nss_ldap¤ò»ÈÍѤ·¤Æ¤¤¤ë»þ¤ËLDAP¥µ¡¼¥Ð¤¬Íî¤Á¤Æ¤¤¤ë¤È¥í¥°¥¤¥ó¤Ë»þ´Ö¤¬¤«¤«¤ë¡£
¤Á¤Ê¤ß¤Ë¤½¤Î»þ¤Î¥í¥°¤Ï¤³¤ó¤Ê´¶¤¸¡£
sshd[29123]: nss_ldap: failed to bind to LDAP server ldap://xxx: Can't contact LDAP server
sshd[29123]: nss_ldap: could not search LDAP server - Server is unavailable
¤Ç¤³¤¤¤Ä¤ò²óÈò¤¹¤ë¤Ë¤ÏÀßÄê¥Õ¥¡¥¤¥ë¤Ê¤É¤Ç¤Ï̵Íý¤Ê¤Î¤Çnss_ldap¤Î¥½¡¼¥¹¤ò½¤Àµ¤·¡¢
¥ê¥³¥ó¥Ñ¥¤¥ë¡¢ºÆ¥¤¥ó¥¹¥È¡¼¥ë¤È¤¤¤¦ºî¶È¤¬È¯À¸¤·¤Æ¤·¤Þ¤¦¡£
¤Á¤Ê¤ß¤Ë¥½¡¼¥¹¤Î½¤Àµ²Õ½ê¤Ï°Ê²¼¡£
ldap-nss.h
#define LDAP_NSS_TRIES 5 /* number of sleeping reconnect attempts */
#define LDAP_NSS_SLEEPTIME 4 /* seconds to sleep; doubled until max */
#define LDAP_NSS_MAXSLEEPTIME 64 /* maximum seconds to sleep */
#define LDAP_NSS_MAXCONNTRIES 2 /* reconnect attempts before sleeping */
¤³¤¤¤Ä¤é¤òŬÀµÃͤËÊѹ¹¤·¤Æ¤¢¤²¤ì¤Ð¤è¤¤¡£
¤Ç¤½¤Î¸å¤Ë¡¢
./configrue
make
make installl
¤³¤ì¤ÇºÆ¥¤¥ó¥¹¥È¡¼¥ë´°Î»¡£
´Êñ¤À¤±¤ÉÌÌÅݤʺî¶È¤Ç¤·¤¿¡£
°Ê¾å¡£
¤Á¤Ê¤ß¤Ë¤½¤Î»þ¤Î¥í¥°¤Ï¤³¤ó¤Ê´¶¤¸¡£
sshd[29123]: nss_ldap: failed to bind to LDAP server ldap://xxx: Can't contact LDAP server
sshd[29123]: nss_ldap: could not search LDAP server - Server is unavailable
¤Ç¤³¤¤¤Ä¤ò²óÈò¤¹¤ë¤Ë¤ÏÀßÄê¥Õ¥¡¥¤¥ë¤Ê¤É¤Ç¤Ï̵Íý¤Ê¤Î¤Çnss_ldap¤Î¥½¡¼¥¹¤ò½¤Àµ¤·¡¢
¥ê¥³¥ó¥Ñ¥¤¥ë¡¢ºÆ¥¤¥ó¥¹¥È¡¼¥ë¤È¤¤¤¦ºî¶È¤¬È¯À¸¤·¤Æ¤·¤Þ¤¦¡£
¤Á¤Ê¤ß¤Ë¥½¡¼¥¹¤Î½¤Àµ²Õ½ê¤Ï°Ê²¼¡£
ldap-nss.h
#define LDAP_NSS_TRIES 5 /* number of sleeping reconnect attempts */
#define LDAP_NSS_SLEEPTIME 4 /* seconds to sleep; doubled until max */
#define LDAP_NSS_MAXSLEEPTIME 64 /* maximum seconds to sleep */
#define LDAP_NSS_MAXCONNTRIES 2 /* reconnect attempts before sleeping */
¤³¤¤¤Ä¤é¤òŬÀµÃͤËÊѹ¹¤·¤Æ¤¢¤²¤ì¤Ð¤è¤¤¡£
¤Ç¤½¤Î¸å¤Ë¡¢
./configrue
make
make installl
¤³¤ì¤ÇºÆ¥¤¥ó¥¹¥È¡¼¥ë´°Î»¡£
´Êñ¤À¤±¤ÉÌÌÅݤʺî¶È¤Ç¤·¤¿¡£
°Ê¾å¡£
![]() | LDAP Super Expert (2006/04/11) ÊÔ½¸Éô ¾¦Éʾܺ٤ò¸«¤ë OpenLDAP ver2.3¤Î¿·µ¡Ç½¤Ê¤É¤Ë¤Ä¤¤¤Æ¾Ü¤·¤¯½ñ¤«¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¤¤¤¯¤Ä¤«¤Î¥ß¥É¥ë¥¦¥§¥¢Ï¢·È¤Î¾¡¢OpenSSH¸°Ç§¾ÚLDAP²½¤äsudo¤ÎLDAP²½¤Þ¤Ç½ñ¤«¤ì¤Æ¤¤¤Æ¤¤¤ë¤Î¤¬Èó¾ï¤ËÌòΩ¤Ä¡£ |
¼ç¤ËNWµ¡´ï¤Îǧ¾Ú¤âLDAP¤ËǤ¤»¤¿¤¤¡¢
¤Ã¤Æ»þ¤Ë¤è¤¯¤¢¤ëRADIUS¤È¤ÎÏ¢·È¤Ë¤Ä¤¤¤ÆÅ»¤á¤Æ¤ß¤Þ¤¹¡£
¤Á¤Ê¤ß¤ËLDAP¤Ï´û¤Ë¹½ÃۺѤߤÇÀµ¾ï¤Ëưºî¤·¤Æ¤¤¤ë¤â¤Î¤È¤·¤Þ¤¹¡£
RADIUS¤Ë¤Ä¤¤¤Æ¤ÏFreeRADIUS¤ò»ÈÍѤ·¤Þ¤·¤¿¡£
¤Ç¤Ï½ç¤òÄɤäÆÀâÌÀ¡£
¡. FreeRADIUS¤Î¥¤¥ó¥¹¥È¡¼¥ë¡£
# cd /usr/local/src/
# tar zxvf freeradius-1.1.7.tar.gz
# cd ./freeradius-1.1.7
# ./configure --prefix=/usr/local/radius¡¡¢«¡¡¤³¤³¤Ï¤ª¹¥¤ß¤Ç
# make
# make install
°Ê¾å¤Ç¥¤¥ó¥¹¥È¡¼¥ë¤Î´°Î»¡£
¤Þ¤º¡¢LDAP¤ÈÏ¢·È¤µ¤»¤ëÁ°¤Ë¥í¡¼¥«¥ë¥æ¡¼¥¶¡¼¤È¤ÎÏ¢·È¤¬²Äǽ¤«³Îǧ¡£
º£²ó¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿FreeRADIUS¤Ï¥Ç¥Õ¥©¥ë¥È¤Ç¥í¡¼¥«¥ëUnix¥æ¡¼¥¶¡¼¤ò
¸«¤Ë¹Ô¤¯ÀßÄê¤Ë¤Ê¤Ã¤Æ¤¤¤ë°Ù¡¢RADIUS¦¤ÎÀßÄê¤ÏÉÔÍפǤ·¤¿¡£
¢. ¥í¡¼¥«¥ë¥¢¥«¥¦¥ó¥È¤Ëtest¥æ¡¼¥¶¡¼¤òÄɲ乤롣
# uesradd test
# passwd test
--------------------------------------------------------------------------
Changing password for user test.
New UNIX password:¡¡¢«¡¡test¤ÈÆþÎÏ
BAD PASSWORD: it is too short
Retype new UNIX password:¡¡¢«¡¡test¤ÈÆþÎÏ
passwd: all authentication tokens updated successfully.
--------------------------------------------------------------------------
£. RADIUS¤ò¥Ç¥Ð¥Ã¥¯¥â¡¼¥É¤Ë¤Æµ¯Æ°¡£
# radiusd -X -A
--------------------------------------------------------------------------------
¡Á°Ê¾å¾Êά
¡¡Module: Loaded radutmp
radutmp: filename = "/usr/local/radius/var/log/radius/radutmp"
radutmp: username = "%{User-Name}"
radutmp: case_sensitive = yes
radutmp: check_with_nas = yes
radutmp: perm = 384
radutmp: callerid = yes
Module: Instantiated radutmp (radutmp)
Listening on authentication *:1812
Listening on accounting *:1813
Ready to process requests.
---------------------------------------------------------------------------------
Àµ¾ï¤Ëµ¯Æ°¤·¤¿¤³¤È¤ò³Îǧ¡£
£. Ê̤Υ³¥ó¥½¡¼¥ë¤«¤é¡¢radtest¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤ÆÇ§¾Ú¤¬Ä̤뤫³Îǧ¤¹¤ë¡£
# radtest test test localhost 1 testing123
¥ª¥×¥·¥ç¥óÀâÌÀ
[user̾]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¡¡Ç§¾Ú¤ò¹Ô¤¦¥æ¡¼¥¶¡¼Ì¾
[password]¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¡¡Âбþ¤¹¤ë¥Ñ¥¹¥ï¡¼¥É
[server̾]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡Ì䤤¹ç¤ï¤»¤ë¥µ¡¼¥Ð̾
[nas-port-number]¡¡¡¡¡¡NAS¥Ý¡¼¥ÈÈÖ¹æ
[secret]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¶¦Í¸°
--------------------------------------------------------------------------------------
Sending Access-Request of id 118 to 127.0.0.1 port 1812
User-Name = "test"
User-Password = "test"
NAS-IP-Address = 255.255.255.255
NAS-Port = 1
rad_recv: Access-Accept packet from host 127.0.0.1:1812, id=118, length=20
--------------------------------------------------------------------------------------
Access-Accept¥Ñ¥±¥Ã¥È¤¬Ê֤äƤ¤Æ¡¢Ç§¾Ú¤¬Ä̤俤³¤È¤ò³Îǧ¡£
¤Á¤Ê¤ß¤Ë¡¢¥µ¡¼¥Ð¦¤Î¥Ç¥Ð¥Ã¥¯¥í¥°¤Ç¤Ï°Ê²¼¤Î¤è¤¦¤Ëɽ¼¨¤µ¤ì¤ë¡£
---------------------------------------------------------------------------
¡Á°Ê¾å¾Êά
Sending Access-Accept of id 118 to 127.0.0.1 port 32770
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 6 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 118 with timestamp 473bf3ce
Nothing to do. Sleeping until we see a request.
----------------------------------------------------------------------------
¤. radtest¤Çǧ¾Ú¤Ë¼ºÇÔ¤·¤¿¾ì¹ç¤ò³Îǧ¤¹¤ë¡£
# radtest test password localhost 1 testing123
-----------------------------------------------------------------------------------
Sending Access-Request of id 251 to 127.0.0.1 port 1812
User-Name = "test"
User-Password = "passwd"
NAS-IP-Address = 255.255.255.255
NAS-Port = 1
rad_recv: Access-Reject packet from host 127.0.0.1:1812, id=251, length=20
----------------------------------------------------------------------------------
¥Ñ¥¹¥ï¡¼¥É¤¬´Ö°ã¤Ã¤Æ¤¤¤ë¤¿¤á¡¢Access-Reject¥Ñ¥±¥Ã¥È¤¬Ê֤äƤ¤Æ¡¢Ç§¾Ú¤¬
¼ºÇÔ¤·¤Æ¤¤¤ë»ö¤ò³Îǧ¡£¥µ¡¼¥Ð¦¤Î¥Ç¥Ð¥Ã¥°¥í¥°¤Ç¤Ï°Ê²¼¤Î¤è¤¦¤Ëɽ¼¨¤µ¤ì¤ë¡£
------------------------------------------------------------------------
¡Á°Ê¾å¾Êά
auth: Failed to validate the user.
Delaying request 0 for 1 seconds
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Sending Access-Reject of id 251 to 127.0.0.1 port 32770
Waking up in 4 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 251 with timestamp 473bf4fd
Nothing to do. Sleeping until we see a request.
-------------------------------------------------------------------------
°Ê¾å¤Ç¥í¡¼¥«¥ë¥¢¥«¥¦¥ó¥È¤ÎRADIUSǧ¾Ú¤Î³Îǧ¤Ï´°Î»¤Ç¤¢¤ë¡£
¼¡¤Ë¡¢RADIUS¤¬LDAP¥æ¡¼¥¶¡¼¤ò¸«¤Ë¹Ô¤¯¤è¤¦¤ËÀßÄê¤ò¤¹¤ë¡£
¥. radius.conf¤òLDAPÂбþ¤Î¤¿¤á¡¢°Ê²¼¤Î¤è¤¦¤ËÊÔ½¸¤¹¤ë¡£
¡¡¡¡LDAP¥µ¡¼¥Ð¼þ¤ê¤ÎÀßÄê¤Ï³Æ´Ä¶¤Ë¤è¤Ã¤Æ°ã¤¦¤Î¤ÇŬÅö¤Ë¹ç¤ï¤»¤ë¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¡Á°Ê¾å¾Êά
ldap {
server = "LDAP¥µ¡¼¥Ð¤ÎIP"
identity = "cn=Manager,dc=my-domain,dc=com"
password = secret
basedn = "dc=my-domain,dc=com"
filter = "(uid=%{Stripped-User-Name:-%{User-Name}})"
start_tls = yes
tls_cacertdir = /etc/openldap/cacerts/
¡ÁÅÓÃæ¾Êά
authenticate {
Auth-Type PAP {
pap
}
Auth-Type CHAP {
chap
}
Auth-Type MS-CHAP {
mschap
}
unix
Auth-Type LDAP {¡¡¢«¡¡¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤¹
ldap¡¡¢«¡¡¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤¹
}¡¡¢«¡¡¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤¹
eap
}
¡Á°Ê²¼¾Êά
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¦. users¤ò°Ê²¼¤Î¤è¤¦¤ËÊÔ½¸¤·¡¢LDAPǧ¾Ú¤ò¥Ç¥Õ¥©¥ë¥È¤ËÊѹ¹¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
DEFAULT Auth-Type = LDAP¡¡¢«¡¡System¤«¤éÊѹ¹
Fall-Through = 1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
