IceWall

IceWall¤È¤Ï

Web¥Ù¡¼¥¹¤Î¥·¥ó¥°¥ë¥µ¥¤¥ó¥ª¥óÀ½Éʤǡ¢Web¥µ¡¼¥Ð¡¼¤Îǧ¾Ú¤ò°ì¸µ´ÉÍý¤¹¤ë
¾ðÊó·Ñ¾µµ¡Ç½¤ò»È¤¦¤³¤È¤Ç¡¢Web¥µ¡¼¥Ð¡¼¤Ø¤Îǧ¾Ú¤ÏIceWall¤Ë¥í¥°¥¤¥ó¤¹¤ë¥¢¥«¥¦¥ó¥È¤Î¤ß¤È¤Ê¤ê¡¢Ê£¿ô¤Î¥Ñ¥¹¥ï¡¼¥É´ÉÍý¤¬ÉÔÍפȤʤë
¤½¤ì¤¾¤ì¤ÎWeb¥µ¡¼¥Ð¡¼¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¸¢¸Â¤Ë¤Ä¤¤¤Æ¤â°ì¸µ´ÉÍý¤µ¤ì¤ë°Ù¡¢WEB¥µ¡¼¥Ð¡¼Ëè¤Îǧ¾Ú¥¢¥×¥ê³«È¯¤¬ÉÔÍפȤʤë

IceWall¤Î´ðËܹ½À®

icewall_summary.png

¥µ¡¼¥Ð¡¼¥×¥í¥»¥¹Ìò³ä
¥Õ¥©¥ï¡¼¥Àdfw¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤È¤·¤Æ¥¯¥é¥¤¥¢¥ó¥È¤È¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤È¤ÎÄÌ¿®Ãæ·Ñ¤ò¹Ô¤¦¡£CGI¤È¤·¤Æ²ÔÆ°¤¹¤ë
ǧ¾Ú¥â¥¸¥å¡¼¥ëcertd¥æ¡¼¥¶¡¼¾ðÊó¡¢¥¢¥¯¥»¥¹À©¸æ¡¢¥í¥°¥¤¥ó¾õ¶·¤ò°ì³ç´ÉÍý¤¹¤ë
ǧ¾ÚDBOracle¤Ê¤ÉIceWall¤Î¥¢¥«¥¦¥ó¥È¤ò´ÉÍý¤¹¤ë
¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼httpd¥Õ¥©¥ï¡¼¥À¤«¤éžÁ÷¤µ¤ì¤ëWeb¥µ¡¼¥Ð¡¼

¥Õ¥©¥ï¡¼¥À¤ÎÄÌ¿®¥È¥é¥ó¥¶¥¯¥·¥ç¥ó

­¡¥¯¥é¥¤¥¢¥ó¥È¤«¤é¥Õ¥©¥ï¡¼¥À¤Ø¥¢¥¯¥»¥¹¤·¡¢¥í¥°¥¤¥ó¥Õ¥©¡¼¥à¤òɽ¼¨¤¹¤ë¡Ê¥í¥°¥¤¥óºÑ¤ß¤Ç¤¢¤ì¤Ð­¤¤Ø¡Ë
­¢¥æ¡¼¥¶¡¼¤È¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·Ç§¾Ú¥µ¡¼¥Ð¡¼¤ØÅϤµ¤ì¤ë
­£Ç§¾Ú¥µ¡¼¥Ð¡¼¤¬Ç§¾ÚDB¤ØÌ䤤¹ç¤ï¤»Àµµ¬¥æ¡¼¥¶¡¼¤«³Îǧ¤·¡¢ÌäÂê¤Ê¤±¤ì¤Ð¥³¥ó¥Õ¥£¥°¤Ç»ØÄꤵ¤ì¤¿¥«¥é¥à¤ÎÃͤòÁ´¤Æcertd¤ËÅϤ¹
¡¡ÉÔÍפÊDB¥¢¥¯¥»¥¹¤òÈò¤±¤ë°Ù¡¢certd¤Ï¥ª¥ó¥á¥â¥ê¤Ç¼èÆÀ¤·¤¿¾ðÊó¤òÊÝ»ý¤¹¤ë
¡¡¥«¥é¥à¤¬Â¿¤±¤ì¤Ð¿¤¤Äø¡¢¥á¥â¥ê¤ò¿©¤¦¤Î¤ÇÉÔÍפʥ«¥é¥à¤Ï¥³¥ó¥Õ¥£¥°¤Çºï½ü¤¹¤ë
­¤¥Õ¥©¥ï¡¼¥À¤Èǧ¾Ú¥µ¡¼¥Ð¡¼¤Ï²èÌÌÁ«°Ü¤ÎÅ٤˳ºÅö¥Ú¡¼¥¸¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¸¢¸Â¤ò¥Á¥§¥Ã¥¯¤¹¤ë
­¥¥¢¥¯¥»¥¹¸¢¸Â¤¬¤¢¤ì¤Ð¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¥Õ¥©¥ï¡¼¥É¤·WEB¥Ú¡¼¥¸¤òɽ¼¨¤µ¤»¤ë

¥¤¥ó¥¹¥È¡¼¥ë

Á´¤Æ/opt/icewall-sso/¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤ë

rpm -iv --nodeps IceWall-SSO-certd_<ǧ¾Ú·Á¼°>_<¥Ð¡¼¥¸¥ç¥ó>_<¥¢¡¼¥­¥Æ¥¯¥Á¥ã>.rpm
rpm -iv --nodeps IceWall-SSO-dfw_<¥Ð¡¼¥¸¥ç¥ó>_<¥¢¡¼¥­¥Æ¥¯¥Á¥ã>.rpm
chown -R iwadmin /opt/icewal-sso/certd¡¡¡¡¡¡¡¡¡Å¡Åcertd¤ò¼Â¹Ô¤¹¤ë¥æ¡¼¥¶¡¼¤Î¸¢¸Â¤Ë¤¹¤ë
chown -R apache:apache /opt/icewall-sso/dfw¡¡ ¡Å¡ÅApache¤ò¼Â¹Ô¤¹¤ë¥æ¡¼¥¶¡¼¤Î¸¢¸Â¤Ë¤¹¤ë

