<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>服务器安全维护工作室 &#187; 网站迁移</title>
	<atom:link href="https://www.fuwuqiok.com/tag/%e7%bd%91%e7%ab%99%e8%bf%81%e7%a7%bb/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.fuwuqiok.com</link>
	<description></description>
	<lastBuildDate>Sun, 01 Mar 2020 07:28:40 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.2.26</generator>
	<item>
		<title>教程：Azure Active Directory 与 Amazon Web Services (AWS) 集成</title>
		<link>https://www.fuwuqiok.com/%e6%95%99%e7%a8%8b%ef%bc%9aazure-active-directory-%e4%b8%8e-amazon-web-services-aws-%e9%9b%86%e6%88%90/</link>
		<comments>https://www.fuwuqiok.com/%e6%95%99%e7%a8%8b%ef%bc%9aazure-active-directory-%e4%b8%8e-amazon-web-services-aws-%e9%9b%86%e6%88%90/#comments</comments>
		<pubDate>Wed, 06 Dec 2017 03:09:26 +0000</pubDate>
		<dc:creator><![CDATA[admin]]></dc:creator>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[服务器代维]]></category>
		<category><![CDATA[服务器代维合同]]></category>
		<category><![CDATA[上云迁移解决方案]]></category>
		<category><![CDATA[云服务器迁移]]></category>
		<category><![CDATA[云迁移]]></category>
		<category><![CDATA[教程：Azure Active Directory 与 Amazon Web Services (AWS) 集成]]></category>
		<category><![CDATA[数据中心迁移]]></category>
		<category><![CDATA[网站迁移]]></category>
		<category><![CDATA[阿里云服务器迁移]]></category>

		<guid isPermaLink="false">https://www.fuwuqiok.com/?p=3414</guid>
		<description><![CDATA[<p>将 Amazon Web Services (AWS) 与 Azure AD 集成提供以下优势： 可以在 Az [&#8230;]</p>
<p><a rel="nofollow" href="https://www.fuwuqiok.com/%e6%95%99%e7%a8%8b%ef%bc%9aazure-active-directory-%e4%b8%8e-amazon-web-services-aws-%e9%9b%86%e6%88%90/">教程：Azure Active Directory 与 Amazon Web Services (AWS) 集成</a>，首发于<a rel="nofollow" href="https://www.fuwuqiok.com">服务器安全维护工作室</a>。</p>
]]></description>
				<content:encoded><![CDATA[<p><span data-ttu-id="6f925-105">将 Amazon Web Services (AWS) 与 Azure AD 集成提供以下优势：</span></p>
<ul>
<li><span data-ttu-id="6f925-106">可以在 Azure AD 中控制谁有权访问 Amazon Web Services (AWS)</span></li>
<li><span data-ttu-id="6f925-107">可以让用户使用其 Azure AD 帐户自动登录到 Amazon Web Services (AWS)（单一登录）</span></li>
<li><span data-ttu-id="6f925-108">可以在一个中心位置（即 Azure 门户）中管理帐户</span></li>
</ul>
<p><span data-ttu-id="6f925-109">如果要了解有关 SaaS 应用与 Azure AD 集成的更多详细信息，请参阅 <a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-appssoaccess-whatis" data-linktype="relative-path">Azure Active Directory 的应用程序访问与单一登录是什么</a>。</span></p>
<h2 id="prerequisites"><span data-ttu-id="6f925-110">先决条件</span></h2>
<p><span data-ttu-id="6f925-111">若要配置 Azure AD 与 Amazon Web Services (AWS) 的集成，需要具有以下项：</span></p>
<ul>
<li><span data-ttu-id="6f925-112">一个 Azure AD 订阅</span></li>
<li><span data-ttu-id="6f925-113">启用了 Amazon Web Services (AWS) 单一登录的订阅</span></li>
</ul>
<div class="NOTE alert">
<p>备注</p>
<p><span data-ttu-id="6f925-114">不建议使用生产环境测试本教程中的步骤。</span></p>
</div>
<p><span data-ttu-id="6f925-115">测试本教程中的步骤应遵循以下建议：</span></p>
<ul>
<li><span data-ttu-id="6f925-116">不应使用生产环境，除非有此必要。</span></li>
<li><span data-ttu-id="6f925-117">如果没有 Azure AD 试用环境，可以在<a href="https://azure.microsoft.com/pricing/free-trial/" data-linktype="external">此处</a>获取一个月的试用版。</span></li>
</ul>
<h2 id="scenario-description"><span data-ttu-id="6f925-118">方案描述</span></h2>
<p><span data-ttu-id="6f925-119">在本教程中，将在测试环境中测试 Azure AD 单一登录。</span> <span data-ttu-id="6f925-120">本教程中概述的方案包括两个主要构建基块：</span></p>
<ol>
<li><span data-ttu-id="6f925-121">从库中添加 Amazon Web Services (AWS)</span></li>
<li><span data-ttu-id="6f925-122">配置和测试 Azure AD 单一登录</span></li>
</ol>
<h2 id="adding-amazon-web-services-aws-from-the-gallery"><span data-ttu-id="6f925-123">从库中添加 Amazon Web Services (AWS)</span></h2>
<p><span data-ttu-id="6f925-124">要配置 Amazon Web Services (AWS) 与 Azure AD 的集成，需要从库将 Amazon Web Services (AWS) 添加到托管 SaaS 应用列表。</span></p>
