Solaris10¤Ç½ð̾ÉÕ¤¥Ñ¥Ã¥±¡¼¥¸¤ÎºîÀ®¤È¥¤¥ó¥¹¥È¡¼¥ë
Solaris 10 1/06 ´Ä¶¤Ç½ð̾ÉÕ¤¥Ñ¥Ã¥±¡¼¥¸¤ÎºîÀ®ÊýË¡¤È¡¢¤½¤Î¤¿¤á¤Î¥¡¼¥¹¥È¥¢¤ÎºîÀ®¤ò¹Ô¤Ã¤Æ¤ß¤ë¡£
¤³¤³¤Ç¤Ï½ð̾ÉÕ¤¥Ñ¥Ã¥±¡¼¥¸¤Î¤¿¤á¤Î trusted ¥¡¼¤òºîÀ®¤¹¤ë¤¿¤á¤Ë openssl ¥³¥Þ¥ó¥É¤ò»ÈÍѤ¹¤ë¡£
openssl ¥³¥Þ¥ó¥É¤Ï Solaris 10 ¤Ç¤Ïɸ½à¤Ç /usr/sfw/bin ¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤Æ¤¤¤ë¡£
º£²ó¤Ï¡¢Æ°ºî¸¡¾Ú¤Ê¤Î¤Ç¥Ù¥ê¥µ¥¤¥ó¤Î¤è¤¦¤Ê¿®Íꤵ¤ì¤¿Ç§¾Ú¶É(CA)¤Î¾ÚÌÀ½ñ¤Ç¤Ï¤Ê¤¯¡¢¼«¸Ê½ð̾¤Î¾ÚÌÀ½ñ¤ò»ÈÍѤ·¤Æ¹Ô¤¦¡£
¢£¡¡¥Ñ¥Ã¥±¡¼¥¸¥¡¼¥¹¥È¥¢¤ÎºîÀ®
°Ê²¼¤Î¤è¤¦¤Ë /keys ¥Ç¥£¥ì¥¯¥È¥ê¤òºîÀ®¤·¡¢¸°Îà¤ÏÁ´¤Æ¤³¤³¤Ë³ÊǼ¤¹¤ë¡£
¥·¥¹¥Æ¥à¤Î¥Ç¥Õ¥©¥ë¥È¥¡¼¥¹¥È¥¢¤Î³ÊǼ¾ì½ê¤Ï /var/sadm/security ¥Ç¥£¥ì¥¯¥È¥ê¤Ê¤Î¤Ç¡¢¥¡¼¥¹¥È¥¢¤Î»ØÄê¤Ê¤É¤ò¾Êά¤·¤¿¤¤¤È¤¤Ï¤³¤Á
¤é¤Ë¤·¤Æ¤ª¤¯Êý¤¬ÊØÍø¤À¤¬¡¢º£²ó¤Ï¼«¸Ê½ð̾¤Î»ÃÄêŪ¤Ê¤â¤Î¤Ê¤Î¤Ç¡¢Ê̥ǥ£¥ì¥¯¥È¥ê¤Ë³ÊǼ¤¹¤ë¡£
bash-3.00#
mkdir /keys
bash-3.00#
cd /keys
bash-3.00#
/usr/sfw/bin/openssl
genrsa -aes128 -out package-key.pem 1024
Generating RSA private key, 1024 bit long modulus
........++++++
...............................++++++
e is 65537 (0x10001)
Enter pass phrase for package-key.pem:
solaris
<-- ÈëÌ©¸°¤òÊݸ¤ë¥Ñ¥¹¥Õ¥ì¡¼¥º¤ÎÆþÎÏ
Verifying - Enter pass phrase for package-key.pem:
solaris¡¡<-- ¤â¤¦°ìÅÙ
¾åµ¥³¥Þ¥ó¥É¤ÇºîÀ®¤µ¤ì¤¿¸°¤ÎÃæ¿È¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£
bash-3.00#
cat package-key.pem
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,2D07BF0A5E1FF82174491A91087E6DF0
H1txKItCMx2JJ9A9PjIL1sigevkfS0GDjJ8bWP9+CzGRtd+Dxp+Vv5a9EPBzmx2I
/EXgfWdQr7Ghke94XLEAOlbvh+OelNrnw19qsTLxLVGgF8g8FSeM0+oksz435RHT
+0MEm3ict3rQkiwXlQwxWwYbSQt/pJ6GBaVi4qAUyjJrL3JiNyV8Kb3C5LovQ11z
lwJk/j5GHvu9T23DkB2NyzU4vxB6T3NVCUc9P3ooHiYJlwAl9IKQfa9UA0Uu97J8
zCGwwIvpxbOpXjSMGFApDFH7V9Dn4EeVOAqm3IYuFWze/pEoQ0eo8xc5IiCQ7vis
SiwahzYQEuJVSTIYdgqiHNtsnlyA72mGSgXw/jfzLgE7ndcKu66swVKPKQ+onLkf
JAMELUlf1DFyD6h7ZFv2LZkVzE01xA0zqrveu99BSADLrCvZmuu+yZrb65/Je/xY
d5jVBQkd41j/XahQJLM/oTyiNe5zCTtPRKOkHDOIhgyPV5YiGtIUc1Ta7KnjqXpe
EPpy4o2Ao/kCk+PuX+Yzy9z4XxlBuTr6T3b++SsiSGkZfALLQps3K50U87eD/Osw
fTcx91nNtVR1fpUNhuFxVt2nCHBje9keF+BDZ3o13q7TIleF1znLkbT6mTxE/jAn
