
ãã³ããŒã¯ãã·ã¹ãã èªäœãšHardening / Security Guideã¯ã©ã¹ããã¥ã¢ã«ã®äž¡æ¹ãèšå®ããæ¹æ³ã«é¢ããããã¥ã¡ã³ãããŸããŸããªãªãŒã¹ããŠããŸãã Citrixã¯ãCommon Criteria Security Target and User Security GuideããªãªãŒã¹ããŸããã ãããã®ããã¥ã¡ã³ãã«ã¯å€ãã®æšå¥šäºé ãšãã³ãããããŸãããå®çšçãªæ å ±ãå°ãªãããŸãã CCSTããã¥ã¡ã³ãã§ã¯ãä¿è·ããããªããžã§ã¯ãã®æ£åŒãªèª¬æãšå®éã®èšå®ã®æ°ãèŠã€ããããšãã§ããŸãã ãŠãŒã¶ãŒã»ãã¥ãªãã£ã§ã¯ãäŒç€Ÿã¯äžè¬çãªã·ã¹ãã ä¿è·æ¹æ³è«ã«ã€ããŠèª¬æããŸããã ãããã£ãŠãæ®å¿µãªããããã¹ãŠã®åŽé¢ãå®å šã«ã«ããŒããå®å šãªCitrixã»ãã¥ãªãã£ã¬ã€ããæ¬ èœããŠããŸãã
2011幎ãCitrixã¯ISSA Security Organization of the Yearã®ã¿ã€ãã«ãç²åŸããŸããã ãSecured By Designããšããçšèªã¯Citrix補åã«é©çšãããããšã匷調ãããŸããã ããããããã®äŒç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã®äžéšã¯ãã®ã«ããŽãªã«èµ·å ããå¯èœæ§ããããŸãããXenServerã®ãµãŒããŒè£œåã®èª¿æ»ã§ã¯ãèšèšã®ããã€ãã®ä»æ§ã®ååšãšãCitrixå°é家ã°ã«ãŒãã«ãããã®çšèªã®è§£éã®äžææ§ã瀺ãããŸããã ãã®èšäºã§ã¯ãCitrix Free XenServer 5.6.0ã®åäœã®ããã€ãã®åŽé¢ãšããã®ã·ã¹ãã ã®å®éã®äœ¿çšäžã«çºçããå¯èœæ§ã®ããã»ãã¥ãªãã£ã®åé¡ã«ã€ããŠèª¬æããŸãã ãã®ç¹å®ã®ããŒãžã§ã³ã®éžæã¯ãããªãé«ãæç çãšäººæ°ã«ãããã®ã§ãã 以äžã§è¿°ã¹ãããŠããããšã®å€ãã¯ã第6ãã¡ããªã®ããŒãžã§ã³ã§å€æŽãããŠããŸããã
ãã€ããŒãã€ã¶ãŒå šäœã®åºç€ã¯XenAPIïŒXAPIïŒã§ãã ããã¯ãã¹ãŒããŒãŠãŒã¶ãŒæš©éãæã€ã·ã¹ãã ã«ãã£ãŠå®è¡ãããããŒã¢ã³ã§ãããã·ã¹ãã èªäœãšä»®æ³ãã·ã³ã管çããããã®ã€ã³ã¿ãŒãã§ãŒã¹ãæäŸããŸãã Red Hat Enterprise Linuxãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®çŽæ¥ã®èŠªAsãšããŠããã€ããŒãã€ã¶ãŒã¯ãã®å ç¥ããå€ãã®æšæºãœãªã¥ãŒã·ã§ã³ãç¶æ¿ããŸããã ããã¯ãXAPIãžã®æ¥ç¶ãæ åœããPAMã¢ãžã¥ãŒã«ã§ãã
