ããŒã1ïŒã·ã¹ãã ã®æºå
ããŒã2ïŒOTRSã®ã€ã³ã¹ããŒã«ãšèšå®
ããŒã3ïŒãã³ãåºå®ãããžã£ã ãä¿®æ£ãã
å°å ¥ãã代ããã«
é ããæ©ããååã«å€§ããªçµç¹ã¯ããã±ããã·ã¹ãã ãŸãã¯ãã«ããã¹ã¯ãå®è£ ããå¿ èŠã«çŽé¢ããŸãã ãããŠãç§ãã¡ã®çµç¹ãäŸå€ã§ã¯ãããŸãããããã«é¢é£ããŠã管çè ã¯ã·ã¹ãã ã®éžæãšå®è£ ãä»»ãããŸããã
ççŽã«èšã£ãŠãéžæã«ã€ããŠç¹ã«çãã¯ãããŸããã§ãã;å人çãªçç±ã§ãéžæã¯OTRSã«èœã¡ãŸããã çµå¶é£ãéåžžã«æããŠããèšå€§ãªæ°ã®ã¬ããŒããåãã匷åã§æè»ãªæ©èœã ããããå€æããããã«ããããå°å ¥ããããšã¯å®å šã«éèŠãªäœæ¥ã§ãã èŠçã¯2é±éç¶ãã倧éã®æ å ±ãã·ã£ãã«ã«ãããããããŸããŸãªããã¥ã¢ã«ãè©ŠãããŸããããç§ã¯å®å šãªãªã¿ã¯ã2人ã®ã©ã¡ããã§ããããã«èŠããŸããããã¹ãŠã®ããã¥ã¢ã«ãšã¬ãã¥ãŒã®å±±ã§ããã¹ãŠãå®å šã«æ©èœããå®å šã«æ©èœããŠãããšäž»åŒµããããããã¯èšå®å¯èœã§ãããç§ãšã¯ç°ãªããŸãã
å®éãããããã¹ãŠã®ããã¥ã¢ã«ã®åé¡ã¯ããã¹ãŠãããªãã®ãã®ãšåãããã«èŠããããšã§ãããã©ããã§ããã±ãŒãžã®ããŒãžã§ã³ãå°ãç°ãªã£ãŠããããADã®æ§é ãã»ãšãã©åãã§ãããªã©ã§ããç³ã®è±ã¯ã»ãšãã©å ç®ãããŸããã äžèšã§èšãã°ãè©Šè¡é¯èª€ã«ãã£ãŠãããã¥ã¡ã³ãã®èªã¿æ¹ãšããã¥ã¢ã«ã®åæãç§èªèº«ã®éåžžã«å¹æçãªæ¹æ³ãéçºãããŸããã
ããŒã¹ã©ã€ã³ãšèŠä»¶
- çµç¹ã¯2ã€ã®Win2008r2ã³ã³ãããŒã©ãŒã§ADã調éããŸããããããããªããADãšã®çµ±åãå¿ èŠã§ãã
- å€ãã®ãµãŒãã¹ïŒã¡ãŒã«ãJabberãªã©ïŒãLinuxã«ã¢ããããŒããããŠãããOSãšããŠUbuntu Server 14.04ãéžæãããŠããŸã.OTRSã¯OpenSourceã§ããããããããã©ã€ãšã¿ãªOSã«çœ®ãããšã¯ç§ã®èãã§ã¯æªãèããªã®ã§ãUbuntuã«ã€ã³ã¹ããŒã«ããŸãã ã¡ãªã¿ã«ã次ã®èšäºã§èå³æ·±ããšæãããå Žåã¯ããããã®ãµãŒãã¹ãé«ããADããã³OTRSãšçµ±åããç§ã®çµéšã«ã€ããŠã話ããŸãã ïŒOTRSãšJabberã®çµ±åã¯äžè¬çã«éåžžã«ã¯ãŒã«ã§äŸ¿å©ãªãã®ã§ãïŒ
- ã¹ãã£ã³ãŠãŒãã£ãªãã£ãªã©ã®ããã«ãã·ã³äžã§ãã¡ã€ã«ãè¿ éã«äžããæ©èœã
- ãããŠæåŸã«ãADããããã³ã³ãã¥ãŒã¿ãŒã®é»æºãå ¥ãããšãããŠãŒã¶ãŒã¯ãŸã ãã¹ã¯ãŒããå ¥åããŠãããã·ã¹ãã ã¯ãã®æç¹ã§ã·ã¹ãã ã§äœæ¥ããŠãããŠãŒã¶ãŒãæ¢ã«ç¥ã£ãŠããã®ã§ããã¹ã¯ãŒããšãã°ã€ã³ã®äœåãªãšã³ããªãŒã圌ã«äžãããã¹ã¹ã«ãŒèªèšŒãå®è£ ããå¿ èŠããããŸãã
æ¢ã«è¿°ã¹ãããã«ãäŒæ¥ã¡ãŒã«ãšJabberã¯ãããã¯ãŒã¯äžã§æ©èœããæšæºçãªèŠä»¶ã®ã»ããã§ãããè¿œå ã®èŠä»¶ã¯OTRSãããããšçµ±åããããšã§ããã ãããããã®èšäºã¯å·šå€§ã§ããããšãå€æãããããOTRSãšãããã®çµ±åã«ã€ããŠèª¬æãããšãã«ãOTRSãšãããã®çµ±åã«ã€ããŠèª¬æããŸãã
å®éãOTRSãé 眮ããããšã¯é£ãããªããäžåºŠã«ADãšçµ±åããããšãã§ããŸããã¹ããã°å šäœã¯æ£ç¢ºã«ãšã³ãããŒãšã³ãèªèšŒïŒSSOïŒã§ããã ãã®ããŒãã«é¢ããäžé£ã®ããã¥ã¢ã«ããããã¯ãŒã¯äžã§èŠã€ãããŸããããããŸããŸãªçç±ã§ç§ã«ãµãããããã®ã¯ãããŸããã§ãã.1ã€ã®OTRSãWindowsã«ã€ã³ã¹ããŒã«ããããã1ã€ã®OTRSã®å€ãããŒãžã§ã³ã§ã¯ã3çªç®ã§ã¯æªç¥ã®äººãšãã€ã«ãã£ãŠæžãããã¢ããã¿ã¢ãžã¥ãŒã«ã䜿çšãããŸãã
äžè¬ã«ããšã³ãããŒãšã³ãèªèšŒãå®è£ ããã«ã¯4ã€ã®æ¹æ³ããããŸãã
- 1ã€ç®ã¯SSPIã§ãããWindowsã§ã®OTRSçšã®ã¢ãžã¥ãŒã«ã§ããããé©åããŸãã
- 2ã€ç®ã¯ãèªå·±èšè¿°åã®ADSSOã¢ãžã¥ãŒã«ã§ãããåºæ¬çã«ã¯ããŒããããLDAPèªèšŒã¢ãžã¥ãŒã«ã§ãããç§ã®æèŠã§ã¯æŸèæã§ãã
- 3ã€ç®ã¯ãOTRSçšã®èªå·±èšè¿°NTLMèªèšŒã¢ãžã¥ãŒã«ã§ããããæŸèæã§ãã
- æåŸã®1ã€ã¯ãKerberosèªèšŒã䜿çšããäŒæ¥ã®æšæºOTRS HTTPBasicAuthã¢ãžã¥ãŒã«ã§ãã
ãããç§ã®æèŠã®æåŸã®ïŒãããŠå€ãã®äººãç§ã«åæããã ãããšæãïŒæãæ£ç¢ºã§å®å šãªãã®ã§ãã ãããã£ãŠããœãŒã¹ããŒã¿ïŒ
- ãããã¯ãŒã¯192.168.0.0/16
- ãã¡ã€ã³DOMAIN.RU
- ãããã®ãã¡ã€ã³ã³ã³ãããŒã©ãšDNSããã³NTP
- PDC-ad1.domain.ruïŒ192.168.10.1ïŒ
- SDC-ad2.domain.ruïŒ192.168.10.2ïŒ
- GATE 192.168.10.10
- ãã¹ãŠã®ãã¡ã€ã³ãŠãŒã¶ãŒã¯ãçµç¹ãŠãããORGANIZATIONå ã«ãããã°ã«ãŒãå ã«åæ£ããŠããŸãã
- OTRSagentsã°ã«ãŒããäœæãããŸãããããã«ã¯ããµãŒãã¹ãããã€ããŒãã€ãŸãã¢ããªã±ãŒã·ã§ã³ãåãå ¥ãã人ïŒOTRSçšèªã§ã¯ããšãŒãžã§ã³ããïŒãå«ãŸããŸãã