§. clients.conf¤ò°Ê²¼¤Î¤è¤¦¤ËÊÔ½¸¤·client¤Î°¤¹¤ë¥»¥°¥á¥ó¥È¤«¤é¤Î¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
client ¥¯¥é¥¤¥¢¥ó¥È¤Î°¤¹¤ë¥Í¥Ã¥È¥ï¡¼¥¯¥¢¥É¥ì¥¹/24{
secret = testing123 ¢«¡¡¶¦Í¸°
shortname = localhost¡¡¢«¡¡¥í¥°¥Õ¥¡¥¤¥ë¤ÎÃæ¤Ç»È¤¦Ì¾¾Î
}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¨. slapd¤ò¥Ç¥Ð¥Ã¥¯¥â¡¼¥É¤ÇΩ¤Á¾å¤²¡£
# slapd -d 1
©. RADIUS¤ò¥Ç¥Ð¥Ã¥¯¥â¡¼¥É¤ÇºÆµ¯Æ°¡£
# Ctrl-C¤ÇÀèÄøÎ©¤Á¾å¤²¤¿RADIUS¤ò¥¹¥È¥Ã¥×
# radiusd -X -A
ª. radtest¤ÇLDAP¥æ¡¼¥¶¡¼¤Îǧ¾Ú¤¬Ä̤뤫³Îǧ¡£
# radtest testUser password LDAP¥µ¡¼¥Ð¤ÎIP 1 testing123
-------------------------------------------------------------------------------------------
Sending Access-Request of id 118 to RADIUS(LDAP)¥µ¡¼¥Ð¤ÎIP port 1812
User-Name = "testUser"
User-Password = "password"
NAS-IP-Address = 255.255.255.255
NAS-Port = 1
rad_recv: Access-Accept packet from host RADIUS(LDAP)¥µ¡¼¥Ð¤ÎIP:1812, id=118, length=20
-------------------------------------------------------------------------------------------
Access-Accept¥Ñ¥±¥Ã¥È¤¬Ê֤äƤ¤Æ¡¢Ç§¾Ú¤¬Ä̤俤³¤È¤ò³Îǧ¡£
¤Á¤Ê¤ß¤Ë¡¢¥µ¡¼¥Ð¦¤Î¥Ç¥Ð¥Ã¥°¥í¥°¤â³Îǧ¤·¤Æ¤ª¤¯¤È¡¢Ç§¾Ú¤Îή¤ì¤¬¤è¤¯Ê¬¤«¤ë¤«¤È¡£
radiusd¤¬radtest¤Ë¤è¤Ã¤ÆÇ§¾Ú°ÍÍê¤ò¼õ¤±¤ë¤È¡¢radiusd¤«¤éslapd¤Ø¤Î¸¡º÷¤¬¤«¤«¤ë¡£
¤Þ¤¿¡¢StartTLS¤â͸ú¤Ë¤·¤Æ¤¤¤ë¤¿¤á¡¢SSL¾ÚÌÀ½ñ¤Î¤ä¤ê¼è¤ê¤â¸«¤ì¤ë¤Ï¤º¡£
¥í¥°¤ÎÎ̤¬Â¿¤¤¤¿¤áºÜ¤»¤Æ¤Ê¤¤¤¹¤¬¤¬¡¢°ìÅÙ³Îǧ¤·¤Æ¤ª¤¯¤È¤¤¤¤¤«¤â¡£
°Ê¾å¤Ç¡¢RADIUS¤ÈLDAP¤ÎÏ¢·È¤¬´°Î»¡£
¤³¤³¤«¤é¤ÏNWµ¡´ï¦¤ÎÀßÄê¡£
¤Á¤Ê¤ß¤Ë¸¡¾Ú¤Ë»ÈÍѤ·¤¿¥¹¥¤¥Ã¥Á¤ÏCisco¤ÎCatalyst3560G¤Ç¤¢¤ë¡£
¥¹¥¤¥Ã¥Á¦¤Ï½é´ü²½¾õÂÖ(startup-config¤Ê¤·)¤Î¾õÂÖ¤«¤é»Ï¤á¤ë¡£
«. ¥³¥ó¥Õ¥£¥°¥â¡¼¥É¤ÇRADIUS¥¯¥é¥¤¥¢¥ó¥È¤È¤·¤Æ¤ÎÀßÄê¤ò¹Ô¤¦¡£
Switch(config)#aaa new-model
Switch(config)#aaa authentication login default group radius local
Switch(config)#radius-server host RADIUS(LDAP)¥µ¡¼¥Ð¤ÎIP auth-port 1812 acct-port 1813
Switch(config)#radius-server key testing123¡¡¢«¡¡¶¦Í¸°
¡ôǧ¾Ú¥Ý¡¼¥È¤È¥¢¥«¥¦¥Æ¥£¥ó¥°¥Ý¡¼¥È¤Ï¡¢ÌÀ¼¨Åª¤Ë»ØÄê
¬. ǰ¤Î°Ù¡¢ÄÌ¿®¤Ë¼ºÇÔ¤·¤¿¾ì¹ç¤ËÈ÷¤¨¤Æ¥í¡¼¥«¥ë¥æ¡¼¥¶¡¼(´ÉÍý¼Ô¸¢¸Â¤Ç¡Ë¤òºîÀ®¤·¤Æ¤ª¤¯¡£
Switch(config)#username test privilege 15 password test
. °ìÅÙ¥í¥°¥¢¥¦¥È¤·¡¢LDAP¥æ¡¼¥¶¡¼¤Ç¥í¥°¥¤¥ó²Äǽ¤«¤É¤¦¤«³Îǧ¤·¤Æ¤ß¤ë¡£
User Access Verification
Username: testUser
Password:¡¡¢«¡¡password¤ÈÆþÎÏ
Switch>
Àµ¾ï¤Ë¥í¥°¥¤¥ó½ÐÍè¤ë¤³¤È¤ò³Îǧ¤Ç¤¤¿¡£
¤Á¤Ê¤ß¤Ë¤Ç¤¹¤¬¡¢RADIUS¤È¤ÎÁÂÄ̤¬²Äǽ¤Ê¾õÂ֤ǤϺîÀ®¤·¤¿¥í¡¼¥«¥ë¥æ¡¼¥¶¡¼¤Ï
¥í¥°¥¤¥ó½ÐÍè¤Þ¤»¤ó¡£RADIUS¤È¤ÎÄÌ¿®¤¬½ÐÍè¤Ê¤¤¶ÛµÞ»þ¤Î¤ß»ÈÍѲÄǽ¤Ç¤¹¡£
¤Ã¤Æ»þ¤Ë¤è¤¯¤¢¤ëRADIUS¤È¤ÎÏ¢·È¤Ë¤Ä¤¤¤ÆÅ»¤á¤Æ¤ß¤Þ¤¹¡£
¤Á¤Ê¤ß¤ËLDAP¤Ï´û¤Ë¹½ÃۺѤߤÇÀµ¾ï¤Ëưºî¤·¤Æ¤¤¤ë¤â¤Î¤È¤·¤Þ¤¹¡£
RADIUS¤Ë¤Ä¤¤¤Æ¤ÏFreeRADIUS¤ò»ÈÍѤ·¤Þ¤·¤¿¡£
¤Ç¤Ï½ç¤òÄɤäÆÀâÌÀ¡£
¡. FreeRADIUS¤Î¥¤¥ó¥¹¥È¡¼¥ë¡£
# cd /usr/local/src/
# tar zxvf freeradius-1.1.7.tar.gz
# cd ./freeradius-1.1.7
# ./configure --prefix=/usr/local/radius¡¡¢«¡¡¤³¤³¤Ï¤ª¹¥¤ß¤Ç
# make
# make install
°Ê¾å¤Ç¥¤¥ó¥¹¥È¡¼¥ë¤Î´°Î»¡£
¤Þ¤º¡¢LDAP¤ÈÏ¢·È¤µ¤»¤ëÁ°¤Ë¥í¡¼¥«¥ë¥æ¡¼¥¶¡¼¤È¤ÎÏ¢·È¤¬²Äǽ¤«³Îǧ¡£
º£²ó¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿FreeRADIUS¤Ï¥Ç¥Õ¥©¥ë¥È¤Ç¥í¡¼¥«¥ëUnix¥æ¡¼¥¶¡¼¤ò
¸«¤Ë¹Ô¤¯ÀßÄê¤Ë¤Ê¤Ã¤Æ¤¤¤ë°Ù¡¢RADIUS¦¤ÎÀßÄê¤ÏÉÔÍפǤ·¤¿¡£
¢. ¥í¡¼¥«¥ë¥¢¥«¥¦¥ó¥È¤Ëtest¥æ¡¼¥¶¡¼¤òÄɲ乤롣
# uesradd test
# passwd test
--------------------------------------------------------------------------
Changing password for user test.
New UNIX password:¡¡¢«¡¡test¤ÈÆþÎÏ
BAD PASSWORD: it is too short
Retype new UNIX password:¡¡¢«¡¡test¤ÈÆþÎÏ
passwd: all authentication tokens updated successfully.
--------------------------------------------------------------------------
£. RADIUS¤ò¥Ç¥Ð¥Ã¥¯¥â¡¼¥É¤Ë¤Æµ¯Æ°¡£
# radiusd -X -A
--------------------------------------------------------------------------------
¡Á°Ê¾å¾Êά
¡¡Module: Loaded radutmp
radutmp: filename = "/usr/local/radius/var/log/radius/radutmp"
radutmp: username = "%{User-Name}"
radutmp: case_sensitive = yes
radutmp: check_with_nas = yes
radutmp: perm = 384
radutmp: callerid = yes
Module: Instantiated radutmp (radutmp)
Listening on authentication *:1812
Listening on accounting *:1813
Ready to process requests.
---------------------------------------------------------------------------------
Àµ¾ï¤Ëµ¯Æ°¤·¤¿¤³¤È¤ò³Îǧ¡£
£. Ê̤Υ³¥ó¥½¡¼¥ë¤«¤é¡¢radtest¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤ÆÇ§¾Ú¤¬Ä̤뤫³Îǧ¤¹¤ë¡£
# radtest test test localhost 1 testing123
¥ª¥×¥·¥ç¥óÀâÌÀ
[user̾]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¡¡Ç§¾Ú¤ò¹Ô¤¦¥æ¡¼¥¶¡¼Ì¾
[password]¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¡¡Âбþ¤¹¤ë¥Ñ¥¹¥ï¡¼¥É
[server̾]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡Ì䤤¹ç¤ï¤»¤ë¥µ¡¼¥Ð̾
[nas-port-number]¡¡¡¡¡¡NAS¥Ý¡¼¥ÈÈÖ¹æ
[secret]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ ¶¦Í¸°
--------------------------------------------------------------------------------------
Sending Access-Request of id 118 to 127.0.0.1 port 1812
User-Name = "test"
User-Password = "test"
NAS-IP-Address = 255.255.255.255
NAS-Port = 1
rad_recv: Access-Accept packet from host 127.0.0.1:1812, id=118, length=20
--------------------------------------------------------------------------------------
Access-Accept¥Ñ¥±¥Ã¥È¤¬Ê֤äƤ¤Æ¡¢Ç§¾Ú¤¬Ä̤俤³¤È¤ò³Îǧ¡£
¤Á¤Ê¤ß¤Ë¡¢¥µ¡¼¥Ð¦¤Î¥Ç¥Ð¥Ã¥¯¥í¥°¤Ç¤Ï°Ê²¼¤Î¤è¤¦¤Ëɽ¼¨¤µ¤ì¤ë¡£
---------------------------------------------------------------------------
¡Á°Ê¾å¾Êά
Sending Access-Accept of id 118 to 127.0.0.1 port 32770
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 6 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 118 with timestamp 473bf3ce
Nothing to do. Sleeping until we see a request.
----------------------------------------------------------------------------
¤. radtest¤Çǧ¾Ú¤Ë¼ºÇÔ¤·¤¿¾ì¹ç¤ò³Îǧ¤¹¤ë¡£
# radtest test password localhost 1 testing123
-----------------------------------------------------------------------------------
Sending Access-Request of id 251 to 127.0.0.1 port 1812
User-Name = "test"
User-Password = "passwd"
NAS-IP-Address = 255.255.255.255
NAS-Port = 1
rad_recv: Access-Reject packet from host 127.0.0.1:1812, id=251, length=20
----------------------------------------------------------------------------------
¥Ñ¥¹¥ï¡¼¥É¤¬´Ö°ã¤Ã¤Æ¤¤¤ë¤¿¤á¡¢Access-Reject¥Ñ¥±¥Ã¥È¤¬Ê֤äƤ¤Æ¡¢Ç§¾Ú¤¬
¼ºÇÔ¤·¤Æ¤¤¤ë»ö¤ò³Îǧ¡£¥µ¡¼¥Ð¦¤Î¥Ç¥Ð¥Ã¥°¥í¥°¤Ç¤Ï°Ê²¼¤Î¤è¤¦¤Ëɽ¼¨¤µ¤ì¤ë¡£
------------------------------------------------------------------------
¡Á°Ê¾å¾Êά
auth: Failed to validate the user.
Delaying request 0 for 1 seconds
Finished request 0
Going to the next request
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Waking up in 1 seconds...
--- Walking the entire request list ---
Sending Access-Reject of id 251 to 127.0.0.1 port 32770
Waking up in 4 seconds...
--- Walking the entire request list ---
Cleaning up request 0 ID 251 with timestamp 473bf4fd
Nothing to do. Sleeping until we see a request.
-------------------------------------------------------------------------
°Ê¾å¤Ç¥í¡¼¥«¥ë¥¢¥«¥¦¥ó¥È¤ÎRADIUSǧ¾Ú¤Î³Îǧ¤Ï´°Î»¤Ç¤¢¤ë¡£
¼¡¤Ë¡¢RADIUS¤¬LDAP¥æ¡¼¥¶¡¼¤ò¸«¤Ë¹Ô¤¯¤è¤¦¤ËÀßÄê¤ò¤¹¤ë¡£
¥. radius.conf¤òLDAPÂбþ¤Î¤¿¤á¡¢°Ê²¼¤Î¤è¤¦¤ËÊÔ½¸¤¹¤ë¡£
¡¡¡¡LDAP¥µ¡¼¥Ð¼þ¤ê¤ÎÀßÄê¤Ï³Æ´Ä¶¤Ë¤è¤Ã¤Æ°ã¤¦¤Î¤ÇŬÅö¤Ë¹ç¤ï¤»¤ë¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¡Á°Ê¾å¾Êά
ldap {
server = "LDAP¥µ¡¼¥Ð¤ÎIP"
identity = "cn=Manager,dc=my-domain,dc=com"
password = secret
basedn = "dc=my-domain,dc=com"
filter = "(uid=%{Stripped-User-Name:-%{User-Name}})"
start_tls = yes
tls_cacertdir = /etc/openldap/cacerts/
¡ÁÅÓÃæ¾Êά
authenticate {
Auth-Type PAP {
pap
}
Auth-Type CHAP {
chap
}
Auth-Type MS-CHAP {
mschap
}
unix
Auth-Type LDAP {¡¡¢«¡¡¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤¹
ldap¡¡¢«¡¡¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤¹
}¡¡¢«¡¡¥³¥á¥ó¥È¥¢¥¦¥È¤ò³°¤¹
eap
}
¡Á°Ê²¼¾Êά
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¦. users¤ò°Ê²¼¤Î¤è¤¦¤ËÊÔ½¸¤·¡¢LDAPǧ¾Ú¤ò¥Ç¥Õ¥©¥ë¥È¤ËÊѹ¹¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
DEFAULT Auth-Type = LDAP¡¡¢«¡¡System¤«¤éÊѹ¹
Fall-Through = 1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
§. clients.conf¤ò°Ê²¼¤Î¤è¤¦¤ËÊÔ½¸¤·client¤Î°¤¹¤ë¥»¥°¥á¥ó¥È¤«¤é¤Î¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
client ¥¯¥é¥¤¥¢¥ó¥È¤Î°¤¹¤ë¥Í¥Ã¥È¥ï¡¼¥¯¥¢¥É¥ì¥¹/24{
secret = testing123 ¢«¡¡¶¦Í¸°
shortname = localhost¡¡¢«¡¡¥í¥°¥Õ¥¡¥¤¥ë¤ÎÃæ¤Ç»È¤¦Ì¾¾Î
}
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¨. slapd¤ò¥Ç¥Ð¥Ã¥¯¥â¡¼¥É¤ÇΩ¤Á¾å¤²¡£
# slapd -d 1
©. RADIUS¤ò¥Ç¥Ð¥Ã¥¯¥â¡¼¥É¤ÇºÆµ¯Æ°¡£
# Ctrl-C¤ÇÀèÄøÎ©¤Á¾å¤²¤¿RADIUS¤ò¥¹¥È¥Ã¥×
# radiusd -X -A
ª. radtest¤ÇLDAP¥æ¡¼¥¶¡¼¤Îǧ¾Ú¤¬Ä̤뤫³Îǧ¡£
# radtest testUser password LDAP¥µ¡¼¥Ð¤ÎIP 1 testing123
-------------------------------------------------------------------------------------------
Sending Access-Request of id 118 to RADIUS(LDAP)¥µ¡¼¥Ð¤ÎIP port 1812
User-Name = "testUser"
User-Password = "password"
NAS-IP-Address = 255.255.255.255
NAS-Port = 1
rad_recv: Access-Accept packet from host RADIUS(LDAP)¥µ¡¼¥Ð¤ÎIP:1812, id=118, length=20
-------------------------------------------------------------------------------------------
Access-Accept¥Ñ¥±¥Ã¥È¤¬Ê֤äƤ¤Æ¡¢Ç§¾Ú¤¬Ä̤俤³¤È¤ò³Îǧ¡£
¤Á¤Ê¤ß¤Ë¡¢¥µ¡¼¥Ð¦¤Î¥Ç¥Ð¥Ã¥°¥í¥°¤â³Îǧ¤·¤Æ¤ª¤¯¤È¡¢Ç§¾Ú¤Îή¤ì¤¬¤è¤¯Ê¬¤«¤ë¤«¤È¡£
radiusd¤¬radtest¤Ë¤è¤Ã¤ÆÇ§¾Ú°ÍÍê¤ò¼õ¤±¤ë¤È¡¢radiusd¤«¤éslapd¤Ø¤Î¸¡º÷¤¬¤«¤«¤ë¡£
¤Þ¤¿¡¢StartTLS¤â͸ú¤Ë¤·¤Æ¤¤¤ë¤¿¤á¡¢SSL¾ÚÌÀ½ñ¤Î¤ä¤ê¼è¤ê¤â¸«¤ì¤ë¤Ï¤º¡£
¥í¥°¤ÎÎ̤¬Â¿¤¤¤¿¤áºÜ¤»¤Æ¤Ê¤¤¤¹¤¬¤¬¡¢°ìÅÙ³Îǧ¤·¤Æ¤ª¤¯¤È¤¤¤¤¤«¤â¡£
°Ê¾å¤Ç¡¢RADIUS¤ÈLDAP¤ÎÏ¢·È¤¬´°Î»¡£
¤³¤³¤«¤é¤ÏNWµ¡´ï¦¤ÎÀßÄê¡£
¤Á¤Ê¤ß¤Ë¸¡¾Ú¤Ë»ÈÍѤ·¤¿¥¹¥¤¥Ã¥Á¤ÏCisco¤ÎCatalyst3560G¤Ç¤¢¤ë¡£
¥¹¥¤¥Ã¥Á¦¤Ï½é´ü²½¾õÂÖ(startup-config¤Ê¤·)¤Î¾õÂÖ¤«¤é»Ï¤á¤ë¡£
«. ¥³¥ó¥Õ¥£¥°¥â¡¼¥É¤ÇRADIUS¥¯¥é¥¤¥¢¥ó¥È¤È¤·¤Æ¤ÎÀßÄê¤ò¹Ô¤¦¡£
Switch(config)#aaa new-model
Switch(config)#aaa authentication login default group radius local
Switch(config)#radius-server host RADIUS(LDAP)¥µ¡¼¥Ð¤ÎIP auth-port 1812 acct-port 1813
Switch(config)#radius-server key testing123¡¡¢«¡¡¶¦Í¸°
¡ôǧ¾Ú¥Ý¡¼¥È¤È¥¢¥«¥¦¥Æ¥£¥ó¥°¥Ý¡¼¥È¤Ï¡¢ÌÀ¼¨Åª¤Ë»ØÄê
¬. ǰ¤Î°Ù¡¢ÄÌ¿®¤Ë¼ºÇÔ¤·¤¿¾ì¹ç¤ËÈ÷¤¨¤Æ¥í¡¼¥«¥ë¥æ¡¼¥¶¡¼(´ÉÍý¼Ô¸¢¸Â¤Ç¡Ë¤òºîÀ®¤·¤Æ¤ª¤¯¡£
Switch(config)#username test privilege 15 password test
. °ìÅÙ¥í¥°¥¢¥¦¥È¤·¡¢LDAP¥æ¡¼¥¶¡¼¤Ç¥í¥°¥¤¥ó²Äǽ¤«¤É¤¦¤«³Îǧ¤·¤Æ¤ß¤ë¡£
User Access Verification
Username: testUser
Password:¡¡¢«¡¡password¤ÈÆþÎÏ
Switch>
Àµ¾ï¤Ë¥í¥°¥¤¥ó½ÐÍè¤ë¤³¤È¤ò³Îǧ¤Ç¤¤¿¡£
¤Á¤Ê¤ß¤Ë¤Ç¤¹¤¬¡¢RADIUS¤È¤ÎÁÂÄ̤¬²Äǽ¤Ê¾õÂ֤ǤϺîÀ®¤·¤¿¥í¡¼¥«¥ë¥æ¡¼¥¶¡¼¤Ï
¥í¥°¥¤¥ó½ÐÍè¤Þ¤»¤ó¡£RADIUS¤È¤ÎÄÌ¿®¤¬½ÐÍè¤Ê¤¤¶ÛµÞ»þ¤Î¤ß»ÈÍѲÄǽ¤Ç¤¹¡£
![]() | LDAP Super Expert (2006/04/11) ÊÔ½¸Éô ¾¦Éʾܺ٤ò¸«¤ë OpenLDAP ver2.3¤Î¿·µ¡Ç½¤Ê¤É¤Ë¤Ä¤¤¤Æ¾Ü¤·¤¯½ñ¤«¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¤¤¤¯¤Ä¤«¤Î¥ß¥É¥ë¥¦¥§¥¢Ï¢·È¤Î¾¡¢OpenSSH¸°Ç§¾ÚLDAP²½¤äsudo¤ÎLDAP²½¤Þ¤Ç½ñ¤«¤ì¤Æ¤¤¤Æ¤¤¤ë¤Î¤¬Èó¾ï¤ËÌòΩ¤Ä¡£ |
LDAP¤Î¥¢¥¯¥»¥¹¥³¥ó¥È¡¼¥ë¤Ïʬ¤«¤ê¤Å¤é¤¤¤Î¤ÇÀßÄê¤òÅ»¤á¤Æ¤ß¤ë¡£
º£²óÎã¤È¤·¤Æ¡¢³«È¯Éô¤È±Ä¶ÈÉô¤È¤¤¤¦²¾¤Î¥°¥ë¡¼¥×¤òºîÀ®¤·¤Æ¤ß¤Þ¤¹¡£
¤½¤ì¤¾¤ìÀìÍÑ¥µ¡¼¥Ð¤òÊÝͤ·¤Æ¤¤¤Æ¡¢¼«Éô½ð¤Î¥µ¡¼¥Ð¤Ë¤Ï¥í¥°¥¤¥ó²Äǽ¤À¤¬
Áê¼ê¤Î¥µ¡¼¥Ð¤Ë¤Ï¥í¥°¥¤¥óÉԲġ¢¤È¤¤¤Ã¤¿·Á¤Î¤É¤³¤Ë¤Ç¤â¤¢¤ê¤¬¤Á¤Ê¹½À®¤Ç¤¹¡£
¼ÂºÝ¤ÎÀßÄê¤ÎÁ°¤Ë¡¢¼«Éô½ð¥µ¡¼¥Ð ¡Á LDAP¥µ¡¼¥Ð´Ö¤Îǧ¾Ú¤Îή¤ì¤ò³Îǧ¡£
1. ¼«Éô½ð¥µ¡¼¥Ð¤Ë¥í¥°¥¤¥ó¤¹¤ëºÝ¡¢¸Ä¿Í¤Î¥¢¥«¥¦¥ó¥È¤È¥Ñ¥¹¥ï¡¼¥É¤òÆþÎÏ
2. ǧ¾Ú¾ðÊó¤òÆþÎϤµ¤ì¤¿¼«Éô½ð¥µ¡¼¥Ð¤Ï¡¢Ç§¾Ú¾ðÊó¤òLDAP¥µ¡¼¥Ð¤ØÌä¹ç
3. LDAP¥µ¡¼¥Ð¤Ï¼õ¤±¼è¤Ã¤¿Ç§¾Ú¾ðÊó¤ò¸µ¤Ë¼«¿È¤¬ÊÝ»ý¤·¤Æ¤¤¤ë¥Ç¡¼¥¿¤ò¸¡º÷
4. LDAP¥µ¡¼¥Ð¤¬¸¡º÷·ë²Ì¤ò¼«Éô½ð¥µ¡¼¥Ð¤ØÊÖ¤¹
5. ÊÖ¤µ¤ì¤¿·ë²Ì¤ò¸µ¤Ë¡¢¼«Éô½ð¥µ¡¼¥Ð¤¬¼ÂºÝ¤Îǧ¾Ú½èÍý¤ò¹Ô¤¦
´Êñ¤Ë³Îǧ¤¹¤ë¤È°Ê¾å¡£
¤³¤³¤Çº£²ó½ÅÍפʤΤ¬2.¤Ç¡¢ ǧ¾Ú¾ðÊó¤òLDAP¥µ¡¼¥Ð¤ØÌä¹ç¤»¤ëºÝ¤Ë¡¢
Ìä¹ç¤»¤½¤Î¤â¤Î¤Ë¤â¸¢¸Â¤¬É¬Íפˤʤ뤿¤á¤³¤³¤Ç°ìÅÙǧ¾Ú¤¬È¯À¸¤·¤Þ¤¹¡£
¤³¤ÎÌä¹ç¤»¤Îǧ¾Ú»þ¤Ë»ÈÍѤµ¤ì¤ë¤Î¤Ï¼«Éô½ð¥µ¡¼¥Ð¤Î¥í¥°¥¤¥ó»þ¤Ë
ÆþÎϤ·¤¿ÃͤǤϤʤ¯¡¢Ç§¾ÚDN(binddn)¤Ç»ØÄꤵ¤ì¤Æ¤¤¤ë¤â¤Î¤¬»ÈÍѤµ¤ì¤Þ¤¹¡£
ǧ¾ÚDN¤Ï/etc/ldap.conf¤Ç»ØÄê½ÐÍè¤Þ¤¹¡£
/etc/ldap.conf¤Ë¡¢binddn¤Èbindpw¤È¤¤¤¦¥Ñ¥é¥á¡¼¥¿¤¬¤¢¤ê¡¢
¤³¤³¤ÇÌä¹ç¤»¤Îǧ¾Ú»þ¤Ë»ÈÍѤ¹¤ëDN¤ò»ØÄꤷ¤Þ¤¹¡£
¤Á¤Ê¤ß¤ËÀßÄꤷ¤Æ¤¤¤Ê¤¤¤Èanonymous(ƿ̾)¤Ç¤Î¥¢¥¯¥»¥¹¤Ç¤¹¡£
º£²ó¡¢ACL¤ÇÀ©¸æ¤¹¤ë¤Î¤Ï¤³¤ÎÌä¹ç¤»»þ¤Îǧ¾ÚDN¤ËÂФ·¤Æ¤Ë¤Ê¤ê¤Þ¤¹¡£
¤ª¸ß¤¤¤Îǧ¾ÚDN¤Ï¼«Éô½ð¤Î¥Ç¥£¥ì¥¯¥È¥ê¥Ä¥ê¡¼¤Ï¥¢¥¯¥»¥¹²Äǽ¤À¤¬¡¢
Áê¼êÉô½ð¤Î¥Ç¥£¥ì¥¯¥È¥ê¥Ä¥ê¡¼¤ËÂФ·¤Æ¤Ï¥¢¥¯¥»¥¹½ÐÍè¤Ê¤¤¤è¤¦ÀßÄꤷ¤Þ¤¹¡£
¾åµ¼Â¸½¤Î°Ù¡¢¤½¤ì¤¾¤ì¤Îǧ¾ÚDN¤Ë¤Ï¥×¥í¥¥·¥æ¡¼¥¶¡¼¤òºîÀ®¤·¤Þ¤¹¡£
¥×¥í¥¥·¥æ¡¼¥¶¡¼¤ÏÌä¹ç¤»ÀìÍѤÎǧ¾ÚDN¤È¤·¤Æ»ÈÍѤ·¡¢Éô½ðËè¤Ë1DNºîÀ®¤·¤Þ¤¹¡£
¤½¤ì¤Ç¤Ï¼ÂºÝ¤Ë¤ä¤Ã¤Æ¤ß¤Þ¤·¤ç¤¦¡£
¤Þ¤º¡¢³«È¯Éô¤È±Ä¶ÈÉô¤Î¥°¥ë¡¼¥×¡¢¥Æ¥¹¥È¥æ¡¼¥¶¡¢¥×¥í¥¥·¥æ¡¼¥¶¡¼¤ÎºîÀ®¤«¤é¡£
¡. °Ê²¼¤Îldif¥Õ¥¡¥¤¥ë(acl_test.ldif)¤òÍѰա£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
dn: ou=dev,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: dev
dn: uid=devproxy,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devproxy
uid: devproxy
uidNumber: 10001
gidNumber: 10001
homeDirectory: /home/devproxy
userPassword: devproxy
loginShell: /bin/bash
dn: uid=devUser,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devUser
uid: devUser
uidNumber: 10011
gidNumber: 10011
homeDirectory: /home/devUser
userPassword: devUser
loginShell: /bin/bash
dn: ou=sal,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: sal
dn: uid=salproxy,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salproxy
uid: salproxy
uidNumber: 20001
gidNumber: 20001
homeDirectory: /home/salproxy
userPassword: salproxy
loginShell: /bin/bash
dn: uid=salUser,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salUser
uid: salUser
uidNumber: 20011
gidNumber: 20011
homeDirectory: /home/salUser
userPassword: salUser
loginShell: /bin/bash
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¢. ldapadd¤ÇÅÐÏ¿¡£
# ldapadd -x -ZZ -D "cn=Manager,dc=my-domain,dc=com" -w secret -f
¡¡¡¡acl_test.ldif
----------------------------------------------------------------------------------
adding new entry "ou=dev,dc=my-domain,dc=com"
adding new entry "uid=devproxy,ou=dev,dc=my-domain,dc=com"
adding new entry "uid=devUser,ou=dev,dc=my-domain,dc=com"
adding new entry "ou=sal,dc=my-domain,dc=com"
adding new entry "uid=salproxy,ou=sal,dc=my-domain,dc=com"
adding new entry "uid=salUser,ou=sal,dc=my-domain,dc=com"
-----------------------------------------------------------------------------------
£. ¤½¤ì¤¾¤ìÄɲä·¤¿¥×¥í¥¥·¥æ¡¼¥¶¡¼¤Ç¡¢Á´¤Æ¤Î¥¨¥ó¥È¥ê¤¬¸¡º÷²Äǽ¤Ç¤¢¤ë»ö¤ò³Îǧ¡£
¡¡¡¡¡ôldap¥¯¥é¥¤¥¢¥ó¥È¥³¥Þ¥ó¥É¤Ç¤Ï¡Ö-D¡×¥ª¥×¥·¥ç¥ó¤Ë¤è¤Ã¤ÆÇ§¾ÚDN¤Î»ØÄ꤬²Äǽ¡£
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=devproxy,ou=dev,dc=my-domain,dc=com" -w devproxy
¡¡
-----------------------------
¡Á°Ê¾å¾Êά
# numResponses: 16
# numEntries: 15
-----------------------------
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=salproxy,ou=sal,dc=my-domain,dc=com" -w salproxy
¡¡
-----------------------------
¡Á°Ê¾å¾Êά
# numResponses: 16
# numEntries: 15
-----------------------------
ÌäÂê¤Ê¤¤¤³¤È¤ò³Îǧ¡£
¸½¾õACL¤¬²¿¤â¤«¤«¤Ã¤Æ¤¤¤Ê¤¤¾õÂ֤ʤΤǡ¢
Á´¤Æ¤Î¥¨¥ó¥È¥ê¤¬¤É¤Îǧ¾Ú¥æ¡¼¥¶¡¼¤«¤é¤Ç¤â³Îǧ½ÐÍè¤ë¤Ï¤º¤Ç¤¹¡£
¼¡¤ËËÜÂê¤ÎACL¤ÎÀßÄê¡£
¦. slapd.conf¤Ø°Ê²¼¤ÎÆâÍÆ¤òÄɵ¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
access to attr=userPassword
by * auth
access to dn.subtree="ou=dev,dc=my-domain,dc=com"
by dn.base="uid=devproxy,ou=dev,dc=my-domain,dc=com" read
by * none
access to dn.subtree="ou=sal,dc=my-domain,dc=com"
by dn.base="uid=salproxy,ou=sal,dc=my-domain,dc=com" read
by * none
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ÀßÄꤷ¤¿¹àÌܤˤĤ¤¤Æ¡¢½ç¤Ë³Îǧ¤·¤Æ¤ß¤Þ¤¹¡£
