ä»®æ³åãã¯ãããžãŒãããã«éçºããããšãããå€æ§ãªãITãã¯ãããžãŒã®å·šäººããåžå Žã«åå
¥ããŸãã Xenãããžã§ã¯ãèªäœããªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ãšããŠé·ãéååšããŠãããšããäºå®ã«ãããããããCitrix XenServerã®ãããªçµ±åãã€ããŒãã€ã¶ãŒãåãããã®ãããªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯æè¿ããšã³ã¿ãŒãã©ã€ãºã¬ãã«ã®é¡§å®¢ã®æ³šç®ãéããŠããŸãã åœåãOSã¯ããŒ/ããããšã³ãäŒæ¥ã«çŠç¹ãåããããã«ããµãŒããŒã¢ãŒããã¯ãã£ã®ã³ã¹ããæå°åããåé¡ã解決ããããšãç®çãšããŠããŸããã ããããéçºã®éçšã§ãCitrixã¯é«å¯çšæ§ãåæ§ã«Active Directoryçµ±åãªã©ã®éèŠãªãã®ããã€ããŒãã€ã¶ãŒã«çµ±åããŸããã ãããã£ãŠãçŸæç¹ã§ã¯ãVMWare ESX / ESXiã®çã®ä»£æ¿ãšããŠäœçœ®ä»ããããŠããCitrix XenServerã®åçšããŒãžã§ã³ããããŸãã ãããããåãã®ãšããããã€ããŒãã€ã¶ãŒã«ã¯ç¹å¥ãªã»ãã¥ãªãã£èŠä»¶ã課ãããŠããŸãã ããã¯ããã€ããŒãã€ã¶ãŒããã£ããã£ãããšãäŒç€Ÿãããã ãã§ãªãããã¹ãŠã®ä»®æ³ãã·ã³ã倱ãå¯èœæ§ãé«ããšããäºå®ã«ãããã®ã§ãã

ãã³ããŒã¯ãã·ã¹ãã èªäœãšHardening / Security Guideã¯ã©ã¹ããã¥ã¢ã«ã®äž¡æ¹ãèšå®ããæ¹æ³ã«é¢ããããã¥ã¡ã³ãããŸããŸããªãªãŒã¹ããŠããŸãã Citrixã¯ãCommon Criteria Security Target and User Security GuideããªãªãŒã¹ããŸããã ãããã®ããã¥ã¡ã³ãã«ã¯å€ãã®æšå¥šäºé
ãšãã³ãããããŸãããå®çšçãªæ
å ±ãå°ãªãããŸãã CCSTããã¥ã¡ã³ãã§ã¯ãä¿è·ããããªããžã§ã¯ãã®æ£åŒãªèª¬æãšå®éã®èšå®ã®æ°ãèŠã€ããããšãã§ããŸãã ãŠãŒã¶ãŒã»ãã¥ãªãã£ã§ã¯ãäŒç€Ÿã¯äžè¬çãªã·ã¹ãã ä¿è·æ¹æ³è«ã«ã€ããŠèª¬æããŸããã ãããã£ãŠãæ®å¿µãªããããã¹ãŠã®åŽé¢ãå®å
šã«ã«ããŒããå®å
šãªCitrixã»ãã¥ãªãã£ã¬ã€ããæ¬ èœããŠããŸãã
2011幎ãCitrixã¯ISSA Security Organization of the Yearã®ã¿ã€ãã«ãç²åŸããŸããã ãSecured By Designããšããçšèªã¯Citrix補åã«é©çšãããããšã匷調ãããŸããã ããããããã®äŒç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã®äžéšã¯ãã®ã«ããŽãªã«èµ·å