翻訳æ¸ã¿è¨èª: en | es | fr | ja | ko | tr
ãã®æ¥æ¬èªè¨³ã¯ãã§ã«å¤ããªã£ã¦ãã å¯è½æ§ãããã¾ãã æè¿æ´æ°ãããå 容ãè¦ãã«ã¯è±èªçãã覧ä¸ããã
ãèªè¨¼ãã¨ã¯ã誰ããèªåã¯èª°ã§ãããã主張ããå ´åã«ã ããã確èªããããã®å ¨éç¨ãæãã¾ãããæ¿èªãã¨ã¯ã 誰ããè¡ãããå ´æã«è¡ããããã«ããããã¯æ¬²ããæ å ±ã å¾ããã¨ãã§ããããã«ããããã®å ¨éç¨ãæãã¾ãã
ã¯ããã«ããæ©å¯ã®æ å ±ããããããå°æ°ã°ã«ã¼ãã®äººåãã®æ å ±ã ã¦ã§ããµã¤ãã«ç½®ãã®ã§ããã°ããã®ææ¸ã«æ¸ããã¦ãã ãã¯ããã¯ã使ããã¨ã§ããã®ãã¼ã¸ãè¦ã¦ãã人ãã¡ã æã¿ã®äººãã¡ã§ãããã¨ã確å®ã«ã§ããã§ãããã
ãã®ææ¸ã§ã¯ãå¤ãã®äººãæ¡ç¨ããã§ãããã ã¦ã§ããµã¤ãã®ä¸é¨åãä¿è·ãããä¸è¬çãªã æ¹æ³ã«ã¤ãã¦ã«ãã¼ãã¦ãã¾ãã
注æãã¼ã¿ãæ¬å½ã«æ©å¯ãªã®ã§ããã°ãèªè¨¼ã«å ãã¦ããã« mod_ssl
ã使ãã¨è¯ãã§ãããã
ãã®ææ¸ã§åãæ±ããããã£ã¬ã¯ãã£ãã¯ã ã¡ã¤ã³ãµã¼ãè¨å®ãã¡ã¤ã« (æ®é㯠<Directory>
ã»ã¯ã·ã§ã³ä¸) ãããããã¯ãã£ã¬ã¯ããªæ¯ã®è¨å®ãã¡ã¤ã« (.htaccess
ãã¡ã¤ã«) ãã§ç¨ãã¾ãã
.htaccess
ãã¡ã¤ã«ãç¨ããã®ã§ããã°ã ãããã®ãã¡ã¤ã«ã«èªè¨¼ç¨ã®ãã£ã¬ã¯ãã£ããç½®ããããã« ãµã¼ãã®è¨å®ãããªãã¨ãããªãã§ãããããã㯠AllowOverride
ãã£ã¬ã¯ãã£ãã§å¯è½ã«ãªãã¾ãã AllowOverride
ãã£ã¬ã¯ãã£ãã§ã¯ããã£ã¬ã¯ããªæ¯ã®è¨å®ãã¡ã¤ã«ä¸ã«ç½®ããã¨ã®ã§ãã ãã£ã¬ã¯ãã£ãããããããã°ãæå®ãã¾ãã
èªè¨¼ã«ã¤ãã¦è©±ãé²ãã¦ããã®ã§ã次ã®ãã㪠AllowOverride
ãã£ã¬ã¯ãã£ããå¿
è¦ã«ãªãã§ãããã
AllowOverride AuthConfig
ããã§ãªããã¡ã¤ã³ãµã¼ãè¨å®ãã¡ã¤ã«ã®ä¸ã« ç´æ¥ç½®ãã®ã§ããã°ãå½ç¶ãªãããã®ãã¡ã¤ã«ã¸ã®æ¸ã込㿠権éãæã£ã¦ããªããã°ãªããªãã§ãããã
ã¾ããã©ã®ãã¡ã¤ã«ãã©ãã«ä¿åããã¦ãããç¥ãããã«ã ãµã¼ãã®ãã£ã¬ã¯ããªæ§é ã«ã¤ãã¦å°ãç¥ã£ã¦ãã å¿ è¦ãããã§ãããã ããã¯ãããªã«é£ãããªãã®ã§ããã®ææ¸ä¸ã§ ãã£ã¬ã¯ããªæ§é ã«ã¤ãã¦ç¥ã£ã¦ããå¿ è¦ãããå ´é¢ã§ã¯ã æããã«ãªãããã«ãã¾ãã
mod_authn_core
㨠mod_authz_core
ã®ä¸¡æ¹ã httpd ãã¤ããªã«éçã«çµã¿è¾¼ã¿æ¸ã¿ã§ããããhttpd.conf è¨å®ãã¡ã¤ã«ã§åçã«ãã¼ããããããã¦ãhttpd ã«çµã¿è¾¼ã¾ãã¦ããªããã° ãªãã¾ããããããã®äºã¤ã®ã¢ã¸ã¥ã¼ã«ã¯ãè¨å®ãã¡ã¤ã«ã®ãªãã§é常㫠éè¦ã§ã¦ã§ããµã¼ãã®èªè¨¼ã¨æ¿èªã§ä½¿ç¨ãããã³ã¢ãã£ã¬ã¯ãã£ã㨠ãã®æ©è½ãæä¾ãã¦ãã¾ãã
ã§ã¯ããµã¼ãä¸ã®ãããã£ã¬ã¯ããªããã¹ã¯ã¼ãã§ä¿è·ãã åºæ¬æé ã示ãã¾ãã