FqT63IIe5EC7z6RTbSY0JNyvLRhmFMDRsX1suxQXZQp5K8oVSQ8nHz/CklZDsHNg
ywQ1OfSwpG6nfDocd1nCCgL0so8uE1cb3kgmLLwUuXH7GcvlAq8gfTaXJGYSmSOz
UFwdTbgoAyzybD3Otmk+CaRp5aP/+Q33KZdoMpF46UPuSt3wXKvjaLo1tVIMh8uE
-----END RSA PRIVATE KEY-----
¼¡¤Ë¡¢¾åµ¼ê½ç¤ÇºîÀ®¤·¤¿¥Ñ¥Ã¥±¡¼¥¸½ð̾¥¡¼¤«¤é¾ÚÌÀ½ñ½ð̾Í×µá(CSR)¤òºîÀ®¤¹¤ë¡£
bash-3.00#
/usr/sfw/bin/openssl req
-new -key package-key.pem -out package-key.pem.csr
Enter pass phrase for package-key.pem:
solaris
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a
DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [US]:
JP
State or Province Name (full name) [Some-State]:
Tokyo
Locality Name (eg, city) []:
Shinagawa
Organization Name (eg, company) [Unconfigured OpenSSL Installation]:
Organizational Unit Name (eg, section) []:
Solaris 10 test
Common Name (eg, YOUR name) []:
Email Address []:
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
¤Á¤Ê¤ß¤Ë¾åµ¼ê½ç¤ÇºîÀ®¤·¤¿CSR¤ÎÃæ¿È¤Ï¤³¤ó¤Ê´¶¤¸¡£
bash-3.00#
cat package-key.pem.csr
-----BEGIN CERTIFICATE REQUEST-----
MIIBtzCCASACAQAwdzELMAkGA1UEBhMCSlAxDjAMBgNVBAgTBVRva3lvMRIwEAYD
VQQHEwlTaGluYWdhd2ExKjAoBgNVBAoTIVVuY29uZmlndXJlZCBPcGVuU1NMIElu
c3RhbGxhdGlvbjEYMBYGA1UECxMPU29sYXJpcyAxMCB0ZXN0MIGfMA0GCSqGSIb3
DQEBAQUAA4GNADCBiQKBgQDR87dDL/IsyY0oNQRNkfhLDWCqUNhzk0+hMuHYK1uz
UI1ftLXk0EZKG9TPf1AH4KDOPWrmogctFlhU2hkqhN6hnnknmAoi2px2XH/gK4QA
WR9CbdM8s6jcH7b3nl6cGaoW++hHat8fzk7lcX1XOjmnX0h0/gBsLjRD5Q6cP/bY
dQIDAQABoAAwDQYJKoZIhvcNAQEEBQADgYEArJAMe/mhyrh31HUSHSX0vlX6Ahq3
B3G5PvcCJ31se1wB5T3OK3OV5FAm6QSY+CxWoO7Z6EMlSss4FKYBdG5KXlhiakCi
ddExns9KWe6gvND3gLnJzNYQ//hhQjXrMQ0GNQcuyBSqW5FCm4Cx8JyGginQKNUl
pvqdIbZm+L+3/9U=
-----END CERTIFICATE REQUEST-----
¥Ñ¥Ã¥±¡¼¥¸½ð̾¥¡¼¤Ë¼«¸Ê½ð̾¤¹¤ë¡£Ä̾ï¤Ï¿®Íꤵ¤ì¤¿Ç§¾Ú¶É(CA)¤Ë¤è¤Ã¤Æ½ð̾¤µ¤ì¤ë¡£
bash-3.00#
/usr/sfw/bin/openssl req
-in package-key.pem.csr -out package-key-public.pem -key
package-key.pem -x509 -days 365
Enter pass phrase for package-key.pem:
solaris
¾åµ¼ê½ç¤ÇºîÀ®¤µ¤ì¤¿¾ÚÌÀ½ñ¤ÎÃæ¿È¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£
bash-3.00#
cat package-key-public.pem