Á°Äó¤È¤·¤ÆACL¤Ï¾å¤«¤é½ç¤Ëɾ²Á¤µ¤ì¡¢¥Þ¥Ã¥Á¤·¤¿¹àÌܤˤĤ¤¤Æ¤Ï°Ê¸å¤Îɾ²Á¤Ï¤µ¤ì¤Þ¤»¤ó¡£
°ìÈÖÌܤιàÌܤÏuserPassword°À¤Ë¤Ä¤¤¤Æ¤Î¤â¤Î¤Ç¡¢Á´¤Æ¤Î¥æ¡¼¥¶¡¼¤Ëǧ¾Ú¤Î
¸¢¸Â¤Î¤ß¤òÍ¿¤¨¤Æ¤¤¤Þ¤¹¡£userPassword°À¤Ë¤Ï¸ÄÊ̤˥¢¥¯¥»¥¹¸¢¤òÍ¿¤¨¤Æ¤ª¤«¤Ê¤¤¤È¡¢
Invalid credentials¤Î¥¨¥é¡¼¤ÇÃÆ¤«¤ì¤Æ¤·¤Þ¤¤¡¢°Ê¹ß¤ÎACL¤¬¸ú¤«¤Ê¤¯¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤¹¡£
¼¡¤Î¹àÌܤÏACL¤ÎÈϰϤȤ·¤Æ¡¢dn.subtree¤Ë"ou=dev,dc=my-domain,dc=com"¤ò
»ØÄꤷ¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤Ï"ou=dev,dc=my-domain,dc=com"¼«¿È¤È¤½¤ÎÇÛ²¼¤Ë¸ºß¤¹¤ë
Á´¤Æ¤Î¥¨¥ó¥È¥ê¤¬Å¬ÍÑÈϰϤȤ¤¤¦»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
¤Á¤Ê¤ß¤Ëdn.children¤È¤·¤¿¾ì¹ç¤Ï"ou=dev,dc=my-domain,dc=com"¤Ï´Þ¤Þ¤ì¤º¡¢
"ou=dev,dc=my-domain,dc=com"ÇÛ²¼¤Î¥¨¥ó¥È¥ê¤Î¤ß¤¬Å¬ÍÑÈϰϤˤʤê¤Þ¤¹¡£
¼¡¤Ë¡¢¼ÂºÝ¤Ë¸¢¸Â¤òÍ¿¤¨¤ë¥ª¥Ö¥¸¥§¥¯¥È¤Ç¤¹¤¬¡¢º£²óACLÍѤ˺îÀ®¤·¤¿¥×¥í¥¥·¥æ¡¼¥¶¡¼¤Ø
dn.base¤Çread¸¢¸Â¤òÍ¿¤¨¤Æ¤ª¤ê¡¢¤½¤Î¾¤Î¥æ¡¼¥¶¡¼¤Ë¤Ä¤¤¤Æ¤Ï²¿¤â¸¢¸Â¤òÍ¿¤¨¤Ê¤¤ÀßÄê¡£
sal¥°¥ë¡¼¥×¤âƱÍͤǤ¹¡£
°Ê¾å¤òÅ»¤á¤ë¤È¡¢¤Þ¤ºpassword°À¤Ë¤Ä¤¤¤Æ¤Ïï¤Ç¤âǧ¾ÚÍ×µá¤Ï²Äǽ¡£
¼¡¤Ë"ou=dev,dc=my-domain,dc=com"°Ê²¼¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤Ë¤Ä¤¤¤Æ¤Ç¤¹¤¬¡¢
ÂåÍý¥æ¡¼¥¶¡¼¤Ç¤¢¤ëxxxproxy¤Î¤ß¤¬read²Äǽ¤Ç¡¢¤½¤Î¾¤ÎDN¤ÏµñÈݤµ¤ì¤Þ¤¹¡£
sal¥°¥ë¡¼¥×¤Ë¤Ä¤¤¤Æ¤âÂåÍý¥æ¡¼¥¶¡¼¤¬°Û¤Ê¤ë¤À¤±¤ÇƱ¤¸ÀßÄê¤Ç¤¹¡£
¤Á¤Ê¤ß¤Ërootdn¤Ë¤Ä¤¤¤Æ¤ÏÅöÁ³ACL¤ÎÈÏáÆ³°¤Ê¤Î¤Ç¤¤¤Ä¤Ç¤âÁ´¤Æ¤Î¥¨¥ó¥È¥ê¤Ë¥¢¥¯¥»¥¹²Äǽ
¤Ç¤Ï¼ÂºÝ¤Ë³Îǧ¤·¤Æ¤ß¤Þ¤·¤ç¤¦¡£
§. ¤½¤ì¤¾¤ì¤Î¥×¥í¥¥·¥æ¡¼¥¶¡¼¤Çldapsearch¡£
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=devproxy,ou=dev,dc=my-domain,dc=com" -w devproxy
¡¡
------------------------------------------------------------------
# extended LDIF
#
# LDAPv3
# base with scope sub
# filter: (objectclass=*)
# requesting: ALL
#
# dev, my-domain.com
dn: ou=dev,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: dev
# devproxy, dev, my-domain.com
dn: uid=devproxy,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devproxy
uid: devproxy
uidNumber: 10001
gidNumber: 10001
homeDirectory: /home/devproxy
userPassword:: ZGV2cHJveHk=
loginShell: /bin/bash
# devUser, dev, my-domain.com
dn: uid=devUser,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devUser
uid: devUser
uidNumber: 10011
gidNumber: 10011
homeDirectory: /home/devUser
loginShell: /bin/bash
# search result
search: 3
result: 0 Success
# numResponses: 4
# numEntries: 3
------------------------------------------------------------------
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=salproxy,ou=sal,dc=my-domain,dc=com" -w salproxy
¡¡
------------------------------------------------------------------
# extended LDIF
#
# LDAPv3
# base with scope sub
# filter: (objectclass=*)
# requesting: ALL
#
# sal, my-domain.com
dn: ou=sal,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: sal
# salproxy, sal, my-domain.com
dn: uid=salproxy,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salproxy
uid: salproxy
uidNumber: 20001
gidNumber: 20001
homeDirectory: /home/salproxy
userPassword:: c2FscHJveHk=
loginShell: /bin/bash
# salUser, sal, my-domain.com
dn: uid=salUser,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salUser
uid: salUser
uidNumber: 20011
gidNumber: 20011
homeDirectory: /home/salUser
loginShell: /bin/bash
# search result
search: 3
result: 0 Success
# numResponses: 4
# numEntries: 3
------------------------------------------------------------------
¤½¤ì¤¾¤ì¼«Éô½ð¤Î¥æ¡¼¥¶¡¼¤·¤«¸«¤¨¤Ê¤¤»ö¤ò³Îǧ½ÐÍè¤Þ¤·¤¿¡£
ºÇ¸å¤Ë¥¯¥é¥¤¥¢¥ó¥È(¼«Éô½ð¥µ¡¼¥Ð)¦¤ÎÀßÄê¤ò¹Ô¤¦¡£
¨. ¤½¤ì¤¾¤ì/etc/ldap.conf¤Î°Ê²¼¤ÎÉôʬ¤òÊÔ½¸¡£
³«È¯Éô¥µ¡¼¥Ð
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
binddn uid=devproxy,ou=dev,dc=my-domain,dc=com
bindpw devproxy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
±Ä¶ÈÉô¥µ¡¼¥Ð
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
binddn uid=salproxy,ou=sal,dc=my-domain,dc=com
bindpw salproxy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
°Ê¾å¡£
º£²óÎã¤È¤·¤Æ¡¢³«È¯Éô¤È±Ä¶ÈÉô¤È¤¤¤¦²¾¤Î¥°¥ë¡¼¥×¤òºîÀ®¤·¤Æ¤ß¤Þ¤¹¡£
¤½¤ì¤¾¤ìÀìÍÑ¥µ¡¼¥Ð¤òÊÝͤ·¤Æ¤¤¤Æ¡¢¼«Éô½ð¤Î¥µ¡¼¥Ð¤Ë¤Ï¥í¥°¥¤¥ó²Äǽ¤À¤¬
Áê¼ê¤Î¥µ¡¼¥Ð¤Ë¤Ï¥í¥°¥¤¥óÉԲġ¢¤È¤¤¤Ã¤¿·Á¤Î¤É¤³¤Ë¤Ç¤â¤¢¤ê¤¬¤Á¤Ê¹½À®¤Ç¤¹¡£
¼ÂºÝ¤ÎÀßÄê¤ÎÁ°¤Ë¡¢¼«Éô½ð¥µ¡¼¥Ð ¡Á LDAP¥µ¡¼¥Ð´Ö¤Îǧ¾Ú¤Îή¤ì¤ò³Îǧ¡£
1. ¼«Éô½ð¥µ¡¼¥Ð¤Ë¥í¥°¥¤¥ó¤¹¤ëºÝ¡¢¸Ä¿Í¤Î¥¢¥«¥¦¥ó¥È¤È¥Ñ¥¹¥ï¡¼¥É¤òÆþÎÏ
2. ǧ¾Ú¾ðÊó¤òÆþÎϤµ¤ì¤¿¼«Éô½ð¥µ¡¼¥Ð¤Ï¡¢Ç§¾Ú¾ðÊó¤òLDAP¥µ¡¼¥Ð¤ØÌä¹ç
3. LDAP¥µ¡¼¥Ð¤Ï¼õ¤±¼è¤Ã¤¿Ç§¾Ú¾ðÊó¤ò¸µ¤Ë¼«¿È¤¬ÊÝ»ý¤·¤Æ¤¤¤ë¥Ç¡¼¥¿¤ò¸¡º÷
4. LDAP¥µ¡¼¥Ð¤¬¸¡º÷·ë²Ì¤ò¼«Éô½ð¥µ¡¼¥Ð¤ØÊÖ¤¹
5. ÊÖ¤µ¤ì¤¿·ë²Ì¤ò¸µ¤Ë¡¢¼«Éô½ð¥µ¡¼¥Ð¤¬¼ÂºÝ¤Îǧ¾Ú½èÍý¤ò¹Ô¤¦
´Êñ¤Ë³Îǧ¤¹¤ë¤È°Ê¾å¡£
¤³¤³¤Çº£²ó½ÅÍפʤΤ¬2.¤Ç¡¢ ǧ¾Ú¾ðÊó¤òLDAP¥µ¡¼¥Ð¤ØÌä¹ç¤»¤ëºÝ¤Ë¡¢
Ìä¹ç¤»¤½¤Î¤â¤Î¤Ë¤â¸¢¸Â¤¬É¬Íפˤʤ뤿¤á¤³¤³¤Ç°ìÅÙǧ¾Ú¤¬È¯À¸¤·¤Þ¤¹¡£
¤³¤ÎÌä¹ç¤»¤Îǧ¾Ú»þ¤Ë»ÈÍѤµ¤ì¤ë¤Î¤Ï¼«Éô½ð¥µ¡¼¥Ð¤Î¥í¥°¥¤¥ó»þ¤Ë
ÆþÎϤ·¤¿ÃͤǤϤʤ¯¡¢Ç§¾ÚDN(binddn)¤Ç»ØÄꤵ¤ì¤Æ¤¤¤ë¤â¤Î¤¬»ÈÍѤµ¤ì¤Þ¤¹¡£
ǧ¾ÚDN¤Ï/etc/ldap.conf¤Ç»ØÄê½ÐÍè¤Þ¤¹¡£
/etc/ldap.conf¤Ë¡¢binddn¤Èbindpw¤È¤¤¤¦¥Ñ¥é¥á¡¼¥¿¤¬¤¢¤ê¡¢
¤³¤³¤ÇÌä¹ç¤»¤Îǧ¾Ú»þ¤Ë»ÈÍѤ¹¤ëDN¤ò»ØÄꤷ¤Þ¤¹¡£
¤Á¤Ê¤ß¤ËÀßÄꤷ¤Æ¤¤¤Ê¤¤¤Èanonymous(ƿ̾)¤Ç¤Î¥¢¥¯¥»¥¹¤Ç¤¹¡£
º£²ó¡¢ACL¤ÇÀ©¸æ¤¹¤ë¤Î¤Ï¤³¤ÎÌä¹ç¤»»þ¤Îǧ¾ÚDN¤ËÂФ·¤Æ¤Ë¤Ê¤ê¤Þ¤¹¡£
¤ª¸ß¤¤¤Îǧ¾ÚDN¤Ï¼«Éô½ð¤Î¥Ç¥£¥ì¥¯¥È¥ê¥Ä¥ê¡¼¤Ï¥¢¥¯¥»¥¹²Äǽ¤À¤¬¡¢
Áê¼êÉô½ð¤Î¥Ç¥£¥ì¥¯¥È¥ê¥Ä¥ê¡¼¤ËÂФ·¤Æ¤Ï¥¢¥¯¥»¥¹½ÐÍè¤Ê¤¤¤è¤¦ÀßÄꤷ¤Þ¤¹¡£
¾åµ¼Â¸½¤Î°Ù¡¢¤½¤ì¤¾¤ì¤Îǧ¾ÚDN¤Ë¤Ï¥×¥í¥¥·¥æ¡¼¥¶¡¼¤òºîÀ®¤·¤Þ¤¹¡£
¥×¥í¥¥·¥æ¡¼¥¶¡¼¤ÏÌä¹ç¤»ÀìÍѤÎǧ¾ÚDN¤È¤·¤Æ»ÈÍѤ·¡¢Éô½ðËè¤Ë1DNºîÀ®¤·¤Þ¤¹¡£
¤½¤ì¤Ç¤Ï¼ÂºÝ¤Ë¤ä¤Ã¤Æ¤ß¤Þ¤·¤ç¤¦¡£
¤Þ¤º¡¢³«È¯Éô¤È±Ä¶ÈÉô¤Î¥°¥ë¡¼¥×¡¢¥Æ¥¹¥È¥æ¡¼¥¶¡¢¥×¥í¥¥·¥æ¡¼¥¶¡¼¤ÎºîÀ®¤«¤é¡£
¡. °Ê²¼¤Îldif¥Õ¥¡¥¤¥ë(acl_test.ldif)¤òÍѰա£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
dn: ou=dev,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: dev
dn: uid=devproxy,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devproxy
uid: devproxy
uidNumber: 10001
gidNumber: 10001
homeDirectory: /home/devproxy
userPassword: devproxy
loginShell: /bin/bash
dn: uid=devUser,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devUser
uid: devUser
uidNumber: 10011
gidNumber: 10011
homeDirectory: /home/devUser
userPassword: devUser
loginShell: /bin/bash
dn: ou=sal,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: sal
dn: uid=salproxy,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salproxy
uid: salproxy
uidNumber: 20001
gidNumber: 20001
homeDirectory: /home/salproxy
userPassword: salproxy
loginShell: /bin/bash
dn: uid=salUser,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salUser
uid: salUser
uidNumber: 20011
gidNumber: 20011
homeDirectory: /home/salUser
userPassword: salUser
loginShell: /bin/bash
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
¢. ldapadd¤ÇÅÐÏ¿¡£
# ldapadd -x -ZZ -D "cn=Manager,dc=my-domain,dc=com" -w secret -f
¡¡¡¡acl_test.ldif
----------------------------------------------------------------------------------
adding new entry "ou=dev,dc=my-domain,dc=com"
adding new entry "uid=devproxy,ou=dev,dc=my-domain,dc=com"
adding new entry "uid=devUser,ou=dev,dc=my-domain,dc=com"
adding new entry "ou=sal,dc=my-domain,dc=com"
adding new entry "uid=salproxy,ou=sal,dc=my-domain,dc=com"
adding new entry "uid=salUser,ou=sal,dc=my-domain,dc=com"
-----------------------------------------------------------------------------------
£. ¤½¤ì¤¾¤ìÄɲä·¤¿¥×¥í¥¥·¥æ¡¼¥¶¡¼¤Ç¡¢Á´¤Æ¤Î¥¨¥ó¥È¥ê¤¬¸¡º÷²Äǽ¤Ç¤¢¤ë»ö¤ò³Îǧ¡£
¡¡¡¡¡ôldap¥¯¥é¥¤¥¢¥ó¥È¥³¥Þ¥ó¥É¤Ç¤Ï¡Ö-D¡×¥ª¥×¥·¥ç¥ó¤Ë¤è¤Ã¤ÆÇ§¾ÚDN¤Î»ØÄ꤬²Äǽ¡£
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=devproxy,ou=dev,dc=my-domain,dc=com" -w devproxy
¡¡
-----------------------------
¡Á°Ê¾å¾Êά
# numResponses: 16
# numEntries: 15
-----------------------------
