ืืืกืืึธืจืืฉ, ืกืืืึธ ืคึผืขืจืืืฉืึทื ื ืืขื ืขื ืืึทืืืขืจื ื ืืืจื ืื ืืื ืืึทืื ืคืื ืืขืงืขืก ืคึฟืื /etc/sudoers.d ะธ visado, ืืื ืฉืืืกื ืืขืจืืืืืขื ืืฉ ืืื ืืขืคืืจื ืืืืก ื ืืฆื ~/.ssh/authorized_keys. ืึธืืขืจ, ืืื ืื ืคืจืึทืกืืจืึทืงืืฉืขืจ ืืืืงืกื, ืขืก ืืื ืึท ืคืึทืจืืึทื ื ืฆื ืคืืจื ืื ืจืขืื ืกืขื ืืจืึทืื. ืืืึทื ื ืขืก ืงืขื ืืืื ืขืืืขืืข ืืืืืื ื ืึธืคึผืฆืืขืก:
- ืงืึทื ืคืืืืขืจืืืฉืึทื ืืึทื ืึทืืขืืขื ื ืกืืกืืขื - ืงืึธืืขืจ, ืืืึทืืงืข, Ansible, ืืึทืืฅ
- ืึทืงืืืื Directory + ืกืกืกื
- ืคืึทืจืฉืืื ืคึผืขืจืืืขืจืกืืึธื ืก ืืื ืื ืคืึธืจืขื ืคืื ืกืงืจืืคึผืก ืืื ืืึทื ืืึทื ืืขืงืข ืขืืืืื ื
ืืื ืืืื ืกืึทืืืืฉืขืงืืืื ืืืื ืื ื, ืืขืจ ืืขืกืืขืจ ืึธืคึผืฆืืข ืคึฟืึทืจ ืกืขื ืืจืึทืืืืื ืคืึทืจืืืึทืืืื ื ืืื ื ืึธื ืึท ืงืึธืืืื ืึทืฆืืข ืึทืงืืืื Directory + ืกืกืกื. ืื ืึทืืืืึทื ืืืืฉืื ืคืื ืืขื ืฆืืืึทื ื ืืขื ืขื:
- ืืืืช ืึท ืืืื ืกืขื ืืจืึทืืืืื ืืึทื ืืฆืขืจ ืืืขืืืืืึทืืขืจ.
- ืคืึทืจืฉืคึผืจืืืืื ื ืคืื ืจืขืื ืกืืืึธ ืงืืื ืึทืจืึธืคึผ ืฆื ืืืืื ืึท ืืึทื ืืฆืขืจ ืฆื ืึท ืกืคึผืขืฆืืคืืฉ ืืืืขืจืืืื ืืจืืคึผืข.
- ืืื ืื ืคืึทื ืคืื ืคืึทืจืฉืืื ืืื ืืงืก ืกืืกืืขืืขื, ืขืก ืืื ื ืืืืืง ืฆื ืืึทืงืขื ืขื ื ืึธื ืืฉืขืงืก ืฆื ืืึทืฉืืืกื ืื ืึทืก ืืืขื ืืืจ ื ืืฆื ืงืึทื ืคืืืืขืจืืืฉืึทื ืกืืกืืขืืขื.
ืืืึทื ื ืก ืกืืืื ืืืขื ืืืื ืืขืืึทืงืืืืึทื ืกืคึผืึทืกืืคืืงืื ืฆื ืื ืงืฉืจ ืึทืงืืืื Directory + ืกืกืกื ืคึฟืึทืจ ืจืขืื ืคืึทืจืืืึทืืืื ื ืกืืืึธ ืืื ืกืืึธืจืืืืฉ ืกืฉ ืฉืืืกืืขื ืืื ืึท ืืืื ืจืืคึผืึทืืึทืืึธืจื.
ืึทืืื, ืืขืจ ืืึทื ืืึธื ืืื ืืขืคืจืืืจื ืืื ืึท ืืขืฉืคึผืึทื ืื ืฉืืืืงืืื, ืืขืจ ืืืจืืืขื ื ืืึธื ืืืืคึฟืืขืืืืื ืืฒึทื ืืึทืืึธื, ืืื ืืขืจ ืึธืจืงืขืกืืขืจ ืืึธื ืืื ืืจืืื.
