ããµãã¥ãŒã»ããå·¥ç§å€§åŠã è¬çŸ©ã³ãŒã¹6.858ã ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã ãã³ã©ã€ã»ãŒã«ããŽã£ããããžã§ãŒã ãºã»ãã±ã³ãºã 2014幎
ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã»ãã¥ãªãã£ã¯ãå®å šãªã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®éçºãšå®è£ ã«é¢ããã³ãŒã¹ã§ãã è¬çŸ©ã§ã¯ãè åšã¢ãã«ãã»ãã¥ãªãã£ãå±éºã«ãããæ»æãããã³æè¿ã®ç§åŠçç 究ã«åºã¥ããã»ãã¥ãªãã£æè¡ãæ±ããŸãã ãããã¯ã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒOSïŒã»ãã¥ãªãã£ãæ©èœãæ å ±ãããŒç®¡çãèšèªã»ãã¥ãªãã£ããããã¯ãŒã¯ãããã³ã«ãããŒããŠã§ã¢ã»ãã¥ãªãã£ãããã³Webã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãå«ãŸããŸãã
è¬çŸ©1ïŒãã¯ããã«ïŒè åšã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©2ïŒãããã«ãŒæ»æã®å¶åŸ¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©3ïŒããããã¡ãªãŒããŒãããŒïŒãšã¯ã¹ããã€ããšä¿è·ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©4ïŒãç¹æš©ã®å ±æã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©5ïŒãã»ãã¥ãªãã£ã·ã¹ãã ã¯ã©ãããæ¥ãã®ãïŒã ããŒã1 / ããŒã2
è¬çŸ©6ïŒãæ©äŒã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©7ïŒããã€ãã£ãã¯ã©ã€ã¢ã³ããµã³ãããã¯ã¹ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©8ïŒããããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©9ïŒãWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©10ïŒãã·ã³ããªãã¯å®è¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©11ïŒãUr / Webããã°ã©ãã³ã°èšèªã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©12ïŒãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©13ïŒããããã¯ãŒã¯ãããã³ã«ã ããŒã1 / ããŒã2 / ããŒã3
åŠçïŒãµãŒãã¹ããŒã䜿çšããŠæå·åãããŠãããããã¯ã©ã€ã¢ã³ãã¯ãã®ãã±ããã解èªã§ããŸããã
ææïŒã¯ããããã¯æ¬åœã«è³¢ãã§ããã ã¯ã©ã€ã¢ã³ããåä¿¡ã§ããããŒKcãsããããŸããããã±ããTcãsã«ã¯ãKsã§æå·åããããã®ããŒã®å¥ã®ã³ããŒããããŸãã
