data:image/s3,"s3://crabby-images/b8ae6/b8ae6e7fcb7af0fa49dac2db2d52905023d7ac87" alt="Novell LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007 Скачать руководство пользователя страница 860"
For the sake of simplicity, assume you are setting up just one realm for your entire or-
ganization. For the remainder of this section, the realm name
EXAMPLE.COM
is used
in all examples.
46.2 Setting Up the KDC Hardware
The first thing required to use Kerberos is a machine that acts as the key distribution
center, or KDC for short. This machine holds the entire Kerberos user database with
passwords and all information.
The KDC is the most important part of your security infrastructure—if someone breaks
into it, all user accounts and all of your infrastructure protected by Kerberos is compro-
mised. An attacker with access to the Kerberos database can impersonate any principal
in the database. Tighten security for this machine as much as possible:
1
Put the server machine into a physically secured location, such as a locked server
room to which only a very few people have access.
2
Do not run any network applications on it except the KDC. This includes servers
and clients—for example, the KDC should not import any file systems via NFS
or use DHCP to retrieve its network configuration.
3
Install a minimal system first then check the list of installed packages and remove
any unneeded packages. This includes servers, such as inetd, portmap, and cups,
as well as anything X-based. Even installing an SSH server should be considered
a potential security risk.
4
No graphical login is provided on this machine as an X server is a potential secu-
rity risk. Kerberos provides its own administration interface.
5
Configure
/etc/nsswitch.conf
to use only local files for user and group
lookup. Change the lines for
passwd
and
group
to look like this:
passwd: files
group: files
Edit the
passwd
,
group
,
shadow
, and
gshadow
files in
/etc
and remove
the lines that start with a
+
character (these are for NIS lookups).
842
Installation and Administration
Содержание LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007
Страница 1: ...SUSE Linux Enterprise Server www novell com 10 May 11 2007 Installation and Administration...
Страница 14: ......
Страница 19: ...Part I Deployment...
Страница 20: ......
Страница 60: ......
Страница 128: ......
Страница 243: ...Part II Administration...
Страница 244: ......
Страница 274: ......
Страница 312: ......
Страница 348: ......
Страница 380: ......
Страница 381: ...Part III System...
Страница 382: ......
Страница 438: ......
Страница 452: ......
Страница 478: ......
Страница 486: ......
Страница 498: ......
Страница 512: ......
Страница 558: ......
Страница 559: ...Part IV Services...
Страница 560: ......
Страница 652: ......
Страница 670: ......
Страница 742: ......
Страница 754: ......
Страница 796: ......
Страница 817: ...Part V Security...
Страница 818: ......
Страница 858: ......
Страница 886: ......
Страница 910: ......
Страница 911: ...Part VI Troubleshooting...
Страница 912: ......
Страница 924: ......