- 入门指南
- 最佳实践
- 租户
- 文件夹上下文
- 自动化
- 流程
- 作业
- 触发器
- 日志
- 监控
- 队列
- 资产
- 存储桶
- Test Suite - Orchestrator
- 其他配置
- 集成
- 传统机器人
- 主机管理
- 组织管理
- 故障排除
安装密钥
安装密钥是一个令牌,用于允许 SSO 连接到 Orchestrator 以用于集成应用程序。
-
以系统管理员身份登录到管理门户。
-
On the Security Settings page, the current installation key is displayed and you can click the Copy icon to copy it to your clipboard:
-
(可选)要生成新的安装密钥,请单击“生成新的”。
右上角将显示一条成功消息,指示已生成新密钥。
外部提供程序
Orchestrator 允许您配置外部身份提供程序,以控制用户的登录方式。 下表概述了可用的不同主机级别外部提供程序。
请按照适用于您要使用的外部提供程序的说明进行操作,如下所示:
下表中的说明适用于全新安装,或者您是首次配置某个外部提供程序。
If you upgraded Orchestrator and were already using one or more of the external providers listed below, the configuration is migrated, but you might need to perform some re-configuration tasks. If so, follow the instructions in Re-configuring authentication after upgrade instead.
| 外部提供程序集成 | 身份验证 | 目录搜索 | 用户配置 |
|---|---|---|---|
| Active Directory 和 Windows 身份验证 | 用户可以通过 Kerberos 协议将 SSO 与 Windows 身份验证一起使用 | 管理员可以从 Active Directory 搜索用户 | 必须为用户分配 Orchestrator 租户中的角色。 可以通过目录搜索为 Active Directory 用户和组分配角色。 |
| Azure Active Directory | 用户可以通过 OpenID Connect 协议将 SSO 与 Azure AD 一起使用 | 不支持 | 必须使用与其 Azure AD 帐户匹配的电子邮件地址手动将用户配置到 Orchestrator 租户中。 |
| 用户可以使用 OpenID Connect 协议将 SSO 与 Google 一起使用 | 不支持 | 必须使用与其 Google 帐户匹配的电子邮件地址手动将用户配置到 Orchestrator 租户中。 | |
| SAML 2.0 | 用户可以将 SSO 与任何支持 SAML 的身份提供程序一起使用 | 不支持 | 必须使用与其 SAML 帐户匹配的用户名手动将用户配置到 Orchestrator 租户中。 |
The host-level Azure AD external identity provider only enables SSO functionality. The organization-level Azure AD integration enables SSO, directory search, and automatic user provisioning.
允许或限制基本身份验证
基本身份验证是指使用本地帐户的用户名和密码登录。
如果基本身份验证受到限制,则您的用户只能使用外部身份提供程序中定义的目录帐户登录。 否则,用户可以使用其本地帐户(如果有)和目录帐户登录。
配置级别和继承
可以配置此选项:
-
at the host level, as described below.
在主机级别设置时,该设置将应用于所有组织及其所有帐户,除非组织或帐户级别的基本身份验证设置未以不同方式显式设置。
-
for system administrator accounts, as described below.
即使限制所有组织使用基本身份验证,您也可以仅允许系统管理员绕过此限制。
-
at the organization level.
如果在组织级别设置,则组织级别设置仅覆盖该组织的主机级别设置。 组织的设置适用于属于该组织的所有帐户,但在帐户级别以不同方式设置基本身份验证的帐户除外。
-
at the account level.
如果在帐户级别设置,则帐户级别设置仅覆盖该帐户的主机级别和组织级别基本身份验证设置。
在主机级别设置基本身份验证
This setting is only available if an external provider integration is enabled at the host level.
在主机级别设置时,该设置将应用于所有组织及其所有帐户。 根据整个公司的偏好或建议进行设置。
对于例外情况,您也可以在组织级别或帐户级别设置基本身份验证,以便以不同方式应用此设置。
要允许或限制所有组织和所有帐户的基本身份验证,请执行以下操作:
-
以系统管理员身份登录到管理门户。
-
Go to Accounts & Groups and select the Authentication Settings tab.
-
Under External Providers, click the Disable basic authentication for the organizations toggle to restrict or allow sign in using basic authentication:
-
如果关闭(左侧切换位置,灰色切换),则允许基本身份验证。
-
If on (right toggle position, blue toggle), basic authentication is restricted. While restricted, the Allow basic authentication for the host administrators toggle is available.
-
-
If you restricted basic authentication, use the Allow basic authentication for the host administrators toggle to choose if you want to allow basic authentications for system administrators, as an exception:
- 如果关闭(左侧切换位置,灰色切换),则系统管理员也不允许进行基本身份验证。
- 如果打开(右侧切换位置,蓝色切换),即使不允许基本身份验证,也有例外情况,仅允许系统管理员帐户使用。
-
At the bottom-right of the External Providers section, click Save to apply your changes.
从锁定中恢复
禁用基本身份验证后,如果您无法访问目录帐户,则可能会被锁定。
要从这种情况中恢复,请转到 https://<FQDN>/host/orchestrator_/account/hostlogin ,然后使用您的基本身份验证凭据登录。
安全性
默认情况下,您在此处指定的设置将由安装中的所有组织继承,但组织管理员可以根据需要在单个组织级别覆盖这些设置。
To configure security options for your Orchestrator installation, go to Accounts & Groups > Authentication Settings and, in the Security section, edit the following options as needed.
密码复杂性
编辑密码复杂性设置不会影响现有密码。
| 字段 | 描述 |
|---|---|
| 特殊字符 | 选择以强制用户在其密码中至少加入一个特殊字符。 默认情况下,该复选框处于未选中状态。 |
| 小写字符 | 选择以强制用户在其密码中至少加入一个小写字符。 默认情况下,该复选框处于选中状态。 |
| 大写字符 | 选择以强制用户在其密码中至少加入一个大写字符。 默认情况下,该复选框处于未选中状态。 |
| 数字 | 选择以强制用户在其密码中至少加入一位数字。 默认情况下,该复选框处于选中状态。 |
| 最小密码长度 | 指定密码应包含的最少字符数。 默认情况下为 8。 长度必须设置在 1 到 256 个字符之间。 |
| 密码到期前的天数 | 指定密码的有效天数。密码将在此段时间后过期,需要更改。 可接受的最小值为 0(密码永不过期),最大值为 1000 天。 |
| 密码可重复使用的次数 | 接受的最小值为 0(不允许重复使用密码),最大值为 10。 |
| 首次登录时更改密码 | 如果设置为“必填”,则首次登录的用户必须先更改其密码,然后才能访问 Orchestrator。 如果设置为“不需要”,则用户可以登录并继续使用管理员定义的密码,直到密码过期。 |
帐户锁定
| 字段 | 描述 |
|---|---|
| 启用或禁用切换 | 如果启用,则在特定数量的登录尝试失败后将帐户锁定特定秒数。 这也适用于密码更改功能。 |
| 帐户锁定持续时间 | 超过锁定前的连续登录尝试次数后,用户在被允许再次登录之前需要等待的秒数。 默认值为 5 分钟。 接受的最小值为 0(无锁定持续时间),最大值为 2592000(1 个月)。 |
| 锁定前连续尝试登录 | 锁定帐户前允许的失败登录尝试次数。 默认值为 10 次。您可以设置一个介于 2 到 10 之间的值。 |