Red Hat Linux 7.1¤Ë¤ª¤±¤ëKerberos 5¥µ¡¼¥Ð¡¼¤Î¥»¥Ã¥È¥¢¥Ã¥×

¡¡Kerberos¤ò¥»¥Ã¥È¥¢¥Ã¥×¤¹¤ë¤Ë¤Ï¡¢¤Þ¤º¥µ¡¼¥Ð¡¼¡Ê·²¡Ë¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£ ¥¹¥ì¡¼¥Ö¥µ¡¼¥Ð¡¼·²¤ò¥»¥Ã¥È¥¢¥Ã¥×¤¹¤ëɬÍפ¬¤¢¤ë¾ì¹ç¡¢¥Þ¥¹¥¿¥µ¡¼¥Ð¡¼¤È¥¹¥ì¡¼¥Ö¥µ¡¼¥Ð¡¼·²¤Î´Ø·¸¤ò¥»¥Ã¥È¥¢¥Ã¥×¤¹¤ëÊýË¡¤Î¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢¡ØKerberos 5 Installation Guide¡Ù( /usr/share/doc/krb5-server-<version-number> ¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ê¤Þ¤¹¡Ë¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

¡¡Kerberos¥µ¡¼¥Ð¡¼¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤Ë¤Ï¡¢°Ê²¼¤Î¤è¤¦¤Ë¤·¤Þ¤¹¡£

  1. Kerberos 5¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤Ë¤Ï¡¢»þ·×¤ÎƱ´ü¤¬¼è¤é¤ì¤Æ¤¤¤ë¤³¤È¤È¡¢¥µ¡¼¥Ð¡¼¾å¤ÇDNS¤¬µ¡Ç½¤·¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£Kerberos¥µ¡¼¥Ð¡¼¤È¿¿ô¤Î¥¯¥é¥¤¥¢¥ó¥È¤È¤Î´Ö¤Ç»þ·×¤ÎƱ´ü¤¬¼è¤é¤ì¤Æ¤¤¤ë¤«¤É¤¦¤«¤Ë¤Ä¤¤¤Æ¤Ï¡¢ÆäËÃí°Õ¤òʧ¤Ã¤Æ¤¯¤À¤µ¤¤¡£ ¥µ¡¼¥Ð¡¼¤È¥¯¥é¥¤¥¢¥ó¥È¤Î»þ·×¤Î¤º¤ì¤¬5ʬ¤òĶ¤¨¤ë¤È¡Ê¤³¤Î¥Ç¥Õ¥©¥ë¥È¤Î¿ôÃͤÏKerberos 5¤ÇÀßÄꤵ¤ì¤Þ¤¹¡Ë¡¢Kerberos¥¯¥é¥¤¥¢¥ó¥È¤Ï¥µ¡¼¥Ð¡¼¤ËÂФ·¤Æǧ¾Ú¤ò¹Ô¤¦¤³¤È¤¬¤Ç¤­¤Þ¤»¤ó¡£ ¤³¤Î¤è¤¦¤Ê»þ·×¤ÎƱ´ü²½¤Ï¡¢¹¶·â¼Ô¤¬ÀµÅö¤Ê¥æ¡¼¥¶¡¼¤È¤·¤Æ¥Þ¥¹¥«¥ì¡¼¥É¤ò¹Ô¤¦ºÝ¤Ë¸Å¤¤Ç§¾Ú¤ò»ÈÍѤǤ­¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤ËɬÍפǤ¹¡£

    Kerberos¤ò»ÈÍѤ·¤Æ¤¤¤Ê¤¤¾ì¹ç¤Ç¤â¡¢Red Hat Linux¤ò»ÈÍѤ·¤Æ¡¢NTP¡ÊNetwork Time Protocol¡Ë¸ß´¹¤Î¥¯¥é¥¤¥¢¥ó¥È/¥µ¡¼¥Ð¡¼¥Í¥Ã¥È¥ï¡¼¥¯¤ò¥»¥Ã¥È¥¢¥Ã¥×¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£ Red Hat Linux 7.1¤Ë¤Ï¡¢¥¤¥ó¥¹¥È¡¼¥ë¤òÍưפˤ¹¤ë¤¿¤á¤Ë¡¢ ntp ¥Ñ¥Ã¥±¡¼¥¸¤¬ÍÑ°Õ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£ NTP¤Î¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢http://www.eecis.udel.edu/~ntp ¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

