ããµãã¥ãŒã»ããå·¥ç§å€§åŠã è¬çŸ©ã³ãŒã¹6.858ã ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã ãã³ã©ã€ã»ãŒã«ããŽã£ããããžã§ãŒã ãºã»ãã±ã³ãºã 2014幎
ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã»ãã¥ãªãã£ã¯ãå®å šãªã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®éçºãšå®è£ ã«é¢ããã³ãŒã¹ã§ãã è¬çŸ©ã§ã¯ãè åšã¢ãã«ãã»ãã¥ãªãã£ãå±éºã«ãããæ»æãããã³æè¿ã®ç§åŠçç 究ã«åºã¥ããã»ãã¥ãªãã£æè¡ãæ±ããŸãã ãããã¯ã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒOSïŒã»ãã¥ãªãã£ãæ©èœãæ å ±ãããŒç®¡çãèšèªã»ãã¥ãªãã£ããããã¯ãŒã¯ãããã³ã«ãããŒããŠã§ã¢ã»ãã¥ãªãã£ãããã³Webã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãå«ãŸããŸãã
è¬çŸ©1ïŒãã¯ããã«ïŒè åšã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©2ïŒãããã«ãŒæ»æã®å¶åŸ¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©3ïŒããããã¡ãªãŒããŒãããŒïŒãšã¯ã¹ããã€ããšä¿è·ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©4ïŒãç¹æš©ã®å ±æã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©5ïŒãã»ãã¥ãªãã£ã·ã¹ãã ã¯ã©ãããæ¥ãã®ãïŒã ããŒã1 / ããŒã2
è¬çŸ©6ïŒãæ©äŒã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©7ïŒããã€ãã£ãã¯ã©ã€ã¢ã³ããµã³ãããã¯ã¹ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©8ïŒããããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©9ïŒãWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©10ïŒãã·ã³ããªãã¯å®è¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©11ïŒãUr / Webããã°ã©ãã³ã°èšèªã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©12ïŒãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©13ïŒããããã¯ãŒã¯ãããã³ã«ã ããŒã1 / ããŒã2 / ããŒã3
ããã§ãæ¬æ¥ã¯ããããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒãšã¢ããªã±ãŒã·ã§ã³ã®çžäºèªèšŒçšã«èšèšãããæå·çã«å®å šãªãããã³ã«ã§ããKerberosã«ã€ããŠã話ããŸãã ããã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®æ¥ç¶ã確ç«ããåã«ã¯ã©ã€ã¢ã³ããšãµãŒããŒãèªèšŒããããã®ãããã³ã«ã§ãã
æåŸã«ãTCP SYNã·ãŒã±ã³ã¹çªå·ã®ã¿ã䜿çšããŠã»ãã¥ãªãã£ä¿è·ãæ€èšããååã®è¬çŸ©ãšã¯ç°ãªããæåŸã«æå·åã䜿çšããŸãã