- ã¯ã©ã€ã¢ã³ããã€ãŸãã¢ããªã±ãŒã·ã§ã³ãéä¿¡ãã人ïŒOTRSçšèªã§ã¯ã顧客ãïŒã¯ãäŸå€ãªããã¡ã€ã³ã®ãã¹ãŠã®ãŠãŒã¶ãŒã«ãªããŸãã
OTRSæ§æãšã¯ç°ãªãæ§æãå¯èœã§ãããŠãŒã¶ãŒãšãšãŒãžã§ã³ãã®ä»ã®å Žæçšã«æ§æããæ¹æ³ã¯ãèªèº«ã§ç解ã§ããŸãã
OTRSãµãŒããŒã¯ããŠãŒã¶ãŒotrs.adminã«ä»£ãã£ãŠLDAPããæ å ±ãèªã¿åããŸããã»ããã¢ããæéäžããã¡ã€ã³ç®¡çè ã®æš©å©ãäžããŸããæ§æåŸãããããéžæãããã·ã³ã«ãã°ã€ã³ããæš©å©ããããLDAPããæ å ±ãèªã¿åãããšãã§ããå¿ èŠããããŸãã
1.ã·ã¹ãã ã®æºå
1.1ãã®ãããªèšå®ã§Ubuntu Serverãé 眮ããŸãïŒãããã¯ç§ã®èšå®ã§ããä»ã«ãèšå®ããããŸãïŒ
- IPïŒ192.168.10.14
- ãã¹ã¯ïŒ255.255.0.0
- ã²ãŒãïŒ192.168.10.10
- DNSïŒ192.168.10.1 192.168.10.2 8.8.8.8
- ååïŒãã«ããã¹ã¯
- ãŠãŒã¶ãŒïŒãã«ããã¹ã¯
- ãã¹ïŒã¹ããã³ã°ãã¹
æåŸã®æ®µéã§ãã€ã³ã¹ããŒã«ã¯ããã€ãã®ãœãããŠã§ã¢ããã¬ã€ã³ã¹ããŒã«ãããã©ãããå°ããŸããOpenSSHãµãŒããŒã®ã€ã³ã¹ããŒã«ãéžæããŸãã
1.2ã SSHãä»ããŠæ°ãããµãŒããŒã«åºå·ãã
ssh 192.168.10.14 -l helpdesk
ããŒãåãå ¥ãããã«ããã¹ã¯ã䜿çšããŠãã¹ã¯ãŒããå ¥åããããšã«åæããŸã
ã«ãŒããžã®æš©å©ãäžãã
sudo su
ïŒ æ³šæïŒ suããããã«ãã¹ãŠã®ã¢ã¯ã·ã§ã³ãå®è¡ããã·ã¹ãã ãåèµ·åããåŸãrootæš©éãå床äžããããšãå¿ããªãã§ãã ããã
/ etc / hostnameããã³/ etc / hostsãã¡ã€ã«å ã®æ å ±ã®é¢é£æ§ã確èªããŸããæåã®æåã¯å€§æåã®ãã·ã³åã§ã2çªç®ã®æåã¯127.0.0.1 helpdesk.domain.ru helpdeskã®ãããªãšã³ããªãæã€å¿ èŠããããŸã
äœããééã£ãŠããå Žå-æ£ããã ããã§ããã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã«å¯ŸããŠãIPïŒå®å šåããã³çç¥åïŒã§pingãè©Šè¡ããŸãã å šå¡ã«pingãå®è¡ããå¿ èŠããããŸãã ããã§ãªãå Žåã¯ããããã¯ãŒã¯èšå®ãåŠçããŸãã
1.3ã æŽæ°ããŠmcã眮ã
apt-get update && apt-get -y upgrade && apt-get install -y mc
çµéšã®ãªã人ã¯ãã³ãã³ããé çªã«å®è¡ã§ããŸã
apt-get update apt-get -y upgrade apt-get install -y mc
2.ãã·ã³ããã¡ã€ã³ã«å ¥åãããã¡ã€ã³èªèšŒãæ§æããŸãã SambaãKerberosãããã³Winbindãæ§æããŸãã
ãã®ããŒãã«é¢ããåªããèšäºã¯ãUbuntuãã¯ãã«ã«ãµããŒããµã€ãã«ãããŸãïŒ help.ubuntu.ru/wiki/%D0%B2%D0%B2%D0%BE%D0%B4_%D0%B2_%D0%B4%D0%BE%D0% BCïŒ D0ïŒ B5ïŒ D0ïŒ BD_windows
2.1ã Kerberosãã€ã³ã¹ããŒã«ããã³æ§æããŸã
å¿ èŠãªããã±ãŒãžãé 眮ããŸãã
apt-get install krb5-user samba winbind libpam-krb5 libpam-winbind libnss-winbind ntp smbclient rlwrap
Kerberosãæ©èœããããã«ã¯ãã³ã³ãã¥ãŒã¿ãŒã®ã¯ããã¯ãåæããŠå®è¡ãããæå·®ã5åãè¶ ããªãããšãéåžžã«éèŠã§ãã /etc/ntp.confãã¡ã€ã«ã§ãã¡ã€ã³ã³ã³ãããŒã©ãŒãšã®æéåæãæ§æããŸã
ååã瀺ãããã«ããã¡ã€ã«ã¯ã·ã¹ãã ã¯ããã¯ãå®æçã«èª¿æŽããntpããŒã¢ã³ã®èšå®ãæ åœããŸãã æ£ç¢ºãªã¿ã€ã ãµãŒããŒã¯serverãã£ã¬ã¯ãã£ãã«ãã£ãŠèšå®ããããããããã«ããæ£ç¢ºãªã¿ã€ã ãµãŒããŒã瀺ããã¹ãŠã®è¡ãã³ã¡ã³ãåããŠãç¬èªã®ãã®ãå ¥åããå¿ èŠããããŸãã
mcedit /etc/ntp.conf
ãµãŒããŒã§å§ãŸããã¹ãŠã®çšèªã«ã€ããŠã³ã¡ã³ãããŸãã
#server 0.ubuntu.pool.ntp.org #server 1.ubuntu.pool.ntp.org #server 2.ubuntu.pool.ntp.org #server 3.ubuntu.pool.ntp.org # Use Ubuntu's ntp server as a fallback. #server ntp.ubuntu.com
ãããŠããªãã®ãã®ãå ¥åããŠãã ããïŒ
server 192.168.10.1 server 192.168.10.2
2ã€ã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒããããããããã§æ£ç¢ºãªã¿ã€ã ãµãŒãã¹ãçºçããŸãã ãã®åŸããã¡ã€ã«ãä¿åããæ°ããèšå®ã§ããŒã¢ã³ãåèµ·åããŸãã
service ntp restart
åºåã¯æ¬¡ã®ããã«ãªããŸãã
root@HELPDESK:/home/helpdesk# service ntp restart * Stopping NTP server ntpd [ OK ] * Starting NTP server ntpd [ OK ]
ããŒã¢ã³ã¯æ°ããèšå®ã§èµ·åããã¯ããã¯ãåæããŸãã Kerberosã¯ã krb5.confãã¡ã€ã«ãç·šéããŠæ§æããŸãã
mcedit /etc/krb5.conf
