4.4. ´ÉÍýÀ©¸æ

¼«Âð¤Î¥Þ¥·¥ó¤ò´ÉÍý¤¹¤ëºÝ¤Ï¡¢root¥æ¡¼¥¶¡¼¤È¤·¤Æ¤¢¤ë¤¤¤Ï sudo ¤ä su ¤Ê¤É¤Î setuid ¥×¥í¥°¥é¥à¤«¤éÍ­¸ú¤Ê root ¸¢¸Â¤ò¼èÆÀ¤·¤Æ¡¢¤¤¤¯¤Ä¤«¤Î¥¿¥¹¥¯¤ò¼Â¹Ô¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£setuid¥×¥í¥°¥é¥à¤Ï¡¢¥æ¡¼¥¶¡¼¤¬¥×¥í¥°¥é¥à¤òÁàºî¤¹¤ë¤Î¤Ç¤Ï¤Ê¤¯¡¢¥×¥í¥°¥é¥à¤Î¥ª¡¼¥Ê¡¼¤Î¥æ¡¼¥¶¡¼ID (UID)¤Çưºî¤¹¤ë¥×¥í¥°¥é¥à¤Ç¤¹¡£¤³¤Î¤è¤¦¤Ê¥×¥í¥°¥é¥à¤Ï¡¢¼¡¤ÎÎã¤Î¤è¤¦¤Ë¡¢Ä¹¤¤°ìÍ÷·Á¼°¤Î¥ª¡¼¥Ê¡¼¥»¥¯¥·¥ç¥ó¤Ë¾®Ê¸»ú¤Îs¤¬É½¼¨¤µ¤ì¤Æ¤¤¤Þ¤¹:

-rwsr-xr-x    1 root     root        47324 May  1 08:09 /bin/su

¤·¤«¤·¡¢¼ÒÆâ¤Î¥·¥¹¥Æ¥à´ÉÍý¼Ô¤Ï¡¢¼ÒÆâ¤Î¥æ¡¼¥¶¡¼¤ËÂФ·Èà¤é¤Î¥Þ¥·¥ó¤Ø¤É¤Î¤¯¤é¤¤¤Î´ÉÍý¥¢¥¯¥»¥¹¤ò»ý¤¿¤»¤ë¤«¤ò·è¤á¤Ê¤¯¤Æ¤Ï¤Ê¤ê¤Þ¤»¤ó¡£pam_console.so¤È¸Æ¤Ð¤ì¤ë PAM¥â¥¸¥å¡¼¥ë¤Ç¡¢ºÆµ¯Æ°¤ä¥ê¥à¡¼¥Ð¥Ö¥ë¥á¥Ç¥£¥¢¤Î¥Þ¥¦¥ó¥È¤Ê¤ÉÄ̾ï¤Ï root¥æ¡¼¥¶¡¼ÀìÍѤΤ¤¤¯¤Ä¤«¤Îºî¶È¤¬ÊªÍýŪ¤Ê¥³¥ó¥½¡¼¥ë¤Ç¥í¥°¥¤¥ó¤·¤¿ºÇ½é¤Î¥æ¡¼¥¶¡¼¤Ëµö²Ä¤µ¤ì¤Þ¤¹ (pam_console.so¥â¥¸¥å¡¼¥ë¤Ë¤Ä¤¤¤Æ¤Î¾ÜºÙ¤Ï¡¢ Red Hat Enterprise Linux ¥ê¥Õ¥¡¥ì¥ó¥¹¥¬¥¤¥É¤Ë¤¢¤ë PAM (Pluggable Authentication Modules)¤Î¾Ï¤ò»²¾È)¡£¤¿¤À¤·¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤ÎÀßÄêÊѹ¹¡¢¿·¤·¤¤¥Þ¥¦¥¹¤ÎÀßÄê¡¢¥Í¥Ã¥È¥ï¡¼¥¯¥Ç¥Ð¥¤¥¹¤Î¥Þ¥¦¥ó¥È¤Ê¤É¤Î¾¤Î½ÅÍפʴÉÍý¥¿¥¹¥¯¤Ï´ÉÍý¥¢¥¯¥»¥¹¤¬¤Ê¤¤¤È¼Â¹Ô¤Ç¤­¤Þ¤»¤ó¡£¤½¤Î·ë²Ì¡¢¥·¥¹¥Æ¥à´ÉÍý¼Ô¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Î¥æ¡¼¥¶¡¼¤¬¤É¤Î¤¯¤é¤¤¥¢¥¯¥»¥¹¤òÍ¿¤¨¤é¤ì¤ë¤«¤ò·èÄꤹ¤ëɬÍפ¬¤Ç¤Æ¤­¤Þ¤¹¡£

