ç°ãªããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšãããããã¯ãŒã¯ã§ãã¡ã€ã³èªèšŒã䜿çšããå Žåãšäœ¿çšããªãå Žåã®CUPSããªã³ããµãŒããŒã®ãŒãããã®ã»ããã¢ãã
ãšã³ããªãŒ
ã ããã ãããããCUPSå°å·ãµãŒãã¹ã¯ãäŒæ¥å
ã§äžå
çãªããªã³ã¿ãŒç®¡çãçµç¹ã§ãã匷åãªãœãªã¥ãŒã·ã§ã³ã§ãã ã§ããããã»ããã¢ããããã»ã¹äžã«ãç¹ã«æšæºã®ã»ããã¢ããããã¥ã¢ã«ãè¶
ããããŒãºãããå Žåã¯ãGoogleã®å€ãã®å°ããªæçœã§ãªãåé¡ã®è§£æ±ºçãæ¢ãããã«æéãè²»ããå¿
èŠããããŸãã
ãã®èšäºã§ã¯ã皌åäžã®Active Directoryãã¡ã€ã³ãæã€ãããã¯ãŒã¯äžã®UbuntuãµãŒããŒãžã®CUPSããªã³ããµãŒããŒã®ã€ã³ã¹ããŒã«ã«ã€ããŠèª¬æããŸããããã®ååšã¯å®å
šã«ãªãã·ã§ã³ã§ãããçžäºäœçšã®ã»ããã¢ãããã»ããã¢ãããããã³çžäºäœçšããLinuxããã³Windowsã¯ã©ã€ã¢ã³ããã·ã³ã®ã»ããã¢ããã®æé ãå®å
šã«ã¹ãããã§ããŸããã®ããªã³ããµãŒããŒã
æé ã§ã¯ããã¡ã€ã³ã¯example.comãšããååã«ãªããããªã³ããµãŒããŒèªäœã¯IPã¢ãã¬ã¹10.10.100.50ã®cupsserver ïŒ cupsserver.example.com ïŒã«ãªããŸããã¯ã©ã€ã¢ã³ããã·ã³linux1 ã linux2 ã linux3ãªã©ãã¯ã©ã€ã¢ã³ããã·ã³Linuxããã³windows1 ã windows2 ã windows3ããã³ãªã© ããããWindowsã¯ã©ã€ã¢ã³ããã·ã³çšã
ããªã³ããµãŒããŒã®ã»ããã¢ãã
ãŸããããªã³ããµãŒããŒãæ§æããŸãããŸãã¯ãããªã³ããµãŒããŒãžã®ç®¡çã¢ã¯ã»ã¹ãæ§æããŠããããã®äžã§å°å·ãæ§æããã¯ã©ã€ã¢ã³ããã·ã³ã®æ§æã«ã€ããŠèª¬æããŸãã
䟿å©ãªæ¹æ³ã§ããªã³ããµãŒããŒã«ã¢ã¯ã»ã¹ãããã®ããã±ãŒãžãæŽæ°ããŸãã
root@cupsserver:~# apt update && apt uprgrade -y
次ã«ãCUPSããµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠãããã©ããã確èªããŸãã
root@cupsserver:~# which cupsd
åºåãæ¬¡ã®ãããªå ŽåïŒ
/usr/bin/cupsd
次ã«CUPSãã€ã³ã¹ããŒã«ãããŸããåºåããªãå Žåã¯ãCUPSãã€ã³ã¹ããŒã«ããŸãã
root@cupsserver:~# apt install cups -y
次ã«ãCUPS Webã€ã³ã¿ãŒãã§ãŒã¹ãžã®ç®¡çã¢ã¯ã»ã¹ãèšå®ããŸãã ãã¹ãŠã®æ§æãã¡ã€ã«ã¯ããã¹/ etc / cups /ã«ãããŸãã ãŸãã念ã®ãããã¡ã€ã³ã®CUPSæ§æãã¡ã€ã«ãããã¯ã¢ããããŸãã
root@cupsserver:~# cp /etc/cups/cupsd.conf /etc/cups/cupsd.conf.original root@cupsserver:~# cp /etc/cups/cups-files.conf /etc/cups/cups-files.conf.original root@cupsserver:~# cp /etc/cups/cups-browsed.conf /etc/cups/cups-browsed.conf.original
ãã ãããããè¡ããªãã£ãå Žå-ããã©ã«ãã§ã¯ããããã®ãã¡ã€ã«ã®ãµã³ãã«ã¯ãã¹/ usr / share / cupsã«ãããŸãã æ¬¡ã®ã³ãã³ãã䜿çšããŠãCUPSæ§æãã¡ã€ã«ã«è¿œå ããããªãã·ã§ã³ã確èªã§ããããšã«ãèšåããŠãã ããã
root@cupsserver:~# cupsd -t
äœããå°ç¡ãã«ããããå°å°ããããCUPSã§ãµããŒããããªããªã£ããªãã·ã§ã³ã䜿çšããå Žåãã³ãã³ãã®åºåã«ã¯ãããã®ãšã©ãŒãåæ ãããŸãã
ãããæåŸã«ãã»ããã¢ããã«åãããããŸãããã / etc / cups /ãã©ã«ããŒå
ã®ãã¡ã€ã«ã倿ŽããããCUPSãµãŒãã¹ãåèµ·åããŠå¹æãåŸãå¿
èŠããããŸãã
root@cupsserver:~# service cups restart root@cupsserver:~# systemctl restart cups root@cupsserver:~# /etc/init.d/cups restart