<p><span data-ttu-id="6f925-125"><strong>若要从库中添加 Amazon Web Services (AWS)，请执行以下步骤：</strong></span></p>
<ol>
<li><span data-ttu-id="6f925-126">在 <strong><a href="https://portal.azure.com/" data-linktype="external">Azure 门户</a></strong>的左侧导航面板中，单击“Azure Active Directory”图标。</span>
<p><img src="https://docs.microsoft.com/zh-cn/azure/active-directory/media/active-directory-saas-amazon-web-service-tutorial/tutorial_general_01.png" alt="" /></li>
<li><span data-ttu-id="6f925-128">导航到“企业应用程序”。</span> <span data-ttu-id="6f925-129">然后转到“所有应用程序”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_02.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_02.png" alt="tutorial_general_02" width="516" height="510" /></a></li>
<li><span data-ttu-id="6f925-131">单击对话框顶部的“添加”按钮。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_03.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_03.png" alt="tutorial_general_03" width="212" height="31" /></a></li>
<li><span data-ttu-id="6f925-133">在搜索框中，键入 <strong>Amazon Web Services (AWS)</strong>。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_search.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_search.png" alt="tutorial_amazonwebservices_search" width="509" height="87" /></a></li>
<li><span data-ttu-id="6f925-135">在结果窗格中，选择“Amazon Web Services (AWS)”，并单击“添加”以添加该应用程序。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_addfromgallery.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_addfromgallery.png" alt="tutorial_amazonwebservices_addfromgallery" width="477" height="74" /></a></li>
</ol>
<h2 id="configuring-and-testing-azure-ad-single-sign-on"><span data-ttu-id="6f925-137">配置和测试 Azure AD 单一登录</span></h2>
<p><span data-ttu-id="6f925-138">在本部分中，将基于名为“Britta Simon”的测试用户配置并测试 Amazon Web Services (AWS) 的 Azure AD 单一登录。</span></p>
<p><span data-ttu-id="6f925-139">若要运行单一登录，Azure AD 需要知道与 Azure AD 用户相对应的 Amazon Web Services (AWS) 用户。</span> <span data-ttu-id="6f925-140">换句话说，需在 Azure AD 用户与 Amazon Web Services (AWS) 中的相关用户间建立链接关系。</span></p>
<p><span data-ttu-id="6f925-141">可以通过将 Azure AD 中的“用户名”值分配为 Amazon Web Services (AWS) 中“用户名”的值来建立此链接关系。</span></p>
<p><span data-ttu-id="6f925-142">若要配置并测试 Amazon Web Services (AWS) 的 Azure AD 单一登录，需要完成以下构建基块：</span></p>
<ol>
<li><span data-ttu-id="6f925-143"><strong><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-saas-amazon-web-service-tutorial#configuring-azure-ad-single-sign-on" data-linktype="self-bookmark">配置 Azure AD 单一登录</a></strong> &#8211; 让用户使用此功能。</span></li>
<li><span data-ttu-id="6f925-144"><strong><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-saas-amazon-web-service-tutorial#creating-an-azure-ad-test-user" data-linktype="self-bookmark">创建 Azure AD 测试用户</a></strong> &#8211; 使用 Britta Simon 测试 Azure AD 单一登录。</span></li>
<li><span data-ttu-id="6f925-145"><strong><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-saas-amazon-web-service-tutorial#creating-an-amazon-web-services-test-user" data-linktype="self-bookmark">创建 Amazon Web Services 测试用户</a></strong> &#8211; 在 Amazon Web Services (AWS) 中创建 Britta Simon 的对应用户，并将其链接到该用户的 Azure AD 表示形式。</span></li>
<li><span data-ttu-id="6f925-146"><strong><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-saas-amazon-web-service-tutorial#assigning-the-azure-ad-test-user" data-linktype="self-bookmark">分配 Azure AD 测试用户</a></strong> &#8211; 让 Britta Simon 使用 Azure AD 单一登录。</span></li>
<li><span data-ttu-id="6f925-147"><strong><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-saas-amazon-web-service-tutorial#testing-single-sign-on" data-linktype="self-bookmark">测试单一登录</a></strong> &#8211; 验证配置是否正常工作。</span></li>
</ol>
<h3 id="configuring-azure-ad-single-sign-on"><span data-ttu-id="6f925-148">配置 Azure AD 单一登录</span></h3>