ããå¯èœæ§ããããŸãããXenServerã®ãµãŒããŒè£œåã®èª¿æ»ã§ã¯ãèšèšã®ããã€ãã®ä»æ§ã®ååšãšãCitrixå°é家ã°ã«ãŒãã«ãããã®çšèªã®è§£éã®äžææ§ã瀺ãããŸããã ãã®èšäºã§ã¯ãCitrix Free XenServer 5.6.0ã®åäœã®ããã€ãã®åŽé¢ãšããã®ã·ã¹ãã ã®å®éã®äœ¿çšäžã«çºçããå¯èœæ§ã®ããã»ãã¥ãªãã£ã®åé¡ã«ã€ããŠèª¬æããŸãã ãã®ç¹å®ã®ããŒãžã§ã³ã®éžæã¯ãããªãé«ãæç
çãšäººæ°ã«ãããã®ã§ãã 以äžã§è¿°ã¹ãããŠããããšã®å€ãã¯ã第6ãã¡ããªã®ããŒãžã§ã³ã§å€æŽãããŠããŸããã
ãã€ããŒãã€ã¶ãŒå
šäœã®åºç€ã¯XenAPIïŒXAPIïŒã§ãã ããã¯ãã¹ãŒããŒãŠãŒã¶ãŒæš©éãæã€ã·ã¹ãã ã«ãã£ãŠå®è¡ãããããŒã¢ã³ã§ãããã·ã¹ãã èªäœãšä»®æ³ãã·ã³ã管çããããã®ã€ã³ã¿ãŒãã§ãŒã¹ãæäŸããŸãã Red Hat Enterprise Linuxãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®çŽæ¥ã®èŠªAsãšããŠããã€ããŒãã€ã¶ãŒã¯ãã®å
ç¥ããå€ãã®æšæºãœãªã¥ãŒã·ã§ã³ãç¶æ¿ããŸããã ããã¯ãXAPIãžã®æ¥ç¶ãæ
åœããPAMã¢ãžã¥ãŒã«ã§ãã
ãã®ã¢ãžã¥ãŒã«ã¯ãããã©ã«ãã§system-authã®æšæºèšå®ãå®å
šã«å«ãããã«æ§æãããŠããŸãã å®éã«ã¯ãããã¯ãã·ã¹ãã å
ã®ã¢ã«ãŠã³ããæã€ãã¹ãŠã®ãŠãŒã¶ãŒããAPIã䜿çšããŠã«ãŒããã¹ã¯ãŒããå€æŽããå Žåãé€ããpool-adminç¹æš©ã§XAPIèŠæ±ãå®è¡ã§ããããšãæå³ããŸãã ã·ã¹ãã ã®ãã®æ©èœã¯ææžåãããŠãããFreeããã³Advanceã®ããŒãžã§ã³ã«åºæã®ãã®ã§ãã Citrixã®ããªã·ãŒã«ãããšããããã®XenServerããªã¢ã³ãã䜿çšããå Žåããã·ã³ã°ã«ã¬ãã«ããŠãŒã¶ãŒïŒLSUïŒããŒã«ã«ã¹ãŒããŒãŠãŒã¶ãŒïŒïŒãæã€ã·ã¹ãã ããããŸãã Citrixã®ãã®æ±ºå®ã¯ãäŒæ¥ã¬ãã«ã®è£œåãæ§ç¯ãããšããã€ããªãã®ãŒã®æ çµã¿ã®äžã§äžè¬ã«ç解ãããŠãããšã¯æããŸããã
ãã®ç¹ç°æ§ã«ããããã€ããŒãã€ã¶ãŒããã«ããŠãŒã¶ãŒã·ã¹ãã ãšããŠäœ¿çšãããã¬ãŒã ã¯ãŒã¯ã«ããã€ãã®åé¡ãçããŸãã åºå¥ãäœæããã«ã¯ãxapiã¢ãžã¥ãŒã«ã®PAMèšå®ã調æŽããŠããã€ããŒãã€ã¶ãŒãå¶åŸ¡ã§ãã人æ°ãå¶éããå¿
èŠããããŸãã ããã«ã¯å€ãã®å¯èœæ§ããããæšæºã®PAMããŒã«ã¯ãã¹ãŠèªç±ã«äœ¿çšã§ããŸãã PAPIæ©èœã®èª¬æãšXAPIã»ãã¥ãªãã£ãæ§æããããã®ã¢ã€ãã¢ã¯ãAndrew G. MortanãšThorsten Kukukã«ãã
ãThe Linux-PAM System Administrators Guideãã«ãããŸãã
