PNG IHDR Û € ; ®IDATxÚíÜ»n€0áŒÿK¡ )(ŠpAá ±Ç7LeG{ý§ §㻢|¬ïذaà 6lذaà 6lذaà 6lomûó$^þy¿úÝØ°ag5 bà 6lذaà 6lذa{íŒ 6lذaà `µçãŽ}HÏFkm,m¶Ðû¬ÓªñÑêÃŽÒÃŽ!ÝxÛ|'Ü¢Ë;·E:Ôõ9&á¶¶}®{v]n&Ñ6ç íhíÕ_õ÷tšÚ ͵-Ò«¯ºZ;úŽZ$Û.PÔÄøkíÅŸ)º!§o¡¡>}l³eQfJÕT±u ѵòåÚª×\âÝX=8ÝîRÙ4`VwòlŸ>ëÃ×únGþ^ìiŸs©Ì"msÙ$×uñÝi»?w¡bs[m©6³K4áãçO¹.£4Þ%ºÐ×/õÀßÏbëC%çtûM× ú-lîG6±mrz2ô¶s%»9Às@¹ì-âk»9 =ìæî)ÎÝõÌåâk»B5ÕËÂ×\Ãñ+ÍçZsÙ²åµòRnÚÂ~G§ ÉRНCíšÉwIcIïén7jJ°åèhÛNCS|ìâÓj0æªò8yï·œiHKÛÖ¶ÐkòÉ+;Sz°¶úšáL /µFÐ*\çÆÔË#"5¯Âmë2Üï[SÅ«»Íú£=©g¯ÎnaóP eÚÒûî¬LÛÿ lذaà 6lØ^kãï̱aà 6lذaà 6lذa;ÿ ¶_ÚÎØ°aà 6lذaà 6lذaà ¶ášëR¢ÇÆ IEND®B`
Apache HTTP ãµãŒã ããŒãžã§ã³ 2.4
ãèªèšŒããšã¯ã誰ããèªåã¯èª°ã§ãããã䞻匵ããå Žåã«ã ããã確èªããããã®å šéçšãæããŸãããæ¿èªããšã¯ã 誰ããè¡ãããå Žæã«è¡ããããã«ããããã¯æ¬²ããæ å ±ã åŸãããšãã§ããããã«ããããã®å šéçšãæããŸãã
èªèšŒãšæ¿èªã®åŠçã«é¢é£ãã 3 çš®é¡ã®ã¢ãžã¥ãŒã«ããããŸãã ããããå°ãªããšãã²ãšã€ãã€å¿ èŠã§ãã
AuthType
ãã£ã¬ã¯ãã£ãåç
§)
AuthBasicProvider
,
AuthDigestProvider
ãã£ã¬ã¯ãã£ãåç
§)
Require
ãã£ã¬ã¯ãã£ãåç
§)
ãããã®ã¢ãžã¥ãŒã«ã«å ããŠãmod_authn_core
ãš mod_authz_core
ããããŸãã
ãã® 2 ã€ã®ã¢ãžã¥ãŒã«ã¯èªèšŒã¢ãžã¥ãŒã«ã«å
±éãªã³ã¢ãã£ã¬ã¯ãã£ãã
å®è£
ããŠããŸãã
mod_authnz_ldap
ã¯èªèšŒãããã€ããšæ¿èªãããã€ãã®
äž¡æ¹ã®æ©èœãæã£ãŠããŸãã
mod_authz_host
ã¯ãã¹ãåãIP ã¢ãã¬ã¹ã
ãªã¯ãšã¹ãã®ç¹åŸŽã«åºã¥ããã¢ã¯ã»ã¹å¶åŸ¡ãè¡ããŸããã
èªèšŒãããã€ãã®ã·ã¹ãã ã®äžéšã§ã¯ãããŸããã
mod_access ãšã®åŸæ¹äºææ§ã®ããã
æ°ããã¢ãžã¥ãŒã«ã® mod_access_compat
ããããŸãã
æ§ã ãªã¢ã¯ã»ã¹å¶åŸ¡ã®è¡ãªãæ¹ã«ã€ããŠã¯ã ã¢ã¯ã»ã¹å¶åŸ¡ã®æ¹æ³ãã芧ãã ããã
ããæ©å¯ã®æ å ±ããããããå°æ°ã°ã«ãŒãã®äººåãã®æ å ±ã ãŠã§ããµã€ãã«çœ®ãã®ã§ããã°ããã®ææžã«æžãããŠãã ãã¯ããã¯ã䜿ãããšã§ããã®ããŒãžãèŠãŠãã人ãã¡ã æã¿ã®äººãã¡ã§ããããšã確å®ã«ã§ããã§ãããã
ãã®ææžã§ã¯ãå€ãã®äººãæ¡çšããã§ãããã ãŠã§ããµã€ãã®äžéšåãä¿è·ãããäžè¬çãªã æ¹æ³ã«ã€ããŠã«ããŒããŠããŸãã
ããŒã¿ãæ¬åœã«æ©å¯ãªã®ã§ããã°ãèªèšŒã«å ããŠããã«
mod_ssl
ã䜿ããšè¯ãã§ãããã
ãã®ææžã§åãæ±ããããã£ã¬ã¯ãã£ãã¯ã
ã¡ã€ã³ãµãŒãèšå®ãã¡ã€ã« (æ®éã¯
<Directory>
ã»ã¯ã·ã§ã³äž) ãããããã¯ãã£ã¬ã¯ããªæ¯ã®èšå®ãã¡ã€ã«
