å°ãåãŸã§ã Digital Securityãšå ±åã§ãäŒæ¥ã®wi-fiãããã¯ãŒã¯ã®ãã¹ããå®æœããŸããã ä»æ¥ãååãšäžç·ã«ããã¡ã€ã³ã¢ã«ãŠã³ãã«ããèªèšŒãåããWPA2-Enterpriseã«åºã¥ããŠæ§ç¯ãããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®è åšãšããããã身ãå®ãæ¹æ³ã«ã€ããŠèª¬æããŸãã
WPA2-Enterpriseã«ã€ããŠ
æ»æãšãã®æ»æããä¿è·ããæ¹æ³ã«ã€ããŠèª¬æããåã«ãWPA2-Enterpriseæšæºã®äž»ãªæ©èœãæãåºããŸãã
èªèšŒ ãããã¯ãŒã¯ã«æ¥ç¶ããã«ã¯ãã¯ã©ã€ã¢ã³ãã¯AAAãµãŒããŒã§èªèšŒããå¿ èŠããããŸãã å€ãã®å ŽåãRADIUSãµãŒããŒã¯ãã®ããã«æ©èœããŸãã èªèšŒã¯ããã¡ã€ã³ãã¹ã¯ãŒããã¯ã©ã€ã¢ã³ã蚌ææžãªã©ïŒEAPïŒã䜿çšããŠå®è¡ã§ããŸãã
æå·å AESã¢ã«ãŽãªãºã ã«ãã£ãŠç·šæãããŠããŸãã RADIUSãµãŒããŒã§ã®èªèšŒæã«ãã¯ã©ã€ã¢ã³ãããšã«åå¥ã®åçæå·åããŒïŒ802.1XïŒãçæãããŸãã ãã®ããŒã¯ãæ¥ç¶ãåæããã«äœæ¥äžã«å®æçã«æŽæ°ã§ããŸãã
WPA2-ãšã³ã¿ãŒãã©ã€ãºã¯ãŒã¯ãããŒ
ã¯ã©ã€ã¢ã³ããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«æ¥ç¶ããããã»ã¹ã¯ã次ã®ããã«ç°¡åã«èª¬æã§ããŸãã
æ¥ç¶ããããšã802.1xãããã³ã«ã®åå ã«ãããã¯ã©ã€ã¢ã³ãããŒã¿ãã¢ã¯ã»ã¹ãã€ã³ã/ã³ã³ãããŒã©ã«éä¿¡ãããŸãã ããã«ãæ
å ±ã¯RADIUSãµãŒããŒã«éä¿¡ãããã¯ã©ã€ã¢ã³ããèªèšŒãããŸããRADIUSãµãŒããŒã¯ããªã¹ãã«æå®ããããã°ã€ã³ãšãã¹ã¯ãŒããæã€ã¯ã©ã€ã¢ã³ããååšãããã©ãããããã³æ¥ç¶ã§ãããã©ããã確èªããŸãã
èªèšŒã«æåãããšãã¢ã¯ã»ã¹ãã€ã³ãã¯ã¯ã©ã€ã¢ã³ãããããã¯ãŒã¯ã«æ¥ç¶ããŸãã
RADIUSãµãŒããŒã§ã®èªèšŒããã»ã¹ãããã«è©³ããèããŠã¿ãŸãããã
- èªèšŒãåžæããã¯ã©ã€ã¢ã³ãã¯ãéä¿¡ã»ãã·ã§ã³ãéå§ããèŠæ±ãåºããŸãã
- ããã«å¿ããŠãçåŒåŽïŒRADIUSãµãŒããŒïŒã¯ä»»æã®æ å ±ãéä¿¡ããŸãããæ¯åç°ãªãæ å ±ïŒãã£ã¬ã³ãžïŒãã¯ã©ã€ã¢ã³ãã«éä¿¡ããŸãã
- ã¯ã©ã€ã¢ã³ãã¯åä¿¡ãããªã¯ãšã¹ãã«ãã¹ã¯ãŒããè¿œå ãããã®è¡ããããã·ã¥ãèšç®ããŸãã
- RADIUSãµãŒããŒã¯éä¿¡ãããå€ã§åãåŠçãè¡ããçµæãæ¯èŒããŸãã ããã·ã¥å€ãäžèŽããå ŽåãèªèšŒã¯æåãããšèŠãªãããŸãã
RADIUSãµãŒããŒã¯å®æçã«æ°ãããã£ã¬ã³ãžãã¯ã©ã€ã¢ã³ãã«éä¿¡ããèªèšŒæé ãå床繰ãè¿ãããŸãã
