Linking to the IIJ ID Service

By linking to the IIJ ID Service, not only operation managers but a person who has an IIJ ID Service account can manage the DNS platform service. Additionally, people who use an IIJ ID Service account can set reference and editing roles of zone information by contract zone at the granular level.

[ Reference ]

  • The IIJ ID Service is an ID management service (IDaaS) in the cloud that links to various service IDs enabling single sign-on (SSO).
  • Linking to or unlinking from the IIJ ID Service must be operated by an operations manager who has both permissions shown below. Refer to "登録が必要な担当者" (Japanese Only) from "ご利用にあたって" (Japanese Only) for IIJ Service Online for more information on each authority of an operations manager.
    • Management permission of this service
    • Management permission of the service group
  • Refer to "利用方法> 契約と担当者の管理" (Japanese Only) in "IIJサービスオンラインご利用にあたって" (Japanese Only) from "ご利用にあたって" (Japanese Only) for IIJ Service Online for how to check if you are an operations manager who has the management permission of the service group.

Linking to the IIJ ID Service

Use the following procedure to link to the IIJ ID Service.

  1. Log in to the control panel as an operations manager who has both permissions shown below. Refer to "Logging In" for more information on how to log in.

    • Management permission of this service
    • Management permission of the service group
  2. Open Dashboard.
  3. Select a service code (dpfxxxxxxxx) for the IIJ DNS Platform Service.
  4. Click "Link to IIJ ID Service."
  5. Click "Link."
  6. The login screen for the IIJ ID Service appears.
    Enter the account of the IIJ ID Service initial administrator in "ID," and then click the "Next" button.

    [ Note ]

    If you have logged in using an account other than that of the IIJ ID Service initial administrator, you cannot link to the IIJ ID Service.

    Click "" located in the upper right of the control panel to log out once, and then log out of the IIJ ID console (https://www.auth.iij.jp/console/) too. Then, redo the operation from step 1.

  7. Follow the instructions on the screen to enter the authentication information. The authentication information varies depending on the IIJ ID Service settings. Refer to the "IIJ ID Service Online Manual" for more information.

  8. Click "Approve."

After linking to the IIJ ID Service, roles can be set with respect to user and group accounts. After linking to the IIJ ID Service, it may take some time before you can set a role. Refer to "Assigning a Role to an IIJ ID Service Account" for more information on role types and how to set them.

[ Note ]

For the following group-related operations, it may take up to one hour for the settings to be reflected.

  • Assignment, change, and deletion of roles/authorities to the operations manager group
  • Addition and deletion of accounts to and from the operations manager group


Cancelling the Link with the IIJ ID Service

Use the following procedure to cancel the link with the IIJ ID Service.

[ Note ]

After cancelling the link with the IIJ ID Service, you can no longer log in to the control panel and perform service management using the IIJ ID service account.

In addition, you can cancel the link with the IIJ ID Service only when you are logged in as an operations manager. If you are logged in using an IIJ ID Service account, log out once and log in again as an operations manager.

  1. Log in to the control panel as an operations manager who has both permissions shown below. Refer to "Logging In" for more information on how to log in.
    • Management permission of this service
    • Management permission of the service group
  2. Open Dashboard.
  3. Select a service code (dpfxxxxxxxx) for the IIJ DNS Platform Service.
  4. Click "Link to IIJ ID Service."
  5. Click "UnLink."
  6. The login screen for the IIJ ID Service appears.
    Enter the account of the IIJ ID Service initial administrator in "ID," and then click "Next."

    [ Note ]

    If you have logged in using an account other than that of the IIJ ID Service initial administrator, you cannot cancel the link with the IIJ ID Service.

    Click "" located in the upper right of the control panel to log out once, and then log out of the IIJ ID console (https://www.auth.iij.jp/console/) too. Then, redo the operation from step 1.

  7. Follow the instructions on the screen to enter the authentication information. The authentication information varies depending on the IIJ ID Service settings. Refer to the "IIJ ID Service Online Manual" for more information.
  8. Click "Approve."


Assigning a Role to an IIJ ID Service Account
[ Note ]

It is recommended that you avoid managing permissions only by the initial administrator and assign an "Administrator" role to two or more persons.

After linking to the IIJ ID Service, you need to perform appropriate role management with respect to the operations manager’s IIJ ID Service account.

There is no function for taking over the role of the operations manager. When taking over the role and authority to a new operations manager, assign a role for each management target.

Use the following procedure to assign a role to an IIJ ID Service account.

  1. Select "Log in with IIJ ID" on the Login screen.

    [ Reference ]

    If you are logged in to the control panel, click "" located in the upper right of the control panel to log out, and then log in with the IIJ ID Service.

  2. The login screen for the IIJ ID Service appears.
    Enter the account of the IIJ ID Service initial administrator in "ID," and then click "Next."

