Red Hat Enterprise Linux 4: ¥ê¥Õ¥¡¥ì¥ó¥¹¥¬¥¤¥É | ||
---|---|---|
Á°¤Î¥Ú¡¼¥¸ | ¾Ï 19¾Ï. Kerberos | ¼¡¤Î¥Ú¡¼¥¸ |
Kerberos¤ò¹½ÃÛ¤¹¤ë¤È¤¤Ï¡¢ºÇ½é¤Ë¥µ¡¼¥Ð¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£¥¹¥ì¡¼¥Ö¥µ¡¼¥Ð¡¼¤ò¹½ÃÛ¤¹¤ëɬÍפ¬¤¢¤ë¾ì¹ç¤Ë¤Ï¡¢¥Þ¥¹¥¿¡¼¤È¥¹¥ì¡¼¥Ö¥µ¡¼¥Ð¡¼¤Î´Ø·¸¤ò¹½ÃÛ¤¹¤ë¾ÜºÙ¤¬ /usr/share/doc/krb5-server-<version-number> ¥Ç¥£¥ì¥¯¥È¥ê¤Î Keberos 5 Installation Guide ¤Ë¤¢¤ê¤Þ¤¹¤Î¤Ç»²¾È¤·¤Æ¤¯¤À¤µ¤¤(<version-number> ¤ÎÉôʬ¤Ï¡¢¥·¥¹¥Æ¥à¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤¤¤ë krb5-server¥Ñ¥Ã¥±¡¼¥¸¤Î¥Ð¡¼¥¸¥ç¥óÈÖ¹æ¤òÆþ¤ì¤Æ¤¯¤À¤µ¤¤)¡£
´ðËÜŪ¤Ê Kerberos¥µ¡¼¥Ð¤òÀßÄꤹ¤ë¤Ë¤Ï¡¢°Ê²¼¤Î¥¹¥Æ¥Ã¥×¤Ë½¾¤¤¤Þ¤¹¡§
Kerberos 5¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ëÁ°¤Ë¡¢ »þ·×Ʊ´ü¤ÈDNS¤¬¤¹¤Ù¤Æ¤Î¥¯¥é¥¤¥¢¥ó¥È¤È¥µ¡¼¥Ð¡¼¾å¤Çµ¡Ç½¤·¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤Æ¤¯¤À¤µ¤¤¡£ Kerberos¥µ¡¼¥Ð¡¼¤È¤½¤Î¥¯¥é¥¤¥¢¥ó¥È´Ö¤Î»þ·×Ʊ´ü¤ÏÆÃ¤ËÃí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡£ Ëü°ì¡¢¥µ¡¼¥Ð¡¼¤È¥¯¥é¥¤¥¢¥ó¥È¤Î»þ·×¤Ë£µÊ¬°Ê¾å¤Î°ã¤¤¤¬¤¢¤ë¾ì¹ç(¤³¤Î¥Ç¥Õ¥©¥ë¥ÈÃÍ¤Ï Keberos 5 ¤ÇÀßÄê²Äǽ)¡¢ Kerberos¥¯¥é¥¤¥¢¥ó¥È¤Ï¥µ¡¼¥Ð¡¼¤Ëǧ¾Ú¤µ¤ì¤Þ¤»¤ó¡£ ¤³¤Î»þ·×Ʊ´ü¤Ï¡¢ Àµµ¬¤Î¥æ¡¼¥¶¡¼¤Èµ¶¤Ã¤Æ¸Å¤¤Kerberos ¥Á¥±¥Ã¥È¤òÍѤ¤¤ë¥¢¥¿¥Ã¥«¡¼¤òËɻߤ¹¤ë¤¿¤á¤ËɬÍפǤ¹¡£
Keberos¤òÍѤ¤¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ç¤â¡¢ ¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¥¯¥é¥¤¥¢¥ó¥È/¥µ¡¼¥Ð¡¼¸ß´¹¤Î NTP (Network Time Protocol) ¤òÀßÄꤷ¤¿Êý¤¬¤è¤¤¤Ç¤·¤ç¤¦¡£ ¤³¤Î¤¿¤á¤Ë¡¢Red Hat Enterprise Linux¤Ë¤Ïntp¥Ñ¥Ã¥±¡¼¥¸¤¬´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£ Network Time Protocol¥µ¡¼¥Ð¤ÎÀßÄê¤Ë¤Ä¤¤¤Æ¤Î¾ÜºÙ¤Ï¡¢ /usr/share/doc/ntp-<version-number>/index.htm¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£ NTP¤Ë´Ø¤¹¤ë¤½¤Î¾¤Î¾ðÊó¤Ï¡¢ http://www.eecis.udel.edu/~ntp¤ò¤´Í÷¤¯¤À¤µ¤¤¡£