ããã§ã¯ãKerberosã«ã€ããŠè©±ããŸãããã ãã®ãããã³ã«ããµããŒãããããšããŠããã®ã¯äœã§ããïŒ è€æ°ã®ãµãŒããŒã³ã³ãã¥ãŒã¿ãŒãšè€æ°ã®ã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒã®çžäºäœçšãä¿èšŒããããã«ã25幎ãŸãã¯30幎åã«ç 究æã§Athenaãããžã§ã¯ãã®äžéšãšããŠäœæãããŸããã
ã©ããã«ãã¡ã€ã«ãµãŒããŒããããšæ³åããŠãã ããã ãããããããã¯ãããã¯ãŒã¯ã«æ¥ç¶ãããã¡ãŒã«ãµãŒããŒããŸãã¯ããªã³ã¿ãŒãªã©ã®ä»ã®ãããã¯ãŒã¯ãµãŒãã¹ã§ãã ãããŠããããã¯ãã¹ãŠåã«1ã€ã®ã³ã³ãã¥ãŒã¿ãŒäžã®ããã»ã¹ã§ã¯ãªããäœããã®ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããŸãã
AthenaãšKerberosãäœæããããã®åææ¡ä»¶ã¯ãåæå ±æã®ããã®ãã·ã³ãããããã¹ãŠãåå¥ã®ããã»ã¹ã§ããã誰ããåãã·ã¹ãã ã«ãã°ã€ã³ããŠããã«ãã¡ã€ã«ãä¿åã§ããããšã§ãã ãã®ãããéçºè ã¯ãã䟿å©ãªåæ£ã·ã¹ãã ãäœæããããšèããŠããŸããã
ãããã£ãŠãããã¯ãäžæ¹ã®åŽã«ãããã®ãµãŒããŒãé 眮ããä»æ¹ã®åŽã«ãŠãŒã¶ââãŒãèªåèªèº«ã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ãå®è¡ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã®æãé 眮ããããšãæå³ããŸããã ãããã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ãããã®ãµãŒããŒã«æ¥ç¶ãããŠãŒã¶ãŒãã¡ã€ã«ãä¿åããããã¡ãŒã«ãåä¿¡ãããããŸãã
圌ãã解決ãããã£ãåé¡ã¯ããããã¯ãŒã¯ãä¿¡é ŒããŠãã®æ£åœæ§ãæ€èšŒããããšãªãããµãŒããŒåŽã®ããããã¹ãŠã®ç°ãªãã³ã³ãã¥ãŒã¿ãŒã§ãããã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã䜿çšãããŠãŒã¶ãŒãèªèšŒããæ¹æ³ã§ããã ããã¯ããããç¹ã§åççãªèšèšèŠä»¶ã§ããã åœæãKerberosã®ä»£æ¿æ段ã¯ãååã®è¬çŸ©ã§èª¬æããRãã°ã€ã³ããŒã ã§ãããããŠãŒã¶ãŒã®èªèšŒã«IPã¢ãã¬ã¹ã䜿çšããã ããªã®ã§ãæªãèšç»ã®ããã«æããŸããã
Kerberosã¯éåžžã«æåããŠãããå®éã«ã¯ãŸã MITãããã¯ãŒã¯ã§äœ¿çšãããŠãããMicrosoftã®Active DirectoryãµãŒããŒã®ããã¯ããŒã³ã§ãã ã»ãŒãã¹ãŠã®Microsoft Windows ServerããŒã¹ã®è£œåã¯ãäœããã®åœ¢ã§Kerberosã䜿çšããŠããŸãã
ãã ãããã®ãããã³ã«ã¯25幎ãŸãã¯30幎åã«éçºããããã以æ¥ãã»ãã¥ãªãã£ã«ã€ããŠã®ç解ãæ·±ãŸã£ãŠãããããå€æŽãå¿ èŠã«ãªããŸããã ãããã£ãŠãKerberosã®çŸåšã®ããŒãžã§ã³ã¯ããã®è¬çŸ©ã®è³æã«èšèŒãããŠããããŒãžã§ã³ãšå€ãã®ç¹ã§èããç°ãªããŸãã ä»æ¥ãã©ã®ä»®å®ãååã§ã¯ãªããæåã®ããŒãžã§ã³ã§äœãééã£ãŠããã®ããæ€èšããŸãã ããã¯ãæ¬æ Œçãªã·ã¹ãã ã§ãããã¯ãŒã¯åå è ãèªèšŒããããã«å®éã«æå·åã䜿çšããæåã®ãããã³ã«ã§ã¯é¿ããããŸããã
ãããã«ãããããŒãã«æãããŠããå³ã¯ãKerberosãäœæããããã®äžçš®ã®ã€ã³ã¹ããŒã«ã§ãã ä¿¡é Œã®ã¢ãã«ãäœã§ããããç¥ãããšã¯èå³æ·±ãã§ãã ãããã£ãŠãè¿œå ã®æ§é ãã¹ããŒã ã«å°å ¥ãããŸã-KerberosãµãŒããŒãããã«æšªã«ãããŸãã