4.4.1. root¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë

´ë¶ÈÆâ¤Î¥æ¡¼¥¶¡¼¤¬¿®Íê¤Ç¤­¤ë¥³¥ó¥Ô¥å¡¼¥¿Ã챤ÎË­É٤ʿÍã¤Ð¤«¤ê¤Ê¤é¡¢root¥¢¥¯¥»¥¹¤Îµö²Ä¤òÍ¿¤¨¤ë¤Î¤Ï°­¤¯¤Ê¤¤¤«¤â¤·¤ì¤Þ¤»¤ó¡£root¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë¤È¤¤¤¦¤³¤È¤Ï¡¢¥Ç¥Ð¥¤¥¹¤ÎÄɲää¥Í¥Ã¥È¥ï¡¼¥¯¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹¤ÎÀßÄê¤Ê¤É¤ò¥æ¡¼¥¶¡¼¸Ä¿Í¤Ç¹Ô¤Ê¤¦¤³¤È¤¬¤Ç¤­¤ë¤¿¤á¡¢¥·¥¹¥Æ¥à´ÉÍý¼Ô¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¥»¥­¥å¥ê¥Æ¥£¤ä¾¤Î½ÅÍפÊÌäÂê¤Î½èÍý¤Ë»þ´Ö¤ò¼è¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

°ìÊý¡¢root¥¢¥¯¥»¥¹¤ò¸ÄÊ̤Υ桼¥¶¡¼¤ËÍ¿¤¨¤ë¤È¼¡¤Î¤è¤¦¤ÊÌäÂê¤Î¸¶°ø¤È¤Ê¤ë²ÄǽÀ­¤¬¤¢¤ê¤Þ¤¹(°ìÉô¤ÎÎã):

4.4.2. root¥¢¥¯¥»¥¹¤ò¶Ø»ß¤¹¤ë

¤³¤¦¤·¤¿Íýͳ¤ä½ô»ö¾ð¤«¤é¡¢¥æ¡¼¥¶¡¼¤Ë root¤È¤·¤Æ¤Î¥í¥°¥¤¥óµö²Ä¤òÍ¿¤¨¤ë¤³¤È¤¬É԰¤˻פï¤ì¤ë¾ì¹ç¡¢ root¥Ñ¥¹¥ï¡¼¥É¤Ïµ¡Ì©¤È¤·¡¢¥é¥ó¥ì¥Ù¥ë1¤ä¥·¥ó¥°¥ë¥æ¡¼¥¶¡¼¥â¡¼¥É¤Ø¤Î¥¢¥¯¥»¥¹¤Ï¥Ö¡¼¥È¥í¡¼¥À¥Ñ¥¹¥ï¡¼¥ÉÊݸî(¾ÜºÙ¤Ï¹à4.2.2¤ò»²¾È) ¤Ç¶Ø»ß¤·¤Æ¤¯¤À¤µ¤¤¡£

ɽ4-1¤Ç¤Ï¡¢´ÉÍý¼Ô¤¬ root¥í¥°¥¤¥ó¤ò³Î¼Â¤Ë¶Ø»ß¤¹¤ëÊýË¡¤ò¼¨¤·¤Þ¤¹:

ÊýË¡ÀâÌÀ¸ú²ÌÂоݳ°
root¥·¥§¥ë¤òÊѹ¹¤¹¤ë¡£/etc/passwd¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Æ¡¢¥·¥§¥ë¤ò/bin/bash¤«¤é/sbin/nologin ¤ËÊѹ¹¤·¤Þ¤¹¡£

root¥·¥§¥ë¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¡¢»î¹Ô¤òµ­Ï¿¤·¤Þ¤¹¡£
¼¡¤Î¥×¥í¥°¥é¥à¤¬root¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤é¤ì¤Þ¤¹¡£
· login
· gdm
· kdm
· xdm
· su
· ssh
· scp
· sftp

¥·¥§¥ë¤òɬÍפȤ·¤Ê¤¤¥×¥í¥°¥é¥à¡¢FTP¥¯¥é¥¤¥¢¥ó¥È¤ä¥á¡¼¥ë¥¯¥é¥¤¥¢¥ó¥È¡¢Â¿¤¯¤Îsetuid¥×¥í¥°¥é¥à¡£
°Ê²¼¤Î¥×¥í¥°¥é¥à¤Ïroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤é¤ì¤Þ¤»¤ó¡£
· sudo
· FTP ¥¯¥é¥¤¥¢¥ó¥È
· Email ¥¯¥é¥¤¥¢¥ó¥È

