Sun Java System Identity Synchronization for Windows 1 2004Q3 ¼³Ä¡ ¹× ±¸¼º ¼³¸í¼ |
9Àå
¹®Á¦ÇØ°áÀÌ Àå¿¡¼´Â Identity Synchronization for Windows¸¦ »ç¿ëÇÏ´Â µ¿¾È ¹ß»ýÇÒ ¼ö ÀÖ´Â ¹®Á¦¸¦ ÇØ°áÇÏ´Â µ¥ µµ¿òÀÌ µÇ´Â ³»¿ëÀ» Á¦°øÇÕ´Ï´Ù. ´ÙÀ½°ú °°Àº ³»¿ëÀ¸·Î ±¸¼ºµË´Ï´Ù.
¹®Á¦ÇØ°á Á¡°Ë ¸ñ·Ï
Âü°í
°ü¸®ÀÚ: ¹®Á¦¸¦ µð¹ö±ëÇÒ ¶§ ·Î±ë ¼öÁØ("·Î±× ÆÄÀÏ ±¸¼º" ÆäÀÌÁö 269¿¡¼ ¼³¸í)À» Á¶Á¤ÇÏ¿© ·Î±×¿¡ ¹®Á¦ÀÇ ¿øÀÎÀÌ µÉ ¼ö ÀÖ´Â ¸ðµç À̺¥Æ®°¡ ¹Ý¿µµÇµµ·Ï ÇÕ´Ï´Ù.
·Î±× ¼öÁØÀ» FINE ÀÌ»óÀ¸·Î Á¶Á¤ÇÏÁö ¾ÊÀ¸¸é ÀϺΠÀ̺¥Æ®(»ç¿ëÀÚ°¡ SUL¿¡ Æ÷ÇÔµÇÁö ¾Ê¾Æ »ç¿ëÀÚ º¯°æ ³»¿ëÀ» µ¿±âÈ ÇÒ ¼ö ¾ø´Â µî)´Â ·Î±× ÆÄÀÏ¿¡ Æ÷ÇÔµÇÁö ¾Ê½À´Ï´Ù. ¸ðµç idsync resync ÀÛ¾÷ µ¿¾È ·Î±× ¼öÁØÀº INFO·Î À¯ÁöµÇ¾î¾ß ÇÕ´Ï´Ù.
Identity Synchronization for Windows¸¦ ¼³Ä¡ ¹× ±¸¼ºÇÏ´Â µ¿¾È idsync printstat ¸í·ÉÀ» À¯¿ëÇÑ µµ±¸·Î »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. printstat("printstat »ç¿ë" ÆäÀÌÁö 314 ÂüÁ¶)¸¦ ½ÇÇàÇÏ¸é ¼³Ä¡ ¹× ±¸¼º °úÁ¤À» ¿Ï·áÇϱâ À§ÇÏ¿© ¼öÇàÇØ¾ß ÇÏ´Â ³ª¸ÓÁö ´Ü°è ¸ñ·ÏÀÌ Ç¥½ÃµË´Ï´Ù.
- Áß¾Ó error.log¿¡ º¸°íµÈ ¹®Á¦°¡ ÀÖ½À´Ï±î?
isw-<hostname>/logs/central/error.log
Áß¾Ó ¿À·ù ·Î±× ÆÄÀÏ¿¡ °ÅÀÇ ¸ðµç ¿À·ù°¡ º¸°íµË´Ï´Ù. ¶ÇÇÑ ¿À·ù¿¡ ´ëÇÑ Ãß°¡ Á¤º¸´Â º¸Åë audit.log ÆÄÀÏ¿¡ ÀÖ½À´Ï´Ù. °ü·Ã ·Î±× Ç׸ñÀÇ »óÈ£ °ü°è¸¦ ½±°Ô Çϱâ À§ÇÏ¿© audit.log ÆÄÀÏ¿¡ ¶ÇÇÑ ¿À·ù ·Î±×ÀÇ ¸ðµç Ç׸ñÀÌ Æ÷ÇԵ˴ϴÙ.
- ¸±¸®½º ³ëÆ®¿¡ ¸¹Àº ¾Ë·ÁÁø ¹®Á¦°¡ ÀÖ½À´Ï´Ù. ¿©±â¿¡ ¹®Á¦°¡ ¼³¸íµÇ¾î ÀÖ½À´Ï±î?
- ¼³Ä¡°¡ ÃʱâÈµÈ ÄÄÇ»ÅÍ¿¡ ¼öÇàµÇ¾ú½À´Ï±î? ÀÌÀü ±¸¼ºÀÇ Á¦°Å°¡ ¿Ï·áµÇÁö ¾ÊÀº »óÅ¿¡¼ Á¦Ç°À» ´Ù½Ã ¼³Ä¡ÇÒ ¶§ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌÀü ¼³Ä¡¸¦ ¿ÏÀüÈ÷ Á¦°ÅÇÏ´Â ¹æ¹ýÀº Á¦ 8Àå, "¼ÒÇÁÆ®¿þ¾î Á¦°Å"¸¦ ÂüÁ¶ÇϽʽÿÀ.
- Äھ ÀûÀýÈ÷ ¼³Ä¡µÇ¾ú½À´Ï±î? ÄÚ¾î ¼³Ä¡°¡ ¼º°øÀûÀ¸·Î ¿Ï·áµÇ¸é isw-<hostname>/logs/central/ µð·ºÅ丮¿¡ ·Î±× ÆÄÀÏÀÌ ¸¸µé¾îÁý´Ï´Ù.
- ÀÚ¿ø ±¸¼º µ¿¾È Directory Server°¡ ½ÇÇàµÇ¾ú½À´Ï±î?
- Message Queue¿Í ½Ã½ºÅÛ °ü¸®ÀÚ¸¦ Æ÷ÇÔÇÏ¿© Äھ ÇöÀç ½ÇÇà ÁßÀԴϱî? WindowsÀÇ °æ¿ì ÀûÀýÇÑ ¼ºñ½º À̸§À» È®ÀÎÇÕ´Ï´Ù. SolarisÀÇ °æ¿ì ÀûÀýÇÑ µ¥¸ó À̸§À» È®ÀÎÇÕ´Ï´Ù. idsync printstat ¸í·ÉÀ» »ç¿ëÇÏ¿© Message Queue¿Í ½Ã½ºÅÛ °ü¸®ÀÚ°¡ ÀÛµ¿ ÁßÀÎÁö È®ÀÎÇÕ´Ï´Ù.
- ±¸¼ºÀÌ ¼º°øÀûÀ¸·Î ÀúÀåµÇ¾ú½À´Ï±î? idsync printstat ¸í·É¿¡¼ Ä¿³ØÅÍ ¸ñ·ÏÀÌ ¸¸µé¾îÁö¸é ±¸¼ºÀÌ ¼º°øÀûÀ¸·Î ÀúÀåµÈ °ÍÀÔ´Ï´Ù.
- Ä¿³ØÅÍ°¡ ¸ðµÎ ¼³Ä¡µÇ¾ú½À´Ï±î? µ¿±âȵǴ °¢ µð·ºÅ丮 ¼Ò½º¸¶´Ù ÇϳªÀÇ Ä¿³ØÅÍ°¡ ¹Ýµå½Ã ¼³Ä¡µÇ¾î¾ß ÇÕ´Ï´Ù.
- ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¸ðµÎ ¼³Ä¡µÇ¾ú½À´Ï±î? Ä¿³ØÅÍ°¡ ¼³Ä¡µÈ ÈÄ Directory Server¿Í Windows NT Ä¿³ØÅÍ¿¡ ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¼³Ä¡µÇ¾î¾ß ÇÕ´Ï´Ù. Directory Server Ç÷¯±×ÀÎÀº ¹Ýµå½Ã °¢ Directory Server º¹Á¦º»¿¡ ¼³Ä¡µÇ¾î¾ß ÇÕ´Ï´Ù.
- ¼³Ä¡ ÈÄ ÀýÂ÷¸¦ ¼öÇàÇß½À´Ï±î? Directory Server Ç÷¯±×ÀÎÀ» ¼³Ä¡ÇÑ ÈÄ ¹Ýµå½Ã Directory Server¸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. Windows NT ÇÏÀ§ ±¸¼º¿ä¼Ò¸¦ ¼³Ä¡ÇÑ ÈÄ ¹Ýµå½Ã Windows ±âº» µµ¸ÞÀÎ Á¦¾î±â¸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
- ÄܼÖÀ̳ª ¸í·ÉÁÙ¿¡¼ µ¿±âÈ°¡ ½ÃÀ۵Ǿú½À´Ï±î?
- ¸ðµç Ä¿³ØÅÍ°¡ ÇöÀç ½ÇÇà ÁßÀԴϱî?
- ÄÜ¼Ö ¶Ç´Â idsync printstat¸¦ »ç¿ëÇÏ¿© ¸ðµç Ä¿³ØÅÍÀÇ »óÅ°¡ SYNCINGÀÎÁö È®ÀÎÇÕ´Ï´Ù.
- µ¿±âȵǴ µð·ºÅ丮 ¼Ò½º°¡ ÇöÀç ½ÇÇà ÁßÀԴϱî?
- ÄܼÖÀ» »ç¿ëÇÏ¿© ¼öÁ¤ ¹× ÀÛ¼º ³»¿ëÀÌ ¿¹ÃøÇÑ ¹æÇâÀ¸·Î µ¿±âȵǴÂÁö È®ÀÎÇÕ´Ï´Ù.
- ¿ÀÁ÷ ÇϳªÀÇ µð·ºÅ丮 ¼Ò½º¿¡¸¸ Á¸ÀçÇÏ´Â »ç¿ëÀÚ¸¦ µ¿±âÈÇÏ´Â °æ¿ì idsync resync ¸í·ÉÀ» »ç¿ëÇÏ¿© ´Ù¸¥ µð·ºÅ丮 ¼Ò½º¿¡¼ ÇØ´ç »ç¿ëÀÚ°¡ ¸¸µé¾îÁ³½À´Ï±î?
- µÎ µð·ºÅ丮 ¼Ò½º ¸ðµÎ¿¡ ÀÖ´Â »ç¿ëÀÚ¸¦ µ¿±âÈÇÏ´Â °æ¿ì idsync resync ¸í·ÉÀ» »ç¿ëÇÏ¿© ÇØ´ç »ç¿ëÀÚ¸¦ ¿¬°áÇß½À´Ï±î?