<p><span data-ttu-id="6f925-149">在本部分中，会在 Azure 门户中启用 Azure AD 单一登录并在 Amazon Web Services (AWS) 应用程序中配置单一登录。</span></p>
<p><span data-ttu-id="6f925-150"><strong>若要配置 Amazon Web Services (AWS) 的 Azure AD 单一登录，请执行以下步骤：</strong></span></p>
<ol>
<li><span data-ttu-id="6f925-151">在 Azure 门户中，在 <strong>Amazon Web Services (AWS)</strong> 应用程序集成页上，单击“单一登录”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_04.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_04.png" alt="tutorial_general_04" width="164" height="283" /></a></li>
<li><span data-ttu-id="6f925-153">在“单一登录”对话框中，选择“基于 SAML 的登录”作为“模式”以启用单一登录。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_samlbase.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_samlbase.png" alt="tutorial_amazonwebservices_samlbase" width="538" height="176" /></a></li>
<li><span data-ttu-id="6f925-155">在“Amazon Web Services (AWS) 域和 URL”部分中，用户不必执行任何步骤，因为该应用已经与 Azure 预先集成。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_url.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_url.png" alt="tutorial_amazonwebservices_url" width="557" height="84" /></a></li>
<li><span data-ttu-id="6f925-157">在“SAML 签名证书”部分中，单击“元数据 XML”，并在计算机上保存 XML 文件。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_certificate.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_certificate.png" alt="tutorial_amazonwebservices_certificate" width="977" height="164" /></a></li>
<li><span data-ttu-id="6f925-159">Amazon Web Services (AWS) Software 应用程序需要采用特定格式的 SAML 断言。</span> <span data-ttu-id="6f925-160">请为此应用程序配置以下声明。</span> <span data-ttu-id="6f925-161">可以在应用程序集成页的“用户属性”部分管理这些属性的值。</span> <span data-ttu-id="6f925-162">以下屏幕截图显示一个示例。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_attribute.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_attribute.png" alt="tutorial_amazonwebservices_attribute" width="720" height="435" /></a></li>
<li><span data-ttu-id="6f925-164">在“单一登录”对话框的“用户属性”部分中，按上图所示配置 SAML 令牌属性，并执行以下步骤：</span><br />
<table>
<thead>
<tr>
<th><span data-ttu-id="6f925-165">属性名称</span></th>
<th><span data-ttu-id="6f925-166">属性值</span></th>
<th><span data-ttu-id="6f925-167">命名空间</span></th>
</tr>
</thead>
<tbody>
<tr>
<td><span data-ttu-id="6f925-168">RoleSessionName</span></td>
<td><span data-ttu-id="6f925-169">user.userprincipalname</span></td>
<td><span data-ttu-id="6f925-170"><a href="https://aws.amazon.com/SAML/Attributes" data-linktype="external">https://aws.amazon.com/SAML/Attributes</a></span></td>
</tr>
<tr>
<td><span data-ttu-id="6f925-171">角色</span></td>
<td><span data-ttu-id="6f925-172">user.assignedroles</span></td>
<td><span data-ttu-id="6f925-173"><a href="https://aws.amazon.com/SAML/Attributes" data-linktype="external">https://aws.amazon.com/SAML/Attributes</a></span></td>
</tr>
</tbody>
</table>
<div class="TIP alert">
<p>提示</p>
<p><span data-ttu-id="6f925-174">需要在 Azure AD 中配置用户预配以从 AWS 控制台中提取所有角色。</span> <span data-ttu-id="6f925-175">请参阅下文中的预配步骤。</span></p>
</div>
<p><span data-ttu-id="6f925-176">a.</span> <span data-ttu-id="6f925-177">单击“添加属性”，打开“添加属性”对话框。</span></p>
<p><img src="https://docs.microsoft.com/zh-cn/azure/active-directory/media/active-directory-saas-amazon-web-service-tutorial/tutorial_attribute_04.png" alt="" /></p>
<p><span data-ttu-id="6f925-179">b.保留“数据库类型”设置，即设置为“共享”。</span> <span data-ttu-id="6f925-180">在“名称”文本框中，键入为该行显示的属性名称。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_attribute_05.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_attribute_05.png" alt="tutorial_attribute_05" width="281" height="338" /></a></p>
<p><span data-ttu-id="6f925-182">c.</span> <span data-ttu-id="6f925-183">在“值”列表中，选择为该行显示的属性值。</span> <span data-ttu-id="6f925-184">根据上文中的指定添加 Namespace 值。</span></p>
<p><span data-ttu-id="6f925-185">d.</span> <span data-ttu-id="6f925-186">单击“确定” 。</span></li>