ãããã£ãŠã3çªç®ã®ã¢ãã«ã¯ãååã®è¬çŸ©ã§è¿°ã¹ãããã«ããããã¯ãŒã¯ã®ä¿¡é Œæ§ãäœããšããäºå®ã«åºã¥ããŠããŸãã ãã®Kerberosã¹ããŒã ã§èª°ãä¿¡é Œãã¹ãã§ããïŒ ãã¡ããããã¹ãŠã®ãããã¯ãŒã¯åå è ã¯KerberosãµãŒããŒãä¿¡é Œããå¿ èŠããããŸãã ãããã£ãŠãã·ã¹ãã ã®äœæè ã¯ãäžæçã«KerberosãµãŒããŒãäœããã®åœ¢ã§ã®ãããã¯ãŒã¯èªèšŒã®ãã¹ãŠã®ãã§ãã¯ãæ åœããããšãææ¡ããŸããã ãã®ãããã¯ãŒã¯ã«ã¯ãä»ã«ä¿¡é Œã§ãããã®ããããŸããïŒ
åŠçïŒãŠãŒã¶ãŒã¯èªåã®ãã·ã³ãä¿¡é Œã§ããŸãã
ææïŒã¯ããããã¯è¯ãè°è«ã§ãã ããã«ã¯ç§ãæããŠããªããŠãŒã¶ãŒãããŸãã ãããããããã®äººã¯ããçš®ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã䜿çšããŠãããå®éãKerberosã§ã¯ãŠãŒã¶ãŒãèªåã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãä¿¡é Œããããšãéåžžã«éèŠã§ãã ã¯ãŒã¯ã¹ããŒã·ã§ã³ãä¿¡é Œããªããšã©ããªããŸããïŒ ãŠãŒã¶ãŒãã¯ãŒã¯ã¹ããŒã·ã§ã³ãä¿¡é ŒããŠããªãå Žåã¯ããã¹ã¯ãŒãããçèŽãããŠãããªãã«ä»£ãã£ãŠè¡åã§ããããã§ãã
åŠçïŒæ»æè ã¯ãããšãã°ãKerberosãµãŒããŒãžã®ãã±ãããåŠç¿ããããšã«ãããããã«å€ãã®ããšãã§ããŸãã
ææïŒã¯ããæ£ç¢ºã«ã ãã°ã€ã³ãããšããã¹ã¯ãŒããå ¥åããŸãããããã¯ãã±ãããããããã«ã²ã©ããã®ã§ãã ãã®ãããå®éã«ã¯ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãä¿¡é Œããªãå ŽåãKerberosã«å°ããªåé¡ããããŸãã èªåã®ã©ãããããã䜿çšããå Žåãããã»ã©æãããã§ã¯ãããŸããããå ¬å ±ã®ã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ã¯çãããã§ãã ãã®å Žåãæ£ç¢ºã«äœãããŸããããªãããæ€èšããŸãã
åŠçïŒãµãŒããŒç®¡çè ãä¿¡é Œããäºãã®ãµãŒããŒãžã®ç¹æš©ã¢ã¯ã»ã¹ãã§ããããšã確èªããå¿ èŠããããŸãã
ææïŒãã·ã³èªäœã¯çžäºã«ä¿¡é Œããå¿ èŠã¯ãªããšæããŸããããšãã°ãã¡ãŒã«ãµãŒããŒã¯ããªã³ããµãŒããŒããã¡ã€ã«ãµãŒããŒãä¿¡é Œããå¿ èŠã¯ãããŸããã
åŠçïŒä¿¡é Œããªãã§ãã ããããã ããå¥ã®ãµãŒããŒãä»ããã¢ã¯ã»ã¹ããµããŒããããŠããªããµãŒããŒã«ã¢ã¯ã»ã¹ããããšã¯ã§ããŸãã
ææïŒã¯ããããã§ãã ã¡ãŒã«ãµãŒããŒãšããªã³ããµãŒããŒã®éã«ä¿¡é Œé¢ä¿ã確ç«ãããã䟿å®ã®ããã«ã¡ãŒã«ãµãŒããŒã«ãã¡ã€ã«ãµãŒããŒäžã®ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããã ãã§ããã°ãããã¯æªçšãããå¯èœæ§ããããŸãã ãããã£ãŠãããã§è¿œå ã®ã¬ãã«ã®ä¿¡é ŒãŸãã¯åé·ãªä¿¡é Œãå°å ¥ããããšã«æ³šæããå¿ èŠããããŸãã
