·Î±×ÀÎ
¾ÆÀ̵ð
¾Ï   È£
ȸ¿ø°¡ÀÔ   ¾ÏÈ£ºÐ½Ç
¬á¬â¬à¬ã¬ä¬Ú¬ä¬å¬ä¬Ü¬Ú, ¬Õ¬à¬ã¬å¬Ô, ¬Ú¬ß¬Õ¬Ú¬Ó¬Ú¬Õ¬å¬Ñ¬Ý¬Ü¬Ú, ¬Ú¬ß¬ä¬Ú¬Þ http://youdosug.com - ¬á¬â¬à¬ã¬ä¬Ú¬ä¬å¬ä¬Ü¬Ú, ¬Õ¬à¬ã¬å¬Ô, ¬Ú¬ß¬Õ¬Ú¬Ó¬Ú¬Õ¬å¬Ñ¬Ý¬Ü¬Ú, ¬Ú¬ß¬ä¬Ú¬Þ
  Home
  ²ôÀû²ôÀû
  ¸®´ª½º
  ¼îÇθô
  °ÔÀÓ
  ¾Æ¹ÙŸ¼¥
  ¾Æ¹ÙŸ°ü¸®ÀÚ
  HTML ±³À° ¿¹Á¦1
  HTML ±³À° ¿¹Á¦2
  Å×½ºÆ®ÆäÀÌÁö


¸®´ª½º Tech °Ô½ÃÆÇ


ADMIN 2024. 05. 05.
 [Tip] bind_9.x_¼³Á¤
  ³¯Â¥: 2002.05.28. 14:04:37   Á¶È¸: 416
9.1.3rc1À» ¼³Ä¡ÇÏ°í DNSSECÀ» ½ÃÇèÇغýÀ´Ï´Ù. ÀÏ´Ü ÀÛµ¿ÇÏ°í ÀÖ´Ù´Â °Í¸¸ È®ÀÎÇß½À´Ï´Ù. ¾Æ·¡¿Í °°ÀÌ Çß½À´Ï´Ù.(¼³Á¤ ¹æ¹ý¿¡ ´ëÇÑ ¾ð±ÞÀÌ ¹èÆ÷µÈ ¹®¼­¿¡´Â ¾ø°í, <http://www.isc.org/>ÀÇ FAQ¿¡µµ 9.1.x ¹öÁ¯¿¡ ´ëÇÑ °ÍÀÌ ¾Æ´Ï¶ó 9.0.x ½ÃÀý¿¡ ÀÛ¼ºÇÑ °ÍÀ¸·Î º¸ÀÌ´Â ³»¿ëÀÌ Àִµ¥, ³°Àº °ÍÀÌÁö¸¸ À¯ÃßÇؼ®ÇÏ´Â µ¥ µµ¿òÀÌ µÇ¾ú½À´Ï´Ù.)

1. DNSSEC Å°¸¦ »ý¼ºÇÕ´Ï´Ù. Red HatÀº named¸¦ name À¯Àú¿¡ named ±×·ì¿¡
¼ÓÇÏ´Â °ÍÀ¸·Î ÇÏ°í Àֱ⠶§¹®¿¡, ¾Æ·¡¿Í °°ÀÌ ÇÏ¿´½À´Ï´Ù.

dnssec-keygen -a hmac-md5 -b 512 -n ZONE -r /dev/random named


ÀÌ·¸°Ô Çϸé, ÇöÀç ÀÛ¾÷ µð·ºÅ丮¿¡ Knamed.+157+61652.key,
Knamed.+157+61652.private¶ó´Â µÎ °¡Áö ÆÄÀÏÀÌ ¸¸µé¾îÁý´Ï´Ù.

2. ÀÇÀÇ key ÆÄÀÏ Áß Knamed.+157+61652.keyÀÇ ³»¿ë Áß base64·Î ÀÎÄÚµù
µÈ °ÍÀ» /etc/rndc.confÀÇ 'key' ¼³Á¤ Áß secure Ç׸ñ¿¡ º¹»çÇÕ´Ï´Ù.
keyÀÇ À̸§Àº Àû´çÈ÷ ºÙÀÔ´Ï´Ù. Àú´Â 'mykey'·Î ÇÏ¿´½À´Ï´Ù.

