
ãã®èšäºã¯ããšããšèªåã®ããã®ã¡ã¢ãšããŠæžããããã®ã§ãããååããã®çµ¶ãéãªãèŠæã«å¿ããŠã1幎ååŸãåæ°ãéããŠåºçããŸããã
è³æã¯æ£æçã§ããã誰ãã«åœ¹ç«ã€ãããããŸããããšãŠãå¬ããã§ãã 建èšçãªã¢ããã€ã¹ãšãã£ãŒãããã¯ã«ããã«æè¬ããŸãã
ãã®ãããç§ãã¡ã®ãããã¯ã¯ã ãã¢ãããªã³ã°ãšéåžžã®ã·ã£ã®ãŒã·ã¹ãã åç©åã®æ¡ä»¶ã§Webã¢ããªã±ãŒã·ã§ã³ã«ã·ã³ã°ã«ãµã€ã³ãªã³ãå®è£ ããæ¹æ³ãã§ãã
ã·ã³ã°ã«ãµã€ã³ãªã³ã å ¥é
誰ã«ä¿¡é ŒãããŠããã®ã§ããã¹ãŠã«ä¿¡é ŒããŠãã ããã
©Cecilius Stacii
ç¥èã®ãªã人ïŒãã®è³æãèªãå¯èœæ§ã¯äœãã§ããïŒã«ã€ããŠã¯ãã·ã³ã°ã«ãµã€ã³ãªã³ïŒä»¥äžãSSOããšåŒã³ãŸãïŒã¯ãæè¡ã§ãéæ³ã®ãããã³ã«ã§ããªããã®ãšããŠäžè¬ã«åãå ¥ããããŠãããšæããŸãã SSOã¯ããšã³ããŠãŒã¶ãŒããã®è¿œå ã®ãžã§ã¹ãã£ãªãã§ãç°çš®ã·ã¹ãã ãšã¢ããªã±ãŒã·ã§ã³éã®AAAïŒèªèšŒãšæ¿èªãšã¢ã«ãŠã³ãã£ã³ã°ïŒæ¥ç¶ã®å®è£ ãå¯èœã«ããææ³ã§ãã
å žåçãªSSOã®äŸã¯ãããšãã°ãå®å šã«ãã€ã¯ããœãã補åã§æ§ç¯ããããœãªã¥ãŒã·ã§ã³ã§ãã ãã®å ŽåãActive DirectoryãµãŒããŒã¯ãã£ã¬ã¯ããªã®ã¹ãã¬ãŒãžãæäŸããã ãã§ãªãããã¡ã€ã³ã«æ¥ç¶ãããã¯ãŒã¯ã¹ããŒã·ã§ã³ããããã«ã€ã³ã¹ããŒã«ããããœãããŠã§ã¢ããã®ä»ãã¹ãŠã®ããŒããŠã§ã¢ã«è³ããŸã§ã®åäœãå¶åŸ¡ããŸãïŒæ¿æ²»å®¶ã«ããåãUSBã®çŠæ¢æ¹æ³ã¯ãã¹ãŠç¥ã£ãŠããŸãïŒã ãã®ç¶æ³ã§ã®ãšã³ãããŒãšã³ãã®AAAãã©ãã€ã ã¯ãMicrosoft補åã䜿çšããå Žåãã€ãŸãåçš®ã®ç°å¢ã§ã»ãŒèªåçã«æäŸãããŸãã
AAAééæ§ã«é¢ããç°çš®ITæ§é ã¯ããè€éã§ããããã®ç°å¢çšã«å€ãã®å®è£ æ¹æ³ãæ¢ã«éçºãããŠãããå€ãã®å®è£ æ¹æ³ããããŸãã
äŸãšããŠïŒ
- æåãªAtlassian瀟ã¯ããã®ãããªåé¡ã解決ããå®çžŸã®ããAtlassian Crowd補åãæèŒããŠããŸããããã®äŒç€Ÿã®ãœãããŠã§ã¢è£œåã®ç¹å®ã®ã©ã€ã³ã«åãããŠèª¿æŽãããŠããŸãã
- ç§ãã¡ã®å€ãã¯State Service Portalã䜿çšããŠãããçŽçšè ã§ããç§ãã¡å šå¡ããState Service Portalãä»ããŠnalog.ru Webãµã€ãã§èªèšŒãå©çšã§ããããšãç¥ã£ãŠããŸãã
- é説çã§ãããé©ãã»ã©é »ç¹ãªèªèšŒãªãã·ã§ã³ïŒãGoogleã«ã¢ã¯ã»ã¹ãã次ã«Googleçµç±ã®èªèšŒã§Facebookã«è¡ãã次ã«Facebookçµç±ã®èªèšŒã§AliExpressã«è¡ããŸããã
äžèšã®3ã€ã®ãã€ã³ãã®ãã¡2ã€ã¯SSOãšã¯é¢ä¿ãããŸããã
ã©ã£ã¡ïŒ :)
å ¬ç
ãã®èšäºã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯ ã SSOã¯ã€ã³ãã©ãããå ïŒäŒæ¥ç°å¢å ïŒã§ã®ã¿å®è£ ããã³åäœããåæã«ååãªä¿¡é Œæ§ããã©ãŒã«ããã¬ã©ã³ã¹ãããã³ã»ãã¥ãªãã£ãæäŸããããšãåãå ¥ããŸãã
ææŠãã