-----BEGIN CERTIFICATE-----
MIIDOTCCAqKgAwIBAgIBADANBgkqhkiG9w0BAQQFADB3MQswCQYDVQQGEwJKUDEO
MAwGA1UECBMFVG9reW8xEjAQBgNVBAcTCVNoaW5hZ2F3YTEqMCgGA1UEChMhVW5j
b25maWd1cmVkIE9wZW5TU0wgSW5zdGFsbGF0aW9uMRgwFgYDVQQLEw9Tb2xhcmlz
IDEwIHRlc3QwHhcNMDYwMzA4MDYwNzA0WhcNMDcwMzA4MDYwNzA0WjB3MQswCQYD
VQQGEwJKUDEOMAwGA1UECBMFVG9reW8xEjAQBgNVBAcTCVNoaW5hZ2F3YTEqMCgG
A1UEChMhVW5jb25maWd1cmVkIE9wZW5TU0wgSW5zdGFsbGF0aW9uMRgwFgYDVQQL
Ew9Tb2xhcmlzIDEwIHRlc3QwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBANHz
t0Mv8izJjSg1BE2R+EsNYKpQ2HOTT6Ey4dgrW7NQjV+0teTQRkob1M9/UAfgoM49
auaiBy0WWFTaGSqE3qGeeSeYCiLanHZcf+ArhABZH0Jt0zyzqNwftveeXpwZqhb7
6Edq3x/OTuVxfVc6OadfSHT+AGwuNEPlDpw/9th1AgMBAAGjgdQwgdEwHQYDVR0O
BBYEFImkHP2F5nguKGS/bNSE+dELpOj+MIGhBgNVHSMEgZkwgZaAFImkHP2F5ngu
KGS/bNSE+dELpOj+oXukeTB3MQswCQYDVQQGEwJKUDEOMAwGA1UECBMFVG9reW8x
EjAQBgNVBAcTCVNoaW5hZ2F3YTEqMCgGA1UEChMhVW5jb25maWd1cmVkIE9wZW5T
U0wgSW5zdGFsbGF0aW9uMRgwFgYDVQQLEw9Tb2xhcmlzIDEwIHRlc3SCAQAwDAYD
VR0TBAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQBT2c3zvGAZTIlrEmPcwZKRyFKn
R5g/Kn4cIJfIMET6MpUIAM+gSJ9hjw+0MK9OhYB9tYpTZSNBs7FNWnDD8dMMULgZ
IZzALoZg9gszRfcNPyrsS9xoxcxWDAqZgwzx/KPqVU3aYhAdaEknoW+uduUuWQhv
puHF0Ff4r73kAtKKqg==
-----END CERTIFICATE-----
¾åµ¤Î¿®Íꤵ¤ì¤ë¾ÚÌÀ½ñ(trusted certificate)¤ò¥Ñ¥Ã¥±¡¼¥¸¥¡¼¥¹¥È¥¢ /keys/pkgkeys ¤Ë¥¤¥ó¥Ý¡¼¥È¤¹¤ë¡£
¤³¤³¤Ç -k ¤Ç¥Ñ¥Ã¥±¡¼¥¸¥¡¼¥¹¥È¥¢¤òÌÀ¼¨¤·¤Ê¤±¤ì¤Ð¥Ç¥Õ¥©¥ë¥È¤Î /var/sadm/security ¥Ç¥£¥ì¥¯¥È¥ê¤Ë truststore
¤È¤¤¤¦Ì¾Á°¤ÇÊݸ¤µ¤ì¤ë¡£
bash-3.00#
pkgadm addcert -k
/keys/pkgkeys -t package-key-public.pem
Keystore Alias:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Common Name:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Certificate Type: Trusted Certificate
Issuer Common Name: /C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Validity Dates: <Mar 8 06:07:04 2006
GMT> - <Mar 8 06:07:04 2007 GMT>
MD5 Fingerprint:
AB:03:A8:EC:1A:7E:A0:B3:6C:6C:17:BB:A0:0E:D1:09
SHA1 Fingerprint:
93:78:14:82:9E:39:E5:51:BC:44:55:4B:E8:DD:B7:F8:57:ED:A7:7C
ËÜÅö¤Ë¤³¤Î¾ÚÌÀ½ñ¤ò¿®Íꤷ¤Þ¤¹¤«?