ãããè¡ãããçç±ã¯ãKerberosãµãŒããŒãå®éã«ä»ã®äººãšã®ã¯ã©ã€ã¢ã³ãã®éä¿¡ãä¿è·ããããšããŠããããã§ãã ãããã£ãŠãKerberosã¯ã©ã³ãã ããŒKcãsãäœæãã1ã€ã®ã³ããŒãã¯ã©ã€ã¢ã³ãã«æäŸããå¥ã®ã³ããŒãã¯ã©ã€ã¢ã³ããéä¿¡ãããµãŒããŒã«æäŸããŸãã KerberosããããããµãŒãã¹ããã®ç·ã¯ããªããšè©±ããããããããéµã ïŒããšããèšèã§ãµãŒãã¹ãåŒã³åºãã ãã ãšæ³åããŠãã ããã ããã¯ãKerberosãµãŒããŒããã¹ãŠã®èŠæ±ã§ãµãŒãã¹ã«äœåºŠãã¢ã¯ã»ã¹ãããããæ®å¿µã§ãã ãã®ãããKDSã¯ã»ãã·ã§ã³ããŒã®2ã€ã®ã³ããŒãäœæããŸãã1ã€ã¯ã¯ã©ã€ã¢ã³ãçšããã1ã€ã¯TGSçšã§ãã
ãã®ããã代ããã«ãéçºè ã¯ã¯ã©ã€ã¢ã³ãã«ãã®ãã±ãããæäŸããè¯ãããªãã¯ãæãã€ããŸããã圌ã¯é©åãªãµãŒãã¹ã§åœŒã«é£çµ¡ãã以å€åœŒãšã¯äœãã§ããŸããã ãããŠããã®ãµãŒãã¹ãæ£ããKsããŒãæã£ãŠããå Žåãããã解èªããããããããã¯ãã®ã¯ã©ã€ã¢ã³ããšè©±ãããã«äœ¿çšããªããã°ãªããªãããŒãšåãã§ãããšèšããŸãã ãããã£ãŠãæ¥ç¶ã®åå è ã§ããã¯ã©ã€ã¢ã³ããšãµãŒãã¹ã®äž¡æ¹ããæ¥ç¶ãä¿è·ããããã®å ±éããŒã確ç«ããŸãã
åŠçïŒ TGSãšã¯äœã§ããïŒ
ææïŒ TGSãšã¯2ã€ã®èŠè§£ããããŸãã ã¯ã©ã€ã¢ã³ãã®èŠ³ç¹ããèŠããšãããã¯ãã±ãããååŸã§ãããã1ã€ã®ãµãŒãã¹ã§ãã ãã®ãµãŒãã¹ãæäŸããæ©èœãå€ãã»ã©ãæäŸãããã±ãããå€ããªããŸãã ããã¯å®éã«ã¯ãã±ãããµãŒãã¹ã§ãã
åŠçïŒç³ãèš³ãããŸããããTGSãšãããã±ãããããããšãæå³ããŸãã
ææïŒãããã¯ããç³ãèš³ãããŸããããã®å³ã®ç¢å°ã®äžã«ããç¢ætgsã¯ããã©ã¡ãŒã¿ãŒTcãsã®ã€ã³ããã¯ã¹sãé€ããèšé²ãããã¯å šäœã®ç¥ã§ããã€ãŸãããã®ãµãŒãã¹ã®å®éã®ååã¯TGSã§ãã KerberosãµãŒããŒãããããã®TGSãµãŒãã¹ããããå°éãããå®éã®ãµãŒãã¹ãããããšãæ³åã§ããŸãã ãã®ãããæåã«ç¹å®ã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããããã®ãã±ãããæäŸããããã«Kerberosã«äŸé Œããå¿ èŠããããŸãã
ãã¡ã€ã«ãµãŒããŒã«çŽæ¥ãã±ãããæž¡ãããã«Kerberosã«äŸé Œããããšãã§ããŸãããããã¯æ©èœããå¯èœæ§ããããŸãã ãã ãããã®ããã«ã¯ã埩å·åã®ãããšããµãŒããŒã䜿çšããæ®ãã®æéã«Kcãå¿ èŠã«ãªããŸãã 代ããã«ãç¹å¥ãªTGSãµãŒãã¹ã®ãã±ãããååŸããŸãã å¥ã®ããã¯ã¹ã«é 眮ãããããšãé€ããŠãä»ã®ãµãŒãã¹ãšåãããã«èŠããŸãã ãŸããå ã®Kcã«ã¹ã¿ããŒããŒãåæäŸããã«ãåŸã§ããå€ãã®ãã±ããããæž¡ãããŸãã
åŠçïŒã€ãŸãã圌ã®èãã¯ãTGSãã±ãââããåãåã£ããããã«KcããŒãåãé€ãããšãã§ãããšããããšã§ããïŒ