ãã®èªèšŒã¡ã«ããºã ã¯ããã£ã¬ã³ãž-ã¬ã¹ãã³ã¹ããšåŒã°ããEAPãããã³ã«ã®1ã€ã§ããPEAP-MSCHAPv2ãä»ããŠçºçããŸã ã
ç§ãã¡ã¯äœãã身ãå®ã£ãŠããŸãã
æµã¯èŠçã§ç¥ãããŠããå¿ èŠãããããããã¡ã€ã³ã¢ã«ãŠã³ãã«ããèªèšŒã䜿çšããŠãWPA2-Enterpriseãããã¯ãŒã¯ã«å¯Ÿããæ»æã®ä»çµã¿ãç°¡åã«èª¬æããŸãã
ã¯ã©ã€ã¢ã³ããåœã®ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããã ãããã¯ãŒã¯åSSIDïŒãããã¯ãŒã¯ãè€æ°ã®ã¢ã¯ã»ã¹ãã€ã³ãã§æ§ç¯ãããŠããå Žåã¯ESSIDïŒãšã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ïŒBSSIDïŒãç¥ã£ãŠãããšãæ»æè ã¯äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããå±éããå¯èœæ§ããããŸãã
æåã®å¯èœæ§ãé«ããããã«ãæ»æè ã¯æ¬¡ã®ç°¡åãªããªãã¯ã䜿çšããŸãã
- äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã«ã¯ãæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãããã匷åãªä¿¡å·ããããŸãã
- æ£èŠã®ã¢ã¯ã»ã¹ãã€ã³ãã®ä¿¡å·ãå±ããªãããéåžžã¯ãã®ãããã¯ãŒã¯ã«æ¥ç¶ããã¯ã©ã€ã¢ã³ããååšããå Žæã«ãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããé 眮ãããŸãã
ãã®ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããå Žæã確ä¿ããããã«ãæ»æè ã¯äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããæ¥ç¶ããRADIUSãµãŒããŒãå±éããŸãã ãã®RADIUSãµãŒããŒã«ã¯ãã¯ã©ã€ã¢ã³ããèªèšŒããæ£ãããã¹ã¯ãŒãããããã©ããã確èªããã¿ã¹ã¯ããããŸããã äž»ãªãã®ã¯ãèªèšŒããŒã¿ããã°ã€ã³ãããã³ã¯ã©ã€ã¢ã³ãããåœã®RadiusãµãŒããŒã«ãã£ãŠæäŸããããã£ã¬ã³ãžãžã®å¿çãååŸããããšã§ãã æ»æè ã¯ããªãã©ã€ã³ãã¹ã¯ãŒãã®æšæž¬ãšããã®åŸã®ã¿ãŒã²ããã®äŒæ¥ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãžã®æ¥ç¶ã«äœ¿çšããŸãã
空æ°ãç£èŠããªããã°ãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããèŠã€ããã®ã¯å¿ ããã容æã§ã¯ãããŸããã æ»æè ã¯ã巚倧ãªããã¯ããã¯ãããããã®ã¢ã³ãããã«ãŒãã«ãã£ãŒãŒã«çºé»æ©ãæã£ãŠããç·æ§ã®ããã«ã¯èŠããŸããã