ãŸãããã¡ã€ã«/etc/cups/cups-browsed.confãç·šéããå Žåãå¥ã®cups- browsedãµãŒãã¹ããã®ãã¡ã€ã«ãåŠçããŸããããããåèµ·åããå¿
èŠããããŸãã
root@cupsserver:~# service cups-browsed restart root@cupsserver:~# systemctl restart cups-browsed root@cupsserver:~# /etc/init.d/cups-browsed restart
ã³ãã³ããå®è¡ãã
root@cupsserver:~# nano /etc/cups/cupsd.conf
æåã®éã³ã¡ã³ãåãªãã·ã§ã³ã¯
LogLevel warn
CUPSãã°ã®æå°éã®æ
å ±å
å®¹ãæ±ºå®ããŸãã CUPSãã°ãã¡ã€ã«ã¯/ var / log / cups /ã«ãããŸãã ããªã³ããµãŒããŒã®ã€ã³ã¹ããŒã«ãèšå®ãããã³ãããã°æã«ããã°ããããã°ã¢ãŒãã«ããã®ãè³¢æã§ãã ãããè¡ãã«ã¯ãwarnãdebug2ã«å€æŽããŸãã
LogLevel debug2
ããã©ã«ãã§ã¯ãCUPSã¯localhostããã®çä¿¡æ¥ç¶ãã€ãŸãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ã¿ããªãã¹ã³ããŸãã ããã確èªããã«ã¯ã次ã®ã³ãã³ããå®è¡ã§ããŸã
root@cupsserver:~# netstat -plutn
è¡ã®1ã€ã¯æ¬¡ã®ããã«ãªããŸãã
tcp 0 0 127.0.0.1:631 0.0.0.0:* LISTEN 737/cupsd
ãããªãè¡åã¯ãããªãã®åŠæ³ã®çšåºŠã«äŸåããŸãã ãããã¯ã«è¿œå ã§ããŸãããã®ãããã¯ã¯ãæ¡ä»¶ä»ãã§ã³ã¡ã³ã#Onlyã§å§ãŸããããŒã«ã«ãã·ã³ããã®æ¥ç¶ããªãã¹ã³ããŸããCUPSãæ¥ç¶ããªãã¹ã³ã§ããIPã¢ãã¬ã¹ãŸãã¯ãµãããããæã€è€æ°ã®è¡ããªãã¹ã³ããŸãã
# Only listen for connections from the local machine. Listen localhost:631 Listen /run/cups/cups.sock # IP Listen 10.10.100.67:631 # Listen 172.16.0.0:631
ãŸãã¯ãCUPSããã¹ãŠã®ã¢ãã¬ã¹ããã®æ¥ç¶ããªãã¹ã³ã§ããããã«ããããšãã§ããŸã
# Only listen for connections from the local machine. Listen /run/cups/cups.sock Port 631
èšå®ã®æ¬¡ã®ãã€ã³ãã¯ããããã¯ãŒã¯ããã³å
±æããªã³ã¿ãŒã®æ€åºã§ãã
# Show shared printers on the local network. Browsing Off BrowseLocalProtocols dnssd
ç§ã®æèŠã§ã¯ããã®ãªãã·ã§ã³ã¯ãããªã³ããµãŒããŒã«æ¥ç¶ãããŠããããªã³ã¿ã«é¢ãããããŒããã£ã¹ãæ
å ±ããããã¯ãŒã¯çµç±ã§éä¿¡ãããã©ãããæ±ºå®ããããããªãã®ãŸãŸã«ããŠããå¿
èŠããããŸãã ãããã圌ãã¯ãã¹ãŠããã«æ¥ç¶ãããŸãã ããã«å¿ããŠããã¹ãŠã®ã¯ã©ã€ã¢ã³ããã·ã³ã«ãã¹ãŠã®ããªã³ã¿ãŒãããã«è¡šç€ºãããŸãã ããªã³ããµãŒããŒã¯ããããã¯ãŒã¯äžã®ãã¹ãŠã®ããªã³ã¿ãŒãæ€çŽ¢ããã³æ€åºããå¿
èŠããããŸããããããã¯ãŒã¯å
šäœã«ç¡é äœã«éä¿¡ããªãã§ãã ããã
èªèšŒèšå®ã¯æ¬¡ã®ãšããã§ãã
# Default authentication type, when authentication is required... DefaultAuthType Basic
CUPS Webã€ã³ã¿ãŒãã§ãŒã¹ãšãã®ç®¡çéšåãžã®ã¢ã¯ã»ã¹æš©ãå®çŸ©ããŸãã ãŠãŒã¶ãŒuserã« CUPSã管çããæš©å©ãä»äžããã«ã¯ã lpadminã·ã¹ãã ã°ã«ãŒãã«è¿œå ããå¿
èŠããããŸãã
root@cupsserver:~# usermod -a -G lpadmin user
äžè¬ã«ãCUPSãžã®ç®¡çã¢ã¯ã»ã¹ãèš±å¯ãããã°ã«ãŒãã¯ããããã¯å
ã®èšå®ãã¡ã€ã«cups-files.confã§å®çŸ©ãããŸã
# Administrator user group, used to match @SYSTEM in cupsd.conf policy rules... # This cannot contain the Group value for security reasons... SystemGroup lpadmin
printadminsãªã©ã®ããªã³ããµãŒããŒã管çããæš©éãLinuxãŠãŒã¶ãŒã®ç¹å®ã®ã°ã«ãŒãã«è¿œå ããå Žåã¯ã lpadminã«ã¹ããŒã¹ãå
