ãã€ãŠãWin XPã§åäœãããã·ã³äžã§FreeBSDãå®è¡ããŠãããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãžã®ãªã¢ãŒãsshã¢ã¯ã»ã¹ã確ç«ããå¿
èŠããããŸããã
Fryushkaã§ã®äœæ¥ãOpenSSLã§ã®ããŒçæãªã©ã«ã€ããŠã¯åå¥ã®ããã¥ã¢ã«ã倿°ãããŸããããã®ç¶æ³ã«é©ããããã¥ã¢ã«ãèŠã€ãããªãã£ããããåå¥ã®æç€ºããŸãšããããšã«ããŸããã
以äžã¯ããã©ãããã©ãŒã ã®æºåããããã©ãŒãã³ã¹ãã¹ããŸã§ã®ããã»ã¹å
šäœã®èª¬æã§ãã
ããŒã1ãæºåã ãŠãŒã¶ãŒãäœæããå¿
èŠãªæš©éãä»äžããŸãã
ãŸãããã¹ãŠã®äœæ¥ã¯Fryushaã®äžã®ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã§è¡ãããŸãã
ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã«ãŠãŒã¶ãŒãããªãã£ããããæåã«äœæããå¿
èŠããããŸãã
% sudo adduser
次ã«ãããããæ¬¡ã®ããã«åçã§ãã質åã«é²ã¿ãŸãã
Username: shurchik
Full name:
çããããŸãããããã¯ãŠãŒã¶ãŒãããã¡ã€ã«ã®infaã§ãïŒã
UID (Leave empty for default):
ã·ã¹ãã èªäœã«ç©ºãèå¥åãéžæããããããã¹ãããããŸãïŒã
Login group [shurchik]: wheel
ïŒããã§ã¯ã¡ã€ã³ãŠãŒã¶ãŒã°ã«ãŒããå
¥åããŸããããã©ã«ãã§ã¯ãŠãŒã¶ãŒåãšåãã§ãããã·ã¹ãã 管çè
ãäœæããã«ã¯wheelã°ã«ãŒãã«é
眮ããããšãã
Login group [shurchik]: wheel
ããŸãïŒ
Login group is wheel. Invite shurchik into other groups?:
Login group is wheel. Invite shurchik into other groups?:
ãã®ãŠãŒã¶ãŒãä»ã®ã°ã«ãŒãã«å«ããå¿
èŠããªãããããªã¯ãšã¹ããã¹ãããããããšãã§ããŸãããã®åŸãã°ã«ãŒãã«è¿œå ããããšãã§ããŸãïŒ
Login class [default]:
ç§ãã¹ãããããŸãããçè«çã«ã¯ããã±ãŒã«ãæå®ã§ããŸã-ã¬ã€ã¢ãŠããšãŠãŒã¶ãŒèšèªããã·ã¢èªïŒã
Shell (sh csh tcsh bash nologin) [sh]: bash
ïŒããã¯ã·ã§ã«ãžã®ãªã¯ãšã¹ãã§ããããã©ã«ãã®ãŸãŸã®ã·ã§ã«ãæ®ãããšãã§ããŸããããã䟿å©ãªbashãŸãã¯zshïŒã
Home directory [/home/shurchik/]:
ãã®ããŒã ãã£ã¬ã¯ããªã
Home directory [/home/shurchik/]:
å Žåã¯EnterãæŒããããã§ãªãå Žåã¯/ home / test /ã®ããã«å¥ã®
Home directory [/home/shurchik/]:
ãæžã蟌ã¿ãŸãïŒ
Home directory permissions (Leave empty for default):
ã¢ã¯ã»ã¹æš©ã匷å¶ããããšãã§ããŸãããããã©ã«ãã§ã¯ãã¹ãŠããã®ãŸãŸã«ããŸãïŒ
Use password-based authentication? [yes]:
Use password-based authentication? [yes]:
éåžžã®æ¹æ³ã§ã¯ã·ã¹ãã ã«ãã°ã€ã³ã§ããªããããããã©ã«ãã®ãŸãŸã«ããŸãïŒã
Use an empty password? (yes/no) [no]:
Use an empty password? (yes/no) [no]:
ãã¹ã¯ãŒããªãã§å
¥åããŠãæå³ããªããããããã©ã«ãã®ãŸãŸã«ããŸãïŒã
Enter password:
ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããå
¥åããŸãããã¢ã¹ã¿ãªã¹ã¯ã䜿çšããŠããã¹ã¯ãŒãããŸã£ãã衚瀺ãããªãããšãèæ
®ããŠãã ããïŒã
Enter password again:
ããã§ããã¹ãŠãæç¢ºã§ããããããã¹ã¯ãŒããç¹°ãè¿ããŠãã ããïŒã
Lock out the account after creation [no]:
çµå±ã®ãšããããŠãŒã¶ãŒã®ãããã¡ã€ã«ã¯ç«¯æ«ã«è¡šç€ºãããåæãããã©ãããå°ããŸãïŒ
Username: shurchik
Password:******
Full name:
UID: 1010
Class:
Groups: wheel
Home directory: /home/shurchik/
Home mode:
Shell: /bin/bash
Locked: no
OK? (yes/no):
ã¯ããšå
¥åããŸã
Adduser: INFO: Successfully added (shurchik) to user database.