ããã§ä»ã«éèŠãªããšã¯äœã§ããïŒ ãµãŒããŒã¯äœããã®åœ¢ã§ãŠãŒã¶ãŒãŸãã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ãä¿¡é Œããå¿ èŠããããŸããïŒ ããã§ã¯ãªããšæããŸãã Kerberosã®ã°ããŒãã«ãªç®æšã¯ããããã®ãŠãŒã¶ãŒãæ£åœãªãŠãŒã¶ãŒã§ãããããŒã¿ãŸãã¯äœãã«ã¢ã¯ã»ã¹ããå¿ èŠãããããšãæå·ã§èšŒæã§ããããã«ãªããŸã§ããµãŒããŒãããããã¹ãŠã®ãŠãŒã¶ãŒãŸãã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ãäºåã«ç¥ãããšããŸãã¯ããããèªèšŒããæ¹æ³ãç¥ãããšã§ã¯ãªãããšã§ãããµãŒããŒã管çãã以äžã®ãã®ã
Kerberosã®ä»çµã¿ãšäžè¬çãªã¢ãŒããã¯ãã£ãèŠãŠã¿ãŸãããã KerberosãµãŒããŒããã倧èŠæš¡ã«æããŠã¿ãŸãããã çŸåšã§ã¯ãKDC-Key Distribution CenterããŸãã¯Key Providing CenterãšåŒã°ããŠããŸãã ã©ããã«æ¥ç¶ã§ãããŠãŒã¶ãŒãšãµãŒãã¹ããããŸãã èšç»ã§ã¯ãKerberosãµãŒããŒã¯ãKerberosãµãŒããŒãšãã®åšå²ã®äžçã®åã³ã³ãã¥ãŒã¿ãŒãšã³ãã£ãã£ãšã®éã®éä¿¡çšã®å ±æããŒã®æ ŒçŽãæ åœããŸãã ãããã£ãŠããŠãŒã¶ãŒãäœããã®çš®é¡ã®ã¯ã©ã€ã¢ã³ãããŒKcãæã£ãŠããå ŽåãKerberosãµãŒããŒã¯ãã®ããŒãèšæ¶ããèªèº«ã®å éšã®ã©ããã«ä¿åããŸãã åæ§ã«ããµãŒãã¹ã®KsããŒã¯ããã®ãµãŒãã¹èªäœãKerberosãµãŒããŒã®ã¿ã«ç¥ãããŠãããä»ã®èª°ã«ãç¥ãããŠããŸããã ãããã£ãŠããã¹ã¯ãŒããç¥ã£ãŠããŠãKerberosããããç¥ã£ãŠããããä»ã®èª°ããããç¥ããªãå Žåããã¹ã¯ãŒãã®äžè¬çãªäœ¿çšãšèããããšãã§ããŸãã
ããã¯ããªãããäºãã«ãç§ã¯ãã®åãç·ã ãããšã蚌æããæ¹æ³ã§ãã ãã¡ãããKerberosãµãŒããŒã¯ãã®ããŒã®ææè ã远跡ããå¿ èŠãããããããŠãŒã¶ãŒåãšãµãŒãã¹åãããšãã°serv afsïŒããã¯ãã¡ã€ã«ãµãŒããŒã§ãïŒãããã³ãããã«å¯Ÿå¿ããããŒãæ ŒçŽãããããŒãã«ãå¿ èŠã§ãã
åæã«ãKDCã¯ãKerberosãµãŒããŒãèªèããå¿ èŠãããMITãããã¯ãŒã¯ã«ååšããã³ã³ãã¥ãŒã¿ãŒãšã³ãã£ãã£ãèæ ®ã«å ¥ããããããã€ãæ°ã®ç¹ã§ã¯ããŸã倧ãããªãããã¬ã³ãŒãæ°ãéåžžã«å€ã巚倧ãªããŒãã«ãæ ŒçŽãã責任ããããŸãã ãããã£ãŠã2çš®é¡ã®ã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã
è¬çŸ©è³æã§ã¯ããã®ããšã«ã€ããŠååã«æ確ã«è©±ãããŠããŸãããã€ãŸããããã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®ååšã¯åã«æ瀺ãããŠããŸãã å®éã1å°ã®ãã·ã³ã«ã¯å®éã«2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã ãããã®1ã€ã¯KerberosãšåŒã°ãã2ã€ç®ã¯TGSãTicket Granting ServiceããŸãã¯Ticket Serviceã§ãã
å®éãçµå±ã®ãšããããããã¯åãããšã話ã2ã€ã®æ¹æ³ã«ãããããããã³ã«ã¯ããã2ã€ã®ããšã§ãããã«ç°ãªãã ãã§ãã ãããã£ãŠãæåã«ããŠãŒã¶ãŒããã°ã€ã³ãããšããŠãŒã¶ãŒã¯äžäœã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ããKerberosãšã話ãããã¯ã©ã€ã¢ã³ãåCãéä¿¡ããŸããããã¯Athena倧åŠã®ãããã¯ãŒã¯äžã®ãŠãŒã¶ãŒåã§ããå¯èœæ§ããããŸãã
