InfoGrab DocsInfoGrab Docs

Teleport를 SAML ID 공급자로 사용하기

Teleport를 SAML ID 공급자로 설정하고 사용하는 방법.

이 가이드는 Teleport를 SAML ID 공급자(IdP)로 사용하는 예제를 설명합니다. Teleport SAML IdP를 설정하면 Teleport 사용자가 Teleport를 통해 외부 서비스에 인증할 수 있습니다. 작동 방식 # Teleport Enterprise 배포에서, Teleport SAML IdP는 Teleport 프록시 서비스의 일부로 실행되며 SAML IdP를 구현하는 프록시 서비스 HTTP API 경로를 노출합니다. SAML IdP 서비스 프로바이더라는 Teleport 동적 리소스를 생성하여 IdP에 서드파티 애플리케이션을 등록할 수 있으며, 이 리소스에는 애플리케이션에 대한 정보가 포함됩니다. 사전 요구사항 # 실행 중인 Teleport Enterprise 클러스터. Teleport를 시작하려면 무료 체험판에 가입 하거나 데모 환경을 구성 하세요. tctl and tsh clients. Installing `tctl` and `tsh` clients Teleport 클러스터의 버전을 확인합니다. tctl and tsh clients는 Teleport 클러스터 버전보다 최대 한 개의 메이저 버전까지만 뒤처질 수 있습니다. Proxy Service의 /v1/webapi/find 로 GET 요청을 보내고 JSON 쿼리 도구를 사용하여 클러스터 버전을 확인합니다. teleport.example.com:443 를 Teleport Proxy Service의 웹 주소로 바꿉니다: $ TELEPORT_DOMAIN=teleport.example.com:443 $ TELEPORT_VERSION="$(curl -s https://$TELEPORT_DOMAIN/v1/webapi/find | jq -r '.server_version')" 사용 중인 플랫폼에 대한 지침에 따라 tctl and tsh clients를 설치합니다: Mac `tctl` and `tsh` clients가 포함된, 서명된 Teleport macOS .pkg 설치 프로그램을 다운로드합니다: ```code $ curl -O https://cdn.teleport.dev/teleport-${TELEPORT_VERSION?}.pkg ``` Finder에서 `pkg` 파일을 더블 클릭하여 설치를 시작합니다. Warning Homebrew를 사용하여 Teleport를 설치하는 것은 지원되지 않습니다. Homebrew의 Teleport 패키지는 Teleport에서 유지 관리하지 않으므로 신뢰성이나 보안을 보장할 수 없습니다. Windows - Powershell ```code $ curl.exe -O https://cdn.teleport.dev/teleport-v${TELEPORT_VERSION?}-windows-amd64-bin.zip # Unzip the archive and move the `tctl` and `tsh` clients to your %PATH% # NOTE: Do not place the `tctl` and `tsh` clients in the System32