  2. KDC¤òÆ°ºî¤µ¤»¤ëͽÄê¤ÎÀìÍÑ¥Þ¥·¥ó¾å¤Ë¡¢krb5-libs ¡¢krb5-server¡¢krb5-workstation¤Î³Æ¥Ñ¥Ã¥±¡¼¥¸¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£ ¤³¤Î¥Þ¥·¥ó¤Ï¡¢Àµ¤·¤¯Êݸ¤ì¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£²Äǽ¤Ç¤¢¤ì¤Ð¡¢KDC°Ê³°¤Î¥µ¡¼¥Ó¥¹¤ò¼Â¹Ô¤¹¤Ù¤­¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡£

    Kerberos¤ò´ÉÍý¤¹¤ë¤¿¤á¤ÎGUI¡ÊGraphical User Interface¡Ë¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤ò»ÈÍѤ·¤¿¤¤¾ì¹ç¤Ë¤Ï¡¢ gnome-kerberos ¥Ñ¥Ã¥±¡¼¥¸¤â¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£ ¤³¤Î¥Ñ¥Ã¥±¡¼¥¸¤Ë¤Ï¡¢¥Á¥±¥Ã¥È´ÉÍýÍѤÎGUI¥Ä¡¼¥ë krb5 ¤ä¡¢Kerberos¤Îrealm¤ò´ÉÍý¤¹¤ë¤¿¤á¤ÎGUI¥Ä¡¼¥ë gkadmin ¤¬´Þ¤Þ¤ì¤Æ¤¤¤Þ¤¹¡£

  3. »ÈÍѤ¹¤ërealm¤Î̾Á°¤È¡¢¥É¥á¥¤¥ó¤«¤érealm¤Ø¤Î¥Þ¥Ã¥Ô¥ó¥°¤òÈ¿±Ç¤¹¤ë¤¿¤á¤Ë¡¢ÀßÄê¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë /etc/krb5.conf ¤È /var/kerberos/krb5kdc/kdc.conf ¤òÊÔ½¸¤·¤Þ¤¹¡£ ñ½ã¤Êrealm¤òºîÀ®¤¹¤ë¤Ë¤Ï¡¢ EXAMPLE.COM ¤È example.com ¤Î¥¤¥ó¥¹¥¿¥ó¥¹¤ò¡¢»ÈÍѤ¹¤ë¥É¥á¥¤¥ó̾¤ÈÃÖ¤­´¹¤¨¡ÊÂçʸ»ú¤Î̾Á°¤ÏÂçʸ»ú¤Î¤Þ¤Þ¡¢¾®Ê¸»ú¤Î̾Á°¤Ï¾®Ê¸»ú¤Î¤Þ¤Þ¤È¤·¤Þ¤¹¡Ë¡¢KDC¤ò kerberos.example.com ¤«¤é¡¢»ÈÍѤ¹¤ëKerberos¥µ¡¼¥Ð¡¼Ì¾¤ËÊѹ¹¤·¤Þ¤¹¡£ ´·½¬¤Ë¤è¤ê¡¢¤¹¤Ù¤Æ¤Îrealm̾¤ÏÂçʸ»ú¤È¤Ê¤Ã¤Æ¤ª¤ê¡¢¤¹¤Ù¤Æ¤ÎDNS¥Û¥¹¥È̾¤È¥É¥á¥¤¥ó̾¤Ï¾®Ê¸»ú¤È¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£ ¾åµ­¤Î¥Õ¥¡¥¤¥ë¤Î¥Õ¥©¡¼¥Þ¥Ã¥È¤Ë´Ø¤¹¤ë¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢³Æman¥Ú¡¼¥¸¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