ããšãã°ãããžã¿ã«ã»ãã¥ãªãã£ã®ååã¯ããã³ãã¹ãã®ããã«ãããããªãå èµããããŒã¿ãã«ãªå®¶åºçšã«ãŒã¿ãŒïŒãã®ãããªïŒã䜿çšããŠããŸãã OpenWRTã䜿çšããŠåãã©ãã·ã¥ããã«ã¹ã¿ã ããã±ãŒãžãã€ã³ã¹ããŒã«ããŸãã åºåã¯ãRADIUSãµãŒããŒãçµã¿èŸŒãŸããã¢ã¯ã»ã¹ãã€ã³ãã§ãããå¿ èŠã«å¿ããŠããšãŒãã«ããªãã¹ã³ããŠããŒã¿ãåéã§ããŸãã å¿ èŠã«å¿ããŠãéåžžã®é»è©±ã䜿çšããããšãã§ããŸãã
ãã®ãããªã¢ã¯ã»ã¹ãã€ã³ãã®å Žæã¯ãã¯ã©ãã«ãŒã®å·¥å€«ã«ãã£ãŠã®ã¿å¶éãããŸãã 被害è ã®ãªãã£ã¹ãããžãã¹ã»ã³ã¿ãŒã«ããå ŽåããããŒã®ã¢ã¯ã»ã¹ãã€ã³ããå転åŒæ¹æå£ãŸãã¯ãœãã¡ä»ãã®ãããŒã«é 眮ã§ããŸãã ãã®ãããªã¢ã¯ã»ã¹ãã€ã³ãããšã¬ããŒã¿ã®ããã«é 眮ãããšäŸ¿å©ã§ããæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãããé«éã§é ãããã®ã§ãã¯ã©ã€ã¢ã³ãããã€ã¹ã¯ãã©ãããããã»ãšãã©ã®å Žåã誀ã£ãã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããŸãã æ»æè ã¯ãäŒæ¥ã®äº€éæ©é¢ã«åœã®ã¢ã¯ã»ã¹ãã€ã³ããä¹ããŠä¹ãããšãã§ããŸãã
匷å¶èªèšŒè§£é€ ã ã¯ã©ã€ã¢ã³ããæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãã«æ¢ã«æ¥ç¶ãããŠããå Žåã¯ãåœã®ã¢ã¯ã»ã¹ãã€ã³ãã«åæ¥ç¶ããããã«ãäœããã®æ¹æ³ã§ã¯ã©ã€ã¢ã³ããåæïŒåŒ·å¶èªèšŒè§£é€ïŒããå¿ èŠããããŸãã æ»æè ããªã³ãšã¢ãèããŠããŸãã ãããè¡ãããã«ã圌ã¯wi-fiã¢ããã¿ãŒãã¢ãã¿ãŒã¢ãŒãã«ããŸãã éåžžãããã«ã¯aicrack-ngãŠãŒãã£ãªãã£ã䜿çšãããŸãã æ»æè ã¯ããã®å©ããåããŠãã¯ã©ã€ã¢ã³ããæ¢ã«æ¥ç¶ãããŠããæ£åœãªã¢ã¯ã»ã¹ãã€ã³ããåæãããæŸæ ããããšããã¡ãã»ãŒãžãã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ãã«éä¿¡ãå§ããŸãã ãã®å¹æã¯ã wi-fi管çãã¬ãŒã ïŒç®¡çãã¬ãŒã ïŒã æ¿å ¥ããããšã§å®çŸãããŸããã€ãŸãã é¢é£ä»ã解é€ããã³èªèšŒè§£é€ãã¬ãŒã ã§ãã
ãã®çµæãã¯ã©ã€ã¢ã³ãã¯ã¢ã¯ã»ã¹ãã€ã³ãããåæãããåãESSIDãæã€æ°ããã¢ã¯ã»ã¹ãã€ã³ãã®æ€çŽ¢ãéå§ããŸãã ãã®ç¶æ³ã§ã¯ããã匷åãªä¿¡å·ãæã€ã¢ã¯ã»ã¹ãã€ã³ãã䟿å©ã§ãã ã¯ã©ã€ã¢ã³ãããã€ã¹ã¯ããã«æ¥ç¶ããããšããŠããŸãã ã¯ã©ã€ã¢ã³ããåœã®RADIUSãµãŒããŒã§èªèšŒããå Žåãæ»æè ã¯ãŠãŒã¶ãŒåãšèªèšŒMSCHAPv2ã»ãã·ã§ã³ããã£ããã£ããå¯èœæ§ããããŸãã