(.htaccess
ãã¡ã€ã«) ãã§çšããŸãã
.htaccess
ãã¡ã€ã«ãçšããã®ã§ããã°ã
ãããã®ãã¡ã€ã«ã«èªèšŒçšã®ãã£ã¬ã¯ãã£ãã眮ããããã«
ãµãŒãã®èšå®ãããªããšãããªãã§ããããããã¯
AllowOverride
ãã£ã¬ã¯ãã£ãã§å¯èœã«ãªããŸãã
AllowOverride
ãã£ã¬ã¯ãã£ãã§ã¯ããã£ã¬ã¯ããªæ¯ã®èšå®ãã¡ã€ã«äžã«çœ®ãããšã®ã§ãã
ãã£ã¬ã¯ãã£ãããããããã°ãæå®ããŸãã
èªèšŒã«ã€ããŠè©±ãé²ããŠããã®ã§ã次ã®ãããª
AllowOverride
ãã£ã¬ã¯ãã£ããå¿
èŠã«ãªãã§ãããã
AllowOverride AuthConfig
ããã§ãªããã¡ã€ã³ãµãŒãèšå®ãã¡ã€ã«ã®äžã« çŽæ¥çœ®ãã®ã§ããã°ãåœç¶ãªãããã®ãã¡ã€ã«ãžã®æžã蟌㿠暩éãæã£ãŠããªããã°ãªããªãã§ãããã
ãŸããã©ã®ãã¡ã€ã«ãã©ãã«ä¿åãããŠãããç¥ãããã«ã ãµãŒãã®ãã£ã¬ã¯ããªæ§é ã«ã€ããŠå°ãç¥ã£ãŠãã å¿ èŠãããã§ãããã ããã¯ãããªã«é£ãããªãã®ã§ããã®ææžäžã§ ãã£ã¬ã¯ããªæ§é ã«ã€ããŠç¥ã£ãŠããå¿ èŠãããå Žé¢ã§ã¯ã æããã«ãªãããã«ããŸãã
mod_authn_core
ãš mod_authz_core
ã®äž¡æ¹ã httpd ãã€ããªã«éçã«çµã¿èŸŒã¿æžã¿ã§ããããhttpd.conf
èšå®ãã¡ã€ã«ã§åçã«ããŒãããããããŠãhttpd ã«çµã¿èŸŒãŸããŠããªããã°
ãªããŸããããããã®äºã€ã®ã¢ãžã¥ãŒã«ã¯ãèšå®ãã¡ã€ã«ã®ãªãã§éåžžã«
éèŠã§ãŠã§ããµãŒãã®èªèšŒãšæ¿èªã§äœ¿çšãããã³ã¢ãã£ã¬ã¯ãã£ããš
ãã®æ©èœãæäŸããŠããŸãã
ã§ã¯ããµãŒãäžã®ãããã£ã¬ã¯ããªããã¹ã¯ãŒãã§ä¿è·ãã åºæ¬æé ã瀺ããŸãã
ãŸãã¯ããã«ããã¹ã¯ãŒããã¡ã€ã«ãäœããŸãã ã©ã®èªèšŒãããã€ãã䜿ããã«ãã£ãŠããã¹ã¯ãŒããã¡ã€ã«çæã®æé 㯠倧ããç°ãªããŸããããã§ã®äŸã§ã¯ãæå§ãã«ããã¹ããã¹ã¯ãŒããã¡ã€ã«ã 䜿ããŸãã
ãã®ãã¹ã¯ãŒããã¡ã€ã«ã¯ããŠã§ãããã¢ã¯ã»ã¹ã§ããå Žæã«
眮ãã¹ãã§ã¯ãããŸãããä»ã®äººããã¹ã¯ãŒããã¡ã€ã«ã
ããŠã³ããŒãã§ããªãããã«ããããã§ããäŸãã°ã
/usr/local/apache/htdocs
ã§ããã¥ã¡ã³ãã
æäŸããŠããã®ã§ããã°ããã¹ã¯ãŒããã¡ã€ã«ã¯
/usr/local/apache/passwd
ãªã©ã«çœ®ããæ¹ãè¯ãã§ãããã
ãã¡ã€ã«ãäœãããã«ã¯ãApache ä»å±ã® htpasswd
ã䜿ããŸãããã®ã³ãã³ã㯠Apache ãã©ãã«ã€ã³ã¹ããŒã«ããããšãã
ã€ã³ã¹ããŒã«ãã£ã¬ã¯ããªã® bin
ãã£ã¬ã¯ããªä»¥äžã«çœ®ãããŸãããµãŒãããŒãã£è£œã®ããã±ãŒãžã§
ã€ã³ã¹ããŒã«ããå Žåã¯ãå®è¡ãã¹ã®äžã§èŠã€ããã§ãããã
ãã¡ã€ã«ãäœãã«ã¯ã次ã®ããã«ã¿ã€ãããŠãã ããã
htpasswd -c /usr/local/apache/passwd/passwords rbowen
htpasswd
ã¯ããã¹ã¯ãŒããèŠæ±ãããã®åŸ
確èªã®ããã«ããäžåºŠå
¥åããããã«èŠæ±ããŠããŸãã
