Sitecore 9中如何实现基于声明的Active Directory授权
关于Sitecore 9中AD原生授权与ADFS声明式授权的区别及配置方案
1. 仅用Active Directory vs 结合ADFS的声明式AD授权的核心区别
咱先把这俩的差异掰透,避免后续配置踩坑:
- 认证机制本质不同:
- 原生AD授权用的是NTLM/Kerberos这类传统域内认证协议,依赖域控制器的直接信任,用户身份是通过域令牌验证的,只能在域内网环境用。
- ADFS是基于声明式认证(SAML 2.0/OAuth 2.0),把AD的身份信息打包成“声明”(比如用户名、角色、邮箱),通过安全令牌传递给Sitecore,支持跨域、跨平台(比如外网访问、非Windows客户端)。
- 信任模型范围不同:
- 原生AD的信任仅限域内或已建立域信任的环境,扩展性差。
- ADFS支持联邦信任,可以对接多个外部系统(比如Sitecore、Office 365、自定义应用),甚至和其他组织的ADFS建立信任,实现跨企业身份共享。
- 权限传递方式不同:
- 原生AD是直接传递域用户的安全组信息,Sitecore直接读取AD组来授权,灵活性低。
- ADFS可以自定义声明规则,比如把AD里的
memberOf映射成Sitecore需要的角色声明,或者添加自定义属性(比如员工ID)作为声明,权限控制更灵活。
- 安全与合规性不同:
- 原生AD依赖域内网络安全,缺乏细粒度的认证策略(比如MFA、条件访问)。
- ADFS支持多因素认证(MFA)、基于IP/设备的条件访问,更符合企业级安全合规要求。
2. 已有ADFS/ADDS/Sitecore 9环境下,配置声明式AD授权的实战步骤
假设你已经部署好ADFS服务器(已配置AD作为身份提供商)、ADDS域,且Sitecore 9已正常运行,分两大块配置:
第一步:ADFS端配置依赖方信任(Relying Party Trust)
- 打开ADFS管理控制台,右键Relying Party Trusts → Add Relying Party Trust,选择Claims aware,点击下一步。
- 选择Enter data about the relying party manually,输入显示名称(比如
Sitecore 9 CMS),点击下一步。 - 选择ADFS profile,点击下一步。
- 跳过加密证书(如果需要加密可以后续配置),点击下一步。
- 勾选Enable support for the SAML 2.0 WebSSO protocol,输入Sitecore Identity Server的回调URL(比如
https://your-sitecore-identity-server.com/signin-saml2),点击下一步。 - 添加依赖方信任标识符(比如
urn:sitecore:identityserver),点击下一步。 - 选择Permit all users to access this relying party,后续可以细化权限,点击下一步完成。
- 配置声明规则:右键刚创建的依赖方信任 → Edit Claim Issuance Policy,添加以下规则:
- 规则1:传递用户名:选择Send LDAP Attributes as Claims,属性存储选Active Directory,LDAP属性选
sAMAccountName,输出声明类型选Name ID(格式选Unspecified)。 - 规则2:传递角色:选择Send Group Membership as Claims,输入AD组的DN(比如
CN=Sitecore Authors,OU=Sitecore Groups,DC=yourdomain,DC=com),输出声明类型选http://schemas.microsoft.com/ws/2008/06/identity/claims/role。 - 可以按需添加其他声明(比如邮箱、部门)。
- 规则1:传递用户名:选择Send LDAP Attributes as Claims,属性存储选Active Directory,LDAP属性选
第二步:Sitecore端配置联邦认证
这里分两种情况,取决于你的Sitecore 9版本:
情况A:Sitecore 9.1+(使用Sitecore Identity Server)
- 登录Sitecore Identity Server服务器,修改
IdentityServer\Config\production\IdentityServerHost.xml:- 添加ADFS作为外部身份提供商,示例配置片段:
<ExternalIdentityProviders> <ExternalIdentityProvider Name="ADFS" DisplayName="ADFS Login" Enabled="true" Type="Sitecore.Owin.Authentication.Configuration.DefaultExternalIdentityProvider, Sitecore.Owin.Authentication"> <AuthenticationType>saml2</AuthenticationType> <Caption>ADFS Login</Caption> <Enabled>true</Enabled> <MetadataAddress>https://adfs.yourdomain.com/federationmetadata/2007-06/federationmetadata.xml</MetadataAddress> <EntityId>urn:sitecore:identityserver</EntityId> <CallbackPath>/signin-saml2</CallbackPath> <SignInScheme>idsrv.external</SignInScheme> </ExternalIdentityProvider> </ExternalIdentityProviders> - 保存后重启Sitecore Identity Server服务。
- 添加ADFS作为外部身份提供商,示例配置片段:
- 修改Sitecore CMS的
App_Config\Include\Sitecore.Owin.Authentication.config(或自定义配置文件),添加声明映射:<authenticationProviders> <provider name="ADFS" type="Sitecore.Owin.Authentication.Configuration.DefaultAuthenticationProvider, Sitecore.Owin.Authentication"> <transformations> <!-- 映射NameID到Sitecore用户名 --> <transformation name="Name Identifier to Claim" type="Sitecore.Owin.Authentication.Services.DefaultTransformation, Sitecore.Owin.Authentication"> <sources> <claim name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier" /> </sources> <targets> <claim name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" /> </targets> <keepSource>true</keepSource> </transformation> <!-- 映射ADFS角色到Sitecore角色 --> <transformation name="Role Transformation" type="Sitecore.Owin.Authentication.Services.DefaultTransformation, Sitecore.Owin.Authentication"> <sources> <claim name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" /> </sources> <targets> <claim name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" value="sitecore\{0}" /> </targets> <keepSource>true</keepSource> </transformation> </transformations> <!-- 自动创建Sitecore用户 --> <userBuilder type="Sitecore.Owin.Authentication.Services.DefaultUserBuilder, Sitecore.Owin.Authentication"> <options> <domain>sitecore</domain> <nameIdentifierClaimType>http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier</nameIdentifierClaimType> </options> </userBuilder> </provider> </authenticationProviders> - 重启Sitecore CMS应用池,测试登录:访问Sitecore后台,点击
ADFS Login,跳转到ADFS登录页面,输入域用户 credentials,验证是否成功登录,且角色是否正确同步。
情况B:Sitecore 9.0(使用传统Federated Authentication模块)
- 安装Sitecore Federated Authentication模块(如果未安装)。
- 配置
App_Config\Include\Sitecore.FederatedAuthentication.config,添加ADFS认证方案,配置元数据地址、声明映射,步骤类似上面的Identity Server配置,但需要手动配置OWIN中间件的SAML2认证。 - 确保ADFS的回调URL指向Sitecore CMS的登录回调(比如
https://your-sitecore-cms.com/sitecore/login)。
关键注意事项
- 证书信任:把ADFS的签名证书导入到Sitecore服务器的受信任根证书颁发机构,避免证书验证失败。
- 回调URL一致性:ADFS里配置的回调URL必须和Sitecore端的
CallbackPath完全一致,包括HTTP/HTTPS、域名、路径。 - 声明映射准确性:确保ADFS输出的声明类型和Sitecore端配置的映射类型一致,否则用户身份或角色无法正确同步。
- 测试权限:登录后检查Sitecore用户的角色是否正确,比如AD组
Sitecore Authors是否映射到Sitecore的sitecore\Sitecore Authors角色。
内容的提问来源于stack exchange,提问作者きむてそん
相关产品推荐
相关产品推荐