èªåãå®ãæ¹æ³
èããããæ»æã¯ã次ã®ä¿è·æ段ã䜿çšããŠé²ãããšãã§ããŸãã
æ»æ | 枬å®ãã |
---|---|
ã¯ã©ã€ã¢ã³ããåœã®ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ãã | åœã®ã¢ã¯ã»ã¹ãã€ã³ããèå¥ããããã®ç©ºæ°ã®ç£èŠã ã¯ã©ã€ã¢ã³ã蚌ææžã䜿çšãããŠãŒã¶ãŒèªèšŒ |
匷å¶çãªã¯ã©ã€ã¢ã³ãèªèšŒè§£é€ | ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã¯ã©ã€ã¢ã³ãã®èªèšŒè§£é€ã匷å¶ããè©Šã¿ãæ€åºããããã®ãšã¢ã¢ãã¿ãªã³ã°ã ã³ã³ãããŒã©äžã®802.11wïŒä¿è·ããã管çãã¬ãŒã ãPMFïŒã®ã¢ã¯ãã£ããŒã·ã§ã³ |
次ã«ããã®ã±ãŒã¹ã§åä¿è·æ¹æ³ãã©ã®ããã«å®è£ ããããã説æããŸãã
äžæ£ã¢ã¯ã»ã¹ãã€ã³ãã®å€§æ°ç£èŠãšæ€åºã ãšã¢ã¢ãã¿ãªã³ã°ã¯ãã¢ã¯ã»ã¹ãã€ã³ãã®æšæºçãªæ段ãšWLANã³ã³ãããŒã©ã䜿çšããŠç·šæã§ããŸãã 次ã«ãã·ã¹ã³ããã€ã¹ã«ã€ããŠèª¬æããŸãã
ãããè¡ãã«ã¯ãã¢ã¯ã»ã¹ãã€ã³ãã§ãªããã£ãã«ã¹ãã£ã³ã¡ã«ããºã ãã¢ã¯ãã£ãã«ãªãããã¹ãŠã®ãã£ãã«ã®ç©ºæ°ãå®æçã«ã¹ãã£ã³ããŸãã ãã®ãããªç£èŠã®çµæãæãè² è·ã®å°ãªããã£ãã«ãšãµãŒãããŒãã£ã®ã¢ã¯ã»ã¹ãã€ã³ããèå¥ããŸãïŒCiscoã®çšèªã§ã¯ãäžæ£APïŒã ã¢ã¯ã»ã¹ãã€ã³ãããã®ããŒã¿ã¯ãæ¥ç¶å
ã®ã³ã³ãããŒã©ãŒã«éä¿¡ãããŸãã
ã³ã³ãããŒã©èªäœã«ããµãŒãããŒãã£ã®ã¢ã¯ã»ã¹ãã€ã³ãã®åé¡ã«ãŒã«ãèšå®ãããŸãããã®ã«ãŒã«ã«åŸã£ãŠãSSIDãåçã®å€éšã¢ã¯ã»ã¹ãã€ã³ãã¯ãã¹ãŠäžæ£ãšèŠãªãããŸãïŒCiscoã®çšèªã§ã¯æªæã®ããïŒã ãã®äžé£ã®èšäºã§ãCiscoã³ã³ãããŒã©ãŒã®æ§æã«ã€ããŠè©³ããèªãããšãã§ããŸãã
ããããã³ã³ãããŒã©ãŒã®ãŠã§ãã€ã³ã¿ãŒãã§ãŒã¹ã«ããäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã«é¢ããã¡ãã»ãŒãžã®è¡šç€ºã§ãã
681 Mon Apr 10 12:10:55 2017 Rogue APïŒ14ïŒ2dïŒ27ïŒefïŒf8ïŒ2b with Contained mode with Classified AP Listã
682æ4æ10æ¥12:10:55 2017äžæ£AP 14ïŒ2dïŒ27ïŒefïŒf8ïŒ2bã¯SSIDã宣äŒããŠããŸãã WPSããªã·ãŒã«ããèªåå°ã蟌ã