å¥ã®ãŠãŒã¶ãŒãäœæããæ°ãããªã¯ãšã¹ãã«å¯ŸããŠãnoãšçããŸãã
Add another user? (yes/no): no
Goodbye!
æ°ããäœæããããŠãŒã¶ãŒãsudoã®æš©å©ãæã€ããã«ã¯ãsudoersãã¡ã€ã«ã«wheelã°ã«ãŒãå
šäœãç»é²ãããããŠãŒã¶ãŒèªèº«ã®ã¿ãç»é²ããå¿
èŠããããŸãã
ããã¯æ¬¡ã®ããã«è¡ãããŸãã
ãã¡ã€ã«/ PCBSD / local / etc / sudoersã®è¡ã®ã³ã¡ã³ããå€ããŸã
% wheel ALL=(ALL) NOPASSWD: ALL
ïŒããã¯ããã¹ã¯ãŒããªãã§wheelã°ã«ãŒãã®ãã¹ãŠã®ã¡ã³ããŒãsudoïŒã¹ãŒããŒãŠãŒã¶ãŒdoïŒã«ã¢ã¯ã»ã¹ã§ããããã«ãªã£ãããšãæå³ããŸãïŒã
ïŒ sudoersãã¡ã€ã«ãžã®å€æŽã¯ãä¿ååŸããã«æå¹ã«ãªããŸãã 440ã®æš©å©ãä»äžããå¿
èŠããããŸãã
æ°ãããŠãŒã¶ãŒãšããŠãã°ã€ã³ããŸãã
% su shurchik
password:
ãã®ãŠãŒã¶ãŒã䜿çšã§ããã³ãã³ãã確èªã§ããŸãã
% sudo âl
ãã¹ãŠã®ã°ã«ãŒããšãã®ã¡ã³ããŒã®ãªã¹ãã衚瀺ã§ããŸãïŒ
% less /etc/group
ããŒã2ãã¡ã€ã³ã sshdããŒã¢ã³ã®åäœãæ§æããŸãã
ç§å¯éµãšå
¬ééµã®çæã
ç§ã¯Opensshããã°ã©ã ã§åããŸãã
1. sshããã°ã©ã ã®ã»ããã¢ããã²ãŒããŠã§ã€ã®ããŒã22ãéããŸãã
æåã«ãããŒã¢ã³ããµãŒããŒã§å®è¡ãããŠãããã©ããã確èªããŸãã ïŒsshããŒã¢ã³ã¯sshdã§ãïŒ
æ¹æ³ïŒ
% ps auwx | grep sshd
ãŸãã¯
% sockstat -4l | grep :22
衚瀺ãããå ŽåïŒ
sshd âŠtcp4 :22
ããŒã22ããªãã¹ã³ããŠããããšãæå³ããŸãïŒããã©ã«ãã§ã¯ãsshã¯ãã®ããŒããééããŸãïŒ
ããŒãããªãã¹ã³ããŠããªãå ŽåãsshããŒã¢ã³ã¯å®è¡ãããŠããŸããã
ãŸãã¯ãåã«ã³ãã³ããäžããããšãã§ããŸãïŒ
% sudo /etc/rc.d/sshd start
æªæ
ãã€ããããæ§æãã¡ã€ã«ã倿Žããå¿
èŠããããŸãã
次ã«ãrc.conf.localæ§æãã¡ã€ã«ã«ç§»åããŸãïŒ/ etcã«ãããŸãïŒã ãŸã äœæãããŠããªãå Žåã¯ãäœæããŠããã«sshd_enable =â YESâãèšè¿°ããŸãã ïŒä»£ããã«ãåã«rc.confã«åãè¡ãæžãããšãã§ããŸããïŒ
ããã¯ãstartã³ãã³ãã§sshããŒã¢ã³ãèµ·åã§ããããã«ããããã«å¿
èŠã§ãã 倿Žã¯ããã«æå¹ã«ãªããŸãã
ããäžåºŠãssh startã³ãã³ããå®è¡ããŸãã
% sudo /etc/rc.d/sshd start
ãéå§
% sudo /etc/rc.d/sshd start
å¿
èŠããããŸãã
次ã«ãããŒã22ããªãã¹ã³ããŠãããã©ãããããäžåºŠç¢ºèªããŸãã
% sockstat -4l | grep :22
åºåããå¿
èŠããããŸãïŒ
sshd âŠtcp4 :22
