ºìÁªLinuxÃÅ»§
Linux°ïÖú

ÓÃSRP½¨Á¢°²È«µÄLinux FTP·þÎñÆ÷

·¢²¼Ê±¼ä:2006-02-03 09:58:13À´Ô´:ºìÁª×÷Õß:zz123
¡¡¡¡ÔÚÖÐСÐÍÒì¹¹ÍøÂçÖУ¬ºÜ¶àÓû§Ñ¡ÔñLinux×÷ÎªÍøÂç²Ù×÷ϵͳ£¬ÀûÓÃÆä¼òµ¥µÄÅäÖúÍÓû§ÊìϤµÄͼÐνçÃæÌṩInternet·þÎñ£¬FTP±ãÊÇÆäÌṩµÄ·þÎñÖ®Ò»¡£ÔÚÖÚ¶àÍøÂçÓ¦ÓÃÖУ¬FTP£¨Îļþ´«ÊäЭÒ飩ÓÐ×ŷdz£ÖØÒªµÄµØÎ»¡£»¥ÁªÍøÒ»¸öÊ®·ÖÖØÒªµÄ×ÊÔ´¾ÍÊÇÈí¼þ×ÊÔ´£¬¶ø¸÷ÖÖ¸÷ÑùµÄÈí¼þ×ÊÔ´´ó¶àÊý¶¼·ÅÔÚFTP·þÎñÆ÷ÖС£Óë´ó¶àÊý»¥ÁªÍø·þÎñÒ»Ñù£¬FTPÒ²ÊÇÒ»¸ö¿Í»§»ú/·þÎñÆ÷ϵͳ¡£


¡¡¡¡FTPÊÇ´«Í³µÄÍøÂç·þÎñ³ÌÐò£¬ÔÚ±¾ÖÊÉÏÊDz»°²È«µÄ£¬ÒòΪËüÃÇÔÚÍøÂçÉÏÓÃÃ÷ÎÄ´«ËÍ¿ÚÁîºÍÊý¾Ý£¬±ðÓÐÓÃÐĵÄÈ˷dz£ÈÝÒ׾ͿÉÒԽػñÕâЩ¿ÚÁîºÍÊý¾Ý¡£¶øÇÒ£¬ÕâЩ·þÎñ³ÌÐòµÄ°²È«ÑéÖ¤·½Ê½Ò²ÊÇÓÐÆäÈõµãµÄ£¬¾ÍÊǺÜÈÝÒ×Êܵ½¡°ÖмäÈË¡±£¨man-in-the-middle£©ÕâÖÖ·½Ê½µÄ¹¥»÷¡£Ëùν¡°ÖмäÈË¡±µÄ¹¥»÷·½Ê½£¬¾ÍÊÇ¡°ÖмäÈË¡±Ã°³äÕæÕýµÄ·þÎñÆ÷½ÓÊÕÄã´«¸ø·þÎñÆ÷µÄÊý¾Ý£¬È»ºóÔÙð³äÄã°ÑÊý¾Ý´«¸øÕæÕýµÄ·þÎñÆ÷¡£·þÎñÆ÷ºÍÄãÖ®¼äµÄÊý¾Ý´«Ëͱ»¡°ÖмäÈË¡±×ªÊÖºó×öÁËÊÖ½ÅÖ®ºó£¬¾Í»á³öÏÖºÜÑÏÖØµÄÎÊÌâ¡£ ½Ø»ñÕâЩ¿ÚÁîµÄ·½Ê½Ö÷ҪΪ±©Á¦ÆÆ½â¡£ÁíÍâʹÓÃsniffer³ÌÐò¼àÊÓÍøÂç·â°ü²¶×½FTP¿ªÊ¼µÄ»á»°ÐÅÏ¢£¬±ã¿É˳ÊֽػñrootÃÜÂë¡£