ืืื.
Given:
- ืึทืงืืืืืข Directory ืคืขืื testopf.local ืืืืฃ Windows Server 2012 R2.
- ืืื ืืงืก ืืึทืืขืืึธืก ืคืืืกื ืืืง Centos 7
- ืงืึทื ืคืืืืขืจื ืืขืจืืืืืขื ืืฉ ื ืืฆื ืกืกืกื
ืืืืืข ืกืึทืืืฉืึทื ื ืืึทืื ืขื ืืขืจืื ืืขื ืฆื ืื ืกืืฉืขืืึท ืึทืงืืืื Directory, ืึทืืื ืืืจ ืงืึธื ืืจืึธืืืจื ืึทืืฅ ืืื ืึท ืคึผืจืึธืืข ืกืืืืืืข ืืื ืืืืื ืืขืืึธืื ืืึทืื ืขื ืืขืจืื ืืขื ืฆื ืื ืืจืืขืื ืื ืคืจืึทืกืืจืึทืงืืฉืขืจ. ืืื ืืืึธืื ืืื ืฆื ืืึธื ืึทื ืึทืืข ืขื ืืขืจืื ืืขื ืืขื ืขื ืืึทืจืืขืืขื ืืื, ืืื ืคืึทืงื, ืืืืื ืืืืื ืื ื ืืืืืง ืึทืืจืืืืืฅ ืืื ืงืืืกื.
ืงืึทืืฃ 1: ืงืึธื ืืจืึธื ืกืืืึธ ืจืึธืืขืก ืืืจื ืึทืงืืืื Directory.
ืฆื ืคืึทืจืืจืืืืขืจื ืื ืงืจืืึทื ืึทืงืืืื Directory ืืืจ ืืึทืจืคึฟื ืฆื ืึธืคึผืืึธืืืจื ืื ืืขืฆืืข ืืขืืืื ื
ldifde -i -f schema.ActiveDirectory -c dc=X dc=testopf,dc=local
(ืื ืืืืกื ื ืืฉื ืคืึทืจืืขืกื ืฆื ืคืึทืจืืืึทืื ืืืื ืืืึทืืืขืก)
ืึธืคื adsiedit.msc ืืื ืคืึทืจืืื ืื ืฆื ืื ืคืขืืืงืืึทื ืงืึธื ืืขืงืกื:
ืฉืึทืคึฟื ืึท ืึธืคึผืืืื ืืื ืืขืจ ืืืึธืจืฆื ืคืื ืื ืคืขืื ืกืืืขืฅ. (ืื ืืืจืืฉืืืืืข ืืขื ืื ืืื ืขืงืฉื ืืช, ืื ืืื ืืขื ืืืื ืืืื ืืื ืืขืจ ืฉื ืกืกืกื ืืืื ืคึฟืึทืจ ืึท ื ืืืขืจ sudoRole ืึทืืืืฉืขืงืฅ. ืึธืืขืจ, ื ืึธื ืืืืกืืขืืจืืื ืืืืฃ ืืืืืืื ืืืืึทืืื ื ืืื ืืขืืขืจื ื ืื ืืึธืืก, ืขืก ืืื ืืขืืืขื ืื ืืคืืขืงื ืึทื ืื ืืืื ืืื ืืืจืืืขืงืึธืื ืืืืขืจ ืื ืืื ืฆืข Directory ืืืื.)
ืืืจ ืืึทืื ืืขืจ ืขืจืฉืืขืจ ืืืืคืขืฅ ืืืืึธื ืืื ื ืฆื ืื ืงืืึทืก ืืื ืืขืจ ืึธืคึผืืืื sudoRole. ืืขืจ ื ืึธืืขื ืงืขื ืขื ืืืื ืืืืกืืขืจืืืืืื ืืขืืึทืืจืข ืึทืจืืืืจืขืจืึทืื, ืืืืึทื ืขืก ืกืขืจืืืขืก ืืืืื ืคึฟืึทืจ ืืึทืงืืืขื ืืขืืืืืืึทืฆืืข.