ããã«ãããšãã°ãlocalhostã«æ¥ç¶ããã³ãã³ããæå®ã§ããŸãã
% ssh localhost
æ¥ç¶ãæåŠãããå Žåãsshã¯å®è¡ãããŠããŸããã ãããŠãããäžåºŠèšå®ã確èªããå¿
èŠããããŸãã
2.ããŒçæããŒãçæããã³ãã³ããæäŸããŸãã
% ssh-keygen
ããã©ã«ãã®æå·åæ¹åŒã¯rsaã§ãã ããšãã°ãdsaæå·åæ¹åŒãçæããã«ã¯ã
% ssh-keygen ât dsa
ãšèšãå¿
èŠããããŸãã
ç§å¯éµ/å
¬ééµã®ãã¢ã®çæãå§ãŸããŸãã
èšãã§ãããïŒ
Enter passphrase:
ã§ããã°é·ããŠè€éïŒ
ããŒã¯ã/ .sshãã£ã¬ã¯ããªïŒ/home/shurchik/.sshïŒã«çæãããŸãã
次ã«ãããã«ãããã®ã確èªããŸãããã
% ls âl ~/.ssh
id_rsaã¯ç§å¯éµã§ãïŒããšãã°ãrsaãšã ãåŒã¶ããšãã§ããŸãïŒã
id_rsa.pubã¯å
¬éããŒã§ãïŒããšãã°ãrsa.pubãšåŒã¶ããšãã§ããŸãïŒã
次ã«ãåãããããæ¹æ³ã§å
¬éããŒããµãŒããŒã«é
眮ããå¿
èŠããããŸãã ãããè¡ãã«ã¯ã次ãå®è¡ããŸãã
id_rsa.pubãã¡ã€ã«ã®å
容ãauthorized_keysãã¡ã€ã«ã®å
容ã«è¿œå ããŸãã
ããã¯æ¬¡ã®ã³ãã³ãã§å®è¡ãããŸãã
% cat id_rsa.pub >> authorized_keys
id_rsa.pubã®å
容ãauthorized_keysãã¡ã€ã«ã®æåŸã«è¿œå ããŸãã ããã§ãªãå Žåã¯ãäœæããŸãã catã¯é£çµã®ç¥ã§ãã
authorized_keysãã¡ã€ã«ããŸã£ãããªãå Žåã¯ãid_rsa.pubãã³ããŒããŠäœæã§ããŸãã
% cp id_rsa.pub authorized_keys
.sshãã©ã«ããŒã®å
容ãå床確èªããŸãã
% ls âl ~/.ssh
ïŒãã®ãããªãã®ã§ãªããã°ãªããŸããïŒ
id_rsa
id_rsa.pub
authorized_keys
ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã«authorized_keysãã¡ã€ã«ãæ®ããid_rsaãšid_rsa.pubãå¥ã®å Žæã«ä¿åããŠãã/ .sshãã©ã«ããŒããåé€ããŸãã ãã以å€ã®å Žåã¯ãã¹ãŠãåçæããå¿
èŠããããããå
¬ééµãçŽå€±ããªãããšãéèŠã§ãã
ãããŠæåŸã«ããªã¢ãŒããã·ã³äžã®ãã¹ãåãèŠã€ããŸãïŒsshãä»ããŠæ¥ç¶ããå Žåã«å¿
èŠã§ãïŒããã®åŸã皌åäžã®ã³ã³ãã¥ãŒã¿ãŒã«ç§»åããæ¢ã«ãã¹ããèŠãããŸãã
% hostname
testhost
ããã§ãã³ã³ãã¥ãŒã¿ãŒã®IPã¢ãã¬ã¹ãèŠã€ããŸãã
% host testhost
ïŒæ³šïŒFreeBsd7ã¯ãPuttyãšäºææ§ã®ããdes-encryptionæ¹åŒã䜿çšããŸãã ãã ããFreeBsd9ã¯ãã§ã«å¥ã®æå·åæ¹åŒã䜿çšããŠããããããã®ããã°ã©ã ã§ã¯èªèãããŸããã ãããã£ãŠããã®å Žåãputty-genããã°ã©ã èªäœã«ãã§ã«ããŒãçæããããããUnixãçè§£ã§ãã圢åŒã«å€æããå¿