¡¡¡¡SSH£¨Secure Shell£©ÊÇÒÔÔ¶³ÌÁª»ú·þÎñ·½Ê½²Ù×÷·þÎñÆ÷ʱµÄ½ÏΪ°²È«µÄ½â¾ö·½°¸¡£Ëü×î³õÓÉ·ÒÀ¼µÄÒ»¼Ò¹«Ë¾¿ª·¢£¬µ«ÓÉÓÚÊܰæÈ¨ºÍ¼ÓÃÜËã·¨µÄÏÞÖÆ£¬ºÜ¶àÈËת¶øÊ¹ÓÃÃâ·ÑµÄÌæ´úÈí¼þOpenSSH¡£SSH£¨Secure Shell£©ÊÇÒÔÔ¶³ÌÁª»ú·þÎñ·½Ê½²Ù×÷·þÎñÆ÷ʱµÄ½ÏΪ°²È«µÄ½â¾ö·½°¸¡£Ëü×î³õÓÉ·ÒÀ¼µÄÒ»¼Ò¹«Ë¾¿ª·¢£¬µ«ÓÉÓÚÊܰæÈ¨ºÍ¼ÓÃÜËã·¨µÄÏÞÖÆ£¬ºÜ¶àÈËת¶øÊ¹ÓÃÃâ·ÑµÄÌæ´úÈí¼þOpenSSH¡£ Óû§Í¨¹ýSSH¿ÉÒÔ°ÑËùÓд«ÊäµÄÊý¾Ý½øÐмÓÃÜ£¬Ê¹¡°ÖмäÈË¡±µÄ¹¥»÷·½Ê½²»¿ÉÄÜʵÏÖ£¬¶øÇÒÒ²Äܹ»·ÀÖ¹DNSºÍIPÆÛÆ­¡£Ëü»¹ÓÐÒ»¸ö¶îÍâµÄºÃ´¦ÊÇ´«ÊäµÄÊý¾ÝÊǾ­¹ýѹËõµÄ£¬¿ÉÒÔ¼Ó¿ì´«ÊäµÄËÙ¶È¡£SSH×÷Óù㷺£¬¼È¿ÉÒÔ´úÌæTelnet£¬ÓÖ¿ÉÒÔΪFTP¡¢POP£¬ÉõÖÁΪPPPÌṩһ¸ö°²È«µÄ¡°Í¨µÀ¡±¡£SSHЭÒéÔÚÔ¤ÉèµÄ״̬ÖУ¬ÌṩÁ½¸ö·þÎñÆ÷¹¦ÄÜ£ºÒ»¸öÊÇÀàËÆTelnetµÄÔ¶³ÌÁª»úʹÓÃShell·þÎñÆ÷£¬¼´Ë׳ÆSSH¹¦ÄÜ£»ÁíÒ»¸öÊÇÀàËÆFTP·þÎñµÄSFTP-Server¹¦ÄÜ£¬¿ÉÌṩ¸ü°²È«µÄFTP·þÎñ¡£

¡¡¡¡SSHµÄ°²È«ÑéÖ¤ÈçºÎ¹¤×÷ÄØ£¿Ö÷ÒªÒÀ¿¿Áª»ú¼ÓÃܼ¼Êõ¡£´Ó¿Í»§¶ËÀ´¿´£¬ÓÐÒÔÏÂÁ½ÖÖ°²È«ÑéÖ¤¼¶±ð£º

¡¡¡¡1£®»ùÓÚ¿ÚÁîµÄ°²È«ÑéÖ¤£¨ssh1£© Ö»ÒªÖªµÀ×Ô¼ºµÄÕ˺źͿÚÁ¾Í¿ÉÒԵǼµ½Ô¶³ÌÖ÷»ú¡£ËùÓд«ÊäµÄÊý¾Ý¶¼½«±»¼ÓÃÜ£¬µ«ÊDz»Äܱ£Ö¤ÕýÔÚÁ¬½ÓµÄ·þÎñÆ÷¾ÍÊÇÏëÒªÁ¬½ÓµÄ·þÎñÆ÷¡£¿ÉÄÜÊܵ½¡°ÖмäÈË¡±µÄ¹¥»÷¡£