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=salproxy,ou=sal,dc=my-domain,dc=com" -w salproxy
¡¡
-----------------------------
¡Á°Ê¾å¾Êά
# numResponses: 16
# numEntries: 15
-----------------------------
ÌäÂê¤Ê¤¤¤³¤È¤ò³Îǧ¡£
¸½¾õACL¤¬²¿¤â¤«¤«¤Ã¤Æ¤¤¤Ê¤¤¾õÂ֤ʤΤǡ¢
Á´¤Æ¤Î¥¨¥ó¥È¥ê¤¬¤É¤Îǧ¾Ú¥æ¡¼¥¶¡¼¤«¤é¤Ç¤â³Îǧ½ÐÍè¤ë¤Ï¤º¤Ç¤¹¡£
¼¡¤ËËÜÂê¤ÎACL¤ÎÀßÄê¡£
¦. slapd.conf¤Ø°Ê²¼¤ÎÆâÍÆ¤òÄɵ¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
access to attr=userPassword
by * auth
access to dn.subtree="ou=dev,dc=my-domain,dc=com"
by dn.base="uid=devproxy,ou=dev,dc=my-domain,dc=com" read
by * none
access to dn.subtree="ou=sal,dc=my-domain,dc=com"
by dn.base="uid=salproxy,ou=sal,dc=my-domain,dc=com" read
by * none
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ÀßÄꤷ¤¿¹àÌܤˤĤ¤¤Æ¡¢½ç¤Ë³Îǧ¤·¤Æ¤ß¤Þ¤¹¡£
Á°Äó¤È¤·¤ÆACL¤Ï¾å¤«¤é½ç¤Ëɾ²Á¤µ¤ì¡¢¥Þ¥Ã¥Á¤·¤¿¹àÌܤˤĤ¤¤Æ¤Ï°Ê¸å¤Îɾ²Á¤Ï¤µ¤ì¤Þ¤»¤ó¡£
°ìÈÖÌܤιàÌܤÏuserPassword°À¤Ë¤Ä¤¤¤Æ¤Î¤â¤Î¤Ç¡¢Á´¤Æ¤Î¥æ¡¼¥¶¡¼¤Ëǧ¾Ú¤Î
¸¢¸Â¤Î¤ß¤òÍ¿¤¨¤Æ¤¤¤Þ¤¹¡£userPassword°À¤Ë¤Ï¸ÄÊ̤˥¢¥¯¥»¥¹¸¢¤òÍ¿¤¨¤Æ¤ª¤«¤Ê¤¤¤È¡¢
Invalid credentials¤Î¥¨¥é¡¼¤ÇÃÆ¤«¤ì¤Æ¤·¤Þ¤¤¡¢°Ê¹ß¤ÎACL¤¬¸ú¤«¤Ê¤¯¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤¹¡£
¼¡¤Î¹àÌܤÏACL¤ÎÈϰϤȤ·¤Æ¡¢dn.subtree¤Ë"ou=dev,dc=my-domain,dc=com"¤ò
»ØÄꤷ¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤Ï"ou=dev,dc=my-domain,dc=com"¼«¿È¤È¤½¤ÎÇÛ²¼¤Ë¸ºß¤¹¤ë
Á´¤Æ¤Î¥¨¥ó¥È¥ê¤¬Å¬ÍÑÈϰϤȤ¤¤¦»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
¤Á¤Ê¤ß¤Ëdn.children¤È¤·¤¿¾ì¹ç¤Ï"ou=dev,dc=my-domain,dc=com"¤Ï´Þ¤Þ¤ì¤º¡¢
"ou=dev,dc=my-domain,dc=com"ÇÛ²¼¤Î¥¨¥ó¥È¥ê¤Î¤ß¤¬Å¬ÍÑÈϰϤˤʤê¤Þ¤¹¡£
¼¡¤Ë¡¢¼ÂºÝ¤Ë¸¢¸Â¤òÍ¿¤¨¤ë¥ª¥Ö¥¸¥§¥¯¥È¤Ç¤¹¤¬¡¢º£²óACLÍѤ˺îÀ®¤·¤¿¥×¥í¥¥·¥æ¡¼¥¶¡¼¤Ø
dn.base¤Çread¸¢¸Â¤òÍ¿¤¨¤Æ¤ª¤ê¡¢¤½¤Î¾¤Î¥æ¡¼¥¶¡¼¤Ë¤Ä¤¤¤Æ¤Ï²¿¤â¸¢¸Â¤òÍ¿¤¨¤Ê¤¤ÀßÄê¡£
sal¥°¥ë¡¼¥×¤âƱÍͤǤ¹¡£
°Ê¾å¤òÅ»¤á¤ë¤È¡¢¤Þ¤ºpassword°À¤Ë¤Ä¤¤¤Æ¤Ïï¤Ç¤âǧ¾ÚÍ×µá¤Ï²Äǽ¡£
¼¡¤Ë"ou=dev,dc=my-domain,dc=com"°Ê²¼¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤Ë¤Ä¤¤¤Æ¤Ç¤¹¤¬¡¢
ÂåÍý¥æ¡¼¥¶¡¼¤Ç¤¢¤ëxxxproxy¤Î¤ß¤¬read²Äǽ¤Ç¡¢¤½¤Î¾¤ÎDN¤ÏµñÈݤµ¤ì¤Þ¤¹¡£
sal¥°¥ë¡¼¥×¤Ë¤Ä¤¤¤Æ¤âÂåÍý¥æ¡¼¥¶¡¼¤¬°Û¤Ê¤ë¤À¤±¤ÇƱ¤¸ÀßÄê¤Ç¤¹¡£
¤Á¤Ê¤ß¤Ërootdn¤Ë¤Ä¤¤¤Æ¤ÏÅöÁ³ACL¤ÎÈÏáÆ³°¤Ê¤Î¤Ç¤¤¤Ä¤Ç¤âÁ´¤Æ¤Î¥¨¥ó¥È¥ê¤Ë¥¢¥¯¥»¥¹²Äǽ
¤Ç¤Ï¼ÂºÝ¤Ë³Îǧ¤·¤Æ¤ß¤Þ¤·¤ç¤¦¡£
§. ¤½¤ì¤¾¤ì¤Î¥×¥í¥¥·¥æ¡¼¥¶¡¼¤Çldapsearch¡£
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=devproxy,ou=dev,dc=my-domain,dc=com" -w devproxy
¡¡
------------------------------------------------------------------
# extended LDIF
#
# LDAPv3
# base
# filter: (objectclass=*)
# requesting: ALL
#
# dev, my-domain.com
dn: ou=dev,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: dev
# devproxy, dev, my-domain.com
dn: uid=devproxy,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devproxy
uid: devproxy
uidNumber: 10001
gidNumber: 10001
homeDirectory: /home/devproxy
userPassword:: ZGV2cHJveHk=
loginShell: /bin/bash
# devUser, dev, my-domain.com
dn: uid=devUser,ou=dev,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: devUser
uid: devUser
uidNumber: 10011
gidNumber: 10011
homeDirectory: /home/devUser
loginShell: /bin/bash
# search result
search: 3
result: 0 Success
# numResponses: 4
# numEntries: 3
------------------------------------------------------------------
# ldapsearch -x -ZZ -b 'dc=my-domain,dc=com' -D "uid=salproxy,ou=sal,dc=my-domain,dc=com" -w salproxy
¡¡
------------------------------------------------------------------
# extended LDIF
#
# LDAPv3
# base
# filter: (objectclass=*)
# requesting: ALL
#
# sal, my-domain.com
dn: ou=sal,dc=my-domain,dc=com
objectClass: organizationalUnit
ou: sal
# salproxy, sal, my-domain.com
dn: uid=salproxy,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salproxy
uid: salproxy
uidNumber: 20001
gidNumber: 20001
homeDirectory: /home/salproxy
userPassword:: c2FscHJveHk=
loginShell: /bin/bash
# salUser, sal, my-domain.com
dn: uid=salUser,ou=sal,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
cn: salUser
uid: salUser
uidNumber: 20011
gidNumber: 20011
homeDirectory: /home/salUser
loginShell: /bin/bash
# search result
search: 3
result: 0 Success
# numResponses: 4
# numEntries: 3
------------------------------------------------------------------
¤½¤ì¤¾¤ì¼«Éô½ð¤Î¥æ¡¼¥¶¡¼¤·¤«¸«¤¨¤Ê¤¤»ö¤ò³Îǧ½ÐÍè¤Þ¤·¤¿¡£
ºÇ¸å¤Ë¥¯¥é¥¤¥¢¥ó¥È(¼«Éô½ð¥µ¡¼¥Ð)¦¤ÎÀßÄê¤ò¹Ô¤¦¡£
¨. ¤½¤ì¤¾¤ì/etc/ldap.conf¤Î°Ê²¼¤ÎÉôʬ¤òÊÔ½¸¡£
³«È¯Éô¥µ¡¼¥Ð
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
binddn uid=devproxy,ou=dev,dc=my-domain,dc=com
bindpw devproxy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
±Ä¶ÈÉô¥µ¡¼¥Ð
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
binddn uid=salproxy,ou=sal,dc=my-domain,dc=com
bindpw salproxy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
°Ê¾å¡£
![]() | LDAP Super Expert (2006/04/11) ÊÔ½¸Éô ¾¦Éʾܺ٤ò¸«¤ë OpenLDAP ver2.3¤Î¿·µ¡Ç½¤Ê¤É¤Ë¤Ä¤¤¤Æ¾Ü¤·¤¯½ñ¤«¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¤¤¤¯¤Ä¤«¤Î¥ß¥É¥ë¥¦¥§¥¢Ï¢·È¤Î¾¡¢OpenSSH¸°Ç§¾ÚLDAP²½¤äsudo¤ÎLDAP²½¤Þ¤Ç½ñ¤«¤ì¤Æ¤¤¤Æ¤¤¤ë¤Î¤¬Èó¾ï¤ËÌòΩ¤Ä¡£ |
sync replication¤Ë¤Ä¤¤¤Æµ¡Ç½³µÍפòÅ»¤á¤Æ¤ß¤Þ¤¹¡£
¤Á¤Ê¤ß¤Ë¸½¹Ô¤ÎOpenLDAP¤Ë¤Ïsync replication(°Ê²¼syncrepl)¤È¡¢
Ver2.2·Ï¤Þ¤Ç¼çή¤Ç¤¢¤Ã¤¿slurpd¤È¤¤¤¦Æó¤Ä¤ÎÊ£À½¼êÃʤ¬Â¸ºß¤·¤Þ¤¹¡£
°ã¤¤¤Ï°Ê²¼¤Î¤è¤¦¤Ê´¶¤¸¤Ç¤¹¡£
slurpd¤È¤Ï¡¢¥¹¥ì¡¼¥Ö¦¤ÎÊ£À½ÀìÍѤΥµ¡¼¥Ó¥¹¤Î¤³¤È¤Ç¤¹¡£
Ê£À½ÊýË¡¤Îή¤ì¤È¤·¤Æ¤Ï¡¢¥Þ¥¹¥¿¡¼¤Ç¹¹¿·¤¬È¯À¸¤·¤¿ºÝ¤Ëslapd¤¬¹¹¿·¾ðÊó¤òslapd.log¤È
¤¤¤¦¥í¥°¥Õ¥¡¥¤¥ë¤Ë½ñ¤½Ð¤·¤Þ¤¹¡£¤³¤ì¤òÊ£À½¥µ¡¼¥Ð¤Îslurpd¤¬Äê´üŪ¤ËÆÉ¤ß½Ð¤·¡¢¹¹¿·¤¬
¤¢¤ë¾ì¹ç¤Ï¼«Ê¬¼«¿È¤Îslapd¤ËŬÍѤ·Æ±´ü¤·¤Æ¤¤¤ë¤È¤¤¤Ã¤¿Î®¤ì¤Ç¤¹¡£
¤¿¤Àslurpd¤Ë¤Ï¤¤¤¯¤Ä¤«¤Î·çÅÀ¤¬¤¢¤ê¤Þ¤¹¡£
¤Þ¤ºslapd.log¤Ë¤Ï¹¹¿·¾ðÊó¤·¤«½ñ¤½Ð¤µ¤ì¤Ê¤¤¤Î¤Ç¡¢±¿ÍѤò»Ï¤á¤ëÁ°¤Ëͽ¤á
¥Þ¥¹¥¿¡¼¤È¥¹¥ì¡¼¥Ö´Ö¤Ç¥Ç¡¼¥¿¤ÎÆâÍÆ¤ò°ìÃפµ¤»¤Æ¤¢¤²¤Ê¤±¤ì¤Ð¤¤¤±¤Þ¤»¤ó¡£
¼¡¤Ë¡¢¥Þ¥¹¥¿¡¼¤È¥¹¥ì¡¼¥Ö´Ö¤Ç¾ï¤ËÀµ¤·¤¯Æ±´ü¤µ¤ì¤Æ¤¤¤ë¤«¤ÎÊݾ㤬¤¢¤ê¤Þ¤»¤ó¡£
Î㤨¤Ð¡¢¤¢¤ë¥¨¥ó¥È¥ê¤ÎƱ´ü¤Ë¼ºÇÔ¤·¤¿¤È¤·¤Þ¤¹¡£
¼ºÇÔ¤·¤¿¤³¤Î¥¨¥ó¥È¥ê¤Ë¤Ä¤¤¤Æ¤Ï¥ê¥¸¥§¥¯¥È¥Õ¥¡¥¤¥ë¤È¤¤¤¦¤â¤Î¤Ë½ñ¤½Ð¤µ¤ì¤Þ¤¹¤¬¡¢
¤½¤Î¸å¼«Æ°¤Ç¤³¤Î¥Õ¥¡¥¤¥ë¤òºÆÆÉ¤ß¹þ¤ß¤Ê¤É¤Ï¤·¤Ê¤¤¤Î¤Ç¡¢
Ì·½â¤¬È¯À¸¤·¤¿¾ì¹ç¤Ï¼êư¤Ç¥¨¥ó¥È¥ê¤òÄɲ乤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
¼¡¤Ï¡¢¿·¤·¤¤µ¡Ç½¤Ç¤¢¤ësyncrepl¤Ë¤Ä¤¤¤Æ¡£
syncrepl¤Ç¤Ï¡¢slurpd¤Ç¤¤¤¦¥Þ¥¹¥¿¡¼¤ËÁêÅö¤¹¤ë¥µ¡¼¥Ð¤ò¡Ö¥×¥í¥Ð¥¤¥À¡×¡¢
¥¹¥ì¡¼¥Ö¤ËÁêÅö¤¹¤ë¥µ¡¼¥Ð¤ò¡Ö¥³¥ó¥·¥å¡¼¥Þ¡×¤È¸Æ¤Ó¤Þ¤¹¡£
slurpd¤È°ã¤¤¡¢Ê£À½¤Î½é´üưºî¤Ï¥³¥ó¥·¥å¡¼¥Þ¦¤«¤éȯÀ¸¤¹¤ë»ö¤Ë¤Ê¤Ã¤Æ¤¤¤Æ¡¢
¥³¥ó¥·¥å¡¼¥Þ¦¤«¤éͽ¤áÀßÄꤵ¤ì¤Æ¤¤¤ë»ØÄê¤Ë´ð¤Å¤¡¢¥×¥í¥Ð¥¤¥À¦¤Ø¸¡º÷¤ò¹Ô¤¤¤Þ¤¹¡£
¤Þ¤¿¡¢Á°²ó¤ÎÊ£À½¤«¤é¤ÎÊѹ¹¾ðÊó¤òÃΤë¼êΩ¤Æ¤È¤·¤Æ¡¢syncrepl¤Ïcookie¤ò»È¤Ã¤Æ¤Þ¤¹¡£
¥×¥í¥Ð¥¤¥À¤ÏÊ£À½¤¬½ª¤ë¤È¡¢¤½¤ÎÅÙ¤ËCSN¤Î¸½»þÅÀ¤ÎºÇÂçÃͤòcookie¤ÇÊÖ¤·¤Þ¤¹¡£
CSN¤È¤Ï¥¨¥ó¥È¥ê¤½¤ì¤¾¤ì¤Ë¸ºß¤¹¤ëURLÊѹ¹½çÈÖ¹æ¤ÎÃͤλö¤Ç¡¢¥×¥í¥Ð¥¤¥À¤Ç
¿·µ¬Äɲää´û¸¥¨¥ó¥È¥ê¤Î¹¹¿·¤¬¹Ô¤ï¤ì¤¿ºÝ¡¢¸½ºß¤ÎÃͤè¤ê¤âÂ礤ÊÃͤËÊѹ¹¤µ¤ì¤Þ¤¹¡£
¥³¥ó¥·¥å¡¼¥Þ¤ÏÊ£À½»þ¤Ë¸¡º÷¾ò·ï¤È¶¦¤ËÁ°²ó¼èÆÀ¤·¤¿cookieÃͤòÄÌÃΤ¹¤ë»ö¤Ç¡¢
¥×¥í¥Ð¥¤¥À¤ÇÄÌÃΤµ¤ì¤¿cookieÃͤè¤ê¤âÂ礤ÊCSN¤ò»ý¤Ä¥¨¥ó¥È¥ê¤òÊ£À½¤¹¤Ù¤¥¨¥ó¥È¥ê
¤È¤·¤ÆÊÖ¤¹»ö¤¬½ÐÍè¤ë¡¢¤È¤¤¤¦»ÅÁȤߤǤ¹¡£
Å»¤á¤ë¤ÈÊ£À½½èÍý¤Îή¤ì¤Ï°Ê²¼¤è¤¦¤Ê´¶¤¸¡£
1. ¥³¥ó¥·¥å¡¼¥Þ¤«¤é¸¡º÷¾ò·ï¤È¶¦¤ËÁ°²ó¤ÎÊ£À½»þ¤Ë¼õ¤±¼è¤Ã¤¿cookieÃÍ(CSN)¤ò
¡¡¡¡¥×¥í¥Ð¥¤¥À¤ØÄÌÃΤ·¡¢Æ±´ü°ÍÍê¤ò¤«¤±¤ë¡£
2. Ʊ´ü°ÍÍê¤ò¼õ¤±¼è¤Ã¤¿¥×¥í¥Ð¥¤¥À¤Ï¸¡º÷¾ò·ï¤Ë¥Þ¥Ã¥Á¤·¤¿¥¨¥ó¥È¥ê¤ò½ç¤ËÄ´¤Ù¡¢
¡¡¡¡ÄÌÃΤµ¤ì¤¿cookie¤ÎÃͤȸ½ºß¤Î¥¨¥ó¥È¥ê¤ÎCSN¤òÈæ³Ó¡£
3. ¥×¥í¥Ð¥¤¥À¤Ï¸½ºß¤Î¥¨¥ó¥È¥ê¤ÎCSN¤¬ÄÌÃΤµ¤ì¤¿cookieÃͤè¤ê¤âÂ礤«¤Ã¤¿¥¨¥ó
¡¡¡¡¥È¥ê¤òÊ£À½¤¹¤ë¥¨¥ó¥È¥ê¤È¤·¤Æ¥³¥ó¥·¥å¡¼¥Þ¤Ë±þÅú¡£
4. Ê£À½¤¹¤ë¥¨¥ó¥È¥ê¤ò¼õ¤±¼è¤Ã¤¿¥³¥ó¥·¥å¡¼¥Þ¤Ï¡¢¼«¿È¤Î¥¨¥ó¥È¥ê¤ò¥¢¥Ã¥×¥Ç¡¼¥È¡£
°Ê¾å¤¬syncrepl¤Ë¤è¤ë´ðËÜŪ¤ÊÊ£À½½èÍý¡£
¤Þ¤¿¡¢syncrepl¤Ë¤ÏÆó¤Ä¤Îưºî¥â¡¼¥É¤¬Â¸ºß¤·¡¢°Ê²¼¤ÎÍÍ¤ÊÆÃħ¤¬¤¢¤ë¡£
¢¢ refreshOnly¥â¡¼¥É
¡¡¡¡¥³¥ó¥·¥å¡¼¥Þ¤«¤é¡¢Äê´üŪ¤ËƱ´ü°ÍÍê¤ò¤«¤±¤ë¡£
¡¡¡¡¥×¥í¥Ð¥¤¥À¤Ç¾åµ¤Îή¤ì¤Ë±è¤Ã¤¿Ê£À½½èÍý¤¬¹Ô¤ï¤ì¡¢