ã³ã³ãããŒã©å
ã®ã¡ãã»ãŒãžã¯ãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã®æ€åºæã«ãã°ã«èšé²ããŸãã
ç£èŠã·ã¹ãã ïŒãã®äŸã§ã¯NagiosïŒã§ã¯ãã³ã³ãããŒã©ãŒã®SNMPããŒãªã³ã°ãæ§æãããŠããŸãã äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããæ€åºããããšãç£èŠç»é¢ã«ä»¥äžãå«ãã¡ãã»ãŒãžã衚瀺ãããŸãã
- äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ã
- ãããæ€åºããã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ã
ã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ãšãã®å Žæã®å¯Ÿå¿è¡šã䜿çšããŠãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã®ããããã®å Žæãç¹å®ã§ããŸãã
äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããèšé²ããããšããç£èŠã·ã¹ãã å ã®ã¡ãã»ãŒãžã
ã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ãã®èªèšŒè§£é€ã匷å¶ããè©Šã¿ã®ããã®ç©ºæ°ç£èŠ ã äŸµå ¥æ€ç¥ã·ã¹ãã ïŒIDSïŒã®äžéšãšããŠãCiscoã³ã³ãããŒã©ãŒã«ã¯ãã¯ã©ã€ã¢ã³ãããã³è¿é£ã®ã¢ã¯ã»ã¹ãã€ã³ãã®æœåšçã«å±éºãªåäœãèªèã§ããæšæºã·ã°ããã£ã®æšæºã»ããããããŸãã ããã«ã¯ãèªèšŒè§£é€ãèªèšŒãé¢é£ä»ããªã©ã®å€æ°ã®è©Šè¡ãå«ãŸããŸãã
2017幎4æ12æ¥æ°Žææ¥10:17:53 2017 IDS眲åæ»æãæ€åºãããŸããã 眲åã¿ã€ãïŒæšæºãååïŒèªèšŒãã©ããã説æïŒèªèšŒèŠæ±ãã©ããããã©ãã¯ïŒçœ²åããšãæ€åºAPåïŒOST_Receptionãç¡ç·ã¿ã€ãïŒ802.11b / gãåïŒ5ããããïŒ500ããã£ãã«ïŒ11ãsrcMacïŒ 14ïŒ2dïŒ27ïŒefïŒf8ïŒ2b
Cisco Controllerãã°ã®è€æ°ã®èªèšŒã¡ãã»ãŒãž
åé¡ã®ã³ã³ãããŒã©ãŒã«ã¯ãäŸµå ¥é²æ¢ã¡ã«ããºã ïŒIPSïŒããããŸãã ããšãã°ãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ããç¹å®ããå Žåãæ»æã§äœ¿çšãããŠããã®ãšåãæ段ãã€ãŸãèªèšŒè§£é€ãšé¢é£ä»ã解é€ã«ãã£ãŠäŸµå ¥ã«å¯Ÿæã§ããŸãã ã¢ããã¿ã€ãºãããã³ã³ãããŒã©ãŒãšäžèŽããSSIDãæã€ã¢ã¯ã»ã¹ãã€ã³ãã衚瀺ããããšãèªåå°ã蟌ãã¡ã«ããºã