¡¡¡¡2£®»ùÓÚÃܳ׵ݲȫÑéÖ¤£¨ssh2£© ÐèÒªÒÀ¿¿Ãܳף¬¼´Óû§±ØÐëΪ×Ô¼º´´½¨Ò»¶ÔÃܳף¬²¢°Ñ¹«ÓÃÃܳ׷ÅÔÚÐèÒª·ÃÎʵķþÎñÆ÷ÉÏ¡£Èç¹ûÒªÁ¬½Óµ½SSH·þÎñÆ÷ÉÏ£¬¿Í»§¶ËÈí¼þ¾Í»áÏò·þÎñÆ÷·¢³öÇëÇó£¬ÇëÇóÓÃÃܳ׽øÐа²È«ÑéÖ¤¡£·þÎñÆ÷ÊÕµ½ÇëÇóÖ®ºó£¬ÏÈÔڸ÷þÎñÆ÷µÄhomeĿ¼ÏÂѰÕÒ¹«ÓÃÃܳף¬È»ºó°ÑËüºÍ·¢Ë͹ýÀ´µÄ¹«ÓÃÃܳ׽øÐбȽϡ£Èç¹ûÁ½¸öÃܳ×Ò»Ö£¬·þÎñÆ÷¾ÍÓù«ÓÃÃܳ׼ÓÃÜ¡°ÖÊѯ¡±£¨challenge£©£¬²¢°ÑËü·¢Ë͸ø¿Í»§¶ËÈí¼þ¡£¿Í»§¶ËÈí¼þÊÕµ½¡°ÖÊѯ¡±ºó£¬¾Í¿ÉÒÔÓÃ˽ÈËÃܳ׽âÃÜÔÙ°ÑËü·¢Ë͸ø·þÎñÆ÷¡£Ê¹ÓÃÕâÖÖ·½Ê½£¬Óû§±ØÐëÖªµÀ×Ô¼ºÃܳ׵ĿÚÁî¡£ÓëµÚÒ»ÖÖ¼¶±ðÏà±È£¬ÕâÖÖ¼¶±ð²»ÐèÒªÔÚÍøÂçÉÏ´«ËÍ¿ÚÁ²»½ö¼ÓÃÜËùÓд«Ë͵ÄÊý¾Ý£¬¶øÇÒ×èÖ¹ÁË¡°ÖмäÈË¡±¹¥»÷·½Ê½¡£OpenSSHĿǰ´æÔÚÁ½¸ö°²È«ÒÅ»¼£º¿ÚÁî¡¢ÃÜ³×ÆÆ½â£¨ÀûÓÃ×ÖµäÎļþÈ¥½âÃÜÂ룩ºÍOpenSSHÖпÉÄܱ»°²·ÅľÂí¡£

¡¡¡¡Ò»¡¢SRP¼ò½é

¡¡¡¡SRPÈ«³Æ£ºSecure Remote Password£¨°²È«Ô¶³ÌÃÜÂ룩£¬ËüÊÇÒ»¸ö¿ª·ÅÔ´´úÂëÈÏ֤ЭÒ顣ʹÓÃSRPµÄ¿Í»§»ú/·þÎñÆ÷²»»áÔÚÍøÂçÉÏÒÔÃ÷ÎÄ»ò¼ÓÃܵķ½Ê½´«ËÍÃÜÂ룬ÕâÑù¿ÉÒÔÍêÈ«Ïû³ýÃÜÂëÆÛÆ­ÐÐΪ¡£±£Ö¤¿ÚÁî¿ÉÒÔ°²È«µØÔÚÍøÂçÉÏÃæ´«ËÍ¡£»ù±¾µÄ˼ÏëÊÇ£¬·ÀÖ¹Óб»¶¯»òÖ÷¶¯ÍøÂçÈëÇÖÕßʹÓÃ×ֵ乥»÷¡£Standford´óѧ¼ÆËã»úϵ¿ª·¢ÁËSRPÈí¼þ°ü£¬Ìṩ»ùÓÚ¿ÚÁîÈÏÖ¤ºÍ»á»°¼ÓÃܵݲȫ»úÖÆ£¬¶ø²»ÐèÒªÓû§»òÕßÊÇÍø¹Ü²ÎÓëÃÜÔ¿µÄ¹ÜÀí»ò·Ö·¢¡£SRPΪÿһ¸öÈËÌṩ͸Ã÷µÄÃÜÂ밲ȫ£¬¶øÃ»ÓÐÆäËû°º¹óµÄÆðʼ¿ªÏú£¬±ÈÈç×èÖ¹ÆäËû°²È«Ì×¼þÈí¼þµÄʹÓõȡ£²»ÏñÆäËûµÄ°²È«Èí¼þ£¬SRPÌ×¼þÊÇÒ»¸öÍêÈ«µÄʵÏÖÃÜÂëÈÏÖ¤µÄÈí¼þ°ü£¬²»ÊÇÁÙʱµÄ½â¾ö·½°¸¡£ºÍ±ê×¼µÄ/etc/shadow-style °²È«±È½Ï£¬SRPÔÚÿһ¸ö·½Ãæ¶¼ÊDZȽϺõġ£Ê¹ÓÃSRP¶ÔÓû§ºÍ¹ÜÀíÕß¶¼ÓÐÒÔϵĺô¦£º