# htpasswd -c /usr/local/apache/passwd/passwords rbowen
New password: mypassword
Re-type new password: mypassword
Adding password for user rbowen
ãã htpasswd
ããã¹ã®äžã«å
¥ã£ãŠããªãå Žåã¯ã
ãã¡ãããå®è¡ããããã«ããã°ã©ã ãŸã§ã®ãã«ãã¹ã
ã¿ã€ãããå¿
èŠããããŸããããã©ã«ãã®ã€ã³ã¹ããŒã«ç¶æ
ã§ããã°ã
/usr/local/apache/bin/htpasswd
ã«ããã°ã©ã ã眮ãããŠããŸãã
次ã«ããµãŒãããã¹ã¯ãŒããèŠæ±ããããã«èšå®ããŠã
ã©ã®ãŠãŒã¶ãã¢ã¯ã»ã¹ãèš±ãããŠãããããµãŒãã«ç¥ãããªããã°
ãªããŸããã httpd.conf
ãç·šéããã
.htaccess
ãã¡ã€ã«ã䜿çšãããã§
èšå®ããŸããäŸãã°ããã£ã¬ã¯ããª
/usr/local/apache/htdocs/secret
ãä¿è·ãããå Žåã¯ã
/usr/local/apache/htdocs/secret/.htaccess
ã httpd.conf äžã® <Directory
/usr/local/apache/htdocs/secret> ã»ã¯ã·ã§ã³ã«
é
眮ããŠã次ã®ãã£ã¬ã¯ãã£ãã䜿ãããšãã§ããŸãã
AuthType Basic
AuthName "Restricted Files"
# (Following line optional)
AuthBasicProvider file
AuthUserFile /usr/local/apache/passwd/passwords
Require user rbowen
åã
ã®ãã£ã¬ã¯ãã£ãã«ã€ããŠèŠãŠã¿ãŸãããã
AuthType
ãã£ã¬ã¯ãã£ãã¯ã©ãããèªèšŒæ¹æ³ã§ãŠãŒã¶ã®èªèšŒãè¡ããã
éžæããŸããæãäžè¬çãªæ¹æ³ã¯ Basic
ã§ããã㯠mod_auth_basic
ã§å®è£
ãããŠããŸããããããªããã
ããã¯æ°ãä»ããã¹ãéèŠãªãã€ã³ããªã®ã§ããã
Basic èªèšŒã¯ã¯ã©ã€ã¢ã³ããããµãŒããžã
ãã¹ã¯ãŒããæå·åããã«éããŸããã§ããããã®æ¹æ³ã¯ã
mod_ssl
ãšçµã¿åãããªãç¶æ
ã§ã¯ã
ç¹ã«æ©å¯æ§ã®é«ãããŒã¿ã«å¯ŸããŠã¯çšããã¹ãã§ã¯
ãããŸããã Apache ã§ã¯ããäžã€å¥ã®èªèšŒæ¹æ³:
AuthType Digest
ããµããŒãããŠããŸãã
ãã®æ¹æ³ã¯ mod_auth_digest
ã§å®è£
ãããŠããŠããã£ãšå®å
šã§ãã
æè¿ã®ã¯ã©ã€ã¢ã³ã㯠Digest
èªèšŒããµããŒãããŠããããã§ãã
AuthName
ãã£ã¬ã¯ãã£ãã§ã¯ãèªèšŒã«äœ¿ã Realm (蚳泚: é å)
ãèšå®ããŸããRealm ã¯å€§ããåããŠäºã€ã®æ©èœãæäŸããŸãã
äžã€ç®ã¯ãã¯ã©ã€ã¢ã³ãããã¹ã¯ãŒããã€ã¢ãã°ããã¯ã¹ã®
äžéšãšããŠãŠãŒã¶ã«ãã®æ
å ±ãããæç€ºããããšãããã®ã§ãã
äºã€ç®ã«ã¯ãã¯ã©ã€ã¢ã³ããäžããããèªèšŒé åã«å¯ŸããŠã©ã®ãã¹ã¯ãŒãã
éä¿¡ããã°è¯ãã®ããæ±ºå®ããããã«äœ¿ãããããšããæ©èœã§ãã
äŸãã°ã"Restricted Files"
é åäžã§
äžåºŠèªèšŒãããã°ãåäžãµãŒãäžã§ "Restricted Files"
Realm ãšããŠããŒã¯ãããã©ããªé åã§ããã¯ã©ã€ã¢ã³ãã¯