XAPIã®å¥ã®ç¹å®ã®æ©èœã¯ãã·ã¹ãã å
ã®HTTP / HTTPSãä»ãããªã¢ãŒãå¶åŸ¡ã®å¯çšæ§ã§ãã ããŒã¢ã³ã¯ã管çã€ã³ã¿ãŒãã§ãŒã¹ã§ããŒã80ããã³443ãéãããŸãŸã«ããŸãã ãã®èšäºã§ã¯ãå¶åŸ¡ãããã¯ãŒã¯ãç©ççã«åé¢ãããå¯èœæ§ãããããããã®åé¡ãããæ·±å»ã§ãªããã«ãã€ã³ã¿ãŒãã§ã€ã¹ã·ã¹ãã ã«ã€ããŠã¯èæ
®ããŸããã ããããç§ã¯ãã®ã¬ã€ã¢ãŠããå®çšŒåãœãªã¥ãŒã·ã§ã³ã«å¿
èŠã§ããããšã«æ³šæããããšæããŸãã

å€ãã®å Žåã管çã€ã³ã¿ãŒãã§ã€ã¹ã¯ãããŒã¿è»¢éãšã«ã¹ã±ãŒãä»®æ³ãã·ã³ã«ãå
±éããŠããŸãã ãããã£ãŠãSSLãã³ãã«ã䜿çšããã«ããŒã80ãå¶åŸ¡ãããšãæ»æè
ã¯å°ãªããšãã¹ããã¡ãŒã䜿çšããŠã·ã¹ãã èšå®ãååŸããã³ãŒãã®æ¿å
¥ãæåãããããå¶åŸ¡ã»ãã·ã§ã³ãæ倧éã«ååããããšãã§ããŸãã ãªãã·ã§ã³ãšããŠãiptablesãæé©ã§ãã äžè¬ã«ãã·ã¹ãã ã®80 \ 443ããŒãã«çä¿¡ãããã©ãã£ãã¯ãå¶éãã䟡å€ããããŸãã ãã®è³ªåã¯ãCitrix XenServer 5.6 Platinum Editionã®Citrix Common Criteria Evaluated Configuration Guideã§èª¬æãã䟡å€ããããŸãã
次ã®çãããå Žæãæ確ã«ããããã«ãCitrix XenServerã®ã¢ãŒã¿ãªã³ã°ã«ã€ããŠããå°ã詳ããèŠãŠã¿ãŸãããã ä»®æ³ãã·ã³ãžã®ã¢ã¯ã»ã¹ã容æã«ããããã«ããã€ããŒãã€ã¶ãŒã¯ã²ã¹ãã·ã¹ãã ã®ããã¹ã/ã°ã©ãã£ãã¯ã³ã³ãœãŒã«ã®XAPIãžã®è»¢éã䜿çšããŸãã ãããè¡ãã«ã¯ãå°ããªããã°ã©ã vnctermã䜿çšããŸãã äœæ¥ã®ã€ããªãã®ãŒã¯ã»ãŒæ¬¡ã®ãšããã§ã
ãXAPIã«ãã£ãŠã³ã³ãœãŒã«ãèŠæ±ããããšã
vnctermããã»ã¹ã®ãã©ãŒã¯ãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§
äœæãããXAPIã§ãŠãŒã¶ãŒã«éä¿¡ãããŸãã

ããã¯ããã€ããŒãã€ã¶ãŒãã¹ãèªäœãå«ããã¹ãŠã®ãã¹ãã§çºçããŸãã ããã€ãã®äŸå€ãé€ããŸãã èªèšŒã®ããã«ãã€ããŒãã€ã¶ãŒãéä¿¡ãã代ããã«ããã€ããŒãã€ã¶ãŒã®ãã¹ãã«æ¥ç¶ãããšãCitrixã®äœæè
ã³ãŒããå®è¡ãããrootãšããŠããŒã«ã«ã³ã³ãœãŒã«ã«å³åº§ã«ã¢ã¯ã»ã¹ã§ããŸãã

Active Directoryã«ãã€ã³ãããã«ãµãŒããŒäžã§XAPIã¢ã¯ã»ã¹ãæã€ãŠãŒã¶ãŒã¯ããã€ããŒãã€ã¶ãŒãã¹ããžã®ã«ãŒãã¢ã¯ã»ã¹ãååŸã§ããŸãã