¡¡¡¡SRPµÖÖÆ¡°password sniffing¡±£¨¿ÚÁî¼àÌý£©¹¥»÷¡£ÔÚÒ»¸öʹÓÃSRPÈÏÖ¤µÄ»á»°ÖУ¬¼àÌýÕß²»»á¼àÊÓµ½ÈκÎÔÚÍøÂçÖд«Ë͵ĿÚÁî¡£ÔÚÔ¶³ÌµÇ½Èí¼þÖУ¬Ã÷ÎĵÄÃÜÂë´«ËÍÊÇ×î´óµÄ°²È«Â©¶´¡£ÈκÎÈË¿ÉÒÔÓÃÒ»¸ö¼òµ¥µÄÐá̽Æ÷£¨sniffer£©¹¤¾ßµÃµ½ÄãµÇ½µ½Ô¶³ÌϵͳµÄÃÜÔ¿¡£
SRPµÖÖÆ×ֵ乥»÷¡£Ò»¸öϵͳ±£»¤¼òµ¥µÄÃÜÂë¼àÌýÊDz»¹»µÄ¡£Èç¹û¹¥»÷ÕßʹÓÃÇ¿Á¦¹¥»÷£¬ÀýÈç×ֵ乥»÷µÈ£¬ËûÃDz»ÊǼòµ¥µÄÖ±½Ó¼àÌýÃÜÂ룬¶øÊǸú×ÙÕû¸öµÄ»á»°¹ý³Ì£¬È»ºó°ÑÕû¸öµÄÐÅÏ¢ºÍ×ÖµäÖÐµÄÆÕͨÃÜÂë¶ÔÕÕ¡£ÉõÖÁÓеÄKerberosϵͳ¶ÔÕâÑùµÄ¹¥»÷Ò²ÊÇ´àÈõµÄ¡£SRPÔÚµÖÖÆ×ֵ乥»÷µÄǰ£¬¾Í½øÐпÚÁîµÄ°²È«´¦ÀíÁË¡£Ê¹ÓõÄËã·¨¾ÍÊÇÔÚ¹¥»÷Õß½øÐÐÇ¿Á¦¹¥»÷ǰ¾ÍÒªÇó¹¥»÷Õß±ØÐëÖ´ÐÐÒ»´Î²»¿ÉÄܵĵĴóµÄ¼ÆËã¡£SRPÉõÖÁ±£»¤Õë¶Ô¿ÚÁîµÄ¡°active¡±¹¥»÷¡£Òò´Ë£¬¼´Ê¹ÈëÇÖÕßÓÐÄÜÁ¦ºÍÍøÂç½Ó´¥£¬Ò²²»Äܹ¥ÆÆSRP¡£ËùÒÔ¼´Ê¹ÊÇÓû§Ê¹ÓõÄÊǺܴàÈõµÄ¿ÚÁҲ²»»áÈÃÈëÇÖÕߺÜÈÝÒ×µØÆÆ½âµÄ¡£SRP¶ÔÓÚÖÕ¶ËÓû§ÊÇÍêȫ͸Ã÷µÄ¡£ÒòΪûÓÐËùνµÄ¡°ÃÜÔ¿Á´¡±(keyrings)ÒÔ¼°¡°Ö¤Ê顱(certificates)£¬»òÕß¡°Æ±¾Ý¡±£¨ticket£©¡£ÄãµÄ¿ÚÁî¾ÍÊÇÃÜÔ¿