ãµãŒããŒã¯ãã®ãªã¯ãšã¹ãã«tgsãã±ãããŸãã¯ãã±ããæ å ±ã§å¿çããŸã;ãã®æ å ±ã®è©³çŽ°ã«ã€ããŠã¯åŸã»ã©èª¬æããŸãã 次ã«ããããµãŒãã¹ãšãã£ãããããå ŽåããŸãTGSã€ã³ã¿ãŒãã§ãŒã¹ã«è¡ãããããäŒããå¿ èŠããããŸãïŒããã§ã«Kerberosã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠãã°ã€ã³ããŠããã®ã§ãç¹å®ã®ãµãŒãã¹ãæäŸããSãµãŒããŒãšè©±ããããã
ãã®ãããTGSã«éä¿¡ããããµãŒããŒã«ã€ããŠäŒãããã®åŸããµãŒããŒSãšéä¿¡ããããã®ãã±ããã®ãããªãã®ãè¿ããŸãããã®åŸããµãŒããŒSã®åä¿¡ãã±ããã䜿çšããŠãå¿ èŠãªãµãŒããŒãšæçµçã«éä¿¡ã§ããŸãã
ããã¯äžçš®ã®é«ã¬ãã«ã®èšç»ã§ãã ã§ã¯ããªã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãããã§äœ¿çšãããã®ã§ããããïŒ ããã«ã€ããŠå€ãã®è³ªåãããããšãã§ããŸãã KsãµãŒããŒã®å Žåããã®ãµãŒãã¹ã¯ãããããã£ã¹ã¯ã«ä¿åãããŸãã ãããŠããŠãŒã¶ãŒåŽã®ãã®Kcã¯ã©ããªããŸããïŒ ãã®Kcã¯Kerberosã®ã©ãããæ¥ãã®ã§ããïŒ
åŠçïŒãã®Kcã¯ãããŒã¿ããŒã¹ã®KDCãµãŒããŒããŒãã«ã«ããå¿ èŠããããŸãã
ææïŒã¯ããããã§ããCããŒã¯ãã®å·šå€§ãªããŒã¿ããŒã¹ã®è¡šã«ãããŸãã ãã ãããŠãŒã¶ãŒã¯èªåããŠãŒã¶ãŒã§ããããšã蚌æããå¿ èŠãããããããŠãŒã¶ãŒã«ãç¥ãããŠããå¿ èŠããããŸãã
åŠçïŒãã¹ã¯ãŒããå¿ èŠãªäžæ¹åã®æ©èœã§ããïŒ
ææïŒã¯ãã圌ãã¯å®éã«ãã®ãããªã¹ããŒããã©ã³ãæã£ãŠããŸããKcã¯ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããŸãã¯ããçš®ã®ããŒçæé¢æ°ãããã·ã¥ããããšã«ãã£ãŠååŸãããŸããããã«ã¯ããã€ãã®ç°ãªãæ¹æ³ããããŸãã ãã ããåºæ¬çã«ã¯ãã¹ã¯ãŒããååŸããäœããã®æ¹æ³ã§å€æããŠããã®ããŒKcãååŸããŸãã ãããã£ãŠãããã¯è¯ãæ¹æ³ã®ããã§ãã
ãããããªã2ã€ã®ãããã³ã«ãå¿ èŠãªã®ã§ããããïŒ çµå±ãæåã®Kerberosã€ã³ã¿ãŒãã§ãŒã¹ããçŽæ¥ãã±ããããªã¯ãšã¹ãããŠãããã®ååã®ãã±ããã欲ããïŒããšèšã£ãŠã圌ã¯ããªãã«ãã±ãããéãè¿ããKcã䜿ã£ãŠè§£èªã§ãããšæ³åã§ããŸãã
åŠçïŒå¥ã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ãããã³ã«ãŠãŒã¶ãŒã«ãã¹ã¯ãŒããåå ¥åãããããªãã®ã§ããããïŒ
ææïŒç¢ºãã«ã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®éãã®çç±ã¯ãæåã®ã€ã³ã¿ãŒãã§ã€ã¹ãããã¹ãŠã®å¿çãKcããŒã§æå·åãããŠè¿ãããKerberosã®äœæè ããã®Kcãé·æéä¿åããå¯èœæ§ãå¿é ããŠããããã§ãã ãŠãŒã¶ãŒã«æ¯åãã¹ã¯ãŒããå ¥åããããã«èŠæ±ããå¿ èŠããããããã¯åã«ãã£ãšãããã ãã§ãããããªããã°ã圌ã¯åžžã«ã¡ã¢ãªã«ã座ã£ãŠãããããã§ãã åºæ¬çã«ãããã¯ãŠãŒã¶ãŒãã¹ã¯ãŒãã ãã§ååã§ããKcã«ã¢ã¯ã»ã¹ã§ãããŠãŒã¶ãŒã¯ããŠãŒã¶ãŒããã¹ã¯ãŒããå€æŽãããŸã§ããŸãã¯ãã以äžå€æŽãããŸã§ãŠãŒã¶ãŒã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããããã§ãã åŸã§ãã®åé¡ãããã«è©³ããæ€èšããŸãã