ã¾ãã¯ããã«ããã¹ã¯ã¼ããã¡ã¤ã«ãä½ãã¾ãã ã©ã®èªè¨¼ãããã¤ãã使ããã«ãã£ã¦ããã¹ã¯ã¼ããã¡ã¤ã«çæã®æé 㯠大ããç°ãªãã¾ããããã§ã®ä¾ã§ã¯ãæå§ãã«ããã¹ããã¹ã¯ã¼ããã¡ã¤ã«ã 使ãã¾ãã
ãã®ãã¹ã¯ã¼ããã¡ã¤ã«ã¯ãã¦ã§ãããã¢ã¯ã»ã¹ã§ããå ´æã« ç½®ãã¹ãã§ã¯ããã¾ãããä»ã®äººããã¹ã¯ã¼ããã¡ã¤ã«ã ãã¦ã³ãã¼ãã§ããªãããã«ããããã§ããä¾ãã°ã /usr/local/apache/htdocs
ã§ããã¥ã¡ã³ãã æä¾ãã¦ããã®ã§ããã°ããã¹ã¯ã¼ããã¡ã¤ã«ã¯ /usr/local/apache/passwd
ãªã©ã«ç½®ããæ¹ãè¯ãã§ãããã
ãã¡ã¤ã«ãä½ãããã«ã¯ãApache ä»å±ã® htpasswd
ã使ãã¾ãããã®ã³ãã³ã㯠Apache ãã©ãã«ã¤ã³ã¹ãã¼ã«ãããã¨ãã ã¤ã³ã¹ãã¼ã«ãã£ã¬ã¯ããªã® bin
ãã£ã¬ã¯ããªä»¥ä¸ã«ç½®ããã¾ãããµã¼ããã¼ãã£è£½ã®ããã±ã¼ã¸ã§ ã¤ã³ã¹ãã¼ã«ããå ´åã¯ãå®è¡ãã¹ã®ä¸ã§è¦ã¤ããã§ãããã
ãã¡ã¤ã«ãä½ãã«ã¯ã次ã®ããã«ã¿ã¤ããã¦ãã ããã
htpasswd -c /usr/local/apache/passwd/passwords rbowen
htpasswd
ã¯ããã¹ã¯ã¼ããè¦æ±ãããã®å¾ 確èªã®ããã«ããä¸åº¦å
¥åããããã«è¦æ±ãã¦ãã¾ãã
# htpasswd -c /usr/local/apache/passwd/passwords rbowen
New password: mypassword
Re-type new password: mypassword
Adding password for user rbowen
ãã htpasswd
ããã¹ã®ä¸ã«å
¥ã£ã¦ããªãå ´åã¯ã ãã¡ãããå®è¡ããããã«ããã°ã©ã ã¾ã§ã®ãã«ãã¹ã ã¿ã¤ãããå¿
è¦ãããã¾ããããã©ã«ãã®ã¤ã³ã¹ãã¼ã«ç¶æ
ã§ããã°ã /usr/local/apache/bin/htpasswd
ã«ããã°ã©ã ãç½®ããã¦ãã¾ãã
次ã«ããµã¼ãããã¹ã¯ã¼ããè¦æ±ããããã«è¨å®ãã¦ã ã©ã®ã¦ã¼ã¶ãã¢ã¯ã»ã¹ã許ããã¦ãããããµã¼ãã«ç¥ãããªããã° ãªãã¾ããã httpd.conf
ãç·¨éããã .htaccess
ãã¡ã¤ã«ã使ç¨ãããã§ è¨å®ãã¾ããä¾ãã°ããã£ã¬ã¯ã㪠/usr/local/apache/htdocs/secret
ãä¿è·ãããå ´åã¯ã /usr/local/apache/htdocs/secret/.htaccess
ã httpd.conf ä¸ã® <Directory /usr/local/apache/htdocs/secret> ã»ã¯ã·ã§ã³ã« é
ç½®ãã¦ã次ã®ãã£ã¬ã¯ãã£ãã使ããã¨ãã§ãã¾ãã
AuthType Basic
AuthName "Restricted Files"
# (Following line optional)
AuthBasicProvider file
AuthUserFile /usr/local/apache/passwd/passwords
Require user rbowen
åã
ã®ãã£ã¬ã¯ãã£ãã«ã¤ãã¦è¦ã¦ã¿ã¾ãããã AuthType
ãã£ã¬ã¯ãã£ãã¯ã©ãããèªè¨¼æ¹æ³ã§ã¦ã¼ã¶ã®èªè¨¼ãè¡ããã 鏿ãã¾ããæãä¸è¬çãªæ¹æ³ã¯ Basic
ã§ããã㯠mod_auth_basic