Apache¤ÎÀßÄê

httpd.conf¤Ë°Ê²¼¤Îʸ¸À¤òÄɲ乤ë

Alias /img/ "/opt/icewall-sso/dfw/html/image/"
SetEnv LD_LIBRARY_PATH "/opt/icewall-sso/lib/dfw:/usr/lib64"
ScriptAlias /fw/ "/opt/icewall-sso/dfw/cgi-bin/"
<Directory "/opt/icewall-sso/dfw/cgi-bin/">
     AllowOverride All
     Options ExecCGI
     SetHandler cgi-script
     Order allow,deny
     Allow from all
</Directory>

¥Ç¥£¥ì¥¯¥È¥ê¹½À®

/opt/icewall-sso/
¡¡certd¡¡¡¡¡¡¡¡¡¡¡¡Ç§¾Ú¥â¥¸¥å¡¼¥ë
¡¡¡¡bin¡¡¡¡¡¡¡¡¡¡¡¡Ç§¾Ú¥â¥¸¥å¡¼¥ë¤Î¥×¥í¥°¥é¥à¤ä¥¹¥¯¥ê¥×¥È
¡¡¡¡config¡¡¡¡¡¡¡¡ ǧ¾Ú¥â¥¸¥å¡¼¥ë¤ÎÀßÄê¥Õ¥¡¥¤¥ë
¡¡dfw¡¡¡¡¡¡¡¡¡¡¡¡¡¡¥Õ¥©¥ï¡¼¥À
¡¡¡¡cgi-bin¡¡¡¡¡¡¡¡¥Õ¥©¥ï¡¼¥À¤ÎCGI¥×¥í¥°¥é¥àµÚ¤ÓÀßÄê¥Õ¥¡¥¤¥ë
¡¡¡¡chtml¡¡¡¡¡¡¡¡¡¡¥í¥°¥¤¥ó¤ä¥¨¥é¡¼²èÌ̤Υ³¥ó¥Æ¥ó¥Ä¡Ê·ÈÂÓÍÑ¡Ë
¡¡¡¡html¡¡¡¡¡¡¡¡¡¡ ¥í¥°¥¤¥ó¤ä¥¨¥é¡¼²èÌ̤Υ³¥ó¥Æ¥ó¥Ä¡ÊPCÍÑ¡Ë

¡¡¡¡

IceWall¥·¥¹¥Æ¥àÍѥơ¼¥Ö¥ë¤ÎºîÀ®

$ cd /opt/ice-wall/tools
$ sqlplus UID/PASS@oracleSID
SQL > @cre_tbl_test.sql¡¡¡¡¡¡ ¡Å¡ÅICEWALLTEST¥Æ¡¼¥Ö¥ë¤òºîÀ®¤¹¤ë¡£Ì¾Á°¤òÊѤ¨¤¿¤±¤ì¤ÐSQL¤ò½¤Àµ¤¹¤ë
SQL > @cre_tbl_history.sql¡¡¡¡¡Å¡ÅHISTORY¥Æ¡¼¥Ö¥ë¤òºîÀ®¤¹¤ë
SQL > @cre_sequence.sql
ICEWALLTEST¡¡¤Î¥«¥é¥à
̾Á°                               NULL?    ·¿
-------------------------------- -------- ----------------------------
USERID                           NOT NULL VARCHAR2(20)
PASSWD                           NOT NULL CHAR(37)
PASSCHANGE                       NOT NULL CHAR(1)
PASSWDEXP                                 CHAR(14)
PASSWDHIS                                 CHAR(37)
CHGDATE                                   CHAR(14)
LOGONDATE                                 CHAR(14)
LASTDATE                                  CHAR(14)
LOGONFAIL                                 CHAR(14)
FAILCOUNT                        NOT NULL NUMBER(38)
LOCKOUT                          NOT NULL CHAR(1)
LOGONSTOP                        NOT NULL CHAR(1)
LOCKDATE                                  CHAR(14)
LOGSTATUS                        NOT NULL CHAR(1)


ºîÀ®¤·¤¿¥Æ¡¼¥Ö¥ë¤È¥«¥é¥à¤ò¥Þ¥Ã¥Ô¥ó¥°¤¹¤ë

¤É¤Î¥«¥é¥à¤ò¥æ¡¼¥¶¡¼Ì¾¡¢¥Ñ¥¹¥ï¡¼¥É¤È¤¹¤ë¤«ÄêµÁ¤·¡¢IceWallǧ¾Ú¾ðÊó¤È¤·¤Æ¥Þ¥Ã¥Ô¥ó¥°¤¹¤ë
¡Ú¥Õ¥¡¥¤¥ë¡Û /opt/icewall-sso/certd/config/dbattr.conf
¡Ú¡¡½ñ¼°¡¡¡Û ¹àÌÜ=DB¦¤Î¥«¥é¥à̾

UID=USERID¡¡¡¡¡¡¡¡¡¡¡¡ ¥æ¡¼¥¶¡¼ID
PASSWORD=PASSWD¡¡¡¡¡¡¡¡¥Ñ¥¹¥ï¡¼¥É
PWDEXPDATE=PASSWDEXP¡¡ ¥Ñ¥¹¥ï¡¼¥ÉÍ­¸ú´ü¸Â
PWDHISTORY=PASSWDHIS¡¡ ¥Ñ¥¹¥ï¡¼¥ÉÍúÎò
PCHGOK=PASSCHANGE¡¡¡¡¡¡¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹ON/OFF¡Ê1¤ÇON¡Ë
PCHGDATE=CHGDATE¡¡¡¡¡¡ ¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹Æü
PLOGINDATE=LOGONDATE¡¡ ¥í¥°¥¤¥ó»þ¹ï
LLOGINDATE=LASTDATE¡¡¡¡ºÇ½ª¥í¥°¥¤¥ó»þ¹ï
FLOGINDATE=LOGONFAIL¡¡ ¥í¥°¥¤¥ó¼ºÇÔ»þ¹ï
PWDRETRY=FAILCOUNT¡¡¡¡ ¥Ñ¥¹¥ï¡¼¥É¥ê¥È¥é¥¤²ó¿ô
PWDLOCK=LOCKOUT¡¡¡¡¡¡¡¡¥¢¥«¥¦¥ó¥È¥í¥Ã¥¯Í­Ìµ¡Ê1¤Ç¥í¥Ã¥¯¡Ë
LOGINOK=LOGONSTOP¡¡¡¡¡¡¥í¥°¥¤¥óOK/NG¡Ê1¤ÇOK¡Ë
LOCKDATE=LOCKDATE¡¡¡¡¡¡¥¢¥«¥¦¥ó¥È¥í¥Ã¥¯»þ¹ï
LOGINSTAT=LOGSTATUS¡¡¡¡¥í¥°¥¤¥ó¥¹¥Æ¡¼¥¿¥¹¡Ê1¤Ç¥í¥°¥¤¥óÃæ¡Ë