y
¾ÚÌÀ½ñ </C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te> ¤ò¿®Íꤷ¤Þ¤¹
¥¡¼¥¹¥È¥¢¤ÎÊݸî¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤¡£
Êݸî¥Ñ¥¹¥ï¡¼¥É¤¬¤Ê¤¤¾ì¹ç¤Ï ENTER ¤ò²¡¤·¤Æ¤¯¤À¤µ¤¤ (¿ä¾©¤µ¤ì¤Þ¤»¤ó):
solaris10
For Verification: ¥¡¼¥¹¥È¥¢¤ÎÊݸî¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤¡£
Êݸî¥Ñ¥¹¥ï¡¼¥É¤¬¤Ê¤¤¾ì¹ç¤Ï ENTER ¤ò²¡¤·¤Æ¤¯¤À¤µ¤¤ (¿ä¾©¤µ¤ì¤Þ¤»¤ó):
solaris10
<package-key-public.pem> ¤«¤é¤Î¾ÚÌÀ½ñ¤¬¿®Íꤵ¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿
¼¡¤Ë¡¢¤¹¤Ù¤Æ¤Î¥Ñ¥Ã¥±¡¼¥¸¤Ë½ð̾¤¹¤ëºÝ¤Ë»ÈÍѤ¹¤ë¼ÂºÝ¤Î¥¡¼¤ò¥Ñ¥Ã¥±¡¼¥¸¥¡¼¥¹¥È¥¢¤Ë¥¤¥ó¥Ý¡¼¥È¤¹¤ë¡£
bash-3.00#
pkgadm addcert -k
/keys/pkgkeys -n signer -e package-key.pem package-key-public.pem
PEM ¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris
¥¡¼¥¹¥È¥¢¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris10
ÊÌ̾ <signer> ¤ò»ý¤Ä¾ÚÌÀ½ñ <package-key-public.pem> ¤ÎÄɲä¬À®¸ù¤·¤Þ¤·¤¿
°Ê²¼¤Ë¥¡¼¥¹¥È¥¢Æâ¤ÎÁ´¤Æ¤Î¥¡¼/¾ÚÌÀ½ñ¤òɽ¼¨¤¹¤ë¡£
ºÇ½é¤Î¥¨¥ó¥È¥ê¤Ç¤¢¤ë"Signing Certificate" ¤Ï¼ÂºÝ¤Ë¥Ñ¥Ã¥±¡¼¥¸¤Ë½ð̾¤¹¤ë¤¿¤á¤Ë»È¤ï¤ì¡¢£²¤ÄÌܤΠ"Trusted
Certificate" ¤Ï "Signing Certificate" ¤Ë½ð̾¤¹¤ë¤¿¤á¤Ë»È¤ï¤ì¤¿¾ÚÌÀ½ñ¤Ç¤¢¤ë¡£
¤È¤¤¤¦¤ï¤±¤Ç¡¢Î¾Êý¤È¤â¥¡¼¥¹¥È¥¢¤Ë¥¤¥ó¥Ý¡¼¥È¤µ¤ì¤Æ¤¤¤ëɬÍפ¬¤¢¤ë¡£
bash-3.00#
pkgadm listcert -k
/keys/pkgkeys
¥¡¼¥¹¥È¥¢¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris10
Keystore Alias: signer
Common Name:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Certificate Type: Signing Certificate
Issuer Common Name: /C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Validity Dates: <Mar 8 06:07:04 2006
GMT> - <Mar 8 06:07:04 2007 GMT>
MD5 Fingerprint:
AB:03:A8:EC:1A:7E:A0:B3:6C:6C:17:BB:A0:0E:D1:09
SHA1 Fingerprint:
93:78:14:82:9E:39:E5:51:BC:44:55:4B:E8:DD:B7:F8:57:ED:A7:7C
Keystore Alias:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Common Name:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Certificate Type: Trusted Certificate
Issuer Common Name: /C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Validity Dates: <Mar 8 06:07:04 2006
GMT> - <Mar 8 06:07:04 2007 GMT>