ã§å®è£
ããã¦ãã¾ããããããªããã ããã¯æ°ãä»ããã¹ãéè¦ãªãã¤ã³ããªã®ã§ããã Basic èªè¨¼ã¯ã¯ã©ã¤ã¢ã³ããããµã¼ãã¸ã ãã¹ã¯ã¼ããæå·åããã«éãã¾ããã§ããããã®æ¹æ³ã¯ã mod_ssl
ã¨çµã¿åãããªãç¶æ
ã§ã¯ã ç¹ã«æ©å¯æ§ã®é«ããã¼ã¿ã«å¯¾ãã¦ã¯ç¨ããã¹ãã§ã¯ ããã¾ããã Apache ã§ã¯ããä¸ã¤å¥ã®èªè¨¼æ¹æ³: AuthType Digest
ããµãã¼ããã¦ãã¾ãã ãã®æ¹æ³ã¯ mod_auth_digest
ã§å®è£
ããã¦ãã¦ããã£ã¨å®å
¨ã§ãã æè¿ã®ã¯ã©ã¤ã¢ã³ã㯠Digest èªè¨¼ããµãã¼ããã¦ããããã§ãã
AuthName
ãã£ã¬ã¯ãã£ãã§ã¯ãèªè¨¼ã«ä½¿ã Realm (訳注: é å) ãè¨å®ãã¾ããRealm ã¯å¤§ããåãã¦äºã¤ã®æ©è½ãæä¾ãã¾ãã ä¸ã¤ç®ã¯ãã¯ã©ã¤ã¢ã³ãããã¹ã¯ã¼ããã¤ã¢ãã°ããã¯ã¹ã® ä¸é¨ã¨ãã¦ã¦ã¼ã¶ã«ãã®æ
å ±ãããæç¤ºãããã¨ãããã®ã§ãã äºã¤ç®ã«ã¯ãã¯ã©ã¤ã¢ã³ããä¸ããããèªè¨¼é åã«å¯¾ãã¦ã©ã®ãã¹ã¯ã¼ãã éä¿¡ããã°è¯ãã®ããæ±ºå®ããããã«ä½¿ããããã¨ããæ©è½ã§ãã
ä¾ãã°ã"Restricted Files"
é åä¸ã§ ä¸åº¦èªè¨¼ãããã°ãåä¸ãµã¼ãä¸ã§ "Restricted Files"
Realm ã¨ãã¦ãã¼ã¯ãããã©ããªé åã§ããã¯ã©ã¤ã¢ã³ã㯠èªåçã«åããã¹ã¯ã¼ãã使ããã¨è©¦ã¿ã¾ãã ãã®ãããã§ãè¤æ°ã®å¶éé åã«åã realm ãå
±æããã¦ã ã¦ã¼ã¶ããã¹ã¯ã¼ããä½åº¦ãè¦æ±ãããäºæ
ã é²ããã¨ãã§ãã¾ãããã¡ãããã»ãã¥ãªãã£ä¸ã®çç±ããã ãµã¼ãã®ãã¹ãåãå¤ããã°ãã¤ã§ãå¿
ãã ã¯ã©ã¤ã¢ã³ãã¯åã³ãã¹ã¯ã¼ããå°ããå¿
è¦ãããã¾ãã
AuthBasicProvider
ã¯ããã©ã«ãå¤ã file
ãªã®ã§ãä»åã®å ´åã¯ç¡ãã¦ãæ§ãã¾ããã mod_authn_dbm
ã mod_authn_dbd
ã¨ãã£ãä»ã®ã¢ã¸ã¥ã¼ã«ã使ãå ´åã«ã¯å¿
è¦ã«ãªãã¾ãã
AuthUserFile
ãã£ã¬ã¯ãã£ã㯠htpasswd
ã§ä½ã£ã ãã¹ã¯ã¼ããã¡ã¤ã«ã¸ã®ãã¹ãè¨å®ãã¾ãã ã¦ã¼ã¶æ°ãå¤ãå ´åã¯ããªã¯ã¨ã¹ãæ¯ã®ã¦ã¼ã¶ã®èªè¨¼ã®ããã® ãã¬ã¼ã³ããã¹ãã®æ¢ç´¢ãé常ã«é
ããªããã¨ãããã¾ãã Apache ã§ã¯ã¦ã¼ã¶æ
å ±ãé«éãªãã¼ã¿ãã¼ã¹ãã¡ã¤ã«ã« ä¿ç®¡ãããã¨ãã§ãã¾ãã mod_authn_dbm
ã¢ã¸ã¥ã¼ã«ã AuthDBMUserFile
ãã£ã¬ã¯ãã£ããæä¾ãã¾ãããããã®ãã¡ã¤ã«ã¯ dbmmanage
ããã°ã©ã ã§ä½æãããæä½ãããã§ãã¾ãã Apache ã¢ã¸ã¥ã¼ã«ãã¼ã¿ãã¼ã¹ä¸ã«ãããµã¼ããã¼ãã£ã¼è£½ã® ã¢ã¸ã¥ã¼ã«ã§ããã®ä»å¤ãã®ã¿ã¤ãã®èªè¨¼ãªãã·ã§ã³ã å©ç¨å¯è½ã§ãã
æå¾ã«ãRequire
ãã£ã¬ã¯ãã£ããããµã¼ãã®ãã®é åã«ã¢ã¯ã»ã¹ã§ããã¦ã¼ã¶ã æå®ãããã¨ã«ãã£ã¦ãããã»ã¹ã®æ¿èªé¨åãæä¾ãã¾ãã æ¬¡ã®ã»ã¯ã·ã§ã³ã§ã¯ãRequire