èŠããããŸãã
3.ç§å¯éµãPuttyãçè§£ã§ãã圢åŒã«å€æããŸããïŒWindowsã®å ŽåïŒ
Puttyããã°ã©ã ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸãã æ°ããçæãããããŒãWindowsãã·ã³ã«æã¡èŸŒã¿ãŸãã Puttyã¯ã1ã€ã®åœ¢åŒïŒ=ïŒ.ppkã®ããŒã®ã¿ãçè§£ããŸã
Putty-genããã°ã©ã ãå®è¡ããŸãïŒã¡ã€ã³ãšåæã«ãŸãã¯åå¥ã«ã€ã³ã¹ããŒã«ãããŸãïŒã
aã ãã¡ã€ã«èªã¿èŸŒã¿ç§å¯éµïŒç§å¯éµãå¿
èŠãªçšŒåäžã®ãã·ã³ã«Puttyãã€ã³ã¹ããŒã«ãããŠããããã倿ããŸããïŒ
bã ç§å¯éµãä¿åããŸãïŒäŸïŒid_rsa.ppkïŒ
ããŒã3ãå³mnã Puttyãæ§æããæå·åããããªã¢ãŒãæ¥ç¶ã確ç«ããŸãã
1. Puttyãå®è¡ããŸããèšå®ã¯æ¬¡ã®ãšããã§ãã
ã»ãã·ã§ã³ïŒãã¹ãåtesthostïŒãŸãã¯ipïŒ
ãã°ïŒä»»æã®ãã°ããªãã·ã§ã³ã®+ããŒã¯ã¯åžžã«ãã°ãäžæžãïŒãŸãã¯æ«å°Ÿã«è¿œå ïŒããæ¯åãã°ãæžãæãããã©ãããå°ããªãããã«ããŸãã
ãŠã£ã³ããŠïŒç¿»èš³utf-8
æ¥ç¶ïŒèªåãã°ã€ã³ãŠãŒã¶ãŒåshurchik
SSHïŒåç
§... id_rsa.ppkãã¡ã€ã«ãžã®ãã¹ãæå®ããŸãïŒã©ãã§ãããŸããŸããããããã¯ãŸã£ããç¡é¢å¿ã§ããã©ãã§å
¥æã§ããŸãããïŒ
ãããŠä»ããã¹ãŠãä¿åããŸãã
ã»ãã·ã§ã³ïŒä¿åãããã»ãã·ã§ã³ïŒæ°èŠïŒãã®ã»ãã·ã§ã³ã®ååãèšå®ïŒã[ä¿å]ãã¯ãªãã¯ãããšãæ°ããã»ãã·ã§ã³ããªã¹ãã«è¡šç€ºãããŸãã
åŸã§ãã¹ãŠãèšå®ããã«åŒã³åºãã«ã¯ãPuttyãèµ·åããåŸããªã¹ããããnewããéžæããŠãLoadããæŒããŸãã
[éã]ãã¯ãªãã¯ãããšãã¿ãŒããã«ãéãããã¹ãã¬ãŒãºã®å
¥åãæ±ããããŸãã
ããŒã«åé¡ãçºçããå Žåãæªæ
ãã€ãããã°ã©ã ã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãïŒshurchikãšãã¹ã¯ãŒãïŒãèŠæ±ããŸãã
2.æçµçã«ããã°ã€ã³ãã¹ã¯ãŒãã䜿çšãããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãžã®æå·åãããæ¥ç¶ãžã®ã¢ã¯ã»ã¹ãçŠæ¢ã§ããŸã ïŒãã¹ãã¬ãŒãºæ¥ç¶ã®ã¿
ãèš±å¯ããŸãïŒã
ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã§ãsshæ§æãã¡ã€ã«ã«ç§»åããŸãã
/ etc / ssh / sshd_configã
ããã§ã次ã®è¡ã远å ïŒãŸãã¯ã³ã¡ã³ãè§£é€ïŒããå¿
èŠããããŸãã
UsePAMçªå·
次ã«ãsshãåèµ·åããå¿
èŠããããŸãã
% sudo /etc/rc.d/sshd stop
% sudo /etc/rc.d/sshd start
ããã ãã§ãïŒ