ææïŒã¯ããããã«ã€ããŠã®çŽ æŽãããããšã¯ãTGSãµãŒãã¹ãããã®ãã±ããTcãåãåããšããã«ããã¹ã¯ãŒããšããŒKcãåãé€ãããšã§ãã ãããã£ãŠãAthenaã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãã°ã€ã³ããæ°ç§åŸã«ãã±ããTãsãåãåããšããã«ããã¹ã¯ãŒããã¡ã¢ãªããåé€ãããŸãã ã ãã誰ããããªããã€ããã§ãã³ã³ãã¥ãŒã¿ãŒãéžæããŠåœŒãšéãããšããŠãã圌ãæã£ãŠããã®ã¯ããªãã®ãã±ããã ãã§ãã ãã¹ã¯ãŒããä¿åãããŠãããã次ã«Athenaãå ¥åãããšãã«ååºŠå ¥åããå¿ èŠãããããã圌ã10æéãŸãã¯ãã±ããã®æéäžã«ããªãã®æ å ±ã«ã¢ã¯ã»ã¹ã§ããã°è¯ãã®ã§ããããã以äžã¯ã§ããŸããã
ãã¹ã¯ãŒããå¿ èŠãªã®ã¯ãKerberosãµãŒããŒã«èŠæ±ãéä¿¡ãããšãã ãã§ãããã±ããã§ãã®å¿çãåãåããããã解èªããŸãã ãã®åŸããã¹ã¯ãŒããå¿ããããšãã§ããŸãã ãã ãããã¡ããããã¹ã¯ãŒãã䜿çšããŠæå·åã解é€ããããšã¯ã§ããŸããã
ãããã£ãŠããã®ã¹ããŒã ã®æåã®äžäœã€ã³ã¿ãŒãã§ã€ã¹Cã¯åæããŒKcã§ãã±ãããååŸããããã«äœ¿çšããã2çªç®ã®äžäœã€ã³ã¿ãŒãã§ã€ã¹Sã¯ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããããã«äœ¿çšãããŸãããåæããŒKcãååŸããå¿ èŠã¯ãããŸããã
ãã®ãããKerberosãããã³ã«ã®2ã€ã®ç¹å®ã®åé¡ã«ã€ããŠæ¢ã«èª¬æããŸããããããã®åé¡ã¯ãããèªäœã«çµã¿èŸŒãŸããŠãããããäžäŸ¿ã§ãã æåã«ãäœæè ã¯æå·åã«ãã£ãŠèªèšŒãŸãã¯ã¡ãã»ãŒãžã®æŽåæ§ãæäŸããããšæ³å®ããŠããŸããããããã¯èµ·ãããŸããã§ããã ãã®æ¬ é¥ã¯ãæ瀺çãªã¡ãã»ãŒãžèªèšŒãå®è¡ãããKerberosããŒãžã§ã³5ã§ä¿®æ£ãããŸããã 第äºã«ãä»»æã®ã¯ã©ã€ã¢ã³ãã®å Žåãä»ã®äººã®ãã¹ã¯ãŒããæšæž¬ããæ©äŒããããŸããã
ããã¯ã©ã®ããã«ä¿®æ£ã§ããŸããïŒ ãã®çš®ã®ãããã³ã«ã§ãã¹ã¯ãŒããæšæž¬ããŠæ»æãé²ãæ¹æ³ã¯ïŒ ç§ãã¡ã¯äœãè©Šãããšãã§ããŸããïŒ
åŠçïŒããããããŸãããããã¹ã¯ãŒããããœã«ããããŠã¿ãŠãã ããã
ææïŒ ã塩挬ãããšã¯ãåã«ã¯ã©ã€ã¢ã³ããããŸããŸãªæ¹æ³ã§ãã¹ã¯ãŒããããã·ã¥ããå¿ èŠãããããšãæå³ããŸãã ããããããã¯ãããæŸãããšããŠã害ã¯ãããŸããã ãã®ãããèŸæžãäœæããæ¹ãè²»çšããããå ŽåããããŸãã
åŠçïŒãã¹ã¯ãŒããèšç®ããæ©èœãè€éã«ããããšãã§ããŸãã
ææïŒã¯ããå¥ã®è¯ãã¢ã€ãã¢ã¯ããã·ã¥ããã»ã¹ãéåžžã«é«äŸ¡ã«ããããšã§ãã ããããããã¯åççã§ãã ãããã£ãŠã2çªç®ã®ã©ãã§è¡ã£ãããã«ããã®ããã·ã¥é¢æ°ã«2ç§ã®èšç®æéããããå Žåããã®å Žåããã¹ã¯ãŒãã®éžæã¯éåžžã«é«äŸ¡ãªã¿ã¹ã¯ã«ãªããŸãã ãããã£ãŠãããã¯åççãªèšç»ã®ããã«æããŸã-ã塩挬ãããšæšæž¬ããã»ã¹ã®è€éåã®çµã¿åããã䜿çšããããšã
çããè€éã«ããããšã¯å¥ã®é²åŸ¡çãããããŸããã ãããã³ã«ã®æåã®ããŒãžã§ã³ã§ã¯ãKerberosãµãŒããŒã¯æ£ããã¯ã©ã€ã¢ã³ãããããã³ã«ã«ã¢ã¯ã»ã¹ããŠãããã©ãããç¥ããªãã£ããšèããŸããã ã§ããããšã¯ãããªããæ£ããã¯ã©ã€ã¢ã³ãã§ãããšãã蚌æ ãæäŸããããšã§ããã€ãŸããçŸåšã®ã¿ã€ã ã¹ã¿ã³ãããã¹ã¯ãŒãããã·ã¥ãªã©ã§æå·åããŸãã 次ã«ãKerberosãµãŒããŒã¯ãããã®ãã®ã®åŠ¥åœæ§ããã§ãã¯ããäžèŽããå Žåã¯ãã±ãããæäŸããŸãã