èªåçã«åããã¹ã¯ãŒãã䜿ãããšè©Šã¿ãŸãã
ãã®ãããã§ãè€æ°ã®å¶éé åã«åã realm ãå
±æãããŠã
ãŠãŒã¶ããã¹ã¯ãŒããäœåºŠãèŠæ±ãããäºæ
ã
é²ãããšãã§ããŸãããã¡ãããã»ãã¥ãªãã£äžã®çç±ããã
ãµãŒãã®ãã¹ãåãå€ããã°ãã€ã§ãå¿
ãã
ã¯ã©ã€ã¢ã³ãã¯åã³ãã¹ã¯ãŒããå°ããå¿
èŠããããŸãã
AuthBasicProvider
ã¯ããã©ã«ãå€ã file
ãªã®ã§ãä»åã®å Žåã¯ç¡ããŠãæ§ããŸããã
mod_authn_dbm
ã mod_authn_dbd
ãšãã£ãä»ã®ã¢ãžã¥ãŒã«ã䜿ãå Žåã«ã¯å¿
èŠã«ãªããŸãã
AuthUserFile
ãã£ã¬ã¯ãã£ã㯠htpasswd
ã§äœã£ã
ãã¹ã¯ãŒããã¡ã€ã«ãžã®ãã¹ãèšå®ããŸãã
ãŠãŒã¶æ°ãå€ãå Žåã¯ããªã¯ãšã¹ãæ¯ã®ãŠãŒã¶ã®èªèšŒã®ããã®
ãã¬ãŒã³ããã¹ãã®æ¢çŽ¢ãéåžžã«é
ããªãããšããããŸãã
Apache ã§ã¯ãŠãŒã¶æ
å ±ãé«éãªããŒã¿ããŒã¹ãã¡ã€ã«ã«
ä¿ç®¡ããããšãã§ããŸãã
mod_authn_dbm
ã¢ãžã¥ãŒã«ã
AuthDBMUserFile
ãã£ã¬ã¯ãã£ããæäŸããŸãããããã®ãã¡ã€ã«ã¯ dbmmanage
ããã°ã©ã ã§äœæãããæäœãããã§ããŸãã
Apache
ã¢ãžã¥ãŒã«ããŒã¿ããŒã¹äžã«ãããµãŒãããŒãã£ãŒè£œã®
ã¢ãžã¥ãŒã«ã§ããã®ä»å€ãã®ã¿ã€ãã®èªèšŒãªãã·ã§ã³ã
å©çšå¯èœã§ãã
æåŸã«ãRequire
ãã£ã¬ã¯ãã£ããããµãŒãã®ãã®é åã«ã¢ã¯ã»ã¹ã§ãããŠãŒã¶ã
æå®ããããšã«ãã£ãŠãããã»ã¹ã®æ¿èªéšåãæäŸããŸãã
次ã®ã»ã¯ã·ã§ã³ã§ã¯ãRequire
ãã£ã¬ã¯ãã£ãã®æ§ã
ãªçšæ³ã«ã€ããŠè¿°ã¹ãŸãã
äžèšã®ãã£ã¬ã¯ãã£ãã¯ããã äžäºº (å
·äœçã«ã¯ãŠãŒã¶å
rbowen
ã®èª°ã) ããã£ã¬ã¯ããªã«
å
¥ããããã«ããŸããå€ãã®å Žåã¯ãè€æ°ã®äººã
å
¥ããããã«ãããã§ããããããã§
AuthGroupFile
ã®ç»å Žã§ãã
ããè€æ°ã®äººãå ¥ããããã«ãããã®ã§ããã°ã ã°ã«ãŒãã«å±ãããŠãŒã¶ã®äžèЧã®å ¥ã£ãŠãããã°ã«ãŒãåã®ã€ãã ã°ã«ãŒããã¡ã€ã«ãäœãå¿ èŠããããŸãããã®ãã¡ã€ã«ã® æžåŒã¯ããããŠåçŽã§ãã奜ã¿ã®ãšãã£ã¿ã§çæã§ããŸãã ãã¡ã€ã«ã®äžèº«ã¯æ¬¡ã®ãããªãã®ã§ãã
GroupName: rbowen dpitts sungo rshersey
äžè¡ã«ã¹ããŒã¹åºåãã§ãã°ã«ãŒãã«æå±ããã¡ã³ããŒã® äžèЧããªãã¹ãã ãã§ãã
æ¢ã«ååšãããã¹ã¯ãŒããã¡ã€ã«ã«ãŠãŒã¶ãå ããå Žåã¯ã 次ã®ããã«ã¿ã€ãããŠãã ããã
htpasswd /usr/local/apache/passwd/passwords dpitts
以åãšåãå¿çãè¿ãããŸãããæ°ãããã¡ã€ã«ã
äœãã®ã§ã¯ãªããæ¢ã«ãããã¡ã€ã«ã«è¿œå ãããŠããŸãã
(æ°ãããã¹ã¯ãŒããã¡ã€ã«ãäœãã«ã¯ -c
ã䜿ããŸãã)
ããã§æ¬¡ã®ããã«ã㊠.htaccess
ãã¡ã€ã«ã
ä¿®æ£ããå¿
èŠããããŸãã
AuthType Basic
AuthName "By Invitation Only"
# Optional line:
AuthBasicProvider file