- Active Directory ¶Ç´Â Windows NT¿¡¼ Sun Java System Directory Server·Î »ç¿ëÀÚ¸¦ ¸¸µé ¼ö ¾ø´Â °æ¿ì Directory Server objectclassÀÇ ¸ðµç Çʼö ¼Ó¼ºÀÌ »ý¼º ¼Ó¼ºÀ¸·Î ÁöÁ¤µÇ¾úÀ¸¸ç ¿ø·¡ »ç¿ëÀÚ Ç׸ñ¿¡ ÇØ´ç ¼Ó¼ºÀÇ °ªÀÌ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
- µ¿±âÈ°¡ Directory Server¿¡¼ Windows NT·Î ÀÛ¼ºÇÏ¸ç »ç¿ëÀÚ°¡ ¸¸µé¾îÁ³À¸³ª °èÁ¤À» »ç¿ëÇÒ ¼ö ¾ø´Â °æ¿ì, »ç¿ëÀÚ À̸§ÀÌ Windows NT ¿ä±¸ »çÇ×À» À§¹ÝÇÏÁö ¾Ê´ÂÁö È®ÀÎÇϽʽÿÀ.
¿¹¸¦ µé¾î Windows NT¿¡¼ Çã¿ëÇÏ´Â ÃÖ´ë ±æÀ̺¸´Ù ±ä »ç¿ëÀÚ À̸§À» ÁöÁ¤ÇÏ´Â °æ¿ì NT¿¡ »ç¿ëÀÚ°¡ ¸¸µé¾îÁöÁö¸¸ À̸§À» º¯°æ(»ç¿ëÀÚ > À̸§ º¯°æ)ÇÒ ¶§±îÁö ÀÌ »ç¿ëÀÚ¸¦ »ç¿ëÇϰųª ÆíÁýÇÒ ¼ö ¾ø½À´Ï´Ù.
- Windows NT SAM º¯°æ °¨Áö±â ÇÏÀ§ ±¸¼º¿ä¼Ò¸¦ »ç¿ëÇÏ·Á¸é ¹Ýµå½Ã NT °¨»ç ·Î±×¸¦ ÀÛµ¿ÇØ¾ß ÇÕ´Ï´Ù. ½ÃÀÛ > ÇÁ·Î±×·¥ > °ü¸® µµ±¸ > »ç¿ëÀÚ °ü¸®ÀÚ¸¦ ¼±ÅÃÇÑ ÈÄ Á¤Ã¥ > °¨»ç Á¤Ã¥À» ¼±ÅÃÇÕ´Ï´Ù.
ÀÌ À̺¥Æ® °¨»ç¸¦ ¼±ÅÃÇÏ°í »ç¿ëÀÚ ¹× ±×·ì °ü¸®¿ë ¼º°ø ¹× ½ÇÆÐ ¼±ÅöõÀ» ¸ðµÎ ¼±ÅÃÇÕ´Ï´Ù.À̺¥Æ® ºä¾î > Event Log Wrapping¿¡¼ Event Log Settings¸¦ ¼±ÅÃÇÑ ÈÄ Overwrite Events as Needed¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- µ¿±âÈ¿¡ ½ÇÆÐÇÑ »ç¿ëÀÚ°¡ Synchronization User List¿¡ ÀÖ½À´Ï±î? ¿¹¸¦ µé¾î µ¿±âÈ »ç¿ëÀÚ ¸ñ·ÏÀÇ ±âº» DN°ú ÇÊÅÍ°¡ ÀÏÄ¡Çմϱî? Active Directory°¡ Æ÷ÇÔµÈ ±¸Çö¿¡¼ Sun Java System Directory Server Ç׸ñÀÌ »ç¿ëÀÚ µ¿±âÈ ¸ñ·Ï¿¡ ¾øÀ¸¸é ¿äû½Ã ºñ¹Ð¹øÈ£ µ¿±âÈ°¡ ¾Æ¹«·± Ç¥½Ã ¾øÀÌ ½ÇÆÐÇÕ´Ï´Ù. ÀÌ´Â ´ëºÎºÐ Synchronization User List°¡ À߸øµÇ¾ú±â ¶§¹®¿¡ ¹ß»ýÇÕ´Ï´Ù.
- µ¿±âÈ ¼³Á¤ÀÌ º¯°æµÇ¾ú½À´Ï±î? µ¿±âÈ ¼³Á¤ÀÌ Active Directory¿¡¼ Sun Java System µð·ºÅ丮 ¼¹ö·Î »ç¿ëÀÚ¸¦ µ¿±âȽÃÅ°´Â °Í¿¡¼ µð·ºÅ丮 ¼¹ö¿¡¼ Active Directory·Î »ç¿ëÀÚ¸¦ µ¿±âȽÃÅ°´Â °ÍÀ¸·Î¸¸ º¯°æµÈ °æ¿ì Active Directory SSL CA ÀÎÁõ¼°¡ ¹Ýµå½Ã Ä¿³ØÅÍÀÇ µ¥ÀÌÅͺ£À̽º¿¡ Ãß°¡µÇ¾î¾ß ÇÕ´Ï´Ù. idsync certinfo ¸í·ÉÀº ÇöÀç SSL ¼³Á¤¿¡ µû¶ó ¼³Ä¡µÇ¾î¾ß ÇÏ´Â SSL ÀÎÁõ¼¸¦ º¸°íÇÕ´Ï´Ù.
- ¸ðµç È£½ºÆ® À̸§ÀÌ ÀûÀýÈ÷ ÁöÁ¤µÇ¾úÀ¸¸ç DNS¿¡¼ º¯È¯ÇÒ ¼ö ÀÖ½À´Ï±î? Active Directory µµ¸ÞÀÎ Á¦¾î±â´Â Active Directory Ä¿³ØÅÍ°¡ ½ÇÇàµÇ´Â ÄÄÇ»ÅÍ¿Í Sun Java System Directory Server Ç÷¯±×ÀÎÀÌ ½ÇÇàµÇ´Â ÄÄÇ»ÅÍ¿¡¼ DNS º¯È¯ÇÒ ¼ö ÀÖ¾î¾ß ÇÕ´Ï´Ù.
- Active Directory µµ¸ÞÀÎ Á¦¾î±âÀÇ IP ÁÖ¼Ò°¡ Ä¿³ØÅÍ°¡ ÀÌ Á¦¾î±â¿¡ ¿¬°áÇÏ´Â µ¥ »ç¿ëÇÏ´Â µ¿ÀÏÇÑ À̸§À¸·Î º¯È¯µË´Ï±î?
- ¼Ò½º Ä¿³ØÅÍ°¡ »ç¿ëÀÚ¿¡ ´ëÇÑ º¯°æ ³»¿ëÀ» ã½À´Ï±î? Áß¾Ó audit.log¸¦ »ç¿ëÇÏ¿© »ç¿ëÀÚ°¡ Ãß°¡ ¶Ç´Â ¼öÁ¤µÇ´Â µð·ºÅ丮 ¼Ò½º¿ë Ä¿³ØÅÍ°¡ ¼öÁ¤ ³»¿ëÀ» ã´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- ´ë»ó Ä¿³ØÅÍ°¡ ÀÌ ¼öÁ¤ ³»¿ëÀ» ó¸®Çմϱî?
- º¹¼ö Synchronization User List°¡ ±¸¼ºµÇ¾ú½À´Ï±î? ±¸¼ºµÈ °æ¿ì Ãæµ¹ÀÌ ÀÖ½À´Ï±î? ´õ¿í ±¸Ã¼ÀûÀÎ Synchronization User List°¡ ´ú ±¸Ã¼ÀûÀÎ Synchronization User Listº¸´Ù ¸ÕÀú ÄܼÖÀ» »ç¿ëÇϵµ·Ï ¼ø¼¸¦ Á¤ÇØ¾ß ÇÕ´Ï´Ù.
- È帧ÀÌ ¾ç¹æÇ⠶Ǵ Sun¿¡¼ Windows·Î ¼³Á¤µÇ¾úÀ¸¸ç ±¸Çö¿¡ Active Directory µ¥ÀÌÅÍ ¼Ò½º°¡ ÀÖ´Â °æ¿ì Ä¿³ØÅÍ°¡ SSL Åë½ÅÀ» »ç¿ëÇϵµ·Ï ±¸¼ºµÇ¾ú½À´Ï±î?
- Solaris ȯ°æ¿¡¼ ¸Þ¸ð¸® ¹®Á¦°¡ ÀǽɵǴ °æ¿ì ÇÁ·Î¼¼½º¸¦ È®ÀÎÇÕ´Ï´Ù. ´Ù¸¥ ÇÁ·Î¼¼½º·Î ½ÇÇàµÇ´Â ±¸¼º¿ä¼Ò¸¦ º¸·Á¸é ´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.
/usr/ucb/ps -gauxwww | grep com.sun.directory.wps
Ãâ·Â¿¡ Ä¿³ØÅÍÀÇ ID, ½Ã½ºÅÛ °ü¸®ÀÚ ¹× Áß¾Ó ±â·Ï±â¸¦ Æ÷ÇÔÇÏ¿© ÀÚ¼¼ÇÑ ³»¿ëÀÌ ¸ðµÎ Á¦°øµË´Ï´Ù. ÀÌ´Â °úµµÇÑ ¸Þ¸ð¸®¸¦ ¼Ò¸ðÇÏ´Â ÇÁ·Î¼¼½º°¡ ÀÖ´Â °æ¿ì À¯¿ëÇÕ´Ï´Ù.
- Sun Java System µð·ºÅ丮 ¼Ò½º¸¦ ¸¸µé°Å³ª ÆíÁýÇÏ°í Directory Server¿¡ Choose a known server µå·Ó´Ù¿î ¸ñ·ÏÀÌ Ç¥½ÃµÇÁö ¾Ê´Â °æ¿ì Directory Server°¡ ½ÇÇàµÇ´ÂÁö È®ÀÎÇϽʽÿÀ. Directory Server°¡ »ç¿ë °¡´ÉÇÑ È£½ºÆ®ÀÇ µå·Ó´Ù¿î ¸ñ·Ï¿¡ Ç¥½ÃµÇ·Á¸é ¹Ýµå½Ã ½ÇÇà ÁßÀ̾î¾ß ÇÕ´Ï´Ù.