¡£SRP¼òµ¥µØ±£»¤Õâ¸öÃÜÔ¿£¬µ«Òª±ÈÀϵġ¢ÈõµÄÃÜÔ¿±£»¤»úÖÆÒªºÃ¡£SRP´Ó¹ÜÀíÕߵĽǶÈÀ´ËµÒ²ÊÇÈÝÒ×ʵʩµÄ¡£Ã»ÓÐËùνµÄ¡°ÃÜÔ¿·þÎñÆ÷¡±¡¢¡°Ö¤ÊéÈÏÖ¤¡±£¬ÒÔ¼°¡°ÈÏÖ¤·þÎñÆ÷¡±µÈÕâÑùµÄ¸ÅÄî¡£SRP¿ÚÁîÎļþÔÚ±ê×¼µÄUnix¿ÚÁîÎļþµÄÅԱߣ¬Èí¼þ±¾ÉíЭͬÕâÁ½¸öϵͳ¿ÚÁîºÍSRP¿ÚÁîÎļþµÄÒ»ÖÂÐÔ£¬Ã»ÓжàÓàµÄά»¤ÏµÍ³µÄ»úÖÆ¡£SRPÔÚÈÏÖ¤Ò»¸öÓû§µÄʱºò½»»»Ò»¸ö¼ÓÃܵÄÃÜÔ¿¡£Õâ¾ÍÒâζ×ÅÒ»¸öµÇ½»á»°ÊÇ¿ÉÒÔ±»¼ÓÃÜ£¬¶øµÖÖÆËùνµÄÍøÂç¼àÌýºÍ¶ñÒâµØ´Û¸Ä¡£Óû§ÔÚÔ¶³ÌÔĶÁËûÃǵÄÐż㣬ÊÇʹÓÃ128-bit¼ÓÃܺóµÄÐÅÏ¢£¬ÕâÊǵ±Óû§µÇ½ºó×Ô¶¯´¦ÀíµÄ£¬¶øÓû§±¾Éí²»±Ø¹ØÐĵ½µ×ÐèÒª²»ÐèÒª¼ÓÃÜ¡£ÏµÍ³Íê³É¼ÓÃÜ£¬È»ºóË͵½Óû§µÄÕâÀï¡£ÁíÍâSRP²»Ê¹ÓüÓÃܽøÐÐÈÏÖ¤£¬ÕâʹµÃËü±È»ùÓÚ¹«ÓÃ/˽ÓÃÃܳ׵ÄÈÏÖ¤·½Ê½Ëٶȸü¿ì½Ý¡¢°²È«¡£SRPȱʡʹÓõÄ128-bitµÄCAST¼ÓÃÜËã·¨¡£CAST-128ÔÚRFC2144£¨http://srp.stanford.edu/srp/rfc2144.txt£©ÖÐÓж¨Òå¡£±ê×¼µÄSRPÒ²Ö§³Ö56-bitµÄDESÒÔ¼°48λµÄDES¡£¸ß¼¶µÄÖ§³ÖTriple-DES¼ÓÃÜÊֶΡ£±¾ÎĽ«½éÉÜÈçºÎ½¨Á¢»ùÓÚSRPµÄTelnet·þÎñÆ÷¡£²Ù×÷»·¾³Redhat Linux 9.0¡£

