Áú»¢¶Ä²©

14 §¯§Ñ§Ý§Ñ§ê§ä§å§Ó§Ñ§ß§ß§ñ Kerberos §Ù§Ñ §Õ§à§á§à§Þ§à§Ô§à§ð Áú»¢¶Ä²©

§°§Ô§Ý§ñ§Õ

§¡§Ó§ä§Ö§ß§ä§Ú§æ?§Ü§Ñ§è?§ð Kerberos §Þ§à§Ø§ß§Ñ §Ó§Ú§Ü§à§â§Ú§ã§ä§à§Ó§å§Ó§Ñ§ä§Ú §Ó §Ó§Ö§Ò-§Þ§à§ß?§ä§à§â§Ú§ß§Ô§å §ä§Ñ §Ö§Ý§Ö§Þ§Ö§ß§ä§Ñ§ç HTTP §Ó Áú»¢¶Ä²©, §á§à§é§Ú§ß§Ñ§ð§é§Ú §Ù §Ó§Ö§â§ã?? 4.4.0.

§µ §è§î§à§Þ§å §â§à§Ù§Õ?§Ý? §à§á§Ú§ã§Ñ§ß§à §á§â§Ú§Ü§Ý§Ñ§Õ §ß§Ñ§Ý§Ñ§ê§ä§å§Ó§Ñ§ß§ß§ñ Kerberos ?§Ù §ã§Ö§â§Ó§Ö§â§à§Þ Áú»¢¶Ä²© §Õ§Ý§ñ §Ó§Ú§Ü§à§ß§Ñ§ß§ß§ñ §Ó§Ö§Ò-§Þ§à§ß?§ä§à§â§Ú§ß§Ô§å www.example.com §Ù§Ñ §Õ§à§á§à§Þ§à§Ô§à§ð §Ü§à§â§Ú§ã§ä§å§Ó§Ñ§é§Ñ 'zabbix'.

§¬§â§à§Ü§Ú

§¬§â§à§Ü 1

§£§ã§ä§Ñ§ß§à§Ó?§ä§î §á§Ñ§Ü§Ö§ä Kerberos.

§¥§Ý§ñ Debian/Ubuntu:

 apt install krb5-user

§¥§Ý§ñ RHEL:

 dnf install krb5-workstation
§¬§â§à§Ü 2

§¯§Ñ§Ý§Ñ§ê§ä§å§Ó§Ñ§ä§Ú §æ§Ñ§Û§Ý §Ü§à§ß§æ?§Ô§å§â§Ñ§è?? Kerberos (§Õ§à§Ü§Ý§Ñ§Õ§ß?§ê§Ö §Õ§Ú§Ó. §å §Õ§à§Ü§å§Þ§Ö§ß§ä§Ñ§è?? MIT)

cat /etc/krb5.conf 
       [libdefaults]
           default_realm = EXAMPLE.COM
       
       # Les variables krb5.conf seg¨¹ents s¨®n nom¨¦s per a MIT Kerberos.
           kdc_timesync = 1
           ccache_type = 4
           forwardable = true
           proxiable = true
       
       [realms]
           EXAMPLE.COM = {
           }
       
       [domain_realm]
           .example.com=EXAMPLE.COM
           example.com=EXAMPLE.COM
§¬§â§à§Ü 3

§³§ä§Ó§à§â?§ä§î §Ü§Ó§Ú§ä§à§Ü Kerberos §Õ§Ý§ñ §Ü§à§â§Ú§ã§ä§å§Ó§Ñ§é§Ñ zabbix. §£§Ú§Ü§à§ß§Ñ§Û§ä§Ö §ß§Ñ§ã§ä§å§á§ß§å §Ü§à§Þ§Ñ§ß§Õ§å §Ó?§Õ ?§Þ§Ö§ß? §Ü§à§â§Ú§ã§ä§å§Ó§Ñ§é§Ñ zabbix:

 kinit zabbix

§£§Ñ§Ø§Ý§Ú§Ó§à §Ó§Ú§Ü§à§ß§Ñ§ä§Ú §ß§Ñ§Ó§Ö§Õ§Ö§ß§å §Ó§Ú§ë§Ö §Ü§à§Þ§Ñ§ß§Õ§å §ñ§Ü §Ü§à§â§Ú§ã§ä§å§Ó§Ñ§é zabbix. §Á§Ü§ë§à §Ó§Ú §Ù§Ñ§á§å§ã§ä§Ú§ä§Ö §Û§à§Ô§à §ñ§Ü root, §Ñ§Ó§ä§Ö§ß§ä§Ú§æ?§Ü§Ñ§è?§ñ §ß§Ö §á§â§Ñ§è§ð§Ó§Ñ§ä§Ú§Þ§Ö.

§¬§â§à§Ü 4

§³§ä§Ó§à§â?§ä§î §Ó§Ö§Ò-§ã§è§Ö§ß§Ñ§â?§Û §Ñ§Ò§à §Ö§Ý§Ö§Þ§Ö§ß§ä HTTP-§Ñ§Ô§Ö§ß§ä§Ñ §Ù §ä§Ú§á§à§Þ §Ñ§Ó§ä§Ö§ß§ä§Ú§æ?§Ü§Ñ§è?? Kerberos.

§¥§à§Õ§Ñ§ä§Ü§à§Ó§à §Þ§à§Ø§ß§Ñ §á§Ö§â§Ö§Ó?§â§Ú§ä§Ú §Ù§Ñ §Õ§à§á§à§Þ§à§Ô§à§ð §ä§Ñ§Ü§à? §Ü§à§Þ§Ñ§ß§Õ§Ú curl:

 curl -v --negotiate -u : http://example.com

§©§Ó§Ö§â§ß?§ä§î §å§Ó§Ñ§Ô§å, §ë§à §Õ§Ý§ñ §ä§â§Ú§Ó§Ñ§Ý§à§Ô§à §Ó§Ö§Ò-§Þ§à§ß?§ä§à§â§Ú§ß§Ô§å §ß§Ö§à§Ò§ç?§Õ§ß§à §á§à§Õ§Ò§Ñ§ä§Ú §á§â§à §à§ß§à§Ó§Ý§Ö§ß§ß§ñ §Ü§Ó§Ú§ä§Ü§Ñ Kerberos. §©§Ñ §Ù§Ñ§Þ§à§Ó§é§å§Ó§Ñ§ß§ß§ñ§Þ §ä§Ö§â§Þ?§ß §Õ?? §Ü§Ó§Ú§ä§Ü§Ñ §ã§ä§Ñ§ß§à§Ó§Ú§ä§î 10 §Ô§à§Õ§Ú§ß.