ã¯ããã«
ãã®å LDAP ãµã¼ããæ§ç¯ããã®ã§ãã¢ã¦ãããããããããªã¨æã£ã¦æ¸ãã¾ããã
ãã ã LDAP ãµã¼ãã¯ãªããªãä¸èº«ãè¤éã§ç解ããã¾ã§ã«æéããããã¾ãã
ããã§ãã¾ãã¯æ§ç¯ããã CentOS7 ç³»ãã£ã¹ããªãã¥ã¼ã·ã§ã³ ã§ãããã¡ãª LDAP ãµã¼ãã®æ§æã解説ãã¦ã¿ããã¨æãã¾ãã
è¨äºç®å®...10å
- ã¯ããã«
- æ§æå³
- åãµã¼ãã¨ã¤ã³ã¹ãã¼ã«ãããããã±ã¼ã¸ã«ã¤ãã¦
- 注æç¹
- ã¾ã¨ã
æ§æå³
è²ã
ãªãããè¨äºãè¦ã¾ãããã以ä¸ã®æ§æãçµãã§ãããã¨ãå¤ãã£ãã§ãã
LDAP ã§ãã使ãã®ã¯ãLDAP ã¦ã¼ã¶ã«ãã SSH æ¥ç¶ã ããã¨åæã«æ¨æ¸¬ãã¦ãè£è¶³ãã¾ããã
å½¹å²ãã¨ã«ç´°ãããµã¼ããåãã¦æ¸ãã¦ã¾ãããå®é㯠LDAP Server 㨠LDAP Manager ãåããµã¼ãã§ãããã¨ãå¤ãã§ãã
åãµã¼ãã¨ã¤ã³ã¹ãã¼ã«ãããããã±ã¼ã¸ã«ã¤ãã¦
LDAP Server ~LDAP ãã¼ã¿ã®ä¿åå ´æ~
LDAP æ¬ä½ã¨ããããå½¹å²ãæã¤ãµã¼ãã§ãã
ããªã¼å DB ã¨ãã¦ã å LDAP ã®ã¨ã³ãã£ãã£(*1) ãä¿åãã¦ãã¾ãã
*1. ã¨ã³ãã£ãã£ã«ã¤ãã¦
åè: https://docs.oracle.com/cd/E19253-01/819-0960/eypin/index.html
openldap-servers
LDAP ãµã¼ãã¨ãã¦èµ·åããããã«å¿ è¦ãªããã±ã¼ã¸ã
ã¤ã³ã¹ãã¼ã«ããã¨ãslapd ãããã»ã¹èµ·åã§ããããã«ãªããã¯ã©ã¤ã¢ã³ãããã®ã¢ã¯ã»ã¹ãåãä»ãã¾ãã
LDAP Manager ~LDAPã管çãã~
LDAP ã管çãããµã¼ãã§ããã¤ã³ã¹ãã¼ã«ããã¦ãã openldap ã³ãã³ãã使ã£ã¦ã LDAP ãµã¼ãã«æ§ã ãªæä½ãè¡ããã¨ãã§ãã¾ãã
e.g.) æä½ä¾
- ldapadd : æ°ãã LDAP ã¨ã³ãã£ãã£ã追å ãã
- ldapmodify : LDAP ã¨ã³ãã£ãã£ãä¿®æ£ãã
- ldapsearch : å種 LDAP ã¨ã³ãã£ãã£ãé²è¦§ãã
åºæ¬çã«ã¯ãLDAP ãµã¼ã ã«ã¾ã¨ãã¦ã¤ã³ã¹ãã¼ã«ãããã¨ãå¤ãã¨æãã¾ããä¸è¨ã®æ§æå³ã®ä½¿ãæ¹ã ã¨ãµã¼ããã ãã¶ãã£ãããªããããª...ã
ãã ããLDAP ã¯ã©ã¤ã¢ã³ã å´ã«å ¥ãããã¨ã¯éæ¨å¥¨ã§ãã LDAP ã¯ã©ã¤ã¢ã³ã ã«ãã°ã¤ã³ããã¦ã¼ã¶ãã LDAP ã®è¨å®å¤æ´ã ã¨ã³ãã£ãã£ã®å¤æ´ãè¡ããªã¹ã¯ãé«ã¾ãã¾ãã
openldap-client
LDAP ãµã¼ãã¨éä¿¡ããããã®ã¯ã©ã¤ã¢ã³ãããã±ã¼ã¸ã