ãã®ã¢ãžã¥ãŒã«ã¯ãããã©ã«ãã§system-authã®æšæºèšå®ãå®å šã«å«ãããã«æ§æãããŠããŸãã å®éã«ã¯ãããã¯ãã·ã¹ãã å ã®ã¢ã«ãŠã³ããæã€ãã¹ãŠã®ãŠãŒã¶ãŒããAPIã䜿çšããŠã«ãŒããã¹ã¯ãŒããå€æŽããå Žåãé€ããpool-adminç¹æš©ã§XAPIèŠæ±ãå®è¡ã§ããããšãæå³ããŸãã ã·ã¹ãã ã®ãã®æ©èœã¯ææžåãããŠãããFreeããã³Advanceã®ããŒãžã§ã³ã«åºæã®ãã®ã§ãã Citrixã®ããªã·ãŒã«ãããšããããã®XenServerããªã¢ã³ãã䜿çšããå Žåããã·ã³ã°ã«ã¬ãã«ããŠãŒã¶ãŒïŒLSUïŒããŒã«ã«ã¹ãŒããŒãŠãŒã¶ãŒïŒïŒãæã€ã·ã¹ãã ããããŸãã Citrixã®ãã®æ±ºå®ã¯ãäŒæ¥ã¬ãã«ã®è£œåãæ§ç¯ãããšããã€ããªãã®ãŒã®æ çµã¿ã®äžã§äžè¬ã«ç解ãããŠãããšã¯æããŸããã
ãã®ç¹ç°æ§ã«ããããã€ããŒãã€ã¶ãŒããã«ããŠãŒã¶ãŒã·ã¹ãã ãšããŠäœ¿çšãããã¬ãŒã ã¯ãŒã¯ã«ããã€ãã®åé¡ãçããŸãã åºå¥ãäœæããã«ã¯ãxapiã¢ãžã¥ãŒã«ã®PAMèšå®ã調æŽããŠããã€ããŒãã€ã¶ãŒãå¶åŸ¡ã§ãã人æ°ãå¶éããå¿ èŠããããŸãã ããã«ã¯å€ãã®å¯èœæ§ããããæšæºã®PAMããŒã«ã¯ãã¹ãŠèªç±ã«äœ¿çšã§ããŸãã PAPIæ©èœã®èª¬æãšXAPIã»ãã¥ãªãã£ãæ§æããããã®ã¢ã€ãã¢ã¯ãAndrew G. MortanãšThorsten Kukukã«ãããThe Linux-PAM System Administrators Guideãã«ãããŸãã
XAPIã®å¥ã®ç¹å®ã®æ©èœã¯ãã·ã¹ãã å ã®HTTP / HTTPSãä»ãããªã¢ãŒãå¶åŸ¡ã®å¯çšæ§ã§ãã ããŒã¢ã³ã¯ã管çã€ã³ã¿ãŒãã§ãŒã¹ã§ããŒã80ããã³443ãéãããŸãŸã«ããŸãã ãã®èšäºã§ã¯ãå¶åŸ¡ãããã¯ãŒã¯ãç©ççã«åé¢ãããå¯èœæ§ãããããããã®åé¡ãããæ·±å»ã§ãªããã«ãã€ã³ã¿ãŒãã§ã€ã¹ã·ã¹ãã ã«ã€ããŠã¯èæ ®ããŸããã ããããç§ã¯ãã®ã¬ã€ã¢ãŠããå®çšŒåãœãªã¥ãŒã·ã§ã³ã«å¿ èŠã§ããããšã«æ³šæããããšæããŸãã

å€ãã®å Žåã管çã€ã³ã¿ãŒãã§ã€ã¹ã¯ãããŒã¿è»¢éãšã«ã¹ã±ãŒãä»®æ³ãã·ã³ã«ãå ±éããŠããŸãã ãããã£ãŠãSSLãã³ãã«ã䜿çšããã«ããŒã80ãå¶åŸ¡ãããšãæ»æè ã¯å°ãªããšãã¹ããã¡ãŒã䜿çšããŠã·ã¹ãã èšå®ãååŸããã³ãŒãã®æ¿å ¥ãæåãããããå¶åŸ¡ã»ãã·ã§ã³ãæ倧éã«ååããããšãã§ããŸãã ãªãã·ã§ã³ãšããŠãiptablesãæé©ã§ãã äžè¬ã«ãã·ã¹ãã ã®80 \ 443ããŒãã«çä¿¡ãããã©ãã£ãã¯ãå¶éãã䟡å€ããããŸãã ãã®è³ªåã¯ãCitrix XenServer 5.6 Platinum Editionã®Citrix Common Criteria Evaluated Configuration Guideã§èª¬æãã䟡å€ããããŸãã