ãããããããã«ãã¹ãã¹ããããè¿œå ããå¿ èŠã¯ãªãã§ãããããããã§ããŸããããããããŸããã ä»ã®ãšãããã¿ã€ã ã¹ã¿ã³ããååŸããŠããŒKcãšäžç·ã«ããã·ã¥ããã¿ã€ã ã¹ã¿ã³ããè¿œå ããã ãã§ãããšä»®å®ããŸãã
ãã®å ŽåããµãŒããŒã¯KcããŒãæã£ãŠããããšã確èªã§ããçŸåšã®ã¿ã€ã ã¹ã¿ã³ããããã·ã¥ããããšãã§ããŸãã åãå€ãåãåã£ãå Žåããªã¯ãšã¹ãã¯ãããããã±ãããéä¿¡ã§ããæ£ãããŠãŒã¶ãŒã«ãã£ãŠè¡ãããŸãã ããã§ãªãå Žåã¯ãééã£ããã¹ã¯ãŒãã§ããã
åŠçïŒãµãŒããŒãæäŸãããªã¯ãšã¹ããå€ãããå Žåããã±ããã®çºè¡ãå¶éã§ããŸãã
ææïŒãŸã£ãããã®éãã§ããå¶éãå°å ¥ã§ããŸãã ãã ããããã«ãŒããµãŒããŒäžã®ãã±ãããè€æ°åèŠæ±ããçç±ã¯ãããŸããã 圌ã¯åã«ç¹å®ã®ãŠãŒã¶ãŒãèŠæ±ãããã®æå·åããããããã¯ã圌ããåãåãã2åç®ã®ãªã¯ãšã¹ããªãã§ç°ãªããã¹ã¯ãŒãã䜿çšããŠãå¿ èŠãªåæ°ã ããªãã©ã€ã³ã§åŸ©å·åãè©Šã¿ãããšãã§ããŸãã ãããã£ãŠãä¿è·ã®å šäœçãªãã€ã³ãã¯ãæ»æè ããµãŒããŒãç¹°ãè¿ãèŠæ±ããç°ãªããã¹ã¯ãŒãã§ã·ã¹ãã ã«å ¥ãããšãããšããµãŒããŒãåŒã³åºãã®æ°ã«äœããã®åœ¢ã§åå¿ããããšã ãšæããŸãã ãã®å Žåããªã¯ãšã¹ãã®å¶éã«éããå¯èœæ§ãããããããããã³ã°ã«å¯Ÿããä¿è·ã匷åãããŸãã
åŠçïŒæ»æè ã¯ã©ã®ããã«ããŠKerberosãµãŒããŒã«ãªã¯ãšã¹ããéä¿¡ã§ããŸããïŒ
ææïŒåœŒã¯æ£ãããŠãŒã¶ãŒã®ã¡ãã»ãŒãžãåçŸã§ãããšæããŸããã€ãŸãããããèŠãŠãã³ããŒããŠãéä¿¡ããŠãKerberosãµãŒããŒããå¿çãåãåãããšãã§ããŸãã ããã«ãŒããããã¯ãŒã¯ãã¹ãã£ã³ãããšãéä¿¡äžã«ã¡ãã»ãŒãžãååã§ããŸãã ãã®ããããªã¯ãšã¹ãã®æ°ãå¶éããããšã¯ãã»ãã¥ãªãã£ããããã«åäžãããäžæçãªæ段ã§ãã ãããããã¡ãããä»ã®äººã®ãããã¯ãŒã¯ãèŠããšãTcãsã®åœ¢æã®æ®µéã§äœãèµ·ãã£ããã«é¢ä¿ãªãããã®ãã±ããããµãŒããŒããã©ã®ããã«è¿ãããããããããŸãã ãã®ãããããã«ãŒã¯ãµãŒããŒã®ã¯ã©ã€ã¢ã³ããžã®å¿çã確èªããæ»æãè©Šã¿ãããšãã§ããŸãã
ãããããã£ãšè€éãªã¹ããŒã ãéçºã§ãããããããŸããããKerberos 5ãã¬ãã¥ãŒããèšç»ãããè€éãªãã®ãå®è£ ããŠãããšã¯æããŸããããã¹ã¯ãŒããã¯ã©ãã¯ãããã
åŠçïŒèªèšŒãªã©ãæäŸããŠãå ±æããŒã確ç«ã§ãããšããŸãã ãããŠããã®ããšãšå ±æããŒãKcã§æå·åã§ããŸãã
ææïŒã¯ããããã§ãã æ¬åœã«æ£ããå®è¡ããå Žåããã®ããã«ããã¹ã¯ãŒãèªèšŒãå®è¡ãããã¹ã¯ãŒãèªèšŒããŒäº€æïŒPAKEïŒãšãããããã³ã«ããããŸãã ããã¯ãŸãã«Kerberosã§èµ·ããããšã§ãã