¡¡¡¡¹¹¿·¤¹¤Ù¤¥¨¥ó¥È¥ê¤òÊÖ¤¹¾ì¹ç¤Ë¡¢¤³¤Î¥â¡¼¥É¤Ï¸ºß¥á¥Ã¥»¡¼¥¸¤È¤¤¤¦¤â¤Î¤âƱ»þ¤ËÊÖ¤¹¡£
¡¡¡¡Â¸ºß¥á¥Ã¥»¡¼¥¸¤È¤Ï¡¢ºï½ü¤µ¤ì¤¿¥¨¥ó¥È¥ê¤ò¼±Ê̤¹¤ë¤¿¤á¤Î¤â¤Î¤Ç¤¹¡£
¡¡¡¡Ä̾ï¤ÎÊѹ¹¤Ç¤¢¤ì¤ÐCSN¤Ç¥¨¥ó¥È¥ê¤Î¹¹¿·¤¬²Äǽ¤À¤¬¡¢
¡¡¡¡¥¨¥ó¥È¥ê¤½¤Î¤â¤Î¤¬Â¸ºß¤·¤Ê¤¯¤Ê¤Ã¤¿¾ì¹çCSN¤âºï½ü¤µ¤ì¤Æ¤·¤Þ¤¦¡£
¡¡¡¡¤½¤Î¾ì¹ç¡¢CSN¤À¤±¤Ç¤Ïºï½ü¤Ë¤ÏÂбþ¤·¤¤ì¤Ê¤¤¡£
¡¡¡¡¤½¤³¤Ç¡¢Â¸ºß¥á¥Ã¥»¡¼¥¸¤òÊÖ¤¹¤è¤¦¤Ë¤·¤Æ¤¤¤Þ¤¹¡£
¡¡¡¡¤³¤Î¥á¥Ã¥»¡¼¥¸¤Ë¤ÏÊѹ¹¤µ¤ì¤Æ¤¤¤Ê¤¤Á´¤Æ¤Î¥¨¥ó¥È¥ê¤ÎUUID¤òÊÝ»ý¤·¤Æ¤¤¤Æ¡¢
¡¡¡¡¥×¥í¥Ð¥¤¥À¤«¤éÊÖ¤µ¤ì¤¿UUID¤Î½¸¹ç¤ò¥³¥ó¥·¥å¡¼¥Þ¤Ï¼«Ê¬¤Î¥¨¥ó¥È¥ê¤ÎUUID¤ÈÈæ³Ó¤·¤Æ¡¢
¡¡¡¡¥×¥í¥Ð¥¤¥À¤«¤éÊÖ¤µ¤ì¤¿UUID¤Î½¸¹ç¤Ë¸ºß¤·¤Æ¤¤¤Ê¤¤(ºï½ü¤¹¤Ù¤¥¨¥ó¥È¥ê)¤ò¸«¤Ä¤±¤ë¡£
¡¡¡¡Ã¢¤·¥Ç¥á¥ê¥Ã¥È¤È¤·¤Æ¡¢¥³¥ó¥·¥å¡¼¥Þ¦¤«¤é¤ÎƱ´ü°ÍÍê¤ÏÄê´üŪ¤Ê¤â¤Î¤Ë¤Ê¤ë¤¿¤á¡¢
¡¡¡¡¼ÂºÝ¤ËÊѹ¹¤¬¥³¥ó¥·¥å¡¼¥Þ¤ËÈ¿±Ç¤µ¤ì¤ë¤Þ¤Ç¥¿¥¤¥à¥é¥°¤¬À¸¤¸¤Æ¤·¤Þ¤¦¡£
¢¢ refreshAndPersist¥â¡¼¥É
¡¡¡¡¤³¤Î¥â¡¼¥É¤Ï´ðËܸ¶Íý¤ÇÀâÌÀ¤·¤¿Æ°ºî¤Ç¤Ï¾¯¤·°Û¤Ê¤ê¡¢»Ï¤á¤ËƱ´ü°ÍÍê¤òȯ¹Ô¡£
¡¡¡¡¤½¤Î¸å¡¢°ìÏ¢¤ÎÊ£À½½èÍý¤¬¹Ô¤ï¤ìƱ´ü¤¹¤Ù¤¥¨¥ó¥È¥ê¤ò¥×¥í¥Ð¥¤¥À¤«¤éÊÖ¤µ¤ì¤¿¸å¤Ç¤â¡¢
¡¡¡¡Àܳ¤òÀÚÃǤ»¤º¤Ë°Ý»ý¤·Â³¤±¤ë¤Î¤Ç¤¢¤ë¡£
¡¡¡¡¤½¤Î´Ö¥×¥í¥Ð¥¤¥À¦¤ËÊѹ¹¤¬È¯À¸¤¹¤ë¤È¡¢¥×¥í¥Ð¥¤¥À¤«¤é¥³¥ó¥·¥å¡¼¥Þ¤ØÂ¨»þÄÌÃΤ¹¤ë¡£
¡¡¡¡
¡¡¡¡Ã¢¤·¥Ç¥á¥ê¥Ã¥È¤È¤·¤Æ¡¢Àܳ¤ò°Ý»ý¤·Â³¤±¤ë¤Î¤Ë¥×¥í¥Ð¥¤¥À¤ËÉé²Ù¤¬¤«¤«¤ë¡£
¡¡¡¡¤Þ¤¿¡¢¥Ð¥Ã¥¯¥¨¥ó¥É¤È¤·¤ÆLDBM¤ò»ÈÍѤ·¤Æ¤¤¤ë¾ì¹ç¡¢
¡¡¡¡syncrepl¤¬¥Ç¡¼¥¿¥Ù¡¼¥¹¤ò¥í¥Ã¥¯¤·¤Æ¤·¤Þ¤¦¤¿¤á¤³¤Î¥â¡¼¥É¤¬À©¸Â¤µ¤ì¤Æ¤¤¤ë¡£
°Ê¾å¤¬¥â¡¼¥É¤ÎÀâÌÀ¤Ë¤Ê¤ê¤Þ¤¹¡£
µ¡Ç½³µÍפȤ·¤Æ¤Ï°Ê¾å¡£
¤Á¤Ê¤ß¤Ë¸½¹Ô¤ÎOpenLDAP¤Ë¤Ïsync replication(°Ê²¼syncrepl)¤È¡¢
Ver2.2·Ï¤Þ¤Ç¼çή¤Ç¤¢¤Ã¤¿slurpd¤È¤¤¤¦Æó¤Ä¤ÎÊ£À½¼êÃʤ¬Â¸ºß¤·¤Þ¤¹¡£
°ã¤¤¤Ï°Ê²¼¤Î¤è¤¦¤Ê´¶¤¸¤Ç¤¹¡£
slurpd¤È¤Ï¡¢¥¹¥ì¡¼¥Ö¦¤ÎÊ£À½ÀìÍѤΥµ¡¼¥Ó¥¹¤Î¤³¤È¤Ç¤¹¡£
Ê£À½ÊýË¡¤Îή¤ì¤È¤·¤Æ¤Ï¡¢¥Þ¥¹¥¿¡¼¤Ç¹¹¿·¤¬È¯À¸¤·¤¿ºÝ¤Ëslapd¤¬¹¹¿·¾ðÊó¤òslapd.log¤È
¤¤¤¦¥í¥°¥Õ¥¡¥¤¥ë¤Ë½ñ¤½Ð¤·¤Þ¤¹¡£¤³¤ì¤òÊ£À½¥µ¡¼¥Ð¤Îslurpd¤¬Äê´üŪ¤ËÆÉ¤ß½Ð¤·¡¢¹¹¿·¤¬
¤¢¤ë¾ì¹ç¤Ï¼«Ê¬¼«¿È¤Îslapd¤ËŬÍѤ·Æ±´ü¤·¤Æ¤¤¤ë¤È¤¤¤Ã¤¿Î®¤ì¤Ç¤¹¡£
¤¿¤Àslurpd¤Ë¤Ï¤¤¤¯¤Ä¤«¤Î·çÅÀ¤¬¤¢¤ê¤Þ¤¹¡£
¤Þ¤ºslapd.log¤Ë¤Ï¹¹¿·¾ðÊó¤·¤«½ñ¤½Ð¤µ¤ì¤Ê¤¤¤Î¤Ç¡¢±¿ÍѤò»Ï¤á¤ëÁ°¤Ëͽ¤á
¥Þ¥¹¥¿¡¼¤È¥¹¥ì¡¼¥Ö´Ö¤Ç¥Ç¡¼¥¿¤ÎÆâÍÆ¤ò°ìÃפµ¤»¤Æ¤¢¤²¤Ê¤±¤ì¤Ð¤¤¤±¤Þ¤»¤ó¡£
¼¡¤Ë¡¢¥Þ¥¹¥¿¡¼¤È¥¹¥ì¡¼¥Ö´Ö¤Ç¾ï¤ËÀµ¤·¤¯Æ±´ü¤µ¤ì¤Æ¤¤¤ë¤«¤ÎÊݾ㤬¤¢¤ê¤Þ¤»¤ó¡£
Î㤨¤Ð¡¢¤¢¤ë¥¨¥ó¥È¥ê¤ÎƱ´ü¤Ë¼ºÇÔ¤·¤¿¤È¤·¤Þ¤¹¡£
¼ºÇÔ¤·¤¿¤³¤Î¥¨¥ó¥È¥ê¤Ë¤Ä¤¤¤Æ¤Ï¥ê¥¸¥§¥¯¥È¥Õ¥¡¥¤¥ë¤È¤¤¤¦¤â¤Î¤Ë½ñ¤½Ð¤µ¤ì¤Þ¤¹¤¬¡¢
¤½¤Î¸å¼«Æ°¤Ç¤³¤Î¥Õ¥¡¥¤¥ë¤òºÆÆÉ¤ß¹þ¤ß¤Ê¤É¤Ï¤·¤Ê¤¤¤Î¤Ç¡¢
Ì·½â¤¬È¯À¸¤·¤¿¾ì¹ç¤Ï¼êư¤Ç¥¨¥ó¥È¥ê¤òÄɲ乤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
¼¡¤Ï¡¢¿·¤·¤¤µ¡Ç½¤Ç¤¢¤ësyncrepl¤Ë¤Ä¤¤¤Æ¡£
syncrepl¤Ç¤Ï¡¢slurpd¤Ç¤¤¤¦¥Þ¥¹¥¿¡¼¤ËÁêÅö¤¹¤ë¥µ¡¼¥Ð¤ò¡Ö¥×¥í¥Ð¥¤¥À¡×¡¢
¥¹¥ì¡¼¥Ö¤ËÁêÅö¤¹¤ë¥µ¡¼¥Ð¤ò¡Ö¥³¥ó¥·¥å¡¼¥Þ¡×¤È¸Æ¤Ó¤Þ¤¹¡£
slurpd¤È°ã¤¤¡¢Ê£À½¤Î½é´üưºî¤Ï¥³¥ó¥·¥å¡¼¥Þ¦¤«¤éȯÀ¸¤¹¤ë»ö¤Ë¤Ê¤Ã¤Æ¤¤¤Æ¡¢
¥³¥ó¥·¥å¡¼¥Þ¦¤«¤éͽ¤áÀßÄꤵ¤ì¤Æ¤¤¤ë»ØÄê¤Ë´ð¤Å¤¡¢¥×¥í¥Ð¥¤¥À¦¤Ø¸¡º÷¤ò¹Ô¤¤¤Þ¤¹¡£
¤Þ¤¿¡¢Á°²ó¤ÎÊ£À½¤«¤é¤ÎÊѹ¹¾ðÊó¤òÃΤë¼êΩ¤Æ¤È¤·¤Æ¡¢syncrepl¤Ïcookie¤ò»È¤Ã¤Æ¤Þ¤¹¡£
¥×¥í¥Ð¥¤¥À¤ÏÊ£À½¤¬½ª¤ë¤È¡¢¤½¤ÎÅÙ¤ËCSN¤Î¸½»þÅÀ¤ÎºÇÂçÃͤòcookie¤ÇÊÖ¤·¤Þ¤¹¡£
CSN¤È¤Ï¥¨¥ó¥È¥ê¤½¤ì¤¾¤ì¤Ë¸ºß¤¹¤ëURLÊѹ¹½çÈÖ¹æ¤ÎÃͤλö¤Ç¡¢¥×¥í¥Ð¥¤¥À¤Ç
¿·µ¬Äɲää´û¸¥¨¥ó¥È¥ê¤Î¹¹¿·¤¬¹Ô¤ï¤ì¤¿ºÝ¡¢¸½ºß¤ÎÃͤè¤ê¤âÂ礤ÊÃͤËÊѹ¹¤µ¤ì¤Þ¤¹¡£
¥³¥ó¥·¥å¡¼¥Þ¤ÏÊ£À½»þ¤Ë¸¡º÷¾ò·ï¤È¶¦¤ËÁ°²ó¼èÆÀ¤·¤¿cookieÃͤòÄÌÃΤ¹¤ë»ö¤Ç¡¢
¥×¥í¥Ð¥¤¥À¤ÇÄÌÃΤµ¤ì¤¿cookieÃͤè¤ê¤âÂ礤ÊCSN¤ò»ý¤Ä¥¨¥ó¥È¥ê¤òÊ£À½¤¹¤Ù¤¥¨¥ó¥È¥ê
¤È¤·¤ÆÊÖ¤¹»ö¤¬½ÐÍè¤ë¡¢¤È¤¤¤¦»ÅÁȤߤǤ¹¡£
Å»¤á¤ë¤ÈÊ£À½½èÍý¤Îή¤ì¤Ï°Ê²¼¤è¤¦¤Ê´¶¤¸¡£
1. ¥³¥ó¥·¥å¡¼¥Þ¤«¤é¸¡º÷¾ò·ï¤È¶¦¤ËÁ°²ó¤ÎÊ£À½»þ¤Ë¼õ¤±¼è¤Ã¤¿cookieÃÍ(CSN)¤ò
¡¡¡¡¥×¥í¥Ð¥¤¥À¤ØÄÌÃΤ·¡¢Æ±´ü°ÍÍê¤ò¤«¤±¤ë¡£
2. Ʊ´ü°ÍÍê¤ò¼õ¤±¼è¤Ã¤¿¥×¥í¥Ð¥¤¥À¤Ï¸¡º÷¾ò·ï¤Ë¥Þ¥Ã¥Á¤·¤¿¥¨¥ó¥È¥ê¤ò½ç¤ËÄ´¤Ù¡¢
¡¡¡¡ÄÌÃΤµ¤ì¤¿cookie¤ÎÃͤȸ½ºß¤Î¥¨¥ó¥È¥ê¤ÎCSN¤òÈæ³Ó¡£
3. ¥×¥í¥Ð¥¤¥À¤Ï¸½ºß¤Î¥¨¥ó¥È¥ê¤ÎCSN¤¬ÄÌÃΤµ¤ì¤¿cookieÃͤè¤ê¤âÂ礤«¤Ã¤¿¥¨¥ó
¡¡¡¡¥È¥ê¤òÊ£À½¤¹¤ë¥¨¥ó¥È¥ê¤È¤·¤Æ¥³¥ó¥·¥å¡¼¥Þ¤Ë±þÅú¡£
4. Ê£À½¤¹¤ë¥¨¥ó¥È¥ê¤ò¼õ¤±¼è¤Ã¤¿¥³¥ó¥·¥å¡¼¥Þ¤Ï¡¢¼«¿È¤Î¥¨¥ó¥È¥ê¤ò¥¢¥Ã¥×¥Ç¡¼¥È¡£
°Ê¾å¤¬syncrepl¤Ë¤è¤ë´ðËÜŪ¤ÊÊ£À½½èÍý¡£
¤Þ¤¿¡¢syncrepl¤Ë¤ÏÆó¤Ä¤Îưºî¥â¡¼¥É¤¬Â¸ºß¤·¡¢°Ê²¼¤ÎÍÍ¤ÊÆÃħ¤¬¤¢¤ë¡£
¢¢ refreshOnly¥â¡¼¥É
¡¡¡¡¥³¥ó¥·¥å¡¼¥Þ¤«¤é¡¢Äê´üŪ¤ËƱ´ü°ÍÍê¤ò¤«¤±¤ë¡£
¡¡¡¡¥×¥í¥Ð¥¤¥À¤Ç¾åµ¤Îή¤ì¤Ë±è¤Ã¤¿Ê£À½½èÍý¤¬¹Ô¤ï¤ì¡¢
¡¡¡¡¹¹¿·¤¹¤Ù¤¥¨¥ó¥È¥ê¤òÊÖ¤¹¾ì¹ç¤Ë¡¢¤³¤Î¥â¡¼¥É¤Ï¸ºß¥á¥Ã¥»¡¼¥¸¤È¤¤¤¦¤â¤Î¤âƱ»þ¤ËÊÖ¤¹¡£
¡¡¡¡Â¸ºß¥á¥Ã¥»¡¼¥¸¤È¤Ï¡¢ºï½ü¤µ¤ì¤¿¥¨¥ó¥È¥ê¤ò¼±Ê̤¹¤ë¤¿¤á¤Î¤â¤Î¤Ç¤¹¡£
¡¡¡¡Ä̾ï¤ÎÊѹ¹¤Ç¤¢¤ì¤ÐCSN¤Ç¥¨¥ó¥È¥ê¤Î¹¹¿·¤¬²Äǽ¤À¤¬¡¢
¡¡¡¡¥¨¥ó¥È¥ê¤½¤Î¤â¤Î¤¬Â¸ºß¤·¤Ê¤¯¤Ê¤Ã¤¿¾ì¹çCSN¤âºï½ü¤µ¤ì¤Æ¤·¤Þ¤¦¡£
¡¡¡¡¤½¤Î¾ì¹ç¡¢CSN¤À¤±¤Ç¤Ïºï½ü¤Ë¤ÏÂбþ¤·¤¤ì¤Ê¤¤¡£
¡¡¡¡¤½¤³¤Ç¡¢Â¸ºß¥á¥Ã¥»¡¼¥¸¤òÊÖ¤¹¤è¤¦¤Ë¤·¤Æ¤¤¤Þ¤¹¡£
¡¡¡¡¤³¤Î¥á¥Ã¥»¡¼¥¸¤Ë¤ÏÊѹ¹¤µ¤ì¤Æ¤¤¤Ê¤¤Á´¤Æ¤Î¥¨¥ó¥È¥ê¤ÎUUID¤òÊÝ»ý¤·¤Æ¤¤¤Æ¡¢
¡¡¡¡¥×¥í¥Ð¥¤¥À¤«¤éÊÖ¤µ¤ì¤¿UUID¤Î½¸¹ç¤ò¥³¥ó¥·¥å¡¼¥Þ¤Ï¼«Ê¬¤Î¥¨¥ó¥È¥ê¤ÎUUID¤ÈÈæ³Ó¤·¤Æ¡¢
¡¡¡¡¥×¥í¥Ð¥¤¥À¤«¤éÊÖ¤µ¤ì¤¿UUID¤Î½¸¹ç¤Ë¸ºß¤·¤Æ¤¤¤Ê¤¤(ºï½ü¤¹¤Ù¤¥¨¥ó¥È¥ê)¤ò¸«¤Ä¤±¤ë¡£
¡¡¡¡Ã¢¤·¥Ç¥á¥ê¥Ã¥È¤È¤·¤Æ¡¢¥³¥ó¥·¥å¡¼¥Þ¦¤«¤é¤ÎƱ´ü°ÍÍê¤ÏÄê´üŪ¤Ê¤â¤Î¤Ë¤Ê¤ë¤¿¤á¡¢
¡¡¡¡¼ÂºÝ¤ËÊѹ¹¤¬¥³¥ó¥·¥å¡¼¥Þ¤ËÈ¿±Ç¤µ¤ì¤ë¤Þ¤Ç¥¿¥¤¥à¥é¥°¤¬À¸¤¸¤Æ¤·¤Þ¤¦¡£
¢¢ refreshAndPersist¥â¡¼¥É
¡¡¡¡¤³¤Î¥â¡¼¥É¤Ï´ðËܸ¶Íý¤ÇÀâÌÀ¤·¤¿Æ°ºî¤Ç¤Ï¾¯¤·°Û¤Ê¤ê¡¢»Ï¤á¤ËƱ´ü°ÍÍê¤òȯ¹Ô¡£
¡¡¡¡¤½¤Î¸å¡¢°ìÏ¢¤ÎÊ£À½½èÍý¤¬¹Ô¤ï¤ìƱ´ü¤¹¤Ù¤¥¨¥ó¥È¥ê¤ò¥×¥í¥Ð¥¤¥À¤«¤éÊÖ¤µ¤ì¤¿¸å¤Ç¤â¡¢
¡¡¡¡Àܳ¤òÀÚÃǤ»¤º¤Ë°Ý»ý¤·Â³¤±¤ë¤Î¤Ç¤¢¤ë¡£
¡¡¡¡¤½¤Î´Ö¥×¥í¥Ð¥¤¥À¦¤ËÊѹ¹¤¬È¯À¸¤¹¤ë¤È¡¢¥×¥í¥Ð¥¤¥À¤«¤é¥³¥ó¥·¥å¡¼¥Þ¤ØÂ¨»þÄÌÃΤ¹¤ë¡£
¡¡¡¡
¡¡¡¡Ã¢¤·¥Ç¥á¥ê¥Ã¥È¤È¤·¤Æ¡¢Àܳ¤ò°Ý»ý¤·Â³¤±¤ë¤Î¤Ë¥×¥í¥Ð¥¤¥À¤ËÉé²Ù¤¬¤«¤«¤ë¡£
¡¡¡¡¤Þ¤¿¡¢¥Ð¥Ã¥¯¥¨¥ó¥É¤È¤·¤ÆLDBM¤ò»ÈÍѤ·¤Æ¤¤¤ë¾ì¹ç¡¢
¡¡¡¡syncrepl¤¬¥Ç¡¼¥¿¥Ù¡¼¥¹¤ò¥í¥Ã¥¯¤·¤Æ¤·¤Þ¤¦¤¿¤á¤³¤Î¥â¡¼¥É¤¬À©¸Â¤µ¤ì¤Æ¤¤¤ë¡£
°Ê¾å¤¬¥â¡¼¥É¤ÎÀâÌÀ¤Ë¤Ê¤ê¤Þ¤¹¡£
µ¡Ç½³µÍפȤ·¤Æ¤Ï°Ê¾å¡£
![]() | LDAP Super Expert (2006/04/11) ÊÔ½¸Éô ¾¦Éʾܺ٤ò¸«¤ë OpenLDAP ver2.3¤Î¿·µ¡Ç½¤Ê¤É¤Ë¤Ä¤¤¤Æ¾Ü¤·¤¯½ñ¤«¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¤¤¤¯¤Ä¤«¤Î¥ß¥É¥ë¥¦¥§¥¢Ï¢·È¤Î¾¡¢OpenSSH¸°Ç§¾ÚLDAP²½¤äsudo¤ÎLDAP²½¤Þ¤Ç½ñ¤«¤ì¤Æ¤¤¤Æ¤¤¤ë¤Î¤¬Èó¾ï¤ËÌòΩ¤Ä¡£ |
º£²ó¤ÏOpenSSH¤Î¸ø³«¸°¤òLDAP¤Ç´ÉÍý¤·¤Æ¤ß¤Þ¤¹¡£
Ä̾ï¤Î¸°Ç§¾Ú¤Î¾ì¹ç¤Ï¤Þ¤º¸ø³«¸°¤ÈÈëÌ©¸°¤òºîÀ®¤·¡¢¥í¥°¥¤¥óÂоÝ
¥µ¡¼¥Ð¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤Ë¸ø³«¸°¤òÃÖ¤¤¤Æ¤¢¤²¤Ê¤±¤ì¤Ð¤¤¤±¤Þ¤»¤ó¡£
¿ôÂæ¤Ç¤¢¤ì¤Ð¼ê´Ö¤Ç¤Ï¤Ê¤¤¤Ç¤¹¤¬¡¢Â絬ÌϤʥ·¥¹¥Æ¥à¤Ç¤ÏÈó¾ï¤ËÌÌÅÝ¡£
¤Þ¤¿¡¢¿·µ¬¤Ë¥æ¡¼¥¶¡¼¤òÄɲ乤ë¾ì¹ç¤âÁ´Âæ¤Ë¸°¤òÄɲ䷤ʤ±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£
¤½¤³¤Ç¡¢¸ø³«¸°¤òLDAP¤Ç´ÉÍý¤µ¤»¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¾ðÊó¤È°ì½ï¤Ë¸°¤âÆÉ¤ß½Ð¤¹¤è¤¦¤Ë¤¹¤ë¡£
¤½¤¦¤¹¤ì¤ÐÂоݥµ¡¼¥Ð¤¬Áý¤¨¤è¤¦¤¬¿·µ¬¥æ¡¼¥¶¡¼Äɲ䷤褦¤¬¤½¤Î¥µ¡¼¥Ð¤¬
LDAP¤ËÂбþ¤·¤Æ¤µ¤¨¤¤¤ì¤Ð°ìÅÙ¤ÎÅÐÏ¿¤ÇÁ´¤Æ»ö¤¬ºÑ¤ó¤Ç¤·¤Þ¤¤¤Þ¤¹¡£
⤷¥Ñ¥Ã¥±¡¼¥¸¤ÇÆþ¤Ã¤Æ¤¤¤ëOpenSSH¤Ï¸ø³«¸°Ç§¾Ú¤ÎLDAP²½¤ò¥µ¥Ý¡¼¥È¤·¤Æ¤¤¤Ê¤¤¤Î¤Ç¡¢
lpk¥Ñ¥Ã¥Á¤òÅö¤Æ¤¿¥½¡¼¥¹¤«¤é¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë»ö¤Ë¤·¤Þ¤¹¡£
¡. OpenSSH¤Î¥¤¥ó¥¹¥È¡¼¥ë¡£
# tar zxvf openssh-4.6p1.tar.tar
# cd openssh-4.6p1.tar.tar
# patch -p2 < ../openssh-lpk-4.6p1-0.3.9.patch
# ./configure --prefix=/usr/local/ssh/ --with-ldap=/usr/local/ldap/lib/ --with-
¡¡¡¡pam --without-zlib-version-check
# make
# make install
°Ê¾å¤Ç¥¤¥ó¥¹¥È¡¼¥ë¤Î´°Î»¡£
¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿OpenSSH¤¬Àµ¾ï¤Ëưºî¤¹¤ë¤«³Îǧ¡£
¢. ´û¸¤Îsshd¤Î¥¹¥È¥Ã¥×¡£
# /etc/init.d/sshd stop
£. ¿·µ¬¤Îsshd¤Î¥¹¥¿¡¼¥È¡£
# /usr/local/ssh/sbin/sshd
¤. ¥×¥í¥»¥¹¤Î³Îǧ¡£
# ps aux | grep -i sshd
------------------------------------------------------------------------------------------
root 26872 0.4 0.0 5252 1028 ? Ss 15:27 0:00 /usr/local/ssh/sbin/sshd
------------------------------------------------------------------------------------------
¥. ¼ÂºÝ¤Ë¥í¥°¥¤¥ó²Äǽ¤«³Îǧ¤¹¤ëÁ°¤Ë¡¢¥Æ¥¹¥È¥æ¡¼¥¶¡¼¤ÎºîÀ®
# useradd testUser01
# passwd testUser01
¦. ¼ÂºÝ¤Ë¥í¥°¥¤¥ó²Äǽ¤«ssh¤Ç³Îǧ¡£
# ssh -l testUser01 localhost
------------------------------------------------------------------------------------------
The authenticity of host 'localhost (127.0.0.1)' can't be established.
RSA key fingerprint is xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'localhost' (RSA) to the list of known hosts.