¥ããŠè¿œå ããŸã ã ã°ã«ãŒãããã¡ã€ã³ã®å Žåãããã¯ããå°ãè€éã§ãããåŸã§èª¬æããŸãã
次ã«ã <Location />ãããã¯ã«é²ã¿ãŸãããã
# Restrict access to the server... <Location /> Order allow,deny </Location>
èš±å¯ãæåŠã¯ãèš±å¯ãç¹ã«ç€ºãããŠããªãéããã©ãããã®æ¥ç¶ãçŠæ¢ãããããšãæå³ããŸãã ã€ãŸããIPã¢ãã¬ã¹ããµããããããã¹ãããŸãã¯ãã¹ãããã¹ã¯ïŒ .example.com ïŒã§ã Allow from [allowed address] *ã ã®åœ¢åŒã§è¿œå ããå¿
èŠããããŸãã
# Restrict access to the server... <Location /> Order allow,deny Allow from cupsserver # Allow from cupsserver.example.com # FQDN Allow from localhost # loopback Allow from 10.10.100.* # Allow from linux4.example.com # Allow from 172.168.5.125 # , IP </Location>
å®å
šãªä¿¡é Œãšãããã°ã®ããã«ãä»ã®ãã¹ãŠãèšå®ãããŸã§ãã©ãããã§ãå°å·ã§ãããããªèšèšã®ãŸãŸã«ããŠããããšãã§ããŸãã
# Restrict access to the server... <Location /> Order allow,deny Allow from all </Location>
ããªã³ããµãŒããŒã§CUPSãžã®ç®¡çã¢ã¯ã»ã¹ãèšå®ããŸãããã CUPSããæ¥ç¶ããIPããµãããããæ±ºå®ãããããã<Location />ãããã¯ãšåæ§ã«è¿œå ããŸãã
# Restrict access to the admin pages... <Location /admin> Order allow,deny Allow from localhost Allow from 10.10.100.* Allow from admin.example.com </Location> # Restrict access to configuration files... <Location /admin/conf> Order allow,deny Allow from localhost Allow from 10.10.100.* Allow from admin.example.com </Location> # Restrict access to log files... <Location /admin/log> Order allow,deny Allow from localhost Allow from 10.10.100.* Allow from admin.example.com </Location>
ãŸããå¿
èŠã«å¿ããŠãããã©ã«ãã®ã€ã³ã¿ãŒãã§ãŒã¹èšèªã远å ã§ããŸãã 䜿çšå¯èœãªèšèªã®ãªã¹ãã¯ã次ã®ã³ãã³ãã䜿çšããŠè¡šç€ºã§ããŸãã
root@cupsserver:~# ls /usr/share/cups/locale
å¿
èŠãªããŒã«ã©ã€ãºïŒ ruãªã©ïŒã®å Žåã /etc / cups / cupsd.confã«è¡ã远å ããŸã ã
DefaultLanguage ru
ãã¹ãïŒãã¹ãåïŒ ããããªã³ããµãŒããŒcupsserver.example.comã«ã¢ã¯ã»ã¹ããã«ã¯ã / etc / cups /ãã©ã«ããŒã«æ¬¡ã®å
容ã®client.confãã¡ã€ã«ãäœæããå¿
èŠããããŸãã
ServerName _
æãç°¡åãªæ¹æ³ã§ã¯ãããã¯æ¬¡ã®ããã«å®è¡ã§ããŸãã
root@cupsserver:/etc/cups# echo "ServerName $(cat /etc/hostname)" > /etc/cups/client.conf
ãããã¯ãŒã¯å
ã«DNSãµãŒããŒããããšæ³å®ããŠããããããã¡ã€ã³åïŒ cupsserver.example.com ïŒã§ããªã³ããµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããšãæãŸããã§ãããã ãµãŒããŒã«ã¯ãDNSãµãŒããŒäžã®printãcupsãªã©ã®CNAMEãšã€ãªã¢ã¹ãå²ãåœãŠãããšãã§ããŸãã ããªã³ããµãŒããŒããã®ãããªåŒã³åºãã§æ¥ç¶ãåãå
¥ããããã«ããã«ã¯ã / etc / cups / cupsd.confãã¡ã€ã«ã«æ¬¡ã®è¡ã远å ããå¿
èŠããããŸãã
