ã¯ããã« ååã¯ãLinuxã®èªè¨¼åºç¤ã§ãããFreeIPAãã«ã¤ãã¦ãIPAãµã¼ã/ã¯ã©ã¤ã¢ã³ãã®ä¸»ãªã³ã³ãã¼ãã³ããç´¹ä»ãã¾ãããä»åã¯ãå®éã«FreeIPAãã¤ã³ã¹ãã¼ã«ãã¦ãFreeIPAãæã¤å¤ãã®æ©è½ã®ããã¤ããè¦ã¦ããã¾ãããã FreeIPAã®ã¤ã³ã¹ãã¼ã«æºå ã¾ãã¯ãFreeIPAãã¤ã³ã¹ãã¼ã«ããåæºåã¨ãã¦ãæå ã®KVMç°å¢ã«ã試ãç¨ã®ipaãµã¼ããæ§ç¯ãã¾ãã ååã§è§£èª¬ããããã«ãåºæ¬çã«FreeIPAã管çãããã¡ã¤ã³ã«ã¯Kerberosã§ãã°ã¤ã³ãããããä»ã®Kerberosã§ç®¡çããã¦ããªããã¡ã¤ã³ã§ãªãã¦ã¯ããã¾ãããDNSã§æ£å¼ãã»éå¼ããå¯è½ãªå¿ è¦ãããã®ã§ãlibvirtã®ãããã¯ã¼ã¯è¨å®ãå¤æ´ãã¦ããããããä»®æ³ãã·ã³ã«å¯¾ãã¦dnsmasqãæä¾ããDNSã«ipa.example.comã¨client.example.comã®ã¨ã³ããªãå®ç¾©ãã¦ãã
ã¤ã³ã¿ã¼ãããã®éè¦ãªåºç¤æè¡ã®1ã¤ã§ããDNSã«å¯¾ãã¦æ°ããªæ»æææ³ãå ¬éããããã®å®å ¨æ§ãè ãããã¦ãããDNSã«ã»ãã¥ãªãã£æ©è½ãæä¾ããããã®æè¡ã§ãããæ®åãé²ãã§ããDNSSECã«ã¤ãã¦ãä»çµã¿ã¨éç¨æ¹æ³ãç´¹ä»ãããï¼ç·¨éé¨ï¼
ä»åã¯ãDNSSECã®æ¤è¨¼æ©è½ãæå¹ã«ãããã£ãã·ã¥DNSãµã¼ããæ§ç¯ã»éç¨ããæ¹æ³ã«ã¤ãã¦è§£èª¬ããã DNSSECã«ããããã£ãã·ã¥DNSãµã¼ãã®å½¹å² ãã£ãã·ã¥DNSãµã¼ãã¯ãåå解決ãä¾é ¼ããã¯ã©ã¤ã¢ã³ãã¨æ¨©å¨DNSãµã¼ãã®éã«ç«ã¡ãå復æ¤ç´¢ãè¡ããµã¼ãã§ãããDNSSECã«ããã¦æ¤è¨¼ãæ å½ãããã®ããããªãã¼ã¿ï¼Validatorï¼ãã¨å¼ã³ãå¤ãã®å ´åãã£ãã·ã¥DNSãµã¼ããããªãã¼ã¿ãæ å½ããã 第2åã§ãç°¡åã«èª¬æããããDNSSECã®æ¤è¨¼ãè¡ãããã«ã¯ä¿¡é ¼ã®é£éã®èµ·ç¹ã¨ãªãæ å ±ãå¿ è¦ã¨ãªãããããããã©ã¹ãã¢ã³ã«ã¼ï¼Trust Anchorï¼ãã¨å¼ã¶ãããªãã¼ã¿ã¨ãªããã£ãã·ã¥DNSãµã¼ãã¯ããã©ã¹ãã¢ã³ã«ã¼ãèµ·ç¹ã«ãDNSSECã®ä¿¡é ¼ã®é£éãæ¤è¨¼ãã¦ãããã¨ã«ãªãã DNSã®é層æ§é ã«ãããå§ä»»ã®èµ·ç¹ãã«ã¼ãã¾ã¼ã³ã§ãããã¨ãããä¸è¬çã«ã¯ã«ã¼ãã¾ã¼ã³ã®å ¬ééµæ å ±ããã©ã¹ã