testUser01@localhost's password:
[testUser01@localhost ~]
------------------------------------------------------------------------------------------
¿·sshd¤Ç¥í¥°¥¤¥ó¤Ç¤¤ë»ö¤ò³Îǧ¡£
¼¡¤Ë¡¢¸°¤òLDAP¤ËÅÐÏ¿¤¹¤ëÁ°¤Ë¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤ËÃÖ¤¯
Ä̾ïÄ̤ê¤ÎÊý¼°¤Ç¸°Ç§¾Ú¤¬½ÐÍè¤ë¤«¤É¤¦¤«³Îǧ¡£
§. ¸°¤ÎºîÀ®¡£(¥Ñ¥¹¥Õ¥ì¡¼¥º¤òµá¤á¤é¤ì¤ë)
# su - testUser01
# ssh-keygen -t rsa
-----------------------------------------------------------------------------------------
Generating public/private rsa key pair.
Enter file in which to save the key (/home/testUser01/.ssh/id_rsa):
Created directory '/home/testUser01/.ssh'.
Enter passphrase (empty for no passphrase):¡¡
Enter same passphrase again:¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
Your identification has been saved in /home/testUser01/.ssh/id_rsa.
Your public key has been saved in /home/testUser01/.ssh/id_rsa.pub.
The key fingerprint is:
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx testUser01@xxxxxxx
------------------------------------------------------------------------------------------
¤³¤ì¤Ç¡¢/home/testUser01/.ssh/ÇÛ²¼¤Ë¡¢
id_rsa(ÈëÌ©¸°)¡¢id_rsa.pub(¸ø³«¸°)¤¬ºîÀ®¤µ¤ì¤ë¡£
§. ¸ø³«¸°¤ò¥µ¡¼¥Ð¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤Ë¥³¥Ô¡¼¡£
¡¡¡¡¡ôº£²ó¤Ï¥¯¥é¥¤¥¢¥ó¥È¤È¥µ¡¼¥Ð¤òƱ¤¸¥µ¡¼¥Ð¤È¤·¤Æ¤¤¤ë¤Î¤Çñ¤Ë¥ê¥Í¡¼¥à
# cp id_rsa.pub /home/testUser01/.ssh/authorized_keys2
¨. ssh¤Ç³Îǧ¡£(¥Ñ¥¹¥Õ¥ì¡¼¥º¤òµá¤á¤é¤ì¤ë)
# ssh localhost
------------------------------------------------------------------------
Enter passphrase for key '/home/testUser01/.ssh/id_rsa':
[testUser01@localhost ~]#
------------------------------------------------------------------------
¸ø³«¸°Ç§¾Ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë»ö¤ò³Îǧ¡£
¼¡¤ËLDAP¤Ø¤ÎÅÐÏ¿¡£
¤Þ¤º¡¢LDAP¤Ë¸ø³«¸°¤òÅÐÏ¿¤¹¤ë°Ù¤Ëopenssh-lpk_openldap.schema¤òÆÉ¤ß¹þ¤Þ¤»¤ë¡£
¤³¤Î¥¹¥¡¼¥Þ¤Ï¡¢openssh¤Î¥½¡¼¥¹¤Ë¥Ñ¥Ã¥Á¤ò¤¢¤Æ¤ë¤ÈºîÀ®¤µ¤ì¤ë¡£
©. ¥¹¥¡¼¥Þ¥Õ¥¡¥¤¥ë¤Î¥³¥Ô¡¼¡£
# cp -rp /usr/local/src/openssh-4.6p1/openssh-
¡¡ lpk_openldap.schema /usr/local/ldap/etc/openldap/schema/
ª. ¥¹¥¡¼¥Þ¤òÆÉ¤ß¹þ¤à¤è¤¦¤Ëslapd.conf¤ÎÊÔ½¸¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include /usr/local/ldap/etc/openldap/schema/openssh-
lpk_openldap.shcema
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
«. slapd¤ÎºÆµ¯Æ°¡£
# kill -HUP `cat /usr/local/ldap/var/run/slapd.pid`
# /usr/local/ldap/libexec/slpad
¼¡¤ËtestUser01¤òLDAP¤ËÅÐÏ¿¤¹¤ë¡£¤³¤Î»þ¸ø³«¸°¤â°ì½ï¤ËÅÐÏ¿¤¹¤ë¡£
¬. °Ê²¼¤Îldif(testUser01.ldif)¥Õ¥¡¥¤¥ë¤òÍѰա£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
dn: uid=testUser01,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
objectClass: ldapPublickey
cn: devproxy
uid: devproxy
uidNumber: 10001
gidNumber: 10001
homeDirectory: /home/devproxy
userPassword: devproxy
loginShell: /bin/bash
sshPublicKey: xxxxxxxxxxxxxxxxxxxxxxxxxxx
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
sshPublickey°À¤Ë¤ÏÀèÄø¥³¥Ô¡¼¤·¤¿authorized_keys2¤ÎÃæ¿È¤ò¤Þ¤ë¤Þ¤ë¥³¥Ô¥Ú¤¹¤ë¡£
¤³¤Î»þ²þ¹Ô¤Ê¤É¤¬´Þ¤Þ¤ì¤Ê¤¤¤è¤¦¤ËÃí°Õ¡£
. testUser01.ldif¤òldapadd¡£
# ldapadd -x -ZZ -D "cn=Manager,dc=my-domain,dc=com" -w secret -f
¡¡ testUser01.ldif
---------------------------------------------------------------------------
adding new entry "uid=testUser01,dc=my-domain,dc=com"
---------------------------------------------------------------------------
ºÇ¸å¤Ë¡¢OpenSSH¤ËLDAP´ØÏ¢¤ÎÀßÄê¤ò¹Ô¤¦¡£
®. /usr/local/ssh/etc/sshd_config¤Ø°Ê²¼¤òÄɵ¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
UseLPK yes
LpkLdapConf /etc/ldap.conf
LpkServers ldap://LDAP¥µ¡¼¥Ð¤ÎIP/
LpkUserDN dc=my-domain,dc=com
LpkBindDN cn=Manager,dc=my-domain,dc=com
LpkBindPw secret
LpkForceTLS yes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
°Ê¾å¤ÇÀßÄê¤ÏÁ´¤Æ´°Î»¡£
². ¥í¡¼¥«¥ë¤ÎtestUser01¤Îºï½ü
# userdel -r testUser01
¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤´¤Èºï½ü¤¹¤ë¡£
¤³¤ì¤Ç¸ø³«¸°¤ÏLDAP¤Ë¤Î¤ß¸ºß¤·¤Æ¤¤¤ë¡£
¤µ¤Æ¡¢¤³¤³¤«¤éưºî³Îǧ¤Ç¤¹¡£
ÈëÌ©¸°¤òwindows PC¤ËÂàÈò¤µ¤»¤¿¤Î¤Ç¤½¤Î¤Þ¤Þwindows¤«¤é³Îǧ¤·¤Æ¤ß¤Þ¤¹¡£
Tera Term¤òΩ¤Á¾å¤²¡¢LDAP¥µ¡¼¥Ð¤ËÂФ·¤ÆSSH¡£
SSH Authentication¤Î¥Ý¥Ã¥×¥¢¥Ã¥×¤¬É½¼¨¤µ¤ì¤¿¤é¡¢¡ÖUse RSA/DSA key to log in¡×¤Ë
¥Á¥§¥Ã¥¯¤òÆþ¤ì¡¢¡ÖPrivate key file¡×¤ËÈëÌ©¸°¤Îrsa¥Õ¥¡¥¤¥ë¤ò»ØÄꤷ¤Æ¤¢¤²¤Þ¤¹¡£
¸å¤Ï¥æ¡¼¥¶¡¼Ì¾¤ËtestUser01¡¢¥Ñ¥¹¥ï¡¼¥É¤ËÀßÄꤷ¤¿¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ¹¤ì¤ÐOK¡£
°Ê¾å¤Ç¡¢Àµ¾ï¤Ë¥í¥°¥¤¥ó½ÐÍè¤Þ¤¹¡£
¤Á¤Ê¤ß¤Ë¤µ¤Ã¤¥í¡¼¥«¥ë¤Î¥æ¡¼¥¶¾Ã¤¹»þ¤Ë¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤â°ì½ï¤Ë¾Ã¤·¤¿¤Î¤Ç¡¢
¥í¥°¥¤¥ó»þ¤Ë¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤¬Â¸ºß¤·¤Ê¤¤¤È¤¤¤¦¥¨¥é¡¼¤Ïɽ¼¨¤µ¤ì¤Þ¤·¤¿¡£
¤Á¤ç¤Ã¤È¤À¤±Êä¡§
ºÇ¸å¤Îưºî³Îǧ¤Ë¤Ä¤¤¤Æ¤Ç¤¹¤¬¡¢putty¤ò»È¤¦¾ì¹ç¤Ï¤Á¤ç¤Ã¤È¤ä¤êÊý¤¬°ã¤¤¤Þ¤¹¡£
putty¤Ïputty·Á¼°¤Î¸°¤·¤«¼õ¤±ÉÕ¤±¤Ê¤¤¤¿¤á¡¢ssh-keygen¤Çºî¤Ã¤¿¸°¤Ï»È¤¨¤Þ¤»¤ó¡£
PuTTYgen¤ò»ÈÍѤ·¤ÆºîÀ®¤·¤¿¸°¤ò¿·¤¿¤ËÅÐÏ¿¤¹¤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
PuTTYgen¤ÏWinSCP¤ËÉÕ°¤Ç¤Ä¤¤¤Æ¤¤¤ë¤Î¤Ç¤Þ¤ºWinSCP¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£
WinSCP¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È¡¢Key Tools¤È¤¤¤¦Ãæ¤ËPuTTYgen¤¬¤¢¤ë¤Î¤Ç¤½¤ì¤òµ¯Æ°¤·¤Þ¤¹¡£
¡ÖGenerate¡×¥Ü¥¿¥ó¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¸°¤ÎÀ¸À®¤¬»Ï¤Þ¤ë¤Î¤Ç¡¢¥¿¥¹¥¯¥Ð¡¼¤¬
¤¹¤Ù¤ÆËä¤Þ¤ë¤Þ¤Ç¡ÖKey¡×¤ÎÏÈÃæ¤Ç¥Þ¥¦¥¹¥«¡¼¥½¥ë¤ò¤Ò¤¿¤¹¤éư¤«¤·¤Þ¤¹¡£
ºîÀ®¸å¤Ë¤Ï¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ·¡¢ÈëÌ©¸°¤ò¡ÖSave private key¡×¤«¤éÊݸ¡£
¼¡¤Ë¡¢¸ø³«¸°¤ÎÃæ¿È¤¬É½¼¨¤µ¤ì¤Æ¤¤¤ë¤Î¤Ç¡¢¤½¤ì¤ò¥á¥âÄ¢¤Ê¤É¤Ë¥³¥Ô¥Ú¤¹¤ë¡£
¤³¤ÎºÝ¡¢²þ¹Ô¤¬¤µ¤ì¤Æ¤Ê¤¤¤«Ãí°Õ¡£
¸å¤Ï¥³¥Ô¥Ú¤·¤¿¸ø³«¸°¤ò¾åµ¤ÈƱ¤¸¼ê½ç¤ÇLDAP¤ËÅÐÏ¿¤¹¤ì¤Ð´°Î»¤Ç¤¹¡£
Ä̾ï¤Î¸°Ç§¾Ú¤Î¾ì¹ç¤Ï¤Þ¤º¸ø³«¸°¤ÈÈëÌ©¸°¤òºîÀ®¤·¡¢¥í¥°¥¤¥óÂоÝ
¥µ¡¼¥Ð¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤Ë¸ø³«¸°¤òÃÖ¤¤¤Æ¤¢¤²¤Ê¤±¤ì¤Ð¤¤¤±¤Þ¤»¤ó¡£
¿ôÂæ¤Ç¤¢¤ì¤Ð¼ê´Ö¤Ç¤Ï¤Ê¤¤¤Ç¤¹¤¬¡¢Â絬ÌϤʥ·¥¹¥Æ¥à¤Ç¤ÏÈó¾ï¤ËÌÌÅÝ¡£
¤Þ¤¿¡¢¿·µ¬¤Ë¥æ¡¼¥¶¡¼¤òÄɲ乤ë¾ì¹ç¤âÁ´Âæ¤Ë¸°¤òÄɲ䷤ʤ±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£
¤½¤³¤Ç¡¢¸ø³«¸°¤òLDAP¤Ç´ÉÍý¤µ¤»¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¾ðÊó¤È°ì½ï¤Ë¸°¤âÆÉ¤ß½Ð¤¹¤è¤¦¤Ë¤¹¤ë¡£
¤½¤¦¤¹¤ì¤ÐÂоݥµ¡¼¥Ð¤¬Áý¤¨¤è¤¦¤¬¿·µ¬¥æ¡¼¥¶¡¼Äɲ䷤褦¤¬¤½¤Î¥µ¡¼¥Ð¤¬
LDAP¤ËÂбþ¤·¤Æ¤µ¤¨¤¤¤ì¤Ð°ìÅÙ¤ÎÅÐÏ¿¤ÇÁ´¤Æ»ö¤¬ºÑ¤ó¤Ç¤·¤Þ¤¤¤Þ¤¹¡£
⤷¥Ñ¥Ã¥±¡¼¥¸¤ÇÆþ¤Ã¤Æ¤¤¤ëOpenSSH¤Ï¸ø³«¸°Ç§¾Ú¤ÎLDAP²½¤ò¥µ¥Ý¡¼¥È¤·¤Æ¤¤¤Ê¤¤¤Î¤Ç¡¢
lpk¥Ñ¥Ã¥Á¤òÅö¤Æ¤¿¥½¡¼¥¹¤«¤é¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë»ö¤Ë¤·¤Þ¤¹¡£
¡. OpenSSH¤Î¥¤¥ó¥¹¥È¡¼¥ë¡£
# tar zxvf openssh-4.6p1.tar.tar
# cd openssh-4.6p1.tar.tar
# patch -p2 < ../openssh-lpk-4.6p1-0.3.9.patch
# ./configure --prefix=/usr/local/ssh/ --with-ldap=/usr/local/ldap/lib/ --with-
¡¡¡¡pam --without-zlib-version-check
# make
# make install
°Ê¾å¤Ç¥¤¥ó¥¹¥È¡¼¥ë¤Î´°Î»¡£
¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿OpenSSH¤¬Àµ¾ï¤Ëưºî¤¹¤ë¤«³Îǧ¡£
¢. ´û¸¤Îsshd¤Î¥¹¥È¥Ã¥×¡£
# /etc/init.d/sshd stop
£. ¿·µ¬¤Îsshd¤Î¥¹¥¿¡¼¥È¡£
# /usr/local/ssh/sbin/sshd
¤. ¥×¥í¥»¥¹¤Î³Îǧ¡£
# ps aux | grep -i sshd
------------------------------------------------------------------------------------------
root 26872 0.4 0.0 5252 1028 ? Ss 15:27 0:00 /usr/local/ssh/sbin/sshd
------------------------------------------------------------------------------------------
¥. ¼ÂºÝ¤Ë¥í¥°¥¤¥ó²Äǽ¤«³Îǧ¤¹¤ëÁ°¤Ë¡¢¥Æ¥¹¥È¥æ¡¼¥¶¡¼¤ÎºîÀ®
# useradd testUser01
# passwd testUser01
¦. ¼ÂºÝ¤Ë¥í¥°¥¤¥ó²Äǽ¤«ssh¤Ç³Îǧ¡£
# ssh -l testUser01 localhost
------------------------------------------------------------------------------------------
The authenticity of host 'localhost (127.0.0.1)' can't be established.
