´ÙÀ½ ÀÌÀü Â÷·Ê

7. NIS+¸¦ ¼³Ä¡Çϱâ À§ÇØ ÇÊ¿äÇÑ °ÍµéÀº ¹«¾ùÀΰ¡?

7.1 ÇÊ¿äÇÑ ¼ÒÇÁÆ®¿þ¾î

¸®´ª½º NIS+ÄÚµå´Â GNU C ¶óÀ̺귯¸® 2¸¦ À§ÇØ ¸¸µé¾îÁ³´Ù. ´ëºÎºÐÀÇ »ó¾÷¿ë ¾î Çø®ÄÉÀ̼ǵéÀÌ libc5¿¡ ¸µÅ©¸¦ °É¾î ³õ°í À־, ¸®´ª½º libc5¿ëÀ¸·Îµµ Æ÷Æà µÇ¾î ÀÖ´Ù. ¿©·¯ºÐÀº libc¸¦ °¡Áö°í ±×°ÍÀ» ´Ù½Ã ÄÄÆÄÀÏ ÇÒ ¼ö ¾ø´Ù. libc5¿Í N IS+¿¡´Â ´ÙÀ½°ú °°Àº ¹®Á¦°¡ ÀÖ´Ù. static ÇÁ·Î±×·¥µéÀº ±×°Í°ú ¸µÅ©µÉ ¼ö ¾ø°í ,ÀÌ ¶óÀ̺귯¸®¿¡ ÀÇÇØ ÄÄÆÄÀÏ µÈ ÇÁ·Î±×·¥µéÀº ´Ù¸¥ libc5¹öÀü¿¡¼­ ½ÇÇàµÇÁö ¾ÊÀ» °ÍÀÌ´Ù.

¿©·¯ºÐÀº ÀÎÅÚ±â¹ÝÀÇ Ç÷§È¨À» À§ÇØ, GNU C ¶óÀ̺귯¸® 2.1·Î ¼öÁ¤ÇÏ°í ÄÄÆÄÀÏ ÇØ¾ß ÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. 64bit Ç÷§Æû¿¡¼­´Â GNU C ¶óÀ̺귯¸® 2.1.1·Î ÇؾßÇÑ´Ù. ±Ù°£ ½Ã½ºÅÛÀ¸·Î´Â µ¥ºñ¾È 2.x, ·¹µåÇÞ 5.x, ¼ö¼¼ 6.x °°Àº glibc°¡ ±Ù°£ÀÎ ¹è Æ÷ÆÇÀ» ÇÊ¿ä·Î ÇÒ °ÍÀÌ´Ù.

¸ðµç ¹èÆ÷ÆÇÀ» À§ÇÏ¿©, gcc/g++ ÄÄÆÄÀÏ·¯¿Í libstc++, ncures¸¦ ´Ù½Ã ÄÄÆÄÀÏÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. ·¹µåÇÞ¿¡¼­, ¿©·¯ºÐÀº ¸¹Àº °æ¿ì PAM ¼³Á¤À» º¯°æÇÏ´Â °ÍÀ» ¸¹ÀÌ ÇÏ°Ô µÈ´Ù. ¼ö¼¼ ¸®´ª½º 6.0 ¿¡¼­´Â ½¦µµ¿ì ÆäÅ°Áö¸¦ ´Ù½Ã ÄÄÆÄÀÏ ÇÒ ÇÊ¿ä°¡ ÀÖ ´Ù.

NIS+ Ŭ¶óÀ̾ðÆ® ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÀ½À¸·Î ºÎÅÍ ¾òÀ» ¼ö ÀÖ´Ù:

Site            Directory                       File Name

ftp.funet.fi    /pub/gnu/funet                  libc-*, glibc-crypt-*,
                                                glibc-linuxthreads-*
ftp.kerbel.org  /pub/linux/utils/net/NIS+       nis-utils-19990223.tar.gz
ftp.kerbel.org  /pub/linux/utils/net/NIS+       pam_keylogin-1.2.tar.gz

¹èÆ÷ÆÇÀÇ glibc´Â ´ÙÀ½À¸·Î ºÎÅÍ ÆÐÄ¡ÇÒ ¼ö ÀÖ´Ù.