¤¹¤Ù¤Æ¤Î¥³¥ó¥½¡¼¥ë¥Ç¥Ð¥¤¥¹(tty)¤«¤é¤Îroot¥¢¥¯¥»¥¹¤ò»ÈÍѶػߤˤ¹¤ë¡£¶õ¤Î/etc/securetty¥Õ¥¡¥¤¥ë¤Ï¥³¥ó¥Ô¥å¡¼¥¿¤ËÀܳ¤·¤Æ¤¤¤ë¤¹¤Ù¤Æ¤Î¥Ç¥Ð¥¤¥¹¤Ç¤Îroot¥í¥°¥¤¥ó¤ò˸¤²¤Þ¤¹¡£

¥³¥ó¥½¡¼¥ë¤Þ¤¿¤Ï¥Í¥Ã¥È¥ï¡¼¥¯¤«¤é¤Îroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤Þ¤¹¡£°Ê²¼¤Î¥×¥í¥°¥é¥à¤Ïroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤é¤ì¤Þ¤¹¡£
· login
· gdm
· kdm
· xdm
· tty¤ò³«¤¯Â¾¤Î¥Í¥Ã¥È¥ï¡¼¥¯¥µ¡¼¥Ó¥¹

root¤È¤·¤Æ¥í¥°¥¤¥ó¤·¤Ê¤¤¥×¥í¥°¥é¥à¡£¤¿¤À¤·¡¢ setuid ¤ä¾¤Î¥á¥«¥Ë¥º¥à¤«¤é´ÉÍý¥¿¥¹¥¯¤ò¼Â¹Ô¤¹¤ë¤â¤Î¡£
°Ê²¼¤Î¥×¥í¥°¥é¥à¤Ïroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤é¤ì¤Þ¤»¤ó¡£
· su
· sudo
· ssh
· scp
· sftp

root¤ÎSSH¥í¥°¥¤¥ó¤ò»ÈÍѶػߤˤ¹¤ë¡£/etc/ssh/sshd_config¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Æ¡¢PermitRootLogin¥Ñ¥é¥á¡¼¥¿¤òno¤ËÀßÄꤷ¤Þ¤¹¡£

OpenSSH¥Ä¡¼¥ë¥»¥Ã¥È¤«¤é¤Îroot¥¢¥¯¥»¥¹¤ò˸¤²¤Þ¤¹¡£°Ê²¼¤Î¥×¥í¥°¥é¥à¤Ïroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤é¤ì¤Þ¤¹¡£
· ssh
· scp
· sftp

¤³¤ì¤ÏOpenSSH¥Ä¡¼¥ë¥»¥Ã¥È¤Ø¤Îroot¥¢¥¯¥»¥¹¤Î¤ß¤ò˸¤²¤Þ¤¹¡£

PAM¤ò»È¤Ã¤Æ¥µ¡¼¥Ó¥¹¤Ø¤Îroot¥¢¥¯¥»¥¹¤òÀ©¸Â¤¹¤ë¡£/etc/pam.d/¥Ç¥£¥ì¥¯¥È¥ê¤ÇÌÜŪ¤Î¥µ¡¼¥Ó¥¹¤Î¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Þ¤¹¡£ pam_listfile.so¤¬Ç§¾Ú¤òɬÍפȤ¹¤ë¤Î¤ò³Îǧ¤·¤Þ¤¹¡£[a]

PAMǧ¼±¤Ç¤¢¤ë¥Í¥Ã¥È¥ï¡¼¥¯¥µ¡¼¥Ó¥¹¥Ø¤Îroot¥¢¥¯¥»¥¹¤ò˸¤²¤Þ¤¹¡£
°Ê²¼¤Î¥µ¡¼¥Ó¥¹¤Ïroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò˸¤²¤é¤ì¤Þ¤¹¡£
· FTP ¥¯¥é¥¤¥¢¥ó¥È
· Email ¥¯¥é¥¤¥¢¥ó¥È
· login
· gdm
· kdm
· xdm
· ssh
· scp
· sftp
· PAMǧ¼±¥µ¡¼¥Ó¥¹¤Ï¤¹¤Ù¤Æ

PAMǧ¼±¤Ç¤Ï¤Ê¤¤¥×¥í¥°¥é¥à¤È¥µ¡¼¥Ó¥¹

Ãíµ­:
a. ¾ÜºÙ¤Ï¡¢¹à4.4.2.4¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

ɽ 4-1. root¥¢¥¯¥»¥¹¤ò»ÈÍѶػߤˤ¹¤ëÊýË¡

4.4.2.1. root¥·¥§¥ë¤ò»ÈÍѶػߤˤ¹¤ë

¥æ¡¼¥¶¡¼¤¬Ä¾ÀÜroot¤È¤·¤Æ¥í¥°¥¤¥ó¤·¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ë¡¢¥·¥¹¥Æ¥à´ÉÍý¼Ô¤Ï root¥¢¥«¥¦¥ó¥È¤Î¥·¥§¥ë¤ò/etc/passwd¥Õ¥¡¥¤¥ë¤Ç /sbin/nologin¤ËÀßÄê¤Ç¤­¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¡¢su¥³¥Þ¥ó¥É¤ässh¥³¥Þ¥ó¥É¤Ê¤É¡¢¥·¥§¥ë¤òɬÍפȤ¹¤ë¥³¥Þ¥ó¥É¤«¤éroot¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤¬Ë¸¤²¤é¤ì¤Þ¤¹¡£

