> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/scepman-nodepuroi/deployment-guides/scenarios/certificate-based-authentication-for-rdp.md).

# RDP の証明書ベース認証

SCEPman を使用して、ユーザーに Smart Card Login 証明書を発行できます。ユーザーを Windows Hello for Business (*Microsoft Passport Key Storage Provider*) に登録すると、Hello PIN または生体認証オプションを使って、これらの証明書をオンプレミスのリソースへの認証に使用できます。

これにより、たとえばユーザーは Windows Hello for Business の資格情報を使用して、Remote Desktop Protocol (RDP) 経由で他のクライアントに接続できるようになります。

## Active Directory のセットアップ

### 要件

* SCEPman の CA 証明書は、 **NTAuth** ストアに公開して、Active Directory でユーザーを認証する必要があります
* スマートカード ユーザーを認証するには、Domain Controller に domain controller 証明書が必要です
* Domain Controller とターゲット マシンは、SCEPman のルート CA を信頼する必要があります

Domain Controller 証明書に関するガイドに従って、SCEPman のルート CA 証明書を **NTAuth** ストアに公開し、Domain Controller に証明書を発行してください:

{% content-ref url="/pages/a67341db70d2882646022e09a7418921797d9b53" %}
[Domain Controller 証明書](/ja/zheng-ming-shu-guan-li/domain-controller-certificates.md)
{% endcontent-ref %}

次を作成できます: **Group Policy Object** 関係するマシンへのルート証明書の配布を処理するための [Group Policy を使用してクライアント コンピューターに証明書を配布するには](https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/distribute-certificates-to-client-computers-by-using-group-policy#to-distribute-certificates-to-client-computers-by-using-group-policy)

この証明書は、認証を処理するすべての Domain Controller と、この方法でユーザーが接続したいすべてのターゲット マシンに展開する必要があります。

{% hint style="danger" %}
SCEPman のルート証明書が NTAuth ストアに公開されると、SCEPman によって発行される証明書の内容に影響を与えられるユーザー（例: Intune 管理者）は、Active Directory の任意のプリンシパルになりすますことができる点にご注意ください。
{% endhint %}

## Intune を使用して Smart Card 証明書を展開する

### 信頼済み証明書プロファイル

クライアントは次を [SCEPman のルート証明書を信頼する必要があります](/ja/zheng-ming-shu-guan-li/microsoft-intune/windows-10.md#root-certificate).

すでに SCEPman を使用してクライアントに証明書を展開している場合、このプロファイルはすでに設定済みです。

### Smart Card 証明書

次のプロファイルを作成します: **Windows 10 以降** 種類: **SCEP 証明書** Microsoft Intune で、以下のようにプロファイルを構成します:

<details>

<summary>証明書の種類: <code>ユーザー</code></summary>

</details>

<details>

<summary>サブジェクト名の形式: <code>CN={{UserPrincipalName}}</code></summary>

対象ユーザーの Entra ID の UPN サフィックスが Active Directory で使用されているものと異なる場合は、次を使用する必要があります `CN={{OnPrem_Distinguished_Name}}`

</details>

<details>

<summary>サブジェクトの代替名: UPN 値: <code>{{UserPrincipalName}}</code> および URI 値: <code>{{OnPremisesSecurityIdentifier}}</code></summary>

SID を含む URI は、 [強力な証明書マッピング](/ja/scepman-gou-cheng/application-settings/certificates.md#appconfig-addsidextension) を AD で有効にするために必要です。あるいは、SCEPman を [SID を含む拡張を追加して](/ja/scepman-gou-cheng/application-settings/scep-endpoints/intune-validation.md#appconfig-intunevalidation-waitforsuccessnotificationresponse) ユーザー証明書に追加し、URI は構成しないようにすることもできます。

</details>

<details>

<summary>キー ストレージ プロバイダー (KSP): <code>Windows Hello for Business に登録し、そうでなければ失敗させる (Windows 10 以降)</code></summary>

</details>

<details>

<summary>キー使用法: <code>デジタル署名</code> および <code>キー暗号化</code></summary>

</details>

<details>

<summary>キー サイズ (ビット): <code>2048</code></summary>

</details>

<details>

<summary>ハッシュ アルゴリズム: <code>SHA-2</code></summary>

</details>

<details>

<summary>ルート証明書: <code>前の手順のプロファイル (Trusted Certificate Profile)</code></summary>

</details>

<details>

<summary>拡張キー使用法: <code>クライアント認証</code> および <code>Smart Card ログ</code>の</summary>

`クライアント認証, 1.3.6.1.5.5.7.3.2`

`Smart Card ログオン, 1.3.6.1.4.1.311.20.2.2`

</details>

<details>

<summary>SCEP サーバー URL: SCEPman ポータルを開き、次の URL をコピーします: <a href="#device-certificates">Intune MDM</a></summary>

</details>

### Windows Hello for Business を使用してリモート ホストに接続する

認証クライアントに証明書を展開したら、リモート ホストに接続し、構成済みの Windows Hello for Business 資格情報プロバイダーを選択します。

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fy9e8WjLUjRD8cd91qlwJ%2Fimage.png?alt=media&amp;token=f975f5d1-2e67-4a89-82c9-decee1665d0a" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/scepman-nodepuroi/deployment-guides/scenarios/certificate-based-authentication-for-rdp.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