<li><span data-ttu-id="6f925-187">单击“保存”按钮在 Azure 中保存设置。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_400.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_400.png" alt="tutorial_general_400" width="499" height="39" /></a></li>
<li><span data-ttu-id="6f925-189">在其他浏览器窗口中，以管理员身份登录 Amazon Web Services (AWS) 公司站点。</span></li>
<li><span data-ttu-id="6f925-190">单击“控制台主页”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795031.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795031.png" alt="ic795031" width="944" height="68" /></a></li>
<li><span data-ttu-id="6f925-192">从<strong>安全性、标识和合规性</strong>服务中单击“IAM”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795032.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795032.png" alt="ic795032" width="515" height="820" /></a></li>
<li><span data-ttu-id="6f925-194">单击“标识提供者”，并单击“创建提供者”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795033.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795033.png" alt="ic795033" width="582" height="422" /></a></li>
<li><span data-ttu-id="6f925-196">在“配置提供者”对话框页上，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795034.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795034.png" alt="ic795034" width="1039" height="645" /></a></p>
<p><span data-ttu-id="6f925-198">a.</span> <span data-ttu-id="6f925-199">对于“提供者类型”，请选择“SAML”。</span></p>
<p><span data-ttu-id="6f925-200">b.</span> <span data-ttu-id="6f925-201">在“提供者名称”文本框中，键入提供者名称（例如：<em>WAAD</em>）。</span></p>
<p><span data-ttu-id="6f925-202">c.</span> <span data-ttu-id="6f925-203">若要上传下载的元数据文件，请单击“选择文件”。</span></p>
<p><span data-ttu-id="6f925-204">d.</span> <span data-ttu-id="6f925-205">单击“下一步”。</span></li>
<li><span data-ttu-id="6f925-206">在“验证提供者信息”对话框页上，单击“创建”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795035.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795035.png" alt="ic795035" width="1177" height="651" /></a></li>
<li><span data-ttu-id="6f925-208">单击“角色”，并单击“创建新角色”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795022.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795022.png" alt="ic795022" width="615" height="366" /></a></li>
<li><span data-ttu-id="6f925-210">在“设置角色名称”对话框中，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795023.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795023.png" alt="ic795023" width="1326" height="423" /></a></p>
<p><span data-ttu-id="6f925-212">a.</span> <span data-ttu-id="6f925-213">在“角色名称”文本框中，键入角色名称（例如：<em>TestUser</em>）。</span></p>
<p><span data-ttu-id="6f925-214">b.</span> <span data-ttu-id="6f925-215">单击“下一步”。</span></li>
<li><span data-ttu-id="6f925-216">在“选择角色类型”对话框中，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795024.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795024.png" alt="ic795024" width="1021" height="443" /></a></p>
<p><span data-ttu-id="6f925-218">a.</span> <span data-ttu-id="6f925-219">选择“标识提供者角色的访问权限”。</span></p>
<p><span data-ttu-id="6f925-220">b.</span> <span data-ttu-id="6f925-221">在<strong>授予 SAML 提供程序的 Web 单一访问 (WebSSO) 访问权限</strong>部分中，单击“选择”。</span></li>
<li><span data-ttu-id="6f925-222">在“建立信任”对话框中，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795025.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795025.png" alt="ic795025" width="842" height="404" /></a></p>
<p><span data-ttu-id="6f925-224">a.</span> <span data-ttu-id="6f925-225">对于 SAML 提供者，选择之前创建的 SAML 提供者（例如：<em>WAAD</em>）</span></p>
<p><span data-ttu-id="6f925-226">b.</span> <span data-ttu-id="6f925-227">单击“下一步”。</span></li>
<li><span data-ttu-id="6f925-228">在“验证角色信任”对话框中，单击“下一步”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950251.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950251.png" alt="ic7950251" width="1134" height="645" /></a></li>