  4. ¥·¥§¥ë¥×¥í¥ó¥×¥È¤«¤é kdb5_util ¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤ò»ÈÍѤ·¤Æ¡¢¥Ç¡¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡£

    /usr/kerberos/sbin/kdb5_util create -s

    create ¥³¥Þ¥ó¥É¤ò»ÈÍѤ¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢Kerberos¤ÎrealmÍѤθ°¤òÊݸ¤¹¤ë¤¿¤á¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹¤òºîÀ®¤·¤Þ¤¹¡£ -s ¥¹¥¤¥Ã¥Á¤ò»ÈÍѤ¹¤ë¤È¡¢¥Þ¥¹¥¿¥µ¡¼¥Ð¡¼¸°¤ÎÊݸ¾ì½ê¤Ç¤¢¤ë stash ¥Õ¥¡¥¤¥ë¤¬¶¯À©Åª¤ËºîÀ®¤µ¤ì¤Þ¤¹¡£ ¸°¤ÎÆɤ߹þ¤ß¸µ¤Ç¤¢¤ëstash¥Õ¥¡¥¤¥ë¤¬Â¸ºß¤·¤Ê¤¤¾ì¹ç¡¢Kerberos¥µ¡¼¥Ð¡¼¡Ê krb5kdc ¡Ë¤Ï¡¢µ¯Æ°¤¹¤ë¤¿¤Ó¤Ë¥æ¡¼¥¶¡¼¤ËÂФ·¤Æ¥Þ¥¹¥¿¥µ¡¼¥Ð¡¼ÍѤΥѥ¹¥ï¡¼¥É¡Ê¸°¤òºÆÀ¸À®¤¹¤ë¤¿¤á¤Ë»ÈÍѤ¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡Ë¤òÆþÎϤ¹¤ë¤è¤¦¤Ë»Ø¼¨¤·¤Þ¤¹¡£

  5. /var/kerberos/krb5kdc/kadm5.acl ¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Þ¤¹¡£ kadmind ¤Ï¡¢¤³¤Î¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¤É¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤ËÂФ·¤Æ¡¢¤É¤Î¤è¤¦¤Ê¥ì¥Ù¥ë¤ÎKerberos¥Ç¡¼¥¿¥Ù¡¼¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤ò²Äǽ¤Ë¤¹¤ë¤«¤ò·èÄꤷ¤Þ¤¹¡£ ¤Û¤È¤ó¤É¤ÎÁÈ¿¥¤Î¾ì¹ç¤Ï¡¢1¹Ô½ñ¤±¤ÐºÑ¤ß¤Þ¤¹¡£

    */admin@EXAMPLE.COM  *

    ¤Û¤È¤ó¤É¤Î¥æ¡¼¥¶¡¼¤Ï¡¢¥Ç¡¼¥¿¥Ù¡¼¥¹¤ÎÃæ¤Ç¤Ï¡¢¡Ê NULL ¡¢¤Ä¤Þ¤ê¶õ¤Î¥¤¥ó¥¹¥¿¥ó¥¹¤ò»ý¤Ä¡¢¤¿¤È¤¨¤Ð joe@EXAMPLE.COM ¤Ê¤É¤Î¡Ë1¤Ä¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤È¤·¤Æɽ¸½¤µ¤ì¤Þ¤¹¡£ ¤³¤ÎÀßÄê¤Î¾ì¹ç¡¢ admin ¤È¤¤¤¦¥¤¥ó¥¹¥¿¥ó¥¹¤ò»ý¤ÄÂèÆó¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤ò»ý¤Ã¤¿¥æ¡¼¥¶¡¼¤Ï¡Ê¤¿¤È¤¨¤Ð joe/admin@EXAMPLE.COM ¡Ë¡¢realm¤ÎKerberos¥Ç¡¼¥¿¥Ù¡¼¥¹¤ËÂФ·¤Æ¤¹¤Ù¤Æ¤Î¸¢¸Â¤ò»ÈÍѤ¹¤ë¤³¤È¤¬¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£

