Chuyển đến nội dung chính

レッスン 15: ID シークレット エンジン、エンティティ、および MFA

ID シークレット エンジン、エンティティとエイリアス、エンティティ ポリシー、内部グループと外部グループ、グループ エイリアス、アイデンティティ トークン (OIDC プロバイダー)、MFA — TOTP、Duo、Okta、PingID、MFA TOTP 自己登録 (1.21)。

🔒 D​​evSecOps — レッスン 15 レッスン 15: ID シークレット エンジン、エンティティ および MFA

HashiCorp Vault の基本から上級まで

パート 3: 認証方法 - 認証と認可

xdev.asia

1. Identity Secrets Engine

Identity Secrets Engine は Vault の内部コンポーネントであり、自動的に有効になり、無効にすることはできません。 identity を管理し、複数の認証方法 ID を統合ビューに結合します。

解決すべき問題

ユーザーはさまざまな認証方法で認証できます:

  • CLI

  • を使用する場合は LDAP でログインします
  • Web UI を使用する場合は OIDC でログイン

  • AppRole

  • を使用するユーザーのサービス アカウント

Vault には、これが 同じ人物 であることを認識し、ポリシーを一貫して適用する方法が必要です。

アイデンティティ アーキテクチャ

┌─────────────────────────────────────────────────┐
│                   Entity                        │
│  (Đại diện cho 1 người/machine duy nhất)       │
│                                                 │
│  ┌─────────┐  ┌─────────┐  ┌─────────┐        │
│  │ Alias 1 │  │ Alias 2 │  │ Alias 3 │        │
│  │ (LDAP)  │  │ (OIDC)  │  │(AppRole)│        │
│  └─────────┘  └─────────┘  └─────────┘        │
│                                                 │
│  Policies: [team-lead, dev-admin]              │
│  Metadata: {team: platform, level: senior}      │
│                                                 │
│  Groups: [platform-team, all-engineers]         │
└─────────────────────────────────────────────────┘

2。エンティティとエイリアス

エンティティの作成

# Tạo entity thủ công
vault write identity/entity \
  name="john-doe" \
  policies="team-lead" \
  metadata='{"team": "platform", "employee_id": "EMP001", "email": "[email protected]"}'

# Đọc entity
vault read identity/entity/name/john-doe

# Liệt kê entities
vault list identity/entity/name

エイリアスの作成

# Lấy mount accessor cho auth methods
vault auth list -format=json | jq -r '."ldap/".accessor'
# auth_ldap_abc123

vault auth list -format=json | jq -r '."oidc/".accessor'
# auth_oidc_def456

# Tạo alias cho LDAP
vault write identity/entity-alias \
  name="john.doe" \
  canonical_id="<entity-id>" \
  mount_accessor="auth_ldap_abc123"

# Tạo alias cho OIDC
vault write identity/entity-alias \
  name="[email protected]" \
  canonical_id="<entity-id>" \
  mount_accessor="auth_oidc_def456"

これで、john.doe が LDAP または OIDC を使用してログインすると、Vault はこれを同じエンティティとして認識し、エンティティ ポリシーとグループ ポリシーを適用します。

Entity Metadata trong Policies

# Policy template sử dụng entity metadata
path "secret/data/teams/{{identity.entity.metadata.team}}/*" {
  capabilities = ["create", "read", "update", "delete", "list"]
}

# Dựa trên entity name
path "secret/data/users/{{identity.entity.name}}/*" {
  capabilities = ["create", "read", "update", "delete", "list"]
}

3. Groups

Internal Groups

内部グループは Vault 内で完全に管理されます:

# Tạo internal group
vault write identity/group \
  name="platform-team" \
  type="internal" \
  policies="platform-admin,kv-platform" \
  member_entity_ids="entity-id-1,entity-id-2,entity-id-3" \
  metadata='{"department": "engineering", "cost_center": "CC001"}'

# Thêm member vào group
vault write identity/group/name/platform-team \
  member_entity_ids="entity-id-1,entity-id-2,entity-id-3,entity-id-4"

# Nested groups (sub-groups)
vault write identity/group \
  name="all-engineers" \
  type="internal" \
  policies="engineer-base" \
  member_group_ids="<platform-team-id>,<backend-team-id>,<frontend-team-id>"

External Groups

外部グループは LDAP/OIDC グループから Vault ポリシーにマップします:

# Tạo external group
vault write identity/group \
  name="ldap-devops" \
  type="external" \
  policies="devops-admin,kv-devops"

# Map đến LDAP group via group alias
vault write identity/group-alias \
  name="CN=DevOps,OU=Groups,DC=company,DC=com" \
  mount_accessor="auth_ldap_abc123" \
  canonical_id="<external-group-id>"

# Map đến OIDC group
vault write identity/group-alias \
  name="devops" \
  mount_accessor="auth_oidc_def456" \
  canonical_id="<external-group-id>"

4. Identity Tokens (OIDC Provider)

Vault は OIDC プロバイダー として機能し、アイデンティティ エンティティ:

