ÔÚ Linux ÉϹ¹½¨Ò»¸ö RADIUS ·þÎñÆ÷
×÷ΪһÃûÍøÂç¹ÜÀíÔ±£¬ÄúÐèҪΪÄúËùÐè¹ÜÀíµÄÿ¸öÍøÂçÉ豸´æ·ÅÓÃÓÚ¹ÜÀíµÄÓû§ÐÅÏ¢¡£µ«ÊÇÍøÂçÉ豸ͨ³£Ö»Ö§³ÖÓÐÏÞµÄÓû§¹ÜÀí¹¦ÄÜ¡£Ñ§Ï°ÈçºÎʹÓà Linux™ ÉϵÄÒ»¸öÍⲿ RADIUS ·þÎñÆ÷À´ÑéÖ¤Óû§£¬¾ßÌåÀ´ËµÊÇͨ¹ýÒ»¸ö LDAP ·þÎñÆ÷½øÐÐÑéÖ¤£¬¿ÉÒÔ¼¯ÖзÅÖô洢ÔÚ LDAP ·þÎñÆ÷Éϲ¢ÇÒÓÉ RADIUS ·þÎñÆ÷½øÐÐÑéÖ¤µÄÓû§ÐÅÏ¢£¬´Ó¶ø¼È¿ÉÒÔ¼õÉÙÓû§¹ÜÀíÉϵĹÜÀí¿ªÏú£¬ÓÖ¿ÉÒÔʹԶ³ÌµÇ¼¹ý³Ì¸ü¼Ó°²È«¡£
Êý¾Ý°²È«×÷ΪÏÖ´úϵͳÖÐÍøÂ簲ȫµÄÒ»²¿·Ö£¬Óëϵͳ°²È«Ò»ÑùµÄÖØÒª£¬ËùÒÔ±£»¤Êý¾Ý —— È·±£Ìṩ»úÃÜÐÔ¡¢ÍêÕûÐԺͿÉÓÃÐÔ —— ¶Ô¹ÜÀíÔ±À´ËµÖÁ¹ØÖØÒª¡£
ÔÚ±¾ÎÄÖУ¬ÎÒ½«Ì¸µ½Êý¾Ý°²È«ÐԵĻúÃÜÐÔ·½Ã棺ȷ±£Êܱ£»¤µÄÊý¾ÝÖ»Äܱ»ÊÚȨÓû§»òϵͳ·ÃÎÊ¡£Äú½«Ñ§Ï°ÈçºÎÔÚ Linux ϵͳÉϽ¨Á¢ºÍÅäÖÃÒ»¸ö Remote Authentication Dial-In User Service ·þÎñÆ÷£¨RADIUS£©£¬ÒÔÖ´ÐжÔÓû§µÄÑéÖ¤¡¢ÊÚȨºÍ¼ÇÕÊ£¨AAA£©¡£
¸÷×é³ÉÔªËØ½éÉÜ
Ê×ÏÈÈÃÎÒÃÇ̸һ̸ RADIUS ÐÒé¡¢AAA ×é¼þÒÔ¼°ËüÃÇÈçºÎ¹¤×÷£¬ÁíÍ⻹ÓÐ LDAP ÐÒé¡£
Remote Authentication Dial-In User Service ÐÒéÊÇÔÚ IETF µÄ RFC 2865 Öж¨ÒåµÄ£¨Çë²ÎÔÄ ²Î¿¼×ÊÁÏ »ñµÃÏà¹ØÁ´½Ó£©¡£ËüÔÊÐíÍøÂç·ÃÎÊ·þÎñÆ÷£¨NAS£©Ö´ÐжÔÓû§µÄÑéÖ¤¡¢ÊÚȨºÍ¼ÇÕÊ¡£RADIUS ÊÇ»ùÓÚ UDP µÄÒ»ÖÖ¿Í»§»ú/·þÎñÆ÷ÐÒé¡£RADIUS ¿Í»§»úÊÇÍøÂç·ÃÎÊ·þÎñÆ÷£¬Ëüͨ³£ÊÇÒ»¸ö·ÓÉÆ÷¡¢½»»»»ú»òÎÞÏß·ÃÎʵ㣨·ÃÎʵãÊÇÍøÂçÉÏרÃÅÅäÖõĽڵ㣻WAP ÊÇÎÞÏß°æ±¾£©¡£RADIUS ·þÎñÆ÷ͨ³£ÊÇÔÚ UNIX »ò Windows 2000 ·þÎñÆ÷ÉÏÔËÐеÄÒ»¸ö¼à»¤³ÌÐò¡£
