ื“ืœื’ ืœืชื•ื›ืŸ ื”ืจืืฉื™

SAML SSO

๐Ÿ”‘ ืงื•ื ืคื™ื’ื•ืจืฆื™ื™ืช SAML SSO ืฉืœ Ruijie Cloud ืขื Microsoft Azure Active Directory

ืกืงื™ืจื” ื›ืœืœื™ืชโ€‹

ืžืืžืจ ื–ื” ืžืกืคืง ื”ื•ืจืื•ืช ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ืืช Azure Active Directory (Azure AD) ื›ืกืคืง ื–ื”ื•ื™ื•ืช (IdP) ืขื‘ื•ืจ ื™ื™ืฉื•ื Ruijie Cloud. ื–ื” ืขื•ื–ืจ ืœืžื ื”ืœื™ื ืฉืจื•ืฆื™ื ืœื”ืขื‘ื™ืจ ืืช ื”-Active Directory ืฉืœื”ื ืœืคืœื˜ืคื•ืจืžืช ืขื ืŸ ื›ืžื• Azure ื›ื“ื™ ืœืฉืœื‘ SAML SSO ืขื ื™ื™ืฉื•ื Ruijie Cloud. ืžื•ืžืœืฅ ืœืžื ื”ืœื™ื ืœืงืจื•ื ืืช "ืฉื™ืœื•ื‘ SAML ืœืœื•ื— ืžื—ื•ื•ื ื™ื" (SAML Integration for Dashboard) ืœืคื ื™ ืฉืžืžืฉื™ื›ื™ื.

ื“ืจื™ืฉื•ืช ืžืงื“ื™ืžื•ืชโ€‹

  • ืขืœื™ืš ืœื”ื™ื•ืช ื‘ืขืœ ื—ืฉื‘ื•ืŸ Microsoft Azure AD.
  • ืขืœื™ืš ืœื”ื™ื•ืช ื‘ืขืœ ื—ืฉื‘ื•ืŸ Ruijie Cloud. (ื—ืฉื‘ื•ืŸ Ruijie Cloud ืžืฉืžืฉ ืœื”ืคืขืœืช SAML SSO ื•ืœืงื•ื ืคื™ื’ื•ืจืฆื™ื” ืฉืœ ืชืคืงื™ื“ื™ื ืœืขื‘ื•ื“ื” ืขื Azure AD).

ื ื•ื”ืœโ€‹

1. ื”ืชืงื ืช ื™ื™ืฉื•ื Ruijie Cloud ื‘-Azureโ€‹

(1) ื‘ืคื•ืจื˜ืœ Azure, ืœื—ืฅ ืขืœ Azure Active Directory. (2) ื‘ืฆื“ ืฉืžืืœ, ืœื—ืฅ ืขืœ Manage (ื ื™ื”ื•ืœ) > Enterprise applications (ื™ื™ืฉื•ืžื™ื ืืจื’ื•ื ื™ื™ื). ื ื™ื”ื•ืœ ื™ื™ืฉื•ืžื™ื ืืจื’ื•ื ื™ื™ื (3) ืœื—ืฅ ืขืœ New application (ื™ื™ืฉื•ื ื—ื“ืฉ). ื™ื™ืฉื•ื ื—ื“ืฉ (4) ืœื—ืฅ ืขืœ Create your own application (ืฆื•ืจ ื™ื™ืฉื•ื ืžืฉืœืš). ืฆื•ืจ ื™ื™ืฉื•ื ืžืฉืœืš (5) ื”ื–ืŸ Ruijie Cloud (ืื• ืฉืžื•ืช ืื—ืจื™ื ื”ื ื™ืชื ื™ื ืœื–ื™ื”ื•ื™ ื‘ืงืœื•ืช), ื‘ื—ืจ Integrate any other application you donโ€™t find in the gallery (Non-gallery) (ืฉืœื‘ ื›ืœ ื™ื™ืฉื•ื ืื—ืจ ืฉืื™ื ืš ืžื•ืฆื ื‘ื’ืœืจื™ื”), ื•ืœื—ืฅ ืขืœ Create (ืฆื•ืจ). ื”ื–ื ืช ืฉื ื™ื™ืฉื•ื ื•ื™ืฆื™ืจื” (6) ื ื•ื•ื˜ ื—ื–ืจื” ืœื“ืฃ Enterprise applications (ื›ืคื™ ืฉืžื•ืฆื’ ื‘ืฉืœื‘ (2)). ืœืื—ืจ ืฉื™ื™ืฉื•ื Ruijie Cloud ื”ื•ืชืงืŸ ื‘ื”ืฆืœื—ื”, ืชืจืื” ืืช Ruijie Cloud ื‘ืจืฉื™ืžืช ื”ื™ื™ืฉื•ืžื™ื ืฉืœืš. ืจืฉื™ืžืช ื™ื™ืฉื•ืžื™ื