ãããã£ãŠããã®KcããŒãæŒããããšã¯éåžžã«å±éºã§ãã ãããã£ãŠãåŸç¶ã®ãã¹ãŠã®èŠæ±ã«æåã®ã€ã³ã¿ãŒãã§ã€ã¹ãš2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããå šäœã®ãã€ã³ãã¯ãKerberosãµãŒããŒTGSã€ã³ã¿ãŒãã§ã€ã¹ããã®å¿çã解èªãããšããã«å®éã«Kcãå¿ããããšãã§ãããšããããšã§ãã ãã以éãããŒãªãŒã¯ãçºçããå Žåã§ããæ©èœã¯åä¿¡ãããã±ããã«äŸåããŸãã ææªã®å Žåã誰ããç¡å¶éã®æéã§ã¯ãªããæ°æéããªãã®ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã ããããåããªãœãŒã¹ãžã®2ã€ã®ã¢ã¯ã»ã¹ãã¹ãæã€ãã®ãããªã¹ããŒã ã®çç±ã§ãã
ãããã£ãŠããããã®ãããã³ã«ãå®éã«ãããã¯ãŒã¯äžã§ã©ã®ããã«èŠãããã®ä»çµã¿ã«å ¥ãåã«ãKerberosåã®åŽé¢ã«ã€ããŠå°ã話ããŸãããã ããæå³ã§ã¯ãKerberosã¯ååã®ã¬ãžã¹ããªãšèŠãªãããšãã§ããŸãã 圌ã¯ããããã®æå·åããŒãå°æåã§è¡šç€ºãã責任ããããŸãã ããã¯ãKerberosãå®è¡ããåºæ¬çãªçš®é¡ã®æäœã§ãã 次ã®è¬çŸ©ã§ã¯ããªãåæ§ã®æ©èœãå¿ èŠãªã®ãã説æããŸãã Kerberosãšã¯ç°ãªãæ¹æ³ã§å®è£ ã§ããŸãããã»ãŒãã¹ãŠã®åæ£ã»ãã¥ãªãã£ã·ã¹ãã ã§åæ§ã®ãã®ã䜿çšããããšãåºæ¬çã«éåžžã«éèŠã§ãã ããã§ã¯ãKerberosãååãã©ã®ããã«æ±ãããèŠãŠã¿ãŸãããã
Kerberosã«ã¯ããããã¯ãŒã¯åå è ã®ããŒã¿ããŒã¹å ã®åã³ã³ãã¥ãŒã¿ãŒãšã³ãã£ãã£ã«å¯Ÿããäžçš®ã®ã·ã¹ãã ã³ãŒã«ãããããã®ããŒã¿ã®äž»ãªåœ¢åŒã¯åãªãæååã§ãã ãã®ãããããšãã°nickolaiã®ãããªåœ¢åŒã§ããã€ãã®åºæ¬çãªååãæã€ããšãã§ããŸãã ããã¯ååã®æååã§ãã
ããã¯Kerberosã®ããé åã®äž»èŠãªãã©ã¡ãŒã¿ãŒã§ããå®éãããã¯KDCããŒãã«ã®å·Šã®åã«ãããã®ã§ãã ãŸãããããã³ã«ããµããŒãããè¿œå ã®ãã©ã¡ãŒã¿ãŒãããã€ããããŸãã ããšãã°ãnickolai.extra secãªã©ã®å¥ã®ååãå ¥åã§ããŸããããã¯ãè¿œå ã®ã»ãã¥ãªãã£ãå¿ èŠãªãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã«ãnickolaiãšããååã«å ããŠäœ¿çšãããŸãã ãããã£ãŠãå€åç§ã¯æ¬åœã«å®å šãªãã®ã®ããã®1ã€ã®ãã¹ã¯ãŒããšç§ã®éåžžã®ã¢ã«ãŠã³ãã®ããã®å¥ã®ãã¹ã¯ãŒããæã£ãŠããŸãã
Kerberosã¯ãã®åŽé¢ã«èšåããŠããŸãã ãããã£ãŠãçåã«æããããããŸãã-圱é¿ã¯ã©ãããæ¥ãŸããïŒ KerberosãµãŒãã¹ã¯ååãç¹å®ã®ããŒã«ãããããŸãããã³ã³ãã¥ãŒã¿ãŒãšè©±ããŠãããšãã«ãã©ã®ååãå°ããã®ãããŸãã¯å¿çãšããŠã©ã®ååãæåŸ ããã®ããã©ã®ããã«ç¥ãã®ã§ããïŒ ã€ãŸããKerberosãµãŒããŒã®å€éšã«è¡šç€ºãããååããŸãã¯ãããã®ãŠãŒã¶ãŒåãæ£ç¢ºã«ã©ãã«è¡šç€ºãããã®ããå°ããŸãã äœãã¢ã€ãã¢ã¯ãããŸããïŒ
åŠçïŒãããããMITãµãŒããŒã«ãŠãŒã¶ãŒåãå°ããããšãã§ããŸãã
