ื’ื•ื’ืœ ืคืจืกืžื” ืืช HIBA, ืชื•ืกืฃ OpenSSH ืœืื™ืžื•ืช ืžื‘ื•ืกืก ืชืขื•ื“ื•ืช

ื’ื•ื’ืœ ืคืจืกืžื” ืืช ืงื•ื“ ื”ืžืงื•ืจ ืฉืœ ืคืจื•ื™ืงื˜ HIBA (Host Identity Based Authorization), ื”ืžืฆื™ืข ื™ื™ืฉื•ื ืฉืœ ืžื ื’ื ื•ืŸ ื”ืจืฉืื” ื ื•ืกืฃ ืœืืจื’ื•ืŸ ื’ื™ืฉืช ืžืฉืชืžืฉื™ื ื‘ืืžืฆืขื•ืช SSH ื‘ืงืฉืจ ืขื ืžืืจื—ื™ื (ื‘ื“ื™ืงื” ืื ืžื•ืชืจืช ื’ื™ืฉื” ืœืžืฉืื‘ ืกืคืฆื™ืคื™ ืื• ืœื ื‘ืขืช ื”ืื™ืžื•ืช ื‘ืืžืฆืขื•ืช ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื). ืื™ื ื˜ื’ืจืฆื™ื” ืขื OpenSSH ืžืกื•ืคืงืช ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื”ืžื˜ืคืœ ื‘-HIBA ื‘ื”ื ื—ื™ื™ืช AuthorizedPrincipalsCommand ื‘-/etc/ssh/sshd_config. ืงื•ื“ ื”ืคืจื•ื™ืงื˜ ื›ืชื•ื‘ ื‘-C ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ BSD.

HIBA ืžืฉืชืžืฉืช ื‘ืžื ื’ื ื•ื ื™ ืื™ืžื•ืช ืกื˜ื ื“ืจื˜ื™ื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืชืขื•ื“ื•ืช OpenSSH ืœื ื™ื”ื•ืœ ื’ืžื™ืฉ ื•ืžืจื•ื›ื– ืฉืœ ื”ืจืฉืื•ืช ืžืฉืชืžืฉื™ื ื‘ื™ื—ืก ืœืžืืจื—ื™ื, ืืš ืื™ื ื” ืžืฆืจื™ื›ื” ืฉื™ื ื•ื™ื™ื ืชืงื•ืคืชื™ื™ื ื‘ืงื‘ืฆื™ Authorized_keys ื•- Authorized_users ื‘ืฆื“ ื”ืžืืจื—ื™ื ืืœื™ื”ื ืžืชื‘ืฆืข ื”ื—ื™ื‘ื•ืจ. ื‘ืžืงื•ื ืœืื—ืกืŸ ืจืฉื™ืžื” ืฉืœ ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื ื—ื•ืงื™ื™ื ื•ืชื ืื™ ื’ื™ืฉื” ื‘ืงื‘ืฆื™ื ืžื•ืจืฉื™ื_(ืžืคืชื—ื•ืช|ืžืฉืชืžืฉื™ื), HIBA ืžืฉืœื‘ืช ืžื™ื“ืข ืขืœ ื›ืจื™ื›ื•ืช ืžืฉืชืžืฉ-ืžืืจื— ื™ืฉื™ืจื•ืช ื‘ืื™ืฉื•ืจื™ื ืขืฆืžื. ื‘ืคืจื˜, ื”ื•ืฆืขื• ื”ืจื—ื‘ื•ืช ืœืชืขื•ื“ื•ืช ืžืืจื— ื•ืชืขื•ื“ื•ืช ืžืฉืชืžืฉ, ื”ืžืื—ืกื ื•ืช ืคืจืžื˜ืจื™ื ืžืืจื— ื•ืชื ืื™ื ืœื”ืขื ืงืช ื’ื™ืฉื” ืœืžืฉืชืžืฉ.

ื‘ื“ื™ืงื” ื‘ืฆื“ ื”ืžืืจื— ืžืชื—ื™ืœื” ืขืœ ื™ื“ื™ ืงืจื™ืื” ืœืžื˜ืคืœ hiba-chk ืฉืฆื•ื™ืŸ ื‘ื”ื ื—ื™ื™ืช AuthorizedPrincipalsCommand. ืžืขื‘ื“ ื–ื” ืžืคืขื ื— ื”ืจื—ื‘ื•ืช ื”ืžืฉื•ืœื‘ื•ืช ื‘ืชืขื•ื“ื•ืช ื•ืžืงื‘ืœ ื”ื—ืœื˜ื” ืœื’ื‘ื™ ื”ืขื ืงืช ืื• ื—ืกื™ืžืช ื’ื™ืฉื”, ื‘ื”ืชื‘ืกืก ืขืœื™ื”ืŸ. ื›ืœืœื™ ื”ื’ื™ืฉื” ื ืงื‘ืขื™ื ื‘ืื•ืคืŸ ืžืจื›ื–ื™ ื‘ืจืžืช ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื (CA) ื•ืžืฉื•ืœื‘ื™ื ื‘ืชืขื•ื“ื•ืช ื‘ืฉืœื‘ ื”ืคืงืชื.