ãã£ã¬ã¯ãã£ãã®æ§ã
ãªç¨æ³ã«ã¤ãã¦è¿°ã¹ã¾ãã
ä¸è¨ã®ãã£ã¬ã¯ãã£ãã¯ããã ä¸äºº (å
·ä½çã«ã¯ã¦ã¼ã¶å rbowen
ã®èª°ã) ããã£ã¬ã¯ããªã« å
¥ããããã«ãã¾ããå¤ãã®å ´åã¯ãè¤æ°ã®äººã å
¥ããããã«ãããã§ããããããã§ AuthGroupFile
ã®ç»å ´ã§ãã
ããè¤æ°ã®äººãå ¥ããããã«ãããã®ã§ããã°ã ã°ã«ã¼ãã«å±ããã¦ã¼ã¶ã®ä¸è¦§ã®å ¥ã£ã¦ãããã°ã«ã¼ãåã®ã¤ãã ã°ã«ã¼ããã¡ã¤ã«ãä½ãå¿ è¦ãããã¾ãããã®ãã¡ã¤ã«ã® æ¸å¼ã¯ãããã¦åç´ã§ãã好ã¿ã®ã¨ãã£ã¿ã§çæã§ãã¾ãã ãã¡ã¤ã«ã®ä¸èº«ã¯æ¬¡ã®ãããªãã®ã§ãã
GroupName: rbowen dpitts sungo rshersey
ä¸è¡ã«ã¹ãã¼ã¹åºåãã§ãã°ã«ã¼ãã«æå±ããã¡ã³ãã¼ã® ä¸è¦§ããªãã¹ãã ãã§ãã
æ¢ã«åå¨ãããã¹ã¯ã¼ããã¡ã¤ã«ã«ã¦ã¼ã¶ãå ããå ´åã¯ã 次ã®ããã«ã¿ã¤ããã¦ãã ããã
htpasswd /usr/local/apache/passwd/passwords dpitts
以åã¨åãå¿çãè¿ããã¾ãããæ°ãããã¡ã¤ã«ã ä½ãã®ã§ã¯ãªããæ¢ã«ãããã¡ã¤ã«ã«è¿½å ããã¦ãã¾ãã (æ°ãããã¹ã¯ã¼ããã¡ã¤ã«ãä½ãã«ã¯ -c
ã使ãã¾ãã)
ããã§æ¬¡ã®ããã«ã㦠.htaccess
ãã¡ã¤ã«ã ä¿®æ£ããå¿
è¦ãããã¾ãã
AuthType Basic
AuthName "By Invitation Only"
# Optional line:
AuthBasicProvider file
AuthUserFile /usr/local/apache/passwd/passwords
AuthGroupFile /usr/local/apache/passwd/groups
Require group GroupName
ããã§ãã°ã«ã¼ã GroupName
ã«ãªã¹ãããã¦ãã¦ã password
ãã¡ã¤ã«ã«ã¨ã³ããªããã人ã¯ã æ£ãããã¹ã¯ã¼ããã¿ã¤ãããã°å
¥ããã¨ãã§ããã§ãããã
ãã£ã¨ç¹å®ããã«è¤æ°ã®ã¦ã¼ã¶ãå ¥ããããã«ããã ããä¸ã¤ã®æ¹æ³ãããã¾ããã°ã«ã¼ããã¡ã¤ã«ãä½ãã®ã§ã¯ãªãã æ¬¡ã®ãã£ã¬ã¯ãã£ãã使ãã°ã§ãã¾ãã
Require valid-user
require user rbowen
è¡ã§ãªããä¸è¨ã使ãã¨ã ãã¹ã¯ã¼ããã¡ã¤ã«ã«ãªã¹ãããã¦ãã人ã§ããã°èª°ã§ã 許å¯ããã¾ãã åã«ãã¹ã¯ã¼ããã¡ã¤ã«ãã°ã«ã¼ãæ¯ã«åãã¦ãããã¨ã§ã ã°ã«ã¼ãã®ãããªæ¯ãèããããããã¨ãã§ãã¾ãã ãã®ã¢ããã¼ãã®å©ç¹ã¯ãApache ã¯äºã¤ã§ã¯ãªãã ãã ä¸ã¤ã®ãã¡ã¤ã«ã ããæ¤æ»ããã°ããã¨ããç¹ã§ãã æ¬ ç¹ã¯ãããããã®ãã¹ã¯ã¼ããã¡ã¤ã«ã管çãã¦ããã®ä¸ãã AuthUserFile
ãã£ã¬ã¯ãã£ãã«æ£ãããã¡ã¤ã«ãåç
§ãããªããã°ãªããªãç¹ã§ãã