¡¡¡¡¶þ¡¢Èí¼þÏÂÔØºÍ±àÒë

¡¡¡¡SRPÈí¼þÖ÷Ò³ÊÇ£ºhttp://srp.stanford.edu ×îа汾2.1.1£¬°²×°SRPǰÏÈÒª°²×°OpenSSL¡£

#wget http://srp.stanford.edu/source/srp-2.1.1.tar.gz

#cp /usr/src/redhat/SOURCES

#./configure --with-openssl=/usr/src/redhat/SOURCES/openssl-0.9.6 \

--with-pam

#make£»make install



¡¡¡¡Èý¡¢½¨Á¢Ö¸ÊýÃÜÂëϵͳEPS

¡¡¡¡EPSÈ«³Æ£ºExponential Password System£¨Ö¸ÊýÃÜÂëϵͳ£©£¬SRPÈí¼þ°üÖÐÒѾ­°üÀ¨EPSÔ´´úÂë¡£

¡¡¡¡1. °²×°PAMÄ£¿é

¡¡¡¡PAM¼ò½é£º

¡¡¡¡PAMÈ«³Æ£ºPluggable Authentication Module £¨Ç¶ÈëʽÈÏ֤ģ¿é£©¡£Ëü×î³õÓÐSUN¹«Ë¾¿ª·¢£»ºÜ¿ì±»LinuxÉçÇøµÄ½ÓÊÜ£¬²¢ÇÒ¿ª·¢Á˸ü¶àµÄÄ£¿é¡£ÆäÄ¿±êÊÇÌṩһÌ׿ÉÓÃÓÚÑéÖ¤Óû§Éí·ÝµÄº¯Êý¿â£¬´Ó¶ø½«ÈÏÖ¤´ÓÓ¦ÓóÌÐò¿ª·¢ÖжÀÁ¢³öÀ´¡£Linux-PAM´¦ÀíËÄÖÖ¶ÀÁ¢µÄ£¨¹ÜÀí£©¹¤×÷¡£ËüÃÇÊÇ£º ÈÏÖ¤¹ÜÀí£» ÕʺŹÜÀí£» »á»°ÆÚ¼ä¹ÜÀí£»ºÍÃÜÂë¹ÜÀí¡£

¡¡¡¡PAM¹¤×÷·½Ê½£º

¡¡¡¡£¨1£© µ÷ÓÃij¸öÓ¦ÓóÌÐò£¬ÒԵõ½¸Ã³ÌÐòµÄ·þÎñ¡£

¡¡¡¡£¨2£© PAMÓ¦ÓóÌÐòµ÷Óúǫ́µÄPAM¿â½øÐÐÈÏÖ¤¹¤×÷¡£

¡¡¡¡£¨3£© PAM¿âÔÚ/etc/pam.d/Ŀ¼ÖвéÕÒÓйØÓ¦ÓóÌÐòϸ½ÚµÄÅäÖÃÎļþ,¸ÃÎļþ¸æËßPAM,±¾Ó¦ÓóÌÐòʹÓúÎÖÖÈÏÖ¤»úÖÆ¡£

¡¡¡¡£¨4£© PAM¿â×°ÔØËùÐèµÄÈÏ֤ģ¿é¡£

¡¡¡¡£¨5£© ÕâЩģ¿é¿ÉÒÔÈÃPAMÓëÓ¦ÓóÌÐòÖеĻỰº¯Êý½øÐÐͨÐÅ¡£

¡¡¡¡£¨6£© »á»°º¯ÊýÏòÓû§ÒªÇóÓйØÐÅÏ¢¡£

¡¡¡¡£¨7£© Óû§¶ÔÕâЩҪÇó×ö³ö»ØÓ¦£¬ÌṩËùÐèÐÅÏ¢¡£

¡¡¡¡£¨8£© PAMÈÏ֤ģ¿éͨ¹ýPAM¿â½«ÈÏÖ¤ÐÅÏ¢Ìṩ¸øÓ¦ÓóÌÐò¡£

¡¡¡¡£¨9£© ÈÏÖ¤Íê³Éºó£¬Ó¦ÓóÌÐò×ö³öÁ½ÖÖÑ¡Ôñ£º

¡¡¡¡½«ËùÐèȨÏÞ¸³ÓèÓû§£¬²¢Í¨ÖªÓû§¡£

¡¡¡¡ÈÏ֤ʧ°Ü£¬²¢Í¨ÖªÓû§¡£

¡¡¡¡PAM¹¤×÷Á÷³Ì¼ûͼ1¡£



ͼ1 PAM¹¤×÷Á÷³Ì

¡¡¡¡PAM¾ßÌåʹÓ÷½·¨£º

#cd /usr/src/redhat/SOURCES/srp-2.1.1/base/pam_eps.

#install -m 644 pam_eps_auth.so pam_eps_passwd.so /lib/security



¡¡¡¡ÉÏÃæÃüÁî»áÔÚ/lib/security Ŀ¼Ï°²×°PAMÄ£¿é¡£È»ºóʹÓÃÃüÁ¡°/usr/local/bin/tconf¡±´´½¨/etc/tpasswd ºÍ /etc/tpasswd.confÎļþ¡£