<li><span data-ttu-id="6f925-230">在“附加策略”对话框中，单击“下一步”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950252.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950252.png" alt="ic7950252" width="1326" height="649" /></a></li>
<li><span data-ttu-id="6f925-232">在“审阅”对话框中，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950253.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950253.png" alt="ic7950253" width="1223" height="514" /></a></p>
<p><span data-ttu-id="6f925-234">a.</span> <span data-ttu-id="6f925-235">单击“创建角色”。</span></p>
<p><span data-ttu-id="6f925-236">b.</span> <span data-ttu-id="6f925-237">创建所需数量的角色，并将其映射到标识提供者。</span></li>
<li><span data-ttu-id="6f925-238">现在，配置用户预配以从 AWS 中提取所有角色</span>
<p><span data-ttu-id="6f925-239">a.</span> <span data-ttu-id="6f925-240">在 AWS 控制台中，使用根帐户进行登录</span></p>
<p><span data-ttu-id="6f925-241">b.</span> <span data-ttu-id="6f925-242">在右上角，单击你的姓名，并单击“我的安全凭据”选项。</span> <span data-ttu-id="6f925-243">这会打开一个屏幕，其中显示了警告消息。</span> <span data-ttu-id="6f925-244">单击“安全凭据”按钮以通过该屏幕。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_securitycredentials.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_securitycredentials.png" alt="tutorial_amazonwebservices_securitycredentials" width="201" height="238" /></a></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_securitycredentials_continue.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_securitycredentials_continue.png" alt="tutorial_amazonwebservices_securitycredentials_continue" width="760" height="212" /></a></p>
<p><span data-ttu-id="6f925-247">c.</span> <span data-ttu-id="6f925-248">在“访问密钥”部分中，单击“新建访问密钥”按钮。</span> <span data-ttu-id="6f925-249">这会生成访问密钥 ID 和令牌值。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_createnewaccesskey.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_createnewaccesskey.png" alt="tutorial_amazonwebservices_createnewaccesskey" width="1601" height="192" /></a></p>
<p><span data-ttu-id="6f925-251">d.</span> <span data-ttu-id="6f925-252">复制这些值并下载它们，以免丢失它们。</span></p>
<p><span data-ttu-id="6f925-253">e.</span> <span data-ttu-id="6f925-254">在 Azure 门户中，在 Amazon Web Services (AWS) 应用程序集成页上，单击“预配”。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning.png" alt="tutorial_amazonwebservices_provisioning" width="214" height="232" /></a></p>
<p><span data-ttu-id="6f925-256">f.</span> <span data-ttu-id="6f925-257">将预配模式设置为“自动”</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning_automatic.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning_automatic.png" alt="tutorial_amazonwebservices_provisioning_automatic" width="616" height="46" /></a></p>
<p><span data-ttu-id="6f925-259">g.</span> <span data-ttu-id="6f925-260">现在，在“clientsecret”和“密钥标记”中，粘贴已从 AWS 控制台复制的相应值。</span></p>
<p><span data-ttu-id="6f925-261">h.</span> <span data-ttu-id="6f925-262">可以单击“测试连接”按钮来测试连接。</span> <span data-ttu-id="6f925-263">在成功后，可以启动预配连接器。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning_testconnection.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning_testconnection.png" alt="tutorial_amazonwebservices_provisioning_testconnection" width="609" height="193" /></a></p>
<p><span data-ttu-id="6f925-265">i.</span> <span data-ttu-id="6f925-266">现在，将预配状态启用为“开启”。</span> <span data-ttu-id="6f925-267">这会开始从应用程序提取角色。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning_on.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_provisioning_on.png" alt="tutorial_amazonwebservices_provisioning_on" width="514" height="156" /></a></p>
<div class="NOTE alert">
<p>备注</p>
<p><span data-ttu-id="6f925-269">Azure AD 预配服务每隔一段时间会运行一次来从 AWS 同步角色。</span> <span data-ttu-id="6f925-270">应当会看到所有标识提供者都已将 AWS 角色附加到 Azure AD 中，并且在将应用程序分配给用户或组时可以使用这些角色。</span></p>
</div>
</li>
</ol>
<h3 id="creating-an-azure-ad-test-user"><span data-ttu-id="6f925-271">创建 Azure AD 测试用户</span></h3>