ServerAlias cupsserver.example.com print cups
ããªã³ããµãŒããŒãåŒã³åºããåãå
¥ããããã«ããå ŽåããŸãã¯ããããããããªãå Žåã¯ãããã远å ã§ããŸãã
ServerAlias *
ãŸãã / etc / cups / cups-browsed.confãã¡ã€ã«ã確èªããå¿
èŠããããŸãã ãã®ãã¡ã€ã«ã¯ãããªã³ããµãŒããŒããããã¯ãŒã¯äžã®ããªã³ã¿ãŒãæ€çŽ¢ãããã®ããªã³ã¿ãŒããããŒããã£ã¹ãããæ¹æ³ãå¶åŸ¡ããŸãã ãã¥ãŒã¹ã¬ã¿ãŒãªãã·ã§ã³ãå®å
šã«ç¡å¹ã«ããããšããå§ãããŸãã ããªã³ããµãŒããŒã¯ãããã¯ãŒã¯äžã®ããªã³ã¿ãŒãæ€çŽ¢ããŸãããããªã³ã¿ãŒããã¯ã©ã€ã¢ã³ããã·ã³ãžã¯æåã§æ¥ç¶ãããŸãã 以äžã«ãã®çç±ã説æããŸãã ãããŸã§ã®éã BrowseRemoteProtocols dnssd cupsãšããè¡ãèŠã€ããŸãã
# Which protocols will we use to discover printers on the network? # Can use DNSSD and/or CUPS and/or LDAP, or 'none' for neither. BrowseRemoteProtocols dnssd cups
ãã®ãªãã·ã§ã³ã«ãããããªã³ããµãŒããŒã¯ãããã¯ãŒã¯äžã®å
±æããªã³ã¿ãŒãæ€çŽ¢ããŸãã ããªã³ããµãŒããŒããããã¯ãŒã¯äžã®ããªã³ã¿ãŒãæ€çŽ¢ããããšãç§ãã¡ã®å©çã§ããããããªã³ã®ãŸãŸã«ããŸãã ããããæ¥ç¶ãããŠãããã¹ãŠã®ããªã³ã¿ãŒãéä¿¡ããããã«ããªã³ããµãŒããŒã¯çµ¶å¯Ÿã«å¿
èŠãããŸãããããããªããšãå€ãã®æ··ä¹±ãçããŸãã ãã®ã·ããªãªãåé¿ããã«ã¯ã次ã®#BrowseLocalProtocols noneãªãã·ã§ã³ãèŠã€ããŠã³ã¡ã³ãè§£é€ããŸãã
# Which protocols will we use to broadcast shared local printers to the network? # Can use DNSSD and/or CUPS, or 'none' for neither. # Only CUPS is actually supported, as DNSSD is done by CUPS itself (we ignore DNSSD in this directive). BrowseLocalProtocols none
ããã§ãããªã³ããµãŒããŒã®æ§æãäžæããWindowsããã³Linuxã®ã¯ã©ã€ã¢ã³ããã·ã³ã®æ§æã«é²ã¿ãŸãã ãããã®èŠä»¶ã¯æ¬¡ã®ãšããã§ããå°å·ãžã§ããããªã³ããµãŒããŒã«éä¿¡ã§ããããã«ãããããã¯ãŒã¯ããªã³ã¿ãŒã«å°å·ããå¿
èŠãããå Žåã«ã®ã¿ïŒããã³ïŒããªã³ããµãŒããŒã«å°å·ãžã§ããéä¿¡ããŸãã
äŸãšããŠãããããLinuxïŒãã¹ãålinux1 ïŒãšWindows 8ïŒãã¹ãåwindows1 ïŒãæã€2å°ã®ã¯ã©ã€ã¢ã³ããã·ã³éã®ããªã³ããµãŒããŒãä»ããå°å·ãèšå®ããŸãã ãŸãã windows1ãããªã³ããµãŒããŒããã®ããªã³ãã¬ã·ãŒããŒãšããŠèšå®ããŸãã Canon i-SENSYS MF4410ããªã³ã¿ãŒãæ¥ç¶ãããæ£åžžã«åäœããŠããŸãã ããªã³ã¿ãŒåã¯Canon-MF4400ã§ãã å®éã windows1ã®ããªã³ããµãŒããŒããã®å°å·ãä¿èšŒããæãç°¡åãªæ¹æ³ã¯ã [ã³ã³ãããŒã«ããã«]> [ããã°ã©ã ]> [ããã°ã©ã ãšæ©èœ]> [Windowsã®æ©èœã® æå¹å ãŸãã¯ç¡å¹å]ã«ç§»åããããšã§ãã ããã§ãPrint and Document Services> LPD Print Serviceã³ã³ããŒãã³ãããªã³ã«ããŸãã ããã«ããã lpdïŒ// windows1 / Canon-MF4400 addressã䜿çšããŠãã®ããªã³ã¿ãŒãããªã³ããµãŒããŒã«æ¥ç¶ã§ããŸãã ãã¡ãããåé¡ã¯æçããŠããŸããSMBã䜿çšããŠæ¥ç¶ããŠã¿ãŸãããã 誰ãçŠæ¢ããŠããŸããã ãã®æ¹æ³ããããã°ããå Žåã¯ããã®æ¹æ³ã§ããªã³ã¿ãŒãå
±æããSMBãããã³ã«ã䜿çšããŠããªã³ã¿ãŒãããªã³ããµãŒããŒã«æ¥ç¶ã§ããŸãã ç§ã®æèŠã§ã¯ããã®æ¥ç¶ã®æé ã¯ãã®èšäºã®ç¯å²å€ã§ããããã§ã«ããªãèšå€§ã§ãã ãããŸã§ã®éãèªè
ã¯http://cupsserver:631/admin