IceWall¥æ¡¼¥¶¡¼¤ÎºîÀ®

/opt/icewal-sso/tools/°Ê²¼¤Î3¤Ä¤Î¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ¹¤ë
DATA.txt¡¡¡¡¡¡TEMPLATE.sql¤Ë°ú¤­ÅϤ¹¥Ñ¥é¥á¡¼¥¿¤ò¥«¥ó¥Þ¶èÀÚ¤ê¤Çµ­ºÜ
TEMPLATE.sql¡¡TABLE¤ËINSERT¤¹¤ëSQLʸ¡£DATA.txt¤ÇÅϤµ¤ì¤¿¥Ñ¥é¥á¡¼¥¿¤ò°Ê²¼¤Î¥­¡¼¥ï¡¼¥É¤ÇÃÖ´¹¤¹¤ë

¥­¡¼¥ï¡¼¥ÉÀâÌÀ
$n$n¥«¥é¥àÌܤΥǡ¼¥¿¤ËÃÖ´¹
$mn$n¥«¥é¥àÌܤΥǡ¼¥¿¤òMD5¤Ç¥Ï¥Ã¥·¥å¤·¤¿ÃͤÇÃÖ´¹¡ÊOracle¤Ê¤É¤Ç¤Ï¤³¤ì¤ò»È¤¦¡Ë
$sn$n¥«¥é¥àÌܤΥǡ¼¥¿¤òSHA1¤Ç¥Ï¥Ã¥·¥å¤·¤¿ÃͤÇÃÖ´¹¡ÊLDAP¤Ê¤É¡Ë
$hn$n¥«¥é¥àÌܤΥǡ¼¥¿¤òSHA256¤Ç¥Ï¥Ã¥·¥å¤·¤¿ÃͤÇÃÖ´¹
$an$n¥«¥é¥àÌܤΥǡ¼¥¿¤òÀ½ÉÊɸ½à·Á¼°(¸°Ä¹128bit)¤Ç°Å¹æ²½¤·¤¿ÃͤËÃÖ´¹
$bn$n¥«¥é¥àÌܤΥǡ¼¥¿¤òÀ½ÉÊɸ½à·Á¼°(¸°Ä¹256bit)¤Ç°Å¹æ²½¤·¤¿ÃͤËÃÖ´¹
# ./mkuser TEMPLATE.sql DATA.txt > outputfile.sql
$ sqlplus UID/PASS@oracleSID @outputfile.sql


ǧ¾Ú¥â¥¸¥å¡¼¥ë¤Î´ðËÜÀßÄê

»ÈÍѤ¹¤ëDBµÚ¤ÓTABLE¤òÄêµÁ¤¹¤ë¡£ÄêµÁÆâÍƤϥե¡¥¤¥ë̾¤ËÀâÌÀ¤¢¤ê
¡Ú¥Õ¥¡¥¤¥ë¡Û /opt/icewall-sso/certd/config/cert.conf
¡Ú¡¡½ñ¼°¡¡¡Û ¥«¥é¥à=ÃÍ¡¡¢¨¶õÇò¤òÆþ¤ì¤Ê¤¤¤³¤È

IceWallǧ¾Ú¤Ë´Ø¤¹¤ëÀßÄê

¥«¥é¥àÀâÌÀ
DBHOSTOracleSID
DBUID¥í¥°¥¤¥ó¥æ¡¼¥¶¡¼(certdºÆµ¯Æ°¸å¡¢°Å¹æ²½¤µ¤ì¤ë¤Î¤Çʿʸ¤Çµ­ºÜ¤·¤ÆOK)
DBPWD¥Ñ¥¹¥ï¡¼¥É(certdºÆµ¯Æ°¸å¡¢°Å¹æ²½¤µ¤ì¤ë¤Î¤Çʿʸ¤Çµ­ºÜ¤·¤ÆOK)
DBTBL¥Æ¡¼¥Ö¥ë̾¡Ê¥Ç¥Õ¥©¥ë¥È¤Ïicewalltest¡Ë
DBEXATTRÆȼ«¤Ë»ÈÍѤ¹¤ë¥«¥é¥à¤òÄɲ乤ë¾ì¹ç¤Ë,¶èÀÚ¤ê¤Ç¥«¥é¥à̾¤òÍåÎ󤹤ë

¥í¥°¤Ë´Ø¤¹¤ëÀßÄê

¥«¥é¥àÀâÌÀ
ALEVEL¥¢¥¯¥»¥¹¥í¥°¥ì¥Ù¥ë»ØÄê¡Ê¢­Ä㤤 0¡Á4¡¡¢¬¹â¤¤¡Ë
ELEVEL¥¨¥é¡¼¥í¥°¥ì¥Ù¥ë»ØÄê¡Ê¢­Ä㤤 0¡Á4¡¡¢¬¹â¤¤¡Ë
ACCESS¥¢¥¯¥»¥¹¥í¥°¤Î¾ì½ê
ERROR¥¨¥é¡¼¥í¥°¤Î¾ì½ê