ãŸãããã°ãæå¹ã«ããŸããããã®ããã«ããã¡ã€ã«ã®æåã«ã»ã¯ã·ã§ã³ãè¿œå ããŸãã
[logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log
ãããŠãKerberosãã©ã®ãã¡ã€ã³ïŒKerberosã®çšèªã§-ã©ã®é åïŒã§åäœãã誰ããã®é åãé§åãããã説æããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãã»ã¯ã·ã§ã³ãç·šéããŸãã
[libdefaults] default_realm = DOMAIN.RU #( ) [realms] # DOMAIN.RU = { #. . kdc = ad1.domain.ru # kdc = ad2.domain.ru #. , admin_server = ad1.domain.ru admin_server = ad2.domain.ru default_domain = domain.ru } [domain_realm] # .domain.ru = DOMAIN.RU # () domain.ru = DOMAIN.RU
ããã§ãèšå®ã®æ©èœã確èªããå¿ èŠããããŸãããã®ããã«ãäžéšã®ãŠãŒã¶ãŒã®ãã¡ã€ã³ã§kerberosãã±ãããååŸããããšããŸãã
kinit username@DOMAIN.COM # username â , ! !
ãã®åŸã圌女ã¯ãã¹ã¯ãŒããèŠæ±ãããã±ãããååŸããããšããŸãã ãã¹ãŠãããŸããã£ãå ŽåãããŒã ã¯æ²é»ãããŸãŸã«ãªããŸããã€ãŸããåºåã¯ç©ºã«ãªããŸãã ãã®ãããªãã®ïŒ
root@HELPDESK:/home/helpdesk# kinit otrs.admin@DOMAIN.RU Password for otrs.admin@DOMAIN.RU: root@HELPDESK:/home/helpdesk#
ãã±ãããåãåã£ããã©ããã確èªãã次ãå ¥åããŸãã
klist
ãããŠã次ã®ãããªãã®ã衚瀺ãããŸãã
root@HELPDESK:/home/helpdesk# klist Ticket cache: FILE:/tmp/krb5cc_0 Default principal: test@DOMAIN.RU Valid starting Expires Service principal 10.08.2015 15:46:01 11.08.2015 01:46:01 krbtgt/DOMAIN.RU@DOMAIN.RU renew until 11.08.2015 15:45:57
ã芧ã®ãšããããã±ããã¯æ£åžžã«åä¿¡ããããã¹ãŠåé¡ãããŸããã ãããã£ãŠãæ§æã¯æ©èœããŠããŸãã ãã±ãããã¯ã©ãã·ã¥ãããŸããä»ã®ãšããå¿ èŠãããŸããã
Kdestroy
åºåã空ã§ããããã±ãããç Žæ£ãããããšãæå³ããŸãïŒã³ãã³ãã¯ãã£ãã·ã¥å ã®ãã¹ãŠã®ãã±ãããç Žæ£ããããšã«æ³šæããŠãã ããïŒã
2.2ããã§ã¯ãSAMBAãæ§æããŠãã¡ã€ã³ã«æ¥ç¶ããŸãã
ãããè¡ãã«ã¯ã/ etc / samba / smb.confãã¡ã€ã«ãç·šéããŸãã
mcedit /etc/samba/smb.conf
ããã§ã[global]ã»ã¯ã·ã§ã³ãç·šéããŸãã
[global] # , workgroup # , realm - workgroup = RUS realm = DOMAIN.RU # AD security = ADS encrypt passwords = true # dns proxy = no socket options = TCP_NODELAY # , , # , domain master = no local master = no preferred master = no os level = 0 domain logons = no # load printers = no show add printer wizard = no printcap name = /dev/null disable spoolss = yes
次ã®ã³ãã³ãã§æ£ããæ§æã確èªããŸãã
testparm
åºåã¯æ¬¡ã®ããã«ãªããŸãã
Load smb config files from /etc/samba/smb.conf rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384) Processing section "[printers]" Processing section "[print$]" Loaded services file OK. Server role: ROLE_DOMAIN_MEMBER Press enter to see a dump of your service definitions
EnterãæŒããšãã³ã³ãã€ã«ãããsmb.confã衚瀺ãããŸã ïŒã€ãŸããã³ã¡ã³ãã¯ãããŸããïŒã
ãrlimit_maxïŒrlimit_maxïŒ1024ïŒãWindowsã®æå°å¶éïŒ16384ïŒã«å¢ãããŸãããšããã¡ãã»ãŒãžã¯ãWindowsãšUbuntuã®å¶éããŒã«ã®éããåå ã§çºçããŸããå¶éãä¿®æ£ãããšãã«ãå°ãåŸã§åé€ããŸãã
ãã¡ã€ã³ãçŽæ¥å ¥åããŠã¿ãŠãã ããã ãããè¡ãã«ã¯ã次ã®ã³ãã³ããå®è¡ããŸãã
net ads join -U username -D DOMAIN #username -
圌女ã¯æåã«ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããèŠæ±ãããã¹ãŠãæ£åžžã§ããã°ãåºåã¯æ¬¡ã®ããã«ãªããŸãã
Using short domain name -- RUS Joined 'HELPDESK' to dns domain 'domain.ru'
次ã®ã³ãã³ãã䜿çšããŠããã¡ã€ã³ãžã®æ£ããæ¥ç¶ã確èªã§ããŸãã
net ads testjoin
圌女ã®çµè«ã¯æ¬¡ã®ããã«ãªããŸãã
Join is OK
ãã¡ã€ã³å ã®ä»»æã®ãã·ã³ã®å ±æãªãœãŒã¹ã®ã€ã³ããã¯ã¹ãäœæããããšã«ããããã®æ®µéã§èšå®ãæ£ããããšã確èªã§ããŸãã ãã±ãããååŸããŸãïŒ