vnctermã®äºæ¬¡çãªåé¡ãšããŠããã¹ãŠã®ã»ãã·ã§ã³ã1ã€ã ãã§ããããšã«æ³šæããŠãã ããã ã€ãŸããrootãšããŠã²ã¹ãã·ã¹ãã äžã«ã»ãã·ã§ã³ãäœæããã²ã¹ãã·ã¹ãã ãããã°ã¢ãŠãããããšãå¿ããããšã§ãéããŠããVNCãã£ãã«ãæ®ããŸãã ãã®ã²ã¹ãã·ã¹ãã ãžã®æ¬¡ã®èŠæ±ã§ããã¹ãŠã®XAPIãŠãŒã¶ãŒã¯åããªãŒãã³ã»ãã·ã§ã³ãåãåããŸãã ã·ã¹ãã ã®äŸµå®³ã¯é¿ããããŸããã ããŒã«ã«ãŠãŒã¶ãŒèªèšŒã¯ãèªåxsconsoleããŒãã䜿çšããmingetty âautologinã«ãŒãã§ãèªåçã«è¡ãããããšã«æ³šæããŠãã ããã

ããã¯éèŠã§ã¯ãããŸããããshã³ãŒãã泚å
¥ããããšã¯çè«çã«ã¯å¯èœã§ãã ãããã£ãŠãã·ã¹ãã ãžã®ã¹ãŒããŒãŠãŒã¶ãŒç¹æš©ã®ä»äžãå¶éããå¿
èŠããããŸãã
ã·ã¹ãã ã®å¥ã®åé¡ã®ããéšåã¯ãXenMotionã¢ãŒãã®ãµãŒããŒéã®ä»®æ³ãã·ã³ã®è»¢éã§ãã ãã¬ãŒã³ããã¹ãã¢ãŒãã§ã·ã¹ãã ã®80çªç®ã®ããŒããä»ããŠçºçããŸãã ãããã£ãŠãæ»æè
ã¯ãã®å Žã§ããŒã¿ãååããããšãã§ããŸãã ãã®åé¡ã«å¯Ÿããå¯äžã®è§£æ±ºçããããŸã-IPã¬ãã«ã®æå·åããŒã«ã®äœ¿çšã§ãã ããããããã¯ããŒã¿ã転éãããšãã®å¯äžã®åé¡ã§ã¯ãããŸãã-iSCSIãµãŒãã¹ã¯ããã©ã«ãã§ã¯ãªã¢ããã¹ãã§è³æ Œæ
å ±ãéä¿¡ããŸãã ãã®åé¡ã¯ãCHAPãã¢ã¯ãã£ãã«ããããšã§è§£æ±ºããŸãã
Citrix XenServerã¯
ãLVMã®åœ¢åŒãšVHDãã¡ã€ã«ã®åœ¢åŒã®ä»®æ³ãã·ã³ã®ããã€ãã®ã¹ãã¬ãŒãžã¢ãŒãã䜿çšã
ãŸãã LVMããŒãã£ã·ã§ã³ãŸãã¯åå¥ã®ãã¡ã€ã«ãšããŠã ã¹ãŒããŒãŠãŒã¶ãŒã®ã¿ãããŒãã£ã·ã§ã³ãããŠã³ãããæš©å©ãæã£ãŠãããããæåã®ã¢ãŒãã¯æ¡ä»¶ä»ãã§å®å
šãšèŠãªãããšãã§ããŸãã ãã ããå¥ã®ãã¡ã€ã«åœ¢åŒã®
VHDã¢ãŒãã®ã¹ãã¬ãŒãžã¯ãå¥ã®ã»ãã¥ãªãã£åé¡ã§ãã ãã¡ã€ã«ã¯ããµãŒããŒã¹ã¯ãªããrw-rrã®æšæºumaskã䜿çšããŠäœæãããŸãã ãããã£ãŠãã·ã¹ãã ã®ãã¹ãŠã®ãŠãŒã¶ãŒãä»®æ³ãã·ã³ã䜿çšã§ããŸãã ãã®åé¡ã¯ãPositive Technologies Citrix XenServer 5.6ã»ãã¥ãªãã£ã¬ã€ãã§èª¬æãããŠããã¹ã¯ãªããä¿®æ£æ¹æ³ã«ãã£ãŠè§£æ±ºãããŸãã
ã·ã¹ãã ã¯RHELã®åå«ã§ãããããyumã¢ãã€ã³ãšãšãã«RPMããã±ãŒãžç®¡çã·ã¹ãã ãç¶æ¿ããŸããã æåã¯ã·ã¹ãã ã§ãäºçŽ°ãªãyum updateããè©ŠããŠããã·ã¹ãã ã®æŽæ°ã¯åä¿¡ãããŸããã