¥í¥°¥¤¥ó¥í¥°¥¢¥¦¥È¡¦¥Ñ¥¹¥ï¡¼¥É¥Ý¥ê¥·¡¼¤Ë´Ø¤¹¤ëÀßÄê

¥«¥é¥àÀâÌÀ
COOKIEEXP¼«Æ°¥í¥°¥¢¥¦¥ÈÀßÄê¡Ê1¤ÇÍ­¸ú¡Ë
COOKIETIME¾åµ­¤¬Í­¸ú¤Î¾ì¹ç¤Î´ü¸Â¡Êʬ¡Ë
LOMETHOD¼«Æ°¥í¥°¥¢¥¦¥È¤ÎÍ­¸ú´ü¸Â¤Î¹Í¤¨Êý¡Ê0¤Ç¥í¥°¥¤¥ó¤«¤é¤Î·Ð²á»þ´Ö¡¢1¤ÇºÇ½ª¥¢¥¯¥»¥¹¤«¤é¤Î·Ð²á»þ´Ö¡Ë
DUPLOGINƱ°ìID¤Ç¤Î¿½Å¥í¥°¥¤¥óÀßÄê¡Ê1¤Çµö²Ä¡Ë
PWDMINLEN¿·¤·¤¤¥Ñ¥¹¥ï¡¼¥É¤ÎºÇ½ªÊ¸»ú¿ô
PWDMAXLEN¿·¤·¤¤¥Ñ¥¹¥ï¡¼¥É¤ÎºÇÂçʸ»ú¿ô
PWDSAMEPASSUID¤ÈƱ¤¸¥Ñ¥¹¥ï¡¼¥É¤òǧ¤á¤ë¤«Èݤ«¡Ê1¤ÇÉÔµö²Ä¡Ë
PWDALPHANUM¿·¤·¤¤¥Ñ¥¹¥ï¡¼¥É¤Ç»ÈÍѲÄǽ¤Êʸ»ú¤Î»ÈÍѥݥꥷ¡¼¤òÄêµÁ¡Ê0¡Á13¤Î¥ë¡¼¥ëÈÖ¹æ¤Î¤É¤ì¤«¡Ë
LOCKCOUNT¥Ñ¥¹¥ï¡¼¥É¥¨¥é¡¼¤¬Â³¤¤¤¿¾ì¹ç¤Ë¥í¥Ã¥¯¤µ¤ì¤ë¥¨¥é¡¼²ó¿ô
PWDEXPCHK¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¸å¤ÎÍ­¸ú´ü¸Â¤òÀߤ±¤ë¤«¡Ê1¤ÇÍ­¸ú¡£1²ó¤â¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¤·¤Æ¤Ê¤¤¾ì¹ç¤Ïµ¡Ç½¤·¤Ê¤¤¡Ë
PWDEXPIRE¥Ñ¥¹¥ï¡¼¥ÉÍ­¸ú´ü¸ÂÀÚ¤ì¤Þ¤Ç¤ÎÆü¿ô
PWDEXPWARN¥Ñ¥¹¥ï¡¼¥ÉÍ­¸ú´ü¸ÂÀڤ줬¶á¤Å¤¤¤¿ºÝ¤Ë·Ù¹ð²èÌ̤ò²¿ÆüÁ°¤«¤é½Ð¤¹¤«
PWDHISCHK¥Ñ¥¹¥ï¡¼¥É¤ÎÍúÎò¥Á¥§¥Ã¥¯¡Ê1¤ÇÍ­¸ú¡Ë
PWDHISCNT¥Ñ¥¹¥ï¡¼¥É¤ÎÍúÎòÊÝ»ý·ï¿ô¤ò1¡Á20¤Ç»ØÄê
PWDFORBID¥Ñ¥¹¥ï¡¼¥É¤È¤·¤Æ»ÈÍѤǤ­¤Ê¤¤¥ï¡¼¥É¤Î¥Ç¥£¥¯¥·¥ç¥Ê¥ê¥Õ¥¡¥¤¥ë¤ò»ØÄꤹ¤ë

¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹Ä´À°¤Ë´Ø¤¹¤ëÀßÄê

¥«¥é¥àÀâÌÀ
MAXDBCONNECTDB¤Ø¤ÎƱ»þÀܳ¿ô
MAXREQTHREAD¥ê¥¯¥¨¥¹¥È¥¹¥ì¥Ã¥É¿ô
REQQUESIZE¥ê¥¯¥¨¥¹¥È¥­¥å¡¼¥µ¥¤¥º
MAXREPTHREAD¥ì¥×¥ê¥±¡¼¥·¥ç¥ó¥¹¥ì¥Ã¥É¿ô
REPQUESIZE¥ì¥×¥ê¥±¡¼¥·¥ç¥ó¥­¥å¡¼¥µ¥¤¥º


¥¢¥¯¥»¥¹¥°¥ë¡¼¥×¤ÎÄêµÁ

¥æ¡¼¥¶¡¼¤ÏÆÃÄê¤Î¥°¥ë¡¼¥×¤Ëɬ¤º½ê°¤µ¤»¤ëɬÍפ¬¤¢¤ë
¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹µö²Ä¤Ï¥°¥ë¡¼¥×ñ°Ì¤ÇÀ©¸æ¤¹¤ë
¡Ú¥Õ¥¡¥¤¥ë¡Û /opt/icewall-sso/certd/config/cert.grp
¡Ú¡¡½ñ¼°¡¡¡Û ¥°¥ë¡¼¥×̾,DB¥«¥é¥à̾=ÃÍ
DB¥«¥é¥à̾¤Ïdbattr.confµÚ¤Ó¡¢DBEXATTR¤Ç»ØÄꤷ¤¿¥«¥é¥à¤Î»ØÄ꤬²Äǽ