½ÅÍ×½ÅÍ×
 

¥·¥§¥ë¤Ë¥¢¥¯¥»¥¹¤¹¤ëɬÍפΤʤ¤¥×¥í¥°¥é¥à¡£ÅŻҥ᡼¥ë¥¯¥é¥¤¥¢¥ó¥È¤ä sudo¥³¥Þ¥ó¥É¤Ê¤É¤Ï¡¢root¥¢¥«¥¦¥ó¥È¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤Þ¤¹¡£

4.4.2.2. root¥í¥°¥¤¥ó¤ò»ÈÍѶػߤˤ¹¤ë

root ¥¢¥«¥¦¥ó¥È¤Ø¤Î¥¢¥¯¥»¥¹¤ò¹¹¤ËÀ©¸Â¤¹¤ë¤Ë¤Ï¡¢/etc/securetty ¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Æ¥³¥ó¥½¡¼¥ë¤Ç root¥í¥°¥¤¥ó¤ò̵¸ú¤Ë¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£¤³¤Î¥Õ¥¡¥¤¥ë¤Ï¡¢root¥æ¡¼¥¶¡¼¤¬¥í¥°¥¤¥ó¤¹¤ëµö²Ä¤Î¤¢¤ë¥Ç¥Ð¥¤¥¹¤¹¤Ù¤Æ¤ò°ìÍ÷ɽ¼¨¤·¤Æ¤¤¤Þ¤¹¡£¥Õ¥¡¥¤¥ë¤¬¤Þ¤Ã¤¿¤¯Â¸ºß¤·¤Ê¤¤¾ì¹ç¤Ï¡¢root¥æ¡¼¥¶¡¼¤Ï¥·¥¹¥Æ¥à¾å¤Î¤¢¤é¤æ¤ëÄÌ¿®¥Ç¥Ð¥¤¥¹¤«¤é¡¢¥³¥ó¥½¡¼¥ë¤« raw¥Í¥Ã¥È¥ï¡¼¥¯¥¤¥ó¥¿¡¼¥Õ¥§¡¼¥¹·Ðͳ¤Ç¥í¥°¥¤¥ó¤Ç¤­¤Þ¤¹¡£¤³¤ì¤Ï¥æ¡¼¥¶¡¼¤¬ root¤È¤·¤Æ¼«¿È¤Î¥Þ¥·¥ó¤Ë Telnet ¤Ç¤­¤ë¤¿¤á´í¸±¤Ç¤¢¤ê¡¢¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Ç¼«Ê¬¤Î¥Ñ¥¹¥ï¡¼¥É¤òʿʸ¤ÇÁ÷¿®¤·¤Æ¤·¤Þ¤¤¤Þ¤¹¡£¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¡¢Red Hat Enterprise Linux ¤Î/etc/securetty¥Õ¥¡¥¤¥ë¤Ï¡¢¥Þ¥·¥ó¤ËʪÍýŪ¤ËÀܳ¤µ¤ì¤Æ¤¤¤ë¥³¥ó¥½¡¼¥ë¤Ç¤Î¥í¥°¥¤¥ó¤Ïroot¥æ¡¼¥¶¡¼¤Î¤ß¤Ëµö²Ä¤·¤Æ¤¤¤Þ¤¹¡£root ¤¬¥í¥°¥¤¥ó¤·¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤Ë¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Æ¤³¤Î¥Õ¥¡¥¤¥ë¤ÎÆâÍÆ¤òºï½ü¤·¤Þ¤¹:

echo > /etc/securetty

·Ù¹ð·Ù¹ð
 

¶õÇò¤Î/etc/securetty¥Õ¥¡¥¤¥ë¤Ï¡¢ ǧ¾Ú¤Þ¤Ç¥³¥ó¥½¡¼¥ë¤¬³«¤«¤Ê¤¤¤¿¤á¡¢OpenSSH¥Ä¡¼¥ë¥»¥Ã¥È¤ò»È¤¦±ó³Ö¤«¤é¤Îroot¥æ¡¼¥¶¡¼ ¥í¥°¥¤¥ó¤ÏËɤ®¤Þ¤»¤ó¡£