¡¡¡¡2. ʹÓÃEPS PAMÄ£¿é½øÐÐÃÜÂëÑéÖ¤

¡¡¡¡£¨1£© Ê×Ïȱ¸·Ý /etc/pam.d/system-authÎļþ

¡¡¡¡£¨2£© ÐÞ¸Ä /etc/pam.d/system-authÎļþÈçÏÂÐÎʽ£º

auth required /lib/security/pam_unix.so likeauth nullok md5 shadow

auth sufficient /lib/security/pam_eps_auth.so

auth required /lib/security/pam_deny.so

account sufficient /lib/security/pam_unix.so

account required /lib/security/pam_deny.so

password required /lib/security/pam_cracklib.so retry=3

password required /lib/security/pam_eps_passwd.so

password sufficient /lib/security/pam_unix.so nullok use_authtok md5 shadow

password required /lib/security/pam_deny.so

session required /lib/security/pam_limits.so

session required /lib/security/pam_unix.so




¡¡¡¡×¢ÒâÉÏÃæµÚÒ»ÐкÚÌå×Ö±íʾPAMµÄeps_authÄ£¿é¿ÉÒÔÂú×ãÈÏÖ¤ÐèÇó¡£µÚ¶þÐкÚÌå×Ö±íʾPAM µÄpam_eps_passwd.so Ä£¿éÓÃÀ´½øÐÐÃÜÂë¹ÜÀí¡£

¡¡¡¡£¨3£© ½«±ê×¼ÃÜÂëת»»ÎªEPS¸ñʽ

¡¡¡¡£¨4£© /etc/pam.d/system-auth ÅäÖÃÎļþµÄÄ£¿épam_eps_passwd.so ½«EPS°æ±¾µÄÃÜÂëÑéÖ¤×Ö·û´®Ð´Èë/etc/tpasswd ÎļþÖС£ ÐÞ¸Ä /etc/pam.dpasswdÎļþÈçÏÂÐÎʽ£º

auth required /lib/security/pam_stack.so service=system-auth

account required /lib/security/pam_stack.so service=system-auth

password required /lib/security/pam_stack.so service=system-auth



¡¡¡¡ËÄ¡¢Æô¶¯SRP°æ±¾ÏµÄFTP·þÎñÆ÷

¡¡¡¡£¨1£©½øÈëSRPÔ´´úÂëFTP×ÓĿ¼£¬·Ö±ð½¨Á¢FTP·þÎñÆ÷ÎļþºÍFTP¿Í»§¶ËÎļþ£º

#cd /usr/src/redhat/SOURCES/srp-2.2.1/ftp

#make£»make install



¡¡¡¡£¨2£©½¨Á¢³¬¼¶·ÃÎʳÌÐò/etc/xinetd.d/srp-ftpd ÄÚÈÝÈçÏ£º

service ftp

{

socket_type = stream

wait = no

user = root

server = /usr/local/sbin/ftpd

log_on_success += DURATION USERID

log_on_failure += USERID

nice = 10

disable = no

}



¡¡¡¡£¨3£©Ê¹ÓÃÃüÁî´ÓÐÂÆô¶¯xinetd

#killall -USR1 xinetd



¡¡¡¡£¨4£©½¨Á¢/etc/pam.d/telnet Îļþ£¬ÄÚÈÝÈçÏ£º

#%PAM-1.0

auth required /lib/security/pam_listfile.so item=user \

sense=deny file=/etc/ftpusers onerr=succeed

auth required /lib/security/pam_stack.so service=srp-ftp

auth required /lib/security/pam_shells.so

account required /lib/security/pam_stack.so service=srp-ftp

session required /lib/security/pam_stack.so service=srp-ftp

¡¡¡¡µ½´ËΪֹÏÖÔھͽ¨Á¢ÁËÒ»¸öʹÓÃSRP·þÎñµÄFTP·þÎñÆ÷¡£Ê×ÏÈÔÚ±¾µØ½øÐÐÊÔÑé¡£ÏÂÃæÊÇÒ»¸öµäÐͻỰ£º

$$ /usr/local/bin/ftp localhost

Connected to localhost.intevo.com.

220 k2.intevo.com FTP server (SRPftp 1.3) ready.

SRP accepted as authentication type.

Name (localhost:kabir): cao

SRP Password: xxxxxxxx

SRP authentication succeeded.

Using cipher CAST5_CBC and hash function SHA.

200 Protection level set to Private.

232 user kabir authorized by SRP.

230 User kabir logged in.

Remote system type is UNIX.