USERID¤ÎÃͤËuser¤¬ÉÕÍ¿¤·¤Æ¤¤¤ëREMOTE_ADDR¤¬192.168.11.0/24¤Î¥æ¡¼¥¶¡¼¤ònormal¥°¥ë¡¼¥×¤È¤¹¤ë

normal,USERID=user.*&REMOTE_ADDR=192.168.11.1-192.168.11.254

Àµµ¬É½¸½µÚ¤Ó¡¢ÏÀÍý¼° ()¡¡!¡¡&¡¡| ¤Î»ÈÍѤ¬²Äǽ


¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹ÄêµÁ

ÆÃÄê¤Î¥°¥ë¡¼¥×¤ËÂФ·¤Æ¡¢¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤ÎÀܳµö²Ä¤òÄêµÁ¤¹¤ë
¥Ñ¥¿¡¼¥ó¥Þ¥Ã¥Á¥ó¥°¤ÏÁ°Êý°ìÃפǥޥåÁ¤·¤¿¤é¤½¤ì°Ê¹ß¤Î¥ë¡¼¥ë¤Ï»²¾È¤·¤Ê¤¤
¡Ú¥Õ¥¡¥¤¥ë¡Û /opt/icewall-sso/certd/config/cert.acl
¡Ú¡¡½ñ¼°¡¡¡Û http://¥¢¥¯¥»¥¹¤µ¤»¤¿¤¤¥µ¡¼¥Ð¡¼¤Î¥Û¥¹¥È̾[:¥Ý¡¼¥ÈÈÖ¹æ]/=¥°¥ë¡¼¥×̾

normal³î¤Äspecil¤Ë°¤¹¤ë¥æ¡¼¥¶¡¼¤ËÂФ·192.168.11.2¤Ø¤Î¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë

http://192.168.11.2/=normal&special


ǧ¾Ú¥â¥¸¥å¡¼¥ë¤ÎÀ©¸æ

/opt/icewall-sso/certd/bin ¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¤Î¥¹¥¯¥ê¥×¥È¤Ë¤ÆÀ©¸æ¤ò¹Ô¤¦

¥¹¥¯¥ê¥×¥ÈÀâÌÀ
start-certcertd¤Îµ¯Æ°
end-certcertd¤ÎÄä»ß
info-certcertd¤Î²ÔƯ¾õ¶·¤ò½ÐÎÏ
reload-certÀßÄê¥Õ¥¡¥¤¥ëºÆÆɤ߹þ¤ß¡£È¿±Ç¤µ¤ì¤Ê¤¤¹àÌܤ⤢¤ë
¥á¥â¥ê¾å¤Îǧ¾Ú¾ðÊó½ñ¤­´¹¤¨¤¬¹Ô¤ï¤ì¤ë´Ö¡¢¥æ¡¼¥¶¡¼¤«¤é¤Î¥ê¥¯¥¨¥¹¥È¤Ïwait¾õÂ֤ˤʤë
logout-cert¥í¥°¥¤¥óÃæ¤ÎÁ´¥æ¡¼¥¶¡¼¶¯À©¥í¥°¥¢¥¦¥È
cdump-cert¸½ºß²ÔÆ°¤·¤Æ¤¤¤ë¾õÂÖ¤ÎÀßÄêÆâÍƤò½ÐÎÏ

info-cert

cert.conf¤ÎACCESS¤Ç»ØÄꤷ¤¿¥í¥°¡Ê¥Ç¥Õ¥©¥ë¥È¤Ï/opt/icewall-sso/logs/cert.log¡Ë¤Ë¼Â¹Ô»þ¤Î²ÔÆ°¾õ¶·¤òµ­Ï¿¤¹¤ë

¹àÌÜUsedMax%Over
CERTINFO USER¸½ºß¥í¥°¥¤¥ó¤·¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¥í¥°¥¤¥ó²Äǽ¤Ê¥æ¡¼¥¶¡¼¥í¥°¥¤¥ó²Äǽ¥æ¡¼¥¶¡¼¤Î³ä¹ç
CERTINFO CACHE»ÈÍÑ¥­¥ã¥Ã¥·¥å¥µ¥¤¥ººÇÂ祭¥ã¥Ã¥·¥å¥µ¥¤¥º¥­¥ã¥Ã¥·¥å»ÈÍÑΨ
CERTINFO REQUEST_QUEUE»ÈÍÑÃæ¤Î¥ê¥¯¥¨¥¹¥È¥­¥å¡¼¿ô¥ê¥¯¥¨¥¹¥È¥­¥å¡¼¥µ¥¤¥º¥ê¥¯¥¨¥¹¥È¥­¥å¡¼¤ÎÍøÍÑΨ¥­¥å¡¼°î¤ì¿ô(Á°²ó¤Îinfo-cert¤«¤éº£²ó¤Îinfo-cert¤Þ¤Ç¤Î¿ô)
CERTINFO ACCTHRED»ÈÍÑÃæ¤Î¥¢¥¯¥»¥¹¥¹¥ì¥Ã¥É¿ô¥ê¥¯¥¨¥¹¥È¥¹¥ì¥Ã¥É¿ô¥¹¥ì¥Ã¥É»ÈÍÑΨ
CERTINFO REPRICA_QUEUE»ÈÍÑÃæ¤Î¥ì¥×¥ê¥±¡¼¥·¥ç¥ó¿ô¥ì¥×¥ê¥±¡¼¥·¥ç¥ó¥­¥å¡¼¥µ¥¤¥º¥ì¥×¥ê¥±¡¼¥·¥ç¥ó¥­¥å¡¼»ÈÍÑΨ¥­¥å¡¼°î¤ì¿ô
CERTINFO REQUEST_THREAD»ÈÍÑÃæ¤Î¥¹¥ì¥Ã¥É¿ôÁ´ÂÎ¥¹¥ì¥Ã¥É¿ô¥¹¥ì¥Ã¥É»ÈÍÑΨ
CERTINFO REPRICA_THREAD»ÈÍÑÃæ¤Î¥¹¥ì¥Ã¥É¿ôÁ´ÂÎ¥¹¥ì¥Ã¥É¿ô¥¹¥ì¥Ã¥É»ÈÍÑΨ
CERTINFO DBCONNECT»ÈÍÑÃæ¤Î¥³¥Í¥¯¥·¥ç¥ó¿ôÁ´ÂÎ¥³¥Í¥¯¥·¥ç¥ó¿ô¥³¥Í¥¯¥·¥ç¥ó»ÈÍÑΨ