ืฆืืืืฉื ืื ืืขืืืขื ืื ืืืฆื ืึทืืจืืืืืฅ ืคืื ืื ืกืืฉืขืืึท ืืขืฉืคึผืจืืื, ืื ืืืืคึผื ืึธื ืขืก ืืขื ืขื ืื ืคืืืืขื ืืข:
- sudoCommand - ืืึทืฉืืืื ืืืึธืก ืงืึทืืึทื ืื ืืขื ืขื ืขืจืืืืื ืฆื ืืืื ืขืงืกืึทืงืืืืึทื ืืืืฃ ืืขืจ ืืึทืืขืืึธืก.
- sudoHost - ืืืฉืืืกื ืืืืฃ ืืืึธืก ืืื ืืช ืืขื ืจืึธืืข ืึทืคึผืืืื. ืงืขื ืขื ืืืื ืกืคึผืขืกืืคืืขื ืืื ืึทืืข, ืืื ืคึฟืึทืจ ืึท ืืืื ืืึทืืขืืึธืก ืืืจื ื ืึธืืขื. ืขืก ืืื ืืืื ืืขืืืขื ืฆื ื ืืฆื ืึท ืืึทืกืงืข.
- sudoUser - ืึธื ืืืืึทืื ืืืึธืก ืืืืขืจื ืืขื ืขื ืขืจืืืืื ืฆื ืืืกืคืืจื ืกืืืึธ.
ืืืื ืืืจ ืกืคึผืขืฆืืคืืฆืืจื ืึท ืืืืขืจืืืื ืืจืืคึผืข, ืืืืื ืึท "%" ืฆืืืื ืืื ืื ืึธื ืืืื ืคืื ืื ื ืึธืืขื. ืืืื ืขืก ืืขื ืขื ืกืคึผืืืกืึทื ืืื ืื ืืจืืคึผืข ื ืึธืืขื, ืขืก ืืื ืืึธืจื ืืฉื ืฆื ืืึธืจื ืืืขืื. ืืืื ืืฉืคืื ืืืื ืื ืืึธืืก, ืื ืึทืจืืขื ืคืื ืืกืงืืืคึผืื ื ืกืคึผืืืกืึทื ืืื ืืืืขืจืืขื ืืืขื ืืืจื ืื ืืขืงืึทื ืืืึทื ืกืกืกื.
ืคืืึทื 1. sudoRole ืึทืืืืฉืขืงืฅ ืืื ืื ืกืืืึธืขืจืก ืกืึทืืืืืืืืฉืึทื ืืื ืืขืจ ืืืึธืจืฆื ืคืื ืื ืืืขืืืืืึทืืขืจ
ืคืืืืจืข 2. ืืืืืืืืขืจืฉืึทืคึฟื ืืื ืืืืขืจืืืื ืืจืืคึผืขืก ืกืคึผืขืกืืคืืขื ืืื ืกืืืึธืจืึธืืข ืึทืืืืฉืขืงืฅ.
ืื ืคืืืืขื ืืข ืกืขืืึทืคึผ ืืื ืืืจืืืขืงืึธืื ืืืืฃ ืื ืืื ืืงืก ืืืึทื.
ืืื ืืขืงืข / ืขืืง / ื ืกืืืืืืฉ .conf ืืืื ืื ืฉืืจื ืฆื ืื ืกืืฃ ืคืื ืื ืืขืงืข:
sudoers: files sss
ืืื ืืขืงืข / ืขืืง / ืกืกืกืกื / ืกืกืกื.ืงืึธื ืฃ ืืื ืึธืคึผืืืืืื ื [ืกืกืกื] ืืืืื ืฆื ืกืขืจืืืืกืขืก ืกืืืึธ
cat /etc/sssd/sssd.conf | grep services
services = nss, pam, sudo
ื ืึธื ืึทืืข ืึทืคึผืขืจืืืฉืึทื ื, ืืืจ ืืึทืจืคึฟื ืฆื ืืืกืืขืงื ืื sssd daemon ืงืึทืฉ. ืึธืืึทืืึทืืืง ืืขืจืืืึทื ืืืงืื ืืขื ืคืึทืื ืืขืืขืจ 6 ืฉืขื, ืึธืืขืจ ืืืึธืก ืืึธื ืืืจ ืืืึทืจืื ืึทืืื ืืึทื ื ืืืขื ืืืจ ืืืขืื ืขืก ืืืฆื?