¿¹¸¦µé¸é, ¾Æ·¡¿Í °°½À´Ï´Ù.(Á¦°¡ ÇÑ °Í°ú´Â ¹°·Ð ´Ù¸£ÁÒ)

key "mykey" {
algorithm hmac-md5;
secret "JHAqThzehwRzCQjtBQdVR0pdKkXaIuiCAaVfzsRtLPeunsRyskWRbasvOOck";
};

3. ÀÌ°ÍÀ» ±×´ë·Î /etc/named.confÀÇ Àû´çÇÑ ´ë¸ñ¿¡ º¹»çÇÕ´Ï´Ù. ¸¶¿ì½º·Î
±Ü¾î¼­ ¿Å±â¸é µÇÁÒ. ±× ´ÙÀ½ Áß¿äÇÑ °ÍÀε¥, ´ÙÀ½ÀÇ ³»¿ëÀ»
/etc/named.conf¿¡ ¼³Á¤ÇÏ¿©¾ß ÇÕ´Ï´Ù. ÀÌ°ÍÀº bind-9.x.xÀÇ CHANGES ÆÄÀÏ
¿¡ ³ª¿À´Âµ¥, ´Ù¸¥ ¾îµð¿¡¼­µµ ¾ð±ÞÇÏÁö ¾Ê´Â ´ë¸ñÀÌ´õ±º¿ä. ³í¸®ÀûÀ¸·Î
ºÁ¼­´Â ÀÌ ´ë¸ñÀÌ ¾Õ¼­ÀÇ key ¼³Á¤ ´ë¸ñº¸´Ù À§·Î °¡´Â °Ô ÁÁ°ÚÁÒ.
¾Æ·¡¿¡ ¿¹¸¦µì´Ï´Ù.

controls {
inet * port 1500
allow { any; } keys { "mykey"; };
};


key "mykey" {
algorithm hmac-md5;
secret "JHAqThzehwRzCQjtBQdVR0pdKkXaIuiCAaVfzsRtLPeunsRyskWRbasvOOck";
};

À§ 'controls' ¼³Á¤¿¡¼­ port ¹øÈ£´Â, CHANGES ÆÄÀÏ¿¡¼­´Â 1024·Î µÇ¾î
ÀÖ½À´Ï´Ù. Á¦ ½Ã½ºÅÛ¿¡¼­´Â ·ÎÄ®¿¡¼­ NFS¸¦ »ç¿ëÇϴµ¥, rpc.statd°¡ ÀÌ
Æ÷Æ®¸¦ ¾²°í Àֱ⠶§¹®¿¡ 1500À¸·Î ¼öÁ¤ÇÏ¿´½À´Ï´Ù. ÀÚ½ÅÀÇ ½Ã½ºÅÛ¿¡¼­
ÀÓÀÇ·Î Á¤ÇÑ Æ÷Æ®¸¦ ´Ù¸¥ ÇÁ·Î±×·¥ÀÌ ÀÌ¹Ì »ç¿ëÇÏ°í ÀÖ´Â Áö ¿©ºÎ¸¦ ¾Ë·Á
¸é, 'fuser -n tcp 1024'Çؼ­ ÆÄ¾ÇµÈ ÇÁ·Î¼¼½º ID¿¡ ±Ù°ÅÇÏ¿©
'ps ax | grep PID' ÇÏ¸é µË´Ï´Ù.

4. ÀÌÁ¦ /etc/named.conf¿¡¼­ °¢ zone, reverse zone ¼³Á¤ *Àüü*¿¡ ¾Æ·¡¿Í
°°Àº ³»¿ëÀ» Ãß°¡ÇÕ´Ï´Ù.(root cache¿Í localhost zoneÀº ÇÒ ÇÊ¿ä°¡ ¾ø°ÚÁÒ)

allow-update { key "mykey"; };

Çϳª¸¸ ¿¹¸¦µé¸é ¾Æ·¡¿Í °°½À´Ï´Ù.

zone "plw.net" {
type master;
file "plw.net.zone";
notify no;
allow-update { key "mykey"; };
};


5. ÀÌÁ¦ 1¿¡¼­ »ý¼ºÇÑ 2°³ÀÇ key ÆÄÀÏÀ» /var/named·Î º¹»çÇÕ´Ï´Ù.(namedÀÇ
FAQ¿¡ ÀÇÇϸé Ŭ¶óÀ̾ðÆ® È£½ºÆ®ÀÇ /var/named¶ó°í ¸»ÇÏ°í Àִµ¥, Àú´Â
±×³É bind9°¡ ¼³Ä¡µÈ Á¦ pcÀÇ °Å±â¿¡ ½ÃÇè»ï¾Æ ¿Å°Üº¸°í Çϴµ¥, Àß µÇ´Â±º
¿ä)

6. '/etc/rc.d/init.d/named restart'Çؼ­ named¸¦ Àç½ÇÇàÇÕ´Ï´Ù.

