccess -introspectURL <uri of the Authorization Server for introspection>
https://tools.ietf.org/html/rfc7662#section-2.1の仕様に準拠しています。
POST /introspect HTTP/1.1
Host: server.example.com
Accept: application/json
Content-Type: application/x-www-form-urlencoded
Authorization: Basic czZCaGRSa3F0MzpnWDFmQmF0M2JW
token=mF_9.B5f-4.1JqM&token_type_hint=access_token
認証仮想サーバーへのバインディングポリシー
add authentication policy oauth-api-access -rule <> -action <oauth-api-access>
bind authentication vserver auth-api-access -policy oauth-api-access -pri 100
NetScaler ADC アプライアンスのその他のセキュリティ設定
add policy patset oauth_audiences
bind patset oauth_audiences https://app1.company.com
bind patset oauth_audiences https://app2.company.com
bind patset oauth_audiences httpsL//app1.company.com/path1
set oAuthAction oauth-api-access -audience oauth_audiences
set oAuthAction oauth-api-access -allowedAlgorithms RS256 RS512
特定のトラフィックを認証からバイパスする
add authentication policy auth-bypass-policy -rule <> -action NO_AUTHN
bind authentication vserver auth-api-access -policy auth-bypass-policy -pri 110