AuthUserFile /usr/local/apache/passwd/passwords
AuthGroupFile /usr/local/apache/passwd/groups
Require group GroupName
ããã§ãã°ã«ãŒã GroupName
ã«ãªã¹ããããŠããŠã
password
ãã¡ã€ã«ã«ãšã³ããªããã人ã¯ã
æ£ãããã¹ã¯ãŒããã¿ã€ãããã°å
¥ãããšãã§ããã§ãããã
ãã£ãšç¹å®ããã«è€æ°ã®ãŠãŒã¶ãå ¥ããããã«ããã ããäžã€ã®æ¹æ³ããããŸããã°ã«ãŒããã¡ã€ã«ãäœãã®ã§ã¯ãªãã æ¬¡ã®ãã£ã¬ã¯ãã£ãã䜿ãã°ã§ããŸãã
Require valid-user
require user rbowen
è¡ã§ãªããäžèšã䜿ããšã
ãã¹ã¯ãŒããã¡ã€ã«ã«ãªã¹ããããŠãã人ã§ããã°èª°ã§ã
èš±å¯ãããŸãã
åã«ãã¹ã¯ãŒããã¡ã€ã«ãã°ã«ãŒãæ¯ã«åããŠããããšã§ã
ã°ã«ãŒãã®ãããªæ¯ãèãããããããšãã§ããŸãã
ãã®ã¢ãããŒãã®å©ç¹ã¯ãApache ã¯äºã€ã§ã¯ãªãã
ãã äžã€ã®ãã¡ã€ã«ã ããæ€æ»ããã°ãããšããç¹ã§ãã
æ¬ ç¹ã¯ãããããã®ãã¹ã¯ãŒããã¡ã€ã«ã管çããŠããã®äžãã
AuthUserFile
ãã£ã¬ã¯ãã£ãã«æ£ãããã¡ã€ã«ãåç
§ãããªããã°ãªããªãç¹ã§ãã
Basic èªèšŒãæå®ãããŠããå Žåã¯ã ãµãŒãã«ããã¥ã¡ã³ãããªã¯ãšã¹ããã床㫠ãŠãŒã¶åãšãã¹ã¯ãŒããæ€æ»ããªããã°ãªããŸããã ããã¯åãããŒãžãããŒãžã«ããå šãŠã®ç»åã ãªããŒãããå Žåã§ãã£ãŠã該åœããŸã (ããç»åãä¿è·ããããã£ã¬ã¯ããªããæ¥ãã®ã§ããã°) ã äºæ³ãããéããããã¯åäœãå€å°é ãããŸãã é ããªãçšåºŠã¯ãã¹ã¯ãŒããã¡ã€ã«ã®å€§ãããšæ¯äŸããŸããã ããã¯ããã¡ã€ã«ãéããŠããªãã®ååãçºèŠãããŸã§ ãŠãŒã¶åã®ãªã¹ããèªãŸãªããã°ãªããªãããã§ãã ãããŠãããŒãžãããŒãããã床ã«ãããè¡ããªããã° ãªããŸããã
çµè«ãšããŠã¯ãäžã€ã®ãã¹ã¯ãŒããã¡ã€ã«ã«çœ®ãããšã®ã§ãã ãŠãŒã¶æ°ã«ã¯å®è³ªçãªéçããããŸãã ãã®éçã¯ãµãŒããã·ã³ã®æ§èœã«äŸåããŠå€ãããŸããã æ°çŸã®ãšã³ããªãè¶ãããããããé床äœäžãèŠããããšäºæãããŠããŸãã ãã®æã¯ä»ã®èªèšŒæ¹æ³ãèæ ®ã«å ¥ããæ¹ãè¯ãã§ãããã
ãã¬ãŒã³ããã¹ãã§ãã¹ã¯ãŒããä¿åããæ¹æ³ã«ã¯äžèšã®åé¡ãããã ããŒã¿ããŒã¹ã®ãããªå¥ã®å Žæã«ãã¹ã¯ãŒããä¿åããããšæã ãããããŸããã
mod_authn_dbm
ãš mod_authn_dbd
ã䜿ããšããããã§ããããã«ãªããŸãã
AuthBasicSource
ã§ file ã®ä»£ããã«ãdbm
ããã㯠dbd
ãæ ŒçŽåœ¢åŒãšããŠéžã¹ãŸãã
ããã¹ããã¡ã€ã«ã®ä»£ããã« dbm ãã¡ã€ã«ãéžæããå Žåã¯ãããšãã°æ¬¡ã®ããã«ããŸãã
<Directory /www/docs/private>
AuthName "Private"
AuthType Basic
AuthBasicProvider dbm
AuthDBMUserFile /www/passwords/passwd.dbm
Require valid-user
</Directory>