    ¤³¤Î¥µ¡¼¥Ð¡¼¾å¤Ç¡¢ kadmind ¤¬µ¯Æ°¤µ¤ì¤¿¸å¤Ç¤Ï¡¢¤É¤Î¥æ¡¼¥¶¡¼¤ârealmÆâ¤ÎǤ°Õ¤Î¥¯¥é¥¤¥¢¥ó¥È¤«¥µ¡¼¥Ð¡¼¾å¤Ç¡¢ kadmin ¤« gkadmin ¤Î¤¤¤º¤ì¤«¤ò¼Â¹Ô¤¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¥µ¡¼¥Ó¥¹¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£ ¤¿¤À¤·¡¢¼«Ê¬¼«¿È¤Î¥Ñ¥¹¥ï¡¼¥É¤òÊѹ¹¤¹¤ë¤³¤È°Ê³°¤Î¡¢²¿¤é¤«¤Î·Á¤Ç¤Î¥Ç¡¼¥¿¥Ù¡¼¥¹½¤Àµ¤ò¼Â¹Ô¤Ç¤­¤ë¤Î¤Ï¡¢ kadm5.acl ¥Õ¥¡¥¤¥ë¤ÎÃæ¤Ë¥ê¥¹¥È¤µ¤ì¤¿¥æ¡¼¥¶¡¼¤Î¤ß¤Ç¤¹¡£

    NoteÃí°Õ
     

    kadmin ¤È gkadmin ¤Î¥æ¡¼¥Æ¥£¥ê¥Æ¥£¤Ï¤¤¤º¤ì¤â¡¢¥Í¥Ã¥È¥ï¡¼¥¯·Ðͳ¤Ç kadmind ¥µ¡¼¥Ð¡¼¤ÈÄÌ¿®¤·¡¢Kerberos¤ò»ÈÍѤ·¤Æǧ¾Ú¤ò¼Â¹Ô¤·¤Þ¤¹¡£ ¤â¤Á¤í¤ó¡¢¥Í¥Ã¥È¥ï¡¼¥¯·Ðͳ¤Î´ÉÍý¤òÌÜŪ¤È¤·¤Æ¥µ¡¼¥Ð¡¼¤ÈÀܳ¤Ç¤­¤ë¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ë¤Ï¡¢Âè°ì¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£ kadmin.local ¥³¥Þ¥ó¥É¤Ë¤è¤ê¡¢Âè°ì¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤·¤Þ¤¹¡£¤³¤Î¥³¥Þ¥ó¥É¤Ï¡¢¸·Ì©¤Ë¸À¤¨¤Ð¡¢KDC¤ÈƱ°ì¤Î¥Û¥¹¥È¾å¤Ç»ÈÍѤ¹¤ë¤¿¤á¤ËÀ߷פµ¤ì¤Æ¤ª¤ê¡¢Ç§¾ÚÍѤËKerberos¤ò»ÈÍѤ·¤Þ¤»¤ó¡£

    KDCüËö¤Ç¡¢°Ê²¼¤Î¤è¤¦¤Ë kadmin.local ¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Æ¡¢Âè°ì¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤òºîÀ®¤·¤Þ¤¹¡£

    /usr/kerberos/sbin/kadmin.local -q "addprinc
    username
    /admin"
  6. °Ê²¼¤Î¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤ÆKerberos¤òµ¯Æ°¤·¤Þ¤¹¡£

    /sbin/service krb5kdc start
    /sbin/service kadmin start
    /sbin/service krb524 start
  7. ¥æ¡¼¥¶¡¼¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤òÄɲ乤ë¤Ë¤Ï¡¢ kadmin ¤Ç addprinc ¥³¥Þ¥ó¥É¤ò»ÈÍѤ¹¤ë¤«¡¢gkadmin¤Î[Principal]-[Add]¥á¥Ë¥å¡¼¤ò»ÈÍѤ·¤Þ¤¹¡£kadmin¡Ê¤È¥Þ¥¹¥¿KDC¾å¤Î kadmin.local¡Ë¤Ï¡¢Kerberos´ÉÍý¥·¥¹¥Æ¥à¤ËÂФ¹¤ë¥³¥Þ¥ó¥É¥é¥¤¥ó¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹¤Ç¤¹¡£ ¤½¤Î¤¿¤á¡¢ kadmin ¥×¥í¥°¥é¥à¤Î¼Â¹Ô¸å¤Ë¡¢Â¿¿ô¤Î¥³¥Þ¥ó¥É¤òÍøÍѤǤ­¤Þ¤¹¡£ ¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢kadmin¤Îman¥Ú¡¼¥¸¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