å ¥ãå£ã«ã¯æ¬¡ã®ãã®ããããŸãã
- InterSystemsãã©ãããã©ãŒã äžã«æ§ç¯ãããWebã¢ããªã±ãŒã·ã§ã³ã
- å転ããŠããLinuxãµãŒããŒã ãµãŒããŒã¯ãã客æ§ã®ã€ã³ãã©ãããã«ãããŸãã
- æèœãªãã¡ã€ã³ãã©ã¬ã¹ããšå€æ°ã®ã³ã³ãããŒã©ãŒã«é¢ããéåžžã«ãã調æŽãããã°ã«ãŒãããªã·ãŒãå«ããéçºããããã€ã¯ããœããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã
- 芪æãªãã客æ§ãããŒãã¬ãŒãºãããã¯å¿ èŠã§ãïŒããšãæšæ¥æºåãã§ããŠããïŒã
- ãããŠã幞ããªããšã«ãæ¬æ Œçãªãã¹ããµãŒããŒãªã®ã§ãå±éããå ŽæããããŸãã
以äžã«èª¬æããæ¹æ³ã«å ããŠããã®åé¡ã解決ããããã®ããç°¡åãªæ¹æ³ãããããšãããã«äºçŽããŸãããç§ãã¡ã¯ããããæ¢ããŠããŸããã ãŸãã顧客ã®èŠä»¶ã¯æãæ確ã§ã¯ãªãã£ãã
ããã§ã¯å§ããŸãããïŒ
ãã³ã®ã³ãšèžãã Linux

ãã¡ã€ã³ïŒçæ žçç©ãçåœïŒåç©ããµããã¡ã€ã³ïŒãŠãŒã¡ã¿ãŸã€ãã¿ã€ãïŒè玢åç©éããµãã¿ã€ãïŒèæ€åç©ãã€ã³ãã©ã¿ã€ãïŒäžé¡ãã¹ãŒããŒã¯ã©ã¹ïŒå足ãã¯ã©ã¹ïŒé³¥ããµãã¯ã©ã¹ïŒæ°çå ãåéïŒãã³ã®ã³ã®ãããªã家æïŒãã³ã®ã³ãã¿ã€ãïŒOracleãµãŒããŒãªãªãŒã¹7.2
èšçœ®
Oracle Linux ServerãªãªãŒã¹7.2ãšããååã§ãæ¬æ ŒçãªRHELã®åå«/ã¯ããŒã³ãåŸãŸããã
ã«ã¹ã¿ãã€ãº
ãã€ãã®ããã«ããµãŒããŒåœ¢åŒã®Linuxã¯ã·ã³ãã«ã§æ°æ¥œã§ã¢ããã¿ã€ã ã§ãããç¹ã«ãããã¯ãŒã¯èšå®ã«é¢ããŠã¯ãLinuxãæ£ããæ§æãããŠããããšã確èªããããšãéèŠã§ãã
ãã¹ãäž
ãŸããDNSèšå®ãèŠãŠãã ããã ããã¯ããœãªã¥ãŒã·ã§ã³å šäœãæ©èœããããã«éèŠã§ãã
[root@my-test-server ~]# cat /etc/resolv.conf # Generated by NetworkManager search my-domain.ru nameserver 172.16.0.1 nameserver 172.16.0.2
ãã®æ®µéã§ã¯ãDNSãµãŒããŒïŒãã®å Žåã¯ãã¡ã€ã³ã³ã³ãããŒã©ãŒã§ãããïŒã®å¯çšæ§ã確èªããå¿ èŠããããŸãã ããŸããŸãªæ¹æ³ã§ãããè¡ãããšãã§ããŸãããæ°ã«å ¥ãã®ãŠãŒãã£ãªãã£ãšæ€èšŒæ¹æ³ïŒhostãdigãtelnetãpingãªã©ïŒã䜿çšããã ãã§ãã å¿ èŠãªããŒããã¢ã¯ã»ã¹å¯èœã§æ©èœããŠããããšãéèŠã§ããDNSã®å Žåãããã¯äž»ã«TCP / 53ã§ãã ãŸããICMPãå«ããã¹ãŠãéããèŠæ±ããåæãããããŒããæ°åã ãæ®ãããšãã§ãããããã¯ãŒã¯ç®¡çè ãšèŠåå¡ïŒç§èªèº«ïŒã®ç ç²ãšæ¬²æãå¿ããªãã§ãã ããã äœãæ£ããã
ç¬ã®ã¯ã«ãã Kerberos

ã±ã«ããã¹ãã±ã«ããã¹ïŒä»ã®ã®ãªã·ã£èªÎÎÏβεεÏοÏãlatãCerberusããïŒ-ã®ãªã·ã£ç¥è©±ã§ã¯ãå£ããæµããææ¯æ··åç©ãå«ã3é ã®ç¬ã§ããTyphonãšEchidnaïŒTartarusãšGaiaïŒã®è£œåã§ãã ã±ã«ããã¹ã¯æ»ãã ããã¹ã®çåœããã®åºå£ãå®ããæ»è ãçããŠããäžçã«æ»ãããšãèš±ããŸããã§ããã ãããããã®é©ãã»ã©åŒ·åãªã¯ãªãŒãã£ãŒã¯ã圌ã®ãšã¯ã¹ããã€ãã®1ã€ã§ãã©ã¯ã¬ã¹ã«æããŸããã