kinit username@DOMAIN.COM
ãããŠããã¡ã€ã«ãµãŒããŒãªã©ã®ãã·ã³ã®ãªãœãŒã¹ã調ã¹ãŠã¿ãŠãã ããã
smbclient -k -L //File-server
-kã¹ã€ããã¯ãkerberosã䜿çšããå¿ èŠãããããšã瀺ããŸããFile-serverã¯ãå ±æãªãœãŒã¹ãæã€ãã¡ã€ã³å ã®ãã·ã³ã®ååã§ãã ã³ãã³ãã®åºåã«ã¯ãæå®ããããã·ã³ã®å ±æãªãœãŒã¹ã®ãªã¹ãã衚瀺ãããã¯ãã§ããã¯ãã®å Žåããã¹ãŠã¯åé¡ãããŸããããããŸã§ã®ãšããããã¹ãŠãæ£ããå®è¡ãããŠããŸãã 次ã«ã次ã®ã³ãã³ãã§ãã±ãããç Žæ£ããŸãã
kdestroy
2.3 Winbindã®æ§æ
ãããè¡ãã«ã¯ãåã/etc/samba/smb.confãç·šéãã次ã®è¡ã[global]ã»ã¯ã·ã§ã³ã«è¿œå ããŸãã
# Winbind. # . idmap config * : range = 10000-20000 idmap config * : backend = tdb # . winbind enum groups = yes winbind enum users = yes # . # , .. username - DOMAIN\username. # , . winbind use default domain = yes # #, , shell' #/bin/false template shell = /bin/bash # Kerberos pam_winbind.so winbind refresh tickets = yes # kerberos # ( # ), «passdb backend = tdbsam» : kerberos method = system keytab dedicated keytab file = /etc/krb5.keytab
èšå®ãæ£ããããšã確èªããŸãã
testparm
ãããŠããã¹ãŠãåé¡ãªããã°ãããŒã¢ã³ãïŒãã®é åºã§ïŒåèµ·åããŸãã
service winbind stop service smbd restart service winbind start
ãµãŒãã¹ãæ£åžžã«åèµ·åããå Žåãåºåã¯æ¬¡ã®ããã«ãªããŸãã
root@HELPDESK:/home/helpdesk# service winbind stop winbind stop/waiting root@HELPDESK:/home/helpdesk# service smbd restart smbd stop/waiting smbd start/running, process 4859 root@HELPDESK:/home/helpdesk# service winbind start winbind start/running, process 4871
ããªãã¯åãã§ããïŒ æ¬¡ã«é²ã¿ãŸãã ããã§ã¯ãSambaãèªãå¶éãä¿®æ£ããŸãã ãããã¯/etc/security/limits.confãã¡ã€ã«ã§ä¿®æ£ãããŠããŸãã ãã¡ã€ã«ã®æåŸã«2è¡è¿œå ããå¿ èŠããããŸãã
* - nofile 16384 root - nofile 16384
ãã®æäœã®åŸããã·ã³ãåèµ·åããå¿ èŠããããŸãã
shutdown -r now
ãŸãã¯
reboot
誰ã奜ãã§ããã
åèµ·ååŸããã·ã³ããã¡ã€ã³ãšã®ä¿¡é Œã確ç«ããŠãããã©ããã確èªããŸãã
wbinfo -t
åºåã¯æ¬¡ã®ããã«ãªããŸãã
checking the trust secret for domain DCN via RPC calls succeeded
ãã¹ãŠã®ã³ãã³ããã«ãŒããšããŠå®è¡ãããããšãæãåºãããŠãã ããã ãªããŒãåŸã«suã«ã¢ããã°ã¬ãŒãããã®ãå¿ãããããæåã¯ãã®æ®µéã§ã®ã£ã°ããããŸããã ãã¹ãŠã®ã·ãŒã¯ã¬ããïŒãã±ãããªã©ïŒã¯ãrootã®ã¿ãã¢ã¯ã»ã¹ã§ããsambaããŒã¹/var/lib/samba/private/*.tdbã¢ã¯ã»ã¹ã«ä¿åãããŸãã ãããã£ãŠããªããŒãåŸã«æš©éãå¢ããããšãå¿ããªãã§ãã ãããã¹ãŒããŒãŠãŒã¶ãŒãããã¹ãŠã®ã³ãã³ããå®è¡ããŸãã ãŸããwinbindããã¡ã€ã³å ã®ãŠãŒã¶ãŒãšã°ã«ãŒããèªèããŠããããšã確èªããŸãã
wbinfo -u
ãããŠ
wbinfo -g
2.4ã ãŸããå¥ã®ããŒãã¹
ãã·ã³ããã¡ã€ã³ã«å ¥åããŠããããããã¡ã€ã³ã¢ã«ãŠã³ãã§ãã·ã³ã«ãã°ã€ã³ããæ©èœãè¿œå ããŸãã ãããè¡ãã«ã¯ã / etc / nsswitch.confãã¡ã€ã«ã«winbindããŒã¿ãœãŒã¹ãè¿œå ããŸãã ãŸããããŒã«ã«ãŠãŒã¶ãŒãšããŠãã¡ã€ã³ãŠãŒã¶ãŒãæäœããæ©äŒãæäŸããŸããããã¯ããã¡ã€ã³ãŠãŒã¶ãŒããªããžã§ã¯ãã®ææè ãšããŠä»»åœããã¢ã¯ã»ã¹æš©ãäžããããšãæå³ããŸãã ããã«ãããLinuxãã·ã³ã§ããŒã«ãäžããããšãå¯èœã«ãªããŸãã 次ã®è¡ãæå®ããŸãã
passwd: compat group: compat
æ°ã«ãã
passwd: compat winbind group: compat winbind
ãŸãããã¡ã€ã«ã®æåŸã«è¡ãè¿œå ããããšããå§ãããŸãã
files: dns mdns4_minimal[NotFound=return] mdns4
ãã®ã¹ããŒãžã¯ã次ã®ã³ãã³ãã§ãŠãŒã¶ãŒãšã°ã«ãŒãã®ãªã¹ããèŠæ±ããããšã§ç¢ºèªãããŸãã
getent passwd
ãããŠ
getent group
åºåã§ã¯ããã¡ã€ã³ãŠãŒã¶ãŒãšã°ã«ãŒããæ¢ããŠãããèŠã€ãã£ãå Žåã¯ãã¹ãŠåé¡ãããŸããã ãããŠæåŸïŒãã¡ã€ã³ãŠãŒã¶ãŒã«ã»ãã·ã§ã³ãéãæ©äŒãäžããŸãã以åã®ããŒãžã§ã³ã§ã¯ãubuntuã¯ããŒã«ãã·ã§ã³æ¥œåšã䜿ã£ãéèªæãªãã³ã¹ãå¿ èŠã§ããããPAM.Dã¯/etc/pam.d/common-sessionãã¡ã€ã«ã«æ¬¡ã®è¡ãè¿œå ã§ããŸã ã