ã®ã¢ãã¬ã¹ã«æ£åžžã«http://cupsserver:631/admin
ãããæ°ããããªã³ã¿ãŒã®è¿œå ããã¿ã³ãã¯ãªãã¯ããçŽæãããžãã¯ãããã³å
ã«èªãã ããã¥ã¢ã«ã«åŸã£ãŠ ã LPDçµç±ã§ããªã³ã¿ãŒãcupsserverã«æ£åžžã«æ¥ç¶ãããšèããŠããŸã[äŸã com]ããã³ããªã³ã¿ããŒãžã¯http://cupsserver:631/printers/Canon-MF4400
å©çšã§ããŸãã
ããã§ããã¹ãåãlinux1ã® Linuxã¯ã©ã€ã¢ã³ããã·ã³ã§åæ§ã®æäœãå®è¡ããŸãã äžè¬ã«ãã¯ã©ã€ã¢ã³ããã·ã³ã«ã¯ç¬èªã®CUPSãµãŒãã¹ããããå°å·ã®æŽçã«ãããåŸå±çãªåœ¹å²ãé€ããŠãããªã³ããµãŒããŒãšã»ãŒåãæ¹æ³ã§æ§æããå¿
èŠãããããããã®éšåã¯ã¯ããã«å€§ãããªããŸãã
ãã¹ãåã«ããã«ãŒãããã¯ãä»ããCUPSãžã®ã¢ã¯ã»ã¹ãšã©ãŒã®ä¿®æ£
äžå¿«ãªç¬éããããŸãã linux1ããã¡ã€ã³ã«å
¥åãããããã®æç€ºã«åŸã£ãŠCUPSãæ§æãããšãå€éšããlinux1 WEBã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ã¯ã»ã¹ã§ãããããã¹ãèªäœã§ãããå®è¡ã§ããªããšããäžæ¡çãªç¶æ³ã«æ°ä»ããããããŸããïŒ ãŸããLinux Mintã®system-config-printerã¢ããªã±ãŒã·ã§ã³ãªã©ãããŒã«ã«ã§ããªã³ã¿ãŒãæ§æããããã®ã°ã©ãã£ã«ã«ã¢ããªã±ãŒã·ã§ã³ã¯åäœããŸãã ã ã¢ãã¬ã¹http://linux1:631/
ã§ç¬èªã®CUPSã«æ¥ç¶ããããšãããšããForbiddenããŸãã¯ãBad Requestããšããã¡ãã»ãŒãžã衚瀺ãããŸãã ããã¯ããç¥ãããåé¡ã§ãããå€ãã®ã€ã³ã¿ãŒããããã©ãŒã©ã ã§å®éã«è§£æ±ºãããŠããªãåé¡ã§ãã
Linuxããã¡ã€ã³ã«å°å
¥ããéã®ã»ãšãã©ã®æé ã§ã¯ããã€ã³ãã®1ã€ã¯/ etc / hostsãã¡ã€ã«ã次ã®ããã«ããããšã§ãã
127.0.0.1 localhost 127.0.1.1 linux1.example.com linux1 # The following lines are desirable for IPv6 capable hosts ::1 ip6-localhost ip6-loopback fe02::2 ip6-localnet ff00::0 ip6-mcastprefix ff02::1 ip6-allnodes ff02::2 ip6-allrouters
äœããã®çç±ã§ãCUPSã¯127.0.1.1ãä»ããŠãã€ãŸãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠããã¹ãåã«ã³ãŒã«ãé¢é£ä»ããããšãã§ããŸããã
ãã®ãšã©ãŒã¯2ã€ã®æ¹æ³ã§ä¿®æ£ãããŸãã ãããã¯ãŒã¯IPã¢ãã¬ã¹ãéçãªå Žåã¯ã / etc / hostsãã¡ã€ã«ã§ãã¯ã©ã€ã¢ã³ããã·ã³ã®å€éšãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ã127.0.1.1 ã«ä¿®æ£ããŸããæ¬¡ã«äŸã瀺ããŸãã
127.0.0.1 localhost 192.168.1.50 linux1.example.com linux1
ãŸãã¯ãLinuxããã¡ã€ã³ã«å°å
¥ããŠãããããDHCPãšActive Directory DNSãµãŒããŒããããã¯ãŒã¯äžã§å®è¡ãããŠãããšæ³å®ããŠããŸãã ãã®å Žåãæ¬¡ã®è¡ãã³ã¡ã³ãã¢ãŠãããŠãã ããã
127.0.0.1 localhost # 127.0.1.1 linux1.example.com linux1
ãããŸã§ã®ãšããããã®ã¢ã¯ã·ã§ã³ãšããã©ãŒãã³ã¹ãåé¡ã®éãã¯æ€åºãããŠããŸããã
Linuxã¯ã©ã€ã¢ã³ããã·ã³ã§ã®CUPSæ¥ç¶ãªã¹ãã³ã°ã¢ãã¬ã¹ã®æ§æ
䟿å©ãªæ¹æ³ã§linux1ã«ã¢ã¯ã»ã¹ããŸãã ãã¡ã€ã«/etc/cups/cupsd.confã®ç·šéïŒ
user@linux1:~$ sudo nano /etc/cups/cupsd.conf
ãã®äžã®è¡ãèŠã€ãã远å ãŸãã¯å€æŽããŸãã