MSADãšã®ãå®ãå€ãååãã®ããã«Kerberosãæ£ããæ§æããå¿ èŠæ§ã«ã€ããŠæãåºãå¿ èŠã¯ãªããšç¢ºä¿¡ããŠããŸãã
ãã¡ãããã€ã³ã¹ããŒã«ããŠèšå®ããã«ã¯ããµãŒããŒã®ã«ãŒãæš©éãå¿ èŠã§ãã ãŸãã¯sudoã ãŸãã¯ãã³ãŒã«ãµãŠã«ãã
èšçœ®
ãæªãããã¯ãŒã¯ç®¡çè ãããµãŒããŒã«ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãèš±å¯ããå Žåãå¿ èŠãªããã±ãŒãžã®ã€ã³ã¹ããŒã«ãšæ§æã¯éåžžã«ç°¡åã§ãã
æ®å¿µãªãããè¯ã管çè ãäºåã«ãã¹ãŠãã€ã³ã¹ããŒã«ããªãã£ãå Žåããªããžããªãžã®ã¢ã¯ã»ã¹ãåããã€ã³ã¿ãŒããããã€ã³ã¹ããŒã«æ®µéã§å¿ èŠã§ãã
ãŸããã¢ã¯ã»ã¹ããããã±ãŒãžãã€ã³ã¹ããŒã«ãããŠããããã±ãŒãžããªãå Žåã¯ããã¹ãŠãæ²ãããªããŸãã
ãã ãã楜芳çã«ãªãã管çè ãå°ãªããšã1æéãã£ãã«ãéããããšãèæ ®ããŠãã€ã³ã¹ããŒã«ãå®è¡ããŸãã
[root@my-test-server ~]# yum install krb5-workstation : ulninfo --> ---> krb5-workstation.x86_64 0:1.14.1-26.el7 --> : libkadm5(x86-64) = 1.14.1-26.el7 : krb5-workstation-1.14.1-26.el7.x86_64 --> : krb5-libs(x86-64) = 1.14.1-26.el7 : krb5-workstation-1.14.1-26.el7.x86_64 --> : libkadm5srv_mit.so.10(kadm5srv_mit_10_MIT)(64bit) : krb5-workstation-1.14.1-26.el7.x86_64 --> : libkadm5srv_mit.so.10()(64bit) : krb5-workstation-1.14.1-26.el7.x86_64 --> ---> krb5-libs.x86_64 0:1.13.2-10.el7 ---> krb5-libs.x86_64 0:1.14.1-26.el7 ---> libkadm5.x86_64 0:1.14.1-26.el7 --> ============================================================== Package ============================================================== : krb5-workstation x86_64 1.14.1-26.el7 ol7_latest 772 k : libkadm5 x86_64 1.14.1-26.el7 ol7_latest 172 k : krb5-libs x86_64 1.14.1-26.el7 ol7_latest 741 k ====+++++============================================= 1 (+1 ) ( 1 ) : 1.6 M Is this ok [y/d/N]: y Downloading packages: No Presto metadata available for ol7_latest (1/3): krb5-libs-1.14.1-26.el7.x86_64.rpm | 741 kB 00:00:00 (2/3): libkadm5-1.14.1-26.el7.x86_64.rpm | 172 kB 00:00:00 (3/3): krb5-workstation-1.14.1-26.el7.x86_64.rpm | 772 kB 00:00:00 -------------------------------------------------------------------------------- 3.9 MB/s | 1.6 MB 00:00:00 Running transaction check Running transaction test Transaction test succeeded Running transaction : krb5-libs-1.14.1-26.el7.x86_64 1/4 : libkadm5-1.14.1-26.el7.x86_64 2/4 : krb5-workstation-1.14.1-26.el7.x86_64 3/4 : krb5-libs-1.13.2-10.el7.x86_64 4/4 : krb5-libs-1.14.1-26.el7.x86_64 1/4 : libkadm5-1.14.1-26.el7.x86_64 2/4 : krb5-workstation-1.14.1-26.el7.x86_64 3/4 : krb5-libs-1.13.2-10.el7.x86_64 4/4 : krb5-workstation.x86_64 0:1.14.1-26.el7 : libkadm5.x86_64 0:1.14.1-26.el7 : krb5-libs.x86_64 0:1.14.1-26.el7 !
ãã¡ããã䜿çšããããã±ãŒãžãããŒãžã£ãŒãšãã®ããŒãžã§ã³ã®äž¡æ¹ãç°ãªãå ŽåããããŸãããããã«ããåé¡ã®æ¬è³ªã¯å€ãããŸããã
ãããŠã ã¯ããç§ã¯ãã®ãããªäºçŽ°ãªã€ã³ã¹ããŒã«ã®æãå®å šãªãªã¹ãã®å€ããèšäºã«è¡šç€ºãããªãããšãçŽæããŸãã
ã«ã¹ã¿ãã€ãº
å®å šã«æ©èœããKerberosæ§æãã¡ã€ã«ã¯ãæåã¯æ¬¡ã®ããã«ãªããŸãã
[root@my-test-server ~]# cat /etc/krb5.conf [logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log [libdefaults] dns_lookup_realm = true ticket_lifetime = 24h renew_lifetime = 7d forwardable = true rdns = false default_realm = MY-DOMAIN.RU default_ccache_name = KEYRING:persistent:%{uid} [realms] MY-DOMAIN.RU = { kdc = ad.my-domain.ru admin_server = ad.my-domain.ru } [domain_realm] .my-domain.ru = MY-DOMAIN.RU my-domain.ru = MY-DOMAIN.RU
ad.my-domain.ruã¯æ£ããFQDNã§ãã ã解決å¯èœã§ã¢ã¯ã»ã¹å¯èœã§ããå¿ èŠããããŸãã ããã¯éèŠã§ãïŒ
ãã¹ãäž
次ã®ã¹ãããã§ã¯ãååãšããŠããã¹ãŠãéåžžã«ç°¡åã«è¡ãããŸãã
ãã¹ãŠãæªãããšã確èªããŠãã ããïŒ
[root@my-test-server ~]# klist klist: Credentials cache keyring 'persistent:0:0' not found
äžé ç¬ã®å°é家ïŒãããã·ãŒã¯ã¬ãããã¡ã€ã³ç®¡çè ãã°ã€ã³/ãã¹ã¯ãŒããç¥ã£ãŠããã·ã¹ãã 管çè ã®å¥åïŒã«é»è©±ãããã次ã®ãããªå ¥åãäŸé ŒããŸãã
[root@my-test-server ~]# kinit SuperPuperAdmin Password for SuperPuperAdmin@MY-DOMAIN.RU: ************************
ãã®åŸãklistã¯ãã§ã«æå³ã®ãããã®ãè¿ãã¯ãã§ãã
ç§ãã¡ã¯ç¬ãå®æãããšèããŠããŸãã...