4.4.2.3. rootSSH¥í¥°¥¤¥ó¤ò»ÈÍѶػߤˤ¹¤ë

SSH ¥×¥í¥È¥³¥ë¤«¤é¤Î root¥í¥°¥¤¥ó¤òËɤ°¤Ë¤Ï¡¢SSH ¥Ç¡¼¥â¥ó¤ÎÀßÄê¥Õ¥¡¥¤¥ë (/etc/ssh/sshd_config)¤òÊÔ½¸¤·¤Þ¤¹¡£¼¡¤Î¤è¤¦¤Ëɽ¼¨¤µ¤ì¤Æ¤¤¤ë¹Ô¤òÊѹ¹¤·¤Þ¤¹:

# PermitRootLogin yes

¼¡¤Î¤è¤¦¤ËÊѹ¹¤·¤Þ¤¹¡£

 
PermitRootLogin no

4.4.2.4. PAM¤ò»È¤¦root¤ò»ÈÍѶػߤˤ¹¤ë

PAM¤Ï¡¢/lib/security/pam_listfile.so¥â¥¸¥å¡¼¥ë¤òÄ̤·¤Æ¡¢ ÆÃÄꥢ¥«¥¦¥ó¥È¤òµñÈݤ¹¤ë¤Î¤Ë½ÀÆðÀ­¤òȯ´ø¤·¤Þ¤¹¡£¤³¤ì¤Ç¡¢¥í¥°¥¤¥óµö²Ä¤Î¤Ê¤¤ ¥æ¡¼¥¶¡¼¤Î°ìÍ÷¤Ç¥â¥¸¥å¡¼¥ë¤ò¥Ý¥¤¥ó¥È¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£ /etc/pam.d/vsftpd PAMÀßÄê¥Õ¥¡¥¤¥ë¤Ë¤¢¤ë vsftpd FTP ¥µ¡¼¥Ð¡¼¤Ë¡¢¤É¤Î¤è¤¦¤Ë¥â¥¸¥å¡¼¥ë¤¬»ÈÍѤµ¤ì¤ë¤Î¤«°Ê²¼¤ËÎã¤ò¼¨¤·¤Þ¤¹(Îã¤ÎÃæ¤ÎºÇ½é¤Î¹Ô¤ÎËöÈø¤Ë¤¢¤ë\ʸ»ú¤Ï¡¢¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¤¬ 1 ¹Ô¤Ç¤¢¤ì¤ÐɬÍפ¢¤ê¤Þ¤»¤ó)¡£

auth   required   /lib/security/pam_listfile.so   item=user \
sense=deny file=/etc/vsftpd.ftpusers onerr=succeed

¤³¤ì¤Ï¡¢PAM¤¬ /etc/vsftpd.ftpusers¥Õ¥¡¥¤¥ë¤ò»²¾È¤·¤Æ¡¢µ­ºÜ¤µ¤ì¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¤¹¤Ù¤Æ¤ËÂФ·¤Æ¥µ¡¼¥Ó¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤òµñÈݤ·¤Þ¤¹¡£¤³¤Î¥Õ¥¡¥¤¥ë¤Î̾Á°¤ÏÊѹ¹¤·¤Æ¤â¹½¤¤¤Þ¤»¤ó¡£³Æ¥µ¡¼¥Ó¥¹¤Î°ìÍ÷¤òÊÌ¡¹¤ËÊÝ»ý¤·¤¿¤ê¡¢Ê£¿ô¤Î¥µ¡¼¥Ó¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤òµñÈݤ¹¤ë¤¿¤á¤Ë1¤Ä¤Î¼çÍ×°ìÍ÷¤ò»È¤¦¤³¤È¤â¤Ç¤­¤Þ¤¹¡£

´ÉÍý¼Ô¤¬Ê£¿ô¤Î¥µ¡¼¥Ó¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤òµñÈݤ·¤¿¤¤¾ì¹ç¡¢¥á¡¼¥ë¥¯¥é¥¤¥¢¥ó¥È¤Î/etc/pam.d/pop ¤ä /etc/pam.d/imap¡¢¤¢¤ë¤¤¤ÏSSH¥¯¥é¥¤¥¢¥ó¥È¤Î /etc/pam.d/ssh¤Ê¤É¤ÎPAMÀßÄꥵ¡¼¥Ó¥¹¤Ë¡¢»÷¤¿¤è¤¦¤Ê¹Ô¤ò²Ã¤¨¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

PAM¤Ä¤¤¤Æ¤Î¾ÜºÙ¤Ï¡¢Red Hat Enterprise Linux ¥ê¥Õ¥¡¥ì¥ó¥¹¥¬¥¤¥É¤Ë¤¢¤ë PAM (Pluggable Authentication Modules)¤Î¾Ï¤ò »²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