MD5 Fingerprint:
AB:03:A8:EC:1A:7E:A0:B3:6C:6C:17:BB:A0:0E:D1:09
SHA1 Fingerprint:
93:78:14:82:9E:39:E5:51:BC:44:55:4B:E8:DD:B7:F8:57:ED:A7:7C
̵»ö¡¢¥Ñ¥Ã¥±¡¼¥¸¥¡¼¥¹¥È¥¢¤ÎºîÀ®¤â½ª¤ï¤Ã¤¿¤Î¤Ç¡¢¤µ¤Ã¤½¤¯¥Ñ¥Ã¥±¡¼¥¸¤Ë½ð̾¤·¤Æ¤ß¤ë¡£
¢£¡¡½ð̾ÉÕ¤¥Ñ¥Ã¥±¡¼¥¸¤ÎºîÀ®
½ð̾¤Ë»ÈÍѤ¹¤ë¥Ñ¥Ã¥±¡¼¥¸¤Ï
Sunfreeware.com
¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¤¤¿ lsof-4.74 ¤Ë¤·¤Æ¤ß¤ë¡£
¤Á¤Ê¤ß¤Ë½ð̾¤¬²Äǽ¤Ê¤Î¤Ï¥Ç¥£¥ì¥¯¥È¥ê¥Õ¥©¡¼¥Þ¥Ã¥È¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤â¤Î¤À¤±¤Ê¤Î¤Ç¡¢¤Þ¤º¤Ïpkgtrans
¥³¥Þ¥ó¥É¤Ç¥¹¥È¥ê¡¼¥à¥Õ¥©¡¼¥Þ¥Ã¥È¤«¤é¥Ç¥£¥ì¥¯¥È¥ê¥Õ¥©¡¼¥Þ¥Ã¥È¤ØÊÑ´¹¤ò¤·¤Æ¤¤¤ë¡£
bash-3.00#
cd /var/tmp
bash-3.00#
file
lsof-4.74-sol10-sparc-local
lsof-4.74-sol10-sparc-local: ¥Ñ¥Ã¥±¡¼¥¸¤Î¥Ç¡¼¥¿¥¹¥È¥ê¡¼¥à
bash-3.00#
pkgtrans
./lsof-4.74-sol10-sparc-local . SMClsof
Transferring <SMClsof> package instance
bash-3.00#
file SMClsof
SMClsof: ¥Ç¥£¥ì¥¯¥È¥ê
bash-3.00#
ls SMClsof
pkginfo pkgmap reloc
¼¡¤Ë°Ê²¼¤Î¤è¤¦¤Ë¥Ñ¥Ã¥±¡¼¥¸¤Ë½ð̾¤ò¤·¡¢¸µ¤Î¥¹¥È¥ê¡¼¥à¥Õ¥©¡¼¥Þ¥Ã¥È¤ËÌ᤹¡£
bash-3.00#
pkgtrans -sg -k
/keys/pkgkeys . lsof-signed.pkg SMClsof
¥¡¼¥¹¥È¥¢ </keys/pkgkeys> ¤«¤é½ð̾¾ÚÌÀ½ñ¤ò¸¡º÷Ãæ¤Ç¤¹
¥¡¼¥¹¥È¥¢¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris10
Generating digital signature for signer
</C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te>
Transferring <SMClsof> package instance
¾åµ¼ê½ç¤Ç½ð̾ÉÕ¤¥Ñ¥Ã¥±¡¼¥¸ lsof-signed.pkg ¤¬ºîÀ®¤µ¤ì¤¿¡£
¢£¡¡½ð̾ÉÕ¤¥Ñ¥Ã¥±¡¼¥¸¤Î¥¤¥ó¥¹¥È¡¼¥ë
°Ê²¼¤Î¤è¤¦¤Ë pkgadd ¥³¥Þ¥ó¥É¤Ë -k ¥ª¥×¥·¥ç¥ó¤ò»ÈÍѤ·¡¢¥Ñ¥Ã¥±¡¼¥¸¥¡¼¥¹¥È¥¢ /keys/pkgkeys ¤ò»ØÄꤹ¤ë¡£
bash-3.00#
pkgadd -d lsof-signed.pkg
-k /keys/pkgkeys
The following packages are available:
1 SMClsof lsof
(sparc) 4.74
Select package(s) you wish to process (or 'all' to process
all packages). (default: all) [?,??,q]:
¥¡¼¥¹¥È¥¢¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
## Verifying signature for signer
</C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te>
## Signature for signer </C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured
OpenSSL Installation/OU=Solaris 10 te> verified.
