މައި ކޮންޓެންޓަށް ދާ

ސިންގަލް ސައިން-އޮން އަދި ޕްރޮވިޝަނިންގް

OpenID Connect ނުވަތަ SAML، SCIM ޕްރޮވިޝަނިންގް އަދި LDAP އިން ސިންގަލް ސައިން-އޮން.

Markdown ގޮތަށް ބަލާ

މީހުންނަށް ކުރިންވެސް ހުރި އެކައުންޓަކުން ޤުއަރޭއަށް ސައިންއިން ކުރުވާށެވެ، އަދި ޤުއަރޭގެ ޔޫޒަރުންގެ ލިސްޓް ތިބާގެ ޑައިރެކްޓަރީއާ އެއްގޮތް ބެހެއްޓާށެވެ.

The Sign-in and security page, where single sign-on is switched on under sign-in methods.
Switch on single sign-on under Sign-in methods, then add your identity provider.

/admin/security/auth ހުޅުވައި، އިޑެންޓިޓީ ޕްރޮވައިޑަރުން އަދި ޑައިރެކްޓަރީތައް ގައި ކަނެކްޝަނެއް އިތުރުކުރާށެވެ. ކޮންމެ ކަނެކްޝަނެއްގައި ތިބާގެ identity provider އަށް ބޭނުންވާ އެޑްރެސްތައް ފެންނާނެއެވެ.

OpenID Connect

Microsoft Entra ID، Google Workspace، Okta، Auth0، Keycloak އަދި ކޮންމެ ސްޓޭންޑަރޑް އެއްގޮތް ޕްރޮވައިޑަރެއްގައި ހިންގާނެއެވެ.

  1. އިޑެންޓިޓީ ޕްރޮވައިޑަރގައި web application އެއް ހަދާށެވެ. އޭގެ redirect address އަކީ ޤުއަރޭ ކަނެކްޝަނަށް ދޭ callback address ސެޓްކުރާށެވެ: https://<organisation>.quirelms.com/api/auth/sso/callback/<connection>.
  2. ޤުއަރޭގައި Add OpenID Connect ހޮވައި ޕްރޮވައިޑަރގެ discovery address (/.well-known/openid-configuration އިން ނިމޭ)، client ID އަދި client secret ލާށެވެ. Secret ސީލް ކޮށް ސްޓޯރކޮށް، އަނބުރާ ދައްކާނީ އޭގެ ފަހު ހަތަރު އަކުރުތައް އެކަނި.
  3. ކަނެކްޝަން ހިދާ އީމެއިލް ޑޮމެއިންތައް ހޮވާށެވެ. އެ ޑޮމެއިންގެ އެޑްރެހެއްން ސައިންއިންވާނީ ތިބާގެ ޕްރޮވައިޑަރަށެވެ.

ވެންޑަރ ނޯޓު

  • Microsoft Entra ID: ޓެނަންޓްގެ އަމިއްލަ discovery address ބޭނުންކުރާށެވެ (https://login.microsoftonline.com/<directory id>/v2.0/.well-known/openid-configuration)، common ނޫނެވެ. ޤުއަރޭ މީހުން ސައިންއިން ކުރަނީ email claim އަކުންނެވެ؛ Entra އީމެއިލް އެޑްރެސެއް ހުރި އެކައުންޓަކަށް އެ claim ފޮނުވާއެވެ. ގްރޫޕްތައް ދައުރަށް މެޕްކުރަން ID token އަށް groups claim އިތުރުކޮށް، group object ID ތައް މެޕްކުރާށެވެ. 200 ގްރޫޕަށް ވުރެ ގިނަވިއްޔާ Entra ލިސްޓްގެ ބަދަލުގައި pointer ފޮނުވާތީ ޤުއަރޭ group role ދޭނެއް ނޫނެވެ؛ އެޕްލިކޭޝަން ހާއްސަ ގްރޫޕްތަކަށް assign ކުރާށެވެ، ނުވަތަ app role ބޭނުންކުރާށެވެ.
  • Okta: https://<your-domain>/.well-known/openid-configuration (ނުވަތަ custom authorization server އަށް /oauth2/<server> address) ބޭނުންކޮށް، groups scope އަދި groups claim އިތުރުކޮށް group name ތައް mapping ކުރާށެވެ. ސައިންއިން ޕޭޖުގެ Okta preset (social sign-in ގައި) އަށް Okta domain މިސާލަކަށް acme.okta.com، client ID އަދި secret އެކަނި ލާށެވެ.
  • Google Workspace: https://accounts.google.com/.well-known/openid-configuration ބޭނުންކޮށް ތިބާގެ domain ކަނެކްޝަނަށް ލާށެވެ؛ އެހެން domain އެއްގެ account އަކުން ސައިންއިން ނުވާނެއެވެ.

SAML 2.0

SAML ސިންގަލް ސައިން-އޮން ލިބެނީ Business ޕްލޭން އަދި މަތީގައި (plan and billing ބަލާށެވެ). އޭގެ ޕްލޭނެއް ނެތްނަމަ ކަނެކްޝަނެއް އިތުރުނުކުރެވޭނެއެވެ. ޕްލޭނުން ފަހުން އެއީ ގެއްލިއްޔާ ކުރިންހުރި ކަނެކްޝަން ކިޔެވޭނެއެވެ، އެކަމަކު ސައިން-އިން މެތަޑްތަކުން ބޭރުކުރެވެއެވެ؛ ޑައުންގްރޭޑްގެ ކުރިން އެހެން ފަހަތެއް ކޮންފިގަރކުރާށެވެ.