に基づいて OIDC トークンを発行します。
# Tạo assignment (ai được phát token)
vault write identity/oidc/assignment/dev-team \
  entity_ids="entity-id-1,entity-id-2" \
  group_ids="group-id-1"

# Tạo key cho signing
vault write identity/oidc/key/app-key \
  algorithm="RS256" \
  allowed_client_ids="*" \
  rotation_period="24h"

# Tạo OIDC client
vault write identity/oidc/client/my-webapp \
  redirect_uris="https://myapp.company.com/callback" \
  assignments="dev-team" \
  key="app-key" \
  id_token_ttl="30m" \
  access_token_ttl="1h"

# Tạo OIDC provider
vault write identity/oidc/provider/company \
  issuer="https://vault.company.com" \
  allowed_client_ids="<client-id>" \
  scopes_supported="openid,email,profile,groups"

5. Multi-Factor Authentication (MFA)

Vault は、認証の 2 番目の層を追加する MFA をサポートしています。 MFA には 2 つのタイプがあります:

タイプ説明必要な場合
ログインMFAログイン時のMFAリクエストすべてのログインリクエスト
ステップアップ MFA機密性の高い操作の MFA リクエスト特定のパス/操作

TOTP MFA

# Tạo TOTP MFA method
vault write identity/mfa/method/totp \
  method_name="company-totp" \
  issuer="VaultCompany" \
  period=30 \
  key_size=20 \
  digits=6 \
  algorithm="SHA1" \
  qr_size=200

# Lấy MFA method ID
vault read identity/mfa/method/totp

# Tạo Login MFA enforcement
vault write identity/mfa/login-enforcement/require-totp \
  mfa_method_ids="<totp-method-id>" \
  auth_method_types="userpass,ldap" \
  identity_group_ids="<admin-group-id>"

MFA TOTP Self-enrollment (Vault 1.21)

Vault 1.21 の新機能により、ユーザーは MFA TOTP に自己登録できます:

# Admin: enable self-enrollment
vault write identity/mfa/method/totp \
  method_name="self-totp" \
  issuer="CompanyVault" \
  allow_self_enrollment=true

# User: login rồi enroll TOTP
# 1. Login
vault login -method=userpass username=john.doe

# 2. Generate TOTP secret (trả về QR code URL)
vault write identity/mfa/method/totp/admin-generate \
  method_id="<totp-method-id>" \
  entity_id="<my-entity-id>"

# 3. Quét QR code bằng app (Google Authenticator, Authy)
# 4. Login lần tiếp theo sẽ yêu cầu TOTP code

Duo MFA

# Cấu hình Duo MFA
vault write identity/mfa/method/duo \
  method_name="company-duo" \
  secret_key="<duo-secret-key>" \
  integration_key="<duo-integration-key>" \
  api_hostname="api-xxxxxxxx.duosecurity.com" \
  push_info="Vault Login"

# Enforcement cho admin group
vault write identity/mfa/login-enforcement/admin-duo \
  mfa_method_ids="<duo-method-id>" \
  identity_group_ids="<admin-group-id>"

6. MFA Login Flow

┌──────────┐   1. Login            ┌──────────────┐
│   User   │ ────────────────────▶ │    Vault     │
│          │                       │              │
│          │   2. MFA Required     │              │
│          │      (request_id)     │              │
│          │ ◀──────────────────── │              │
│          │                       │              │
│          │   3. Submit MFA code  │              │
│          │      + request_id     │              │
│          │ ────────────────────▶ │              │
│          │                       │              │
│          │   4. Vault Token      │              │
│          │ ◀──────────────────── │              │
└──────────┘                       └──────────────┘
# Step 1: Login (trả về mfa_request_id nếu MFA required)
vault login -method=userpass username=john.doe
# Enter MFA code for method "company-totp":

# Step 2: Enter TOTP code
# 123456

# API flow
# Login → nhận mfa_request_id
curl -s --request POST \
  --data '{"password": "p@ss"}' \
  ${VAULT_ADDR}/v1/auth/userpass/login/john.doe

# Validate MFA
curl -s --request POST \
  --data '{
    "mfa_request_id": "...",
    "mfa_payload": {
      "<totp-method-id>": ["123456"]
    }
  }' \
  ${VAULT_ADDR}/v1/sys/mfa/validate

7。概要

  • Identity Engine — 複数の認証 ID を単一のエンティティに結合

  • Entities + Aliases — map users across LDAP, OIDC, AppRole

  • Groups — 内部 (Vault 管理) および外部 (LDAP/OIDC グループ)

  • ID トークン — OIDC プロバイダーとしてのボールト

  • MFA — TOTP、Duo、ログイン MFA、およびステップアップ MFA

  • TOTP 自己登録 (1.21) — ユーザーは MFA

  • を自己登録します

次のセクションでは、高度なシークレット エンジン (SSH、TOTP、変換、KMIP、カスタム プラグイン) について説明します。