DefaultLanguage ru # /usr/share/cups/locale ServerAlias linux1.example.com linux1 [CNAME DNS ] ServerAlias * # Listen /run/cups/cups.sock Listen localhost:631 # localhost Listen 10.10.100.50:631 # IP . Listen cupsserver:631 # . IP , Listen linux1:631 # Port 631 # Listen /run/cups/cups.sock Browsing off # . DefaultAuthType Basic # . Kerberos,
CUPSæ¥ç¶ãªã¹ãã³ã°ã¢ãã¬ã¹ã®èšå®
åã®ãããã¯ã§ã¯ãCUPSã«æ¥ç¶ããæ©èœãæ§æããŸããã æ¬¡ã«ãå°å·ã®èš±å¯ã®èšå®ãšã linux1ãã¹ãäžã®CUPSãµãŒãã¹ã®ç®¡çããŒãžã«é²ã¿ãŸãã /etc/cups/cupsd.confãã¡ã€ã«ãéããå Žåã¯å床éã ã <Location /> ã <Location / admin> ã <Location / admin / conf> ã <Location / admin / log>ãããã¯ã®ç·šéã«é²ã¿ãŸãã
# Restrict access to the server... <Location /> Order allow,deny # " , " Allow from localhost # linux1 Allow from linux1 # . Allow from cupsserver # CUPS DNS, . , Allow from cupsserver.example.com # FQDN Allow from 10.10.100.50 # IP **cupsserver** </Location> # Restrict access to the admin pages... <Location /admin> Order allow,deny # Allow from localhost # Allow from linux1 # Allow from 10.10.101.71 # , IP Allow from 10.20.50.* # , IT AuthType Default # CUPS . Require user @SYSTEM # CUPS </Location> # Restrict access to configuration files... <Location /admin/conf> # Order allow,deny # Allow from localhost # Allow from linux1 # Allow from 10.10.101.71 # , IP Allow from 10.20.50.* # , IT AuthType Default # CUPS . Require user @SYSTEM # CUPS </Location> # Restrict access to log files... <Location /admin/log> # Order allow,deny # Allow from localhost # Allow from linux1 # Allow from 10.10.101.71 # , IP Allow from 10.20.50.* # , IT AuthType Default # CUPS . Require user @SYSTEM # CUPS </Location>
ãããã¯ãŒã¯ããªã³ã¿ãŒã®é
åžãšãããŒããã£ã¹ãã®æ§æ
Linuxã¯ã©ã€ã¢ã³ããã·ã³ïŒãã®å Žåã¯linux1 ïŒã§ãã / etc / cups / cups-browsed.confãã¡ã€ã«ãç·šéããå¿
èŠããããŸãã
user@linux1:~$ sudo nano /etc/cups/cups-browsed.conf BrowseRemoteProtocols none # none . BrowseLocalProtocols cups # . DNSSD , cupsd.conf BrowseOrder Allow,Deny # Order cupsd.conf - , BrowseAllow 10.10.100.50 # IP BrowseAllow cupsserver # BrowseAllow cupsserver.example.com #
管çã¢ã¯ã»ã¹ãæ§æãã
ããªã³ããµãŒããŒãšä»»æã®Linuxã¯ã©ã€ã¢ã³ããã·ã³ã®äž¡æ¹ã®CUPS WEBã€ã³ã¿ãŒãã§ã€ã¹ã§ã®ç®¡çã¢ã¯ã»ã¹ã«ã€ããŠã®ã»ãã®äžèšã 30ã50å°ã®ã³ã³ãã¥ãŒã¿ãŒã䜿çšããŠããå Žåã§ããCUPSã§èªèšŒãçµ±åããå¿
èŠããããŸããåãã·ã³ã®ãã¹ã¯ãŒããã©ãã§ãèŠããŠããå¿
èŠã¯ãããŸããã ãŸããããã¯ãã¹ãŠã®Linuxãã·ã³ã§éèŠã§ãããµãŒããŒã«ããªã³ã¿ãŒã远å ããã«ã¯ãæåã«ããŒã«ã«ã«ã€ã³ã¹ããŒã«ããå¿
èŠãããããã§ãã ããã€ãã®æ¹æ³ããããŸãã
æåã®æ¹æ³ã¯ãåLinuxã·ã¹ãã ã§printeradminãŠãŒã¶ãŒãäœæãïŒããšãã°ïŒã lpadminãã°ã«ãŒãã«è¿œå ããããšã§ãã