Googleã§SRPãŸãã¯PAKEãããã³ã«ã®ç®çã確èªã§ããŸãã ãããã®ãããã³ã«ãšããã«é¢é£ããèŠçŽ ã¯ãæ°ããããŒãã€ã³ã¹ããŒã«ããããšãåæ¹ã«èšŒæããå¿ èŠãããã¿ã¹ã¯ã§ãã¯ããã«åªããŠããŸãã ãã®å Žåãäž¡åœäºè ã¯äºãã®æ£åœæ§ãšããã確信ããå¿ èŠãããããã®ãã¹ã¯ãŒãããªãã©ã€ã³ã§æšæž¬ããããç£èŠããŠãããããã¯ãŒã¯ãã±ããã®ã»ãããæ»æãããªã©ã®æ¹æ³ã¯ãããŸããã
ãããã¯æå·åã«å€§ããäŸåãããããã³ã«ã§ãããããããããæ©èœããçç±ãããŒãäžã§èª¬æããã®ã¯å°é£ã§ãã
åŠçïŒéçºè ããããè¡ã£ãçç±ã®1ã€ã¯ããã¹ã¯ãŒãã®ã¿ãéä¿¡ããæ©èœããµããŒããããã£ãããã§ãã ãŸãããããã³ã«ã§ã¯ããªãŒã»ã³ãã£ã±ãŒã¿ãŒãšããŠéä¿¡ã§ããã®ã¯1ã€ã ãã§ãã
ææïŒã¯ãããããã®äººãèæ ®ã«å ¥ããå€ãã®å¥åŠãªèŠä»¶ããããŸãã ãã¡ãããå®éã«ã¯ããããã®ãµãŒããŒã¯Kerberosæ¥ç¶ãšéKerberosæ¥ç¶ã®äž¡æ¹ãåãå ¥ããããšãã§ããŸãã ãŸããKerberos以å€ã®æ¥ç¶ã®å Žåã誰ããã¡ãŒã«ãµãŒããŒã«æ¥ç¶ããŠããããAthenaã¯ãŒã¯ã¹ããŒã·ã§ã³ã䜿çšããŠããªããã®ããã«èŠããŸãã 圌ã¯ãã¹ã¯ãŒããéä¿¡ãããã ãã§ãã
ãããŠãããã®ã¡ãŒã«ã¯ã©ã€ã¢ã³ãã¯ãããšãã°ããã®ãã¹ã¯ãŒããååŸãã確èªã®ããã ãã«ãã±ãããååŸããŠããã®ã¡ãŒã«ã¯ã©ã€ã¢ã³ãã䜿çšã§ããããã«ããŸãã ãã®ãããããããKerberosã§Kerberosãã¹ã¯ãŒããæ€èšŒããå¿ èŠããããŸãã ãã¡ãããKerberos 5ã¯ãã®ã¿ã€ã ã¹ã¿ã³ãããã·ã¥ãªã©ãå±éããã®ã§ããããåé¡å€ã ãšã¯æããŸããã
è¬çŸ©è³æã§æ³šæãã¹ããã1ã€ã®ç¹ã¯ãKerberos 4ã®éçºè ã1ã€ã®æå·åã¹ããŒã ãéžæããããšã§ããDESã¯ãåœææã人æ°ã®ããæå·åã¢ã«ãŽãªãºã ã§ãã ããã¯å¯Ÿç§°ãããã¯æå·ã§ãããéåžžã«é«éã§ãã åœæãããã¯ååãªã»ãã¥ãªãã£ãæäŸãã圌ãã¯åã«ããããããã³ã«ã«çµã¿èŸŒã¿ãŸããã
Kerberosã®ãã¹ãŠãDESã®ã¿ã䜿çšããããå°ãªããšãKerberosããŒãžã§ã³4ã®ãã¹ãŠã䜿çšããããšã«ãªã£ãŠããŸããããã¯ãçŸåš25ã30幎åŸã«ãæå·åããŒãéåžžã«å°ãããµã€ãº-56ãããã®ã¿ã
ãããã£ãŠã2ã56床ã®çµã¿åãããèšç®ããå®éã®ãã¹ã¯ãŒããèŠã€ããäœããã®çš®é¡ã®ãŠãŒã¶ãŒæ©åšãç°¡åã«äœæã§ããŸãã ããã¯ãçŸåšéçºäžã®ãããã³ã«ã§ã¯é¿ããããã®ã§ãã
KerberosããŒãžã§ã³5ã¯ãAESããã®ä»ã®æå·åã¢ã«ãŽãªãºã ãªã©ãããã€ãã®ç°ãªãæå·åã¹ããŒã ããµããŒãããŠããŸãã ãããã£ãŠãããã¯ã»ãã¥ãªãã£ã確ä¿ããããã®ã¯ããã«åªããæ¹æ³ã®ããã§ãã äžæ¹ãMITã¯2幎åã«DESããµããŒããç¶ããŠããŸããããçŸåšã¯æåŠããŠããŸãããã®ãããä»æ¥ãå°ãªããšããã®ã¿ã€ãã®æ»æããåŠé·ã¯ä¿è·ãããŠããŸãã 次ã«ããã±ãããåãåãTGSãµãŒãã¹ã§äœãèµ·ããããèŠãŠã¿ãŸãããã ãã®ãµãŒãã¹ãšã®çžäºäœçšã¯å°ãç°ãªããŸãã