  1. ޤުއަރޭގައި Add SAML 2.0 ހޮވާށެވެ. އިޑެންޓިޓީ ޕްރޮވައިޑަރަށް ޤުއަރޭގެ ޑިޓެއިލް ދޭށެވެ:

    • Metadata: https://<organisation>.quirelms.com/api/auth/sso/saml2/sp/metadata
    • Assertion consumer service (ACS): https://<organisation>.quirelms.com/api/auth/sso/saml2/sp/acs/<connection>
  2. އިޑެންޓިޓީ ޕްރޮވައިޑަރުން އޭގެ metadata address ޤުއަރޭއަށް ދީ، ނުވަތަ metadata XML ޕޭސްޓްކޮށް، ނުވަތަ ސައިން-އިން އެޑްރެސް އަދި ސޮއި ސަރޓިފިކެޓް ލިޔާށެވެ.

  3. އީމެއިލް އެޑްރެސް name ID ގޮތުގައި، given name އަދި family name attributes ގޮތުގައި ފޮނުވާށެވެ.

    Microsoft Entra ID އީމެއިލް ފޮނުވަނީ http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress، ނަން http://schemas.microsoft.com/identity/claims/displayname އަދި ގްރޫޕް http://schemas.microsoft.com/ws/2008/06/identity/claims/groups ގެ ތެރޭގައެވެ؛ attribute mapping ގައި އެ ނަންތައް ލާށެވެ. Okta އިން ތިބާ define ކުރި attribute statement ފޮނުވާއެވެ؛ email، displayName އަދި groups group attribute statement ބޭނުންކުރާށެވެ. ޤުއަރޭ އީމެއިލް ކިޔަނީ attribute އިންނެވެ، އެހެންވެ ކޮންމެ name ID format އެއްވެސް ހިންގާނެއެވެ.

ޓެސްޓްކުރުން

ހުރިހާމީހުނަށް ބުނުމުގެ ކުރިން private browser window އަކުން test account އެއްއަކުން sign in ކޮށްލާށެވެ. ކޮންފިގަރޭޝަން ތަފާތުވެ ހުރިހާމީހުންވެސް ބްލޮކް ނުވާން ސިންގަލް ސައިން-އޮން ތައިދީވާންދެން ޕާސްވޯޑަކުން ސައިންއިންވާ އެކްސެސް ހުރި އެޑްމިނެއް ބެހެއްޓާށެވެ.

SCIM އިން ޕްރޮވިޝަންކުރުން

SCIM 2.0 އިން ތިބާގެ ޑައިރެކްޓަރީއަކު ޤުއަރޭ ޔޫޒަރުން ހަދާ، އަޕްޑޭޓް، ސަސްޕެންޑްކޮށް، ގްރޫޕް މެމްބަރޝިޕް އިދާރާ ކުރެއެވެ؛ ސްޕްރެޑްޝީޓެއް އަޕްލޯޑް ނުކުރަންވެސް.

  1. /admin/security/auth ގައި User provisioning (SCIM) ދަށުން token އެއް ހަދާށެވެ. އެއީ ފަހަރަކު އެކަނި ފެންނާނެއެވެ.
  2. އިޑެންޓިޓީ ޕްރޮވައިޑަރގެ provisioning settings ގައި SCIM base address https://<organisation>.quirelms.com/scim/v2 އަދި bearer token ގޮތުގައި token ލާށެވެ.
  3. ޔޫޒަރުން އަދި ގްރޫޕުތައް application އަށް assign ކުރާށެވެ.

ޑައިރެކްޓަރީއިން މީހެއް ފޮހުމުން ޤުއަރޭއިން އޭނާ ސަސްޕެންޑް ކުރެވެއެވެ، ޑިލީޓް ނުކުރެވޭނެއެވެ؛ އޭނާގެ ގްރޭޑުތައް އަދި ސަރޓިފިކެޓްތައް ބެހެއްޓެވެ. SCIM ހެދި ކޮންމެ ބަދަލެއްވެސް token ގެ ނަމުގައި audit log ގައިވެއެވެ.

LDAP

SAML ނުވަތަ OpenID Connect ނެތް on-premises directory އަށް ސާރވަރ އެޑްރެސް، bind account އަދި ޔޫޒަރުން ހޯދޭ base އާއެކު LDAP directory connection އެއް އިތުރުކުރާށެވެ. މީހުން އެތަނުގެ ޑައިރެކްޓަރީ ޕާސްވޯޑުން ސައިންއިން ކުރެއެވެ؛ ޤުއަރޭ އެއީ ޑައިރެކްޓަރީއާއި ޗެކްކޮށް ކޮންމެއްވެސް ސްޓޯރ ނުކުރެއެވެ.

ނެވިގޭޝަން

ހޯދުމަށް ލިޔޭ…

↑↓ ބަދަލުކުރޭ↵ ނަންގާEsc ބަންދުކުރޭ