user@linux1:~$ sudo usermod -a -G lpamin printeradmin
http://_:631/admin
ã«è³æ Œæ
å ±ã䜿çšããŠãã°ã€ã³ããŸãã
2çªç®ã®ãªãã·ã§ã³ã¯ã»ãšãã©åãã§ãããã·ã¹ãã ã«ã°ã«ãŒãïŒ printersadminsãªã©ïŒãäœæã ãããã«å¿
èŠãªCUPS管çè
ïŒ printeradmin ã user ïŒã远å ããããšãææ¡ããŸã ã
user@linux1:~$ sudo groupadd printersadmins user@linux1:~$ sudo usermod -a -G printersadmins printeradmin user@linux1:~$ sudo usermod -a -G printersadmins user
次ã«ã / etc / cups / cups-files.confãã¡ã€ã«ã§è¡ãèŠã€ããå¿
èŠããããŸã
# Administrator user group, used to match @SYSTEM in cupsd.conf policy rules... # This cannot contain the Group value for security reasons... SystemGroup lpadmin
ã¹ããŒã¹ãä»ããŠCUPSã管çããæš©éãæã€1ã€ä»¥äžã®ãŠãŒã¶ãŒã°ã«ãŒãã远å ããŸãã
# Administrator user group, used to match @SYSTEM in cupsd.conf policy rules... # This cannot contain the Group value for security reasons... SystemGroup lpadmin printersadmins somegroup
ãããŠæåŸã«ã3çªç®ã®ãªãã·ã§ã³ã ããªã³ããµãŒããŒãšã¯ã©ã€ã¢ã³ããã·ã³ã®CUPSã®ç®¡çè
ããŠãŒã¶ãŒã®ãã¡ã€ã³ã°ã«ãŒãã«ããŸãã ãããè¡ãã«ã¯ãããªã³ããµãŒããŒãšLinuxã¯ã©ã€ã¢ã³ããã·ã³ãADãã¡ã€ã³ã«åå ãããå¿
èŠããããŸãã LinuxãWindowsãã¡ã€ã³ã«æ¥ç¶ããæ¹æ³ã¯ããã€ããããŸãããç§ãç¥ãéããäž»ãªæ¹æ³ã¯winbindãšSSSDïŒrealmdïŒã䜿çšããŠæ¥ç¶ããããšã§ãã ãããã®ã¡ãœããã®èª¬æã¯ãã®èšäºã«ã¯å«ãŸããŠããªããããCUPSã«ç¹ã«é¢é£ããç¹ã®ã¿ã«çŠç¹ãåœãŠãŸãã
CUPS管çã®ããã®ãã¡ã€ã³ãŠãŒã¶ãŒã°ã«ãŒãã®äœ¿çšã®æ§æ
Linuxã®äžå€®èªèšŒã·ã¹ãã ã«åå ããåæ¹æ³ã¯ãã¢ããªã±ãŒã·ã§ã³ããã¡ã€ã³ãŠãŒã¶ãŒã®ãªã¹ãã衚瀺ã§ããç¹å¥ãªããã€ãããã¡ã€ã«ãäœæããŸãã CUPSããããå®è¡ã§ããããã«ãAppArmorã§ãã€ãã䜿çšããŠãŠãŒã¶ãŒãèªèšŒã§ããããã«ããå¿
èŠããããŸãã AppArmorã¯ãã¢ã¯ã»ã¹å¶åŸ¡ã®ããã®Linuxã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ã§ãã ç¹å®ã®ããã°ã©ã ãããã®ããªã·ãŒã«ãªã¹ããããŠãããã¡ã€ã«ã®ã»ããã«å¶éããŸãã winbinddãä»ããŠCUPSã«ãŠãŒã¶ãŒãšãã¡ã€ã³ã°ã«ãŒãã䜿çšããæš©å©ã远å ããã«ã¯ã / etc / apparmod.d / local / usr.sbin.cupsdãã¡ã€ã«ã«æ¬¡ã®è¡ã远å ããŸãã
/var/lib/samba/winbindd_privileged/pipe rw
LinuxãSSSDãä»ããŠãã¡ã€ã³ã«å
¥åãããå Žåããã€ãã®å Žæã/etc/apparmod.d/local/usr.sbin.cupsdã§æå®ããããã«è¡ã远å ããå¿
èŠããããŸãã
/var/lib/sss/pipes/private/pam rw
ããã«ãSSSDã®å Žåãããã«ããèªèšŒïŒãã°ã€ã³ããŠãããŠãŒã¶ãŒãèŠã€ããïŒãèš±å¯ãããŸãããèªèšŒïŒãŠãŒã¶ãŒãCUPSã管çããæš©å©ãæã£ãŠãããã©ããã調ã¹ãïŒããã«ã¯ã SSSDæ§æãã¡ã€ã«/etc/sssd/sssd.confã«è¡ã远å ããå¿
èŠããããŸãïŒ
ad_gpo_map_interactive = +cups
ããã¯ãæ¡ä»¶ä»ãã§èšãã°ãCUPSã«SSSDããèŠããæš©å©ãäžããŸãã
ããã«ãCUPSã¯SSSDãµãŒãã¹ã«äŸåããããã«ãªã£ããããSSSDã®åŸã«éå§ããå¿
èŠãããããšãCUPSã«äŒããå¿
èŠããããŸããããããªããšãCUPSããªã³ã«ãªã£ããšãã«ãªãã«ãªããæ¯åæåã§ãªã³ã«ããå¿