次ã®çãããå Žæãæ確ã«ããããã«ãCitrix XenServerã®ã¢ãŒã¿ãªã³ã°ã«ã€ããŠããå°ã詳ããèŠãŠã¿ãŸãããã ä»®æ³ãã·ã³ãžã®ã¢ã¯ã»ã¹ã容æã«ããããã«ããã€ããŒãã€ã¶ãŒã¯ã²ã¹ãã·ã¹ãã ã®ããã¹ã/ã°ã©ãã£ãã¯ã³ã³ãœãŒã«ã®XAPIãžã®è»¢éã䜿çšããŸãã ãããè¡ãã«ã¯ãå°ããªããã°ã©ã vnctermã䜿çšããŸãã äœæ¥ã®ã€ããªãã®ãŒã¯ã»ãŒæ¬¡ã®ãšããã§ããXAPIã«ãã£ãŠã³ã³ãœãŒã«ãèŠæ±ããããšã vnctermããã»ã¹ã®ãã©ãŒã¯ãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§äœæãããXAPIã§ãŠãŒã¶ãŒã«éä¿¡ãããŸãã

ããã¯ããã€ããŒãã€ã¶ãŒãã¹ãèªäœãå«ããã¹ãŠã®ãã¹ãã§çºçããŸãã ããã€ãã®äŸå€ãé€ããŸãã èªèšŒã®ããã«ãã€ããŒãã€ã¶ãŒãéä¿¡ãã代ããã«ããã€ããŒãã€ã¶ãŒã®ãã¹ãã«æ¥ç¶ãããšãCitrixã®äœæè ã³ãŒããå®è¡ãããrootãšããŠããŒã«ã«ã³ã³ãœãŒã«ã«å³åº§ã«ã¢ã¯ã»ã¹ã§ããŸãã

Active Directoryã«ãã€ã³ãããã«ãµãŒããŒäžã§XAPIã¢ã¯ã»ã¹ãæã€ãŠãŒã¶ãŒã¯ããã€ããŒãã€ã¶ãŒãã¹ããžã®ã«ãŒãã¢ã¯ã»ã¹ãååŸã§ããŸãã
vnctermã®äºæ¬¡çãªåé¡ãšããŠããã¹ãŠã®ã»ãã·ã§ã³ã1ã€ã ãã§ããããšã«æ³šæããŠãã ããã ã€ãŸããrootãšããŠã²ã¹ãã·ã¹ãã äžã«ã»ãã·ã§ã³ãäœæããã²ã¹ãã·ã¹ãã ãããã°ã¢ãŠãããããšãå¿ããããšã§ãéããŠããVNCãã£ãã«ãæ®ããŸãã ãã®ã²ã¹ãã·ã¹ãã ãžã®æ¬¡ã®èŠæ±ã§ããã¹ãŠã®XAPIãŠãŒã¶ãŒã¯åããªãŒãã³ã»ãã·ã§ã³ãåãåããŸãã ã·ã¹ãã ã®äŸµå®³ã¯é¿ããããŸããã ããŒã«ã«ãŠãŒã¶ãŒèªèšŒã¯ãèªåxsconsoleããŒãã䜿çšããmingetty âautologinã«ãŒãã§ãèªåçã«è¡ãããããšã«æ³šæããŠãã ããã

ããã¯éèŠã§ã¯ãããŸããããshã³ãŒããæ³šå ¥ããããšã¯çè«çã«ã¯å¯èœã§ãã ãããã£ãŠãã·ã¹ãã ãžã®ã¹ãŒããŒãŠãŒã¶ãŒç¹æš©ã®ä»äžãå¶éããå¿ èŠããããŸãã