</var/tmp/lsof-signed.pkg> Ãæ¤Î¥Ñ¥Ã¥±¡¼¥¸¥¤¥ó¥¹¥¿¥ó¥¹ <SMClsof> ¤ò½èÍýÃæ¤Ç¤¹¡£
lsof(sparc) 4.74
Vic Abell
ÁªÂò¤µ¤ì¤¿¥Ù¡¼¥¹¥Ç¥£¥ì¥¯¥È¥ê </usr/local> ¤Ï¡¢¥¤¥ó¥¹¥È¡¼¥ë Á°¤Ë¸ºß¤·
¤Æ¤¤¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£
º£¤³¤Î¥Ç¥£¥ì¥¯¥È¥ê¤òºîÀ®¤·¤Þ¤¹¤« [y,n,?,q]
y
</usr/local> ¤ò¥Ñ¥Ã¥±¡¼¥¸¤Î¥Ù¡¼¥¹¥Ç¥£¥ì¥¯¥È¥ê¤È¤·¤Æ»ÈÍѤ·¤Þ¤¹¡£
## ¥Ñ¥Ã¥±¡¼¥¸¾ðÊó¤ò½èÍýÃæ¤Ç¤¹¡£
## ¥·¥¹¥Æ¥à¾ðÊó¤ò½èÍýÃæ¤Ç¤¹¡£
## ¥Ç¥£¥¹¥¯Îΰè¤ÎÍ×·ï¤ò³ÎÇ§Ãæ¤Ç¤¹¡£
## ¤¹¤Ç¤Ë¥¤¥ó¥¹¥È¡¼¥ëºÑ¤ß¤Î¥Ñ¥Ã¥±¡¼¥¸¤È¤Î½ÅÊ£¤ò³ÎÇ§Ãæ¤Ç¤¹¡£
## setuid/setgid ¤ò¹Ô¤¦¥×¥í¥°¥é¥à¤ò¸¡ººÃæ¤Ç¤¹¡£
¼¡¤Î¥Õ¥¡¥¤¥ë¤Ï setuid¡¢setgid¡¢¤Þ¤¿¤Ï¤½¤ÎξÊý¤Î¥¢¥¯¥»¥¹¸¢¤Ç¥¤¥ó¥¹¥È¡¼
¥ë¤µ¤ì¤Þ¤¹¡£
/usr/local/bin/lsof <setgid sys>
¤³¤ì¤é¤Î¥Õ¥¡¥¤¥ë¤ò setuid ¤Þ¤¿¤Ï setgid ¥Õ¥¡¥¤¥ë¤È¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¤«
[y,n,?,q]
y
lsof ¤ò <SMClsof> ¤È¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ëÃæ¤Ç¤¹¡£
## 1/1 Éôʬ¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤¤¤Þ¤¹¡£
/usr/local/bin/lsof
/usr/local/doc/lsof/00.README.FIRST
/usr/local/doc/lsof/00CREDITS
/usr/local/doc/lsof/00DCACHE
/usr/local/doc/lsof/00DIALECTS
/usr/local/doc/lsof/00DIST
/usr/local/doc/lsof/00FAQ
/usr/local/doc/lsof/00LSOF-L
/usr/local/doc/lsof/00MANIFEST
/usr/local/doc/lsof/00PORTING
/usr/local/doc/lsof/00QUICKSTART
/usr/local/doc/lsof/00README
/usr/local/doc/lsof/00TEST
/usr/local/doc/lsof/00XCONFIG
/usr/local/doc/lsof/lsof.man
/usr/local/man/man8/lsof.8
[ ¥¯¥é¥¹ <none> ¤ò¸¡ºº¤·¤Æ¤¤¤Þ¤¹ ]
<SMClsof> ¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ËÀ®¸ù¤·¤Þ¤·¤¿¡£
¢£¡¡¥Ç¥Õ¥©¥ë¥È¤Î¥¡¼¥¹¥È¥¢ÊݸÀè /var/sadm/security ¥Ç¥£¥ì¥¯¥È¥ê¤ÎÍøÍÑ
¤Á¤Ê¤ß¤Ë¡¢²¼µ¤Î¤è¤¦¤Ë¥Ç¥Õ¥©¥ë¥È¤ÎÊݸÀè¤Ë¥¡¼¥¹¥È¥¢¤òºîÀ®¤¹¤ë¤È¡¢pkgadd ¤Ç¥¡¼¥¹¥È¥¢¤Î»ØÄ꤬ÉÔÍפˤʤ롣
bash-3.00#
pkgadm addcert -t
package-key-public.pem
Keystore Alias:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Common Name:
/C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Certificate Type: Trusted Certificate