sss_cache -E
ืขืก ืึธืคื ืืึทืคึผืึทื ื ืึทื ืงืืึธืจ ืื ืงืึทืฉ ืืื ื ืืฉื ืืขืืคื. ืืขืจื ืึธื ืืืจ ืืึทืืื ืื ืืื ืกื, ืจืืื ืื ืืึทืืึทืืืืก ืืื ืึธื ืืืืื ืื ืืื ืกื.
service sssd stop
rm -rf /var/lib/sss/db/*
service sssd start
ืืืจ ืคืึทืจืืื ืื ืืื ืืขืจ ืขืจืฉืืขืจ ืืึทื ืืฆืขืจ ืืื ืงืึธื ืืจืึธืืืจื ืืืึธืก ืืื ืื ืืืฆื ืคึฟืึทืจ ืืื ืืื ืืขืจ ืกืืืึธ:
su user1
[user1@testsshad log]$ id
uid=1109801141(user1) gid=1109800513(domain users) groups=1109800513(domain users),1109801132(admins_)
[user1@testsshad log]$ sudo -l
[sudo] password for user1:
Matching Defaults entries for user1 on testsshad:
!visiblepw, always_set_home, match_group_by_gid, always_query_group_plugin,
env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS",
env_keep+="MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE",
env_keep+="LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES",
env_keep+="LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE",
env_keep+="LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY",
secure_path=/sbin:/bin:/usr/sbin:/usr/bin
User user1 may run the following commands on testsshad:
(root) /usr/bin/ls, /usr/bin/cat
ืืืจ ืืึธื ืื ืืขืืืข ืืื ืืื ืืืขืจ ืฆืืืืื ืืึทื ืืฆืขืจ:
su user2
[user2@testsshad log]$ id
uid=1109801142(user2) gid=1109800513(domain users) groups=1109800513(domain users),1109801138(sudo_root)
[user2@testsshad log]$ sudo -l
Matching Defaults entries for user2 on testsshad:
!visiblepw, always_set_home, match_group_by_gid, always_query_group_plugin,
env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS",
env_keep+="MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE",
env_keep+="LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES",
env_keep+="LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE",
env_keep+="LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY",
secure_path=/sbin:/bin:/usr/sbin:/usr/bin
User user2 may run the following commands on testsshad:
(root) ALL
ืืขืจ ืฆืืืึทื ื ืึทืืึทืื ืืืจ ืฆื ืฆืขื ืืจืื ืืขืคืื ืืจื ืกืืืึธ ืจืึธืืขืก ืคึฟืึทืจ ืคืึทืจืฉืืืขื ืข ืืึทื ืืฆืขืจ ืืจืืคึผืขืก.
ืกืืึธืจืื ื ืืื ื ืืฆื ssh ืฉืืืกืืขื ืืื ืึทืงืืืื Directory
ืืื ืึท ืงืืืื ืืงืกืคึผืึทื ืฉืึทื ืคืื ืื ืกืืขืืข, ืขืก ืืื ืืขืืืขื ืฆื ืงืจืึธื ssh ืฉืืืกืืขื ืืื ืึทืงืืืืืข Directory ืืึทื ืืฆืขืจ ืึทืืจืืืืืฅ ืืื ื ืืฆื ืืื ืืืขื ืึธืืขืจืืืืื ื ืืืืฃ ืืื ืืงืก ืืื ืืช.
ืืขืจืืืืืขื ืืฉ ืืืจื sssd ืืืื ืืืื ืงืึทื ืคืืืืขืจื.
ืืืื ืื ืคืืจืืื ืื ืึทืืจืืืืื ื ืืฆื ืึท PowerShell ืฉืจืืคื.
