多要素(nFactor)の概念、エンティティ、用語
ログインスキーマ
add authentication loginSchema <name> -authenticationSchema <string> [-userExpression <string>] [-passwdExpression <string>] [-userCredentialIndex <positive_integer>] [-passwordCredentialIndex <positive_integer>] [-authenticationStrength <positive_integer>] [-SSOCredentials ( YES | NO )]
<https://developer-docs.citrix.com/projects/citrix-adc-command-reference/en/latest/authentication/authentication-loginSchema/#add-authentication-loginschema>」を参照してください。
ポリシーラベル
add authentication policy label mylabel –loginSchema <>
仮想サーバラベル
次の因子
認証なしポリシー
No-authポリシーは、次の CLI コマンドを実行して作成できます。
add authentication policy noauthpolicy –rule <> -action NO_AUTHN
no-authentication ポリシーは任意の高度なポリシー式であることができるルールを取ります。認証結果は常に NO_AUTHN から成功する。
no-authポリシー自体は価値を付加するものではないようです。ただし、パススルーポリシーラベルとともに使用すると、ユーザ認証フローを促進する論理的な決定を柔軟に行うことができます。NO_AUTHN ポリシーとパススルーファクターは、nFactor の柔軟性に新たな次元を提供します。
no-auth およびパススルーの使用方法を示す例を確認してください。
パススルー・ファクタ/ラベル
add authentication policylabel example1
add loginschema passthrough_schema –authenticationSchema noschema
add authentication policylabel example2 –loginschema passthrough_schema
-
ユーザに 2 つのパスワードフィールドが表示された場合、1 つ目のファクタの後に 2 番目のファクタにユーザの介入は必要ありません。
-
あるタイプ (証明書など) の認証が行われ、管理者がそのユーザーのグループを抽出する必要がある場合。
NO_AUTHポリシーとともに使用して、条件付きジャンプを行うことができます。
nFactor 認証フロー
パススルーファクターと非認証ポリシーを使用して論理的な決定を下す例
add authentication policylabel group check
add authentication policy admin group –rule http.req.user.is_member_of("Administrators") –action NO_AUTHN
add authentication policy nonadmins –rule true –action NO_AUTHN
bind authentication policy label group check –policy admingroup –pri 1 –nextFactor factor-for-admin
bind authentication policy label groupcheck –policy nonadmins –pri 10 –nextfactor factor-for-others
add authentication policy first_factor_policy –rule <> -action <>
bind authentication vserver <> -policy first_factor_policy –priority 10 –nextFactor groupcheck