èŠããããŸãã
SSSDã®åŸã«ããŒãããããã«ãCUPSã«æç€ºã远å ããŸãã ãã¹/ lib / systemd / system /ã«æ²¿ã£ãŠcups.serviceãµãŒãã¹ãã¡ã€ã«ãç·šéãã [Unit]ã»ã¯ã·ã§ã³ã«Afterã¹ããŒãã¡ã³ãã远å ããŸãã
[Unit] Description=CUPS Scheduler Documentation=man:cupsd(8) After=sssd.service
ãããã£ãŠãCUPSã¯ããã¡ã€ã³ãä»ããåºæ¬èªèšŒãã€ãŸããCUPS管çç¹æš©ãæã€ãã¡ã€ã³ãŠãŒã¶ãŒã®ãã°ã€ã³ãšãã¹ã¯ãŒããå
¥åããããšã«ããèªèšŒã®ããã«æ§æãããŸãã
æ¿èªã¯å¥ã®æ¹æ³ã§æ§æã§ããŸãããååïŒãã€ããã¡ã€ã«ïŒã¯äžè¬çã«æ®éçã§ããã顿šã«ãã£ãŠLDAPãFreeIPAããã³ãã®ä»ã®ãã£ã¬ã¯ããªãµãŒãã¹çšã«æ§æããæ©äŒããããŸãã
Linuxã§ã®ããªã³ã¿ãŒã®ã€ã³ã¹ããŒã«
Linuxã«ããªã³ã¿ãŒãã€ã³ã¹ããŒã«ããããšã¯ãç¹å®ã®ã¿ã¹ã¯ã§ããããšãå€ãããã©ã³ããã¢ãã«ã«ãã£ãŠãç°ãªããŸãã ãããã£ãŠãããªã³ã¿ãŒã®ã€ã³ã¹ããŒã«ã«ã€ããŠèª¬æããçç±ã¯ãªãã linux1ãã¹ãã« Kyocera-1024FPãšããååã®Kyocera-1024FPããªã³ã¿ãŒãã€ã³ã¹ããŒã«ãããŠãããããªã³ã¿ãŒããŒãžã¯http://linux1:631/printers/Kyocera-1024FP
å©çšã§ãããšhttp://linux1:631/printers/Kyocera-1024FP
ãŸãã
LinuxãµãŒããŒãšã¯ã©ã€ã¢ã³ããã·ã³ãæ§æãããããªã³ã¿ãŒããããã®äžéšã«æ¥ç¶ãããå°å·ããWindowsãã·ã³ããããããPCã®ããããã®ããªã³ã¿ãŒã亀æããå¿
èŠãããå Žåã§ãããã®ã·ã¹ãã å
šäœãå®å®ããŠããå¿
èŠããããŸãããã¹ãŠã§ã¯ãªãã«ããŠããããã¯ãã¹ãŠã®PCã®è¯ãååã®åæ§æã䌎ãã¹ãã§ã¯ãããŸããã ããã«ããã©ã€ããŒã«é¢ããåé¡ãã§ããã ãå°ãªãããå¿
èŠããããŸãã ãããŠããã¯ããªãå¯èœã§ãã
ããªã³ã¿ãŒã°ã«ãŒãïŒã¯ã©ã¹ïŒ
Canon-MF4400 c windows1 LPD. http://cupsserver:631/printers/Canon-MF4400
. cupsserver http://cupsserver:631/admin
. " " [Add Class]. . "", "", "", . . Canon-MF4400 , "" , printer-windows1 , "" "" , " ".
printer-windows1 Canon-MF4400 . Canon-MF4400 â http://cupsserver:631/classes/printer-windows1
.
linux1 Kyocera-1024FP. HTTP. " (http)" [Internet Printing Protocol (http)], "Generic", "IPP Everywhere". , linux1 â Kyocera-1024FP . http://cupsserver:631/printers/Kyocera-1024FP
. printer-windows1 printer-linux1 c Kyocera-1024FP . http://cupsserver:631/classes/printer-linux1
.
Kyocera-1024FP linux1 cupsserver windows1 Windows 8 (!) . " ". http://_c:631/classes/_
. â http://cupsserver:631/classes/printer-linux1
. "Generic", â "MS Publisher Imagesetter". , printer-linux1 http://cupsserver:631
. , Kyocera-1024FP.
Canon-MF4400 windows1 cupsserver linux1 Linux (!) . , Kyocera-1024FP cupsserver . linux1 " (http)", ( Canon-MF4400 ) â http://cupsserver:631/classes/printer-windows1
. "Generic", â "IPP Everywhere". , â printer-windows1 . linux1 http://linux1:631/printers/printer-windows1
, .
, , , , , . â , , , , . , . "IPP Everywhere" "MS Publisher Imagesetter" , .., .
ãããã«
, - , . , , , , .