ãéå§ããããã«ã³ã³ãããŒã©ãŒãæ§æã§ããŸãïŒäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã®ä¿¡å·ããã£ããã£ããã¢ã¯ã»ã¹ãã€ã³ãã¯ããã®ã¢ã¯ã»ã¹ãã€ã³ãã«ä»£ãã£ãŠèªèšŒè§£é€ãã¬ãŒã ã®éä¿¡ãéå§ããŸãã ãã®çµæãã¯ã©ã€ã¢ã³ããäœæ¥ããŠããŒã¿ãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã«è»¢éããããšã¯éåžžã«å°é£ã«ãªããŸãã
Ciscoã³ã³ãããŒã©ã®äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããã¯ã©ã€ã¢ã³ãã®èªåèªèšŒè§£é€ãèšå®ããŸãã
IDSã€ãã³ãã«é¢ããæ å ±ãã³ã³ãããŒã©ããååŸããã«ã¯ã2ã€ã®æ¹æ³ããããŸããSNMPãã©ãããç£èŠã·ã¹ãã ã«éä¿¡ããæ¹æ³ãšãã³ã³ãããŒã©ãã°ã解æããæ¹æ³ã§ãã
ç£èŠã·ã¹ãã ã¯ãäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ãšããããæ€åºããæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãã®MACã¢ãã¬ã¹ãå«ãã¡ãã»ãŒãžãåä¿¡ããŸãã
匷å¶çãªèªèšŒè§£é€ããä¿è·ããããã«ãã³ã³ãããŒã©ãŒã¯802.11wïŒProtected Management FramesãPMFïŒãã¢ã¯ãã£ãã«ããŸãã ãã®ã¢ãŒãã¯ãæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãããã¯ã©ã€ã¢ã³ãã匷å¶çã«åæããäžæ£ãªã¢ã¯ã»ã¹ãã€ã³ãã«åæ¥ç¶ããããšãç®çãšããæ»æãé²ããŸãã 802.11wã䜿çšããå ŽåãDisassociationãReassociationãããã³Deauthenticationãã¬ãŒã ã¯ãæ¿èªãããã¯ã©ã€ã¢ã³ããšæ£åœãªã¢ã¯ã»ã¹ãã€ã³ãã®ã¿ãç¥ã£ãŠããããŒã§çœ²åãããŸãã ãã®çµæãã¯ã©ã€ã¢ã³ãã¯ããã®ãã¬ãŒã ãæ£åœãªãã€ã³ãããåä¿¡ããããã©ãããå€æã§ããŸãã
Cisco Controller Web Interfaceã§802.11w PMFãæå¹ã«ããŸãã
ãŠãŒã¶ãŒèšŒææžèªèšŒã ãã®æ¹æ³ã®æ¬è³ªã¯ãä¿¡é Œã§ããèªèšŒå±ãçºè¡ãããŠãŒã¶ãŒèšŒææžã䜿çšããŠã¯ã©ã€ã¢ã³ããèªèšŒãããããšã§ãã ãã®èšŒææžã¯ãåã¯ã€ã€ã¬ã¹ããã€ã¹ã®ãŠãŒã¶ãŒèšŒææžã¹ãã¢ã«é 眮ãããŸãã æ¥ç¶æã«ãèªèšŒãµãŒããŒïŒAAAãµãŒããŒïŒã¯ãããã€ã¹ã«ãã£ãŠæ瀺ããã蚌ææžã確ç«ãããããªã·ãŒã§æ€èšŒããŸãã