KDC¤ò¼Â¹Ô¤¹¤ëÀìÍÑ¥Þ¥·¥ó¤Ë¡¢krb5-libs¡¢ krb5-server¡¢krb5-workstation¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£ ¤³¤Î¥Þ¥·¥ó¤ÏÆÃ¤Ë°ÂÁ´¤¬³ÎÊݤµ¤ì¤ë¤³¤È¤¬É¬ÍפǤ¹¡£ — ¤Ç¤¤ì¤Ð KDC °Ê³°¤Î¥µ¡¼¥Ó¥¹¤Ï¼Â¹Ô¤·¤Ê¤¤¤Ç¤¯¤À¤µ¤¤¡£
Kerberos¤ò´ÉÍý¤¹¤ë¤Î¤Ë¡¢GUI(Graphical User Interface)¤¬É¬Íפʾì¹ç¤Ï¡¢ gnome-kerberos¥Ñ¥Ã¥±¡¼¥¸¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤¯¤À¤µ¤¤¡£ ¤³¤Î¥Ñ¥Ã¥±¡¼¥¸¤Ë¤Ï¡¢krb5¤È¤¤¤¦¥Á¥±¥Ã¥È¤ò´ÉÍý¤¹¤ëGUI¥Ä¡¼¥ë¤¬´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£
realm ̾¤È¥É¥á¥¤¥ó-realm´Ö¥Þ¥Ã¥Ô¥ó¥°¤òÈ¿±Ç¤¹¤ë¤¿¤á¤Ë¤Ï¡¢/etc/krb5.conf¤È /var/keberos/krb5kdc/kdc.conf ÀßÄê¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Æ¤¯¤À¤µ¤¤¡£Ã±½ã¤Ê realm ¤Ê¤é¡¢EXAMPLE.COM¤Èexample.com ¥¤¥ó¥¹¥¿¥ó¥¹¤ÎÉôʬ¤Ë¡¢ Àµ¤·¤¤¥É¥á¥¤¥ó̾ (Âçʸ»ú¡¢¾®Ê¸»ú¤¬Àµ¤·¤¤¤«³Îǧ¤·¤Æ¤¯¤À¤µ¤¤) ¤òÆþ¤ì¡¢ KDC ¤òkerberos.example.com¤«¤é Kerberos ¥µ¡¼¥Ð¡¼Ì¾ ¤ËÊѹ¹¤¹¤ë¤³¤È¤Ç¡¢¹½ÃۤǤ¤Þ¤¹¡£´·Îã¤Ç¤Ï¡¢Á´¤Æ¤Î realm ̾¤ÏÂçʸ»ú¤Ç¡¢DNS ¥Û¥¹¥È̾¤È¥É¥á¥¤¥ó̾¤Ï¾®Ê¸»ú¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤éÀßÄê¥Õ¥¡¥¤¥ë¤Î·Á¼°¤Î¾ÜºÙ ¤Ë¤Ä¤¤¤Æ¤Ï¡¢³ºÅö¤¹¤ë man ¥Ú¡¼¥¸¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£
¥·¥§¥ë¥×¥í¥ó¥×¥È¤«¤ékrb5_util¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤ò»È¤Ã¤Æ¥Ç¡¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡§
/usr/kerberos/sbin/kdb5_util create -s |
create¥³¥Þ¥ó¥É¤Ï¡¢ Kerberos realm ¤Î¸°¤ò³ÊǼ¤¹¤ë¤¿¤á¤Î ¥Ç¡¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡£-s¥¹¥¤¥Ã¥Á¤Ï¡¢¥Þ¥¹¥¿¡¼¥µ¡¼¥Ð¡¼¸°¤ò³ÊǼ¤¹¤ëstash¥Õ¥¡¥¤¥ë¤òºîÀ®¤ò¶¯À©¤·¤Þ¤¹¡£ ¸°¤òÆÉ¤à¤¿¤á¤Î stash ¥Õ¥¡¥¤¥ë¤¬Ìµ¤¤¾ì¹ç¤Ï¡¢Kerberos ¥µ¡¼¥Ð¡¼( krb5kdc)¤Ïµ¯Æ°¤¹¤ëÅ٤ˡ¢¥æ¡¼¥¶¡¼¤Ë¥Þ¥¹¥¿¡¼¥µ¡¼¥Ð¡¼¥Ñ¥¹¥ï¡¼¥É(¸°¤ò ºÆÀ¸À®¤¹¤ë¤Î¤Ë»ÈÍÑ)¤ÎÆþÎϤòÂ¥¤·¤Þ¤¹¡£