Site            Directory

ftp.debian.org  /pub/debian/dists/slink
ftp.redhat.com  /pub/redhat/redhat-5.2
ftp.suse.de     /pub/SuSE-Linux/6.0

GNU C ¶óÀ̺귯¸®¸¦ °íÃļ­ ¸¸µç ¼ÒÇÁÆ®¿þ¾îµé¿¡ ´ëÇؼ­´Â Æ÷ÇÔµÈ Áö½Ã¹®À» Àß ÀÐ¾î º¸±æ ¹Ù¶õ´Ù. ¿©·¯ºÐÀº NYS¿¡ ±Ù°£ÇÑ libc5 ÆÐÄ¡¸¦ ãÀ» ¼ö ÀÖ´Ù. Ç¥ÁØ li bc5¸¦ ´ëüÇÑ ±× ¼Ò½º´Â ´ÙÀ½ Àå¼Ò¿¡ ÀÖ´Ù:

Site            Directory               File Name

ftp.kernel.org  /pub/linux/utils/NIS+   libc-5.4.44-nsl-0.4.10.tar.gz

¿©·¯ºÐÀº http://www.suse.de/~kukuk/linux/nisplus.html ¿¡¼­ ´õ ¸¹Àº Á¤º¸¿Í ÃֽŠ¹öÀüÀÇ ¼Ò½º¸¦ ¾òÀ» ¼ö ÀÖ´Ù.

7.2 NIS+ Ŭ¶óÀ̾ðÆ® ¼³Ä¡Çϱâ

Áß¿ä»çÇ× : NIS+ Ŭ¶óÀ̾ðÆ®¸¦ ¼¼ÆÃÇϱâ À§ÇÏ¿© ¼­¹öÂÊ¿¡¼­ ¾î¶»°Ô µÇ´ÂÁö ³ª¿Í ÀÖ´Â ¼Ö¶ó¸®½º NIS+ ¹®¼­¸¦ Àо¶ó! ÀÌ ¹®¼­´Â ´ÜÁö Ŭ¶óÀ̾ðÆ® ÂÊ¿¡¼­ ¹«¾ù À» ÇÏ´ÂÁö¿¡ ´ëÇÏ¿©¸¸ ³ª¿ÍÀÖ´Ù!

»õ·Î¿î glibc¿Í nis-toolµéÀ» ¼³Ä¡ÇÑ ÈÄ¿¡, NIS+ ¼­¹öÀÇ »õ·Î¿î Ŭ¶óÀ̾ðÆ®µé À» À§ÇÏ¿© º¸ÁõÀ» Çضó. portmapÀÌ µ¹¾Æ°¡°í ÀÖ´Ù´Â °ÍÀ» È®ÀÎÇضó. ±×¸®°í ¿© ·¯ºÐÀÇ ¸®´ª½ºPC°¡ NIS+ ¼­¹ö¿Í °°Àº ½Ã°£ÀÌ ¼³Á¤µÇ¾ú´ÂÁö üũ¸¦ Ç϶ó. ¾ÈÀü ÇÑ RPC¸¦ À§ÇØ, º¸ÁõÀÌ À¯È¿ÇÑ ¾à 3ºÐÁ¤µµ ´ÜÁö ÇϳªÀÇ ÀÛÀº À©µµ¿ì¸¦ °¡Áø´Ù. ¸ðµç È£½ºÆ®¿¡ xntpd¸¦ ½ÇÇà½ÃÅ°´Â ÁÁÀº ¹æ¹ýÀÌ ÀÖ´Ù. ÀÌ°ÍÀ» ÇÑ ÈÄ¿¡ ´ÙÀ½À» ½ÇÇàÇ϶ó.