ื‘ืฆื“ ืžืจื›ื– ื”ื”ืกืžื›ื” ืžืชืงื™ื™ืžืช ืจืฉื™ืžื” ื›ืœืœื™ืช ืฉืœ ืกืžื›ื•ื™ื•ืช ื–ืžื™ื ื•ืช (ืžืืจื—ื™ื ืฉืืœื™ื”ื ืžื•ืชืจื™ื ื—ื™ื‘ื•ืจื™ื) ื•ืจืฉื™ืžืช ืžืฉืชืžืฉื™ื ื”ืžื•ืจืฉื™ื ืœื”ืฉืชืžืฉ ื‘ืกืžื›ื•ื™ื•ืช ืืœื•. ื›ื“ื™ ืœื”ืคื™ืง ืื™ืฉื•ืจื™ื ืžืื•ืฉืจื™ื ืขื ืžื™ื“ืข ืžืฉื•ืœื‘ ืขืœ ืื™ืฉื•ืจื™ื, ืžื•ืฆืข ื›ืœื™ ื”ืฉื™ืจื•ืช hiba-gen, ื•ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื”ื“ืจื•ืฉื” ืœื™ืฆื™ืจืช ืจืฉื•ืช ืื™ืฉื•ืจ ื›ืœื•ืœื” ื‘ืกืงืจื™ืคื˜ iba-ca.sh.

ื›ืืฉืจ ืžืฉืชืžืฉ ืžืชื—ื‘ืจ, ื”ืกืžื›ื•ืช ื”ืžืฆื•ื™ื ืช ื‘ืชืขื•ื“ื” ืžืื•ืฉืจืช ื‘ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื, ื”ืžืืคืฉืจืช ืœื‘ืฆืข ืืช ื›ืœ ื”ื‘ื“ื™ืงื•ืช ื‘ืžืœื•ืืŸ ื‘ืฆื“ ืžืืจื— ื”ื™ืขื“ ืฉืืœื™ื• ืžืชื‘ืฆืข ื”ื—ื™ื‘ื•ืจ, ืœืœื ืคื ื™ื™ื” ืœืฉื™ืจื•ืชื™ื ื—ื™ืฆื•ื ื™ื™ื. ืจืฉื™ืžืช ื”ืžืคืชื—ื•ืช ื”ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื ื”ืžืืฉืจืช ืชืขื•ื“ื•ืช SSH ืžืฆื•ื™ื ืช ื‘ืืžืฆืขื•ืช ื”ื•ืจืืช TrustedUserCAKeys.

ื‘ื ื•ืกืฃ ืœืงื™ืฉื•ืจ ื™ืฉื™ืจ ืฉืœ ืžืฉืชืžืฉื™ื ืœืžืืจื—ื™ื, HIBA ืžืืคืฉืจ ืœืš ืœื”ื’ื“ื™ืจ ื›ืœืœื™ ื’ื™ืฉื” ื’ืžื™ืฉื™ื ื™ื•ืชืจ. ืœื“ื•ื’ืžื”, ืžื™ื“ืข ื›ื’ื•ืŸ ืžื™ืงื•ื ื•ืกื•ื’ ืฉื™ืจื•ืช ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืฉื•ื™ืš ืœืžืืจื—ื™ื, ื•ื›ืืฉืจ ืžื’ื“ื™ืจื™ื ื›ืœืœื™ ื’ื™ืฉื” ืœืžืฉืชืžืฉ, ื ื™ืชืŸ ืœืืคืฉืจ ื—ื™ื‘ื•ืจื™ื ืœื›ืœ ื”ืžืืจื—ื™ื ืขื ืกื•ื’ ืฉื™ืจื•ืช ื ืชื•ืŸ ืื• ืœืžืืจื—ื™ื ื‘ืžื™ืงื•ื ืžื•ื’ื“ืจ.

ื’ื•ื’ืœ ืคืจืกืžื” ืืช HIBA, ืชื•ืกืฃ OpenSSH ืœืื™ืžื•ืช ืžื‘ื•ืกืก ืชืขื•ื“ื•ืช
ื’ื•ื’ืœ ืคืจืกืžื” ืืช HIBA, ืชื•ืกืฃ OpenSSH ืœืื™ืžื•ืช ืžื‘ื•ืกืก ืชืขื•ื“ื•ืช


ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”