英語 での The federation server の使用例とその 日本語 への翻訳
{-}
-
Colloquial
-
Ecclesiastic
-
Computer
-
Programming
Specifying the Federation Server.
The federation server proxy is located in the perimeter network.
Cookies must be enabled- or at least trusted- for the federation servers and Web applications that are being accessed.
The federation server proxy that is located in the perimeter network of the resource partner organization.
Token-signing certificate This is a standard X509 certificate thatis used for securely signing all tokens that the federation server issues.
The federation server proxy that is located in the perimeter network of the account partner organization.
This is necessary so that credentials andtokens can be successfully routed from the role service to the federation server for processing.
When the federation server proxy is protecting an account partner, it collects user credential information from browser clients.
We strongly recommend that the traffic between the AD LDS server and the federation server be protected by TLS/SSL or by other means, such as Internet Protocol security(IPsec).
Configure the federation server to work with DNS, install and configure certificates, and verify that the server is functional.
We strongly recommend that the traffic between the AD LDS server and the federation server be protected by TLS/SSL or other means, such as Internet Protocol security(IPsec).
The federation server proxy writes all three types of cookies: authentication cookies, account partner cookies, and sign-out cookies.
For more information about the role of the federation server proxy, see Understanding the Federation Service Proxy Role Service.
The federation server proxy uses SSL server authentication certificates to secure Web services traffic for communication with Web clients.
Do not use a certificate that was issued by your enterprise CA for client authentication of an Active Directory user(especially a domain administrator)because the private key is stored on the federation server proxy.
When the federation server proxy is protecting a resource partner, it relays requests by and for Web applications to the Federation Service.
To verify that a security token was issued by a given federation server and not modified,the federation server must have a verification certificate for the federation server that issued the security token.
Configure the federation server to work with Domain Name System(DNS), install and configure certificates, and verify that the server is functional.
If you choose a directory that is different from the default directory, you must assign Read, Write, Create files, and List folder permissions to the identity of the ADFSAppPool that is defined in Internet Information Services(IIS)Manager(by default Network Service) so that the federation server or federation server proxy has the necessary permissions to write to the log files.
The federation server proxy also stores Hypertext Transfer Protocol(HTTP) cookies on clients when necessary to facilitate single sign-on(SSO).
In AD FS, a signed security token indicates that the federation server that issues the security token has successfully verified the authenticity of the federated user.
The federation server presents this choice to the client browser as a drop box containing the account partner names as they are configured in the trust policy.
A verification certificate is stored in the trust policy andused by the federation server in one organization to verify that incoming security tokens have been issued by valid federation servers in the organization's farm and in other organizations.
The federation server uses Secure Sockets Layer(SSL) server authentication certificates to secure Web services traffic for communication with Web clients or the federation server proxy.
Storing a private key on the federation server proxy allows an administrator or a successful attacker to assume the identity that the certificate represents.
Federation server proxies host the Federation Service Proxy role service of AD FS.
Configure the Federation Service or federation server farm.
I want to enable logging on the account federation server.
To enable logging for the account federation server authentication package, perform the following tasks in order:.