¥È¥Ã¥×¥Ú¡¼¥¸ » Solaris10ºÇ¾®ÆÃ¸¢(Least Privilege)µ¡Ç½ » Least Privilege¡ÊºÇ¾®ÆÃ¸¢µ¡Ç½¡Ë¤Ç¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¤ËÆÃ¸¢¤òÍ¿¤¨¤ë¤Ë¤Ï
¥«¥Æ¥´¥ê¡¼
Solaris10Âбþ¥³¡¼¥¹
¢£Solaris½é¿´¼Ô¸þ¤±
ÆþÌ祳¡¼¥¹¡¡
¥·¥¹¥Æ¥à´ÉÍý­µ¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥·¥¹¥Æ¥à´ÉÍý­¶¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥·¥¹¥Æ¥à´ÉÍý­·¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥·¥¹¥Æ¥à´ÉÍý­¸¡¡¡Êx86ÈǤϤ³¤Á¤é¡Ë
¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý­µ
¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý­¶

¢£·Ð¸³¼Ô¡¦¾åµé¼Ô¸þ¤±
Solaris10¥È¥é¥Ö¥ë¥·¥å¡¼¥Æ¥£¥ó¥° ¡úNEW¡ú
¥»¥­¥å¥¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¡¼¹½ÃÛ ¡úNEW¡ú
Solaris 10 ZFS ´ÉÍý
Solaris 10¥³¥ó¥Æ¥Ê(¥¾¡¼¥ó)
·Ð¸³¼Ô¸þ¤±Â®½¬¥³¡¼¥¹
Solaris10¿·µ¡Ç½¡Ê¥·¥¹¥Æ¥à´ÉÍýÊÔ¡Ë
Solaris10¿·µ¡Ç½¡Ê¥Í¥Ã¥È¥ï¡¼¥¯ÊÔ¡Ë
Solaris ¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹´ÉÍý
DTrace ¤ò»È¤Ã¤¿¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹¥Á¥å¡¼¥Ë¥ó¥°¤È ¥È¥é¥Ö¥ë¥·¥å¡¼¥Æ¥£¥ó¥°

Solaris 8/9 Âбþ¥³¡¼¥¹
¢£½é¿´¼Ô¸þ¤±
ǧÄê»î¸³Âкö¥³¡¼¥¹
UNIXÆþÌç
¥·¥¹¥Æ¥à´ÉÍý­µ
¥·¥¹¥Æ¥à´ÉÍý­¶
¥·¥¹¥Æ¥à´ÉÍý­·
¥Í¥Ã¥È¥ï¡¼¥¯´ÉÍý´ðÁÃ

¢£·Ð¸³¼Ô¡¦¾åµé¼Ô¸þ¤±
¥È¥é¥Ö¥ë¥·¥å¡¼¥Æ¥£¥ó¥°´ðÁÃ
OS¥»¥­¥å¥ê¥Æ¥£ for Solaris
Solaris ¥Í¥Ã¥È¥ï¡¼¥¯¿¯Æþ¸¡ÃÎ
Sun Ray ¥·¥¹¥Æ¥à¤Î¥¤¥ó¥¹¥È¡¼¥ë¤È´ÉÍý ¡úNEW¡ú
Sun Systems Fault Analysis Workshop
Crash Dump Analysis and the SunOS Kernel
Solaris¥¤¥ó¥¿¡¼¥Ê¥ë(ÆâÉô¹½Â¤)

¢£DNS,Apache,¥×¥í¥­¥·,¥á¡¼¥ë·Ï
Solaris10¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¡¼¹½ÃÛ ¡úNEW¡ú
¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¹½ÃÛ
¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ð¥»¥­¥å¥ê¥Æ¥£

¢£¥Ü¥ê¥å¡¼¥à´ÉÍý¡¢¥¯¥é¥¹¥¿·Ï
Solaris Volume Manager ´ÉÍý
VERITAS Volume Manager4.0´ÉÍý
Sun Cluster 3.x ´ÉÍý
Sun Cluster 3.2 ´ÉÍý ¡úNEW¡ú

¢£¥Ï¡¼¥É¥¦¥§¥¢¡¢¥á¥ó¥Æ¥Ê¥ó¥¹·Ï
Sun Fire¥µ¡¼¥Ð¡¼´ÉÍý
Sun Fire 15K ¥µ¡¼¥Ð¡¼´ÉÍý

¢£¥·¥§¥ë¥×¥í¥°¥é¥ß¥ó¥°·Ï
C¥·¥§¥ë¥×¥í¥°¥é¥ß¥ó¥°
B¥·¥§¥ë/K¥·¥§¥ë¥×¥í¥°¥é¥ß¥ó¥°

SunJavaSystem¥³¡¼¥¹
¢£¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£´ÉÍý
¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£´ÉÍý¡Ê´ðËÜÊÔ¡Ë
¥¢¥¤¥Ç¥ó¥Æ¥£¥Æ¥£´ÉÍý¡Ê±þÍÑÊÔ¡Ë
¥¢¥¯¥»¥¹¥Þ¥Í¡¼¥¸¥ã¡¼
¢£LDAP¥µ¡¼¥Ð¡¢¥á¡¼¥ë¥µ¡¼¥Ð
¥Ç¥£¥ì¥¯¥È¥ê¥µ¡¼¥Ó¥¹ 5.x
¥á¥Ã¥»¡¼¥¸¥ó¥°¥µ¡¼¥Ó¥¹ 5.x

Least Privilege¡ÊºÇ¾®ÆÃ¸¢µ¡Ç½¡Ë¤Ç¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¤ËÆÃ¸¢¤òÍ¿¤¨¤ë¤Ë¤Ï