Á¦´ë·Î µÇ¸é /var/log/messages¿¡ ¾Æ·¡¿Í °°Àº ³»¿ëÀÌ º¸¿©¾ß ÇÕ´Ï´Ù.
±×´ë·Î ¿Å±â´Ï ÇàÀÌ ³Ê¹« ±æ¾îÁ® ¿¬µµ, ³¯Â¥, ½Ã°¢Àº »ý·«ÇÏ¿´½À´Ï´Ù.
¸¶Áö¸·ÀÇ 'running'ÀÌ º¸¿©¾ß Á¦´ë·Î ½ÇÇàµÈ °ÍÀÔ´Ï´Ù. À§ÀÇ named
½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¶§´Â ¼º°ø ¿©ºÎ¸¦ Àß ¸ð¸£´Â ¼ö°¡ ¸¹½À´Ï´Ù.

progress named: named shutdown succeeded
progress named: named startup succeeded
progress named[3842]: starting BIND 9.1.3rc1 -u named
progress named[3842]: using 1 CPU
progress named[3846]: loading configuration from '/etc/named.conf'
progress named[3846]: no IPv6 interfaces found
progress named[3846]: listening on IPv4 interface lo, 127.0.0.1#53
progress named[3846]: listening on IPv4 interface eth0, 192.168.2.1#53
progress named[3846]: listening on IPv4 interface eth1, 192.168.1.1#53
progress named[3846]: listening on IPv4 interface ppp0, 211.58.12.247#53
progress named[3846]: command channel listening on 0.0.0.0#1500
progress named[3846]: running


7. rndc, nsupdate ¸í·ÉÀÌ µè´Â Áö ½ÃÇèÇÑ´Ù.

7-1) /usr/sbin/rndc -p 1500 reload
ÇöÀç rndc´Â 8.x.x ÀÌÀü ¹öÁ¯ÀÇ ndcd¿¡ ºñÇØ ±¸ÇöµÈ ±â´ÉÀÌ Àû½À
´Ï´Ù.

7-2) /us/nsupdate -d -k /var/named/Knamed.+157+61652.key

nsupdateÀÇ °æ¿ì´Â ¼º°øÀûÀÌ¸é ¼Ð ÇüÅ·Π¸í·ÉÀ» ³»·Á¾ß ÇÕ´Ï´Ù. ÀÚ
¼¼ÇÑ °ÍÀº 'man nsupdate'Çؼ­ »ìÆ캸½Ã±æ ...

Ã߽Š#1 :
bind-9.1.x rpm¿¡ °°ÀÌ ¹èÆ÷µÇ´Â À¯Æ¿¸®Æ¼ Áß name-checkconf´Â Àß
ÀÛµ¿Çϳª named-checkzoneÀº Á» ¹®Á¦°¡ ÀÖ´Â °Í°°±º¿ä. named°¡ ½ÇÇà
µÇ¸é¼­ ¾Æ¹«·± °æ°í¸¦ ³»Áöµµ ¾Ê´Âµ¥(µð¹ö±ë ¿É¼ÇÀ» ÁØ »óÅ¿¡¼­µµ),
ÀÌ°Ç °è¼Ó ¹º°¡°¡ À߸øµÇ¾ú´Ù°í °æ°í¸¦ ³»°í ÀÖ±º¿ä. °á°úÀûÀ¸·Î name
lookup µîÀº Àß ÀÛµ¿Çϴµ¥ ...

Ã߽Š#2:
¿À´Ã Áú¹® ´ö¿¡ ±× µ¿¾È, ½Å°æµµ ¾È ¾²°í ÀÖ´ø DNSSEC¿¡ »ìÆ캸°í ¾à
°£ÀÇ Á¤¸®¸¦ ÇÒ ±âȸ¸¦ °¡Á³½À´Ï´Ù. °¨»çÇÕ´Ï´Ù. :-)

---------------------------------------------------------------------------
--
.~. ¸®´ª½º ÇÑ±Û ÆÁ ÇÁ·ÎÁ§Æ® - <http://kltp.kldp.org/>
/V\ KorWeblog ´º½º/Æ÷·³ - <http://weblog.kldp.org/>
/( )\ Koru.org - ·¯½Ã¾Æ ÇÑÀÎÀÇ ÀÎÅÍ³Ý Ä¿¹Â´ÏƼ <http://Koru.org>
^^-^^ ÀÓ ÀºÀç mailto:eunjea@kldp.org <http://linux.koru.org/>