Basic èªè¨¼ãæå®ããã¦ããå ´åã¯ã ãµã¼ãã«ããã¥ã¡ã³ãããªã¯ã¨ã¹ããã度㫠ã¦ã¼ã¶åã¨ãã¹ã¯ã¼ããæ¤æ»ããªããã°ãªãã¾ããã ããã¯åããã¼ã¸ããã¼ã¸ã«ããå ¨ã¦ã®ç»åã ãªãã¼ãããå ´åã§ãã£ã¦ã該å½ãã¾ã (ããç»åãä¿è·ããããã£ã¬ã¯ããªããæ¥ãã®ã§ããã°) ã äºæ³ãããéããããã¯åä½ãå¤å°é ããã¾ãã é ããªãç¨åº¦ã¯ãã¹ã¯ã¼ããã¡ã¤ã«ã®å¤§ããã¨æ¯ä¾ãã¾ããã ããã¯ããã¡ã¤ã«ãéãã¦ããªãã®ååãçºè¦ããã¾ã§ ã¦ã¼ã¶åã®ãªã¹ããèªã¾ãªããã°ãªããªãããã§ãã ããã¦ããã¼ã¸ããã¼ãããã度ã«ãããè¡ããªããã° ãªãã¾ããã
çµè«ã¨ãã¦ã¯ãä¸ã¤ã®ãã¹ã¯ã¼ããã¡ã¤ã«ã«ç½®ããã¨ã®ã§ãã ã¦ã¼ã¶æ°ã«ã¯å®è³ªçãªéçãããã¾ãã ãã®éçã¯ãµã¼ããã·ã³ã®æ§è½ã«ä¾åãã¦å¤ããã¾ããã æ°ç¾ã®ã¨ã³ããªãè¶ãããããããé度ä½ä¸ãè¦ãããã¨äºæããã¦ãã¾ãã ãã®æã¯ä»ã®èªè¨¼æ¹æ³ãèæ ®ã«å ¥ããæ¹ãè¯ãã§ãããã
ãã¹ã¯ã¼ãã®ä¿åå½¢å¼ãå¤ãããã¬ã¼ã³ããã¹ãã§ãã¹ã¯ã¼ããä¿åããæ¹æ³ã«ã¯ä¸è¨ã®åé¡ãããã ãã¼ã¿ãã¼ã¹ã®ãããªå¥ã®å ´æã«ãã¹ã¯ã¼ããä¿åãããã¨æã ããããã¾ããã
mod_authn_dbm
㨠mod_authn_dbd
ã使ãã¨ããããã§ããããã«ãªãã¾ãã AuthBasicSource
ã§ file ã®ä»£ããã«ãdbm
ããã㯠dbd
ãæ ¼ç´å½¢å¼ã¨ãã¦é¸ã¹ã¾ãã
ããã¹ããã¡ã¤ã«ã®ä»£ããã« dbm ãã¡ã¤ã«ã鏿ããå ´åã¯ããã¨ãã°æ¬¡ã®ããã«ãã¾ãã
<Directory /www/docs/private>
AuthName "Private"
AuthType Basic
AuthBasicProvider dbm
AuthDBMUserFile /www/passwords/passwd.dbm
Require valid-user
</Directory>
ãã®ä»ã®ãªãã·ã§ã³ãåå¨ãã¾ãã詳細ã«é¢ãã¦ã¯ mod_authn_dbm
ã®ããã¥ã¡ã³ããã覧ãã ããã
èªè¨¼æ¿èªã¢ã¼ããã¯ãã£ã«åºã¥ãã¦ããæ°ãããããã¤ãã使ãã¨ã èªè¨¼æ¿èªã®æ¹æ³ãã²ã¨ã¤ã«ç¸ãå¿ è¦ããªããªãã¾ãã ããã¤ãã®ãããã¤ããçµã¿åããã¦ãèªåã®æã¿ã®æåã«ã§ãã¾ãã æ¬¡ã®ä¾ã§ã¯ file èªè¨¼ãããã¤ã㨠ldap èªè¨¼ãããã¤ãã çµã¿åããã¦ãã¾ãã
<Directory /www/docs/private>
AuthName "Private"
AuthType Basic
AuthBasicProvider file ldap
AuthUserFile /usr/local/apache/passwd/passwords
AuthLDAPURL ldap://ldaphost/o=yourorg
Require valid-user
ãã®ä¾ã§ã¯ãã¾ã file ãããã¤ããã¦ã¼ã¶èªè¨¼ã試ã¿ã¾ãã èªè¨¼ã§ããªãã£ãå ´åã«ã¯ãldap ãããã¤ããå¼ã³åºããã¾ãã çµç¹ã§è¤æ°ã®èªè¨¼æ ¼ç´æ¹æ³ã使ã£ã¦ããéãªã©ã«ã ãã®æ¹æ³ã使ã£ã¦èªè¨¼ã®ã¹ã³ã¼ããæ¡å¤§ã§ãã¾ãã ããã²ã¨ã¤ã®ã·ããªãªã¯ãã²ã¨ã¤ã®èªè¨¼ã¿ã¤ãã¨ç°ãªãæ¿èªã çµã¿åãããæ¹æ³ã§ãããããã¨ãã°ããã¹ã¯ã¼ããã¡ã¤ã«ã§èªè¨¼ãã¦ã ldap ãã£ã¬ã¯ããªã§æ¿èªãè¡ãã¨ãã£ãå ´åã§ãã