  8. ¥µ¡¼¥Ð¡¼¤Ë¤è¤Ã¤Æ¥Á¥±¥Ã¥È¤¬È¯¹Ô¤µ¤ì¤ë¤³¤È¤ò¸¡¾Ú¤·¤Þ¤¹¡£ ¤Þ¤º¡¢ kinit ¤ò¼Â¹Ô¤·¤Æ¥Á¥±¥Ã¥È¤ò¼èÆÀ¤·¡¢¤½¤Î¥Á¥±¥Ã¥È¤ò¾ÚÌÀ½ñ¥­¥ã¥Ã¥·¥å¥Õ¥¡¥¤¥ë¤ËÊݸ¤·¤Þ¤¹¡£ ¼¡¤Ë¡¢ klist ¤ò»ÈÍѤ·¤Æ¥­¥ã¥Ã¥·¥åÆâ¤Î¾ÚÌÀ½ñ°ìÍ÷¤ò»²¾È¤·¡¢ kdestroy ¤ò»ÈÍѤ·¤Æ¥­¥ã¥Ã¥·¥å¤È¤½¤ÎÃæ¤Ë´Þ¤Þ¤ì¤ë¾ÚÌÀ½ñ¤òÇË´þ¤·¤Þ¤¹¡£

    NoteÃí°Õ
     

    ¥Ç¥Õ¥©¥ë¥ÈÀßÄê¤Î¾ì¹ç¡¢ kinit ¤Ï¡¢¥æ¡¼¥¶¡¼¤¬ºÇ½é¤Ë¥·¥¹¥Æ¥à¡ÊKerberos¥µ¡¼¥Ð¡¼¤Ç¤Ï¤Ê¤¤¡Ë¤Ë¥í¥°¥¤¥ó¤·¤¿ºÝ¤Ë»ÈÍѤ·¤¿¥¢¥«¥¦¥ó¥È¤Î¥í¥°¥¤¥ó¥æ¡¼¥¶¡¼Ì¾¤ò»ÈÍѤ·¤Æ¥æ¡¼¥¶¡¼¤òǧ¾Ú¤·¤è¤¦¤È¤·¤Þ¤¹¡£ ¥·¥¹¥Æ¥à¤Î¥æ¡¼¥¶¡¼Ì¾¤¬Kerberos¥Ç¡¼¥¿¥Ù¡¼¥¹Æâ¤Î¥×¥ê¥ó¥·¥Ñ¥ë¤ÈÂбþ¤·¤Ê¤¤¾ì¹ç¤Ï¡¢¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤¬É½¼¨¤µ¤ì¤Þ¤¹¡£ ¤½¤Î¾ì¹ç¤Ë¤Ï¡¢ kinit ¤ËÂФ·¤Æ¡¢¥³¥Þ¥ó¥É¥é¥¤¥ó¾å¤Î°ú¿ô¤È¤·¤Æ¥×¥ê¥ó¥·¥Ñ¥ë¤Î̾Á°¤ò»ØÄꤷ¤Æ¤¯¤À¤µ¤¤¡Êkinit principal ¡Ë¡£

¡¡¾åµ­¤Î¥¹¥Æ¥Ã¥×¤ò´°Î»¤¹¤ë¤È¡¢Kerberos¥µ¡¼¥Ð¡¼¤¬Î©¤Á¾å¤¬¤ê¡¢²ÔÆ°¤¹¤ë¤Ï¤º¤Ç¤¹¡£ ¼¡¤Ë¡¢Kerberos¥¯¥é¥¤¥¢¥ó¥È¤ò¥»¥Ã¥È¥¢¥Ã¥×¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£