17.5. Keberos 5¥µ¡¼¥Ð¡¼¤ÎÀßÄê

Kerberos¤ò¹½ÃÛ¤¹¤ë¤Ë¤Ï¡¢ºÇ½é¤Ë¥µ¡¼¥Ð¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£¥¹¥ì¡¼¥Ö¥µ¡¼¥Ð¡¼¤ò¹½ÃÛ¤¹¤ë¤Ë¤Ï¡¢ ¥Þ¥¹¥¿¡¼¤È¥¹¥ì¡¼¥Ö¥µ¡¼¥Ð¡¼´Ø·¸¤ò¹½ÃÛ¤¹¤ë¾ÜºÙ¤¬Keberos 5 Installation Guide (/usr/share/doc/krb5-server-<¥Ð¡¼¥¸¥ç¥óÈÖ¹æ> ¥Ç¥£¥ì¥¯¥È¥ê¤ÎÃæ)¤Ë¤¢¤ê¤Þ¤¹¤Î¤Ç»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

´ðËÜŪ¤Ê Kerberos¥µ¡¼¥Ð¤òÀßÄꤹ¤ë¤Ë¤Ï¡¢°Ê²¼¤Î¥¹¥Æ¥Ã¥×¤Ë½¾¤¤¤Þ¤¹¡§

  1. Kerberos 5¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ëÁ°¤Ë¡¢»þ·×Ʊ´ü¤ÈDNS¤¬¥µ¡¼¥Ð¡¼¤Ç Àµ¾ï¤ËÆ°ºî¤·¤Æ¤¤¤ë»ö¤ò³Îǧ¤·¤Æ¤¯¤À¤µ¤¤¡£Kerberos¥µ¡¼¥Ð¡¼¤È³Æ¥¯¥é¥¤¥¢¥ó¥È´Ö¤Î »þ·×Ʊ´ü¤ÏÆäËÃí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡£¤â¤·¡¢¥µ¡¼¥Ð¡¼¤È¥¯¥é¥¤¥¢¥ó¥È¤Î»þ·×¤¬£µÊ¬°Ê¾å °Û¤Ê¤Ã¤Æ¤¤¤¿¤é¡¢(¤³¤ì¤Ï¥Ç¥Õ¥©¥ë¥È¤ÎKeberos 5ÀßÄê»þ´Ö¤Ç¤¹¡£)Kerberos¥¯¥é¥¤¥¢¥ó¥È¤Ï ¥µ¡¼¥Ð¡¼¤Ëǧ¾Ú¤µ¤ì¤Þ¤»¤ó¡£¤³¤Î»þ·×Ʊ´ü¤Ï¡¢Àµµ¬¤Î¥æ¡¼¥¶¡¼¤Èµ¶¤Ã¤Æ¡¢¸Å¤¤Kerberos ¥Á¥±¥Ã¥È¤òÍѤ¤¤ë¥¢¥¿¥Ã¥«¡¼¤òËɻߤ¹¤ë¤¿¤á¤ËɬÍפǤ¹¡£

    Keberos¤òÍѤ¤¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ç¤â¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¥¯¥é¥¤¥¢¥ó¥È/¥µ¡¼¥Ð¡¼¸ß´¹¤Î NTP(Network Time Protocol)¤ÎÀßÄê¤ò¤¹¤Ù¤­¤Ç¤¹¡£Red Hat Linux¤Ë¤Ï¡¢´Êñ¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤Ç¤­¤ë ntp¥Ñ¥Ã¥±¡¼¥¸¤¬´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£Network Time Protocol¥µ¡¼¥Ð¤Î ÀßÄê¤Ë´Ø¤¹¤ë¾ÜºÙ¤Ë¤Ï/usr/share/doc/ntp-<version-number>/index.htm¤ò »²¾È¤·¤Æ¡¢NTP¤Ë´Ø¤¹¤ë¤½¤Î¾¤Î¾ðÊó¤Ë¤Ä¤¤¤Æ¤Ï http://www.eecis.udel.edu/~ntp¤ò¸æÍ÷²¼¤µ¤¤¡£