¥Õ¥©¥ï¡¼¥À¤ÎÀßÄê

¡Ú¥Õ¥¡¥¤¥ë¡Û /opt/icewall-sso/dfw/cgi-bin/dfw.conf

ǧ¾Ú¥â¥¸¥å¡¼¥ë(certd)¤Î°ÌÃ֤ȥ¢¥¯¥»¥¹¥Ý¡¼¥È¤Î»ØÄê

CERT=ǧ¾Ú¥â¥¸¥å¡¼¥ë¥Û¥¹¥È:¥Ý¡¼¥ÈÈÖ¹æ

¥Ý¡¼¥ÈÈÖ¹æ¤Ï cert.conf ¤Î PORT ¤ÈƱ¤¸ÈÖ¹æ¤Ë¤¹¤ë¤³¤È

¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Î¥¨¥¤¥ê¥¢¥¹Ì¾¤È°ÌÃÖ»ØÄê

¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¥¢¥¯¥»¥¹¤¹¤ëºÝ¤ÎURL¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤ë

http://forwarder.com/fw/dfw/back01/index.html
¡¡¡¡¡¡ ­¡¡¡¡¡¡¡¡¡¡¡¡¡­¢¡¡¡¡ ­£¡¡¡¡ ­¤

­¡¥Õ¥©¥ï¡¼¥À¤ÎFQDN
­¢¥Õ¥©¥ï¡¼¥À¤Ø¤Î¥Ñ¥¹¡Ê¸ÇÄê¡Ë
­£¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Î¥¨¥¤¥ê¥¢¥¹¡Êdfw.conf¤ÎHOST¤ÇÄêµÁ¤¹¤ë¡Ë
­¤¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Î¾å¤ÎURL

HOST=back01=192.168.11.2¡¡¡Å¡Å192.168.11.2¤Î¥¨¥¤¥ê¥¢¥¹Ì¾¤òback01¤È¤¹¤ë
SHOST=back01=192.168.11.3 ¡Å¡Å192.168.11.3¤Î¥¨¥¤¥ê¥¢¥¹Ì¾¤òback02¤È¤¹¤ë

¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹ÊýË¡¤Î»ØÄê

HOST/SHOST¤ÈÂФò¤Ê¤¹·Á¤Ç¡¢¤½¤ì¤¾¤ì¤Î¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤Î¥¢¥¯¥»¥¹¤¹¤ëºÝ¤Î¾ò·ï¤ò»ØÄꤷ¤¿¡Ö¥Û¥¹¥ÈÀßÄê¡×¥Õ¥¡¥¤¥ë¤ò»ØÄꤹ¤ë
ͽ¤ásample.conf¤¬ÍÑ°Õ¤µ¤ì¤Æ¤ª¤ê¡¢¤³¤ì¤Ï¥×¥ì¡¼¥ó¤Ê¥µ¡¼¥Ð¡¼¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤¿¤á¤Î¾ò·ï¤¬ÄêµÁ¤µ¤ì¤Æ¤¤¤ë

SVRFILE=back01,./sample.conf
SVRFILE=back02,./sample.conf

html.conf

¥í¥°¥¤¥ó²èÌ̤ʤɡ¢¤É¤Î¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ¹¤ë¤«ÄêµÁ¤¹¤ë

¾ðÊó·Ñ¾µµ¡Ç½¡Êǧ¾ÚÂå¹Ô¡Ë

IceWall¤Çǧ¾Ú¤·¤¿ºÝ¤Î¾ðÊó¤òÍѤ¤¤Æ¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤ÎBASICǧ¾Ú¤äFORMǧ¾Ú¤ò¼«Æ°Åª¤Ë¹Ô¤ï¤»¤ëµ¡Ç½
cert.conf ¤Î DBEXATTR ¤ÇÆȼ«¤Î¥«¥é¥à¤òÄêµÁ¤·¡¢¤³¤Î¥«¥é¥à¤ÎÃͤò»È¤Ã¤Æǧ¾Ú¤òÂå¹Ô¤µ¤»¤ë

BASICǧ¾Ú¤ÎÂå¹Ô

¥Û¥¹¥ÈÀßÄê¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·ÊÔ½¸¤¹¤ë

cd /opt/icewall-sso/certd/config
cp -ip sample.conf back01.conf
vi back01.conf
BASICAUTH=1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¡Å¡ÅBASICǧ¾ÚÂå¹Ô¤òÍ­¸ú¤Ë¤¹¤ë
SVRFILE=back01,./back01.conf¡¡¡Å¡Å¥Û¥¹¥ÈÀßÄê¥Õ¥¡¥¤¥ë¤òÊѹ¹¤¹¤ë
BA-UID=<UID>¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡Å¡Åǧ¾Ú¤Ë»È¤¦¥æ¡¼¥¶¡¼Ì¾¤ÎDB¥«¥é¥à̾¤ò»ØÄê¡ÊDEFAULT¤Ë¤¹¤ë¤ÈIceWall¤Îǧ¾Ú¤ÎUID¤ò»ÈÍÑ¡Ë
BA-PWD=<PWD>¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡Å¡Åǧ¾Ú¤Ë»È¤¦¥Ñ¥¹¥ï¡¼¥É¤ÎDB¥«¥é¥à̾¤ò»ØÄê¡ÊDEFAULT¤Ë¤¹¤ë¤ÈIceWall¤Îǧ¾Ú¤Î¥Ñ¥¹¥ï¡¼¥É¤ò»ÈÍÑ¡Ë

FORMǧ¾Ú¤ÎÂå¹Ô

¥Û¥¹¥ÈÀßÄê¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·ÊÔ½¸¤¹¤ë

cd /opt/icewall-sso/certd/config
cp -ip sample.conf back01.conf
vi back01.conf
FORM_FILE=FORM01,./form.conf  ¡Å¡ÅFORM01¤È¤¤¤¦¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾¤òÄêµÁ¤·¡¢¥Õ¥©¡¼¥à¤ÎÀßÄê¥Õ¥¡¥¤¥ë¤Ïform.conf¤È¤¹¤ë