æ¥ç£ã¯æ©è¡ã§ããªãããµãŒãã§ããããšã¯ããç¥ãããŠããŸãã
倧平åã®ãã³ã¹ã ã¢ããã

ã¢ãããã¯ããªã³ãã³å®¶æã®ã¢ã¿ãã¹ã«ã³æ¯éšã®ã¢ãããèšèªã話ããåç±³ã€ã³ãã£ã¢ã³ã®æåçã«é¢é£ããããã€ãã®éšæã®ç·ç§°ã§ãã
ã¢ãããæã¯ããã³ãšããåã®æ¯ãã®ããããªç¬èªã®ä»®é¢èèžãäœããŸããã ã¢ãããã«ã¯ãããžã§ã³ãšäºæž¬ã®ããã®ãã³ã¹ååŒããããŸãã
Apache Indiansãšäžç·ã«ç©ããå§ããŸãã
èšçœ®
åãšåæ§ã«ãããã±ãŒãžããã¹ãŠã§ãïŒãã¡ãããå šèœã®ç®¡çè ã·ã£ãŒãã³ãé€ããŸãïŒã
[root@my-test-server ~]# yum install httpd : ulninfo [âŠskippedâŠ] : httpd.x86_64 0:2.4.6-45.0.1.el7 : httpd-tools.x86_64 0:2.4.6-45.0.1.el7 !
ã«ã¹ã¿ãã€ãº
ãã¡ãããããã¯ååã§ã¯ãããŸãããæ°ããèšç«ãããã€ã³ã人ã¯ç§ãã¡ã®èšèªãç¥ããªãããã§ãã 次ã®ããã«æ§æããŸã ã
[root@my-test-server ~]# cat > /etc/httpd/conf.d/ensemble.conf DocumentRoot "/opt/isc/ensemble/csp" CSPModulePath /opt/isc/ensemble/csp/bin/ LoadModule csp_module_sa /opt/isc/ensemble/csp/bin/CSPa24.so User cacheusr Group cacheusr <Location /> CSP On SetHandler csp-handler-sa </Location> ServerName my-test-server.my-domain.ru /> <Directory /> Options MultiViews FollowSymLinks AllowOverride None Require all granted <FilesMatch "\.(log|ini|pid|exe|so)$"> Require all denied </FilesMatch> </Directory> HostnameLookups Off <Location /csp> CSP On SetHandler csp-handler-sa </Location> <Location "/csp/bin/Systems/"> SetHandler cspsys-handler-sa </Location> <Location "/csp/bin/RunTime/"> SetHandler csp-handler-sa </Location> CSPFileTypes csp cls zen cxw Alias /csp/ /opt/isc/ensemble/csp/ <Directory "/opt/isc/ensemble/csp/"> AllowOverride None Options MultiViews FollowSymLinks ExecCGI Require all granted <FilesMatch "\.(log|ini|pid|exe)$"> Require all denied </FilesMatch> </Directory>
ãããŠãããå°»ã«è¹ŽãããäžããŸãã
[root@my-test-server ~]# systemctl restart httpd
ã·ã¹ãã 管çããŒã¿ã«ã«ã¢ã¯ã»ã¹ããŠã圌ãNasvenskyã話ãããšãåŠãã ããšã確èªããŸãã
ã¢ãããæã¯ãã€ãŠèªãé«ãç¬ç«ãã人ã ã ã£ãã®ã§ãè¡ãæµããŠããã®ã§ãæ¬æãšç€Œåããã£ãŠãã¢ãããã«ãã£ãããŒãã³ã®ã³ãšä»äºãããããäŸé ŒããŸãã
[root@my-test-server ~]# systemctl is-enabled httpd disabled [root@my-test-server ~]# systemctl enable httpd Created symlink from /etc/systemd/system/multi-user.target.wants/httpd.service to /usr/lib/systemd/system/httpd.service. [root@my-test-server ~]# systemctl is-enabled httpd enabled
ãPioneer DawnããèããŠãæ°Žã®æé ãè¡ãã3é ã®ç¬ãæ£æ©ãããã€ã³ã人ããšãããããããã¯ã·ã§ã³äœæãã«é²ã¿ãŸããããã¯ä»æ¥ãã³ã¹ïŒãããŠã¿ã³ããªã³ãå«ãïŒã«ãªããŸãã
ãµã³ããèžã£ãŠããŸãïŒ