4.4.3. root¥¢¥¯¥»¥¹¤òÀ©¸Â¤¹¤ë

root¥æ¡¼¥¶¡¼¤Ø¤Î¥¢¥¯¥»¥¹¤ò´°Á´¤ËµñÈݤ¹¤ëÂå¤ï¤ê¤Ë¡¢su ¤äsudo¤Ê¤É¤Î setuid ¥×¥í¥°¥é¥à¤«¤é¤Î¤ß¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë¤³¤È¤â¤Ç¤­¤Þ¤¹¡£

4.4.3.1. su¥³¥Þ¥ó¥É

su¥³¥Þ¥ó¥É¤òÆþÎϤ¹¤ë¤È¡¢¥æ¡¼¥¶¡¼¤Ïroot¥Ñ¥¹¥ï¡¼¥É¤òµá¤á¤é¤ì¡¢Ç§¾Ú¤µ¤ì¤ë¤Èroot¥·¥§¥ë¥×¥í¥ó¥×¥È¤¬Í¿¤¨¤é¤ì¤Þ¤¹¡£

su¥³¥Þ¥ó¥É¤«¤é¥í¥°¥¤¥ó¤¹¤ë¤È¡¢¥æ¡¼¥¶¡¼¤Ï root¥æ¡¼¥¶¡¼¤È¤Ê¤ê¡¢¥·¥¹¥Æ¥à¤ËÂФ·¤ÆÀäÂÐŪ¤Ê´ÉÍý¥¢¥¯¥»¥¹¸¢¤ò»ý¤Á¤Þ¤¹¡£¤µ¤é¤Ë¡¢¥æ¡¼¥¶¡¼¤¬ root ¤Ë¤Ê¤ë¤È¡¢¥Ñ¥¹¥ï¡¼¥É¤òµá¤á¤é¤ì¤ë¤³¤È¤Ê¤¯su¥³¥Þ¥ó¥É¤ò»È¤Ã¤Æ¥·¥¹¥Æ¥à¾å¤Î¾¤Î¥æ¡¼¥¶¡¼¤Ë¤Ê¤ë¤³¤È¤¬²Äǽ¤Ë¤Ê¤ê¤Þ¤¹¡£

¤³¤Î¥×¥í¥°¥é¥à¤ÏÈó¾ï¤Ë¶¯ÎϤǤ¢¤ë¤¿¤á¡¢´ë¶ÈÆâ¤Î´ÉÍý¼Ô¤Ï¤½¤Î¥³¥Þ¥ó¥É¤Ø¤Î¥¢¥¯¥»¥¹¤ò»ý¤Ä¿Í¤ò¸ÂÄꤷ¤¿¤¤¤³¤È¤¬¤¢¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£

¤³¤ì¤ò¹Ô¤Ê¤¦´Êñ¤ÊÊýË¡¤Ï¡¢¥æ¡¼¥¶¡¼¤òwheel¤È¸Æ¤Ð¤ì¤ëÆÃ¼ì´ÉÍý¥°¥ë¡¼¥×¤ËÄɲ乤뤳¤È¤Ç¤¹¡£Äɲ乤ë¤Ë¤Ï¡¢root¤Ë¤Ê¤ê¼¡¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Þ¤¹¡£

usermod -G wheel <username>

¾åµ­¤Î¥³¥Þ¥ó¥É¤Ç¡¢<username>¤Ë¤Ï¡¢wheel ¥°¥ë¡¼¥×¤ËÄɲä¹¤ë¥æ¡¼¥¶¡¼Ì¾¤òÆþ¤ì¤Þ¤¹¡£

¤³¤ÎÌÜŪ¤Ç ¥æ¡¼¥¶¡¼¥Þ¥Í¡¼¥¸¥ã ¤ò»ÈÍѤ¹¤ë¤Ë¤Ï¡¢¥á¥¤¥ó¥á¥Ë¥å¡¼¥Ü¥¿¥ó (¥Ñ¥Í¥ë¾å) => ¥·¥¹¥Æ¥àÀßÄê => ¥æ¡¼¥¶¡¼¤È¥°¥ë¡¼¥×¤Î½ç¤Ë¿Ê¤à¤«¡¢¥·¥§¥ë¥×¥í¥ó¥×¥È¤Çsystem-config-users¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Þ¤¹¡£¥æ¡¼¥¶¡¼¥¿¥Ö¤òÁªÂò¤·¤Æ¡¢¥æ¡¼¥¶¡¼¤Î°ìÍ÷¤«¤é¥æ¡¼¥¶¡¼¤òÁªÂò¤·¤Þ¤¹¡£¥Ü¥¿¥ó¥á¥Ë¥å¡¼¤Î¥×¥í¥Ñ¥Æ¥£¤ò¥¯¥ê¥Ã¥¯¤·¤Þ¤¹(¤Þ¤¿¤Ï¡¢¥×¥ë¥À¥¦¥ó¥á¥Ë¥å¡¼¤«¤é¥Õ¥¡¥¤¥ë => ¥×¥í¥Ñ¥Æ¥£¤ÈÁª¤Ö)¡£