IIJã§ããç¬èªéçºã«ããDNSSECã®å®ç¾ãã¨ããè¨äºãå ¬éããã¦ãã¾ãã é常ã«é¢ç½ãè¨äºã ã£ãã®ã§ããå§ãã§ãã è¨äºã®æ¦è¦ã¯ã以ä¸ã®ããã«è¿°ã¹ããã¦ãã¾ãã DNSã«å¯¾ããã»ãã¥ãªãã£æ©è½ã®æ¡å¼µã§ããDNSSECã¯ãè¿å¹´ã«ãªã£ã¦å°å ¥ãéå§ãããããã«ãªã£ããã®ã®ãå®è£ ãããã£ã¦ããªãããæ®åãé ãã¦ãã¾ããããã§ãIIJã§ã¯ãDNSSECå®ç¾ã®ããã®ãã¹ã¦ã®å¦çãç¬èªã«å®è£ ãããã¨ã«ãç¹å¥ãªç¥èããªãã¦ãããå©ç¨ã®ãã¡ã¤ã³ãDNSSEC対å¿ã«ãããã¨ãå¯è½ã«ãã¾ããã ããã§ã¯ãDNSSECå®ç¾ã®ããã®å¦çãç¬èªéçºããçµç·¯ãç´¹ä»ãã¾ãã æ¬æã§ã¯ãæåã«å®å ¨ãªDNSãµã¼ãã¹ãä½æ å¿ è¦ã§ãããã¨ã¨ãã«ãIIJãæä¾ãã¦ããDNSSEC対å¿ãµã¼ãã¹ã§ãããIIJ DNSã¢ã¦ãã½ã¼ã¹ãµã¼ãã¹ããå®ç¾ããããã«ç¬èªéçºãè¡ã£ãçµç·¯(èæ¯)ãç´¹ä»ããã¦ãã¾ãã ãè¦æ ¼ããã£ã¦ãå®å ¨ãªå®è£ ã
2010/10/19ãã³ã¼ã¹ï¼å ç¥ãã£ã¦ã ãå ç¥ãã£ã¦ããè¨äºã¯ãããã¨ã¼ã¸ã§ã³ãæ§ããã°[netagent-blog.jp]ã«æ²è¼ããã¦ããè¨äºã§ãããç¾å¨ãããã¨ã¼ã¸ã§ã³ãã«å¨ç±ãã¦ããªãã©ã¤ã¿ã¼ã®è¨äºãå«ã¿ã¾ãã æè¿ã®DNSSECã®åå ããã«ã¡ã¯ããããã¨ã¼ã¸ã§ã³ãæ ªå¼ä¼ç¤¾ç 究éçºé¨ã大éªæ¯ç¤¾ã®å±±å£ã§ããä»åã¯ãDNS ã®ãã¼ãããã¯ã®ã²ã¨ã¤ã§ãã DNSSECï¼DNS Security Extensionï¼ ã«ã¤ãã¦ç´¹ä»ãããã¨æãã¾ãã ----- DNSï¼Domain Name Systemï¼ ã¨ã¯ããåãã®éããã¤ã³ã¿ã¼ãããä¸ã«å±éããã¦ããé層çãªåæ£åãã¼ã¿ãã¼ã¹ã®ãã¨ã§ã主ã«ãã¹ãåã¨IPã¢ãã¬ã¹ã®å¯¾å¿ä»ãçã«ä½¿ç¨ããã¦ãã¾ããç¾å¨ã®ã¤ã³ã¿ã¼ãããã«ããã¦ã¯ DNS ã¯ãã¯ãå¿ è¦ä¸å¯æ¬ ãªã·ã¹ãã ã§ãããã¤ã³ã¿ã¼ãããæè¡ã®æ ¹å¹¹ã¨ãã£ã¦ãéè¨ã§ã¯ããã¾ãããããã
Netã®ä¸çã«è»¢ãããæ§ã ãªãã¿ãè¦ã¦ã¯æ¥½ããããNewsãµã¤ããã¨ãã¦ãæè¿ã»ã¼æ¯æ¥æè¦ãã¦ãã ãGizmodo Japanã ã®ã¨ã³ããªã¼ã«ãå¦ãªè¨äºãè¼ã£ã¦ããã WWWã¸ã®ã¢ã¯ã»ã¹æ¨©ãæã¤7人 http://www.gizmodo.jp/2010/07/seven-people-have-been-entrusted-with-the-keys-to-the-internet.html æç²ï¼ ä¸ã®ç»ã«ãããã®ã«ã¼ããä¸çã§7人ã ããä¿æãã¦ããã大ç½å®³æã«Wold Wide Webãåèµ·åãããåãæã¤ã«ã¼ããªã®ã§ãã ããªã¢ããªãNetã®ä¸çã«ã·ã³ã°ã«ã¨ã³ããã¤ã³ãSingle Point of Failureï¼SPOFï¼ï¼1ç®æã®ã·ã¹ãã ããµã¼ãã¹ãæä¾ã§ããªããªãã¨ãã·ã¹ãã å ¨ä½ãæ¢ã¾ãï¼ããã訳ç¡ãããã¾ãã¦ãWWWâhttp/httpsãããã³ã«éå®ã¨ãæãå¾ãªãï¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}