ãã®ä»ã®ãªãã·ã§ã³ãååšããŸãã詳现ã«é¢ããŠã¯
mod_authn_dbm
ã®ããã¥ã¡ã³ããã芧ãã ããã
èªèšŒæ¿èªã¢ãŒããã¯ãã£ã«åºã¥ããŠããæ°ãããããã€ãã䜿ããšã èªèšŒæ¿èªã®æ¹æ³ãã²ãšã€ã«çžãå¿ èŠããªããªããŸãã ããã€ãã®ãããã€ããçµã¿åãããŠãèªåã®æã¿ã®æåã«ã§ããŸãã æ¬¡ã®äŸã§ã¯ file èªèšŒãããã€ããš ldap èªèšŒãããã€ãã çµã¿åãããŠããŸãã
<Directory /www/docs/private>
AuthName "Private"
AuthType Basic
AuthBasicProvider file ldap
AuthUserFile /usr/local/apache/passwd/passwords
AuthLDAPURL ldap://ldaphost/o=yourorg
Require valid-user
ãã®äŸã§ã¯ããŸã file ãããã€ãããŠãŒã¶èªèšŒã詊ã¿ãŸãã èªèšŒã§ããªãã£ãå Žåã«ã¯ãldap ãããã€ããåŒã³åºãããŸãã çµç¹ã§è€æ°ã®èªèšŒæ ŒçŽæ¹æ³ã䜿ã£ãŠããéãªã©ã«ã ãã®æ¹æ³ã䜿ã£ãŠèªèšŒã®ã¹ã³ãŒããæ¡å€§ã§ããŸãã ããã²ãšã€ã®ã·ããªãªã¯ãã²ãšã€ã®èªèšŒã¿ã€ããšç°ãªãæ¿èªã çµã¿åãããæ¹æ³ã§ããããããšãã°ããã¹ã¯ãŒããã¡ã€ã«ã§èªèšŒããŠã ldap ãã£ã¬ã¯ããªã§æ¿èªãè¡ããšãã£ãå Žåã§ãã
èªèšŒãããã€ããè€æ°å®è£ ã§ããããã«ãæ¿èªæ¹æ³ãè€æ°äœ¿çšã§ããŸãã ãã®äŸã§ã¯ file ã°ã«ãŒãæ¿èªãš ldap ã°ã«ãŒãæ¿èªã䜿ã£ãŠããŸãã
<Directory /www/docs/private>
AuthName "Private"
AuthType Basic
AuthBasicProvider file
AuthUserFile /usr/local/apache/passwd/passwords
AuthLDAPURL ldap://ldaphost/o=yourorg
AuthGroupFile /usr/local/apache/passwd/groups
Require group GroupName
Require ldap-group cn=mygroup,o=yourorg
æ¿èªããã现ããå¶åŸ¡ãããå Žåã¯ã
<SatisfyAll>
ãš
<SatisfyOne>
ãã£ã¬ã¯ãã£ãã䜿ã£ãŠ AND/OR ããžãã¯ã§æå®ããèšå®ãã¡ã€ã«ã§
æ¿èªã®åŠçé çªã®å¶åŸ¡ãã§ããããã«ãªã£ãŠããŸãã
ãããã®ãã£ã¬ã¯ãã£ããã©ã®ããã«äœ¿ããããç¶²çŸ
ããäŸãã芧ãã ããã
æ¿èªã®æ¹æ³ã¯ãã²ãšã€ã®ããŒã¿ãœãŒã¹ãèŠãŠäžåã ããã§ãã¯ããã®ãšæ¯ã¹ãŠã ãã£ãšå€åœ©ãªé©ç𿹿³ãã§ããŸãã æ¿èªåŠçã®é©çšé åºãå¶åŸ¡ãéžæãã§ããããã«ãªããŸããã
æ¿èªãã©ã®ãããªé åºã§é©çšãããŠãããããŸãããããã©ã®ããã«å¶åŸ¡ãããã¯ã
ãããŸã§æ··ä¹±ãæããŠããŸããã
Apache 2.2 ã§ã¯ãããã€ãããŒã¹ã®èªèšŒã¡ã«ããºã ãå°å
¥ããã
æ¿èªåŠçããèªèšŒåŠçãšãµããŒãæ©èœãšãåãåããããŸããã
ããã«ããã²ãšã€ã®å¹æãšããŠã
èªèšŒã¢ãžã¥ãŒã«ã®ããŒãé ãã¢ãžã¥ãŒã«èªäœã®é åºã«äŸåããããšãªãã
æå®ããé çªã§èªèšŒãããã€ããåŒã³åºããããã
èšå®ã§ããããã«ãªããŸããã