Linuxæ§ç¯ã®æç«ãçŸããã¹ã¯ãªãŒã³ã»ãŒããŒã®åŸãã«é ããŠããããšã¯æããã§ãã åé¡ã¯ãCitrixãyumæ§æã¬ãã«ã§CentOSãªããžããªãžã®æ¥ç¶ããããã¯ããŠããããšã§ãã ãã¡ãããããããåã³æå¹ã«ããŠã·ã¹ãã ã®æŽæ°ãå®è¡ããããšã¯åé¡ã§ã¯ãããŸããã ããããCitrixãã·ã¹ãã å
ã®ããã€ãã®æšæºçãªãã®ããå³å¯ã«å¿ å®ãªãç¬èªã®ãã®ã«å€æŽãããšããäºå®ã«ããããã®ã¢ã¯ã·ã§ã³ã¯ãã€ããŒãã€ã¶ãŒã®æ©æã®äŒæ¯ã«ã€ãªãããçŸåšããŒãªã³ã°ã¢ããããŒãã¯ã·ã¹ãã ã®åŽ©å£ã«ã€ãªãããŸãã ã·ã¹ãã å
ã®äžéšã®ããã±ãŒãžã¯ãã»ãã¥ãªãã£ã¹ãã£ããŒã«ãã£ãŠé倧ãªè匱æ§ïŒdhclientãªã©ïŒããããšå®çŸ©ãããŠãããããã¢ããããŒãã®ã€ã³ã¹ããŒã«ã¯å¿
é ã«ãªããŸãã ãã®ãããªåé¡ã解決ããã«ã¯ãã»ãã¥ãªãã£ã¹ãã£ããŒãyumãdumpãå¿èãå¿
èŠã§ãã
ãç®±ããåºããŠããã«ãã·ã¹ãã ã®äžè¬çãªèšå®ãããpam_unix.soã¢ãžã¥ãŒã«ã®èšå®ã«éèŠãªãšã©ãŒãããããšã«æ³šæããããšæããŸãã å
·äœçã«ã¯ã/ etc / shadowã®ãã¹ã¯ãŒãä¿åã¢ãŒããæå¹ã«ãªã£ãŠããŸããã
ãããã£ãŠã/ etc / passwdãã¡ã€ã«ã«å¯Ÿããæšæºã®ã¢ã¯ã»ã¹èš±å¯ãäžããããŠããå Žåãã·ã¹ãã ãã¹ã¯ãŒãããã·ã¥ãžã®æœåšçãªã¢ã¯ã»ã¹ããããŸãã ããã¯ãNFSãªããžããªã䜿çšããã·ã¹ãã ã®éåæ§ã«ãé©çšãããŸãã Citrix XenServer管çã¬ã€ãã§ã¯ãNFSãµãŒããŒã§no_root_squashãªãã·ã§ã³ãèšå®ããããšããå§ãããŸãã ãã®ãããªãœãªã¥ãŒã·ã§ã³ã¯ãã€ããŒãã€ã¶ãŒã®æšæºã§ãããiptablesãªã©ã䜿çšããŠãå€éšã¹ãã¬ãŒãžããå¯èœãªéããã®ãããªã¹ãã¬ãŒãžãåé¢ããå¿
èŠããããŸãã ãŸãããã¡ããããã¡ã€ã«äœæã¢ãŒãã調æŽããã«ãŒããŠãŒã¶ãŒãç¹æ®ãªã·ã¹ãã ãŠãŒã¶ãŒã«åãããã³ã°ããå¿
èŠããããŸãã
ãããã£ãŠãå
šäœçãªçµæãèŠçŽãããšãåææ§æã®Citrix Free XenServer補åã«ã¯ãããã€ãã®æ·±å»ãªãèšèšãã»ãã¥ãªãã£åé¡ãååšããå¯èœæ§ããããŸãã ãããã®å€ãã¯RHELãã¡ããªãŒã«å
±éã®åé¡ã§ããããã®ä»ã¯ãã®ã·ã¹ãã ã«åºæã®ãã®ã§ãã ãã¡ãããCitrixã®èŠ³ç¹ããèŠããšããããã¯åé¡ã§ã¯ãªãããã€ããŒãã€ã¶ãŒã®ã¢ãŒããã¯ãã£æ©èœã§ãã ã»ãã¥ãªãã£åé¡ãšãã®OSãä¿è·ããããã®äžè¬çãªæ¹æ³è«ã«ã€ããŠã¯ããPositive TechnologiesïŒCitrix XenServerã»ãã¥ãªãã£ã¬ã€ããã§èª¬æãããŸããããã¯è¿ãå°æ¥ã«ãªãŒãã³ããŒã¿ãã¹ããè¡ââãããŸãã