ãµã³ãïŒããŒãããµã³ãïŒ-ãã©ãžã«äººã®æ°æçã¢ã€ãã³ãã£ãã£ã®è±¡åŸŽã§ãããã©ãžã«ã®ãã³ã¹ã ãã©ãžã«ã®ã«ãŒããã«ã®ãããã§ããã³ã¹ã¯äžççãªå声ãåŸãŸããã ãµã³ãã®çš®é¡ã®1ã€ã¯ãã©ãã³ã¢ã¡ãªã«ã®ç€Ÿäº€ãã³ã¹ã®5ã€ã®å¿ é ããã°ã©ã ã«å«ãŸããŠããŸããã 2/4ãŸãã¯4/4ã®éã§ã1åããã50ã52ããŒãã®ããŒã¹ã§å®è¡ãããŸãã
誰ããç¥ã£ãŠããããã«ããµãŒããŒããŒãžã§ã³ã§ã®ææã®Sambaã¯ãè«ççã«3ã€ã®å®è¡å¯èœã¢ãžã¥ãŒã«ïŒsmb | nmb | winbindïŒdã«åå²ãããŠããŸãã
çè«çã«ã¯ãæå¹ãªwinbinddã®ã¿ãå¿ èŠã§ãã ã¯ããããã¯SambaããŒã¢ã³ã®1ã€ã«ãããŸããã ããããããã±ãŒãžå šäœãšã¯å¥ã«ã€ã³ã¹ããŒã«ããã圌ã¯ãäœããã®çç±ã§æ¢åã®ãã©ãããã©ãŒã ã§äœæ¥ããããªãã£ããããç§ã¯åœŒã®äžæºã®çç±ãæ¢ã«ç解ããããããŸããã§ããã
ãããã£ãŠãå®å šã«ã€ã³ã¹ããŒã«ããŸãã
èšçœ®
æé ã¯éåžžã«ç°¡åã§ããç¹ã«ãïŒaïŒç®¡çè ïŒshaïŒãããªããšèžã£ãŠããå Žåã
[root@my-test-server ~]# yum install samba : ulninfo --> ---> samba.x86_64 0:4.4.4-9.el7 --> [âŠskippedâŠ] 1 (+12 ) : 6.6 M : 23 M Is this ok [y/d/N]: y [âŠskippedâŠ] : samba.x86_64 0:4.4.4-9.el7 : libaio.x86_64 0:0.3.109-13.el7 libldb.x86_64 0:1.1.26-1.el7 libtalloc.x86_64 0:2.1.6-1.el7 libtdb.x86_64 0:1.3.8-1.el7_2 libtevent.x86_64 0:0.9.28-1.el7 libwbclient.x86_64 0:4.4.4-9.el7 pytalloc.x86_64 0:2.1.6-1.el7 samba-client-libs.x86_64 0:4.4.4-9.el7 samba-common.noarch 0:4.4.4-9.el7 samba-common-libs.x86_64 0:4.4.4-9.el7 samba-common-tools.x86_64 0:4.4.4-9.el7 samba-libs.x86_64 0:4.4.4-9.el7 !
ã¹ãŒãã®æºåãã§ãããããã¯ã¿ã€ãç· ããŸãïŒ
[root@my-test-server ~]# yum install samba-winbind [âŠskippedâŠ] : samba-winbind.x86_64 0:4.4.4-9.el7 : samba-winbind-modules.x86_64 0:4.4.4-9.el7 !
ã«ã¹ã¿ãã€ãº
ã«ãŒããã«ã«è¡ãã ãã§ã¯ååã§ã¯ãããŸãããå°ãèžãå¿ èŠããããŸãïŒãã§ã«ã¿ã³ããªã³ã§ïŒïŒ
[root@my-test-server ~]# cat /etc/samba/smb.conf # See smb.conf.example for a more detailed config file or # read the smb.conf manpage. # Run 'testparm' to verify the config is correct after # you modified it. [global] workgroup = AD security = ads server string = my-test-server netbios name = my-test-server security = ads realm = my-domain.ru password server = *
æåã®ã¹ãããããªããŒãµã«ããŸãïŒãã¡ãããæåã¯ééã£ãŠããŸãïŒïŒ
[root@my-test-server ~]# systemctl restart winbind Job for winbind.service failed because the control process exited with error code. See "systemctl status winbind.service" and "journalctl -xe" for details.
ç§ãã¡ã¯ãã³ã¹æåž«ã®å©ããæ±ããŸãããããŠïŒãç§ãã¡ã«ã¯ããã€ãã®çŽ æŽãããçºèŠããããŸã...ãïŒããã¯ç§ãã¡ã®3é ã®åç¬ã飌ããªããã®ãå©ããã®ãšåãç¬ã®ãã³ãã©ãŒã§ããããšãå€æããŸããïŒ
[root@my-test-server ~]# net ads join --U SuperPuperAdmin@my-domain.ru Enter root's password: ************************
ãããŠç§ãã¡ã¯å¥è·¡ãæã¿ãŸã...ããã¯ãã¹ãŠæãšåœŒããæé·ããå Žæã«äŸåããŸã...