¼¡¤Ë¡¢¥°¥ë¡¼¥×¥¿¥Ö¤òÁªÂò¤·¤Æ¡¢ ¿Þ4-2¤Ç¼¨¤¹¤è¤¦¤Ë wheel ¥°¥ë¡¼¥×¤ò¥¯¥ê¥Ã¥¯¤·¤Þ¤¹¡£

¿Þ 4-2. Groups¤Î¥¿¥Ö²èÌÌ

¼¡¤Ë¡¢su (/etc/pam.d/su)¤Î PAMÀßÄê¥Õ¥¡¥¤¥ë¤ò¥Æ¥­¥¹¥È¥¨¥Ç¥£¥¿¤Ç³«¤­¡¢°Ê²¼¤Î¹Ô¤«¤é[#]¥³¥á¥ó¥È¤òºï½ü¤·¤Þ¤¹¡£

auth  required /lib/security/$ISA/pam_wheel.so use_uid

¤³¤ì¤ò¹Ô¤Ê¤¦¤È¡¢´ÉÍý¥°¥ë¡¼¥×wheel¤Î¥á¥ó¥Ð¡¼¤À¤±¤Ë¤½¤Î¥×¥í¥°¥é¥à¤Î»ÈÍѤòµö²Ä¤·¤Þ¤¹¡£

Ãíµ­Ãíµ­
 

¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï¡¢root¥æ¡¼¥¶¡¼¤Ïwheel¥°¥ë¡¼¥×¤Î¥á¥ó¥Ð¡¼¤Ç¤¹¡£

4.4.3.2. sudo¥³¥Þ¥ó¥É

sudo¥³¥Þ¥ó¥É¤Ç¤Ï¡¢¥æ¡¼¥¶¡¼¤Ë´ÉÍý¥¢¥¯¥»¥¹¤òÍ¿¤¨¤ëÊ̤ÎÊýË¡¤òÄ󶡤·¤Æ¤¤¤Þ¤¹¡£¿®Íê¤Ç¤­¤ë¥æ¡¼¥¶¡¼¤¬´ÉÍý¥³¥Þ¥ó¥É¤Ësudo¤òÀè¤ËÉÕ¤±¤Æ¼Â¹Ô¤¹¤ë¤È¡¢¤³¤Î¥æ¡¼¥¶¡¼¤Ï¼«¿È¤Î¥Ñ¥¹¥ï¡¼¥É¤òÍ׵ᤵ¤ì¤Þ¤¹¡£Ç§¾Ú¤µ¤ì¡¢¤½¤Î¥³¥Þ¥ó¥É¤¬µö²Ä¤µ¤ì¤ì¤Ð¡¢´ÉÍý¥³¥Þ¥ó¥É¤Ïroot¥æ¡¼¥¶¡¼¤Ç¹Ô¤Ê¤ï¤ì¤¿¤«¤Î¤è¤¦¤Ë¼Â¹Ô¤µ¤ì¤Þ¤¹¡£

sudo¥³¥Þ¥ó¥É¤Î´ðËÜ·Á¼°¤Ï¼¡¤Î¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹:

sudo <command>

¾åµ­¤ÎÎã¤Ç¡¢<command>¤Ë¤Ï¡¢ mount¤Ê¤É¤ÎÄ̾ï¤Ï root¥æ¡¼¥¶¡¼ÀìÍѤΥ³¥Þ¥ó¥É¤òÆþ¤ì¤Þ¤¹¡£

½ÅÍ×½ÅÍ×
 

sudoer ¤Ï 5ʬ´Ö¥Ñ¥¹¥ï¡¼¥É¤òµá¤á¤é¤ì¤ë¤³¤È¤Ê¤¯ºÆÅÙ¤½¤Î¥³¥Þ¥ó¥É¤ò»ÈÍѤǤ­¤ë¤¿¤á¡¢sudo¥³¥Þ¥ó¥É¤Î¥æ¡¼¥¶¡¼¤Ï¡¢¥Þ¥·¥ó¤«¤éÎ¥¤ì¤ëÁ°¤Ë¥í¥°¥¢¥¦¥È¤¹¤ë¤è¤¦½½Ê¬¤Ëµ¤¤ò¤Ä¤±¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¤³¤Î¥»¥Ã¥Æ¥£¥ó¥°¤ÏÀßÄê¥Õ¥¡¥¤¥ë¤Î/etc/sudoers¤«¤éÊѹ¹¤Ç¤­¤Þ¤¹¡£