  2. KDC¤¬¼Â¹Ô¤¹¤ë¤è¤¦¤Ë·èÄꤷ¤Æ¤¤¤ëÀìÍÑ¥Þ¥·¥ó¤Ë¡¢krb5-libs, krb5-server, krb5-workstation¤ò¥¤¥ó¥¹¥È¡¼¥ë ¤·¤Þ¤¹¡£¤³¤Î¥Þ¥·¥ó¤ÏÆä˥»¥­¥å¥¢¤Ç¤¢¤ë¤³¤È¤¬É¬ÍפǤ¹¡£ —²Äǽ¤Ê¤é¡¢KDC°Ê³°¤Î ¾¤Î¥µ¡¼¥Ó¥¹¤Ï¼Â¹Ô¤·¤Ê¤¤¤³¤È¤¬Ë¾¤Þ¤ì¤Þ¤¹¡£

    Kerberos¤ò´ÉÍý¤¹¤ë¤Î¤Ë¡¢GUI(Graphical User Interface)¤ò»È¤¤¤¿¤¤¾ì¹ç¤Ï¡¢ gnome-kerberos¥Ñ¥Ã¥±¡¼¥¸¤â¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤¯¤À¤µ¤¤¡£ ¤³¤Î¥Ñ¥Ã¥±¡¼¥¸¤Ë¤Ï¡¢krb5¤È¤¤¤¦¥Á¥±¥Ã¥È¤ò´ÉÍý¤¹¤ëGUI¥Ä¡¼¥ë¤¬ ´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£

  3. realm̾¤È¥É¥á¥¤¥ó-realm´Ö¥Þ¥Ã¥Ô¥ó¥°¤òÈ¿±Ç¤¹¤ë¤¿¤á¤Ë¤Ï/etc/krb5.conf¤È /var/keberos/krb5kdc/kdc.confÀßÄê¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Æ¤¯¤À¤µ¤¤¡£´Êñ¤Êreaml¤Ï EXAMPLE.COM¤Èexample.com¤ÎÎã¤ò¥É¥á¥¤¥ó̾ —Âçʸ»ú¤«¾®Ê¸»ú¤«¡¢Àµ¤·¤¤¥Õ¥©¡¼¥Þ¥Ã¥È¤ò³Î¤«¤á¤Æ²¼¤µ¤¤—¤ÇÃÖ¤­´¹¤¨¡¢¤½¤·¤Æ KDC¤òkerberos.example.com¤«¤éKerberos¥µ¡¼¥Ð¡¼Ì¾¤ËÊѹ¹¤¹¤ë¤³¤È¤Ç¡¢ ¹½ÃۤǤ­¤Þ¤¹¡£´·½¬Åª¤Ë¡¢realm̾¤ÏÂçʸ»ú¤Ç¡¢DNS¥Û¥¹¥È̾¤È¥É¥á¥¤¥ó̾¤Ï¾®Ê¸»ú¤Ç¤¹¡£ ¤³¤ì¤é¥Õ¥¡¥¤¥ë·Á¼°¤Î¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢³ºÅö¤¹¤ë¥Þ¥Ë¥å¥¢¥ë¥Ú¡¼¥¸¤ò»²¾È¤¯¤À¤µ¤¤¡£

  4. ¥·¥§¥ë¥×¥í¥ó¥×¥È¤«¤ékrb5_util¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤ò»È¤Ã¤Æ¥Ç¡¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡§

    /usr/kerberos/sbin/kdb5_util create -s

    create¥³¥Þ¥ó¥É¤ÏKerberos realm¤Î¸°¤ò³ÊǼ¤¹¤ë¤¿¤á¤Ë»ÈÍѤ¹¤ë ¥Ç¡¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡£-s¥¹¥¤¥Ã¥Á¤Ï¡¢¥Þ¥¹¥¿¡¼¥µ¡¼¥Ð¡¼¸°¤ò ³ÊǼ¤¹¤ëstash¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¤Þ¤¹¡£¸°¤òÆɤि¤á¤Îstash¥Õ¥¡¥¤¥ë¤¬ ̵¤¤¾ì¹ç¤Ï¡¢Kerberos¥µ¡¼¥Ð¡¼(krb5kdc)¤Ï µ¯Æ°¤¹¤ëÅ٤ˡ¢ ¥æ¡¼¥¶¡¼¤Ë¥Þ¥¹¥¿¡¼¥µ¡¼¥Ð¡¼¥Ñ¥¹¥ï¡¼¥É(¸°¤òºÆÀ¸À®¤¹¤ë¤Î¤Ë»È¤ï¤ì¤ë)¤ÎÆþÎϤòÂ¥¤·¤Þ¤¹¡£