ã·ã¹ãã ã®å¥ã®åé¡ã®ããéšåã¯ãXenMotionã¢ãŒãã®ãµãŒããŒéã®ä»®æ³ãã·ã³ã®è»¢éã§ãã ãã¬ãŒã³ããã¹ãã¢ãŒãã§ã·ã¹ãã ã®80çªç®ã®ããŒããä»ããŠçºçããŸãã ãããã£ãŠãæ»æè ã¯ãã®å Žã§ããŒã¿ãååããããšãã§ããŸãã ãã®åé¡ã«å¯Ÿããå¯äžã®è§£æ±ºçããããŸã-IPã¬ãã«ã®æå·åããŒã«ã®äœ¿çšã§ãã ããããããã¯ããŒã¿ã転éãããšãã®å¯äžã®åé¡ã§ã¯ãããŸãã-iSCSIãµãŒãã¹ã¯ããã©ã«ãã§ã¯ãªã¢ããã¹ãã§è³æ Œæ å ±ãéä¿¡ããŸãã ãã®åé¡ã¯ãCHAPãã¢ã¯ãã£ãã«ããããšã§è§£æ±ºããŸãã
Citrix XenServerã¯
ã·ã¹ãã ã¯RHELã®åå«ã§ãããããyumã¢ãã€ã³ãšãšãã«RPMããã±ãŒãžç®¡çã·ã¹ãã ãç¶æ¿ããŸããã æåã¯ã·ã¹ãã ã§ãäºçŽ°ãªãyum updateããè©ŠããŠããã·ã¹ãã ã®æŽæ°ã¯åä¿¡ãããŸããã
ãç®±ããåºããŠããã«ãã·ã¹ãã ã®äžè¬çãªèšå®ãããpam_unix.soã¢ãžã¥ãŒã«ã®èšå®ã«éèŠãªãšã©ãŒãããããšã«æ³šæããããšæããŸãã å ·äœçã«ã¯ã/ etc / shadowã®ãã¹ã¯ãŒãä¿åã¢ãŒããæå¹ã«ãªã£ãŠããŸããã
ãããã£ãŠã/ etc / passwdãã¡ã€ã«ã«å¯Ÿããæšæºã®ã¢ã¯ã»ã¹èš±å¯ãäžããããŠããå Žåãã·ã¹ãã ãã¹ã¯ãŒãããã·ã¥ãžã®æœåšçãªã¢ã¯ã»ã¹ããããŸãã ããã¯ãNFSãªããžããªã䜿çšããã·ã¹ãã ã®éåæ§ã«ãé©çšãããŸãã Citrix XenServer管çã¬ã€ãã§ã¯ãNFSãµãŒããŒã§no_root_squashãªãã·ã§ã³ãèšå®ããããšããå§ãããŸãã ãã®ãããªãœãªã¥ãŒã·ã§ã³ã¯ãã€ããŒãã€ã¶ãŒã®æšæºã§ãããiptablesãªã©ã䜿çšããŠãå€éšã¹ãã¬ãŒãžããå¯èœãªéããã®ãããªã¹ãã¬ãŒãžãåé¢ããå¿ èŠããããŸãã ãŸãããã¡ããããã¡ã€ã«äœæã¢ãŒãã調æŽããã«ãŒããŠãŒã¶ãŒãç¹æ®ãªã·ã¹ãã ãŠãŒã¶ãŒã«åãããã³ã°ããå¿ èŠããããŸãã
ãããã£ãŠãå šäœçãªçµæãèŠçŽãããšãåææ§æã®Citrix Free XenServer補åã«ã¯ãããã€ãã®æ·±å»ãªãèšèšãã»ãã¥ãªãã£åé¡ãååšããå¯èœæ§ããããŸãã ãããã®å€ãã¯RHELãã¡ããªãŒã«å ±éã®åé¡ã§ããããã®ä»ã¯ãã®ã·ã¹ãã ã«åºæã®ãã®ã§ãã ãã¡ãããCitrixã®èŠ³ç¹ããèŠããšããããã¯åé¡ã§ã¯ãªãããã€ããŒãã€ã¶ãŒã®ã¢ãŒããã¯ãã£æ©èœã§ãã ã»ãã¥ãªãã£åé¡ãšãã®OSãä¿è·ããããã®äžè¬çãªæ¹æ³è«ã«ã€ããŠã¯ããPositive TechnologiesïŒCitrix XenServerã»ãã¥ãªãã£ã¬ã€ããã§èª¬æãããŸããããã¯è¿ãå°æ¥ã«ãªãŒãã³ããŒã¿ãã¹ããè¡ââãããŸãã