    [ Note ]

    If you have logged in using an account other than that of the IIJ ID Service initial administrator, you cannot set a role for the first time.

    Click "" located in the upper right of the control panel to log out once, and then log out of the IIJ ID console (https://www.auth.iij.jp/console/) too. Then, redo the operation from step 1.

  3. Follow the instructions on the screen to enter the authentication information. The authentication information varies depending on the IIJ ID Service settings. Refer to the "IIJ ID Service Online Manual" for more information.
  4. Click "" located in the upper right of the control panel.
  5. Click "Authority Management Screen."

  6. Add authorities on the IIJ Authority Management console after screen transition.
    Refer to "Operation Method," "Settings for each service code for the management target and view management target," and "Examples of role settings by major purpose" shown below to configure desired settings.

Refer to "ロール及び権限の管理" (Japanese only) in the "IIJ権限管理コンソール マニュアル" (Japanese only) for more information on the list of roles and authorities.

[ Reference ]

  • The "Administrator" role is the initial administration role given to the initial administrator account for which Link to IIJ ID Service was executed with this service. The "Administrator" role can execute any operation.
    • If you log in to the Control Panel as an operations manager, you can have role contents that are the same as those for this role.
  • Since the following roles are not used for the IIJ DNS Platform Service, there is no need to configure the settings.
    • Staff
    • Billing Viewer
    • Operation Administrator
    • Operation Staff

Operation Method

Perform step 2 and subsequent steps in "Add roles or authorities" described in "ロール及び権限の管理" (Japanese only) in the "IIJ権限管理コンソール マニュアル." (Japanese only)

Settings for each service code for the management target and targets for view management

When adding authorities, the descriptions of management vary for each service code for the management target. The target descriptions of management are as follows.

Service code for the management target Description of management Notes
dpfxxxxxxxx Settings and view management for the following menus in "Service Management" on the control panel are targeted.
  • Service List
  • Common Settings
  • TSIG Key Management
  • Service Operation Log
  • Link to IIJ ID Service
Settings for the "Name Server Registration" menu for "Name Server Management" can be operated without the role for dpfxxxxxxxx.
dpmxxxxxxxx Settings and view management for the following menus in "Zone Management" on the control panel are targeted.
  • Record Management
  • DNSSEC Management
  • Zone Application History
  • Zone Proxy Management
  • Zone Operation Log
  • A role with respect to each "Zone Management" menu can be set for each zone.
  • Settings for the "Name Server Registration" menu in "Name Server Management" can be operated without the role for dpmxxxxxxxx.
dplxxxxxxxx

Settings and view management for the following menus in "Traffic Control" on the control panel are targeted.

  • Site Management
  • Monitoring Management
  • Rule Management
  • File Operation
  • Operation Log
  • The management permission for each menu in "Traffic Control" can be set for each dpl contract.
  • Settings for the "Name Server Registration" menu in "Name Server Management" can be operated without the role for dplxxxxxxxx.
Examples of role settings by major purpose

The role or authority to be given varies depending on the purpose of use. Examples of the role setting for each major purpose are as shown below.

No Purpose How to set the role to the target zone
1 To permit all types of management of the target zone, including Editing DNS Records Add the IIJ ID Service account of the relevant person in the "[Configuration] Update Role" to the target zone’s service code (dpmxxxxxxxx).
2 To permit only information references of the target zone (changes to DNS records are not permitted) Add the IIJ ID Service account of the relevant person in the "[Configuration] View Role" to the target zone’s service code (dpmxxxxxxxx).
Cancelling the Role Assigned to an IIJ ID Service Account

Use the following procedure to cancel the role setting that is assigned to an account linked to the IIJ ID Service.

  1. Select "Log in with IIJ ID" on the Login screen.

    [ Reference ]

    If you are logged in to the control panel, click "" located in the upper right of the control panel to log out once.

  2. The login screen for the IIJ ID Service appears.
    Enter the account of the IIJ ID Service in "ID," and click "Next."

    [ Note ]

    Log in to the zone whose role is to be cancelled, using the IIJ ID Service account to which any of the "[Contract] Authority Update Authority" and "[Configuration] Authority Update Authority" is set.

  3. Follow the instructions on the screen to enter the authentication information. The authentication information varies depending on the IIJ ID Service settings. Refer to the "IIJ ID Service Online Manual" for more information.
  4. Click "" located in the upper right of the control panel.
  5. Click "Authority Management Screen."
  6. Cancel roles or authorities on the IIJ Authority Management console after screen transition.
Operation Method

Perform step 2 and subsequent steps in "Cancel roles or authorities" described in "ロール及び権限の管理" (Japanese only) described in "IIJ権限管理コンソール マニュアル." (Japanese only)