2. ื™ืฆื™ืจืช ืชืคืงื™ื“ื™ ื™ื™ืฉื•ื (App Roles) ื‘ืชื•ืš ื™ื™ืฉื•ื Ruijie Cloud ื‘-Azureโ€‹

ื™ืฉ ืฉืชื™ ืฉื™ื˜ื•ืช ืœื”ืฆื”ื™ืจ ืขืœ ืชืคืงื™ื“ื™ ื™ื™ืฉื•ื ื‘ืืžืฆืขื•ืช ืคื•ืจื˜ืœ Azure:

  • ืชืคืงื™ื“ื™ ื™ื™ืฉื•ื ื‘ืืžืฆืขื•ืช ืžืžืฉืง ื”ืžืฉืชืžืฉ ืฉืœ ืคื•ืจื˜ืœ Azure (ื›ืคื™ ืฉืžื•ืฆื’ ืœื”ืœืŸ).
  • ืชืคืงื™ื“ื™ ื™ื™ืฉื•ื ื‘ืืžืฆืขื•ืช ืžื ื™ืคืกื˜.

(1) ื ื•ื•ื˜ ืืœ App registrations (ืจื™ืฉื•ืžื™ ื™ื™ืฉื•ืžื™ื). ืจื™ืฉื•ืžื™ ื™ื™ืฉื•ืžื™ื (2) ืœื—ืฅ ืขืœ All applications (ื›ืœ ื”ื™ื™ืฉื•ืžื™ื). (3) ืœื—ืฅ ืขืœ Ruijie Cloud (ืื• ื›ืœ ืฉื ืื—ืจ ืฉื”ื’ื“ืจืช ื‘ืฉืœื‘ 1). (4) ืœื—ืฅ ืขืœ App roles (ืชืคืงื™ื“ื™ ื™ื™ืฉื•ื). ืชืคืงื™ื“ื™ ื™ื™ืฉื•ื (5) ืœื—ืฅ ืขืœ Create app role (ืฆื•ืจ ืชืคืงื™ื“ ื™ื™ืฉื•ื). (6) ืฆื•ืจ ืชืคืงื™ื“ ื•ื”ื’ื“ืจ ืืช Display name (ืฉื ืชืฆื•ื’ื”), Allowed member types (ืกื•ื’ื™ ื—ื‘ืจื™ื ืžื•ืชืจื™ื) ื•-Value (ืขืจืš). ื”-Value ื”ื•ื ืžื” ืฉื™ื•ืขื‘ืจ ืœื”ืฆื”ืจืช SAML. ื™ืฆื™ืจืช ืชืคืงื™ื“ ื™ื™ืฉื•ื (7) ืœื—ืฅ ืขืœ Apply (ื”ื—ืœ). (8) ื—ื–ื•ืจ ืขืœ ืฉืœื‘ื™ื (5) ืขื“ (7) ืขื‘ื•ืจ ื›ืœ ืชืคืงื™ื“ื™ ื”ื™ื™ืฉื•ื ื”ื“ืจื•ืฉื™ื.