äžæ¹ã§ã¯ãã¯ã©ã€ã¢ã³ããšããŠãããããä»ã®Kerberos察å¿ãµãŒãã¹ãšè©±ããŠãããã®ããã«ã圌ãšè©±ããŸãã ãã·ã³ãžã®ãã±ããã䜿çšããŠç¬èªã®èªèšŒãå®è¡ããæ¹æ³ãæ€èšããŠãã ããã ãã ããè¿ãããåçã¯ãä»ã®ååãžã®åãªããã±ããã§ãããããã«åºã¥ããŠãããšãã°ãã¡ã€ã«ãµãŒããŒãšéä¿¡ããŸãã
ãããã£ãŠããããã³ã«ã¬ãã«ã®ã¡ãã»ãŒãžã¯æ¬¡ã®ããã«ãªããŸã-å³åŽã¯TGSãæç»ããå·ŠåŽã¯ã¯ã©ã€ã¢ã³ããæç»ããŸãã ã¯ã©ã€ã¢ã³ãã«ã¯ãäžéšã«ç€ºãããŠãããããã³ã«ã䜿çšããŠååŸããTGSã®ãã±ãããæ¢ã«ãããŸãã
ã¯ã©ã€ã¢ã³ãã¯ãèªåãæ£ããã¯ã©ã€ã¢ã³ãã§ããããšã蚌æããã¡ãã»ãŒãžã®çµã¿åãããéä¿¡ããŸãããããã®ã¡ãã»ãŒãžã¯ãTGSãä»ããç¹å®ã®ååã«åºã¥ããªã¯ãšã¹ãã®çºè¡ã«é¢é£ããŠããŸãã
ãããã£ãŠãã¯ã©ã€ã¢ã³ãã¯æ¬¡ã®ã¡ãã»ãŒãžãTGSã«éä¿¡ããŸããSã¯ããã«éä¿¡ãããµãŒãã¹ã§ããã¡ãŒã«ãµãŒããŒãŸãã¯ãã¡ã€ã«ãµãŒããŒã®å ŽåããããŸããããã«ã¯ãããŒK tgsã䜿çšããŠæå·åãããtgsã«å¯ŸããŠåä¿¡ããTcã¯ã©ã€ã¢ã³ããã±ãããå«ãŸããŸãããŒKcãã¯ã©ã€ã¢ã³ãããã³TGSãµãŒãã¹ã«å ±éã®tgsã§æå·åãããèªèšŒã·ã¹ãã ã TGSã«éä¿¡ããã¡ãã»ãŒãžã¯æ¬¡ã®ããã«ãªããŸããããã®ã¡ãã»ãŒãžãèŠãŠããããåŠçãããã®æ°ããSãµãŒãã¹ãžã®ãã±ããã§è¿ä¿¡ããŸããã ããã§ã®çãã¯äžã®å³ãšã»ãŒåãã«èŠããŸãããå®éã¯åãã§ããããã¯ãKsã䜿çšããŠæå·åãããã¯ã©ã€ã¢ã³ããšãã®æ°ãããµãŒãã¹éã®ãã±ããã§ãã ããããä»ã§ã¯å°ãç°ãªããŸãã
ã¯ã©ã€ã¢ã³ãããã以éå¿ããŠããKcããŒã«ããæå·åã®ä»£ããã«ãã¯ã©ã€ã¢ã³ããšTGSãµãŒãã¹éã®å ±éããŒKcãtgsã䜿çšããŠæå·åãå®è¡ãããããã«ãªããŸããã
ãµãŒããŒã¯ãã¯ã©ã€ã¢ã³ããäœãæãã§ããããã©ã®ããã«å€æãããµãŒããŒã¯ã©ã®ããã«ã¯ã©ã€ã¢ã³ããèªèšŒããŸããïŒ TGSãµãŒããŒã¯èªèº«ã®KtgsããŒãç¥ã£ãŠãããããæåã«ãã®ã¡ãã»ãŒãžTcãtgsã解èªãããã±ããã®å éšãèŠãŠãäœãèµ·ãããã調ã¹ãŸãã ãã±ããã«ããããã¹ãŠã®ãã£ãŒã«ããå¿ èŠãªã®ã¯ãªãã§ããïŒ ãã±ããã«ãµãŒããŒåSãä»ããããšãéèŠãªã®ã¯ãªãã§ããïŒ Sããªãã£ããã©ããªãã§ããããïŒ
åŠçïŒãªãã£ãå ŽåããµãŒããŒã䜿çšããèš±å¯ãåŸãå¯èœæ§ããããŸãã
ææïŒã¯ããããã§ãã äžè¬ã«ããã®ã¡ãã»ãŒãžã®æå³ãæ£ç¢ºã«äŒããããšãã§ããããã«ããããã¯ãŒã¯ãããã³ã«ãäœæããããšããå§ãããŸãã Sãçç¥ããå Žåãééã£ãSã®ãã±ããã䜿çšãããšãå¥ã®ããŒKsãããã埩å·åãªã©ãå®è¡ã§ããªãå¯èœæ§ããããšããäºå®ã«äŸåã§ããŸãã ãããã£ãŠããããã®ãã±ãããåä¿¡ãããµãŒããŒããããã埩å·åãããããç§ãŸãã¯ä»ã®èª°ãã®ããã®ãã±ããã§ãããã©ããã確èªããããã«ããµãŒãã¹ã®ååãå«ããããšã¯è¯ãèãã®ããã«æããŸããïŒ