  5. /var/kerberos/krb5kdc/kadm5.acl¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Þ¤¹¡£ ¤³¤Î¥Õ¥¡¥¤¥ë¤Ï¤É¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤¬Kerberos¥Ç¡¼¥¿¥Ù¡¼¥¹¤Ë¤É¤Î¥ì¥Ù¥ë¤Ç¥¢¥¯¥»¥¹¤¹¤ë¤«¤ò·è¤á¤ë kadmind¤Ç»È¤ï¤ì¤Þ¤¹¡£Â¿¤¯¤Î¾ì¹ç¡¢°Ê²¼¤ÎÍͤ˰ì¹Ô¤ÇÊÔ½¸¤Ç¤­¤Þ¤¹¡§

    */admin@EXAMPLE.COM  *

    ¤Û¤È¤ó¤É¤Î¥æ¡¼¥¶¡¼¤Ï¡¢¥Ç¡¼¥¿¥Ù¡¼¥¹¾å¤Ëñ°ì¤Î¥×¥ê¥ó¥·¥Ñ¥ë(Î㤨¤Ðjoe@EXAMPLE.COM¤ÎÎ㠤褦¤ËNULL¤¢¤ë¤¤¤Ï¶õ¤Ç¡Ë¤Çɽ¼¨¤µ¤ì¤Þ¤¹¡£¤³¤ÎÀßÄê¤òÍѤ¤¤Æ¡¢Â裲¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤ò»ý¤Ã¤Æ¤¤¤ë ¥æ¡¼¥¶¡¼¤Ï(Î㤨¤Ðjoe/admin@EXAMPLE.COM¤Î¤è¤¦¤Ë)admin¤ÎÎã¤ò»È¤Ã¤Æ realm¤ÎKerberos¥Ç¡¼¥¿¥Ù¡¼¥¹¾å¤ÇÁ´¸¢¸Â¤ò»È¤¦»ö¤¬¤Ç¤­¤Þ¤¹¡£

    °ìö¡¢kadmind¤¬¥µ¡¼¥Ð¡¼¾å¤Çµ¯Æ°¤¹¤ë¤È¡¢realmÆâ¤Î¥¯¥é¥¤¥¢¥ó¥È¤ä ¥µ¡¼¥Ð¡¼¤«¤ékadmin¤òµ¯Æ°¤¹¤ë»ö¤Ç¡¢¤É¤Î¥æ¡¼¥¶¡¼¤â ¤½¤Î¥µ¡¼¥Ó¥¹¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤Þ¤¹¡£¤·¤«¤·¡¢kadm5.acl¥Õ¥¡¥¤¥ë¤Ë µ­ºÜ¤µ¤ì¤Æ¤¤¤ë¥æ¡¼¥¶¤À¤±¤¬¡¢¼«¿È¤Î¥Ñ¥¹¥ï¡¼¥ÉÊѹ¹°Ê³°¤Ê¤é¡¢¤É¤Î¤è¤¦¤ÊÊѹ¹¤â ¥Ç¡¼¥¿¡¼¥Ù¡¼¥¹¤ËÂФ·¤Æ¹Ô¤¨¤Þ¤¹¡£

    Ãí°ÕÃí°Õ
     

    kadmin¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤Ï¥Í¥Ã¥È¥ï¡¼¥¯±Û¤·¤Ëkadmind¥µ¡¼¥Ð¡¼¤È ÄÌ¿®¤·¤Æ¤ª¤ê¡¢Ç§¾Ú¤ò°·¤¦¤¿¤á¤ËKerberos¤ò»È¤¤¤Þ¤¹¡£ÅöÁ³¡¢¥Í¥Ã¥È¥ï¡¼¥¯±Û¤·¤Ë¥µ¡¼¥Ð¡¼¤ËÀܳ¤¹¤ëÁ°¤Ë¡¢ ¥Í¥Ã¥È¥ï¡¼¥¯¤ò´ÉÍý¤¹¤ëÂè°ì¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£Âè°ì¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤¹¤ë¤Ë¤Ï kadmin.local¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Þ¤¹¡£¤³¤ì¤ÏÆäËKDC¤ÈƱ¤¸¥Û¥¹¥È¤Ç»ÈÍѤ¹¤ë¤è¤¦¤Ë À߷פ·¤Æ¤¢¤ê¡¢Ç§¾ÚÍѤËKerberos¤ò»ÈÍѤ·¤Þ¤»¤ó¡£