<p><span data-ttu-id="6f925-272">本部分的目的是在 Azure 门户中创建名为 Britta Simon 的测试用户。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_100.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_100.png" alt="tutorial_general_100" width="536" height="79" /></a></p>
<p><span data-ttu-id="6f925-274"><strong>若要在 Azure AD 中创建测试用户，请执行以下步骤：</strong></span></p>
<ol>
<li><span data-ttu-id="6f925-275">在 <strong>Azure 门户</strong>的左侧导航窗格中，单击“Azure Active Directory”图标。</span>
<p><img src="https://docs.microsoft.com/zh-cn/azure/active-directory/media/active-directory-saas-amazon-web-service-tutorial/create_aaduser_01.png" alt="" /></li>
<li><span data-ttu-id="6f925-277">转到“用户和组”，单击“所有用户”显示用户列表。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/create_aaduser_02.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/create_aaduser_02.png" alt="create_aaduser_02" width="436" height="420" /></a></li>
<li><span data-ttu-id="6f925-279">在对话框顶部单击“添加”，打开“用户”对话框。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/create_aaduser_03.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/create_aaduser_03.png" alt="create_aaduser_03" width="401" height="33" /></a></li>
<li><span data-ttu-id="6f925-281">在“用户”对话框页上，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/create_aaduser_04.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/create_aaduser_04.png" alt="create_aaduser_04" width="293" height="591" /></a></p>
<p><span data-ttu-id="6f925-283">a.</span> <span data-ttu-id="6f925-284">在“名称”文本框中，键入 <strong>BrittaSimon</strong>。</span></p>
<p><span data-ttu-id="6f925-285">b.保留“数据库类型”设置，即设置为“共享”。</span> <span data-ttu-id="6f925-286">在“用户名”文本框中，键入 BrittaSimon 的“电子邮件地址”。</span></p>
<p><span data-ttu-id="6f925-287">c.</span> <span data-ttu-id="6f925-288">选择“显示密码”并记下“密码”的值。</span></p>
<p><span data-ttu-id="6f925-289">d.单击“下一步”。</span> <span data-ttu-id="6f925-290">单击“创建” 。</span></li>
</ol>
<h3 id="creating-an-amazon-web-services-test-user"><span data-ttu-id="6f925-291">创建 Amazon Web Services 测试用户</span></h3>
<p><span data-ttu-id="6f925-292">为了使 Azure AD 用户能够登录到 Amazon Web Services (AWS)，必须将其预配到 Amazon Web Services (AWS) 中。</span> <span data-ttu-id="6f925-293">对于 Amazon Web Services (AWS)，预配任务需要手动完成。</span></p>
<p><span data-ttu-id="6f925-294"><strong>若要预配用户帐户，请执行以下步骤：</strong></span></p>
<ol>
<li><span data-ttu-id="6f925-295">以管理员身份登录 <strong>Amazon Web Services (AWS)</strong> 公司站点。</span></li>
<li><span data-ttu-id="6f925-296">单击“控制台主页”图标。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950311.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950311.png" alt="ic7950311" width="944" height="68" /></a></li>
<li><span data-ttu-id="6f925-298">单击“标识和访问管理”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950321.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic7950321.png" alt="ic7950321" width="843" height="265" /></a></li>
<li><span data-ttu-id="6f925-300">在仪表板中，单击“用户”，并单击“创建新用户”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795037.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795037.png" alt="ic795037" width="743" height="263" /></a></li>
<li><span data-ttu-id="6f925-302">在“创建用户”对话框页上，执行以下步骤：</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795038.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ic795038.png" alt="ic795038" width="1112" height="536" /></a></p>
<p><span data-ttu-id="6f925-304">a.</span> <span data-ttu-id="6f925-305">在“输入用户名称”文本框中，键入 Brita Simon 在 Azure AD 中的用户名 (userprincipalname)。</span></p>
<p><span data-ttu-id="6f925-306">b.</span> <span data-ttu-id="6f925-307">单击“创建”。</span></li>
</ol>
<h3 id="assigning-the-azure-ad-test-user"><span data-ttu-id="6f925-308">分配 Azure AD 测试用户</span></h3>