¹®Á¦ÀÇ ¼¹ö°¡ ÀϽÃÀûÀ¸·Î Á¤ÁöµÈ °æ¿ì Specify a serverÀÇ È£½ºÆ® À̸§°ú Æ÷Æ® Çʵ忡 È£½ºÆ®¿Í Æ÷Æ®¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
- Á¦°Å ÇÁ·Î±×·¥À» ½ÇÇàÇÒ ¶§ ´ÙÀ½ ¿À·ù°¡ Ç¥½ÃµË´Ï±î?
./runInstaller.sh
IOException while making /tmp/SolarisNativeToolkit_5.5.1_1 executable:java.io.IOException: Not enough space
java.io.IOException: Not enough space
/tmp¿¡ ÀÖ´Â ½º¿Ò ÆÄÀÏÀÇ Å©±â¸¦ ´ÃÀÔ´Ï´Ù.
Ä¿³ØÅÍ ¹®Á¦ ÇØ°áÀÌ ºÎºÐÀÇ ³»¿ëÀ» »ç¿ëÇÏ¿© Ä¿³ØÅÍ ¹®Á¦¸¦ ÇØ°áÇϽʽÿÀ. ´ÙÀ½°ú °°Àº ³»¿ëÀ¸·Î ±¸¼ºµË´Ï´Ù.
µð·ºÅ丮 ¼Ò½º¸¦ °ü¸®ÇÏ´Â Ä¿³ØÅÍÀÇ ID¸¦ È®ÀÎÇÏ´Â ¹æ¹ý
´ÙÀ½ ¹æ¹ý Áß ÇÑ °¡Áö¸¦ »ç¿ëÇÏ¿© Ä¿³ØÅÍ ID¸¦ È®ÀÎÇÕ´Ï´Ù.
Áß¾Ó ·Î±× »ç¿ë
Áß¾Ó audit.log¿¡¼ µ¿±âȵǴ µð·ºÅ丮 ¼Ò½ºÀÇ Ä¿³ØÅÍ ID¸¦ È®ÀÎÇÕ´Ï´Ù. ½ÃÀ۽ÿ¡ Áß¾Ó ±â·Ï±â´Â °¢ Ä¿³ØÅÍÀÇ ID¿Í Ä¿³ØÅÍ°¡ °ü¸®ÇÏ´Â µð·ºÅ丮 ¼Ò½º¸¦ ±â·ÏÇÕ´Ï´Ù. °¡Àå ÃÖ±Ù Á¤º¸´Â ½ÃÀÛ ¹è³ÊÀÇ ¸¶Áö¸· ÀνºÅϽº¸¦ È®ÀÎÇÕ´Ï´Ù.
¿¹¸¦ µé¾î ´ÙÀ½ ·Î±× ¸Þ½ÃÁö¿¡´Â µÎ °³ÀÇ Ä¿³ØÅÍ°¡ ÀÖ½À´Ï´Ù.
- CNN101 is a Sun Directory Connector that manages dc=airius,dc=com
- CNN100 is an Active Directory Connector that manages the airius.com domain
idsync printstat »ç¿ë
idsync printstat ¸í·É¿¡¼ ¶ÇÇÑ Ä¿³ØÅÍ ID¿Í »óŸ¦ ¾Ë ¼ö ÀÖ½À´Ï´Ù("printstat »ç¿ë" ÆäÀÌÁö 314 ÂüÁ¶).
ÀÌ ¸í·ÉÀÇ Ãâ·Â ¿¹´Â ´ÙÀ½°ú °°½À´Ï´Ù.
Connector ID: CNN100
Type: Active Directory
Manages: airius.com (ldaps://host2.airius.com:636)
State: READYConnector ID: CNN101
Type: Sun Java System Directory
Manages: dc=airius,dc=com (ldap://host1.airius.com:389)
State: READYSun Java System Message Queue Status: Started
Sun Java System Message Queue¸¦ ÅëÇÏ¿© System Manager È®ÀÎ.
System Manager Status: Started
SUCCESS
Ä¿³ØÅÍÀÇ ÇöÀç »óÅ ȮÀÎ ¹æ¹ý
ÄܼÖÀÇ Status â, idsync printstat ¸í·É(¾ÕÀÇ ¼³¸í ÂüÁ¶) ¶Ç´Â Áß¾Ó audit.log¸¦ »ç¿ëÇÏ¿© µ¿±âÈ¿¡ ¿¬°üµÈ Ä¿³ØÅÍÀÇ ÇöÀç »óŸ¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
audit.logÀÇ ¸¶Áö¸· ¸Þ½ÃÁö¿¡¼ Ä¿³ØÅÍ »óÅ¿¡ ´ëÇÑ º¸°í¸¦ ã½À´Ï´Ù.
¿¹¸¦ µé¾î ´ÙÀ½ ·Î±× ¸Þ½ÃÁö¿¡¼ Ä¿³ØÅÍ CNN101ÀÇ »óÅ´ READYÀÔ´Ï´Ù.
[2003/03/19 10:20:16.889 -0600] INFO 13 SysMgr_100 host1 "Connector [CNN101] is now in state "READY"."
¿¡¼´Â ´Ù¾çÇÑ Ä¿³ØÅÍ »óŸ¦ ¼³¸íÇÕ´Ï´Ù.
Ç¥ 9-1) Ä¿³ØÅÍ »óÅ ¼³¸í
»óÅÂ
ÀǹÌ
UNINSTALLED
Ä¿³ØÅÍ°¡ ¼³Ä¡µÇÁö ¾Ê¾Ò½À´Ï´Ù.
INSTALLED
Ä¿³ØÅÍ°¡ ¼³Ä¡µÇ¾úÀ¸³ª ±¸¼ºÀ» ¼ö½ÅÇÏÁö ¾Ê¾Ò½À´Ï´Ù.
READY
Ä¿³ØÅÍ°¡ ¼³Ä¡µÇ¾úÀ¸¸ç ±¸¼ºÀ» ¼ö½ÅÇßÀ¸³ª µ¿±âȸ¦ ½ÃÀÛÇÏÁö ¾Ê¾Ò½À´Ï´Ù.
SYNCING
Ä¿³ØÅÍ°¡ ¼³Ä¡µÇ°í ±¸¼ºÀ» ¼ö½ÅÇßÀ¸¸ç µ¿±âȸ¦ ½ÃÀÛÇÏ·Á ÇÕ´Ï´Ù.
Ä¿³ØÅÍÀÇ »óÅ°¡ UNINSTALLEDÀÎ °æ¿ìÀÇ ÀÛ¾÷
Ä¿³ØÅ͸¦ ¼³Ä¡ÇÕ´Ï´Ù.
Ä¿³ØÅÍ ¼³Ä¡°¡ ½ÇÆÐÇßÀ¸³ª ´Ù½Ã ¼³Ä¡ÇÒ ¼ö ¾ø´Â °æ¿ìÀÇ ÀÛ¾÷
Ä¿³ØÅÍ »óÅ°¡ ½ÇÆÐÇßÀ¸³ª Identity Synchronization for Windows ¼³Ä¡ ÇÁ·Î±×·¥Àº Ä¿³ØÅÍ°¡ ¼³Ä¡µÈ °ÍÀ¸·Î °£ÁÖÇÏ´Â °æ¿ì ¼³Ä¡ ÇÁ·Î±×·¥À¸·Î ÇØ´ç Ä¿³ØÅ͸¦ ´Ù½Ã ¼³Ä¡ÇÒ ¼ö ¾ø½À´Ï´Ù.
idsync resetconnÀ» ½ÇÇàÇÏ¿©("resetconn »ç¿ë" ÆäÀÌÁö 315¿¡¼ ¼³¸í) Ä¿³ØÅÍÀÇ »óŸ¦ UNINSTALLED·Î Àç¼³Á¤ÇÑ ÈÄ Ä¿³ØÅ͸¦ ´Ù½Ã ¼³Ä¡ÇÕ´Ï´Ù.
Ä¿³ØÅÍÀÇ »óÅ°¡ INSTALLEDÀÎ °æ¿ìÀÇ ÀÛ¾÷
¿À·§µ¿¾È Ä¿³ØÅÍÀÇ »óÅ°¡ ¼³Ä¡µÈ »óÅ·ΠÀ¯ÁöµÇ´Â °æ¿ì ´ëºÎºÐ ½ÇÇàµÇÁö ¾Ê°Å³ª Message Queue¿Í Åë½ÅÇÒ ¼ö ¾ø°Ô µË´Ï´Ù.
Ä¿³ØÅÍ°¡ ¼³Ä¡µÈ ÄÄÇ»ÅÍ¿¡¼ Ä¿³ØÅÍÀÇ ·Î±×(audit.log ¹× error.log)¿¡¼ ÀáÀçÀû ¿À·ù¸¦ È®ÀÎÇÕ´Ï´Ù. Ä¿³ØÅÍ°¡ Message Queue¿¡ ¿¬°áµÇÁö ¾Ê´Â °æ¿ì ¿©±â¿¡ ¿À·ù°¡ º¸°íµË´Ï´Ù. ÀÌ °æ¿ì °¡´ÉÇÑ ¿øÀÎÀº Message Queue ¹®Á¦ ÇØ°áÀ» ÂüÁ¶ÇϽʽÿÀ.
°¨»ç ·Î±×ÀÇ °¡Àå ÃֽŠ¸Þ½ÃÁö°¡ ¿À·¡µÈ °æ¿ì Ä¿³ØÅÍ°¡ ½ÇÇàµÇÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ±¸¼º¿ä¼Ò ¹®Á¦ÇØ°á ÂüÁ¶.
Ä¿³ØÅÍÀÇ »óÅ°¡ READYÀÎ °æ¿ìÀÇ ÀÛ¾÷
µ¿±âÈ°¡ ½ÃÀ۵ǰí ÇØ´ç ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¼³Ä¡µÇ¾úÀ¸¸ç Ä¿³ØÅÍ·Î ¿¬°áµÉ ¶§±îÁö Ä¿³ØÅÍÀÇ »óÅ´ READY·Î À¯ÁöµË´Ï´Ù. µ¿±âÈ°¡ ½ÃÀÛµÇÁö ¾Ê¾ÒÀ¸¸é ÄܼÖÀ̳ª ¸í·ÉÁÙ À¯Æ¿¸®Æ¼¸¦ »ç¿ëÇÏ¿© ½ÃÀÛÇÕ´Ï´Ù.