æ»æè ã¯ã蚌ææžã䜿çšããŠããã€ã¹ãçã¿ãããã€ã¹ã«ãã°ã€ã³ããããã®ãã°ã€ã³/ãã¹ã¯ãŒããååŸããããšã§ãã¯ã©ã€ã¢ã³ã蚌ææžã«ããèªèšŒã§ã®ã¿ãããã¯ãŒã¯ã«äŸµå ¥ã§ããŸãã ããããããã§æãç©Žã¯ããã«éããããŸããçé£ã«ã€ããŠç¥ãããããã«ãªããšã蚌ææžã¯èšŒææžã»ã³ã¿ãŒã§ããã«åãæ¶ãããŸãã èªèšŒãµãŒããŒã¯èšŒææžãåãæ¶ãããããšãéç¥ããããããæ»æè ã¯èšŒææžã䜿çšããŠã¿ãŒã²ãããããã¯ãŒã¯ã«æ¥ç¶ã§ããŸããã
以äžã¯ããŠãŒã¶ãŒèšŒææžèªèšŒã䜿çšããWPA2-Enterpriseã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®å®è£ æ¹æ³ã®å³ã§ãã
ãã®ã¹ããŒã ã®æ¬¡ã®ã³ã³ããŒãã³ããããã«è©³ããèããŠã¿ãŸãããã
RADIUSãµãŒããŒã ããã€ã¹ããã®èŠæ±ãåãå ¥ããŠãã¯ã€ã€ã¬ã¹ããã€ã¹ïŒååŸã¯ã©ã€ã¢ã³ãïŒãæ¥ç¶ããŸãã
ãããã¯ãŒã¯ããªã·ãŒãµãŒããŒãNPS ã èªèšŒãšèªèšŒãå®è¡ããŸãã ããã§ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«æ¥ç¶ããããã®æ¡ä»¶ãæ§æã§ããŸãã äŸïŒ
- 蚌ææžèŠæ±;
- 蚌ææžçºè¡è
- æ¥ç¶ã¹ã±ãžã¥ãŒã«ã
Active Directoryãã¡ã€ã³ãµãŒããŒïŒ AD DS ïŒã ãŠãŒã¶ãŒã¢ã«ãŠã³ããšãŠãŒã¶ãŒã°ã«ãŒããå«ãããŒã¿ããŒã¹ãå«ãŸããŠããŸãã NPSããŠãŒã¶ãŒããŒã¿ãåä¿¡ããã«ã¯ãAD DSã«NPSãç»é²ããå¿ èŠããããŸãã
Active Directory蚌ææžãµãŒãã¹ã å ¬éããŒåºç€ïŒPKIïŒ
ã«ãŒããµãŒããŒã ã«ãŒã蚌ææ©é¢ã ããã§ã¯ãç§å¯éµã«åºã¥ããŠãèªèšŒã»ã³ã¿ãŒã®èšŒææžãçæãããŸãã ãã®èšŒææžã䜿çšããŠãäžé蚌ææ©é¢ã®èšŒææžã眲åãããŸãã
éåžžããã®èšŒææžã¯ããŒãšäžç·ã«USBãã©ãã·ã¥ãã©ã€ãã«ãšã¯ã¹ããŒããããå°äžå®€ãé庫ã«é ãããŠãããããéšå€è ãç©ççã«ã¢ã¯ã»ã¹ããããšã¯ã§ããŸããã ãµãŒããŒèªäœã¯ãªãã«ãªã£ãŠããŸãã
- äžäœãµãŒããŒã äžéèªèšŒå±ã äžé蚌ææ©é¢ã®èšŒææžã¯ããã«ä¿åãããŸãã å°æ¥ãã¯ã©ã€ã¢ã³ã蚌ææžãããã§çºè¡ãããäžé蚌ææžã«ãã£ãŠçœ²åãããŸãã ã°ã«ãŒãããªã·ãŒã䜿çšããŠãActive Directoryã¯ã¯ã©ã€ã¢ã³ãããã€ã¹ã«ãŠãŒã¶ãŒã®èšŒææžãèŠæ±ããããæ瀺ããŸãã 蚌ææžãçºè¡ãããããã€ã¹ã®ãŠãŒã¶ãŒã¹ãã¢ã«å ¥ããŸãã
äžäœãµãŒããŒã䜿çšããã¹ããŒã ã¯ãäžé蚌ææžãå±éºã«ãããããå Žåã«ãã«ãŒã蚌ææžããŸã£ãã圱é¿ãåããªããšããå©ç¹ããããŸãã ãã®å Žåã䟵害ããã蚌ææžã¯åã«ã«ãŒããµãŒããŒãä»ããŠåãæ¶ãããäžäœãµãŒããŒã¯åé€ãããŸãã
ä»æ¥ã¯ä»¥äžã§ããã³ã¡ã³ãæ¬ã§è³ªåããŠãã ããã