3. ื”ื’ื“ืจืช ืžืฉืชืžืฉื™ื ื•ืชืคืงื™ื“ื™ื (Users and Roles) ื‘ื™ื™ืฉื•ื Ruijie Cloud ื‘-Azureโ€‹

(1) ื ื•ื•ื˜ ืืœ ื“ืฃ Enterprise applications (ื›ืคื™ ืฉืžื•ืฆื’ ื‘ืฉืœื‘ 1(2)). (2) ืœื—ืฅ ืขืœ Ruijie Cloud. (3) ื‘ืฆื“ ืฉืžืืœ, ืœื—ืฅ ืขืœ Manage (ื ื™ื”ื•ืœ) > Users and groups (ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช). ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช (4) ืœื—ืฅ ืขืœ Add user/group (ื”ื•ืกืฃ ืžืฉืชืžืฉ/ืงื‘ื•ืฆื”). ื”ื•ืกืฃ ืžืฉืชืžืฉ/ืงื‘ื•ืฆื” (5) ืœื—ืฅ ืขืœ None selected (ืœื ื ื‘ื—ืจ) ื‘ืชื™ื‘ื” Users. (6) ื‘ื—ืจ ืžืฉืชืžืฉื™ื/ืงื‘ื•ืฆื•ืช ืžื”ืจืฉื™ืžื” ื•ืœื—ืฅ ืขืœ Select (ื‘ื—ืจ). ื‘ื—ื™ืจืช ืžืฉืชืžืฉื™ื/ืงื‘ื•ืฆื•ืช (7) ืœื—ืฅ ืขืœ None selected (ืœื ื ื‘ื—ืจ) ื‘ืชื™ื‘ื” Select a role (ื‘ื—ืจ ืชืคืงื™ื“). (8) ื‘ื—ืจ ืชืคืงื™ื“ ืžื”ืจืฉื™ืžื” ืฉื ื•ืฆืจื” ื‘ืฉืœื‘ 2 ื•ืœื—ืฅ ืขืœ Select (ื‘ื—ืจ). ื‘ื—ื™ืจืช ืชืคืงื™ื“ (9) ืœื—ืฅ ืขืœ Assign (ื”ืงืฆื”).

4. ื”ื’ื“ืจืช Single Sign-On (SSO) ื‘ื™ื™ืฉื•ื Ruijie Cloud ื‘-Azureโ€‹

(1) ื ื•ื•ื˜ ืืœ ื“ืฃ Enterprise applications. (2) ืœื—ืฅ ืขืœ Ruijie Cloud. (3) ื‘ืฆื“ ืฉืžืืœ, ืœื—ืฅ ืขืœ Manage (ื ื™ื”ื•ืœ) > Single sign-on (ื›ื ื™ืกื” ื™ื—ื™ื“ื”). ื›ื ื™ืกื” ื™ื—ื™ื“ื” (4) ื‘ื—ืจ SAML. ื‘ื—ื™ืจืช SAML (5) ืœื—ืฅ ืขืœ Edit (ืขืจื•ืš) ื‘ื—ืœื•ื ื™ืช Attributes & Claims (ืชื›ื•ื ื•ืช ื•ืชื‘ื™ืขื•ืช). ืขืจื™ื›ืช ืชื›ื•ื ื•ืช ื•ืชื‘ื™ืขื•ืช (6) ืœื—ืฅ ืขืœ Add new claim (ื”ื•ืกืฃ ืชื‘ื™ืขื” ื—ื“ืฉื”). (7) ื”ื–ืŸ Role (ืชืคืงื™ื“) ื‘ืชื™ื‘ื” Name (ืฉื) ื•ื‘ื—ืจ user.assignedroles (ืชืคืงื™ื“ื™ื ืฉื”ื•ืงืฆื• ืœืžืฉืชืžืฉ) ื‘ืชื™ื‘ื” Source attribute (ืชื›ื•ื ืช ืžืงื•ืจ). ืœื—ืฅ ืขืœ Save (ืฉืžื•ืจ). ื”ื•ืกืคืช ืชื‘ื™ืขืช ืชืคืงื™ื“ (8) ืœืื—ืจ ืฉื ื•ืกืคื” ื”ืชื‘ื™ืขื” ื”ื—ื“ืฉื”, ืœื—ืฅ ืขืœ Add a group claim (ื”ื•ืกืฃ ืชื‘ื™ืขืช ืงื‘ื•ืฆื”). (9) ื‘ื—ืจ All groups (ื›ืœ ื”ืงื‘ื•ืฆื•ืช). ื”ื•ืกืคืช ืชื‘ื™ืขืช ืงื‘ื•ืฆื” (10) ืœื—ืฅ ืขืœ Download (ื”ื•ืจื“) ืœื™ื“ Federation Metadata XML (ืžื˜ื ื ืชื•ื ื™ื ืฉืœ ืคื“ืจืฆื™ื” XML) ื‘ื—ืœื•ื ื™ืช SAML Signing Certificate (ืื™ืฉื•ืจ ื—ืชื™ืžืช SAML). (ืงื•ื‘ืฅ ื–ื” ื ื“ืจืฉ ืœื”ืคืขืœืช SSO ื‘-Ruijie Cloud ื‘ืฉืœื‘ 5).