session optional pam_mkhomedir.so skel=/etc/skel/ umask=0077
ããã§åèµ·åãããã¡ã€ã³ã¢ã«ãŠã³ãã§ãã°ã€ã³ããŠã¿ãŠãã ãããå€æããå Žåã¯ãåã®æé ã¯ãã¹ãŠæ£ããå®äºããŠããŸãã
3. KerberosããŒãäœæããHTTPããªã³ã·ãã«ããã¡ã€ã³ã«è¿œå ããŸãã
次ã®3ã€ã®ã¹ããŒãžã§ã¯ãäœãèµ·ããŠããã®ããããããŸã§2é±éãè²»ãããŸããã ããããããšã§ããããã¹ãŠãéåžžã«ã·ã³ãã«ã§æåã«èµ·åããããšãå€æããããã倧éã®æ å ±ãåæãããããåäžã®ã¢ã¯ã·ã§ã³ã·ãŒã±ã³ã¹ã«åæžããå¿ èŠããããŸããã
ãã®3ã€ã®æ®µéã§ã ãã®èšäºã¯éåžžã«åœ¹ç«ã¡ãŸããã
ãããã£ãŠãKerberosãããã³ã«ãããã¯ããã£ã¬ã¯ããªãç§ãã¡ã«èšãããã«ã第äžè ã«å¯Ÿããä¿¡é Œã®ååã«åºã¥ãããããã¯ãŒã¯èªèšŒãããã³ã«ã§ãã ããã¯ã©ãããæå³ã§ããïŒ ã€ãŸããèªèšŒããã»ã¹ã§ã¯ãããã©ã«ãã§çžäºäœçšåå è ãä¿¡é ŒãããµãŒãããŒãã£ã衚瀺ãããŸãããµãŒããŒåŽã«ã¢ã¯ã»ã¹ããåã«ãã¯ã©ã€ã¢ã³ããKDCã¡ãã»ãŒãžãéä¿¡ããã»ãã·ã§ã³ã®ååå è ã«ã»ãã·ã§ã³ã®ã³ããŒãéä¿¡ããæ¹ãç°¡åãªå Žåããã¡ãåŽã¯ããŒé åžã»ã³ã¿ãŒãšåŒã°ããŸãããŒã¯çæéæå¹ã§ãã ãããã®ããŒã®ç®çã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒãèªèšŒããããšã§ãã
æå·åã«ç²ŸéããŠãã人ã«ãšã£ãŠã¯ãKerberosãšã³ãžã³å šäœã¯PKIãšã³ãžã³ã®å®å šãªã³ããŒãããå°ã倧ãããšèšããŸãã å®éãä»ã®ä»äºã®ããã ãã«æçãããã®ã¯åœŒã§ãã ãã®å ŽåãèªèšŒå±ã®ä»£ããã«ã®ã¿ããŒé åžã»ã³ã¿ãŒïŒKDCïŒããããŸãã éåžžããã¡ã€ã³ã³ã³ãããŒã©ãŒäžã«ãããŸãã
æ°ããçšèªãããªã³ã·ãã«ãã¯ãKerberosã®çšèªã§ããããããããã¯ãŒã¯ã€ã³ã¿ã©ã¯ã·ã§ã³ã®åå è ãã€ãŸãããŒãKDCã«é Œã人ãã¡ã§ãã
ãã®ã¹ãããã¯ã2ã€ã®è€éã§ç°¡åãªæ¹æ³ã§å®äºã§ããŸãã äœããã®çç±ã§ããããã¯ãŒã¯äžã®ãã¹ãŠã®ããã¥ã¢ã«ã«ã¯ãããè€éãªæ¹æ³ãã€ãŸãktpassãŠãŒãã£ãªãã£ïŒä¿¡ããããªãã»ã©ã®æ°ã®ããŒãæã€æãããç£ïŒã䜿çšããŠãã¡ã€ã³ã³ã³ãããŒã©ãŒã«KerberosããŒãäœæãããããLinuxãã·ã³ã«ã³ããŒããæ¹æ³ãèšèŒãããŠããŸãã ãã®ãã¹ã®æšæºçãªæ£ç¢ºãã¯åŠå®ããŸãããããããããã°ãã³ãã³ãã¯æ°è¡ã§ååŸãããŸãããããã䜿çšãããšãã«Zenãç解ã§ããŸããã§ããã
å€æããããã«ããã£ãšç°¡åãªæ¹æ³ããããŸã-Linuxãã·ã³ã§çŽæ¥ããŒãäœæããŸãã ãããã¯ãŒã¯ã§åœŒã«ã€ããŠèšåããã®ã¯1ã€ã ãã§ããã¶ãèŠãç®ãæªãã®ã§ãããããŸããããŸããã
ãŸãããã®æ®µéã§æ£ç¢ºæ§ãå¶åŸ¡ããã«ã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒã§äœããããå¿ èŠããããŸãã
ãŸããã³ã³ãããŒã©ãŒã«ã¢ã¯ã»ã¹ããŠããADãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãŒãã¹ãããã€ã³ãéããã³ã³ãããŒãã³ã³ãã¥ãŒã¿ãŒã§éããLinuxãã·ã³ãæ¢ããŸãããã¡ã€ã³ã«å«ããåŸãããã«è¡šç€ºãããã¯ãã§ãã çºèŠ-çŽ ç¶ããŸãããã
次ã«ãADSIãšãã£ã¿ãŒãå¿ èŠã§ããã³ãã³ãã©ã€ã³ãéãã次ã®ããã«å ¥åããŸãã
adsiedit.msc
ãããŠãã€ã³ã¿ãŒãæŒããŸãã ã³ã³ãœãŒã«ããªãŒããã®æ§é ã«ADã³ã³ãœãŒã«ãã³ããŒããŠããã®ãããããŸãã ããã§ãã·ã³ãèŠã€ãããã®ããããã£ãéãããªã¹ãã§servicePrincipalNameå±æ§ãæ¢ããŸãã ããã§ã HOST / hepldesk.domain.ruãšHOST / helpdeskã®ãããª2ã€ã®ãšã³ããªãããã¯ãã§ãã
ã©ã¡ããHOSTã§ãã·ã³ã®ççž®åã§å§ãŸããå¥ã®ãã·ã³ã§å®å šã«ãªããŸããã€ãŸãããã·ã³ã¯HOSTãã€ãŸããã¡ã€ã³å ã®éåžžã®ãã·ã³ã«ãªããŸãã
次ã«ãLinuxãã·ã³ã«ç§»åããŠãã³ãã³ããå®è¡ããŸãã
net ads keytab create
ã³ãã³ãããã®åºåã¯ç©ºã§ãããå®è¡åŸã å°çšã®keytabãã¡ã€ã«ãã£ã¬ã¯ãã£ãã®smb.confãã¡ã€ã«ã§æå®ããå 容ã«å¿ããŠããã¡ã€ã«/etc/krb5.keytabãäœæããå¿ èŠããããŸãã ããããOTRSãããã¯Webã¢ããªã±ãŒã·ã§ã³ã§ãããLinuxãã·ã³ã¯httpãµãŒãã¹ãæäŸãããããå¥ã®HTTPååãè¿œå ããå¿ èŠããããŸãã ããã«èšã£ãŠãã£ãïŒ
net ads keytab add HTTP
ãã¡ã€ã³ã®ãã·ã³ã®ããããã£ã§ããªã³ã·ãã«ã®ãªã¹ããèŠããšãããã«ããã«2ã€è¿œå ãããŠããããšãããããŸã -ã HTTP / helpdesk.domain.ru ããšã HTTP / helpdesk ãïŒå°ããªãã¥ã¢ã³ã¹ïŒADSIãšãã£ã¿ãŒãŠã£ã³ããŠã®æ å ±ã¯èªåçã«æŽæ°ãããŸããããããã£ãŠããã·ã³ã®ããããã£ãéããF5ãæŒããŠå床éããŸãïŒã