RSA key fingerprint is xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'localhost' (RSA) to the list of known hosts.
testUser01@localhost's password:
[testUser01@localhost ~]
------------------------------------------------------------------------------------------
¿·sshd¤Ç¥í¥°¥¤¥ó¤Ç¤¤ë»ö¤ò³Îǧ¡£
¼¡¤Ë¡¢¸°¤òLDAP¤ËÅÐÏ¿¤¹¤ëÁ°¤Ë¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤ËÃÖ¤¯
Ä̾ïÄ̤ê¤ÎÊý¼°¤Ç¸°Ç§¾Ú¤¬½ÐÍè¤ë¤«¤É¤¦¤«³Îǧ¡£
§. ¸°¤ÎºîÀ®¡£(¥Ñ¥¹¥Õ¥ì¡¼¥º¤òµá¤á¤é¤ì¤ë)
# su - testUser01
# ssh-keygen -t rsa
-----------------------------------------------------------------------------------------
Generating public/private rsa key pair.
Enter file in which to save the key (/home/testUser01/.ssh/id_rsa):
Created directory '/home/testUser01/.ssh'.
Enter passphrase (empty for no passphrase):¡¡
Enter same passphrase again:¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡
Your identification has been saved in /home/testUser01/.ssh/id_rsa.
Your public key has been saved in /home/testUser01/.ssh/id_rsa.pub.
The key fingerprint is:
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx testUser01@xxxxxxx
------------------------------------------------------------------------------------------
¤³¤ì¤Ç¡¢/home/testUser01/.ssh/ÇÛ²¼¤Ë¡¢
id_rsa(ÈëÌ©¸°)¡¢id_rsa.pub(¸ø³«¸°)¤¬ºîÀ®¤µ¤ì¤ë¡£
§. ¸ø³«¸°¤ò¥µ¡¼¥Ð¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤Ë¥³¥Ô¡¼¡£
¡¡¡¡¡ôº£²ó¤Ï¥¯¥é¥¤¥¢¥ó¥È¤È¥µ¡¼¥Ð¤òƱ¤¸¥µ¡¼¥Ð¤È¤·¤Æ¤¤¤ë¤Î¤Çñ¤Ë¥ê¥Í¡¼¥à
# cp id_rsa.pub /home/testUser01/.ssh/authorized_keys2
¨. ssh¤Ç³Îǧ¡£(¥Ñ¥¹¥Õ¥ì¡¼¥º¤òµá¤á¤é¤ì¤ë)
# ssh localhost
------------------------------------------------------------------------
Enter passphrase for key '/home/testUser01/.ssh/id_rsa':
[testUser01@localhost ~]#
------------------------------------------------------------------------
¸ø³«¸°Ç§¾Ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë»ö¤ò³Îǧ¡£
¼¡¤ËLDAP¤Ø¤ÎÅÐÏ¿¡£
¤Þ¤º¡¢LDAP¤Ë¸ø³«¸°¤òÅÐÏ¿¤¹¤ë°Ù¤Ëopenssh-lpk_openldap.schema¤òÆÉ¤ß¹þ¤Þ¤»¤ë¡£
¤³¤Î¥¹¥¡¼¥Þ¤Ï¡¢openssh¤Î¥½¡¼¥¹¤Ë¥Ñ¥Ã¥Á¤ò¤¢¤Æ¤ë¤ÈºîÀ®¤µ¤ì¤ë¡£
©. ¥¹¥¡¼¥Þ¥Õ¥¡¥¤¥ë¤Î¥³¥Ô¡¼¡£
# cp -rp /usr/local/src/openssh-4.6p1/openssh-
¡¡ lpk_openldap.schema /usr/local/ldap/etc/openldap/schema/
ª. ¥¹¥¡¼¥Þ¤òÆÉ¤ß¹þ¤à¤è¤¦¤Ëslapd.conf¤ÎÊÔ½¸¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include /usr/local/ldap/etc/openldap/schema/openssh-
lpk_openldap.shcema
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
«. slapd¤ÎºÆµ¯Æ°¡£
# kill -HUP `cat /usr/local/ldap/var/run/slapd.pid`
# /usr/local/ldap/libexec/slpad
¼¡¤ËtestUser01¤òLDAP¤ËÅÐÏ¿¤¹¤ë¡£¤³¤Î»þ¸ø³«¸°¤â°ì½ï¤ËÅÐÏ¿¤¹¤ë¡£
¬. °Ê²¼¤Îldif(testUser01.ldif)¥Õ¥¡¥¤¥ë¤òÍѰա£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
dn: uid=testUser01,dc=my-domain,dc=com
objectClass: account
objectClass: posixAccount
objectClass: ldapPublickey
cn: devproxy
uid: devproxy
uidNumber: 10001
gidNumber: 10001
homeDirectory: /home/devproxy
userPassword: devproxy
loginShell: /bin/bash
sshPublicKey: xxxxxxxxxxxxxxxxxxxxxxxxxxx
~~~~~~~~~~~~~~~~~~~~~~~~~~~~
sshPublickey°À¤Ë¤ÏÀèÄø¥³¥Ô¡¼¤·¤¿authorized_keys2¤ÎÃæ¿È¤ò¤Þ¤ë¤Þ¤ë¥³¥Ô¥Ú¤¹¤ë¡£
¤³¤Î»þ²þ¹Ô¤Ê¤É¤¬´Þ¤Þ¤ì¤Ê¤¤¤è¤¦¤ËÃí°Õ¡£
. testUser01.ldif¤òldapadd¡£
# ldapadd -x -ZZ -D "cn=Manager,dc=my-domain,dc=com" -w secret -f
¡¡ testUser01.ldif
---------------------------------------------------------------------------
adding new entry "uid=testUser01,dc=my-domain,dc=com"
---------------------------------------------------------------------------
ºÇ¸å¤Ë¡¢OpenSSH¤ËLDAP´ØÏ¢¤ÎÀßÄê¤ò¹Ô¤¦¡£
®. /usr/local/ssh/etc/sshd_config¤Ø°Ê²¼¤òÄɵ¡£
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
UseLPK yes
LpkLdapConf /etc/ldap.conf
LpkServers ldap://LDAP¥µ¡¼¥Ð¤ÎIP/
LpkUserDN dc=my-domain,dc=com
LpkBindDN cn=Manager,dc=my-domain,dc=com
LpkBindPw secret
LpkForceTLS yes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
°Ê¾å¤ÇÀßÄê¤ÏÁ´¤Æ´°Î»¡£
². ¥í¡¼¥«¥ë¤ÎtestUser01¤Îºï½ü
# userdel -r testUser01
¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤´¤Èºï½ü¤¹¤ë¡£
¤³¤ì¤Ç¸ø³«¸°¤ÏLDAP¤Ë¤Î¤ß¸ºß¤·¤Æ¤¤¤ë¡£
¤µ¤Æ¡¢¤³¤³¤«¤éưºî³Îǧ¤Ç¤¹¡£
ÈëÌ©¸°¤òwindows PC¤ËÂàÈò¤µ¤»¤¿¤Î¤Ç¤½¤Î¤Þ¤Þwindows¤«¤é³Îǧ¤·¤Æ¤ß¤Þ¤¹¡£
Tera Term¤òΩ¤Á¾å¤²¡¢LDAP¥µ¡¼¥Ð¤ËÂФ·¤ÆSSH¡£
SSH Authentication¤Î¥Ý¥Ã¥×¥¢¥Ã¥×¤¬É½¼¨¤µ¤ì¤¿¤é¡¢¡ÖUse RSA/DSA key to log in¡×¤Ë
¥Á¥§¥Ã¥¯¤òÆþ¤ì¡¢¡ÖPrivate key file¡×¤ËÈëÌ©¸°¤Îrsa¥Õ¥¡¥¤¥ë¤ò»ØÄꤷ¤Æ¤¢¤²¤Þ¤¹¡£
¸å¤Ï¥æ¡¼¥¶¡¼Ì¾¤ËtestUser01¡¢¥Ñ¥¹¥ï¡¼¥É¤ËÀßÄꤷ¤¿¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ¹¤ì¤ÐOK¡£
°Ê¾å¤Ç¡¢Àµ¾ï¤Ë¥í¥°¥¤¥ó½ÐÍè¤Þ¤¹¡£
¤Á¤Ê¤ß¤Ë¤µ¤Ã¤¥í¡¼¥«¥ë¤Î¥æ¡¼¥¶¾Ã¤¹»þ¤Ë¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤â°ì½ï¤Ë¾Ã¤·¤¿¤Î¤Ç¡¢
¥í¥°¥¤¥ó»þ¤Ë¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤¬Â¸ºß¤·¤Ê¤¤¤È¤¤¤¦¥¨¥é¡¼¤Ïɽ¼¨¤µ¤ì¤Þ¤·¤¿¡£
¤Á¤ç¤Ã¤È¤À¤±Êä¡§
ºÇ¸å¤Îưºî³Îǧ¤Ë¤Ä¤¤¤Æ¤Ç¤¹¤¬¡¢putty¤ò»È¤¦¾ì¹ç¤Ï¤Á¤ç¤Ã¤È¤ä¤êÊý¤¬°ã¤¤¤Þ¤¹¡£
putty¤Ïputty·Á¼°¤Î¸°¤·¤«¼õ¤±ÉÕ¤±¤Ê¤¤¤¿¤á¡¢ssh-keygen¤Çºî¤Ã¤¿¸°¤Ï»È¤¨¤Þ¤»¤ó¡£
PuTTYgen¤ò»ÈÍѤ·¤ÆºîÀ®¤·¤¿¸°¤ò¿·¤¿¤ËÅÐÏ¿¤¹¤ë»ö¤Ë¤Ê¤ê¤Þ¤¹¡£
PuTTYgen¤ÏWinSCP¤ËÉÕ°¤Ç¤Ä¤¤¤Æ¤¤¤ë¤Î¤Ç¤Þ¤ºWinSCP¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£
WinSCP¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È¡¢Key Tools¤È¤¤¤¦Ãæ¤ËPuTTYgen¤¬¤¢¤ë¤Î¤Ç¤½¤ì¤òµ¯Æ°¤·¤Þ¤¹¡£
¡ÖGenerate¡×¥Ü¥¿¥ó¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¸°¤ÎÀ¸À®¤¬»Ï¤Þ¤ë¤Î¤Ç¡¢¥¿¥¹¥¯¥Ð¡¼¤¬
¤¹¤Ù¤ÆËä¤Þ¤ë¤Þ¤Ç¡ÖKey¡×¤ÎÏÈÃæ¤Ç¥Þ¥¦¥¹¥«¡¼¥½¥ë¤ò¤Ò¤¿¤¹¤éư¤«¤·¤Þ¤¹¡£
ºîÀ®¸å¤Ë¤Ï¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ·¡¢ÈëÌ©¸°¤ò¡ÖSave private key¡×¤«¤éÊݸ¡£
¼¡¤Ë¡¢¸ø³«¸°¤ÎÃæ¿È¤¬É½¼¨¤µ¤ì¤Æ¤¤¤ë¤Î¤Ç¡¢¤½¤ì¤ò¥á¥âÄ¢¤Ê¤É¤Ë¥³¥Ô¥Ú¤¹¤ë¡£
¤³¤ÎºÝ¡¢²þ¹Ô¤¬¤µ¤ì¤Æ¤Ê¤¤¤«Ãí°Õ¡£
¸å¤Ï¥³¥Ô¥Ú¤·¤¿¸ø³«¸°¤ò¾åµ¤ÈƱ¤¸¼ê½ç¤ÇLDAP¤ËÅÐÏ¿¤¹¤ì¤Ð´°Î»¤Ç¤¹¡£
![]() | LDAP Super Expert (2006/04/11) ÊÔ½¸Éô ¾¦Éʾܺ٤ò¸«¤ë OpenLDAP ver2.3¤Î¿·µ¡Ç½¤Ê¤É¤Ë¤Ä¤¤¤Æ¾Ü¤·¤¯½ñ¤«¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¤¤¤¯¤Ä¤«¤Î¥ß¥É¥ë¥¦¥§¥¢Ï¢·È¤Î¾¡¢OpenSSH¸°Ç§¾ÚLDAP²½¤äsudo¤ÎLDAP²½¤Þ¤Ç½ñ¤«¤ì¤Æ¤¤¤Æ¤¤¤ë¤Î¤¬Èó¾ï¤ËÌòΩ¤Ä¡£ |
| ¥Û¡¼¥à |
¼¡¤Î¥Ú¡¼¥¸ »




