ºîÀ®Æü¡§2004ǯ12·î11Æü
ºÇ½ª¹¹¿·Æü¡§2004ǯ12·î20Æü

LDAPǧ¾Ú

¡ÚSquid Home¤Ø¡Û

Ä̾ï¤Ç¤Ï£Ð£ò£ï£ø£ù¤Ë¥æ¡¼¥¶Ç§¾Ú¤ò¹Ô¤¦¤è¤¦¤Ê±¿ÍѤϾ¯¤Ê¤¤¤È»×¤¤¤Þ¤¹¤¬¡¢¥»¥­¥å¥ê¥Æ¥£¤ò¿´ÇÛ¤¹¤ë´ë¶È¤ä³Ø¹»¤Ê¤É¤Ç¤Ï¡¢ÆâÉô¤ÎProxy¤òÍøÍѤ¹¤ëºÝ¤Ë¡¢¥æ¡¼¥¶Â¦¤ËID¤Ë¤è¤ëǧ¾Ú¤òµá¤á¤ë±¿ÍѤò¹Ô¤¦¥±¡¼¥¹¤â¤¢¤ê¤Þ¤¹¡£¡¡Â絬ÌϤÊÁÈ¿¥¤Ç¤Ï¡¢¥æ¡¼¥¶´ÉÍý¤ä¥æ¡¼¥¶¾ðÊó¤Î°ì¸µ²½¤Î°Ù¤ËLDAP¥µ¡¼¥Ð¤ò´û¤Ë¹½ÃÛ¤·¤Æ¤¤¤ë¾ì¹ç¤âÍ­¤ë¤³¤È¤Ç¤·¤ç¤¦¡£¡¡

Squid ¤Ë¤Ï¡¢LDAP¤ò»È¤Ã¤¿Ç§¾Ú¥×¥í¥°¥é¥à¤¬ÍѰդµ¤ì¤Æ¤ª¤ê¡¢¤³¤ì¤ò»È¤Ã¤ÆSquid¤òÍøÍѤǤ­¤ë¥æ¡¼¥¶¤Îǧ¾Ú¤ò¹Ô¤¦¤³¤È¤¬²Äǽ¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¥æ¡¼¥¶¾ðÊó¼«ÂΤÏSquid¤ÈÊ̤Υµ¡¼¥Ð¤Ë»ý¤¿¤»¤¿±¿ÍÑ·ÁÂ֤ˤʤ뤿¤á¡¢¥»¥­¥å¥ê¥Æ¥£Åª¤Ë¤â°ÂÁ´À­¤¬¹â¤á¤ë»ö¤¬²Äǽ¤Ë¤Ê¤ê¤Þ¤¹¡£

Squid¤«¤éLDAP¤ò»È¤¦ÊýË¡¤Ë¤Ï¡¢¥Ð¡¼¥¸¥ç¥ó¤Ë¤è¤Ã¤Æ»È¤¦¥â¥¸¥å¡¼¥ë¤¬°ã¤¦¤è¤¦¤Ç¤¹¤¬¡¢Squid2.5°Ê¹ß¤Ë¤Ï¥Ù¡¼¥·¥Ã¥¯Ç§¾Ú¤ÈƱ¤¸¾ì½ê¤ËLDAPǧ¾Ú¤Ë´Ø¤¹¤ë¥â¥¸¥å¡¼¥ë¤È¤·¤Æ¡¢"ldap_auth"¤È"squid_ldap_group"¤¬Â¸ºß¤¹¤ëȦ¤Ç¤¹¡£

¹¹¤ËSquid¤òPAM¤Î»È¤¨¤ëOS¤Çµ¯Æ°¤¹¤ë¾ì¹ç¡¢PAM¤ò·Ðͳ¤·¤ÆLDAP¤Ø¤Î¥¢¥¯¥»¥¹ÊýË¡¤â¹Í¤¨¤é¤ì¤Þ¤¹¤¬¡¢¤³¤ÎÊýË¡¤ÏLDAP¤È¤¤¤¦¤è¤êPAM¤ÎÀâÌÀ¤Ë¤Ê¤ë¤¿¤á¡¢ËÜ»ñÎÁ¤Ë¤Ïµ­½Ò¤·¤Þ¤»¤ó¤Î¤Ç¤¢¤·¤«¤é¤º¡£¡ÊPAMǧ¾Ú¤Çµ­½Ò¤¹¤ëͽÄê¤Ç¤¹¡Ë

£±¡¥ÁÛÄꤹ¤ë´Ä¶­

¼¡¤Î¿Þ¤Î¤è¤¦¤Ë¡¢LDAP¥µ¡¼¥Ð¤¬Â¸ºß¤¹¤ë´Ä¶­¤Ë Proxy ¤È¤·¤Æ Squid ¤ò¹½ÃÛ¤·¡¢¥æ¡¼¥¶Ç§¾Ú¤È¤·¤Æ LDAP ¤ò»È¤Ã¤¿Ç§¾Ú¤Ë¤è¤Ã¤Æ Proxy ¤ò¥¯¥é¥¤¥¢¥ó¥È¤«¤é»È¤¨¤ë¤è¤¦¤Ë¤·¤Þ¤¹¡£