RADIUS ºÍ AAA
Èç¹û NAS ÊÕµ½Óû§Á¬½ÓÇëÇó£¬Ëü»á½«ËüÃÇ´«µÝµ½Ö¸¶¨µÄ RADIUS ·þÎñÆ÷£¬ºóÕß¶ÔÓû§½øÐÐÑéÖ¤£¬²¢½«Óû§µÄÅäÖÃÐÅÏ¢·µ»Ø¸ø NAS¡£È»ºó£¬NAS ½ÓÊÜ»ò¾Ü¾øÁ¬½ÓÇëÇó¡£
¹¦ÄÜÍêÕûµÄ RADIUS ·þÎñÆ÷¿ÉÒÔÖ§³ÖºÜ¶à²»Í¬µÄÓû§ÑéÖ¤»úÖÆ£¬³ýÁË LDAP ÒÔÍ⣬»¹°üÀ¨£º
PAP£¨Password Authentication Protocol£¬ÃÜÂëÑéÖ¤ÐÒ飬Óë PPP Ò»ÆðʹÓã¬ÔÚ´Ë»úÖÆÏ£¬ÃÜÂëÒÔÃ÷ÎÄÐÎʽ±»·¢Ë͵½¿Í»§»ú½øÐбȽϣ©£»
CHAP£¨Challenge Handshake Authentication Protocol£¬ÌôÕ½ÎÕÊÖÑéÖ¤ÐÒ飬±È PAP ¸ü°²È«£¬ËüͬʱʹÓÃÓû§ÃûºÍÃÜÂ룩£»
±¾µØ UNIX/Linux ϵͳÃÜÂëÊý¾Ý¿â£¨/etc/passwd£©£»
ÆäËû±¾µØÊý¾Ý¿â¡£
ÔÚ RADIUS ÖУ¬ÑéÖ¤ºÍÊÚȨÊÇ×éºÏÔÚÒ»ÆðµÄ¡£Èç¹û·¢ÏÖÁËÓû§Ãû£¬²¢ÇÒÃÜÂëÕýÈ·£¬ÄÇô RADIUS ·þÎñÆ÷½«·µ»ØÒ»¸ö Access-Accept ÏìÓ¦£¬ÆäÖаüÀ¨Ò»Ð©²ÎÊý£¨ÊôÐÔ-Öµ¶Ô£©£¬ÒÔ±£Ö¤¶Ô¸ÃÓû§µÄ·ÃÎÊ¡£ÕâЩ²ÎÊýÊÇÔÚ RADIUS ÖÐ
Ïà¹ØÎĵµ£º
ѧlinuxÓм¸ÌìÁË ½ñÌìͻȻÏëÔÚlinuxÏ¿´¿´ÊÓÆµ ͻȻ·¢ÏÖ adobeûÓÐ×° ÓÚÊǾÍÈ¥ÍøÉÏÏÂÔØÁËÒ»¶Ñadobe ·¢ÏÖ¶¼Ã»ÓÐÓà ÎÊÌ⻹ÊÇûÓнâ¾ö ÓÚÊÇÔÚÂÛ̳ÉÏÇó½Ì Ч¹ûÒ²²»ÊÇºÜ´ó ²»ÊÇ˵µÄ̫רҵ ¾ÍÊǶÔÎÒµÄÇé¿ö²»Á˽â ûÓа취 Ö»ºÃ×Ô¼ºÃþ ......