ææïŒã¯ãããã¡ããã ããã¯ããããã®ãã®ããªã¹ãããæ¹æ³ã§ãã ããã«ããŠãŒã¶ãŒã¯ãã°ã€ã³æã«å ¥åããã ãã§ãããããã¢ã¯ã»ã¹ã§ããŸãã ãŠãŒã¶ãŒåã¯ä»ã®å Žæã«è¡šç€ºãããŸããïŒ ä»ã®å Žæã«è¡šç€ºããå¿ èŠããããŸããïŒ
åŠçïŒããŸããŸãªãµãŒãã¹ã®ãªã¹ãã«ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã瀺ãããŠããå¯èœæ§ããããŸãã
ææïŒã¯ããããã¯æ¬åœã«éèŠãªãã€ã³ãã§ãããïŒ Kerberosã®ç®æšã¯ãããŒãååã«åçŽã«ãããã³ã°ããããšã§ãã ããããããã¯ãã®ååãäœã«ã¢ã¯ã»ã¹ããã¹ãããæããŠãããŸããã
å®éãã¢ããªã±ãŒã·ã§ã³ãéåžžKerberosã䜿çšããæ¹æ³ã¯ããããã®ãµãŒããŒã®1ã€ãKerberosã䜿çšããŠãéä¿¡ããŠããå°æåã®ååãå€å¥ããããšã§ãã ã¡ãŒã«ãµãŒããŒãäœããã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããæ¥ç¶ãåä¿¡ãããšãKerberosãã±ãããåä¿¡ããŸããããã«ããããã®ãŠãŒã¶ãŒããã³ã©ã€ã§ããããšã蚌æããŸãã ãã®åŸãã¡ãŒã«ãµãŒããŒã¯ããã®ãŠãŒã¶ãŒãã¢ã¯ã»ã¹ã§ãããã®ãå éšã§èŠã€ããŸãã ãã¡ã€ã«ãµãŒããŒãåæ§ã§ãã
ãããã£ãŠãããããã¹ãŠã®ãµãŒããŒã®å éšã«ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ããã°ã«ãŒããªã¹ãããŸãã¯èš±å¯ãå®è¡ãããã®ä»ã®é ç®ããããŸãã ãã®ãããKerberosã¯ãããªãã誰ãšè©±ããŠããã®ãã瀺ãèªèšŒãæäŸããŸãã ãµãŒãã¹èªäœãæ¿èªã®ãã®éšåã®å®è£ ãæ åœãããŠãŒã¶ãŒåã«åºã¥ããŠã¢ã¯ã»ã¹ã®ã¬ãã«ã決å®ããŸãã ããã§ããŠãŒã¶ãŒåã衚瀺ãããå ŽæãèŠã€ããŸããã KerberosããµãŒãã¹ãšå¯Ÿè©±ããããã«ãµããŒãããä»ã®åºæ¬çãªååããããŸãã
è¬çŸ©è³æã«ããã°ããµãŒãã¹ã¯rcmd.hostnameã®ããã«ãªããŸãã ãããã®ãµãŒãã¹ã®1ã€ã«ååãå¿ èŠãªçç±ã¯ãããšãã°ãã¡ã€ã«ãµãŒããŒã«æ¥ç¶ãããšãã«çžäºèªèšŒãå®è¡ããããã§ãã ããã¯ããã®æé ã§ã¯ãå®å ãµãŒããŒãèªåèªèº«ãèŠã€ããã ãã§ãªãããŠãŒã¶ãŒãŸãã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ãèŠã€ããŠãèªåãåœé ããåœã®ãã¡ã€ã«ãµãŒããŒã§ã¯ãªããæ£ãããã¡ã€ã«ãµãŒããŒãšéä¿¡ããŠããããšã確èªããŸããã¡ã€ã«ã ãããããç§ã¯è©äŸ¡ä»ãã®ãã¡ã€ã«ãèŠãŠããããã¬ãžã¹ãã©ã«éä¿¡ãããã®ã§ãã ãããã£ãŠãä»ã®ãã¡ã€ã«ãµãŒããŒãé©åãªãµãŒããŒãšããŠæ©èœããééã£ãè©äŸ¡ãã¡ã€ã«ãæäŸããŠããŸããšãããã¯éåžžã«æªãããšã§ãã
ãããã£ãŠããµãŒãã¹ã«ãç¬èªã®ååãå¿ èŠã§ãããã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ããµãŒãã¹ã«æ¥ç¶ãããšãã«è¡šç€ºãããååãææ¡ããå¿ èŠããããŸãã
ååãšããŠãããã¬ãã«ã§ã¯ãããã¯ãŠãŒã¶ãŒããã®ãã®ã§ãã ãããã£ãŠãããšãã°ãssh.fooãšå ¥åãããšãrcmd.fooãªã©ã®Kerberosã¡ã€ã³åããã®æ¥ç¶ã®ããäžæ¹ã®ç«¯ã«è¡šç€ºãããããšãæåŸ ããå¿ èŠããããŸãã ãããŠãä»ã®èª°ããããã«ããå ŽåãSSHã¯ã©ã€ã¢ã³ãã¯åæãããæ¥ç¶ãããªãããã«ããªããã°ãªããŸããã