AddsshPublicKeyAttribute.ps1ืคืื ืงืฆืืข New-AttributeID {
$Prefix="1.2.840.113556.1.8000.2554"
$GUID=[ืกืืกืืขื.ืืืื]::NewGuid().ToString()
$ ืคึผืึทืจืฅ=@()
$Parts+=[UInt64]::Parse($guid.SubString(0,4),,"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(4,4),,"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(9,4),,"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(14,4),,"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(19,4),,"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(24,6),,"AllowHexSpecifier")
$Parts+=[UInt64]::Parse($guid.SubString(30,6),,"AllowHexSpecifier")
$oid=[String]::Format(ยซ{0}.{1}.{2}.{3}.{4}.{5}.{6}.{7}ยป,$prefix,$Parts[0],
$Parts[1],$Parts[2],$Parts[3],$Parts[4],$Parts[5],$Parts[6])
$ืึธืื
}
$ schemaPath = (ืืึทืงืืืขื-ADRootDSE). schemaNamingContext
$ืึธืื = New-AttributeID
$ ืึทืืจืืืืืฅ = @{
lDAPDisplayName = 'sshPublicKey';
attributeId = $ืึธืื;
ืึธืืกืื ืืึทืงืก = 22;
ืึทืืจืืืืืืกืื ืืึทืงืก = "2.5.5.5";
isSingleValued = $ ืืืช;
adminDescription = 'ืืึทื ืืฆืขืจ ืคึผืืืืืง ืฉืืืกื ืคึฟืึทืจ SSH ืืึธืืื';
}
New-ADObject -Name sshPublicKey -Type attributeSchema -Path $schemapath -OtherAttributes $attributes
$userSchema = get-adobject -SearchBase $schemapath -ืคืืืืขืจ 'ื ืึธืืขื -eq "ืืึทื ืืฆืขืจ"'
$userSchema | Set-ADObject -Add @{mayContain = 'sshPublicKey'}
ื ืึธื ืึทืืื ื ืื ืึทืืจืืืืื, ืืืจ ืืืื ืจืืกืืึทืจื Active Directory ืืึธืืึทืื ืืึทืืื ืื ืืก.
ืืื ืก ืืึทื ืืืืฃ ืฆื ืึทืงืืืืืข Directory ืืืืขืจื. ืืืจ ืืืขืื ืืืฉืขื ืขืจืืื ืึท ืฉืืืกื ืคึผืึธืจ ืคึฟืึทืจ ssh ืคึฟืึทืจืืื ืืื ื ืืื ืงืืื ืืขืืึธื ืืืึธืก ืืื ืืึทืงืืืขื ืคึฟืึทืจ ืืืจ.
ืืืจ ืงืึทืืขืจ PuttyGen, ืืจืืงื ืื "ืืขื ืขืจืึทืืข" ืงื ืขืคึผื ืืื ืคืจืึทื ืืึทืงืื ืืึทื ืื ืืืื ืืื ืื ืืืืืืง ืืขืื ื.
ื ืึธื ืงืึทืืคึผืืืฉืึทื ืคืื ืืขื ืคึผืจืึธืฆืขืก, ืืืจ ืงืขื ืขื ืจืึทืืขืืืขื ืื ืฆืืืืจ ืืื ืคึผืจืืืืึทื ืฉืืืกืืขื, ืฆืืคึฟืขืืืงืขืจ ืืขื ืฆืืืืจ ืฉืืืกื ืฆื ืื ืึทืงืืืืืข Directory ืืึทื ืืฆืขืจ ืึทืืจืืืืื ืืื ืื ืื ืืขื ืคึผืจืึธืฆืขืก. ืึธืืขืจ, ืืขืจ ืฆืืืืจ ืฉืืืกื ืืืื ืืืื ืืขืืืืื ื ืคึฟืื ืื "ืฆืืืืจ ืฉืืืกื ืคึฟืึทืจ ืคึผืึทืกืืื ื ืืื OpenSSH Authorized_keys ืืขืงืข:".
ืืืื ืืขื ืฉืืืกื ืฆื ืื ืืึทื ืืฆืขืจ ืึทืืจืืืืื.