/var/kerberos/krb5kdc/kadm5.acl¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Þ¤¹¡£ ¤³¤Î¥Õ¥¡¥¤¥ë¤Ïkadmind¤Ç»ÈÍѤµ¤ì¡¢ ¤É¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤¬ Kerberos ¥Ç¡¼¥¿¥Ù¡¼¥¹¤Ë´ÉÍý¥¢¥¯¥»¥¹¤ò»ý¤Ä¤«¤ò·èÄꤷ¡¢ ¤Þ¤¿¡¢¤½¤ì¤¾¤ì¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤Î¥¢¥¯¥»¥¹¥ì¥Ù¥ë¤ò·èÄꤷ¤Þ¤¹¡£ ¤Û¤È¤ó¤É¤Î´ë¶È¡¢ÃÄÂΤǰʲ¼¤ÎÍͤʰì¹Ô¤ÇÊÔ½¸¤¹¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
*/admin@EXAMPLE.COM * |
¤Û¤È¤ó¤É¤Î¥æ¡¼¥¶¡¼¤Ï¡¢¥Ç¡¼¥¿¥Ù¡¼¥¹Æâ¤Ëñ°ì¤Î¥×¥ê¥ó¥·¥Ñ¥ë (Î㤨¤Ðjoe@EXAMPLE.COM¤Î¤è¤¦¤Ë¡¢NULL¡¢ ¶õ¡¢¥¤¥ó¥¹¥¿¥ó¥¹¤Ê¤É¡Ë¤Çɽ¼¨¤µ¤ì¤Þ¤¹¡£¤³¤ÎÀßÄê¤òÍѤ¤¤Æ¡¢admin¤Î¥¤¥ó¥¹¥¿¥ó¥¹¤¬Â裲¥×¥ê¥ó¥·¥Ñ¥ë¤Ç¤¢¤ë¥æ¡¼¥¶¡¼¤Ï (Îã¡¢joe/admin@EXAMPLE.COM)¡¢ realm ¤Î Kerberos ¥Ç¡¼¥¿¥Ù¡¼¥¹¾å¤ÇÁ´¸¢¸Â¤ò¹Ô»È¤¹¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
°ìö¡¢kadmind¤¬¥µ¡¼¥Ð¡¼¾å¤Çµ¯Æ°¤¹¤ë¤È¡¢realm Æâ¤Î¥¯¥é¥¤¥¢¥ó¥È¤ä¥µ¡¼¥Ð¡¼¤«¤ékadmin¤ò¼Â¹Ô¤¹¤ë»ö¤Ç¡¢¤É¤Î¥æ¡¼¥¶¡¼¤â¤½¤Î¥µ¡¼¥Ó¥¹¤Ë¥¢¥¯¥»¥¹¤Ç¤¤Þ¤¹¡£¤·¤«¤·¡¢kadm5.acl¥Õ¥¡¥¤¥ë¤ËµºÜ¤µ¤ì¤Æ¤¤¤ë¥æ¡¼¥¶¤À¤±¤¬¡¢¼«¿È¤Î¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹¤ò½ü¤¡¢¤É¤Î¤è¤¦¤ÊÊѹ¹¤â¥Ç¡¼¥¿¡¼¥Ù¡¼¥¹¤ËÂФ·¤Æ¹Ô¤¨¤Þ¤¹¡£
![]() | Ãíµ |
---|---|
kadmin¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤Ï¡¢ ¥Í¥Ã¥È¥ï¡¼¥¯¤ò²ð¤·¤Ækadmind¥µ¡¼¥Ð¡¼¤ÈÄÌ¿®¤·¤Æ¤ª¤ê¡¢ Kerberos¤ò»È¤Ã¤ÆÇ§¾Ú¤ò½èÍý¤·¤Þ¤¹¡£ ¤³¤Î¤¿¤á¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤ò²ð¤·¤Æ¥µ¡¼¥Ð¡¼¤ËÀܳ¤¹¤ëÁ°¤Ë¡¢ ¤½¤ì¤ò´ÉÍý¤¹¤ëºÇ½é¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤¬Â¸ºß¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£ kadmin.local¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤ÆºÇ½é¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤·¤Þ¤¹¡£ ¤³¤ì¤ÏÆÃ¤ËKDC¤ÈƱ¤¸¥Û¥¹¥È¤Ç»ÈÍѤ¹¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤ª¤ê¡¢ ǧ¾Ú¤ËKerberos¤ò»ÈÍѤ·¤Þ¤»¤ó¡£ |