åŠçïŒã¯ã©ã€ã¢ã³ãã¯åãåã£ãKtgsããŒã§äœãããŸããïŒ
ææïŒãã質åã§ãïŒ ã¯ã©ã€ã¢ã³ãã¯ãããäœã§ããããç¥ããŸããã ããã¯æé«ã®ç§å¯éµã ããã§ãã ç¥ã£ãŠããã°ããã¹ãŠã®Kerberosã解èªã§ããŸãã ãããã£ãŠãã¯ã©ã€ã¢ã³ãã¯Ktgsãäœã§ãããããããŸããã
åŠçïŒãã®Ktgsã¯ã©ãããæ¥ãã®ã§ããïŒ
ææïŒ KerberosãµãŒããŒèªäœããã¹ãŠã®ãã®ã¡ãã»ãŒãžãçæããŸããTcãtgsãããã³Ktgsãæ¢ã«å«ãŸããŠãããããèªåã§äœæããã®ã§ã¯ãªããããããã³ããŒããã ãã§ãã
ã§ã¯ããªã顧客åããããªã«éèŠãªã®ã§ããããïŒ ããã¯ç°¡åã«ç解ã§ããŸãã ãã±ããã«ã¯ã©ã€ã¢ã³ãã®ååãä»ããªãå ŽåããµãŒããŒã¯ãã®ã¡ãã»ãŒãžãåãåããŸããã誰ã話ããããããšããŠããã®ãããããŸããã 圌ã¯èª°ã®ããã«ãã±ãããçºè¡ãã¹ãããç¥ããŸãã-ããªãã®ããã«ããŸãã¯ä»ã®èª°ãã®ããã«ã
ä»ã®ãã£ãŒã«ãã¯ã©ãã§ããïŒ éçºè ãTcãsãã±ããã«addrã¢ãã¬ã¹ãæ¿å ¥ããã®ã¯ãªãã§ããïŒ ã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ã ããªã®ã§ãçŽæ¥äœ¿çšããªãã®ã¯ãªãã§ããïŒ
ãã®ãœãªã¥ãŒã·ã§ã³ã®æå³ã¯ãéçºè ãã»ãã¥ãªãã£ãé«ããããšããé¡æã ãšæããŸãã ã¯ã©ã€ã¢ã³ããç¹å®ã®IPã¢ãã¬ã¹ãããã°ã€ã³ããå Žåãåããã±ããã®ä»ã®ãã¹ãŠãåãIPã¢ãã¬ã¹ããã®ãã®ã§ããããšã確èªãããã£ãã®ã§ãã ããšãã°ã18.26.4.9ãªã©ã®IPã¢ãã¬ã¹ãããã°ã€ã³ããŠããå Žåããã¡ã€ã«ãŸãã¯ã¡ãŒã«ãµãŒããŒãžã®åæ¥ç¶ã¯åãIPã¢ãã¬ã¹ããã®ãã®ã§ãªããã°ãªããŸããã ããã§ãªãå Žåã誰ããããªãã®ãã±ãããçãã ããšã瀺åããå¯èœæ§ãããããããµãŒããŒã¯æ¥ç¶ãæåŠããå¿ èŠããããŸãã ãããã£ãŠãããã§ã¯çé£ãã±ããã®äœ¿çšãã身ãå®ããŸãã ãŸã åããã±ãããæã£ãŠããå Žå-çµæ§ã§ãããåãIPã¢ãã¬ã¹ã䜿çšããªããšæåããŸããã
ããã¯çŸæç¹ã§ã¯èª€è§£ã®ããã«æãããKerberos 5ã¯åæ§ã®ã¢ãããŒãã䜿çšããŠããŸãããããã¯å¿ é ã§ã¯ãããŸããã å®éãIPã¢ãã¬ã¹ãä¿è·ããã®ã§ã¯ãªããåã«æå·åã«é Œãã¹ãã§ãã
ãããããã±ããã®ã¿ã€ã ã¹ã¿ã³ããšã©ã€ãã¿ã€ã ã¹ã¿ã³ãã®æå³ã¯äœã§ããïŒ ãããã¯äœã®ããã«ãäœã®ããã«åœ¹ç«ã€ã®ã§ããããïŒ
åŠçïŒãªãã¬ã€æ»æãé²ãããã«å¿ èŠã§ãã
ææïŒãªãŒã»ã³ãã£ã±ãŒã¿ãŒã¯ããªãã¬ã€æ»æã®é²æ¢ã«åœ¹ç«ã¡ãŸããããã¯ãæ°ãããªã¯ãšã¹ããè¡ããã³ã«ãªãã¬ã€æ»æãçæãããããã§ãã ãããäžæ¹ã§ããã±ããã¯åããŸãŸãªã®ã§ãããã¯ãã¡ãããªãã¬ã€æ»æã劚害ããŸããã
åŠçïŒããã¯ã誰ããããªãã®ãã±ãããçã¿ããããèªåã®ç®çã«äœ¿çšããããšãé²ããŸãã