¥æ¡¼¥¶¤¬¥¯¥é¥¤¥¢¥ó¥È¤«¤éHTTP¤ò¥ê¥¯¥¨¥¹¥È¡Ê­¡¡Ë¤·¡¢¤½¤ì¤òSquid¤¬¼õ¤±¼è¤ë¤ÈºÇ½é¤Ë¥æ¡¼¥¶Ç§¾Ú¤¬Æ¯¤­¤Þ¤¹¡£¡¡¥¯¥é¥¤¥¢¥ó¥È¤Ëɽ¼¨¤µ¤ì¤¿Ç§¾Ú¥À¥¤¥¢¥í¥°¥Ü¥Ã¥¯¥¹¤Ç¥æ¡¼¥¶ID¤È¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϡʭ¢¡Ë¤¹¤ë¤È¡¢Squid¤Ï¤³¤ì¤òLDAP¥µ¡¼¥Ð¤ËÌ䤤¹ç¤ï¤»¡Ê­£¡Ë¤Æ¡¢¥æ¡¼¥¶¤¬¼ÂºÝ¤ËLDAP¥µ¡¼¥Ð¾å¤Ë¸ºß¤¹¤ë¤Ê¤é¡¢¥ê¥¯¥¨¥¹¥È¤µ¤ì¤¿HTTP¤ò¼ÂºÝ¤Î¥ê¥¯¥¨¥¹¥ÈÀè¤ÎWeb¥µ¡¼¥Ð¤Ø¤ÈÁ÷¤ê¤Þ¤¹¡£¡Ê­¤¡Ë

£²¡¥ldap_auth¤ò»È¤Ã¤¿LDAPǧ¾Ú

ldap_auth¤ò»È¤Ã¤¿Ç§¾Ú¤Ï¡¢Ç§¾Ú¥µ¡¼¥Ð¤È¤·¤ÆLDAP¤ò»È¤Ã¤Æ¤¤¤ë»ö°Ê³°¤ÏÀßÄê²Õ½ê¤ò´Þ¤á¤Æ¡¢¥Ù¡¼¥·¥Ã¥¯Ç§¾Ú¤ÈƱ¤¸ÊýË¡¤Ë¤Ê¤ê¤Þ¤¹¡£
¤Ä¤Þ¤ê¡¢¥æ¡¼¥¶ID¤È¥Ñ¥¹¥ï¡¼¥É¤ò¥¯¥ê¥¢¥Æ¥­¥¹¥È¤ÇSquid¤ÇÅϤ¹¤È¡¢¤³¤ì¤òSquid¤ÏLDAP¥µ¡¼¥Ð¤ËÌ䤤¹ç¤ï¤»¤ëÌõ¤Ç¤¹¡£¡ÊLDAP¥Ñ¥±¥Ã¥È¤Ï°Å¹æ²½¤µ¤ì¤Æ¤Ê¤¤»ö¤ËÃí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡Ë

¡ÊÀßÄêÆâÍÆ¡Ë

  1. squid.conf¤Çauth_param¤Ç¥Ù¡¼¥·¥Ã¥¯Ç§¾Ú¥×¥í¥°¥é¥à¤È¤·¤Æ¡¢ldap_auth¤ò»È¤¦¤è¤¦¤Ë¹½À®¤·¤Æ²¼¤µ¤¤¡£

    Îã:

    auth_param basic program /usr/lib/squid/ldap_auth -b "dc=robata,dc=org" -f "(&(uid=%s)(objectClass=posixAccount))" ldap-server.robata.org
    auth_param basic children 5
    auth_param basic realm Squid proxy-caching web server
    auth_param basic credentialsttl 2 hours

¾åµ­¤ÎÀßÄê¤ò¹Ô¤¦»ö¤Ç¡¢LDAP¥µ¡¼¥Ð¡Êldap-server.robata.org¡Ë¤«¤é¥Ù¡¼¥¹¼±ÊÌ̾¤¬"dc=robata,dc=org"¤Ë°¤¹¤ë¥æ¡¼¥¶¤ò¸¡º÷¤¹¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£¡¡¤³¤Î»þ¡¢-f¥ª¥×¥·¥ç¥ó¤ÇLDAP¥µ¡¼¥Ð¤«¤é¸¡º÷¤¹¤ë¥ª¥Ö¥¸¥§¥¯¥È¥¯¥é¥¹¤È¤·¤Æ°ìÈÌŪ¤Ê"posixAccount"¤Î¾ðÊó¤Ë¤¢¤ë¡Öuid¡×¤ò»È¤¦¤è¤¦¤Ë¤·¤Æ¤¤¤Þ¤¹¡£¡¡¡Ê¤³¤Î¤¢¤¿¤ê¤Î¾Ü¤·¤¤°ÕÌ£¤Ë¤Ä¤¤¤Æ¤ÏLDAP¤Î²òÀâ½ñ¤ò¤´Í÷¤¯¤À¤µ¡Ë


¡ÚSquid Home¤Ø¡Û

Copyright© 1998-2003 ROBATA.ORG