µ¿±âÈ°¡ ½ÃÀ۵ǾúÀ¸³ª Ä¿³ØÅÍÀÇ »óÅ°¡ SYNCING·Î º¯°æµÇÁö ¾Ê´Â °æ¿ì ÇÏÀ§ ±¸¼º¿ä¼Ò¿¡ ¹®Á¦°¡ ÀÖÀ» °¡´É¼ºÀÌ ³ô½À´Ï´Ù. ÇÏÀ§ ±¸¼º¿ä¼Ò ¹®Á¦ ÇØ°á ÂüÁ¶.
Ä¿³ØÅÍÀÇ »óÅ°¡ SYNCINGÀÎ °æ¿ìÀÇ ÀÛ¾÷
Ä¿³ØÅÍÀÇ »óÅ°¡ SYNCINGÀÌÁö¸¸ ¼öÁ¤ ³»¿ëÀÌ µ¿±âȵÇÁö ¾Ê´Â °æ¿ì µ¿±âÈ ¼³Á¤ÀÌ ¿Ã¹Ù¸¥Áö È®ÀÎÇÕ´Ï´Ù.
- ÄܼÖÀ» »ç¿ëÇÏ¿© ¼öÁ¤ ³»¿ë ¹× ÀÛ¼º ³»¿ëÀÌ ¿øÇÏ´Â ¹æÇâÀ¸·Î(Áï, Windows¿¡¼ Sun Java System Directory Server·Î) µ¿±âȵǴÂÁö È®ÀÎÇÕ´Ï´Ù.
- ÄܼÖÀ» »ç¿ëÇÏ¿© ¼öÁ¤µÇ´Â ¼Ó¼ºÀÌ µ¿±âÈµÈ ¼Ó¼ºÀÎÁö È®ÀÎÇÕ´Ï´Ù.(Âü°í: ºñ¹Ð¹øÈ£´Â Ç×»ó µ¿±âȵ˴ϴÙ.) ÀÛ¼ºµÈ »ç¿ëÀÚ Ç׸ñÀÌ µ¿±âȵÇÁö ¾Ê´Â °æ¿ì Äֿܼ¡¼ »ç¿ëÀÚ ÀÛ¼º È帧À» »ç¿ëÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- ¼Ò½º Ä¿³ØÅÍ°¡ »ç¿ëÀÚ¿¡ ´ëÇÑ º¯°æ ³»¿ëÀ» ã½À´Ï±î? Áß¾Ó audit.log¸¦ »ç¿ëÇÏ¿© »ç¿ëÀÚ°¡ Ãß°¡ ¶Ç´Â ¼öÁ¤µÇ´Â µð·ºÅ丮 ¼Ò½º¿ë Ä¿³ØÅÍ°¡ ¼öÁ¤ ³»¿ëÀ» ã´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ë»ó Ä¿³ØÅÍ°¡ ÀÌ ¼öÁ¤ ³»¿ëÀ» ó¸®Çմϱî?
Active Directory Ä¿³ØÅÍ°¡ SSLÀ» ÅëÇÏ¿© Active Directory¿¡ ¿¬°áÇÒ ¼ö ¾ø´Â °æ¿ìÀÇ ÀÛ¾÷
Active Directory Ä¿³ØÅÍ°¡ SSLÀ» ÅëÇÏ¿© Active Directory¿¡ ¿¬°áÇÒ ¼ö ¾øÀ¸¸ç ´ÙÀ½ ¿À·ù ¸Þ½ÃÁö°¡ Ç¥½ÃµÇ´Â °æ¿ì AD µµ¸ÞÀÎ Á¦¾î±â¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
Failed to open connection to ldaps://server.example.com:636, error(91): Cannot connect to the LDAP server, reason: SSL_ForceHandshake failed: (-5938) Encountered end of file.
±¸¼º¿ä¼Ò ¹®Á¦ÇØ°áÀÌ ºÎºÐÀÇ ³»¿ëÀ» »ç¿ëÇÏ¿© ±¸¼º¿ä¼Ò ¹®Á¦¸¦ ÇØ°áÇÕ´Ï´Ù. ´ÙÀ½°ú °°Àº ³»¿ëÀ¸·Î ±¸¼ºµË´Ï´Ù.
Solaris
/usr/ucb/ps -auxww | grep com.sun.directory.wps ¸í·ÉÀ» »ç¿ëÇÏ¿© ½ÇÇàµÇ´Â Identity Synchronization for Windows ÇÁ·Î¼¼½º¸¦ ¸ðµÎ ¸ñ·ÏÀ¸·Î ¸¸µì´Ï´Ù. ÀÌ Ç¥¿¡ ½ÇÇàµÇ¾î¾ß ÇÏ´Â ÇÁ·Î¼¼½º°¡ Ç¥½ÃµË´Ï´Ù.
Ç¥ 9-2) Identity Synchronization for Windows ÇÁ·Î¼¼½º
Java ÇÁ·Î¼¼½º Ŭ·¡½º À̸§
±¸¼º¿ä¼Ò
ÀÖ´Â °æ¿ì
com.sun.directory.wps.watchdog.server.WatchDog
½Ã½ºÅÛ ¿öÄ¡µ¶
Ç×»ó
com.sun.directory.wps.centrallogger.CentralLoggerManager
Áß¾Ó ±â·Ï±â
Äھ ¼³Ä¡µÈ À§Ä¡¸¸
com.sun.directory.wps.manager.SystemManager
½Ã½ºÅÛ °ü¸®ÀÚ
Äھ ¼³Ä¡µÈ À§Ä¡¸¸
com.sun.directory.wps.controller.AgentHarness
Ä¿³ØÅÍ
¼³Ä¡µÈ Ä¿³ØÅ͸¶´Ù ÇÑ °³
±â´ëÇÑ ¼öÀÇ ÇÁ·Î¼¼½º°¡ ½ÇÇàµÇÁö ¾Ê´Â °æ¿ì ´ÙÀ½ ¸í·ÉÀ¸·Î ¸ðµç Identity Synchronization for Windows ÇÁ·Î¼¼½º¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
¿öÄ¡µ¶ ÇÁ·Î¼¼½º°¡ ½ÇÇàµÇÁö¸¸ ±â´ëÇÑ ¼öÀÇ java.exe ÇÁ·Î¼¼½º°¡ ½ÇÇàµÇÁö ¾Ê´Â °æ¿ì "WatchList.properties °Ë»ç" ºÎºÐ¿¡¼ ¸ðµç ±¸¼º¿ä¼Ò°¡ ÀûÀýÈ÷ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
´Ù¸¥ ½Ã½ºÅÛ ±¸¼º¿ä¼Ò¿Í ¸¶Âù°¡Áö·Î Sun Java System Directory Server Ç÷¯±×ÀÎÀº Áß¾Ó ±â·Ï±â°¡ °ü¸®ÇÏ´Â ¹ö½º¸¦ ÅëÇÏ¿© ·Î±× ±â·ÏÀ» ¼Û½ÅÇÏ¿© »ç¿ëÀÚ°¡ º¼ ¼ö ÀÖµµ·Ï ÇÕ´Ï´Ù. ±×·¯³ª Ç÷¯±×Àο¡´Â ¹ö½º¸¦ ÅëÇÏ¿© Ç¥½ÃµÇÁö ¾Ê´Â ÀϺΠ¸Þ½ÃÁö°¡ ±â·ÏµË´Ï´Ù.(¿¹: ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ Ä¿³ØÅÍ¿¡ ¿¬°áÇÏÁö ¸øÇÑ ÀνºÅϽº) ÀÌ °æ¿ì ·Î±× ¸Þ½ÃÁö¿¡´Â ÆÄÀÏ ½Ã½ºÅÛ¿¡ ÀÖ´Â Ç÷¯±×ÀÎÀÇ logs µð·ºÅ丮¸¸ Ç¥½ÃµÇ¸ç, ´ÙÀ½°ú À¯»çÇÕ´Ï´Ù.
<serverroot>/isw-<hostname>/logs/SUBC<id>.
Ç÷¯±×ÀÎÀº Directory Server ÇÁ·Î¼¼½º¿Í ÇÔ²² ½ÇÇàµÇ¹Ç·Î Ç÷¯±×ÀÎÀÌ ÀÚüÀÇ logs µð·ºÅ丮¿¡ ±â·ÏÇÏ´Â ±â´É¿¡ ¹®Á¦°¡ ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÌ´Â Directory Server°¡ logs µð·ºÅ丮ÀÇ ¼ÒÀ¯ÀÚ°¡ ¾Æ´Ñ ´Ù¸¥ »ç¿ëÀÚ·Î ½ÇÇàµÇ´Â °æ¿ì ¹ß»ýÇÕ´Ï´Ù. ÀÌ °æ¿ì µð·ºÅ丮 ±ÇÇÑÀ» º¯°æÇϰųª ¿ø·¡ ¿î¿µ üÁ¦ ¸í·ÉÀ» »ç¿ëÇÏ´Â »ç¿ëÀÚ·Î º¯°æÇÏ¿© ¸í½ÃÀûÀ¸·Î Ç÷¯±×ÀÎ ±ÇÇÑÀ» ºÎ¿©ÇØ¾ß ÇÒ ¼ö ÀÖ½À´Ï´Ù.