ååãšããŠãããã¯ãã§ã«è¿œå ãæåããããšãæå³ããŸãã ãã ããkeytabã«ãããã®ãèŠãŠã¿ãŸãããã
klist -ek /etc/krb5.keytab # keytab Keytab name: FILE:/etc/krb5.keytab KVNO Principal ---- -------------------------------------------------------------------------- 2 host/helpdesk.domain.ru@DOMAIN.RU (DES cbc mode with CRC-32) 2 host/helpdesk.domain.ru@DOMAIN.RU (DES cbc mode with RSA-MD5) 2 host/helpdesk.domain.ru@DOMAIN.RU (ArcFour with HMAC/md5) 2 host/helpdesk@DOMAIN.RU (DES cbc mode with CRC-32) 2 host/helpdesk@DOMAIN.RU (DES cbc mode with RSA-MD5) 2 host/helpdesk@DOMAIN.RU (ArcFour with HMAC/md5) 2 HELPDESK$@DOMAIN.RU (DES cbc mode with CRC-32) 2 HELPDESK$@DOMAIN.RU (DES cbc mode with RSA-MD5) 2 HELPDESK$@DOMAIN.RU (ArcFour with HMAC/md5) 2 HTTP/helpdesk.domain.ru@DOMAIN.RU (DES cbc mode with CRC-32) 2 HTTP/helpdesk.domain.ru@DOMAIN.RU (DES cbc mode with RSA-MD5) 2 HTTP/helpdesk.domain.ru@DOMAIN.RU (ArcFour with HMAC/md5) 2 HTTP/helpdesk@DOMAIN.RU (DES cbc mode with CRC-32) 2 HTTP/helpdesk@DOMAIN.RU (DES cbc mode with RSA-MD5) 2 HTTP/helpdesk@DOMAIN.RU (ArcFour with HMAC/md5)
確ãã«ãæ°ãã確ç«ãããããªã³ã·ãã«ã®KDCããKerberosãã±ãããååŸã§ããŸãã
kvno HTTP/web.domain.ru@DOMAIN.RU HTTP/web@DOMAIN.RU HTTP/web.domain.ru@DOMAIN.RU: kvno = 2 HTTP/web@DOMAIN.RU: kvno = 2
ããŒã ã§ãã±ããã確èªããŸãã
klist -e
çµè«ã¯çŸåšå©çšå¯èœãªãã±ããã®å®å šãªãªã¹ãã«ãªããŸãããã®äžã«HTTPãã±ããããããŸããããããã°ããã¹ãŠã¯åé¡ãããŸãããå®ç§äž»çŸ©è ã§ãªããã°ã次ã®ã¹ãããã«é²ãããšãã§ããŸãã
æ®ãã®éšåã«ã€ããŠã¯ãç§ã¯å®ç§äž»çŸ©è ã§ããããã¹ãŠã®ããŒã1ã€ã®ãã¡ã€ã«ã«ä¿åããã®ã¯é©åã§ã¯ãªããšæããŸããHTTPã«é¢ãããã¹ãŠãå¥ã®ããŒãã¡ã€ã«ã«ãã€ã©ã€ãããŸããããããã¯ktutilã§å®è¡ã§ããŸãã é«åºŠãªç·šéæ©èœããµããŒãããŠããªãããã rlwrapã䜿çšããŠèµ·åã§ããŸãã
rlwrap ktutil
keytabãã¡ã€ã«ã®å 容ãããŠã³ããŒãããŸãã
ktutil: read_kt /etc/krb5.keytab
ç§ãã¡ãä»æã£ãŠãããã®ãèŠãŠã¿ãŸãããïŒ
ktutil: list
HTTPã§å§ãŸããã¹ãŠã«èå³ããããäžèŠãªãã®ã¯ãã¹ãŠåé€ããŸãã
ktutil: delent 1 # 1
次ã®ããã«ãªããŸãã
ktutil: list slot KVNO Principal ---- ---- --------------------------------------------------------------------- 1 2 HTTP/helpdesk.domain.ru@DOMAIN.RU 2 2 HTTP/helpdesk.domain.ru@DOMAIN.RU 3 2 HTTP/helpdesk.domain.ru@DOMAIN.RU 4 2 HTTP/helpdesk.domain.ru@DOMAIN.RU 5 2 HTTP/helpdesk.domain.ru@DOMAIN.RU 6 2 HTTP/HELPDESK@DOMAIN.RU 7 2 HTTP/HELPDESK@DOMAIN.RU 8 2 HTTP/HELPDESK@DOMAIN.RU 9 2 HTTP/HELPDESK@DOMAIN.RU 10 2 HTTP/HELPDESK@DOMAIN.RU
次ã«ãæ®ã£ãŠãããã¹ãŠãå¥ã®ãã¡ã€ã«ã«ä¿åããŸãã
ktutil: write_kt /etc/httpd.keytab
ãããŠããŠãŒãã£ãªãã£ãçµäºããŸãã
quit
4. Apache2ãšã¢ãžã¥ãŒã«ãé 眮ããŸãã ïŒã©ã³ãïŒ+ Perl
Ubuntu 14 ã§ã®ãµãŒãã¹ã®ã»ããã¢ããã«é¢ããåªããããã¥ã¢ã«ã¯ãã¡ã
ã
ç§ã¯ããªãã®ããã«ã©ã®ããã«ãããããã®ãããããŸããããç§ã«ãšã£ãŠã¯ãWebãµãŒããŒã LAMPã®å Žåãç¹ã«MySQLãšApacheãå¿ èŠãªãããã¹ã¿ãã¯å šäœãäžåºŠã«é 眮ããŸããphpã«ã¯äŸ¿å©ãªé¢æ°phpinfoïŒïŒ ç°å¢å€æ°ãç£èŠããŸãã
è¡ããŸãããã Apacheã眮ããŸã
apt-get install mysql-server apache2 php5 libapache2-mod-php5 libapache2-mod-auth-mysql php5-mysql php5-cgi libapache2-mod-php5 php5-common php-pear