ืึธืคึผืฆืืข 1 - GUI:
ืึธืคึผืฆืืข 2 - PowerShell:
get-aduser user1 | set-aduser -add @{sshPublicKey = 'AAAAB...XAVnX9ZRJJ0p/Q=='}
ืึทืืื, ืืืจ ืืขืจืืืืึทื ืืึธืื: ืึท ืืึทื ืืฆืขืจ ืืื ืื sshPublicKey ืึทืืจืืืืื ืึธื ืืขืคืืื, ืึท ืงืึทื ืคืืืืขืจื ืคึผืึทืื ืงืืืขื ื ืคึฟืึทืจ ืืขืจืืืืืขื ืืฉ ื ืืฆื ืฉืืืกืืขื. ืขืก ืืืืืื ืืืื ืงืืืื ืคืื ื: ืืื ืฆื ืฆืืืื ืืขื ืื sshd ืืืืืึทื ืฆื ืขืงืกืืจืึทืงื ืื ืฆืืืืจ ืฉืืืกื ืืืึธืก ืืืจ ืืึทืจืคึฟื ืคืื ืื ืึทืืจืืืืืฅ ืคืื ืื ืืึทื ืืฆืขืจ. ื ืงืืืื ืฉืจืืคื ืืขืคืื ืขื ืืืืฃ ืื ืืืจืืฉืืืืข ืืื ืืขืจื ืขื ืงืขื ืขื ืืฆืืื ืงืึธืคึผืข ืืื ืืขื.
cat /usr/local/bin/fetchSSHKeysFromLDAP
#!/bin/sh
ldapsearch -h testmdt.testopf.local -xb "dc=testopf,dc=local" '(sAMAccountName='"${1%@*}"')' -D [email protected] -w superSecretPassword 'sshPublicKey' | sed -n '/^ /{H;d};/sshPublicKey:/x;$g;s/n *//g;s/sshPublicKey: //gp'
ืืืจ ืฉืืขืื ืื ืคึผืขืจืืืฉืึทื ื ืืืืฃ ืขืก ืฆื 0500 ืคึฟืึทืจ ืืืึธืจืฆื.
chmod 0500 /usr/local/bin/fetchSSHKeysFromLDAP
ืืื ืืขื ืืืึทืฉืคึผืื, ืึท ืึทืืืื ืืกืืจืึทืืึธืจ ืืฉืืื ืืื ืืขื ืืฆื ืฆื ืืื ืื ืฆื ืื ืืืขืืืืืึทืืขืจ. ืืื ืงืึทืืืึทื ืื ืึธืื ืขืก ืืืื ืืืื ืึท ืืึทืืื ืืขืจ ืืฉืืื ืืื ืึท ืืื ืืืื ืฉืืขืื ืคืื ืจืขืื.
ืืื ืคึผืขืจืกื ืึทืื ืืื ืืขืืืขื ืืืืขืจ ืฆืขืืืฉื ืืืจื ืืขื ืืึธืืขื ื ืคืื ืื ืคึผืึทืจืึธื ืืื ืืืึทื ืจืืื ืคืึธืจืขื ืืื ืื ืฉืจืืคื, ืืจืึธืฅ ืื ืจืขืื ืฉืืขืื.
ืืืืืื ื ืึธืคึผืฆืืข:
- ืืื ืืื ืืขื ืคึผืึทืจืึธื ืืื ืึท ืืึทืืื ืืขืจ ืืขืงืข:
echo -n Supersecretpassword > /usr/local/etc/secretpass
- ืืื ืฉืืขืื ืืขืงืข ืคึผืขืจืืืฉืึทื ื ืฆื 0500 ืคึฟืึทืจ ืืืึธืจืฆื
chmod 0500 /usr/local/etc/secretpass
- ืืฉืึทื ืืื ื ืืืึทืคึผืกืขืึทืจืืฉ ืงืึทืืขืจ ืคึผืึทืจืึทืืขืืขืจืก: ืคึผืึทืจืึทืืขืืขืจ -w superSecretPassword ืืื ืืืืฉื ืขืก ืฆื -ื /usr/local/etc/secretpass
ืื ืืขืฆื ืงืึธืจื ืืื ืืืึทื ื ืก ืกืืืื ืืื ืขืืืืื ื sshd_config
cat /etc/ssh/sshd_config | egrep -v -E "#|^$" | grep -E "AuthorizedKeysCommand|PubkeyAuthe"
PubkeyAuthentication yes
AuthorizedKeysCommand /usr/local/bin/fetchSSHKeysFromLDAP
AuthorizedKeysCommandUser root
ืืื ืึท ืจืขืืืืืึทื, ืืืจ ืืึทืงืืืขื ืื ืคืืืืขื ืืข ืกืืงืืืึทื ืก ืืื ืฉืืืกื ืืขืจืืืืืขื ืืฉ ืงืึทื ืคืืืืขืจื ืืื ืื ssh ืงืืืขื ื:
- ืืขืจ ืืึทื ืืฆืขืจ ืงืึทื ืขืงืฅ ืฆื ืื ืกืขืจืืืขืจ ืืืจื ืื ืืึทืงืืืืื ื ืืืื ืืึธืืื.