<p><span data-ttu-id="6f925-309">在本部分中，将通过向 Britta Simon 授予对 Amazon Web Services (AWS) 的访问权限使她能够使用 Azure 单一登录。</span></p>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_200.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_200.png" alt="tutorial_general_200" width="540" height="78" /></a></p>
<p><span data-ttu-id="6f925-311"><strong>要将 Britta Simon 分配到 Amazon Web Services (AWS)，请执行以下步骤：</strong></span></p>
<ol>
<li><span data-ttu-id="6f925-312">在 Azure 门户中打开应用程序视图，导航到目录视图，接着转到“企业应用程序”，并单击“所有应用程序”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_201.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_201.png" alt="tutorial_general_201" width="418" height="315" /></a></li>
<li><span data-ttu-id="6f925-314">在应用程序列表中，选择“Amazon Web Services (AWS)”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_app.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_amazonwebservices_app.png" alt="tutorial_amazonwebservices_app" width="590" height="148" /></a></li>
<li><span data-ttu-id="6f925-316">在左侧菜单中，单击“用户和组”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_202.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_202.png" alt="tutorial_general_202" width="155" height="283" /></a></li>
<li><span data-ttu-id="6f925-318">单击“添加”按钮。</span> <span data-ttu-id="6f925-319">然后在“添加分配”对话框中选择“用户和组”。</span>
<p><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_203.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/tutorial_general_203.png" alt="tutorial_general_203" width="883" height="188" /></a></li>
<li><span data-ttu-id="6f925-321">在“用户和组”对话框的“用户”列表中，选择“Britta Simon”。</span></li>
<li><span data-ttu-id="6f925-322">在“用户和组”对话框中单击“选择”按钮。</span></li>
<li><span data-ttu-id="6f925-323">在“选择角色”选项卡上，为用户选择合适的角色。</span> <span data-ttu-id="6f925-324">所有这些角色都显示有角色名称和标识提供者名称。</span> <span data-ttu-id="6f925-325">因此，可以轻松识别来自 AWS 的角色。</span></li>
<li><span data-ttu-id="6f925-326">在“添加分配”对话框中单击“分配”按钮。</span></li>
</ol>
<h3 id="testing-single-sign-on"><span data-ttu-id="6f925-327">测试单一登录</span></h3>
<p><span data-ttu-id="6f925-328">在本部分中，使用访问面板测试 Azure AD 单一登录配置。</span></p>
<p><span data-ttu-id="6f925-329">在访问面板中单击“Amazon Web Services (AWS)”磁贴时，应该会自动登录 Amazon Web Services (AWS) 应用程序。</span></p>
<h2 id="additional-resources"><span data-ttu-id="6f925-330">其他资源</span></h2>
<ul>
<li><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-saas-tutorial-list" data-linktype="relative-path"><span data-ttu-id="6f925-331">有关如何将 SaaS 应用与 Azure Active Directory 集成的教程列表</span></a></li>
<li><a href="https://docs.microsoft.com/zh-cn/azure/active-directory/active-directory-appssoaccess-whatis" data-linktype="relative-path"><span data-ttu-id="6f925-332">Azure Active Directory 的应用程序访问与单一登录是什么？</span></a></li>
</ul>
<p><a rel="nofollow" href="https://www.fuwuqiok.com/%e6%95%99%e7%a8%8b%ef%bc%9aazure-active-directory-%e4%b8%8e-amazon-web-services-aws-%e9%9b%86%e6%88%90/">教程：Azure Active Directory 与 Amazon Web Services (AWS) 集成</a>，首发于<a rel="nofollow" href="https://www.fuwuqiok.com">服务器安全维护工作室</a>。</p>
]]></content:encoded>
			<wfw:commentRss>https://www.fuwuqiok.com/%e6%95%99%e7%a8%8b%ef%bc%9aazure-active-directory-%e4%b8%8e-amazon-web-services-aws-%e9%9b%86%e6%88%90/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AWS在AMAZON ELB环境下限制客户端的访问配置</title>
		<link>https://www.fuwuqiok.com/aws%e5%9c%a8amazon-elb%e7%8e%af%e5%a2%83%e4%b8%8b%e9%99%90%e5%88%b6%e5%ae%a2%e6%88%b7%e7%ab%af%e7%9a%84%e8%ae%bf%e9%97%ae%e9%85%8d%e7%bd%ae/</link>
		<comments>https://www.fuwuqiok.com/aws%e5%9c%a8amazon-elb%e7%8e%af%e5%a2%83%e4%b8%8b%e9%99%90%e5%88%b6%e5%ae%a2%e6%88%b7%e7%ab%af%e7%9a%84%e8%ae%bf%e9%97%ae%e9%85%8d%e7%bd%ae/#comments</comments>
		<pubDate>Wed, 06 Dec 2017 02:31:40 +0000</pubDate>
		<dc:creator><![CDATA[admin]]></dc:creator>
				<category><![CDATA[Amazon AWS]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[linux代维]]></category>