5. ื”ื’ื“ืจืช SSO ื‘-Ruijie Cloudโ€‹

(1) ื”ื™ื›ื ืก ืœ-Ruijie Cloud ื•ื ื•ื•ื˜ ืืœ SAML SSO > SAML Settings. (2) ืœื—ืฅ ืขืœ Upload XML (ื”ืขืœื” XML) ื•ื”ืขืœื” ืืช ืงื•ื‘ืฅ ื”-Federation Metadata XML ืฉื”ื•ืจื“ ื‘ืฉืœื‘ 4. ื”ืขืœืืช XML (3) ืœืื—ืจ ื”ื”ืขืœืื”, ืœื—ืฅ ืขืœ Enable SAML SSO (ื”ืคืขืœ SAML SSO). ื”ืคืขืœืช SAML SSO (4) ื”ืขืชืง ืืช ื”-Consumer URL (ื›ืชื•ื‘ืช URL ืœืฆืจื›ืŸ) ื•ืฉืžื•ืจ ืื•ืชื• ืœื”ืžืฉืš. ืฉืžื™ืจืช ืงื•ื ืคื™ื’ื•ืจืฆื™ื” (5) ื—ื–ื•ืจ ืœื“ืฃ ื”ื‘ื™ืช ืฉืœ ืคื•ืจื˜ืœ Azure, ืœื—ืฅ ืขืœ Manage (ื ื™ื”ื•ืœ) > Single sign-on (ื›ื ื™ืกื” ื™ื—ื™ื“ื”). ื‘ื—ืœื•ื ื™ืช Basic SAML Configuration (ืงื•ื ืคื™ื’ื•ืจืฆื™ื™ืช SAML ื‘ืกื™ืกื™ืช), ืœื—ืฅ ืขืœ Edit (ืขืจื•ืš). ืขืจื™ื›ืช ืงื•ื ืคื™ื’ื•ืจืฆื™ื™ืช SAML ื‘ืกื™ืกื™ืช (6) ื“ืจื•ืก ืืช Reply URL (Assertion Consumer Service URL) (ื›ืชื•ื‘ืช URL ืœื”ืฉื‘ื”) ื”ืžื•ื’ื“ืจ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื”ืงื™ื™ื ืขื Consumer URL (ื›ืชื•ื‘ืช URL ืœืฆืจื›ืŸ) ืžืฉืœื‘ (4). ื”ืฉื“ื” Identifier (Entity ID) (ืžื–ื”ื”) ืืžื•ืจ ืœื”ืชืžืœื ืื•ื˜ื•ืžื˜ื™ืช. ืื ืœื, ื”ื–ืŸ https://cloud-as.ruijienetworks.com ื‘ืฉื“ื” ื–ื”. (ื”ืขืจื”: ื”ืžื–ื”ื” ื›ืคื•ืฃ ืœืขืจืš ื‘ืฉื“ื” Reply URL). ืขื“ื›ื•ืŸ ื›ืชื•ื‘ืช URL ืœื”ืฉื‘ื” ื•ืžื–ื”ื”