ãã®ãããã€ãã¡ã«ããºã ã¯æ¿èªåŠçã§ãå°å
¥ãããŠããŸãã
ã€ãŸããRequire
ãã£ã¬ã¯ãã£ãã¯åã«ã©ã®æ¿èªææ³ã䜿ãããããæå®ããã ãã§ã¯ãªãã
ãããã®åŒã³åºãé åºãæå®ã§ããããã«ãªããŸããã
è€æ°ã®æ¿èªææ³ããããšãããã®åŒã³åºãé ã¯ãèšå®ãã¡ã€ã«ã®
Require
ãã£ã¬ã¯ãã£ãäžã§
çŸããé åºãšåãã«ãªããŸãã
远å ã§å°å
¥ããã
<SatisfyAll>
,
<SatisfyOne>
ãã£ã¬ã¯ãã£ãã䜿ã£ãŠãæ¿èªææ³ããã€åŒã³åºãããã¢ã¯ã»ã¹ãèš±å¯ãããéã«
ã©ã®æç¶ããé©çšããããæå®ããããšãã§ããŸãã
ããšãã°ãæ¬¡ã®æ¿èªãããã¯ã®ããžãã¯ãèŠãŠã¿ãŸããã:
# if ((user == "John") ||
# ((Group == "admin")
# && (ldap-group <ldap-object> contains auth'ed_user)
# && ((ldap-attribute dept == "sales")
# || (file-group contains auth'ed_user))))
# then
# auth_granted
# else
# auth_denied
#
<Directory /www/mydocs>
Authname ...
AuthBasicProvider ...
...
Require user John
<SatisfyAll>
Require Group admins
Require ldap-group cn=mygroup,o=foo
<SatisfyOne>
Require ldap-attribute dept="sales"
Require file-group
</SatisfyOne>
</SatisfyAll>
</Directory>
ããã©ã«ãã§ã¯ Require
ãã£ã¬ã¯ãã£ã㯠OR æäœãšããŠæ±ãããŸããã€ãŸããããæå®ããæ¿èªææ³ã®
ã²ãšã€ã§ãåæ Œããã°ãæ¿èªãããŸãã
Require
ãã£ã¬ã¯ãã£ãã®ã»ããã
ã²ãšã€ã® <SatisfyAll>
ãããã¯ã§å²ããšAND æäœãšãªããå
šãŠã®æ¿èªææ³ã§åæ Œããªããã°èš±å¯ãããŸããã
ãŠãŒã¶åãšãã¹ã¯ãŒãã«ããèªèšŒã¯å šäœã®äžéšåã§ãããããŸããã 誰ãã¢ã¯ã»ã¹ããŠããããšãã£ãæ å ±ä»¥å€ã®æ¡ä»¶ã䜿ãããã ãšããæãããšã§ãããã ããšãã°ãã©ãããã¢ã¯ã»ã¹ããŠããŠãããããšãã£ãå ·åã§ãã
æ¿èªãããã€ã all
,
env
,
host
,
ip
ã䜿ããšããªã¯ãšã¹ããéä¿¡ããŠããŠãããã·ã³ã®ãã¹ãåã IP ã¢ãã¬ã¹
ãšãã£ãããã¹ãããŒã¹ã§ã®ã¢ã¯ã»ã¹å¶åŸ¡ãã§ããŸãã
ããããããã€ãã®æ±ãã¯
Require
ã
Reject
ã§
æå®ãããŸãããããã®ãã£ã¬ã¯ãã£ãã¯æ¿èªãããã€ããç»é²ãã
ãªã¯ãšã¹ãåŠçã®æ¿èªæ®µéã§åŒã³åºãããŸããããšãã°:
Require ip address
ããã§ãaddress 㯠IP ã¢ãã¬ã¹ (ããã㯠IP ã¢ãã¬ã¹ã® äžéš) ã :
Require host domain_name
ããã§ domain_name 㯠FQDN (ãããã¯ãã¡ã€ã³åã®äžéš) ã§ãå¿ èŠã§ããã°è€æ°ã®ã¢ãã¬ã¹ããã¡ã€ã³åãæžãããšãã§ããŸãã
ããšãã°ãã¹ãã ã¡ãã»ãŒãžãéä¿¡ããŠãã誰ããæåŠãããå Žåã æ¬¡ã®ããã«ãªããŸã :
Reject ip 10.252.46.165