Windows
¼ºñ½º Á¦¾îÆÇÀ» »ç¿ëÇÏ¿© "Sun Java SystemIdentity Synchronization for Windows" ¼ºñ½º°¡ ½ÃÀ۵Ǿú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ½ÃÀÛµÇÁö ¾Ê¾ÒÀ¸¸é Identity Synchronization for Windows°¡ ÄÄÇ»ÅÍ¿¡¼ ½ÇÇàµÇÁö ¾Ê´Â °ÍÀ̹ǷΠ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. ¼ºñ½º°¡ ½ÃÀ۵Ǹé ÀÛ¾÷ °ü¸®ÀÚ¸¦ »ç¿ëÇÏ¿© pswwatchdog.exe(Watchdog ÇÁ·Î¼¼½º)°¡ ½ÇÇàµÇÁö È®ÀÎÇÏ°í ¿¹»óµÈ ¼ýÀÚÀÇ java.exe ÇÁ·Î¼¼½º°¡ ½ÇÇàµÇ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
Âü°í
Directory Server ÄÜ¼Ö µî ´Ù¸¥ java ÇÁ·Î¼¼½º°¡ »ç¿ë ÁßÀÏ ¼ö ÀÖ½À´Ï´Ù. pswwatchdog.exe°¡ ½ÇÇàµÇÁö ¾Ê´Â °æ¿ì "Sun Java System Identity Synchronization for Windows" ¼ºñ½º¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù. pswwatchdog.exe°¡ ½ÇÇàµÇÁö¸¸ ±â´ëÇÑ ¼öÀÇ java.exe ÇÁ·Î¼¼½º°¡ ½ÇÇàµÇÁö ¾Ê´Â °æ¿ì WatchList.properties °Ë»ç¿¡¼ ¸ðµç ±¸¼º¿ä¼Ò°¡ ÀûÀýÈ÷ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
WatchList.properties °Ë»ç
Identity Synchronization for Windows ±¸¼º¿ä¼Ò°¡ ¼³Ä¡µÈ °¢ ÄÄÇ»ÅÍ¿¡¼ isw-<machine_name>/resources/WatchList.properties ÆÄÀÏÀÌ ÇØ´ç ÄÄÇ»ÅÍ¿¡¼ ½ÇÇàµÇ¾î¾ß ÇÏ´Â ±¸¼º¿ä¼Ò¸¦ ¿°ÅÇÕ´Ï´Ù. process.name[n] ±âº» ¼³Á¤ÀÌ ½ÇÇàµÇ¾î¾ß ÇÏ´Â ±¸¼º¿ä¼ÒÀÇ À̸§À» ÁöÁ¤ÇÕ´Ï´Ù.
Äھ ¼³Ä¡µÈ ÄÄÇ»ÅÍ¿¡¼ WatchList.properties¿¡ Áß¾Ó ±â·Ï±â ¹× ½Ã½ºÅÛ °ü¸®ÀÚ¿ë Ç׸ñÀÌ Æ÷ÇԵ˴ϴÙ.
Ä¿³ØÅÍ°¡ ¼³Ä¡µÈ ÄÄÇ»ÅÍ¿¡¼ WatchList.properties¿¡ °¢ Ä¿³ØÅÍÀÇ Ç׸ñÀÌ º°µµ·Î Æ÷ÇԵ˴ϴÙ. process.name µî·Ï Á¤º¸´Â ´ÙÀ½ Ä¿³ØÅÍ IDÀÔ´Ï´Ù.
WatchList.propertiesÀÇ Ç׸ñ°ú ½ÇÁ¦·Î ½ÇÇàµÇ´Â ÇÁ·Î¼¼½º »çÀÌ¿¡ ºÒÀÏÄ¡°¡ ÀÖ´Â °æ¿ì Identity Synchronization for Windows µ¥¸ó ¶Ç´Â ¼ºñ½º¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
WatchList.propertiesÀÇ Ç׸ñÀÌ ±â´ëÇÑ ¼ö º¸´Ù ÀûÀº °æ¿ì(Áï, Ä¿³ØÅÍ°¡ µÑ ¼³Ä¡µÇ¾úÀ¸³ª Çϳª¸¸ ÀÖ´Â °æ¿ì) ¼³Ä¡ ·Î±×¿¡¼ ¼³Ä¡ ÀÌ»óÀÌ ¾ø´ÂÁö È®ÀÎÇÕ´Ï´Ù.
ÇÏÀ§ ±¸¼º¿ä¼Ò ¹®Á¦ ÇØ°á´ÙÀ½ Á¡°Ë ¸ñ·ÏÀ» »ç¿ëÇÏ¿© ±¸ÇöÀÇ ÇÏÀ§ ±¸¼º¿ä¼Ò¿¡ ´ëÇÑ ¹®Á¦¸¦ ÇØ°áÇÕ´Ï´Ù.
- ¸ðµç ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¼³Ä¡µÇ¾ú½À´Ï±î?
Ä¿³ØÅÍ°¡ ¼³Ä¡µÈ ÈÄ ¹Ýµå½Ã ÇÏÀ§ ±¸¼º¿ä¼Ò ¼³Ä¡°¡ ¿Ï·áµÇ¾î¾ß ÇÕ´Ï´Ù.
- Active Directory Ä¿³ØÅÍÀÇ °æ¿ì ¼³Ä¡µÇ´Â ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¾ø½À´Ï´Ù.
- Sun Java System Directory Server Ä¿³ØÅÍÀÇ °æ¿ì µ¿±âȵǴ Sun Java System Directory Server¿¡ Directory Server Ç÷¯±×ÀÎÀ» ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù.
- Windows NT Ä¿³ØÅÍÀÇ °æ¿ì µ¿±âȵǴ °¢ Windows NT µµ¸ÞÀÎ¿ë ±âº» µµ¸ÞÀÎ Á¦¾î±â¿¡ Windows º¯È °¨Áö±â¿Í ºñ¹Ð¹øÈ£ ÇÊÅÍ Ç÷¯±×ÀÎÀÌ ¹Ýµå½Ã ¼³Ä¡µÇ¾î¾ß ÇÕ´Ï´Ù. ÀÌ µÎ ÇÏÀ§ ±¸¼º¿ä¼Ò´Â Windows NT Ä¿³ØÅÍ°¡ ¼³Ä¡µÈ ÈÄ ÇÔ²² ¼³Ä¡µË´Ï´Ù.
Âü°í
Windows NT SAM º¯°æ °¨Áö±â ÇÏÀ§ ±¸¼º¿ä¼Ò¸¦ »ç¿ëÇÏ·Á¸é ¹Ýµå½Ã NT °¨»ç ·Î±×¸¦ ÀÛµ¿ÇØ¾ß ÇÕ´Ï´Ù. ½ÃÀÛ > ÇÁ·Î±×·¥ > °ü¸® µµ±¸ > »ç¿ëÀÚ °ü¸®ÀÚ¸¦ ¼±ÅÃÇÑ ÈÄ Á¤Ã¥ > °¨»ç Á¤Ã¥À» ¼±ÅÃÇÕ´Ï´Ù. ÀÌ À̺¥Æ® °¨»ç¸¦ ¼±ÅÃÇÏ°í »ç¿ëÀÚ ¹× ±×·ì °ü¸®¿ë ¼º°ø ¹× ½ÇÆÐ ¼±ÅöõÀ» ¸ðµÎ ¼±ÅÃÇÕ´Ï´Ù.
À̺¥Æ® ºä¾î > Event Log Wrapping¿¡¼ Event Log Settings¸¦ ¼±ÅÃÇÑ ÈÄ Overwrite Events as Needed¸¦ ¼±ÅÃÇÕ´Ï´Ù.
.
- ÇÏÀ§ ±¸¼º¿ä¼Ò ¼³Ä¡ ÈÄ ´Ü°è¸¦ ¼öÇàÇß½À´Ï±î?
Directory Server¿¡ Directory Server Ç÷¯±×ÀÎÀ» ¼³Ä¡ÇÑ ÈÄ ¼¹ö¸¦ ¹Ýµå½Ã ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù. ±âº» µµ¸ÞÀÎ Á¦¾î±â¿¡ NT Change Detector¿Í Password Filter°¡ ¼³Ä¡µÈ ÈÄ ¹Ýµå½Ã ¼¹ö¸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
- ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ½ÇÇàµË´Ï±î?
Ç÷¯±×ÀÎÀÌ ¼³Ä¡µÈ À§Ä¡ÀÇ Directory Server°¡ ½ÇÇà ÁßÀԴϱî? º¯°æ °¨Áö±â¿Í ºñ¹Ð¹øÈ£ ÇÊÅÍ°¡ ¼³Ä¡µÈ À§Ä¡ÀÇ ±âº» µµ¸ÞÀÎ Á¦¾î±â°¡ ½ÇÇà ÁßÀԴϱî?
- ÇÏÀ§ ±¸¼º¿ä¼Ò¿¡ Ä¿³ØÅÍ·ÎÀÇ ³×Æ®¿öÅ© ¿¬°áÀÌ ¼³Á¤µÇ¾ú½À´Ï±î?
Ä¿³ØÅÍ°¡ ½ÇÇàµÇ´Â ÄÄÇ»ÅÍ¿¡¼ netstat -n -a¸¦ ½ÇÇàÇÏ¿© Ä¿³ØÅÍ°¡ ÇÏÀ§ ±¸¼º¿ä¼ÒÀÇ ¿¬°áÀ» ¼ö½ÅÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ ¿¹´Â ¼¼ °¡Áö ¼·Î ´Ù¸¥ ½Ã³ª¸®¿À¿¡¼ ÀÌ ¸í·ÉÀ» ½ÇÇàÇÑ °á°úÀÔ´Ï´Ù. (Ä¿³ØÅÍ´Â Æ÷Æ® 9999¸¦ ¼ö½ÅÇϵµ·Ï ±¸¼ºµÇ¾ú½À´Ï´Ù.)
- Ä¿³ØÅÍ°¡ ÀÔÁß°è ¿¬°áÀ» ¼ö½ÅÇϸç ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¿¬°á(¿¹»óµÈ °á°ú):
netstat n a | grep 9999
*.9999 *.* 0 0 65536 0 LISTEN
12.13.1.2.44397 12.13.1.2.9999 73620 0 73620 0 ESTABLISHED
12.13.1.2.9999 12.13.1.2.44397 73620 0 73620 0 ESTABLISHED
- Ä¿³ØÅÍ°¡ ÀÔÁß°è ¿¬°áÀ» ¼ö½ÅÇÏÁö¸¸ ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ¿¬°áµÇÁö ¾ÊÀº °æ¿ì
ÇÏÀ§ ±¸¼º¿ä¼Ò°¡ ½ÇÇàµÇ´ÂÁö È®ÀÎÇÑ ÈÄ ÇÏÀ§ ±¸¼º¿ä¼ÒÀÇ ·ÎÄà ·Î±×¿¡¼ ÀáÀçÀûÀÎ ¹®Á¦°¡ ¾ø´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- Ä¿³ØÅÍ°¡ ÀÔÁß°è ¿¬°áÀ» ¼ö½ÅÇÏÁö ¾Ê´Â °æ¿ì:
¿Ã¹Ù¸¥ Æ÷Æ® ¹øÈ£¸¦ ÁöÁ¤Çß´ÂÁö È®ÀÎÇÕ´Ï´Ù. Ä¿³ØÅÍ°¡ ½ÇÇà ÁßÀ̸ç READY »óÅÂÀÎÁö È®ÀÎÇÕ´Ï´Ù. Ä¿³ØÅÍÀÇ ·ÎÄà ·Î±×¿¡¼ ÀáÀçÀûÀÎ ¹®Á¦°¡ ¾ø´ÂÁö È®ÀÎÇÕ´Ï´Ù.