ããã¯1ã€ã®èå³æ·±ã質åãæèµ·ããŸãã Kerberosã§ååãåå©çšã§ããã®ã¯ãã€ã§ããïŒ ããšãã°ããã¹ãŠã®äººãã¢ããã€ã³ã¹ãã£ãã¥ãŒãã·ã¹ãã ã«ã¢ã«ãŠã³ããæã£ãŠããŸãã åæ¥ãããšãMITã¯ããŒã¿ããŒã¹ãšã³ããªãç Žæ£ããä»ã®ãŠãŒã¶ãŒãåããŠãŒã¶ãŒåãç»é²ã§ããããã«ããŸããïŒ ããã¯è¯ãã¢ã€ãã¢ã§ããããïŒ
åŠçïŒ KerberosããŒã¿ããŒã¹ã ãã§ãªãããµãŒãã¹ã«ããŠãŒã¶ãŒåã®ãªã¹ãããããŸããïŒ
ææïŒã¯ãããããã®ååã¯å®éã«ã¯ãã¡ã€ã«ãŸãã¯ã¡ãŒã«ãµãŒããŒäžã®ACLã®ã©ããã«ããæååãšã³ããªã«ãã£ãŠè¡šãããŠããã ãã§ãã KerberosãµãŒããŒããŒã¿ããŒã¹ã®ãšã³ããªãæ¶å»ããŠãããšã³ããªãå®å šã«æ¶ããããã§ã¯ãããŸããã ãããã®ãšã³ããªã¯ããŒãžã§ã³ã«äŸåããŸããã
ããšãã°ãããèšé²ã«ã¯ãã¢ãªã¹ãã¢ããã®ããã«ãŒã«ã¢ã¯ã»ã¹ã§ãããšæžãããŠããŸãã ãã®åŸãã¢ãªã¹ã¯åæ¥ãã圌女ã®èšé²ã¯åé€ãããŸãããäžéšã®æ°ããã¢ãªã¹ã¯ç 究æã«å ¥ããKerberosããŒã¿ããŒã¹ã§ã®ç»é²ããã»ã¹ãè¡ãããŸãã , , .
, Kerberos , Kerberos . , , , .
. , , , , , . , , , - . , . , , .
, . , , , TGS.
, , Kerberos, «». : s , IP â addr, time stump, life, , , Kc,s, . .
.
, Kerberos «». Ac , IP- , , . , . K,s, , Kerberos Ks. , .
, , Kerberos TGS. , , Kerberos, , . : C, , S, TGS. .
Tc,s, Ks, , Ks, , Kc. .
. , Kerberos ? , ?
: , , , Kc.
: , , Kerberos , . : «, , . , , , Kc». , .
, , , Kerberos, Kerberos , . , , - Kerberos, , .
: âŠ
: , , Kerberos, ? , ? , , , , , , , , , .
«», , , , , . , , . . Kerberos, , . , , .
: ? , âŠ
: , . , Kerberos , . , , - , , , . 30 , .
Kerberos 5 : , â . , , , , .
Kerberos 4 , , , . , . , , .
, , , . , . â K,s - ? K,s T,s. K,s?
27:10
MITã³ãŒã¹ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã 13: « », 2
ã³ãŒã¹ã®å®å šçã¯ãã¡ãããå ¥æã§ããŸã ã
ãæ»åšããã ãããããšãããããŸãã ? ããèå³æ·±ãè³æãèŠããã§ããïŒ , 30% entry-level , : VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps $20 ? ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§ 6ãæã®æéãæ¯æãå Žåã¯12æãŸã§ç¡æ㧠ã ããã§æ³šæã§ããŸã ã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšç±³åœã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯æ¹æ³ã«ã€ããŠèªã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