3¡¢Ìõ¼þ±äÁ¿
¡¡¡¡Ç°Ò»½ÚÖÐÎÒÃǽ²ÊöÁËÈçºÎʹÓû¥³âËøÀ´ÊµÏÖÏ̼߳äÊý¾ÝµÄ¹²ÏíºÍͨÐÅ£¬»¥³âËøÒ»¸öÃ÷ÏÔµÄȱµãÊÇËüÖ»ÓÐÁ½ÖÖ״̬£ºËø¶¨ºÍ·ÇËø¶¨¡£¶øÌõ¼þ±äÁ¿Í¨¹ýÔÊÐíÏß³Ì×èÈûºÍµÈ´ýÁíÒ»¸öÏ̷߳¢ËÍÐźŵķ½·¨ÃÖ²¹ÁË»¥³âËøµÄ²»×㣬Ëü³£ºÍ»¥³âËøÒ»ÆðʹÓá£Ê¹ÓÃʱ£¬Ìõ¼þ±äÁ¿±»ÓÃÀ´×èÈûÒ»¸öỊ̈߳¬µ±Ìõ¼þ²»Âú×ãʱ£¬Ïß³ÌÍùÍù½â¿ªÏ ......
tables=fuckme query=where fucktime > trunc(sysdate)-1 direct=y
on linux query=\"where fucktime \> trunc\(sysdate\)-1\" ҪתÒå·û һǰһºó Öм䶼Ҫ ·ûºÅλǰ
direct=N ¿Éϧ²»Ö§³ÖÖ±½Ó·¾¶µ¼³ö ......
NRPE×ܹ²ÓÉÁ½²¿·Ö×é³É:
(1).check_nrpe²å¼þ,ÔËÐÐÔÚ¼à¿ØÖ÷»úÉÏ¡£
(2).NRPE daemon,ÔËÐÐÔÚÔ¶³ÌµÄlinuxÖ÷»úÉÏ(ͨ³£¾ÍÊDZ»¼à¿Ø»ú)
µ±NagiosÐèÒª¼à¿ØÄ³¸öÔ¶³ÌlinuxÖ÷»úµÄ·þÎñ»òÕß×ÊÔ´Çé¿öʱ£º
1).nagios»áÔËÐÐcheck_nrpe²å¼þ,ÎÒÃÇÒªÔÚnagiosÅäÖÃÎļþÖиæËßËüÒª¼ì²éʲô.
2).check_nrpe²å¼þ»áͨ¹ýSSLÁ¬½Óµ½Ô¶³ÌµÄNRPE d ......
½ø³ÌÒ»µ©µ÷ÓÃÁËwait£¬¾ÍÁ¢¼´×èÈû×Ô¼º£¬ÓÉwait×Ô¶¯·ÖÎöÊÇ·ñµ±Ç°½ø³ÌµÄij¸ö×Ó½ø³ÌÒѾÍ˳ö£¬Èç¹ûÈÃËüÕÒµ½ÁËÕâÑùÒ»¸öÒѾ±ä³É½©Ê¬µÄ×Ó½ø³Ì£¬wait ¾Í»áÊÕ¼¯Õâ¸ö×Ó½ø³ÌµÄÐÅÏ¢£¬ ²¢°ÑËü³¹µ×Ïú»Ùºó·µ»Ø£»Èç¹ûûÓÐÕÒµ½ÕâÑùÒ»¸ö×Ó½ø³Ì£¬wait¾Í»áÒ»Ö±×èÈûÔÚÕâÀֱµ½ÓÐÒ»¸ö³öÏÖΪֹ¡£
wait£¨µÈ´ý×Ó½ø³ÌÖжϻò½áÊø£©
Ïà¹Øº¯Êý waitp ......