sudo¥³¥Þ¥ó¥É¤Ï¹â¤¤½ÀÆðÀ­¤òÈ÷¤¨¤Æ¤¤¤Þ¤¹¡£Î㤨¤Ð¡¢/etc/sudoersÀßÄê¥Õ¥¡¥¤¥ë¤Ëµ­ºÜ¤µ¤ì¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¤Î¤ß¤¬sudo¥³¥Þ¥ó¥É¤Î»ÈÍѤòµö²Ä¤µ¤ì¡¢¤½¤Î¥³¥Þ¥ó¥É¤Ï root¥·¥§¥ë¤Ç¤Ï¤Ê¤¯¤½¤Î¥æ¡¼¥¶¡¼¤Î¥·¥§¥ë¤Ç¼Â¹Ô¤µ¤ì¤Þ¤¹¡£¤Ä¤Þ¤ê¡¢¹à4.4.2.1¤Ç¼¨¤¹¤è¤¦¤Ë root¥·¥§¥ë¤ò´°Á´¤Ë»ÈÍѶػߤˤ¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

sudo¥³¥Þ¥ó¥É¤Ï¹­ÈϰϤÎÄÉÀ״ƺº¤â¹Ô¤Ê¤¤¤Þ¤¹¡£À®¸ù¤·¤¿Ç§¾Ú¤Ï¤½¤ì¤¾¤ì/var/log/messages¥Õ¥¡¥¤¥ë¤Ëµ­Ï¿¤µ¤ì¡¢È¯¹Ô¤µ¤ì¤¿¥³¥Þ¥ó¥É¤Ïȯ¹Ô¼Ô¤Î¥æ¡¼¥¶¡¼Ì¾¤È¶¦¤Ë/var/log/secure ¥Õ¥¡¥¤¥ë¤Ëµ­Ï¿¤µ¤ì¤Þ¤¹¡£

sudo¥³¥Þ¥ó¥É¤Î¤â¤¦¤Ò¤È¤Ä¤ÎÍøÅÀ¤Ï¡¢´ÉÍý¼Ô¤¬É¬Íפ˱þ¤¸¤ÆÆÃÄꥳ¥Þ¥ó¥É¤ËÊÌ¡¹¤Î¥æ¡¼¥¶¡¼¥¢¥¯¥»¥¹¤òµö²Ä¤¹¤ë¤³¤È¤¬¤Ç¤­¤ë¤³¤È¤Ç¤¹¡£

sudoÀßÄê¥Õ¥¡¥¤¥ë¤Î/etc/sudoers¤òÊÔ½¸¤¹¤ë´ÉÍý¼Ô¤Ï¡¢visudo¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Æ¤¯¤À¤µ¤¤¡£

狼¤Ë´ÉÍý¸¢¸Â¤òÍ¿¤¨¤ë¤Ë¤Ï¡¢visudo¤òÆþÎϤ·¤Æ¤«¤é¥æ¡¼¥¶¡¼¤Î¸¢Íø»ØÄꥻ¥¯¥·¥ç¥ó¤Ç°Ê²¼¤Î¤è¤¦¤Ê¹Ô¤òÄɲä·¤Þ¤¹¡£

juan ALL=(ALL) ALL

¤³¤ÎÎã¤Ç¤Ï¡¢¥æ¡¼¥¶¡¼juan¤¬ ¤É¤Î¥Û¥¹¥È¤«¤é¤âsudo¤ò»ÈÍѤ·¤Æ¤É¤Î¥³¥Þ¥ó¥É¤â¼Â¹Ô¤Ç¤­¤ë¤è¤¦¤Ë·è¤á¤Æ¤¤¤Þ¤¹¡£

Î㤨¤Ð¡¢sudo¤òÀßÄꤹ¤ëºÝ¤Ë¡¢°Ê²¼¤Î¤è¤¦¤ËÆÃÄꥳ¥Þ¥ó¥É¤òÀßÄê¤Ç¤­¤Þ¤¹¡£

%users  localhost=/sbin/shutdown -h now

¤³¤ÎÎã¤Ç¤Ï¡¢¥³¥ó¥½¡¼¥ë¤Ç¤Ê¤é¤¤¤º¤ì¤Î¥æ¡¼¥¶¡¼¤â/sbin/shutdown -h now ¥³¥Þ¥ó¥É¤òȯ¹Ô¤Ç¤­¤ë¤è¤¦¤Ë·è¤á¤Æ¤¤¤Þ¤¹¡£

sudoers¤Îman¥Ú¡¼¥¸¤Ë¤Ï¤³¤Î¥Õ¥¡¥¤¥ëÍÑ¥ª¥×¥·¥ç¥ó¤Î¾ÜºÙ°ìÍ÷¤¬µ­½Ò¤µ¤ì¤Æ¤¤¤Þ¤¹¡£