¡¡¡¡Òþ²ØÃÜÂë×÷ΪLinux²úÆ·µÄ¼È¶¨ÊÂʵ±ê×¼ÒѾÓкöàÄêÁË£¬md5ÃÜÂëµÄʹÓÃÒàÊÇÈç´Ë¡£µ«ÊÇ£¬Ê¹Óô«Í³µÄÒþ²ØÃÜÂë·½·¨Ò²Óв»×ãÖ®´¦£¬ÉõÖÁmd5Ò²²»ÏñÒÔǰÄÇô°²È«ÁË¡£
Òþ²ØÃÜÂëÎļþµÄÒ»¸öȱµã¾ÍÊÇ£¬ÈÎÒâÒ»¸öÐèÒª²éѯ¸ö±ðÒþ²ØÃÜÂ루ÈçÄúµÄÃÜÂ룩µÄÓ¦ÓóÌÐòÒ²¿ÉÒÔ¿´µ½ÆäËûÈ˵ÄÒþ²ØÃÜÂ룬ÕâÒ²¾ÍÒâζ×ÅÈÎÒâÒ»¸ö¿ÉÒÔ¶ÁÈ¡Òþ²ØÎļþµÄ¶ñÒ⹤¾ß¶¼Äܹ»»ñµÃ±ðÈ˵ÄÒþ²ØÃÜÂë¡£
³ýÁËÒþ²Ø£¬»¹ÓÐÒ»¸ö½Ð×ötcbµÄ¿É¹©Ñ¡ÔñµÄ°ì·¨£¬ËüÓÉOpenwall Project±àд£¬¿ÉÒÔ´ÓtcbÖ÷Ò³ÉÏ»ñÈ¡¡£Ç¨ÒƵ½tcbËäÈ»ÐèÒª×öһЩ¹¤×÷£¬µ«ÊÇÏ൱ֱ½Ó¡£ÒòΪֻÓÐOpenwall GNU/*/Linux¡¢ALT Linux¡¢ºÍAnnvix Ö±½ÓÖ§³Ötcb¡£ÒªÎªÄúÑ¡ÔñµÄÁ÷ͨ²úÆ·»ñµÃtcbÖ§³Ö£¬Äú±ØÐëÖØÐ±༼¸¸ö³ÌÐò£¬´òÉϲ¹¶¡¡£
´ÓtcbÕ¾µãÉÏ£¬Äú¿ÉÒÔÏÂÔØtcb³ÌÐò£¬²¢½«ËüºÍÏà¹ØµÄpam_tcbºÍnss_tcb¿âÒ»Æð½øÐб༡£Äú»¹ÐèÒª´òÉÏÖ§³Öcrypt_blowfishµÄglibc²¹¶¡£¨ÏñSUSEÒ»ÑùµÄÓÐЩ²úÆ·¿ÉÄÜÒѾ¿ÉÒÔÖ§³ÖblowfishÃÜÂ룬¾Í²»ÐèÒªÔÙ´ò²¹¶¡ÁË£©¡£
Ò²ÐíÄú»¹ÏëΪshadow-utils×é´òÉϲ¹¶¡£»È¡¾öÓÚÄúµÄ²úÆ·Ëù²ÉÓõÄshadow-utilsµÄ°æ±¾£¬Äú¿ÉÒÔ´ÓOpenwall CVSΪshadow-utils 4.0.4.1»ò´ÓAnnvix SVN´¢´æ¿âΪ4.0.12»ñµÃËùÐèµÄ²¹¶¡¡£Ïñadduser¡¢chageµÈÕâÑùµÄ¹¤¾ßÖеÄShadow-utilsÐèÒª±»´òÉϲ¹¶¡£¬ÌṩtcbÖ§³Ö¡£ÔÚtcbÒ³ÃæÉÏÓпÉÒÔ´òglibc²¹¶¡µÄ×îÐÂcrypt_blowfishµÄÁ´½Ó¡£
Ò»µ©ÕâЩÏȾöÌõ¼þ¶¼Âú×ãÁË£¬ÇÒtcb±àÒëºÍ°²×°ÒÔºó£¬Ö»Ðè¼òµ¥µØ½«/etc/pam.d/*ÎļþÖеÄËùÓе÷Óö¼Ì滻Ϊpam_unix.soºÍ/»òpam_pwdb.so¾ÍÐÐÁË¡£È»ºó¾Í¿ÉÒÔÏñÁбíAÖÐÄÇÑùʹÓÃpam_tcb.soÁË¡£
¡¡¡¡ÁбíA[table][tr][td]auth
[/td][td]required
[/td][td]pam_env.so
[/td][/tr][tr][td]auth
[/td][td]required
[/td][td]pam_tcb.so shadow fork nullok prefix=$2a$ count=8
[/td][/tr][tr][td]
[/td][td]
[/td][td]
[/td][/tr][tr][td]account
[/td][td]required
[/td][td]pam_tcb.so shadow fork
[/td][/tr][tr][td]password
[/td][td]required
[/td][td]pam_passwdqc.so min=disabled,12,8,6,5 max=40 passphrase=3 match=4 similar=deny random=42 enforce=everyone retry=3
[/td][/tr][tr][td]password
[/td][td]required
[/td][td]pam_tcb.so use_authtok shadow write_to=tcb fork nullok prefix=$2a$ count=8
[/td][/tr][tr][td]session
[/td][td]required
[/td][td]pam_limits.so
[/td][/tr][tr][td]session
[/td][td]required
[/td][td]pam_tcb.so
[/td][/tr][/table]Èç¹ûÄúÏ£Íû¼ÌÐøÊ¹ÓÃmd5ÃÜÂ룬¶ø²»ÊÇblowfishÃÜÂ룬½«prefix=$2a$ count=8Ò»Ìõ´ÓÃÜÂëÐÐÒÆ³ý£¬Í¬Ê±£¬Äú»¹ÐèÒªÐÞ¸Ä/etc/nsswitch.conf£¬ÈÃÒþ²ØÐиĶÁ£º
shadow: tcb nisplus nis
passwd³ÌÐòÐèÒªsgidÒþ²Ø£¬¶ø²»ÊÇsuid¸ù£¬²¢ÇÒ/etc/login.defsÖÐÒª°üÀ¨USE_TCB yes¡£ÕâЩÍê³ÉÒÔºó£¬Äú¾Í¿ÉÒÔÖ´ÐÐ/sbin/tcb_convert³ÌÐò£¬½«Òþ²ØÎļþת»»³ÉΪÊʵ±µÄµ¥Ò»Óû§ÎļþÁË£¬ÕâЩÎļþ½«´¢´æÔÚ/etc/tcb/ÖС£×öÍêÕâЩ֮ºó£¬ÒƳý/etc/shadowºÍ/etc/shadow-Îļþ£¬È»ºóÄúµÄϵͳ¾Í¿ÉÒÔʹÓÃtcbÁË¡£
»ñµÃtcbÖ§³Ö¿ÉÄÜÐèÒª»¨µã¹¦·ò£¬µ«Òź¶µÄÊǸü¶àµÄ²úƷûÓÐÌṩ֧³Ö£¬ËüÃǼÈûÓб¾µØÖ§³ÖҲûÓÐͨ¹ý²å¼þÀ´Ö§³Ö¡£Ê¹ÓÃtcb£¬Á¬Í¬blowfishÃÜÂëÒ»Æð£¬»áΪÄúµÄLinux²úÆ·Ìṩһ¸ö°²È«µÃ¶àµÄÃÜÂëϵͳ¡£