domainname nisplus.domain.
nisinit -c -H <NIS+ server>

¾Æ¹«·± ¿É¼ÇÀÌ ¾ø´Â ½ÃÀÛÆÄÀÏÀ» ÃʱâÈ­Çϱâ À§ÇØ, nisinit ¸Ç ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ ¶ó. domainnameÀº Ç×»ó ¸®ºÎÆ® ÈÄ¿¡ ¼¼Æà µÈ´Ù´Â °ÍÀ» ¸í½ÉÇ϶ó. ¸¸ÀÏ ³×Æ®¿÷¿¡ ¼­ NIS+ µµ¸ÞÀÎ ³×ÀÓÀÌ ¹«¾ùÀÎÁö ¸ð¸£¸é, ¿©·¯ºÐÀÇ ½Ã½ºÅÛ/³×Æ®¿öÅ© °ü¸®ÀÚ¿¡°Ô ¹®ÀÇÇ϶ó.

ÀÌÁ¦ /etc/nsswitch.confÆÄÀÏÀ» º¯°æÇØ¾ß ÇÑ´Ù. ´ÜÁö publickeyµÚ¿¡ ¿À´Â ¼­ºñ ½º´Â nisnis¹Û¿¡ ¾ø´Ù´Â °ÍÀ» ¸í½ÉÇ϶ó. ( "publickey: nisnis" )

±×¸®°í keyserv¸¦ ½ÇÇà½ÃÄѶó. ¸í½ÉÇÒ °ÍÀº ÀÌ°ÍÀÌ ½Ã½ºÅÛÀÌ ºÎÆ®µÉ ¶§, portma pÀÌ ½ÇÇàµÇ°í ³ª¼­ ¹Ù·Î óÀ½À¸·Î ½ÇÇàµÇ´Â µ¥¸óÀ̶ó´Â °ÍÀÌ´Ù. ½Ã½ºÅÛ¿¡¼­ roo tÀÇ ºñ¹ÐÅ°¸¦ ÀúÀåÇϱâ À§ÇØ, ´ÙÀ½°ú °°ÀÌ ½ÇÇàÇ϶ó.

keylogin -r
(³ª´Â ¿©·¯ºÐÀÌ NIS+ ¼­¹ö¿¡ ´ëÇÑ »õ·Î¿î È£½ºÆ®¸¦ À§ÇØ publickey¸¦ Ãß°¡ ÇßÀ» °Å¶ó ±â´ëÇÑ´Ù?)

"niscat passwd.org_dir"Àº Æнº¿öµå µ¥ÀÌÅͺ£À̽ºÀÇ ¸ðµç ¿£Æ®¸®¸¦ ³ªÅ¸³»¾ß ÇÑ´Ù.

7.3 NIS+, keylogin, login ±×¸®°í PAM

À¯Àú°¡ ·Î±äÀ» ÇßÀ» ¶§, keyserv¸¦ À§ÇØ °¢ À¯ÀúÀÇ ºñ¹ÐÅ°¸¦ ¼¼ÆÃÇÒ ÇÊ¿ä°¡ ÀÖ ´Ù. ÀÌ°ÍÀº "keylogin"À̶ó °Í¿¡ ÀÇÇØ µÈ´Ù. ½¦µµ¿ì ÆÐÅ°Áö¿¡¼­ÀÇ ·Î±äÀº glibc 2.1¿¡ ÀÇÇØ ÄÄÆÄÀϵǾî ÀÖ´Ù¸é ¾Ë¾Æ¼­ ¼¼ÆÃÇÑ´Ù. PAM aware ·Î±ä¸¦ À§ÇÏ¿©, ¿© ·¯ºÐÀº NIS+¸¦ Áö¿øÇÏÁö ¾Ê´Â pwdb°¡ ¾Æ´Ñ pam_unix_auth ¸¦ »ç¿ëÇϱâ À§ÇØ, pam-keylogin-1.2.tar.gz¸¦ ¼³Ä¡ÇÏ°í /etc/pam.d/loginÆÄÀÏÀ» ¼öÁ¤ÇØ¾ß ÇÑ´Ù. ¿¹ ¸¦ µé¾î:


#%PAM-1.0
auth            required        /lib/security/pam_securetty.so
auth            required        /lib/security/pam_keylogin.so
auth            required        /lib/security/pam_unix_auth.so
auth            required        /lib/security/pam_nologin.so
account         required        /lib/security/pam_unix_acct.so
password        required        /lib/security/pam_unix_passwd.so
session         required        /lib/security/pam_unix_session.so

7.4 nsswitch.conf ÆÄÀÏ

³×Æ®¿öÅ© ¼­ºñ½º ½ºÀ§Ä¡( network service switch ) ÆÄÀÏ /etc/nsswitch.conf ´Â /etc/host.confÆÄÀÏÀÌ È£½ºÆ®¸¦ ã´Â ¹æ¹ýµéÀ» °áÁ¤ÇÏ´Â °Í°ú °°ÀÌ, ¾î¶² Á¤º¸°¡ ¿ä±¸ µÇ¾îÁ³À»¶§, ±×°ÍÀ» ã´Â ¼ø¼­¸¦ °áÁ¤ÇÑ´Ù. ¿¹¸¦ µé¾î¼­ ´ÙÀ½ ¶ó ÀÎÀ» º¸¸é,

        hosts: files nisplus dns

ÀÌ°ÍÀº È£½ºÆ®¸¦ ã´Â Æã¼Ç¿¡¼­ ¸ÕÀú ·ÎÄÃÀÇ /etc/hosts ÆÄÀÏ¿¡¼­ ¸ÕÀú ã°í, ±× ´ÙÀ½ NIS+¿¡ ÀÇÇØ Ã£°í, ¸¶Áö¸·À¸·Î µµ¸ÞÀÎ ³×ÀÓ ¼­ºñ½º(/etc/resolv.conf ¿Í named)¸¦ ÅëÇØ Ã£´Â´Ù. ÀÌ °æ¿ì ¸Â´Â °ÍÀ» ¸øã¾ÒÀ» °æ¿ì ¿¡·¯°¡ ¸®ÅϵȴÙ.

´ÙÀ½Àº NIS+¸¦ À§ÇÑ /etc/nsswitch.confÀÇ ÁÁÀº ¿¹ÀÌ´Ù.

#
# /etc/nsswitch.conf
#
# An example Name Service Switch config file. This file should be
# sorted with the most-used services at the beginning.
#
# The entry '[NOTFOUND=return]' means that the search for an
# entry should stop if the search in the previous entry turned
# up nothing. Note that if the search failed due to some other reason
# (like no NIS server responding) then the search continues with the
# next entry.
#
# Legal entries are:
#
#   nisplus or nis+     Use NIS+ (NIS version 3)
#   nis or yp       Use NIS (NIS version 2), also called YP
#   dns         Use DNS (Domain Name Service)
#   files           Use the local files
#   db          Use the local database (.db) files
#   compat          Use NIS on compat mode
#   [NOTFOUND=return]   Stop searching if not found so far
#

passwd:         compat
# for libc5: passwd: files nisplus
group:          compat
# for libc5: group: files nisplus
shadow:         compat
# for libc5: shadow: files nisplus

passwd_compat: nisplus
group_compat: nisplus
shadow_compat: nisplus

hosts:          nisplus files dns

services:   nisplus [NOTFOUND=return] files
networks:   nisplus [NOTFOUND=return] files
protocols:  nisplus [NOTFOUND=return] files
rpc:        nisplus [NOTFOUND=return] files
ethers:     nisplus [NOTFOUND=return] files
netmasks:   nisplus [NOTFOUND=return] files
netgroup:   nisplus
bootparams: nisplus [NOTFOUND=return] files
publickey:  nisplus
automount:  files
aliases:    nisplus [NOTFOUND=return] files


´ÙÀ½ ÀÌÀü Â÷·Ê