ãã®ãã£ã¬ã¯ãã£ããæå¹ãªç¯å²ã®ã³ã³ãã³ãã«å¯ŸããŠã¯ã ãã®ã¢ãã¬ã¹ããã¢ã¯ã»ã¹ããŠããŠãèŠãããšãã§ããŸããã ãããã·ã³åãããã£ãŠã㊠IP ã¢ãã¬ã¹ããããã¡ãã§ æå®ãããã®ã§ããã°ããã®ãã·ã³åã䜿ããŸãã
Reject host host.example.com
ãŸããç¹å®ã®ãã¡ã€ã³ããã®ã¢ã¯ã»ã¹å šãŠããããã¯ãããå Žåã¯ã IP ã¢ãã¬ã¹ã®äžéšãããã¡ã€ã³åãæå®ã§ããŸã :
<SatisfyAll>
Reject ip 192.168.205
Reject host phishers.example.com moreidiots.example
Reject host ke
</SatisfyAll>
Reject
ãã£ã¬ã¯ãã£ãã
<SatisfyAll>
ãããã¯ã®äžã§äœ¿ããšã
èš±å¯ãããã°ã«ãŒãã«ã®ã¿ã¢ã¯ã»ã¹ãã§ããããã«ç¢ºèªã§ããŸãã
äžèšã®äŸã§ã¯ <SatisfyAll>
ã䜿ã£ãŠãã¢ã¯ã»ã¹ã«åæ Œããåæ®µéã§ãå
šãŠã®
Reject
ãã£ã¬ã¯ãã£ãã
æºããããŠããããšã確èªããŠããŸãã
èªèšŒãããã€ãããŒã¹ã®æ©æ§ãããããã以å䜿çšãããŠãããã£ã¬ã¯ãã£ã
Order
,
Allow
,
Deny
,
Satisfy
ã¯å¿
èŠãªããªããŸããã
ãšã¯ãããã®ã®ãå€ãèšå®ãã¡ã€ã«ã§ã®åŸæ¹äºææ§ãæäŸããããã
ãããã®ãã£ã¬ã¯ãã£ã㯠mod_access_compat
ã¢ãžã¥ãŒã«ã«ç§»ãããŸããã
ãããã®ãã£ã¬ã¯ãã£ãã®æ±ããŠããåé¡ã®ã²ãšã€ã«ãæ¿èªã®èšå®è¡ãšã¢ã¯ã»ã¹å¶åŸ¡ã®èšå®è¡ã®
é¢ä¿ããšãŠããããŸãã ã£ãããšãæããããŸãã
Satisfy
ãã£ã¬ã¯ãã£ãã¯
ãªã¯ãšã¹ãåŠçäžã§ããèªèº«ãåŒã³åºãããšã«ãã£ãŠããããã® 2 ã€ã®åŠç段éãçµã³ã€ããããšããŸãã
çŸåšã¯ããããã®ãã£ã¬ã¯ãã£ã㯠mod_access_compat
ã«ç§»åãã
æ°ããèªèšŒãã£ã¬ã¯ãã£ããšå€ãã¢ã¯ã»ã¹å¶åŸ¡ãã£ã¬ã¯ãã£ããæ··ããŠäœ¿ãããšã¯
é£ãããªã£ãŠããŸãããã®åé¡ã®ãããmod_authz_default
ã¢ãžã¥ãŒã«ã
ããŒãããããšããšãŠãéèŠã§ãå¿
é ã«ãªã£ãŠããŸãã
mod_authz_default
ãã¢ãžã¥ãŒã«ã®äž»ãªç®çã¯ãã©ã®æ¿èªãããã€ãã§
åŠçãããªãã£ãæ¿èªãªã¯ãšã¹ããåããããšã«ãããŸãã
ããããå€ãã¢ã¯ã»ã¹å¶åŸ¡ãã£ã¬ã¯ãã£ããçšããããå Žåã«ã¯ã
ã¢ã¯ã»ã¹å¶åŸ¡ãšæ¿èªãçµã³ã€ããŠããã¹ãŠã®åŠç段éã®åºåçµæãèŠãŠã¢ã¯ã»ã¹ã«åæ Œããããæ±ºããŠããŸãã
ã§ããããå€ããã£ã¬ã¯ãã£ããããŸãåäœããªãå Žåã¯ã
mod_authz_default
ãããŒããããŠããªããããããããªãã
ãšçã£ãŠã¿ãŠãã ããã
ãããå
šãŠãã©ã®ããã«åäœãããã«ã€ããŠ
ãã£ãšå€ãã®æ
å ±ãæžãããŠãã mod_auth_basic
ãš
mod_authz_host
ã®ææžãèªããšããã§ãããã
<AuthnProviderAlias>
ãã£ã¬ã¯ãã£ãã䜿ããšãç¹å®ã®èªèšŒèšå®ãç°¡åã«æžããããã«ãªããŸãã
ã¢ã¯ã»ã¹å¶åŸ¡ã®æ¹æ³ãã é¢é£ãããããã¯ãããããèšèŒãããŠããŸãã®ã§ãã芧ãã ããã