Web認証
-
サーバ IP:認証 Web サーバの IP アドレス。
-
サーバポート:認証 Web サーバのポート。
-
認証規則:Citrix ADCアプライアンスのデフォルト構文の式。Webサーバーが想定する形式でユーザーの資格情報を格納します。
-
\[Scheme\]:HTTP(暗号化されていない Web 認証の場合)または HTTPS(暗号化された Web 認証の場合)。
-
成功規則:Citrix ADCアプライアンスのデフォルトの構文で、ユーザーが正常に認証されたことを示すWebサーバーの応答文字列と一致します。
コマンドラインインターフェイスを使用して Web 認証アクションを構成するには
add authentication webAuthAction <name> -serverIP <ip_addr|ipv6_addr|\*> -serverPort <port|\*> [-fullReqExpr <string>] -scheme ( http | https ) -successRule <expression> [-defaultAuthenticationGroup <string>][-Attribute1 <string>][-Attribute2 <string>] [-Attribute3 <string>][-Attribute4 <string>] [-Attribute5 <string>][-Attribute6 <string>] [-Attribute7 <string>][-Attribute8 <string>] [-Attribute9 <string>][-Attribute10 <string>] [-Attribute11 <string>][-Attribute12 <string>] [-Attribute13 <string>][-Attribute14 <string>] [-Attribute15 <string>][-Attribute16 <string>]
add policy expression post_data ""username=" + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("login=").BEFORE_STR("&") + "&passwort=" + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("passwd=")"
add policy expression length_post_data "("username= " + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("login=").BEFORE_STR("&") + "passwort=" + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("passwd=")).length"
add authentication webAuthAction webAuth_POST -serverIP 10.106.187.54 -serverPort 80 -fullReqExpr q{"POST /MyPHP/auth.php HTTP/" + http.req.version.major + "." + http.req.version.major + "\r\nAccept:\*/\*\r\nHost: 10.106.187.54\r\nReferer: http://10.106.187.54/MyPHP/auth.php\r\nAccept-Language: en-US\r\nUser-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)\r\nContent-Type: application/x-www-form-urlencoded\r\n" + "Content-Length: " + length_post_data + "\r\nConnection: Keep-Alive\r\n\r\n" + post_data} -scheme http -successRule "http.res.status.eq(200)"
構成ユーティリティを使用して Web 認証アクションを構成するには
-
\[**セキュリティ\] > \[AAA-アプリケーショントラフィック\] > \[ポリシー\] > \[LDAP\]**に移動します。
-
詳細ウィンドウの \[サーバー\] タブで、次のいずれかの操作を行います。
-
新しい Web 認証アクションを作成する場合は、\[Add\] をクリックします。
-
既存の Web 認証アクションを変更する場合は、データペインでアクションを選択し、\[編集\] をクリックします。
-
-
新しい Web 認証アクションを作成する場合は、\[認証 Web サーバーの作成\] ダイアログボックスの \[名前\] ボックスに、新しい Web 認証アクションの名前を入力します。名前の長さは 1 ~ 127 文字で、大文字、小文字、数字、ハイフン (-) およびアンダースコア (_) を使用できます。既存の Web 認証アクションを変更する場合は、この手順をスキップします。名前は読み取り専用です。変更できません。</span>
-
\[Web サーバーの IP アドレス\] テキストボックスに、認証 Web サーバーの IPv4 または IPv6 IP アドレスを入力します。アドレスが IPv6 IP アドレスの場合は、最初に \[IPv6\] チェックボックスをオンにします。
-
「ポート」テキストボックスに、Web サーバーが接続を受け入れるポート番号を入力します。
-
\[プロトコル\] ドロップダウンリストで \[HTTP\] または \[HTTPS\] を選択します。
-
\[HTTP 要求式\] テキスト領域で、認証 Web サーバーで想定される正確な形式で、ユーザーの資格情報を含む Web サーバー要求を作成する PCRE-形式の正規表現を入力します。
-
[認証を検証する式]テキスト領域に、Citrix ADCアプライアンスのデフォルトの構文式を入力します。この式には、ユーザー認証が成功したことを示すWebサーバー応答の情報を記述します。
-
一般的な認証アクションのマニュアルで説明されているように、残りのフィールドに入力します。
-
[OK] をクリックします。