ãå°çäžã«ã¯éåžžã«å€ãã®åé¢ããããŸãã
ãããŠç°ãªãéåœ
åžæã¯å€æãã«äžããŸãã
人ãžã®ãã§ãªãŒãã³â
©ProdigyïŒRammsteinã2048
ãã®å Žåã次ã®ããã«è¡šç€ºãããŸãã
[root@my-test-server]# net ads info LDAP server: 172.16.0.123 LDAP server name: AD.my-domain.ru Realm: MY-DOMAIN.RU Bind Path: dc=MYDOMAiN,dc=RU LDAP port: 389 Server time: , 33 2049 17:48:12 ATL KDC server: 172.16.0.123 Server time offset: 0
幞ãã¯ããããããã«ãããŸãïŒ
ãã¹ãäž
ç§ãã¡ã¯ããã確èªããŸãïŒå¹žçŠïŒ
[root@my-test-server /]# wbinfo -g MYDOMAIN\proverka MYDOMAIN\ MYDOMAIN\ MYDOMAIN\ MYDOMAIN\ MYDOMAIN\ MYDOMAIN\ MYDOMAIN\ MYDOMAIN\ windows MYDOMAIN\ 1c MYDOMAIN\ MYDOMAIN\
é£çµ¡å ããããŸãïŒ
ã¹ããŒã¢ãŒã·ã§ã³ã mod_auth_ntlm_winbind

ã¹ããŒãã³ã¹ãèžãåã«ã誰ãããã®ãã³ã¹ã«æåŸ ããå¿ èŠããããŸãããªããªãããã®äžã§åãã ãã§ã¯åãå ¥ããããªãããã§ãã ç¬éãã€ãã¿ãé åçãªå¥³ã®åã«è¡ããŸãã ã¹ããŒãã³ã¹ãèžãã€ãããªããäžå¿ èŠãªåé·æ§ãªãã«ãæœåšçãªããŒãããŒã«çŽæ¥ããªãã®æå³ãçºè¡šããŠãã ããã ããŸãã«çææ°ã§æå®çã§ã¯ãªãã圌女ã«åæãããã©ããã®æ±ºå®ãæ®ããŸãã åŸè ã®å Žåã圌女ã¯æåŠããŸãããæè¬ããŸãã
èšçœ®
mod_auth_ntlm_winbindã䜿çšããŠãWebã§ã©ã€ããªããžããªãæ€çŽ¢ããŸã ã
ã¯ããçããŠãã人ã¯ã»ãšãã©ããŸããïŒsvnããååŸããŸããïŒã
ã¯ããããŒãžã§ã³ã¯ãŸã£ããæ°ãããã®ã§ã¯ãããŸããã
ã¯ããæåã§çµã¿ç«ãŠãå¿
èŠããããŸãã
ã¯ããå
šå¡ãéãŸãããã§ã¯ãããŸããã
ã¯ããããããæåç·šéã®åŸã§ãå¯èœã§ãã
ã¯ããã¢ã»ã³ããªã«ã¯ãå®å
šã«æ§æãããç°å¢ïŒgcc + glib + apxs +ããããŒ+ * -dev + ...ïŒãå¿
èŠã§ãã
ã¯ããããã¯ç§ãç¥ã£ãŠããå¯äžã®å®å®ãããªãã·ã§ã³ã§ãã
ã«ã¹ã¿ãã€ãº
æ§æã§ã¯ããã¹ãŠãå€å°åºæ¬çã§ãããApacheãæ§æãã¡ã€ã«ã«è¿œå ããŸãïŒã¡ã€ã³ãã¡ã€ã«ãŸãã¯å¿ èŠã«å¿ããŠconf.d / xyz.confã«ïŒïŒ
<Directory "/opt/isc/ensemble/csp/myapp/"> AuthName "NTLM my-domain.ru" NegotiateAuth on NegotiateAuthHelper "/usr/bin/ntlm_auth --helper-protocol=gss-spnego" NTLMBasicAuthoritative on AuthType Negotiate require valid-user #LogLevel debug ## </Directory>
ãã¡ãããä»ã®ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒãšåæ§ã«ãã€ã³ã¹ããŒã«çšã«ãã¹ãæ£ããæå®ããå¿ èŠããããŸãã