6. ื™ืฆื™ืจืช ืชืคืงื™ื“ื™ ืžื ื”ืœ SAML ื‘-Ruijie Cloudโ€‹

(1) ื”ื™ื›ื ืก ืœ-Ruijie Cloud, ื ื•ื•ื˜ ืืœ SAML SSO > SAML Roles Manager ื•ืœื—ืฅ ืขืœ Add SAML role (ื”ื•ืกืฃ ืชืคืงื™ื“ SAML). ื”ื•ืกืคืช ืชืคืงื™ื“ SAML (2) ืฆื•ืจ ืชืคืงื™ื“ ื•ื‘ื—ืจ ืืช ื”ืจืฉืื•ืช ื”ื’ื™ืฉื” (Read-only - ืงืจื™ืื” ื‘ืœื‘ื“ ืื• Read & Write - ืงืจื™ืื” ื•ื›ืชื™ื‘ื”) ืขื‘ื•ืจ ืชืคืงื™ื“ ื–ื”. ืฉื ื”-Role (ืชืคืงื™ื“) ื—ื™ื™ื‘ ืœื”ืชืื™ื ืœ-Value (ืขืจืš) ืฉืœ ืชืคืงื™ื“ ื”ื™ื™ืฉื•ื ืฉื”ื•ื’ื“ืจ ื‘-Azure. ืื—ืจืช, ืžืฉืชืžืฉื™ื ืœื ื™ื•ื›ืœื• ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช SAML ืœืืจื’ื•ืŸ ืฉื”ื•ื’ื“ืจ. ื™ืฆื™ืจืช ืชืคืงื™ื“ ื•ื‘ื—ื™ืจืช ื”ืจืฉืื•ืช (3) ืœื—ืฅ ืขืœ Save (ืฉืžื•ืจ). ื—ื–ื•ืจ ืขืœ ืฉืœื‘ื™ื (1) ืขื“ (3) ืขื‘ื•ืจ ื›ืœ ืชืคืงื™ื“ SAML ื ื•ืกืฃ ืฉื ื•ืฆืจ ื‘-Azure. ืฉืžื™ืจืช ื”ืชืคืงื™ื“

ื‘ื“ื™ืงืช ื”ื™ื™ืฉื•ื ื‘-Azure AD https://myapps.microsoft.com/ ื‘ื“ื™ืงืช ื”ื™ื™ืฉื•ื ื‘-Azure AD

ืฉืืœื•ืช ื ืคื•ืฆื•ืช (FAQ)

  • ืื ืชืคืงื™ื“ ื‘-Ruijie Cloud ืฉื•ื ื” ืžื–ื” ืฉื‘-Azure, ื”ืžืฉืชืžืฉ ืœื ื™ืฆืœื™ื— ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช SAML.
  • ืื ืื™ื ืš ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช SAML, ื•ื“ื ืฉื”ืืคืœื™ืงืฆื™ื” ื‘-Azure AD ืžื•ื’ื“ืจืช ื›ืจืื•ื™ ื•ืฉื”ืžืฉืชืžืฉ ืจืฉื•ื ืœืืคืœื™ืงืฆื™ื” ื‘-Azure AD.

ืื ืื™ื ืš ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช SAML, ื•ื“ื ืฉื”ืืคืœื™ืงืฆื™ื” ื‘-Azure AD ืžื•ื’ื“ืจืช ื›ืจืื•ื™ ื•ืฉื”ืžืฉืชืžืฉ ืจืฉื•ื ืœืืคืœื™ืงืฆื™ื” ื‘-Azure AD. ืื ื”ืชืคืงื™ื“ ื‘-Ruijie Cloud ืฉื•ื ื” ืžื–ื” ืฉื‘-Azure, ื”ืžืฉืชืžืฉ ืœื ื™ืฆืœื™ื— ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช SAML.