Message Queue ¹®Á¦ ÇØ°áSun Java System Message Queue ºê·ÎÄ¿°¡ ½ÇÇà ÁßÀÎÁö È®ÀÎÇÕ´Ï´Ù. Message Queue ºê·ÎÄ¿°¡ ½ÇÇàµÇ´Â ÄÄÇ»ÅÍ¿Í Æ÷Æ®¿¡ telnet ¸í·ÉÀ» ½ÇÇàÇÏ¸é »ç¿ëÁßÀÎ Message Queue ¼ºñ½º ¸ñ·ÏÀÌ ¹ÝȯµË´Ï´Ù.
# telnet localhost 7676
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
101 psw-broker 3.0.1
cluster tcp CLUSTER 32914
admin tcp ADMIN 32912
portmapper tcp PORTMAPPER 7676
ssljms tls NORMAL 32913
jms tcp NORMAL 32911
.
Connection closed by foreign host.
- Ãâ·Â ¸ñ·Ï¿¡ "ssljms tcp NORMAL" ¼ºñ½º°¡ ¾ø´Â °æ¿ì Message Queue ·Î±×¿¡¼ ÀáÀçÀû ¹®Á¦¸¦ È®ÀÎÇÕ´Ï´Ù. Äھ Solaris¿¡ ¼³Ä¡µÈ °æ¿ì Message Queue ºê·ÎÄ¿ÀÇ ·Î±×´Â ´ÙÀ½°ú °°½À´Ï´Ù.
/var/imq/instances/psw-broker/log/log.txt
- Äھ Windows¿¡ ¼³Ä¡µÈ °æ¿ì ºê·ÎÄ¿ÀÇ ·Î±×´Â ´ÙÀ½°ú °°½À´Ï´Ù.
<installation_root>\isw-<machine_name>\imq\var\instances\isw-broker\ log\log.txt
telnet ¸í·ÉÀÌ ½ÇÆÐÇÏ´Â °æ¿ì ºê·ÎÄ¿°¡ ½ÇÇàµÇÁö ¾Ê°Å³ª À߸øµÈ Æ÷Æ®°¡ ÁöÁ¤µÈ °ÍÀÔ´Ï´Ù. ºê·ÎÄ¿ÀÇ ·Î±×¿¡¼ Æ÷Æ® ¹øÈ£¸¦ È®ÀÎÇÕ´Ï´Ù. ºê·ÎÄ¿ÀÇ Æ÷Æ®´Â ´ÙÀ½ ÁÙ¿¡ ÁöÁ¤µË´Ï´Ù.
[13/Mar/2003:18:17:09 CST] [B1004]: ?tarting the portmapper service using tcp [ 7676, 50 ] with min threads 1 and max threads of 1
ºê·ÎÄ¿°¡ ½ÇÇàµÇÁö ¾Ê´Â °æ¿ì SolarisÀÇ °æ¿ì /etc/init.d/imq start¸¦ ½ÇÇàÇϰųª WindowsÀÇ °æ¿ì iMQ Broker Windows ¼ºñ½º¸¦ ½ÃÀÛÇÏ¿© ºê·ÎÄ¿¸¦ ½ÃÀÛÇÒ ¼ö ÀÖ½À´Ï´Ù.
Message Queue¸¦ Solaris 8¿¡ ¼³Ä¡Çϸç mquinstall¸¦ ½ÇÇàÇÏ¿© ÆÐÅ°Áö¸¦ ¸ðµÎ ¼³Ä¡ÇÏ´Â °æ¿ì ¹Ýµå½Ã mqinstall¸¦ ½ÇÇàÇϱâ Àü¿¡ IMQ_JAVAHOMEÀ» ¼³Á¤ÇÏ¿© ¼ÒÇÁÆ®¿þ¾î°¡ ¿Ã¹Ù¸¥ ¹öÀüÀÇ Java¸¦ ¼±ÅÃÇϵµ·Ï ÇØ¾ß ÇÕ´Ï´Ù.
¾ÆÁ÷ Äھ ¼³Ä¡ÇÏÁö ¾Ê¾ÒÀ¸¸é Identity Synchronization for Windows ¼³Ä¡ ÇÁ·Î±×·¥ÀÌ Message Queue ºê·ÎÄ¿°¡ »ç¿ëÇÒ JVMÀ» ÁöÁ¤ÇϹǷΠIMQ_JAVAHOMEÀ» ¼³Á¤ÇÏÁö ¾Ê¾Æµµ µË´Ï´Ù.
ºê·ÎÄ¿ ±¸¼º µð·ºÅ丮 Åë½Å ¹®Á¦ ÇØ°á
Message Queue ºê·ÎÄ¿´Â Identity Synchronization for Windows ±¸¼ºÀÌ ÀúÀåµÈ Directory Server¿¡ ´ëÇÏ¿© Ŭ¶óÀ̾ðÆ®¸¦ ÀÎÁõÇÕ´Ï´Ù. ºê·ÎÄ¿°¡ ÀÌ Directory Server¿¡ ¿¬°áÇÒ ¼ö ¾ø´Â °æ¿ì ¸ðµç Ŭ¶óÀ̾ðÆ®°¡ Message Queue¿¡ ¿¬°áÇÒ ¼ö ¾øÀ¸¸ç, ºê·ÎÄ¿ ·Î±×¿¡ "javax.naming.CommunicationException" ¶Ç´Â "javax.naming.NameNotFoundException" µîÀÇ javax.naming ¿¹¿Ü°¡ ±â·ÏµË´Ï´Ù.
javax.naming ¿¹¿Ü°¡ ¹ß»ýÇÏ´Â °æ¿ì ´ÙÀ½°ú °°ÀÌ ÇÕ´Ï´Ù.
- /var/imq/instances/isw-broker/props/config.propertiesÀÇ ¸ðµç imq.user_repository.ldap properties¿¡ ¿Ã¹Ù¸¥ °ªÀÌ ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. À߸øµÈ ³»¿ëÀÌ ÀÖÀ¸¸ç Message Queue ºê·ÎÄ¿¸¦ Á¤ÁöÇÏ°í ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© ÀúÀåÇÑ ÈÄ, ºê·ÎÄ¿¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù. Directory Server È£½ºÆ® À̸§Àº ºê·ÎÄ¿ÀÇ ÄÄÇ»ÅÍ¿¡¼ º¯È¯µÉ ¼ö ÀÖ¾î¾ß ÇÕ´Ï´Ù.
- /etc/imq/passfileÀÇ imq.user_repository.ldap.password µî·ÏÁ¤º¸°¡ ¿Ã¹Ù¸¥Áö È®ÀÎÇÕ´Ï´Ù.
- ÀϺΠ·çÆ® Á¢¹Ì¾î¿¡ °ø¹éÀÌ ÀÖ´Â °æ¿ì ºê·ÎÄ¿°¡ Ç׸ñÀ» °Ë»öÇÏÁö ¸øÇÒ ¼ö ÀÖ½À´Ï´Ù.
ºê·ÎÄ¿ ¸Þ¸ð¸® ¼³Á¤ ¹®Á¦ ÇØ°á
Á¤»óÀûÀÎ ¿î¿µ µ¿¾È Message Queue ºê·ÎÄ¿´Â ÀûÀýÇÑ Á¤µµÀÇ ¸Þ¸ð¸®¸¦ »ç¿ëÇÕ´Ï´Ù. ±×·¯³ª idsync resync ÀÛ¾÷ µ¿¾È ºê·ÎÄ¿ÀÇ ¸Þ¸ð¸® ¿ä±¸ »çÇ×ÀÌ Áõ°¡ÇÕ´Ï´Ù. ºê·ÎÄ¿ÀÇ ¸Þ¸ð¸® ÇÑ°è°¡ ÃÊ°úÇϸé Àü´ÞµÇÁö ¾ÊÀº ¸Þ½ÃÁö°¡ ½×ÀÌ°Ô µÇ°í, idsync resync ÀÛ¾÷ÀÌ ¸Å¿ì ´À·ÁÁö°Å³ª ¿ÏÀüÈ÷ Á¤ÁöÇÕ´Ï´Ù. ¶ÇÇÑ ÀÌ ÈÄ Identity Synchronization for Windows ½Ã½ºÅÛÀÌ ÀÀ´äÇÏÁö ¾Ê°Ô µË´Ï´Ù.
ºê·ÎÄ¿°¡ ¸Þ¸ð¸® ºÎÁ· »óÅ°¡ µÇ¸é ·Î±×¿¡ ´ÙÀ½ ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
[03/Nov/2003:14:07:51 CST] [B1089]: In low memory condition, Broker is attempting to free up resources
[03/Nov/2003:14:07:51 CST] [B1088]: Entering Memory State [B0024]: RED from previous state [B0023]: ORANGE - current memory is 1829876K, 90% of total memory
ÀÌ·¯ÇÑ »óȲÀ» ÇÇÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇÕ´Ï´Ù.
- Sun Java System 1 2004Q3 Identity Synchronization for Windows ¸±¸®½º ³ëÆ®¿¡¼ ¼³¸íÇÑ °Í°ú °°ÀÌ ºê·ÎÄ¿ÀÇ ¸Þ¸ð¸® ÇѰ踦 1 ¶Ç´Â 2GB·Î Áõ°¡½Ãŵ´Ï´Ù.
- idsync resync ÀÛ¾÷ µ¿¾È ·Î±× ¼öÁØÀ» INFO ¼³Á¤À¸·Î À¯ÁöÇÕ´Ï´Ù. ·Î±× ¼öÁØÀ» FINE ÀÌ»óÀ¸·Î ¿Ã¸®¸é ºê·ÎÄ¿ÀÇ ºÎÇÏ°¡ ·Î±× ¸Þ½ÃÁö°¡ Áß¾Ó ±â·Ï±â·Î Àü´ÞµÇ´Â ¸¸Å Áõ°¡ÇÕ´Ï´Ù.
- ÇÑ ¹ø¿¡ µ¿±âÈ »ç¿ëÀÚ ¸ñ·Ï Çϳª¿¡ ´ëÇÏ¿©¸¸ idsync resync¸¦ ½ÇÇàÇÕ´Ï´Ù.