- ืื sshd ืืืืืึทื, ืืืจื ืึท ืฉืจืืคื, ืขืงืกืืจืึทืงื ืื ืฆืืืืจ ืฉืืืกื ืืืขืจื ืคืื ืึท ืืึทื ืืฆืขืจ ืึทืืจืืืืื ืืื ืึทืงืืืื Directory ืืื ืคึผืขืจืคืึธืจืื ืืขืจืืืืืขื ืืฉ ื ืืฆื ืื ืฉืืืกืืขื.
- ืื sssd ืืึทืขืืึธื ืืืืึทืืขืจ ืึธืืขื ืืึทืงืืืฅ ืืขืจ ืืึทื ืืฆืขืจ ืืืืืจื ืืืืฃ ืืจืืคึผืข ืืืืืืืืขืจืฉืึทืคื. ืืคืืขืจืงืืึทืืงืืึทื! ืืืื ืืึธืก ืืื ื ืืฉื ืงืึทื ืคืืืืขืจื, ืืขืืขืจ ืคืขืื ืืึทื ืืฆืขืจ ืืืขื ืืึธืื ืึทืงืกืขืก ืฆื ืืขืจ ืืึทืืขืืึธืก.
- ืืืขื ืืืจ ืคึผืจืึผืืื ืฆื ืกืืืึธ, ืื sssd ืืืืืึทื ืืืื ืื ืึทืงืืืืืข Directory ืคึฟืึทืจ ืจืึธืืขืก. ืืืื ืจืึธืืขืก ืืขื ืขื ืคืึธืจืฉืืขืื, ืื ืืึทื ืืฆืขืจ ืก ืึทืืจืืืืืฅ ืืื ืืจืืคึผืข ืืืืืืืืขืจืฉืึทืคื ืืขื ืขื ืึธืคึผืืขืฉืืขืื (ืืืื sudoRoles ืืื ืงืึทื ืคืืืืขืจื ืฆื ื ืืฆื ืืึทื ืืฆืขืจ ืืจืืคึผืขืก)
ืืขืจ ืจืขืืืืืึทื.
ืืืื, ืื ืฉืืืกืืขื ืืขื ืขื ืกืืึธืจื ืืื ืึทืงืืืื Directory ืืึทื ืืฆืขืจ ืึทืืจืืืืืฅ, ืกืืืึธ ืคึผืขืจืืืฉืึทื ื - ืกืืืืืึทืจืื, ืึทืงืกืขืก ืฆื ืืื ืืงืก ืืื ืืช ืืืจื ืคืขืื ืึทืงืึทืื ืฅ ืืื ืืืจืืืขืงืึธืื ืืืจื ืงืึธื ืืจืึธืืืจื ืืืืืืืืขืจืฉืึทืคื ืืื ืื ืึทืงืืืืืข Directory ืืจืืคึผืข.
ืื ืืขืฆืืข ืืืืึทืืืข ืคืื โโืื ืงืึธื ืืืงืืึธืจืก ืืึทืืึทื - ืืื ืืขืจ ืืึทื ืคืจืืจื ืืื ืืืจื ืฉืืืืงืืึทื.
ืจืขืกืึธืืจืกืขืก ืืขื ืืฆื ืืื ืฉืจืืืื:
ืืงืืจ: www.habr.com