mysql-serverã®ã€ã³ã¹ããŒã«äžã«ã圌ã¯mysqlã¹ãŒããŒãŠãŒã¶ãŒïŒ root @ localhost ïŒã®ãã¹ã¯ãŒããèšå®ããããã«æ±ããŸããäž¡æ¹ãšãrootã§ãã ãç°ãªããŠãŒã¶ãŒã§ããã«ãããããããã·ã¹ãã ã¹ãŒããŒãŠãŒã¶ãŒãšæ··åããªãããã«ãé¡ãããŸãã 誰ãåããã¹ã¯ãŒããæå®ããããšãçŠæ¢ããŠããŸãããã ãã®ããããã®ãã¹ã¯ãŒããæå®ããŠèŠããŠãããŠãã ãããããã§ãå¿ èŠã§ãã
ãã¹ãŠã®ããã±ãŒãžãé ä¿¡ãããã ãããã«MySQLãå°ãæ§æããå¿ èŠããããŸãããã®ããã«ã / etc / mysql / my.cnfãã¡ã€ã«ãéããŸãã
mcedit /etc/mysql/my.cnf
ãã¡ã€ã«ã«ã¯ãåä¿¡ãã±ããã®æ倧ãµã€ãºã瀺ã2è¡ããããŸãã è¡ã¯max_allowed_paââcketã§å§ãŸããŸãã ããã©ã«ãã§ã¯ããã®artibootã¯16ã¡ã¬ãã€ãã«èšå®ãããŠãããäž¡æ¹ã®è¡ã§20 MBã«å€æŽãããŸãã
max_allowed_packet = 20M
ãŸãã innodbãã°ãã¡ã€ã«ã®ãµã€ãºãå€æŽããå¿ èŠããããŸããããã¯ãMS SQLã®ãã©ã³ã¶ã¯ã·ã§ã³ãã°ã«é¡äŒŒããŠãããšç解ããŠããããã§ãã ãããè¡ãã«ã¯ã次ã®è¡ãèŠã€ããŸãã
# * InnoDB
ãããŠã次ã®å 容ã®å¥ã®è¡ãè¿œå ããŸãã
innodb_log_file_size = 512M
ããªãã¯ãã£ãšããããšãã§ããŸãããOTRSã¯ãŸãã«ãã®ãããªããªã¥ãŒã ããå§ãããŸãã ã¡ãã£ãšãããã¥ã¢ã³ã¹ïŒå€ããã°ãã¡ã€ã«ãããéããMySQLã¯æ°ãããã¡ã€ã«ãäœæã§ãããããã«å¿ããŠããªã¥ãŒã ãå¢ããããšãã§ããªãã®ã§ã / var / lib / mysqlãã©ã«ããŒã«ç§»åããã©ãã«ã§ãåé€ãŸãã¯ç§»åããŸãïŒç§»åããæ¹ãè¯ããããåžžã«åé€ããæéãããïŒ ib_logfile0ãib_logfile1ãªã©ã®åå ã
次ã«ãMySQLãåèµ·åããŸãã
service mysql restart
å€ããã°ãã¡ã€ã«ã®ä»£ããã«ãå¢å ããããªã¥ãŒã ã®æ°ãããã°ãã¡ã€ã«ãäœæãããããšã確èªãããã¹ãŠãæ£åžžã§ããããšã確èªããŸãã ãã®åŸãé£æ¥ãããã·ã³ã§ãã©ãŠã¶ãŒãéãã ãã«ããã¹ã¯ã«ã¢ã¯ã»ã¹ããŠãApache2ã¹ã¿ãŒãããŒãžãéããŸãã éããïŒ ããã§ãã¹ãŠåé¡ãããŸããâ Apacheãã€ã³ã¹ããŒã«ãããŸããã
ä»Perlã
apt-get install perl libapache2-mod-perl2 libdbd-mysql-perl libnet-dns-perl libnet-ldap-perl libio-socket-ssl-perl libpdf-api2-perl libsoap-lite-perl libgd-text-perl libgd-graph-perl libapache-dbi-perl libyaml-libyaml-perl
ApacheãPHPããã³PERLã¹ã¯ãªãããã©ãåŠçãããã説æããŸãããããããè¡ãã«ã¯ã/ etc / apache2 / mods-enabled / mime.confãã¡ã€ã«ã®220è¡ç®ã®AddHandlerè¡ã®ã³ã¡ã³ããå€ããŠããã©ãŒã ã«è¿œå ããŸãã
AddHandler cgi-script .cgi .pl
ãŸãããã®çš®é¡ã®å¥ã®1ã€ãè¿œå ããŸãã
AddHandler php5-script .php
php5ãperlãããã³cgiã¢ãžã¥ãŒã«ãæå¹ã«ããŠãApacheãåèµ·åããŸãã
a2enmod php5 a2enmod perl a2enmod cgi service apache2 restart
次ã«ããã¹ãŠãæ©èœãããã©ããã確èªããŸãããã ãããè¡ãã«ã¯ã / var / www / htmlã« 2ã€ã®ãã£ã¬ã¯ããªãäœæããŸãã
mkdir /var/www/html/php mkdir /var/www/html/perl
ãããŠãããããã«ãã¹ããã¡ã€ã«ãäœæããŸãã
touch /var/www/html/php/index.php touch /var/www/html/perl/index.cgi
次ã®ããã«å ¥åããæåã®ãã¡ã€ã«ïŒindex.phpïŒïŒ
cat /var/www/html/php/index.php <html> <body> <div style="width: 100%; font-size: 40px; font-weight: bold; text-align:center;"> <?php print Date("Y/m/d"); echo "<br>Path :".$_SERVER['PHP_SELF']; echo "<br>Remote User :".$_SERVER['REMOTE_USER']; echo "<br>Auth type :".$_SERVER['AUTH_TYPE']; echo "<br>Auth User :".$_SERVER['PHP_AUTH_USER']; ?> </div> <?php phpinfo(); ?> </body> </html>
2çªç®ã§ã¯ã次ã®ããã«èšè¿°ããŸãã
cat /var/www/html/perl/index.cgi #!/usr/bin/perl print "Content-type: text/html\n\n"; print "<html>\n<body>\n"; print "<div style=\"width: 100%; font-size: 40px; font-weight: bold; text-align: center;\">\n"; print "CGI Test Page"; print "\n</div>\n"; print "</body>\n</html>\n";
æš©å©ãèšå®ããŸãã
chmod 755 /var/www/html/php/index.php chmod 755 /var/www/html/perl/index.cgi