Âè°ì¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤¹¤ë¤Ë¤Ï¡¢KDC¥¿¡¼¥ß¥Ê¥ë¤Ç¼¡¤Îkadmin.local¥³¥Þ¥ó¥É¤ò ÆþÎϤ·¤Þ¤¹¡§
/usr/kerberos/sbin/kadmin.local -q "addprinc username/admin" |
°Ê²¼¤Î¥³¥Þ¥ó¥É¤ÇKerberos¤òµ¯Æ°¤·¤Þ¤¹¡§
/sbin/service krb5kdc start /sbin/service kadmin start /sbin/service krb524 start |
kadmin¤Çaddprinc¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Æ ¥æ¡¼¥¶¡¼¤Î¤¿¤á¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤òÄɲä·¤Þ¤¹¡£ kadmin¤Èkadmin.local ¤Ï KDC ¤Î ¥³¥Þ¥ó¥É¥é¥¤¥ó¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹¤Ç¤¹¡£ ¤³¤ÎÃæ¤Ç¤Ï¡¢kadmin¥×¥í¥°¥é¥à¤òµ¯Æ°¤·¤¿¸å¤Ë¿¤¯¤Î¥³¥Þ¥ó¥É¤¬ÍøÍѤǤ¤Þ¤¹¡£ ¾ÜºÙ¤Ïkadmin¤Îman ¥Ú¡¼¥¸¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£
KDC ¤¬¥Á¥±¥Ã¥È¤òȯ¹Ô¤·¤Æ¤¤¤ë¤«³Îǧ¤·¤Þ¤¹¡£ ºÇ½é¤Ë¡¢kinit¤ò¼Â¹Ô¤·¤Æ¥Á¥±¥Ã¥È¤òÀ¸À®¤·¡¢ ¾ÚÌÀ½ñ¥¥ã¥Ã¥·¥å¥Õ¥¡¥¤¥ë¤Ë³ÊǼ¤·¤Þ¤¹¡£ ¤½¤ì¤«¤é¡¢klist¤ò»ÈÍѤ·¤Æ¥¥ã¥Ã¥·¥åÆâ¤Î¾ÚÌÀ½ñ°ìÍ÷¤òɽ¼¨¤·¤Þ¤¹¡£ kdestroy¤òÍѤ¤¤Æ¡¢¥¥ã¥Ã¥·¥å¤È¥¥ã¥Ã¥·¥åÆâ¤Î¾ÚÌÀ½ñ¤òÇË´þ¤·¤Þ¤¹¡£
![]() | Ãíµ |
---|---|
¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¡¢kinit¤Ï¡¢¥·¥¹¥Æ¥à(Kerberos¥µ¡¼¥Ð¡¼¤Ç¤Ï¤Ê¤¤¡Ë¤Ë¥í¥°¥¤¥ó¤·¤¿»þ¤Ë»È¤Ã¤¿¥í¥°¥¤¥ó¥æ¡¼¥¶¡¼Ì¾¤òÍѤ¤¤ÆÇ§¾Ú¤·¤è¤¦¤È¤·¤Þ¤¹¡£¤½¤Î¥æ¡¼¥¶¡¼Ì¾¤¬ Kerberos ¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤È°ìÃפ·¤Ê¤¤¾ì¹ç¤Ï¡¢ kinit¤Ï¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤òȯ¹Ô¤·¤Þ¤¹¡£¤³¤Î¤è¤¦¤Ê¾ì¹ç¡¢ ¥³¥Þ¥ó¥É¥é¥¤¥ó¤Ë°ú¿ô¤È¤·¤ÆÅ¬Àڤʥץê¥ó¥·¥Ñ¥ë¤Î̾Á°¤ò¤Ä¤±¤Æ¡¢kinit ¤ËÍ¿¤¨¤Þ¤¹¡£(kinit <principal>) |
°Ê¾å¤Î¥¹¥Æ¥Ã¥×¤ò´°Î»¤¹¤ë¤È¡¢Kerberos¥µ¡¼¥Ð¡¼¤Ïµ¯Æ°¤·ºîư¤·¤Æ¤ë¤Ï¤º¤Ç¤¹¡£
Á°¤Î¥Ú¡¼¥¸ | ¥Û¡¼¥à | ¼¡¤Î¥Ú¡¼¥¸ |
Kerberos ¤È PAM | ¾å¤ËÌá¤ë | Kerberos 5¥¯¥é¥¤¥¢¥ó¥È¤ÎÀßÄê |