¥Õ¥©¡¼¥àÀßÄê¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤¹¤ë

vi form.conf

¡Ú¡¡½ñ¼°¡¡¡Û ¹àÌÜ=¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾,ÀßÄêÃÍ

¹àÌÜÀâÌÀ
FORM_URL¥Õ¥©¡¼¥àǧ¾Ú¤¬¹Ô¤ï¤ì¤ë²ÄǽÀ­¤Î¤¢¤ëURL¤ò»ØÄê¡£/¤ÇÁ´ÂÎ
/secure/¤Ç/secure¥Ç¥£¥ì¥¯¥È¥ê°Ê²¼¡£form.html¤Î¤è¤¦¤ËÆÃÄê¥Õ¥¡¥¤¥ë¤Î»ØÄê
FORM_KEYFORMǧ¾Ú¤Èǧ¼±¤¹¤ë¥­¡¼¥ï¡¼¥É¤Î»ØÄꡣʣ¿ô»ØÄꤷ¤¿¾ì¹ç¤ÏAND¾ò·ï¤Ë¤Ê¤ë
FORM_METHODformǧ¾Ú¤Î¥á¥½¥Ã¥É¤ò»ØÄê¡£<form>¥¿¥°¤Îmethod°À­¤ÎÃͤòµ­½Ò
FORM_SEND¥ê¥¯¥¨¥¹¥ÈÀè¤ÎURL¡£<form>¥¿¥°¤Îaction°À­¤ÎÃͤòµ­½Ò
FORM_DATA_STRFORM¤ËÆþÎϤ¹¤ë¸ÇÄêÃͤòÄêµÁ
FORM_DATA_USRFORM¤ËÆþÎϤ¹¤ëÃͤò¾ðÊó·Ñ¾µ¤Ê¤É¤«¤éÆÀ¤é¤ì¤ë²ÄÊÑÃͤòÄêµÁ

¡Ú¡¡½ñ¼°¡¡¡Û FORM_DATA_STR=¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾,¥á¥½¥Ã¥É,name°À­,¸ÇÄêÃÍ

FORM_DATA_STR=FORM01,POSTDATA,id,user01
FORM_DATA_STR=FORM01,POSTDATA,pwd,pass01
¢¨¥á¥½¥Ã¥É¤ÏGET¤ÏQUERY_STRING¡¢POST¤ÏPOSTDATA

¡Ú¡¡½ñ¼°¡¡¡Û FORM_DATA_STR=¥Õ¥©¡¼¥à¥°¥ë¡¼¥×̾,¥á¥½¥Ã¥É,name°À­,DB¥«¥é¥à̾

FORM_DATA_USR=FORM01,POSTDATA,id,EXTRAUID
FORM_DATA_USR=FORM01,POSTDATA,pwd,EXTRAPWD
¢¨DB¥«¥é¥à¤Ïcert.conf¤ÎDBEXATTR¤ÇÄêµÁ¤·¤¿¥«¥é¥à¤ò»ØÄꤹ¤ë


¥Õ¥©¥ï¡¼¥À¤Î¥¢¥¯¥»¥¹¥í¥°¡Êdfw.log¡Ë

dfw.conf¤ÎACCESS¤Ç»ØÄꤷ¤¿¾ì½ê¡Ê¥Ç¥Õ¥©¥ë¥È¤Ï/opt/icewall-sso/logs/dfw.log¡Ë¤Ë½ÐÎϤµ¤ì¤ë

¡Ú½ÐÎÏÎã¡Û[2012/03/12 09:21:16]  0.024  0.117  0.000 user1 POST [web.test.com:443/sdrive/download.php] 56 192.168.11.10 TID=TID201¡Á
¹àÌÜÀâÌÀ
[2012/03/12¡ÁÆü»þ
0.024­¡¥Õ¥©¥ï¡¼¥Àµ¯Æ°¤«¤é¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼Àܳ¤Þ¤Ç¤Î·Ð²á»þ´Ö¡ÊÉáË
0.117­¢¥Ð¥Ã¥¯¥¨¥ó¥ÉÀܳ¤«¤éÀÚÃǤ¹¤ë¤Þ¤Ç¤Î·Ð²á»þ´Ö¡ÊÉáË
0.000­£¥Ð¥Ã¥¯¥¨¥ó¥É¤«¤é¥³¥ó¥Æ¥ó¥Ä¤ò¼õ¤±¼è¤Ã¤Æ¤«¤é¥¯¥é¥¤¥¢¥ó¥È¤Ë½ÐÎϤ¹¤ë¤Þ¤Ç¤Î»þ´Ö¡ÊÉáË
user1¥ê¥¯¥¨¥¹¥È¤·¤¿¥æ¡¼¥¶¡¼ID
POST¥ê¥¯¥¨¥¹¥È¤µ¤ì¤¿HTTP¥á¥½¥Ã¥É
[web.test¡Á¥ê¥¯¥¨¥¹¥È¤µ¤ì¤¿URL¡ÊALEVEL2°Ê¾å¤Ç½ÐÎÏ¡Ë
56¥³¥ó¥Æ¥ó¥Ä¥µ¥¤¥º(byte)¡ÊALEVEL2°Ê¾å¤Ç½ÐÎÏ¡Ë
192.168.11.10¥¯¥é¥¤¥¢¥ó¥È¤ÎIP¥¢¥É¥ì¥¹¡ÊALEVEL2°Ê¾å¤Ç½ÐÎÏ¡Ë
TID=¡Á¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¡Ê¥³¥ó¥Õ¥£¥°¤ÇÍ­¸ú¤Ë¤¹¤ë¤³¤È¤Ç½ÐÎÏ¡Ë

·Ð²á»þ´Ö¤Ë¤Ä¤¤¤Æ

icewall_transaction.png
­¡¥Õ¥©¥ï¡¼¥À¤¬µ¯Æ°¸å¡¢¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤Ø¤ÎTCP/IPÀܳ¤¬³ÎΩ¤µ¤ì¤ë¤Þ¤Ç¤Î·Ð²á»þ´Ö
­¢HTTP¤Ë¤è¤ë¥³¥ó¥Æ¥ó¥ÄžÁ÷»þ´Ö
­£TCP/IPÀܳ¤¬ÀÚÃǤ·¡¢¥¯¥é¥¤¥¢¥ó¥È¤È¤ÎÄÌ¿®¤ò³«»Ï¤¹¤ë¤Þ¤Ç¤Î»þ´Ö
¡¡URL¡¦¥­¡¼¥ï¡¼¥ÉÊÑ´¹¤Ë³Ý¤«¤Ã¤¿»þ´Ö¤Ç¥¯¥é¥¤¥¢¥ó¥È¤Ø¤Î¥³¥ó¥Æ¥ó¥ÄžÁ÷»þ´Ö¤Ç¤Ï¤Ê¤¤