Issuer Common Name: /C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te
Validity Dates: <Mar 8 06:07:04 2006
GMT> - <Mar 8 06:07:04 2007 GMT>
MD5 Fingerprint:
AB:03:A8:EC:1A:7E:A0:B3:6C:6C:17:BB:A0:0E:D1:09
SHA1 Fingerprint:
93:78:14:82:9E:39:E5:51:BC:44:55:4B:E8:DD:B7:F8:57:ED:A7:7C
ËÜÅö¤Ë¤³¤Î¾ÚÌÀ½ñ¤ò¿®Íꤷ¤Þ¤¹¤«?y
¾ÚÌÀ½ñ </C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te> ¤ò¿®Íꤷ¤Þ¤¹
¥¡¼¥¹¥È¥¢¤ÎÊݸî¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤¡£
Êݸî¥Ñ¥¹¥ï¡¼¥É¤¬¤Ê¤¤¾ì¹ç¤Ï ENTER ¤ò²¡¤·¤Æ¤¯¤À¤µ¤¤ (¿ä¾©¤µ¤ì¤Þ¤»¤ó):
solaris10
For Verification: ¥¡¼¥¹¥È¥¢¤ÎÊݸî¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤¡£
Êݸî¥Ñ¥¹¥ï¡¼¥É¤¬¤Ê¤¤¾ì¹ç¤Ï ENTER ¤ò²¡¤·¤Æ¤¯¤À¤µ¤¤ (¿ä¾©¤µ¤ì¤Þ¤»¤ó):
solaris10
<package-key-public.pem> ¤«¤é¤Î¾ÚÌÀ½ñ¤¬¿®Íꤵ¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿
bash-3.00#
pkgadm addcert -n signer
-e package-key.pem package-key-public.pem
PEM ¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris
¥¡¼¥¹¥È¥¢¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris10
ÊÌ̾ <signer> ¤ò»ý¤Ä¾ÚÌÀ½ñ <package-key-public.pem> ¤ÎÄɲä¬À®¸ù¤·¤Þ¤·¤¿
bash-3.00#
ls -l /var/sadm/security/
¹ç·× 10
-rw------- 1 root
root 1072 3·î
8Æü 15:55 certstore
-rw------- 1 root
root 842 3·î
8Æü 15:55 keystore
-rw------- 1 root
root 1224 3·î
8Æü 15:55 truststore
bash-3.00#
pkgadd -d lsof-signed.pkg
The following packages are available:
1 SMClsof lsof
(sparc) 4.74
Select package(s) you wish to process (or 'all' to process
all packages). (default: all) [?,??,q]:
¥¡¼¥¹¥È¥¢¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤:
solaris10
## Verifying signature for signer
</C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured OpenSSL
Installation/OU=Solaris 10 te>
## Signature for signer </C=JP/ST=Tokyo/L=Shinagawa/O=Unconfigured
OpenSSL Installation/OU=Solaris 10 te> verified.
</var/tmp/lsof-signed.pkg> Ãæ¤Î¥Ñ¥Ã¥±¡¼¥¸¥¤¥ó¥¹¥¿¥ó¥¹ <SMClsof> ¤ò½èÍýÃæ¤Ç¤¹¡£
...
...
¡Ú¥¢¥ó¥±¡¼¥È¡Û
¤³¤Îµ»ö¤Ï¤¿¤á¤Ë¤Ê¤ê¤Þ¤·¤¿¤«¡©
¡¡¡¡¡¡¤Ï¤¤¡¡¡¡/¡¡¡¡¤¤¤¤¤¨