èªè¨¼ãããã¤ããè¤æ°å®è£ ã§ããããã«ãæ¿èªæ¹æ³ãè¤æ°ä½¿ç¨ã§ãã¾ãã ãã®ä¾ã§ã¯ file ã°ã«ã¼ãæ¿èªã¨ ldap ã°ã«ã¼ãæ¿èªã使ã£ã¦ãã¾ãã
<Directory /www/docs/private>
AuthName "Private"
AuthType Basic
AuthBasicProvider file
AuthUserFile /usr/local/apache/passwd/passwords
AuthLDAPURL ldap://ldaphost/o=yourorg AuthGroupFile /usr/local/apache/passwd/groups
Require group GroupName
Require ldap-group cn=mygroup,o=yourorg
æ¿èªãããç´°ããå¶å¾¡ãããå ´åã¯ã <SatisfyAll>
㨠<SatisfyOne>
ãã£ã¬ã¯ãã£ãã使ã£ã¦ AND/OR ãã¸ãã¯ã§æå®ããè¨å®ãã¡ã¤ã«ã§ æ¿èªã®å¦çé çªã®å¶å¾¡ãã§ããããã«ãªã£ã¦ãã¾ãã ãããã®ãã£ã¬ã¯ãã£ããã©ã®ããã«ä½¿ããããç¶²ç¾
ããä¾ãã覧ãã ããã
æ¿èªã®æ¹æ³ã¯ãã²ã¨ã¤ã®ãã¼ã¿ã½ã¼ã¹ãè¦ã¦ä¸åã ããã§ãã¯ããã®ã¨æ¯ã¹ã¦ã ãã£ã¨å¤å½©ãªé©ç¨æ¹æ³ãã§ãã¾ãã æ¿èªå¦çã®é©ç¨é åºãå¶å¾¡ã鏿ãã§ããããã«ãªãã¾ããã
AND/OR ãã¸ãã¯ã®é©ç¨ã¨é åºä»ãæ¿èªãã©ã®ãããªé åºã§é©ç¨ããã¦ããããã¾ãããããã©ã®ããã«å¶å¾¡ãããã¯ã ããã¾ã§æ··ä¹±ãæãã¦ãã¾ããã Apache 2.2 ã§ã¯ãããã¤ããã¼ã¹ã®èªè¨¼ã¡ã«ããºã ãå°å
¥ããã æ¿èªå¦çããèªè¨¼å¦çã¨ãµãã¼ãæ©è½ã¨ãåãåãããã¾ããã ããã«ããã²ã¨ã¤ã®å¹æã¨ãã¦ã èªè¨¼ã¢ã¸ã¥ã¼ã«ã®ãã¼ãé ãã¢ã¸ã¥ã¼ã«èªä½ã®é åºã«ä¾åãããã¨ãªãã æå®ããé çªã§èªè¨¼ãããã¤ããå¼ã³åºããããã è¨å®ã§ããããã«ãªãã¾ããã ãã®ãããã¤ãã¡ã«ããºã ã¯æ¿èªå¦çã§ãå°å
¥ããã¦ãã¾ãã ã¤ã¾ããRequire
ãã£ã¬ã¯ãã£ãã¯åã«ã©ã®æ¿èªææ³ã使ãããããæå®ããã ãã§ã¯ãªãã ãããã®å¼ã³åºãé åºãæå®ã§ããããã«ãªãã¾ããã è¤æ°ã®æ¿èªææ³ãããã¨ãããã®å¼ã³åºãé ã¯ãè¨å®ãã¡ã¤ã«ã® Require
ãã£ã¬ã¯ãã£ãä¸ã§ ç¾ããé åºã¨åãã«ãªãã¾ãã
追å ã§å°å
¥ããã <SatisfyAll>
, <SatisfyOne>
ãã£ã¬ã¯ãã£ãã使ã£ã¦ãæ¿èªææ³ããã¤å¼ã³åºãããã¢ã¯ã»ã¹ã許å¯ãããéã« ã©ã®æç¶ããé©ç¨ããããæå®ãããã¨ãã§ãã¾ãã ãã¨ãã°ãæ¬¡ã®æ¿èªãããã¯ã®ãã¸ãã¯ãè¦ã¦ã¿ã¾ããã:
# if ((user == "John") ||
# ((Group == "admin")
# && (ldap-group <ldap-object> contains auth'ed_user)
# && ((ldap-attribute dept == "sales")
# || (file-group contains auth'ed_user))))
# then
# auth_granted
# else
# auth_denied
#
<Directory /www/mydocs>
Authname ...