    Âè°ì¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤¹¤ë¤Ë¤Ï¡¢KDC¥¿¡¼¥ß¥Ê¥ë¤Ç¼¡¤Îkadmin.local¥³¥Þ¥ó¥É¤ò ÆþÎϤ·¤Þ¤¹¡§

    /usr/kerberos/sbin/kadmin.local -q "addprinc username/admin"
  6. °Ê²¼¤Î¥³¥Þ¥ó¥É¤ÇKerberos¤òµ¯Æ°¤·¤Þ¤¹¡§

    /sbin/service krb5kdc start
    /sbin/service kadmin start
    /sbin/service krb524 start
  7. addprinc¥³¥Þ¥ó¥É¤Èkadmin»ÈÍѤ·¤Æ¥æ¡¼¥¶¡¼¤Î¤¿¤á¤Î ¥×¥ê¥ó¥·¥Ñ¥ë¤òÄɲä·¤Þ¤¹¡£kadmin¤Èkadmin.local¤ÏKDC¤Î ¥³¥Þ¥ó¥É¥é¥¤¥ó¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹¤Ç¤¹¡£¤³¤ÎÃæ¤Ç¤Ï¡¢kadmin¥×¥í¥°¥é¥à¤ò µ¯Æ°¤·¤¿¸å¤Ë¿¤¯¤Î¥³¥Þ¥ó¥É¤¬ÍøÍѤǤ­¤Þ¤¹¡£¾ÜºÙ¤Ïkadmin¤Îman ¥Ú¡¼¥¸¤ò¸æÍ÷²¼¤µ¤¤¡£

  8. ¥·¥¹¥Æ¥à¤¬¥Á¥±¥Ã¥È¤òȯ¹Ô¤Ç¤­¤ë¤«³Î¤«¤á¤Þ¤¹¡£ºÇ½é¤Ë¡¢kinit¤ò ¼Â¹Ô¤·¤Æ¥Á¥±¥Ã¥È¤òÀ¸À®¤·¡¢¾ÚÌÀ½ñ¥­¥ã¥Ã¥·¥å¥Õ¥¡¥¤¥ë¤Ë³ÊǼ¤·¤Þ¤¹¡£¤½¤ì¤«¤éklist¤ò »ÈÍѤ·¤Æ¥­¥ã¥Ã¥·¥åÆâ¤Î¾ÚÌÀ½ñ°ìÍ÷¤òɽ¼¨¤·¤Æ¡¢¤½¤Î¸å¡¢kdestroy¤ò ÍѤ¤¤Æ¡¢¥­¥ã¥Ã¥·¥å¤È¤½¤ÎÃæ¿È¤Î¾ÚÌÀ½ñ¤òÇË´þ¤·¤Þ¤¹¡£

    Ãí°ÕÃí°Õ
     

    ¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¡¢kinit¤Ï¡¢ºÇ½é¤Ë¥·¥¹¥Æ¥à(Kerberos¥µ¡¼¥Ð¡¼¤Ç¤Ï¤Ê¤¤¡Ë¤Ë ¥í¥°¥¤¥ó¤·¤¿»þ¤Ë»È¤Ã¤¿¥¢¥«¥¦¥ó¥È¤Î¥í¥°¥¤¥ó¥æ¡¼¥¶¡¼Ì¾¤òÍѤ¤¤Æ¡¢Ç§¾Ú¤·¤è¤¦¤È¤·¤Þ¤¹¡£ ¤½¤Î¥·¥¹¥Æ¥à¤Î¥æ¡¼¥¶¡¼Ì¾¤¬Kerberos¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤È¹çÃפ·¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ï¡¢ ¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤¬É½¼¨¤µ¤ì¤Þ¤¹¡£¤³¤Î¾ì¹ç¤Ï¡¢¥³¥Þ¥ó¥É¥é¥¤¥ó¤Î°ú¿ô¤È¤·¤Æ¥×¥ê¥ó¥·¥Ñ¥ë¤Î̾Á°¤ò kinit¤ËÍ¿¤¨¤Þ¤¹¡£(kinitprincipal)¡£

°Ê¾å¤Î¥¹¥Æ¥Ã¥×¤ò´°Î»¤¹¤ë¤È¡¢Kerberos¥µ¡¼¥Ð¡¼¤Ïµ¯Æ°¤·ºîÆ°¤·¤Æ¤ë¤Ï¤º¤Ç¤¹¡£¼¡¤Ï¡¢ Kerberos¥¯¥é¥¤¥¢¥ó¥È¤ÎÀßÄê¤ò¤·¤Þ¤¹¡£