512Mãã©ã³ã ã£ããã©ãä¹ãæãåªéãã©ã³ã®æ¡å ãæ¥ãã®ã§ä¹ãæããã
ã¨ãããããã£ããã¨ã
OS ã«ã¹ã¿ã ã¤ã³ã¹ãã¼ã«ã§ãã¼ãã£ã·ã§ã³è¨å®
defaultã§ç¨æããã¦ããCentOS 6.2 64bitçã®ãã¼ãã£ã·ã§ã³æ§æã¯ä»¥ä¸ã
partition | size |
---|---|
/boot | 250M |
swap | 2G |
/ | 97G |
大ãããã¨ããªãã®ã§ãã¾ãæ°ã«ããªãã¦ãããã£ããã©
- redhatã®documentããããRHEL6ç³»ã®/bootã®æ¨å¥¨ã500M以ä¸ã ã£ã
- disk ã«ä½è£ãããã®ã§swapãããå°ãå¢ããããã£ã
ãã¨ããã«ã¹ã¿ã ã¤ã³ã¹ãã¼ã«ãããã
os: CentOS 6 x86_64
(RHEL6ç³»ããtext modeãé¸ã¶ã¨ãã¼ãã£ã·ã§ã³ãã«ã¹ã¿ãã¤ãºã§ããªãã®ã§æ³¨æ)
Install CentOS
keyborad type : jp106
Enable IPv4 support
manual configuration
Enable IPv6 support ãªã
ãããã®ç®¡çç»é¢ã®ã¤ã³ã¹ãã¼ã«æ
å ±ã®IPãå
¥å
root password å
¥å
partitionã¯
- Use All Space
- Review and modify partitioning layout ãã§ãã¯
é©å½ã«ãã¼ãã£ã·ã§ã³è¨å®
- /boot 500M
- swapã4G
- ãã¨ã¯lvmã®/
5åãããå¾
ã¤ãã¤ã³ã¹ãã¼ã«çµäºå¾ãvncãåããã®ã§ã³ã³ããã¼ã«ããã«ã®VPSãã¼ã ããä»®æ³ãµã¼ããèµ·åãã¦ãã³ã³ã½ã¼ã« or ssh ããrootãã°ã¤ã³ããã
OSåã¤ã³ã¹ãã¼ã«å¾
sshdã®è¨å®
sshdã®rootãã°ã¤ã³ãæå¦ããã¹ã¯ã¼ãèªè¨¼ãæå¦ãããportçªå·ã¯æ°ä¼ãã§å¤æ´ãã¦ããã (å¤æ´ãã¦ãport scanããããã©ãããã¬ããã©)
# cd /etc/ssh/ # cp sshd_config sshd_config.org # vim sshd_config PermitRootLogin no PasswordAuthentication no Port "é©å½ãªport"
su ã®è¨å®
æä½ç¨ã®ã¦ã¼ã¶ä½æ(wheelã°ã«ã¼ãã«æå±ããã)ãsuãå®è¡ã§ããã®ãwheelã°ã«ã¼ãã«å¶éã
# useradd -G wheel hogem # passwd hogem ### é©å½ã«è¨å® # vim /etc/pam.d/su ### 以ä¸ã®è¨å®ãã³ã¡ã³ãããã¦ããã®ãå¤ã auth required pam_wheel.so use_uid
sshã®éµãä½æ
ssh èªè¨¼ç¨ã®éµãä½ããããã©ããããããµã¼ãã§ssh-keygen ãã¦ããã©ããããããlocalã®PCã§ãã£ã¦ããã¦ãå ¬ééµãssh-copy-id ãã¦uploadããã»ããæ£è§£ããã
# su - hogem $ ssh-keygen ### éµã®ååãpassphraseã¯é©å½ã«è¨å® $ cd .ssh $ mv id_rsa.pub authorized_keys ### ã³ãããããªããªããªããã¦id_rsa ãèªåã®PCã«ä¿å $ cat id_rsa ### ä¿åå¾ã¯ãµã¼ãã«ç§å¯éµã¯ä¸è¦ãªã®ã§æ¶ã $ rm id_rsa
iptables ã§22çªãã¼ãã¸ã®éä¿¡ãdrop
ãããæ°ä¼ããsshdã22222çªã«å¤æ´ãã¦22çªãéãããã©å·æã«ã¢ã¯ã»ã¹ãã¦ããipãããã®ã§ä¸å¿log ãåã£ã¦dropã
# iptables -A INPUT --protocol tcp --dport 22 -j LOG # iptables -A INPUT --protocol tcp --dport 22 -j DROP # /etc/init.d/iptables save
yumã®ãµã¼ããã¼ãã£ãªãã¸ããªã®è¨å®
epel ãinstall ... ãããã¨ãããã©æåããå ¥ã£ã¦ãããããã ãenabled=1 ã«ãªã£ã¦ããã®ã§ãdefaultã§ã¯epelã使ç¨ããªãããã«å¤æ´ããã
# sed -i 's/enabled=1/enabled=0/g' /etc/yum.repos.d/epel*
epelã使ãã¨ãã¯yum --enablerepo=epel ã§ãkernelçã¯ææ°ã®ãã®ãããã®ã§ãyum update ã¯ä¸è¦ã ã£ãã
ç°å¢å¤æ°çã®è¨å®
ããããã¯åèªå¥½ããªè¨å®ã§ãæä½ébash ã®rm, mv, cp ã«ç¢ºèªãããªãã-i ãã¤ãã¦ãããã
- .bash_profile
alias rm='rm -i --preserve-root' alias mv='mv -i' alias cp='cp -i'
rmã®--preseve-root(rm -rf / ãå®è¡ã§ããªããã)ã¯RHEL6ãdebainçã§ã¯defaultãªã®ã§æ示çã«æ¸ããªãã¦ããããã©ã