AuthBasicProvider ...
...
Require user John
<SatisfyAll>
Require Group admins
Require ldap-group cn=mygroup,o=foo
<SatisfyOne>
Require ldap-attribute dept="sales"
Require file-group
</SatisfyOne>
</SatisfyAll>
</Directory>
ããã©ã«ãã§ã¯ Require
ãã£ã¬ã¯ãã£ã㯠OR æä½ã¨ãã¦æ±ããã¾ããã¤ã¾ããããæå®ããæ¿èªææ³ã® ã²ã¨ã¤ã§ãåæ ¼ããã°ãæ¿èªããã¾ãã Require
ãã£ã¬ã¯ãã£ãã®ã»ããã ã²ã¨ã¤ã® <SatisfyAll>
ãããã¯ã§å²ãã¨AND æä½ã¨ãªããå
¨ã¦ã®æ¿èªææ³ã§åæ ¼ããªããã°è¨±å¯ããã¾ããã
ã¦ã¼ã¶åã¨ãã¹ã¯ã¼ãã«ããèªè¨¼ã¯å ¨ä½ã®ä¸é¨åã§ããããã¾ããã 誰ãã¢ã¯ã»ã¹ãã¦ãããã¨ãã£ãæ å ±ä»¥å¤ã®æ¡ä»¶ã使ãããã ã¨ããæããã¨ã§ãããã ãã¨ãã°ãã©ãããã¢ã¯ã»ã¹ãã¦ãã¦ããããã¨ãã£ãå ·åã§ãã
æ¿èªãããã¤ã all
, env
, host
, ip
ã使ãã¨ããªã¯ã¨ã¹ããéä¿¡ãã¦ãã¦ãããã·ã³ã®ãã¹ãåã IP ã¢ãã¬ã¹ ã¨ãã£ãããã¹ããã¼ã¹ã§ã®ã¢ã¯ã»ã¹å¶å¾¡ãã§ãã¾ãã
ããããããã¤ãã®æ±ã㯠Require
ã Reject
ã§ æå®ããã¾ãããããã®ãã£ã¬ã¯ãã£ãã¯æ¿èªãããã¤ããç»é²ãã ãªã¯ã¨ã¹ãå¦çã®æ¿èªæ®µéã§å¼ã³åºããã¾ãããã¨ãã°:
Require ip address
ããã§ãaddress 㯠IP ã¢ãã¬ã¹ (ããã㯠IP ã¢ãã¬ã¹ã® ä¸é¨) ã :
Require host domain_name
ããã§ domain_name 㯠FQDN (ãããã¯ãã¡ã¤ã³åã®ä¸é¨) ã§ãå¿ è¦ã§ããã°è¤æ°ã®ã¢ãã¬ã¹ããã¡ã¤ã³åãæ¸ããã¨ãã§ãã¾ãã
ãã¨ãã°ãã¹ãã ã¡ãã»ã¼ã¸ãéä¿¡ãã¦ãã誰ããæå¦ãããå ´åã æ¬¡ã®ããã«ãªãã¾ã :
Reject ip 10.252.46.165
ãã®ãã£ã¬ã¯ãã£ããæå¹ãªç¯å²ã®ã³ã³ãã³ãã«å¯¾ãã¦ã¯ã ãã®ã¢ãã¬ã¹ããã¢ã¯ã»ã¹ãã¦ãã¦ãè¦ããã¨ãã§ãã¾ããã ãããã·ã³åãããã£ã¦ã㦠IP ã¢ãã¬ã¹ããããã¡ãã§ æå®ãããã®ã§ããã°ããã®ãã·ã³åã使ãã¾ãã
Reject host host.example.com
ã¾ããç¹å®ã®ãã¡ã¤ã³ããã®ã¢ã¯ã»ã¹å ¨ã¦ããããã¯ãããå ´åã¯ã IP ã¢ãã¬ã¹ã®ä¸é¨ãããã¡ã¤ã³åãæå®ã§ãã¾ã :
<SatisfyAll>
Reject ip 192.168.205
Reject host phishers.example.com moreidiots.example