ãããŠãã1ã€ã®ãã¥ã¢ã³ã¹ïŒã¹ã¯ãªããã/ var / www / html / perl /ãã£ã¬ã¯ããªã«ãããããããå®è¡ã§ããããšãApacheã«èª¬æããå¿ èŠããããŸãã ãããè¡ãã«ã¯ã DocumentRootè¡ã®åŸã«/etc/apache2/sites-available/000-default.confãã¡ã€ã«ã«æ¬¡ã®ãããã¯ãè¿œå ããŸãã
<Directory "/var/www/html/perl">
AllowOverride All
Options +ExecCGI
Require all granted
ãããŠãapachephp5ãåèµ·åããŸãã
service apache2 restart
ããã§ããã©ãŠã¶ã§helpdesk / perl / index.cg iããã³helpdesk / php / index.phpã¢ãã¬ã¹ãéãããšããŸã ã éãå¿ èŠããããŸããphpã¹ã¯ãªããã«æ³šæããŠãã ãããããŒãžã®æäžéšã«å°ããªãããã¯ããããçŸåšã®æ¥ä»ãšããã€ãã®ç°å¢å€æ°ããããŸãããã®ãããã¯ã¯ãKerberosèªèšŒããããã°ãããšãã«åœ¹ç«ã¡ãŸãã
ãŸããçãååã§ã¯ããŒãžãéããªãå ŽåããããŸã ãã³ã³ãã¥ãŒã¿ãŒã®ãã«ããŒã ãã€ãŸãhelpdesk.domain.ru/php/index.phpãšhelpdesk.domain.ru/perl/index.cgiãå ¥åããå¿ èŠããããŸã ã ãããä¿®æ£ããæ¹æ³ã¯æ€èšããŸãããããããã¯ã«é¢ä¿ãªãã®ã§ãDNSãšApacheã®èšå®ã®æ¹åãæãäžããå¿ èŠããããšã ãèšããŸãã
5. Apache2ã§KerberosèªèšŒãæ§æããŸãã èªèšŒããã©ãŒãã³ã¹ã®ç¢ºèªã ééèªèšŒãèšå®ããŸãã
ãã®ã¢ã€ãã ã䜿çšãããšããã¹ãŠãããã«ã·ã³ãã«ã«ãªããŸãã ã¢ãžã¥ãŒã«ãé 眮ããŸãã
apt-get install libapache2-mod-auth-kerb
ãªã³ã«ããŸãïŒ
a2enmod auth_kerb
Apacheãåèµ·åããŸãã
service apache2 restart
ãããŠãphpã¹ã¯ãªããããããã©ã«ããŒã®æ¿èªãè¿œå ããŸãïŒå®éãphpã¹ã¯ãªããã§ç°å¢å€æ°ã®åºåãåããããªããºããããã®ã§ãããããããã°ããŸãïŒããããè¡ãã«ã¯ã/ etc / apache2 / sites-available / 000-default.confãå床éããperlãã©ã«ããŒã®ãããã¯ã®åŸã«phpãã©ã«ããŒã«å¥ã®ãããã¯ãè¿œå ããŸããApacheã«KerberosããŒã§ãã¡ã€ã«ãèªã¿åãæš©éãäžããŸãã
<Directory /var/www/html/php>
AuthType Kerberos
AuthName "Kerberos Authntication"
KrbAuthRealms DOMAIN.RU
Krb5Keytab /etc/httpd.keytab
KrbMethodNegotiate Off
KrbSaveCredentials Off
KrbVerifyKDC Off
Require valid-user
chmod 644 /etc/httpd.keytab
Apacheãåèµ·åããŸãã
service apache2 restart
ããã§ãhelpdesk / php / index.phpã®ãã©ãŠã¶ãŒã«ç§»åããŸãããã¹ãŠãæ£åžžã§ããã°ãæ¿èªèŠæ±ã衚瀺ãããŸãããã¡ã€ã³ãŠãŒã¶ãŒã®è³æ Œæ å ±ãå ¥åãããšãã¢ã¯ã»ã¹ãèš±å¯ãããŸãã空ã§ãããŒãžã®äžéšã®Remote_userãAuth_typeãAuth_userã®è¡ã«å¯Ÿå¿ããå€ã衚瀺ãããŠããå Žåããã¹ãŠãçŽ æŽãããã§ããKerberosèªèšŒãæ©èœããŸãã
æ®ã£ãŠããã®ã¯ããã®èªèšŒãééçã«ããããšã§ããã€ãŸãããŠãŒã¶ãŒã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥åããããã¡ã€ã³ã®ã»ãã·ã§ã³ããçŽæ¥ååŸãããŸãã
ãããè¡ãã«ã¯ããŸã/etc/apache2/sites-available/000-default.confãã¡ã€ã«ã§æ¬¡ã®è¡ãä¿®æ£ããŸãã
KrbMethodNegotiate Off
ã«
KrbMethodNegotiate On
次ã«ããŠãŒã¶ãŒã®ãã©ãŠã¶ãŒãæ§æããŸãã
IE
IEã§ã¯ããªãœãŒã¹ãè¿œå ããå¿ èŠãããããã«ããã¹ã¯ãhelpdesk.domain.ruããä¿¡é Œã«ïŒ
[ã»ãã¥ãªãã£]ã¿ãã§ãWindowsçµ±åèªèšŒãèš±å¯ããå¿ èŠããããŸãã
ãã®åŸãIEãåèµ·åããŠã¹ã¯ãªããã«ãã°ã€ã³ããŸãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããèŠæ±ããã®ã§ã¯ãªããããã«ãŠãŒã¶ãŒãèªèšŒããå¿ èŠããããŸãã
Firefox
Mozilla Firefoxã®ã»ããã¢ããã«ç§»ããŸããããããã§ã¯ãåèµ·åããããšãªããã¹ãŠãç°¡åã«ãªããŸããã¢ãã¬ã¹ããŒã«ãaboutïŒconfigãããã£ã«ã¿ãŒããŒã«ãnetwork.negããšå ¥åããŸããå³ã«ç€ºãããã«ã2è¡ã§ãã¡ã€ã³ãå ¥åããŸãã
ããäžåºŠããã©ãŠã¶ã§helpdesk / php / index.phpãéããŸãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããèŠæ±ããã«ããã«ããŒãžãéããäžã®ãããã¯ã«å®å šãªãŠãŒã¶ãŒãã°ã€ã³ã衚瀺ãããå Žåãããã§ãšãããããŸããééèªèšŒãèšå®ãããŠããŸãããã¹ãŠã®äœæ¥ã§æ倧ãã€æãå°é£ãªæ®µéãå®äºããŸããã
ïŒ æ³šæïŒ ãã©ãŠã¶ã§ã®ãã¹ãŠã®æäœã¯ããã¡ã€ã³ã¢ã«ãŠã³ãã§ãã¡ã€ã³ã«ãã°ã€ã³ããŠãããã·ã³ããå®è¡ããå¿ èŠããããŸãïŒ