æåã®ãããã°ã§ã¯ã LogLevelè¡ã®ã³ã¡ã³ãã解é€ããããšããå§ãããŸããè¿œå ãããšãå Žåã«ãã£ãŠã¯éåžžã«åœ¹ç«ã€ã¡ãã»ãŒãžãApacheãã°ãã¡ã€ã«ã«æžã蟌ãŸããŸãã
çœããã³ã¹ã 誰ã誰ïŒ

Leicht versprochenãleicht gebrochenã
éåžžã«è«ççã§éåžžã«ã¿ã€ã ãªãŒã«ïŒèšäºã®çµãããŸã§ã«ïŒïŒè³ªåãããã¯ãã¹ãŠäžäœäœãããã®ã§ããïŒãããã¯ãã¹ãŠãHTTPãµãŒããŒå¿çã®1è¡ã®ããã ãã ãšçããŸãïŒ
èèã®æšœ
次ã®ããã«ãWebãµãŒããŒã«ãã£ãŠèªåçã«éä¿¡ãããæ£ããREMOTE_USERïŒãŸãã¯HTTP_REMOTE_USER-é¢ä¿ãããŸããïŒãå¿ èŠã§ãã
- ãã¡ã€ã³ã¢ã«ãŠã³ãã§Windowsã«æ£åžžã«ãã°ã€ã³ãããŠãŒã¶ãŒã
- MSADã®ãã¹ãŠã®ãã§ãã¯ã«åæ Œããã
- ãã®åŸãWebãã©ãŠã¶ã䜿çšããŠãã€ã³ã¿ãŒã·ã¹ãã ãºè£œåã®1ã€ã§éçºãããã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããŸããã
- ãã¡ã€ã³ã«å«ãŸããŠããLinuxãµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠãã
- å¿ èŠãªã¢ãžã¥ãŒã«ãåããApache WebãµãŒããŒãã€ã³ã¹ããŒã«ããã³æ§æãããŠããå Žæ
- ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®ãã¡ã€ã³åïŒsAMAccountNameïŒãè¿ããŸããã
ãããŠãæã ã¯ãããåŸãïŒ
ãã®åŸããµãŒããŒåŽã§ãADãžã®LDAPã¢ã¯ã»ã¹ãªã©ã䜿çšããŠããã®ãŠãŒã¶ãŒã®ä»ã®è©³çŽ°ïŒã°ã«ãŒãã¡ã³ããŒã·ãããªã©ïŒãç°¡åã«èŠæ±ã§ããŸãã
ãã®ã¡ã«ããºã ã«ã€ããŠã¯å¥ã®èšäºãèšç»ãããŠãããç¬èªã®åŸ®åŠãªç¹ããããŸãã
ã¹ããŒã³2æ¯ã®ã¿ãŒã«
- ãããŸã§ã®ãšãããMSã®ãã©ãŠã¶ïŒIEãEdgeïŒã®ã¿ãNTLMã§ãã€ãã£ãã«åäœããŸãïŒNTMLã䜿çšããŠããŸãïŒã ãã ããFireFoxãšChromeã®äž¡æ¹ã«ã«ã¹ã¿ãã€ãºã®ãªãã·ã§ã³ããããããã«ãäŒæ¥ç°å¢ã§ã¯ãã°ã«ãŒãããªã·ãŒã䜿çšããéäžèšå®ãšäºåèšå®æžã¿ããã±ãŒãžã®é åžã®äž¡æ¹ãå¯èœã§ãã
- InterSystemsCachéåŽã§åä¿¡ããREMOTE_USERã®åŠçã誰ããããã«ç解ã§ããããã§ã¯ãããŸããã ãã®ããŒãã«ã€ããŠã¯ãŸã å šäŒäžèŽã®æèŠã¯ãããŸãããã ïŒ session.LoginïŒïŒãžã®åŸç¶ã®åŒã³åºãã§ãã¹ãŠã®ãŠãŒã¶ãŒã1ã€ã®ã¹ãŒããŒã·ãŒã¯ã¬ãããã¹ã¯ãŒãã«èšå®ãããŠãŒã¶ãŒããŒã«ã»ãã¥ãªãã£ã¢ãã«ãäœæããããšããå§ããŠãå€ãã®ç°ãªããªãã·ã§ã³ããããŸãã è°è«ã®ãããã¯ããããŸãïŒ
ã·ã³ã°ã«ãµã€ã³ãªã³ã åºå
ã³ã¡ã³ãã§ãã£ãšæåããèšå®ãæããŠãããããšãŠãæè¬ããŠããŸãã Linux + Apache + MSADãã³ãã«ã«æ°ããAAAã€ã³ã¿ã©ã¯ã·ã§ã³ã¡ã«ããºã ãç»å ŽããããšãèªããŠããŸãããããã«ã€ããŠã¯ç¥ããŸããã
ãããããé¡ãããŸãïŒ