ºê·ÎÄ¿ÀÇ ¸Þ¸ð¸®°¡ ºÎÁ·ÇØÁö´Â °æ¿ì ´ÙÀ½°ú °°ÀÌ º¹±¸ÇÕ´Ï´Ù.
- ÀûÀýÇÑ µð·ºÅ丮ÀÇ ºê·ÎÄ¿ÀÇ ¿µ±¸ ¸Þ½ÃÁö ÀúÀå¿¡¼ Àü´ÞµÇÁö ¾ÊÀº ¸Þ½ÃÁö°¡ ´ë±âÁßÀÎÁö È®ÀÎÇÕ´Ï´Ù.
- ÀÌ µð·ºÅ丮ÀÇ °¢ ÆÄÀÏ¿¡´Â ÇϳªÀÇ Àü´ÞµÇÁö ¾ÊÀº ¸Þ½ÃÁö°¡ ÀÖ½À´Ï´Ù. ÀÌ µð·ºÅ丮ÀÇ ÆÄÀÏ ¼ö°¡ 10000À» ÃÊ°úÇÏ´Â °æ¿ì ºê·ÎÄ¿°¡ ¸Þ½ÃÁö¸¦ Áö¿¬ÇÏ°í ÀÖ´Â °ÍÀÔ´Ï´Ù.1 ±×·¸Áö ¾ÊÀº °æ¿ì ºê·ÎÄ¿¿¡ ´Ù¸¥ ¹®Á¦°¡ ÀÖ½À´Ï´Ù.
- ¸Þ½ÃÁö Áö¿¬Àº idsync resync ÀÛ¾÷¿¡ °ü·ÃµÈ À¯ÀÏÇÑ ·Î±× ÆÄÀÏÀÏ °ÍÀ̹ǷΠ¾ÈÀüÇÏ°Ô Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù.
- "¼ºñ½º ½ÃÀÛ ¹× Á¤Áö" ÆäÀÌÁö 183¿¡ ¼³¸íÇÑ °Í°ú °°ÀÌ Message Queue ºê·ÎÄ¿¸¦ Á¤ÁöÇÕ´Ï´Ù.
- ¿µ±¸ ¸Þ½ÃÁö ÀúÀå¿¡¼ ¸ðµç ÆÄÀÏÀ» Á¦°ÅÇÕ´Ï´Ù. À̵é ÆÄÀÏÀ» Á¦°ÅÇÏ´Â °¡Àå ½¬¿î ¹æ¹ýÀº message/ µð·ºÅ丮¸¦ ¹Ýº¹ÀûÀ¸·Î Á¦°ÅÇÏ°í À̸¦ ´Ù½Ã ¸¸µå´Â ¹æ¹ýÀÔ´Ï´Ù.
- Message Queue ºê·ÎÄ¿¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
¿©±âÀÇ ´Ü°è¸¦ ÅëÇÏ¿© ºê·ÎÄ¿ÀÇ ¸Þ¸ð¸®°¡ ´Ù½Ã ºÎÁ·ÇØÁöÁö ¾Êµµ·Ï ÇÕ´Ï´Ù.
SSL ¹®Á¦ ÇØ°áSSLÀÇ ¹®Á¦¸¦ Áø´ÜÇÒ ¶§ Á¦ 11Àå, "º¸¾È ±¸¼º,"¿¡ ¼³¸íÇÑ Identity Synchronization for WindowsÀÇ ±¸¼º¿ä¼Ò »çÀÌ¿¡¼ SSLÀ» ¼³Á¤ÇÏ´Â ¹æ¹ý ¶ÇÇÑ ÂüÁ¶ÇϽʽÿÀ. ÀÌ ºÎºÐÀÇ ³»¿ë:
ÄÚ¾î ±¸¼º¿ä¼Ò »çÀÌÀÇ SSL
Identity Synchronization for Windows ÇÁ·Î±×·¥Àº ÄÚ¾î ¼³Ä¡ µ¿¾È Á¦°øµÈ SSL Æ÷Æ®°¡ ¿Ã¹Ù¸¥Áö È®ÀÎÇÒ ¼ö ¾ø½À´Ï´Ù. ÄÚ¾î ¼³Ä¡ µ¿¾È SSL Æ÷Æ®¸¦ À߸ø ÀÔ·ÂÇÑ °æ¿ì ÄÚ¾î ±¸¼º¿ä¼Ò°¡ ÀûÀýÈ÷ Åë½ÅÇÒ ¼ö ¾ø½À´Ï´Ù. ±¸¼ºÀ» óÀ½ ÀúÀåÇÒ ¶§±îÁö ¹®Á¦¸¦ ¾Ë ¼ö ¾øÀ» °ÍÀÔ´Ï´Ù. Äֿܼ¡ ´ÙÀ½ °æ°í°¡ Ç¥½ÃµË´Ï´Ù.
The configuration was successfully saved, however, the System Manager could not be notified of the new configuration.
½Ã½ºÅÛ °ü¸®ÀÚ ·Î±×¿¡´Â ´ÙÀ½ Ç׸ñÀÌ Ç¥½ÃµË´Ï´Ù.
[10/Nov/2003:10:24:35.137 -0600] WARNING 14 example "Failed to connect
to the configuration directory because "Unable to connect: (-5981)
Connection refused by peer.". Will retry shortly."
ÀÌ °æ¿ì Äھ Á¦°ÅÇÏ°í ¿Ã¹Ù¸¥ SSL Æ÷Æ® ¹øÈ£·Î ´Ù½Ã ¼³Ä¡ÇÕ´Ï´Ù.
Ä¿³ØÅÍ¿Í Directory Server ¶Ç´Â Active Directory »çÀÌÀÇ SSL
Ä¿³ØÅÍ°¡ SSLÀ» ÅëÇÏ¿© Directory Server ¶Ç´Â Active Directory·Î ¿¬°áÇÒ ¼ö ¾ø´Â °æ¿ì Áß¾Ó ¿À·ù ·Î±×¿¡ ´ÙÀ½ ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
[06/Oct/2003:14:02:48.911 -0600] WARNING 14 CNN100 host1 "failed to open connection to ldaps://host2.airius.com:636."
ÄܼÖÀ» ¿°í Specifying Advanced Security Options ÆгÎÀ» ¼±ÅÃÇÕ´Ï´Ù
(ÆäÀÌÁö 120 ÂüÁ¶).½Å·ÚµÇÁö ¾ÊÀº ÀÎÁõ¼
´õ ÀÚ¼¼ÇÑ ³»¿ëÀº Áß¾Ó °¨»ç ·Î±×¿¡ ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î LDAP ¼¹öÀÇ SSL ÀÎÁõ¼°¡ ½Å·ÚµÇÁö ¾Ê´Â °æ¿ì ÀÌ ¸Þ½ÃÁö°¡ ±â·ÏµË´Ï´Ù.
[06/Oct/2003:14:02:48.951 -0600] INFO 14 CNN100 host1 "failed to open connection to ldaps://host2.airius.com:636, error(91): Cannot connect to the LDAP server, reason: SSL_ForceHandshake failed: (-8179) Peer? Certificate issuer is not recognized."
´ëºÎºÐÀÇ °æ¿ì Ä¿³ØÅÍÀÇ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡ CA ÀÎÁõ¼°¡ Ãß°¡µÇÁö ¾ÊÀº °ÍÀÔ´Ï´Ù. ÀÌ´Â Directory Server¿Í ÇÔ²² Á¦°øµÇ´Â certutil ÇÁ·Î±×·¥À» ½ÇÇàÇÏ¿© È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.2
Âü°í
certutil µîÀÇ ÀÚ°Ý Áõ¸í °ü¸® À¯Æ¿¸®Æ¼´Â SUNWtlsu ÆÐÅ°Áö¿Í ÇÔ²² Á¦°øµÇ¸ç Directory Server¿¡ Æ÷ÇÔµÇÁö´Â ¾Ê½À´Ï´Ù. (ÀÌ ÆÐÅ°Áö´Â Sun Microsystems¿¡¼ ¹«·á·Î ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÆÐÅ°Áö¸¦ ´Ù¿î·ÎµåÇÑ ÈÄ ´ÙÀ½¿¡¼ certutil¸¦ ã½À´Ï´Ù.
/usr/sfw/bin/certutil
ÀÌ ¿¹¿¡¼ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡ Æ÷ÇÔµÈ ÀÎÁõ¼°¡ ¾ø½À´Ï´Ù.3
# /usr/sunone/servers/shared/bin/certutil -L -d /usr/sunone/servers/ isw-host1/etc/CNN100
ÀÎÁõ¼ À̸§ ½Å·Ú ¼Ó¼º
p À¯È¿ÇÑ ÇǾî
P ½Å·ÚµÈ ÇǾî (p Æ÷ÇÔ)
c À¯È¿ÇÑ CA
T Ŭ¶óÀ̾ðÆ® ÀÎÁõ¼ ¹ßÇàÀ» À§ÇÑ ½Å·ÚµÈ CA (c Æ÷ÇÔ)
C ÀÎÁõ¼¿¡ ´ëÇÑ ½Å·ÚµÈ CA (SSL¿ë ¼¹ö ÀÎÁõ¼ Àü¿ë) (c Æ÷ÇÔ)
u »ç¿ëÀÚ ÀÎÁõ¼
w °æ°í º¸³¿
´ÙÀ½ ¿¹¿¡¼ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡ ¿ÀÁ÷ Active Directory CA ÀÎÁõ¼¸¸ ÀÖ½À´Ï´Ù.