		<category><![CDATA[linux服务器代维护]]></category>
		<category><![CDATA[服务器代维合同]]></category>
		<category><![CDATA[AWS代付]]></category>
		<category><![CDATA[上云迁移解决方案]]></category>
		<category><![CDATA[云主机托管]]></category>
		<category><![CDATA[云服务器迁移]]></category>
		<category><![CDATA[云服务解决方案]]></category>
		<category><![CDATA[云迁移]]></category>
		<category><![CDATA[企业上云服务咨询]]></category>
		<category><![CDATA[数据中心迁移]]></category>
		<category><![CDATA[服务器迁移]]></category>
		<category><![CDATA[电话告警]]></category>
		<category><![CDATA[网站迁移]]></category>
		<category><![CDATA[运维支持]]></category>
		<category><![CDATA[阿里云服务器迁移]]></category>

		<guid isPermaLink="false">https://www.fuwuqiok.com/?p=3355</guid>
		<description><![CDATA[<p>&#160; ELB(Elastic Load Balancer) Amazon ELB(Elastic Lo [&#8230;]</p>
<p><a rel="nofollow" href="https://www.fuwuqiok.com/aws%e5%9c%a8amazon-elb%e7%8e%af%e5%a2%83%e4%b8%8b%e9%99%90%e5%88%b6%e5%ae%a2%e6%88%b7%e7%ab%af%e7%9a%84%e8%ae%bf%e9%97%ae%e9%85%8d%e7%bd%ae/">AWS在AMAZON ELB环境下限制客户端的访问配置</a>，首发于<a rel="nofollow" href="https://www.fuwuqiok.com">服务器安全维护工作室</a>。</p>
]]></description>
				<content:encoded><![CDATA[<p>&nbsp;</p>
<div class="entry-text clearfix"><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ELB.png"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ELB.png" alt="ELB" width="770" height="500" /></a></p>
<div class="shortcode-br clearfix"></div>
<h2>ELB(Elastic Load Balancer)</h2>
<div class="shortcode-columns outer clearfix">
<div class="eight column">
<div class="inner">
<p>Amazon ELB(Elastic Load Balancer)，是AWS提供的弹性负载均衡器，可根据实际情况为外部访问分配最合适的服务器。在实际使用过程中，会需要对经由ELB的客户端访问加以限制，本文将介绍如何通过配置EC2实例来实现对此类客户端的限制访问。</p>
</div>
</div>
<div class="four column">
<div class="inner"><a href="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ELB.jpg"><img class="attachment-medium" src="https://www.fuwuqiok.com/wp-content/uploads/2017/12/ELB.jpg" alt="ELB" width="365" height="138" /></a></div>
</div>
</div>
<p>如图所示，由于ELB不属于安全组，所以对于安全组实施限制并不会对ELB生效，经由ELB的客户端访问依然可以抵达EC2。</p>
<p>然而倘若限制ELB访问EC2，ELB对EC2发出HealthCheck（健康检查）动作时，ELB将无法访问成功检查，而判断该EC2出现异常情况。所以只有通过在EC2实例上的Web服务器上配置访问限制，才能对经由ELB的客户端访问加以限制。</p>
<p>可是在对访问的客户端实施限制时，由于访问全部经由ELB，则检知的访问IP均为ELB的IP，此时需要借助XFF头（X-Forwarded-For）实施确认和限制。</p>
<h2>举例说明</h2>
<p>1.只允许地址为172.24.40.83的IP访问该网站。</p>
<p>编辑网站配置文件，添加或修改配置文件如下：</p>
<pre>SetEnvIf X-Forwarded-For "172.24.40.83" allow_ip
Order deny,allow
Deny  from all
Allow from env=allow_ip
</pre>
<p>2.拒绝地址为172.24.40.83和17224.40.84的IP访问该网站。</p>
<p>编辑网站配置文件,添加或修改配置文件如下：</p>
<pre>SetEnvIf X-Forwarded-For "172.24.40.83" deny_ip01
SetEnvIf X-Forwarded-For "172.24.40.84" deny_ip02
Order allow,deny
Allow from all
Deny  from env=allow_ip01
Deny  from env=allow_ip02
</pre>
<p>X-Forwarded-For的功能是在ELB接受客户端的请求后，分配到EC2时在数据包的尾部添加上真正客户端的IP地址。</p>
<p>采用Apache的Web服务器，通过mod_extract_forwarded的安装和配置，可以将客户端的IP修改成X-Forwarded-For，具体的方法目前还有待研究。</p>
<pre># yum install mod_extract_forwarded</pre>
<h2>负载均衡器分配方式简介</h2>
<p>ELB弹性负载均衡器是一款比较简单易用的负载均衡器，其采用Round Robin方式平均的将外部访问分配到ELB管理下的EC2实例中，保障实例群在大访问量下最好的分配使用系统资源。</p>
<p>此外，常见的高性能的负载均衡器，一般含有：Least Connections，Observed，Dynamic Ratio，Round Robin，Ratio，Fastest，Predictive等等。由于ELB只提供Round Robin功能所以说是简单的，通过万维网只几步就可以拥有负载均衡器,因此说它又是易用的。</p>
</div>
<p><a rel="nofollow" href="https://www.fuwuqiok.com/aws%e5%9c%a8amazon-elb%e7%8e%af%e5%a2%83%e4%b8%8b%e9%99%90%e5%88%b6%e5%ae%a2%e6%88%b7%e7%ab%af%e7%9a%84%e8%ae%bf%e9%97%ae%e9%85%8d%e7%bd%ae/">AWS在AMAZON ELB环境下限制客户端的访问配置</a>，首发于<a rel="nofollow" href="https://www.fuwuqiok.com">服务器安全维护工作室</a>。</p>
]]></content:encoded>
			<wfw:commentRss>https://www.fuwuqiok.com/aws%e5%9c%a8amazon-elb%e7%8e%af%e5%a2%83%e4%b8%8b%e9%99%90%e5%88%b6%e5%ae%a2%e6%88%b7%e7%ab%af%e7%9a%84%e8%ae%bf%e9%97%ae%e9%85%8d%e7%bd%ae/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