LIST  MODIFY DELETE WRITE REPLY 





Àüü±Û ¸ñ·Ï 2024. 05. 05.  Àüü±Û: 109  ¹æ¹®¼ö: 62186
45 [Perl] ¼­¹ö ÅëÇÕ ÈÄ Àß µ¹´ø perl °Ô½ÃÆÇÀÌ ÀÎÅͳμ­¹ö¿¡·¯°¡ ³¯ ¶§  2005.06.24.423
44 Æнº¿öµå Å©·¢ Åø John the Ripper  2005.06.10.1068
43 [ÇØÅ·] psybnc? eggdrop?  2005.06.08.825
42 [±â»ç] ¿ÀǼҽº ½ºÆÔ SWÀÇ Áø¼ö¡¸½ºÆÔ¾î½Ø½Å¡¹  2005.06.03.360
41 make: *** [ext/standard/microtime.lo] ¿À·ù  2005.05.25.450
40 [Tip] ¸®´ª½º ½Ã½ºÅÛ¿¡¼­ ¿¡·¯°¡ Çѱ۷Π³ª¿Ã ¶§  2005.03.08.353
39 [Tip] hdparmÀ» ÀÌ¿ëÇÏ¿© ÇÏµå µð½ºÅ© ¼Óµµ Çâ»ó½ÃÅ°±â  2005.01.28.1152
83 ILEEQENYSivLKCDZw  2011.10.27.335
38 È¨ÆäÁã À§º¯Á¶ ¹æÁö ±³À°  2004.11.11.385
37 test  2004.11.11.363
36 [¾ÆÆÄÄ¡] ½Ã½ºÅÛ°ü¸®ÀÚ¸¦ À§ÇÑ ½Ã½ºÅÛÀå¾Ö¿Í ´ëó¹ý(1) - ¾ÆÆÄÄ¡  2004.11.02.2203
96 PjRPbInBgCTS  2014.06.29.306
35 [º¸¾È] iptables »ç¿ë¹ý  2004.10.28.362
34 [¸®´ª½º] vi ¸ðµå¿¡¼­ ÇѱÛÀÌ ±úÁ® º¸ÀÏ ¶§  2004.08.20.351
33 [¾ÆÆÄÄ¡] 404 µî ¿¡·¯ ÆäÀÌÁö ¼öÁ¤ ¹æ¹ý  2004.08.20.354
32 [¾ÆÆÄÄ¡] access ·Î±×¿¡ µµ¸ÞÀÎ¸í ³²°Ô ÇÏ±â  2004.08.16.354
31 [TIP} ½© »ó¿¡¼­( vi ¿¡¼­)ÇѱÛÀÌ ±úÁ® º¸ÀÏ ¶§  2004.08.10.359
30 [°æÇè] .forward ¸¦ ¼³Á¤Çߴµ¥µµ ¸ÞÀÏ Æ÷¿öµùÀÌ ¾È µÉ ¶§  2004.07.30.354
29 [¾ÆÇÇÄ¡] ·Î±× ÆÄÀÏ - ƯÁ¤ Çü½ÄÀÇ ÆÄÀÏ ·Î±×¸¦ µû·Î ³²±â°Å³ª ³²±âÁö ¾Ê±â  2004.07.24.1192
28 [TIP] ¿©·¯°¡Áö Æ÷¿öµù ¹æ½Ä  2004.07.24.460
27 [¾ÆÆÄÄ¡] ¹«´Ü ¸µÅ© ¹æÁö  2004.06.29.318
26 [TIP] SYN Flooding ÇØ°áÃ¥  2004.06.28.371
25 [TIP] À¯Àú ±ÇÇÑ ¹× ±×·ì ±ÇÇÑ ÀÏ°ý º¯°æÇÏ±â  2004.06.14.364
24 [TIP] ´ë¹®ÀÚ ¾ÆÀ̵ð Ãß°¡ ¾È µÉ ¶§  2004.03.11.373
23 [MySQL] MySQL ¸í·É¾î ¸ðÀ½  2004.02.21.501
22 [TIP] ¼­¹ö °ü¸®¿ë ¸í·É¾î ¸ðÀ½  2004.02.18.354
82 RZliYGRoRwSmt  2011.10.26.325
21 [Á¤º¸] ÃÖ±Ù ¶ß´Â mrtg ´ë¿ë, ±¹³»»ê rrdbelt  2004.02.18.440
20 [named] lame server ·Î±× ³²Áö ¾Ê°Ô Á¶Á¤  2003.11.17.401
19 [¾ÆÆÄÄ¡] php ÆÄÀÏÀÌ ¿­¸®Áö ¾Ê°í ´Ù¿î·Îµå âÀÌ ¿­¸± ¶§  2003.09.26.684
RELOAD WRITE
[1] [2] 3 [4] 





Copyright¨Ï 2002 RUBICON