¥È¥é¥ó¥¶¥¯¥·¥ç¥óID

¥Õ¥©¥ï¡¼¥À¤Ë¤è¤ê¸Ä¡¹¤Î¥ê¥¯¥¨¥¹¥È¤ò¸ÄÊ̤˳ä¤ê¿¶¤é¤ì¤¿TID¤Ç¥í¥°¤Ëµ­Ï¿¤¹¤ë
TID¤Ïǧ¾Ú¥â¥¸¥å¡¼¥ë¦¤Ç¤âƱ¤¸Ãͤǵ­Ï¿¤µ¤ì¤ë°Ù¡¢¥í¥°¤ÎÆ͹礻¤¬²Äǽ¤Ë¤Ê¤ë

dfw.conf
TRANSID=1    ¥È¥é¥ó¥¶¥¯¥·¥ç¥óID½ÐÎϤòÍ­¸ú¤Ë¤¹¤ë
TRANSID_STR¡¡¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¤Î¸å¤ËǤ°Õ¤Îʸ»úÎó¤òÄɵ­¤¹¤ë¡Ê¥Õ¥©¥ï¡¼¥ÀËè¤Ë°Û¤Ê¤ëʸ»úÎó¤òÆþ¤ì¤ë¤³¤È¤Ç¥µ¡¼¥Ð¡¼ÀÚ¤êʬ¤±¤¬°Â°×¤Ë¤Ê¤ë¡Ë
cert.conf
TRANSID=1¡¡¡¡Ç§¾Ú¥â¥¸¥å¡¼¥ë¥í¥°¤Ø¤Î¥È¥é¥ó¥¶¥¯¥·¥ç¥óID½ÐÎϤòÍ­¸ú¤Ë¤¹¤ë


ǧ¾Ú¥â¥¸¥å¡¼¥ë¤Î¥¢¥¯¥»¥¹¥í¥°¡Êcert.log¡Ë

cert.conf¤ÎACCESS¤Ç»ØÄꤷ¤¿¾ì½ê¡Ê¥Ç¥Õ¥©¥ë¥È¤Ï/opt/icewall-sso/logs/dfw.log¡Ë¤Ë½ÐÎϤµ¤ì¤ë

¡Ú½ÐÎÏÎã¡Û[2012/03/12 09:21:05] User Login. TID=TID201¡Á UserID=user1 [AC10124-25065]
¹àÌÜÀâÌÀ
[2012/03/12¡ÁÆü»þ
User Logout¥í¥°¥á¥Ã¥»¡¼¥¸
TID=¡Á¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¡Ê¥³¥ó¥Õ¥£¥°¤ÇÍ­¸ú¤Ë¤¹¤ë¤³¤È¤Ç½ÐÎÏ¡Ë
UserUD=¥æ¡¼¥¶¡¼ID
[AC10124¥á¥Ã¥»¡¼¥¸ID

ǧ¾ÚDB¥¢¥¯¥»¥¹»þ´Ö¤Îµ­Ï¿

ALEVEL¤Ë1°Ê¾å³î¤Ä¡¢LOGPERF=1¤ËÀßÄꤷ¤¿¾ì¹ç¡¢Ç§¾ÚDB¤Ø¤Î¥¢¥¯¥»¥¹»þ´Ö¤¬µ­Ï¿¤µ¤ì¤ë

¡Ú½ÐÎÏÎã2¡Û[2012/03/12 09:21:05] PERF 1104244 LOGINUID user1 0.007303 S:0.024 U:0.014 TID=20121¡Á [AC28201-29999]
¹àÌÜÀâÌÀ
[2012/03/12¡ÁÆü»þ
PERFPERF¸ÇÄê
1104244¥¹¥ì¥Ã¥ÉID¡ÊÆâÉô½èÍý¤Î¥ê¥¯¥¨¥¹¥È¥¹¥ì¥Ã¥ÉID¡Ë
LOGINUID¥ê¥¯¥¨¥¹¥È¼ïÊ̡ʲ¼µ­»²¾È¡Ë
UserUD=¥æ¡¼¥¶¡¼ID
0.007303¥ê¥¯¥¨¥¹¥È½èÍý»þ´Ö
S:¡ÁU:DB½èÍý»þ´Ö¡£S:Select¡¢U:Update¡¢I:Insert¡¢B:bind½èÍý
TID=¡Á¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¡Ê¥³¥ó¥Õ¥£¥°¤ÇÍ­¸ú¤Ë¤¹¤ë¤³¤È¤Ç½ÐÎÏ¡Ë
[AC10124¥á¥Ã¥»¡¼¥¸ID
¥ê¥¯¥¨¥¹¥È¼ïÊÌÀâÌÀ
LOGINUID¥æ¡¼¥¶¡¼ID¤Î¥í¥°¥¤¥ó
FLOGINUID¶¯À©¥æ¡¼¥¶ID¤Î¥í¥°¥¤¥ó
LOGINCERT¾ÚÌÀ½ñ¥í¥°¥¤¥ó
LOGINSAMLSAML¥í¥°¥¤¥ó
FLOGINSAML¶¯À©SAML¥í¥°¥¤¥ó
LOGINFEDE¥Õ¥§¥Ç¥ì¡¼¥·¥ç¥ó¥í¥°¥¤¥ó
FLOGINFEDE¶¯À©¥§¥Ç¥ì¡¼¥·¥ç¥ó¥í¥°¥¤¥ó
ACCESSUID¥æ¡¼¥¶¡¼ID¤Î¥¢¥¯¥»¥¹À©¸æ
ACCESSCERT¾ÚÌÀ½ñ¥µ¥¯¥»¥¹À©¸æ
PWDCHG¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹
LOGOUT¥í¥°¥¢¥¦¥È
AUTOLOGOUT¼«Æ°¥í¥°¥¢¥¦¥È

¥È¥Ã¥×   ÊÔ½¸ Åà·ë²ò½ü º¹Ê¬ źÉÕ Ê£À½ ̾Á°Êѹ¹ ¥ê¥í¡¼¥É   ¿·µ¬ °ìÍ÷ ñ¸ì¸¡º÷ ºÇ½ª¹¹¿·   ¥Ø¥ë¥×   ºÇ½ª¹¹¿·¤ÎRSS
Last-modified: 2012-03-12 (·î) 19:19:33 (4422d)