ã¤ã³ã¹ãã¼ã«ãããã¨ã§ã LDAP ãµã¼ãã管çãã openldap ã³ãã³ãã使ããããã«ãªãã¾ãã
ããã nslcd ã¨æ··ãã£ã¦ããããããã£ã¦ãªãã¾ããã
LDAP Client ~LDAP ãµã¼ãã«åãåãããè¡ã~
LDAP ãµã¼ãã«åãåãããè¡ã ãµã¼ã群ã®ãã¨ã§ããããããåç°å¢ã§åãä¸è¬ãµã¼ããæãã¦ãã¾ãã
LDAP ãµã¼ãã¸ã®åãåãã㯠nslcd ãåãä»ãã¦ãåã·ã¹ãã ã®ä»£ããã«éä¿¡ããããªãã¾ãã
ãã¤ã³ãã¨ãã¦ã¯ãåãåãããè¡ãå ´åã ã³ãã³ãã«ãã£ã¦åãåããå ãå¤åãã¾ã (å人çã«ã¯ãããä¸çªæ··ä¹±ãã¾ãã)ã
- ssh ã³ãã³ãã®å ´å
ssh ã³ãã³ããåãä»ããã®ã¯ã sshd ã§ãããæ£ããã¦ã¼ã¶ãèªè¨¼ããæ©æ§ã¯ PAM ãè¡ã£ã¦ãã¾ãã ãããã£ã¦ PAM ã nslcd ã«åãåãããè¡ãã¾ãã - id, getent passwd ã®å ´å
id ã getent passwd ã³ãã³ãã¯ã NSS ãã³ãã³ããåãä»ãã¾ããNSS ã®è¨å®ãã¡ã¤ã«ã«ã¯ãè¨è¿°ãããåæ å ±ã®åãåããå ãè¨è¿°ããã¦ãã¾ãã
ãããã£ã¦ nslcd ã«åãåãããè¡ãã¾ãã
nss-pam-ldapd
NSS ããã³ã PAM ã LDAP ã¨é£æºããããã«å¿ è¦ãªã¢ã¸ã¥ã¼ã«ã©ã¤ãã©ãªãæä¾ããããã±ã¼ã¸ã
ã¤ã³ã¹ãã¼ã«ããã¨ãnslcd ãããã»ã¹èµ·åã§ããããã«ãªãã¾ããååããããããã§ãã
nscd
LDAP ã¸ã®åãåããæ
å ±ããã£ãã·ã¥æ©è½ãæä¾ããããã±ã¼ã¸ã§ãã
ããã«ããã nslcd ãã LDAP ãµã¼ãã¸ã® ãããã¯ã¼ã¯ãã©ãã£ãã¯éãæ¸ãããã¨ãã§ãã¾ãã
ã¤ã³ã¹ãã¼ã«ããã¨ã nscd ãããã»ã¹èµ·åã§ããããã«ãªãã ãã£ãã·ã¥æ å ±ã®åãåããå ã¨ãªãã¾ãã ååããããããã§ãã
注æç¹
ä»å¾ãRedhat ã§ã¯ã openldap-server, nss-pam-ldapd ãå©ç¨ãããã¨ã¯ éæ¨å¥¨ã«ãªãããã§ãã
åè: 9.2ã OpenLDAP Red Hat Enterprise Linux 7 | RedHatã«ã¹ã¿ãã¼ãã¼ã¿ã«
åè: 5.4. éæ¨å¥¨ã®æ©è½ Red Hat Enterprise Linux 8 | Red Hat Customer Portal
ãã®ãããã«ã¤ãã¦ã¯ã¾ãå¥éã¾ã¨ãããã¨æãã¾ãã
ã¾ã¨ã
ã¨ãããã¨ã§ã CentOS7ç³»ãã£ã¹ããªãã¥ã¼ã·ã§ã³ ã«ããã¦ãä¸çªã¡ã¸ã£ã¼ã¨æããã LDAP æ§æã«ã¤ãã¦è§£èª¬ãã¾ããã
EC2 ä¸ã«æ§ç¯ããããã°ããããæ¸ããããªãã¨æãã¾ãã
ã覧ããã ããããã¨ããããã¾ããã
è è°· æ© (è¨äºä¸è¦§)