Reject host ke
</SatisfyAll>
Reject
ãã£ã¬ã¯ãã£ãã <SatisfyAll>
ãããã¯ã®ä¸ã§ä½¿ãã¨ã 許å¯ãããã°ã«ã¼ãã«ã®ã¿ã¢ã¯ã»ã¹ãã§ããããã«ç¢ºèªã§ãã¾ãã
ä¸è¨ã®ä¾ã§ã¯ <SatisfyAll>
ã使ã£ã¦ãã¢ã¯ã»ã¹ã«åæ ¼ããåæ®µéã§ãå
¨ã¦ã® Reject
ãã£ã¬ã¯ãã£ãã æºãããã¦ãããã¨ã確èªãã¦ãã¾ãã
èªè¨¼ãããã¤ããã¼ã¹ã®æ©æ§ãããããã以å使ç¨ããã¦ãããã£ã¬ã¯ãã£ã Order
, Allow
, Deny
, Satisfy
ã¯å¿
è¦ãªããªãã¾ããã ã¨ã¯ãããã®ã®ãå¤ãè¨å®ãã¡ã¤ã«ã§ã®å¾æ¹äºææ§ãæä¾ããããã ãããã®ãã£ã¬ã¯ãã£ã㯠mod_access_compat
ã¢ã¸ã¥ã¼ã«ã«ç§»ããã¾ããã
ãããã®ãã£ã¬ã¯ãã£ãã®æ±ãã¦ããåé¡ã®ã²ã¨ã¤ã«ãæ¿èªã®è¨å®è¡ã¨ã¢ã¯ã»ã¹å¶å¾¡ã®è¨å®è¡ã® é¢ä¿ãã¨ã¦ãããã¾ãã ã£ããã¨ãæãããã¾ãã Satisfy
ãã£ã¬ã¯ãã£ã㯠ãªã¯ã¨ã¹ãå¦çä¸ã§ããèªèº«ãå¼ã³åºããã¨ã«ãã£ã¦ããããã® 2 ã¤ã®å¦ç段éãçµã³ã¤ãããã¨ãã¾ãã ç¾å¨ã¯ããããã®ãã£ã¬ã¯ãã£ã㯠mod_access_compat
ã«ç§»åãã æ°ããèªè¨¼ãã£ã¬ã¯ãã£ãã¨å¤ãã¢ã¯ã»ã¹å¶å¾¡ãã£ã¬ã¯ãã£ããæ··ãã¦ä½¿ããã¨ã¯ é£ãããªã£ã¦ãã¾ãããã®åé¡ã®ãããmod_authz_default
ã¢ã¸ã¥ã¼ã«ã ãã¼ããããã¨ãã¨ã¦ãéè¦ã§ãå¿
é ã«ãªã£ã¦ãã¾ãã mod_authz_default
ãã¢ã¸ã¥ã¼ã«ã®ä¸»ãªç®çã¯ãã©ã®æ¿èªãããã¤ãã§ å¦çãããªãã£ãæ¿èªãªã¯ã¨ã¹ããåãããã¨ã«ããã¾ãã ããããå¤ãã¢ã¯ã»ã¹å¶å¾¡ãã£ã¬ã¯ãã£ããç¨ããããå ´åã«ã¯ã ã¢ã¯ã»ã¹å¶å¾¡ã¨æ¿èªãçµã³ã¤ãã¦ããã¹ã¦ã®å¦ç段éã®åºåçµæãè¦ã¦ã¢ã¯ã»ã¹ã«åæ ¼ããããæ±ºãã¦ãã¾ãã ã§ããããå¤ããã£ã¬ã¯ãã£ãããã¾ãåä½ããªãå ´åã¯ã mod_authz_default
ããã¼ãããã¦ããªããããããããªãã ã¨çã£ã¦ã¿ã¦ãã ããã
ãããå
¨ã¦ãã©ã®ããã«åä½ãããã«ã¤ã㦠ãã£ã¨å¤ãã®æ
å ±ãæ¸ããã¦ãã mod_auth_basic
㨠mod_authz_host
ã®ææ¸ãèªãã¨ããã§ãããã <AuthnProviderAlias>
ãã£ã¬ã¯ãã£ãã使ãã¨ãç¹å®ã®èªè¨¼è¨å®ãç°¡åã«æ¸ããããã«ãªãã¾ãã
ã¢ã¯ã»ã¹å¶å¾¡ã®æ¹æ³ãã é¢é£ãããããã¯ãããããè¨è¼ããã¦ãã¾ãã®ã§ãã覧ãã ããã
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4