# /usr/sunone/servers/shared/bin/certutil -L -d /usr/sunone/servers/ isw-host1/etc/CNN100
ÀÎÁõ¼ À̸§ ½Å·Ú ¼Ó¼º
airius.com CA C,c,
p À¯È¿ÇÑ ÇǾî
P ½Å·ÚµÈ ÇǾî (p Æ÷ÇÔ)
c À¯È¿ÇÑ CA
T Ŭ¶óÀ̾ðÆ® ÀÎÁõ¼ ¹ßÇàÀ» À§ÇÑ ½Å·ÚµÈ CA (c Æ÷ÇÔ)
C ÀÎÁõ¼¿¡ ´ëÇÑ ½Å·ÚµÈ CA (SSL¿ë ¼¹ö ÀÎÁõ¼ Àü¿ë) (c Æ÷ÇÔ)
u »ç¿ëÀÚ ÀÎÁõ¼
w °æ°í º¸³¿
¿©±â¿¡ º¸ÀÌ´Â °Í°ú °°ÀÌ CA ÀÎÁõ¼ÀÇ ½Å·Ú Ç÷¡±×´Â ¹Ýµå½Ã "C,,"À̾î¾ß ÇÕ´Ï´Ù. ÀÎÁõ¼°¡ ÀÖÀ¸¸ç ½Å·Ú Ç÷¡±×°¡ ÀûÀýÈ÷ ¼³Á¤µÇ¾úÀ¸³ª Ä¿³ØÅÍ°¡ ¿©ÀüÈ÷ ¿¬°áÇÒ ¼ö ¾ø´Â °æ¿ì ¿ì¼± ÀÎÁõ¼¸¦ Ãß°¡ÇÑ ÈÄ Ä¿³ØÅÍ°¡ ´Ù½Ã ½ÃÀ۵Ǿú´ÂÁö È®ÀÎÇÑ ÈÄ, Sun Java System µð·ºÅ丮¿Í ÇÔ²² Á¦°øµÇ´Â ldapsearch ¸í·ÉÀ» »ç¿ëÇÏ¿© ¹®Á¦ Áø´ÜÀ» º¸Á¶ÇÕ´Ï´Ù. ldapsearch¿¡¼ ÀÎÁõ¼°¡ Çã¿ëµÇÁö ¾Ê´Â °æ¿ì Ä¿³ØÅÍ¿¡¼µµ Çã¿ëµÇÁö ¾Ê½À´Ï´Ù. ¿¹¸¦ µé¾î ldapsearch´Â ½Å·ÚµÇÁö ¾ÊÀº ÀÎÁõ¼¸¦ °ÅºÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
# /usr/sunone/servers/shared/bin/ldapsearch -Z -P /usr/sunone/ servers/isw-host1/etc/CNN100 -h host2 -b "" -s base "(objectclass=*)"
ldap_search: Can't contact LDAP server
SSL error -8179 (Peer? Certificate issuer is not recognized.)
-P ¿É¼ÇÀ» »ç¿ëÇϸé ldapsearch°¡ Ä¿³ØÅÍ CNN100ÀÇ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¸¦ SSL ÀÎÁõ¼ À¯È¿¼º °Ë»ç¿¡ »ç¿ëÇÕ´Ï´Ù. Ä¿³ØÅÍÀÇ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡ ¿Ã¹Ù¸¥ ÀÎÁõ¼°¡ Ãß°¡µÈ ÈÄ ldapsearch°¡ ÇØ´ç ÀÎÁõ¼¸¦ Çã¿ëÇÏ´ÂÁö È®ÀÎÇÑ ÈÄ Ä¿³ØÅ͸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
ÀÏÄ¡µÇÁö ¾Ê´Â È£½ºÆ®À̸§
Identity Synchronization for Windows°¡ SSL ¿¬°á ¼³Á¤À» ½ÃµµÇÒ ¶§(¸ðµç ÀÎÁõ¼ ½Å·Ú ¼³Á¤ »ç¿ë ¾È ÇÔ) Identity Synchronization for WindowsÀÇ Ä¿³ØÅÍ´Â ¼¹öÀÇ È£½ºÆ® À̸§ÀÌ SSL Çù»ó ´Ü°è µ¿¾È ¼¹ö°¡ Á¦½ÃÇÑ ÀÎÁõ¼¿¡ Àִ ȣ½ºÆ® À̸§°ú ÀÏÄ¡ÇÏ´ÂÁö È®ÀÎÇÕ´Ï´Ù. È£½ºÆ® À̸§ÀÌ ÀÏÄ¡ÇÏÁö ¾ÊÀ¸¸é Ä¿³ØÅÍ°¡ ¿¬°á ¼³Á¤À» °ÅºÎÇÕ´Ï´Ù.
Identity Synchronization for Windows ±¸¼ºÀÇ µð·ºÅ丮 ¼Ò½º È£½ºÆ® À̸§Àº ¹Ýµå½Ã Ç×»ó ÇØ´ç µð·ºÅ丮 ¼Ò½º°¡ »ç¿ëÇÏ´Â ÀÎÁõ¼¿¡ Æ÷ÇÔµÈ È£½ºÆ® À̸§°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù.
´ÙÀ½°ú °°ÀÌ ldapsearch¸¦ »ç¿ëÇÏ¿© È£½ºÆ® À̸§ÀÌ ÀÏÄ¡ÇÏ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
/var/mps/serverroot/shared/bin/ldapsearch.exe -Z -P /var/opt/SUNWisw/etc/CNN100 -3
-h host2.example.com -p 636 -s base -b "" "(objectclass=*)"
¸í·ÉÁÙÀÇ È£½ºÆ® À̸§(host2.example.com)°ú ÀÎÁõ¼¿¡ Æ÷ÇÔµÈ È£½ºÆ® À̸§ÀÌ ÀÏÄ¡ÇÏÁö ¾Ê´Â °æ¿ì ´ÙÀ½ÀÇ ¿À·ù ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
ldap_search: CanÕt contact LDAP server
SSL error -12276 (Unable to communicate securely with peer: requested do main name does not match the serverÕs certificate.)
È£½ºÆ® À̸§ÀÌ ÀÏÄ¡Çϸé ldapsearch ¸í·ÉÀÌ ¼º°øÇÏ¸ç ·çÆ® DSEÀÇ ³»¿ëÀÌ Ç¥½ÃµË´Ï´Ù.
¸¸·áµÈ ÀÚ°Ý Áõ¸í
¼¹öÀÇ ÀÎÁõ¼°¡ ¸¸·áµÈ °æ¿ì ÀÌ ¸Þ½ÃÁö°¡ ±â·ÏµË´Ï´Ù.
[06/Oct/2003:14:06:470.130 -0600] INFO 20 CNN100 host1 "failed to open connection to ldaps://host2.airius.com:636, error(91): Cannot connect to the LDAP server, reason: SSL_ForceHandshake failed: (-8181) PeerÕs Certificate has expired."
ÀÌ °æ¿ì ¼¹ö´Â ¹Ýµå½Ã »õ ÀÎÁõ¼¸¦ ¹ßÇàÇØ¾ß ÇÕ´Ï´Ù.
Directory Server Ç÷¯±×Àΰú Active Directory »çÀÌÀÇ SSL
±âº»ÀûÀ¸·Î ¿äû½Ã ºñ¹Ð¹øÈ£ µ¿±âȸ¦ ¼öÇàÇÒ ¶§ Directory Server´Â SSLÀ» ÅëÇÏ¿© Active Directory¿Í Åë½ÅÇÏÁö ¾Ê½À´Ï´Ù. ±âº»°ªÀ» º¯°æÇÏ¿© ÀÌ Åë½ÅÀ» SSL·Î º¸È£Çϵµ·Ï Çϸé Á¦ 11Àå, "º¸¾È ±¸¼º"¿¡ ¼³¸íÇÑ °Í°ú °°ÀÌ °¢ ¸¶½ºÅÍ º¹Á¦º»ÀÇ µð·ºÅ丮 ¼¹ö ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡ ¹Ýµå½Ã Active Directory CA ÀÎÁõ¼°¡ Ãß°¡µÇ¾î¾ß ÇÕ´Ï´Ù. ÀÌ ÀÎÁõ¼°¡ Ãß°¡µÇÁö ¾ÊÀ¸¸é »ç¿ëÀÚ°¡ µð·ºÅ丮 ¼¹ö·Î ¹ÙÀεåÇÒ ¼ö ¾øÀ¸¸ç "DSA is unwilling to perform" ¿À·ù°¡ ¹ß»ýÇÕ´Ï´Ù. ¶ÇÇÑ Ç÷¯±×ÀÎÀÇ ·Î±×(¿¹¸¦ µé¾î isw-<hostname>/logs/SUBC100/pluginwps_log_0.txt)°¡ ´ÙÀ½À» º¸°íÇÕ´Ï´Ù.
[06/Nov/2003:15:56:16.310 -0600] INFO td=0x0376DD74 logCode=81 ADRepository.cpp:310 "unable to open connection to Active Directory server at ldaps://host2.airius.com:636, reason: "
ÀÌ °æ¿ì ¹Ýµå½Ã Active Directory CA ÀÎÁõ¼¸¦ Directory ServerÀÇ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡ Ãß°¡ÇÏ°í Directory Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
Á¦¾î±â ¹®Á¦ ÇØ°á¹é¾÷ ÆÄÀÏ¿¡¼ Active Directory µµ¸ÞÀÎ Á¦¾î±â¸¦ º¹±¸ÇÒ ¶§ ÀϺΠī¿îÅÍ´Â Àç¼³Á¤µÇÁö ¾Ê½À´Ï´Ù.
¸ðµç Ä«¿îÅÍ°¡ ÀûÀýÈ÷ Àç¼³Á¤µÇµµ·Ï ÇÏ·Á¸é Active Directory µµ¸ÞÀÎ Á¦¾î±â¸¦ º¹±¸ÇÑ ÈÄ ¸ðµç »ç¿ëÀÚ¸¦ À絿±âÈÇØ¾ß ÇÕ´Ï´Ù.
1¸ðµç ¸Þ½ÃÁö°¡ Àü´ÞµÈ °æ¿ì¶óµµ ÆÄÀÏ ÀÛ¼º ¹× »èÁ¦·Î ÀÎÇÑ ¼º´É ÀúÇϸ¦ ÇÇÇϱâ À§ÇÏ¿© ºê·ÎÄ¿´Â ÃÖ´ë 10000°³ÀÇ ¸Þ½ÃÁö ÆÄÀÏÀ» À¯ÁöÇÒ ¼ö ÀÖ½À´Ï´Ù.2Solaris¿¡¼ ÀÌ ¸í·ÉÀ» ½ÇÇàÇϱâ Àü¿¡ ¹Ýµå½Ã LD_LIBRARY_PATH ȯ°æ º¯¼ö¿¡ <installation_root>/lib µð·ºÅ丮¸¦ Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù.3Sun Java System Directory Server¿Í Windows NT Ä¿³ØÅÍ¿ë ±âº» ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¿¡´Â saint-cert100 ¹× saintRootCAÀÇ µÎ °³ÀÇ ÀÎÁõ¼°¡ ÀÖ½À´Ï´Ù. ÀÌ ¸±¸®½º¿¡¼´Â À̵é ÀÎÁõ¼¸¦ »ç¿ëÇÏÁö ¾Ê½À´Ï´Ù.