º£²ó¤ÏÆÉ¤ß¼è¤ê¸¢¤Î¤Ê¤¤¥Õ¥¡¥¤¥ë¤ä¥Ç¥£¥ì¥¯¥È¥ê¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤ë file_dac_read ÆÃ¸¢¤ò¥í¥°¥¤¥ó»þ¤Ë¥æ¡¼¥¶¤ËÍ¿¤¨¤ëÊýË¡¤ò¾Ò²ð¤¹¤ë¡£¡Ê¢Í³ÆÆÃ¸¢¤ÎÀâÌÀ¤Ï¤³¤Á¤é¡Ë
¤Þ¤º¡¢°Ê²¼¤Î¤è¤¦¤Ë°ìÈ̥桼¥¶¤Ç/etc/shadow¥Õ¥¡¥¤¥ë¤ò³«¤¤¤Æ¤ß¤ë¡£
# su - user1
Sun Microsystems Inc.   SunOS 5.10      Generic January 2005
$
$
$ more /etc/shadow
/etc/shadow: ¥¢¥¯¥»¥¹¸¢¤¬¤¢¤ê¤Þ¤»¤ó¡£

¤È¡¢¤Þ¤¡ÅöÁ³¼ºÇÔ¤¹¤ë¡£
¤½¤³¤Ç/etc/user_attr¥Õ¥¡¥¤¥ë¤Ëdefaultpriv¥­¡¼¥ï¡¼¥É¤ò»È¤¤¡¢°Ê²¼¤Î¤è¤¦¤Ëfile_dac_readÆÃ¸¢¤òŬÍѤ¹¤ë¡£
¤³¤Î»ØÄê¤ÇEffective¥»¥Ã¥È¡¢Permitted¥»¥Ã¥È¡¢Inheritable¥»¥Ã¥È¤Ëfile_dac_readÆÃ¸¢¤¬Äɲ䵤ì¤ë¡£
¤³¤Î¤Û¤«¤Ë¤âlimitpriv¥­¡¼¥ï¡¼¥É¤¬¤¢¤ê¡¢Limit¥»¥Ã¥È¤â¥«¥¹¥¿¥Þ¥¤¥º²Äǽ¤À¤¬¡¢¤³¤Á¤é¤Ï¥°¥í¡¼¥Ð¥ë¥½¡¼¥ó¤Ç¤Ï°ìÈ̥桼¥¶¤Ç¤â¥Ç¥Õ¥©¥ë¥È¤Ç all¤Ê¤Î¤Ç¡¢ÆÃ¤Ë¸¢¸Â¤ò³ÈÄ¥¤¹¤ëɬÍפϤʤ¤¡£

# cat /etc/user_attr
...
adm::::profiles=Log Management
lp::::profiles=Printer Management
root::::auths=solaris.*,solaris.grant;profiles=Web Console Management,All;lock_a
fter_retries=no
user1::::defaultpriv=basic,file_dac_read

¾åµ­¡¢ÀßÄê¤Ë¤·¤Æ¡¢¤â¤¦°ìÅÙ¡¢°ìÈ̥桼¥¶¤Ç/etc/shadow¥Õ¥¡¥¤¥ë¤ò³«¤¤¤Æ¤ß¤ë¡£

# su - user1
Sun Microsystems Inc.   SunOS 5.10      Generic January 2005
$ more /etc/shadow
...
listen:*LK*:::::::
gdm:*LK*:::::::
webservd:*LK*:::::::
nobody:*LK*:6445::::::
noaccess:*LK*:6445::::::
nobody4:*LK*:6445::::::
user1:AxEfnuHATDQB2:12930::::::

¤È¤Þ¤¡¤³¤ó¤Ê¶ñ¹ç¤Ë¥¢¥¯¥»¥¹¸¢¤ò̵»ë¤·¤Æ¡¢¥Õ¥¡¥¤¥ë¤òÆÉ¤ß¼è¤ë¤³¤È¤¬²Äǽ¤Ë¤Ê¤ë¡£
°Ê²¼¤Î¤è¤¦¤Ë¡¢ppriv¥³¥Þ¥ó¥É¤Ç¸½ºß¤Î¥·¥§¥ë¤Î»ý¤Ã¤Æ¤¤¤ëÆÃ¸¢¤ò¸«¤Æ¤â E, I, P ¤½¤ì¤¾¤ì¤ÎÆÃ¸¢¥»¥Ã¥È¤Ëfile_dac_readÆÃ¸¢¤¬Äɲäµ¤ì¤Æ¤¤¤ë¤³¤È¤¬³Îǧ¤Ç¤­¤ë¡£

$ ppriv $$
1020:   bash
flags = <none>
        E: basic,file_dac_read
        I: basic,file_dac_read
        P: basic,file_dac_read
        L: all


RBAC¤ÈÍí¤á¤ÆÆÃÄê¤Î¥³¥Þ¥ó¥É¤Ë¸ÂÄꤷ¤ÆÆÃ¸¢¤ò³ä¤êÅö¤Æ¤ëÊýË¡¤Ï¤³¤Á¤é

========================================
¢¨¾Ü¤·¤¤¾ðÊó¤Ï°Ê²¼¤Î¥È¥ì¡¼¥Ë¥ó¥°¥³¡¼¥¹»²¾È
Solaris10¿·µ¡Ç½¡Ê¥·¥¹¥Æ¥à´ÉÍýÊÔ¡Ë
========================================

¡Ú¥¢¥ó¥±¡¼¥È¡Û
¤³¤Îµ­»ö¤Ï¤¿¤á¤Ë¤Ê¤ê¤Þ¤·¤¿¤«¡©
¡¡¡¡¡¡¤Ï¤¤¡¡¡¡/¡¡¡¡¤¤¤¤¤¨

My Yahoo!¤ËÄɲÃ


¥³¥á¥ó¥È