ææïŒã¯ããããã¯ãã±ããã®æå¹æéãå¶éããã ããªã®ã§ãçé£ã«ãã被害ã軜æžãããŸãã ã¿ã€ã ã¹ã¿ã³ãã¯ãã±ãããåãåã£ãæéã§ãããã©ã€ãã¿ã€ã ã¯ãã®ãã±ãããæåã®ã¿ã€ã ã¹ã¿ã³ãããæå¹ãªæéã瀺ããŸãã ãããã£ãŠãæ©ããããé ããããããããšãããšããµãŒããŒã¯Kerberosãããã³ã«ã䜿çšããŠãã®ãããªãã±ãããæåŠããå¿ èŠããããŸãã ããã¯ãåãµãŒããŒãã¯ããã¯ãåæããå¿ èŠãããããšãæå³ããŸãã
åŠçïŒã¯ã©ã€ã¢ã³ãã¯æåã®ããŒãæšãŠãŠKcãç Žæ£ã§ããŸãããTGSããåãåã£ãKcãä¿åããªããã°ãªããªãããšãå ã«è¿°ã¹ãŸããã
ææïŒã¯ããã¯ã©ã€ã¢ã³ãã¯ãã°ã€ã³åŸã«KcãããããããŸãããKcãsãç¶æããå¿ èŠããããŸãã
: , - K,s, âŠ
: , , ? , Kc,tgs, K?
: K,s, , K, .
: . , Kc,s â , , . , Tc,tgs, . , 56 Kc,s. . , Tc,tgs , Kc,s , - .
: , - â Tc,tgs, Kc,tgs, Kc,tgs, Kc â .
: , - , , , , 10 . Kc , .
, , , IP-, . - , , Kc,tgs, TGS. â , , , .
, , , . , , . TGS , , PO12, TGS PO12. , , Kc,s . , , . Kc,s.
, , Tc,mail, Kmail, , , , 5 â DELETE 5, Kc,mail.
, mail? Kmail, - , , Kc,s, Kerberos 5. : «, C , ».
: Kerberos Tc,tgs Kc,s. ?
: Ac . , Kc,s, , . , .
, Kerberos 4 , , , , , , , .
, , , , . , . , , . , , , , . , .
. Kerberos, , , Kerberos 4. , - .
, , , , , Kerberos 4, , , K,mail. , .
, , . , , . - : «, , DELETE 5, - ».
, Kerberos 5 -, . , , , , , .
: K,mail?
: .
, TGS , , S â mail, S Tc,s â mail, S Kc,s â mail. Kc,s K,mail. , .
: K,mail?
: , ? , , . K,mail ?
: ?
: , , ! Kmail, T,mail, , . , , .
, . . Kerberos , , 30 .
, , . , Kerberos 4 . , .
54:00
MITã³ãŒã¹ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã 13: « », 3
ã³ãŒã¹ã®å®å šçã¯ãã¡ãããå ¥æã§ããŸã ã
ãæ»åšããã ãããããšãããããŸãã ? ããèå³æ·±ãè³æãèŠããã§ããïŒ , 30% entry-level , : VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps $20 ? ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§ 6ãæã®æéãæ¯æãå Žåã¯12æãŸã§ç¡æ㧠ã ããã§æ³šæã§ããŸã ã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšç±³åœã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯æ¹æ³ã«ã€ããŠèªã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