Using binary mode to transfer file


¡¡¡¡Èç¹ûÏ£ÍûÔÚÆäËûLinux¼ÆËã»úʹÓÃFTPµÇ¼µ½SRP·þÎñÆ÷£¬ÐèÒª°²×°SRP·þÎñÖ§³ÖºÍSRP¿Í»§»úÈí¼þ¡£·½·¨ÊǺÍÔÚSRP·þÎñÆ÷¶ËÏàͬµÄ¡£
¡¡¡¡Ê¹ÓÃSRPµÄFTP·þÎñÖзdz£ºÃÏÂÃæµÄÃÜÂ빫ʽ£º

NONE (1)

BLOWFISH_ECB (2)

BLOWFISH_CBC (3)

BLOWFISH_CFB64 (4)

BLOWFISH_OFB64 (5)

CAST5_ECB (6)

CAST5_CBC (7)

CAST5_CFB64 (8)

CAST5_OFB64 (9)

DES_ECB (10)

DES_CBC (11)

DES_CFB64 (12)

DES_OFB64 (13)

DES3_ECB (14)

DES3_CBC (15)

DES3_CFB64 (16)

DES3_OFB64 (17)



¡¡¡¡SRPÒ²Ö§³ÖMD5ºÍSHA¹þÏ£º¯Êý¡£È±Ê¡Çé¿öÏÂSRPʹÓÃCAST5_CBC ÃÜÂëºÍSHA º¯Êý¡£ÒªÊ¹ÓÃÆäËü¸ñʽµÄÃÜÂë¡£¿ÉÒÔʹÓã­c»ò£­hÑ¡Ïî¡£

#/usr/local/bin/ftp -c blowfish_cfb64 ¡°ipµØÖ·¡±



¡¡¡¡ÉÏÃæµÄÃüÁîʹÓÃBLOWFISH_CFB64 ÃÜÂë¶ø²»ÊÇȱʡµÄCAST5_CBC¡£

#/usr/local/bin/ftp -h md5 ¡°ipµØÖ·¡±



¡¡¡¡ÉÏÃæµÄÃüÁîʹÓÃMD5º¯Êý¶ø²»ÊÇȱʡµÄSHAº¯Êý¡£

¡¡¡¡Îå¡¢ÔÚ·ÇLinuxƽ̨ÉÏʹÓÃSRP¿Í»§»ú

¡¡¡¡SRPͬÑùÖ§³ÖÆäËûÁ÷ÐеIJÙ×÷ϵͳ£¨Unix¡¢BSD¡¢Winodws¡¢MacOS£©¡£Kermit 95ÊÇÒ»¸ö¹¤×÷ÔÚWindows 9x, ME, NT, and 2000, XPºÍ OS/2²Ù×÷ϵͳϵÄSRP¿Í»§»ú¡£ÏêϸÇé¿öǰ²é¿´Ïà¹ØÍøÖ·£ºhttp://www.columbia.edu/kermit/k95.html ¡£

¡¡¡¡×ܽ᣺ÏêϸµÄSRP¹¤×÷Ô­Àí¿ÉÒÔÔÚSRPµÄÓйØÕ¾µã·¢ÏÖ¡£µØÖ·ÊÇhttp://srp.stanford.edu/srp£¬ÔÚÕâÀïÄã¿ÉÒԵõ½ÓйØÐ­ÒéµÄÔÚÏß˵Ã÷http://srp.standford.edu/srp/design.html»òÕßÊÇÒ»¸ö³ö°æµÄ¹ØÓÚSRPµÄ¼¼Êõ°×ƤÊéhttp://srp.standford.edu/srp/ftp¡£ ÒÔÉÏÌṩÁËÏà¶ÔOPENSSH¸ü¼Ó°²È«¿ì½ÝµÄFTPµÇ¼Զ³ÌLinux·þÎñÆ÷µÄ·½·¨£¬»ùÓÚSRP·þÎñ FTPÓ¦ÓÃÓëÆäËûÍøÂçÓ¦ÓÃÒ»ÑùÊôÓÚ¿Í»§»ú/·þÎñÆ÷Ä£ÐÍ£¬Ò»µ©Á¬Í¨ºó£¬¿Í»§»ú¿ÉÒÔÏíÓзþÎñÆ÷ËùÌṩµÄÒ»ÇзþÎñ¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