7Àå


½Ã½ºÅÛ º¸¾È

ÀÌ ÀåÀº »õ·Î¿î ½Ã½ºÅÛÀÇ ¼³Ä¡ ¹× º¸¾È¿¡ ´ëÇØ ÀÌÀü Àå¿¡¼­ Á¦°øµÈ Á¤º¸¿Í Àü¹® Áö½ÄÀ» ½ÇÇö °¡´ÉÇÑ ½Ã³ª¸®¿À¿¡ Àû¿ëÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. ÀÌ ÀåÀº Solaris 8 OS¿ë Check PointFirewall-1 NG¸¦ °®´Â Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¸¦ Àü°³ÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù.

ÀÌ Àå¿¡ ÀÖ´Â Á¤º¸¸¦ »õ·Î¿î ½Ã½ºÅÛ ¹× ÀÀ¿ë ÇÁ·Î±×·¥ º¸¾ÈÀ» À§ÇÑ Áöħ ¹× »ç·Ê ½Ã³ª¸®¿À·Î »ç¿ëÇϽʽÿÀ.

Sun BluePrint ¼³¸í¼­¿Í ¿Â¶óÀÎ ±â»ç´Â ¿©·¯ Sun ½Ã½ºÅÛÀÇ ÃÖ¼ÒÈ­ ¹× °­È­ ÇÁ·Î¼¼½º °úÁ¤À» ÀÌÇØÇϴµ¥ À¯¿ëÇÕ´Ï´Ù. ÃֽŠÁ¦Ç° °ü·Ã ¼³¸í¼­ ¹× ±â»ç´Â ´ÙÀ½ À¥»çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ.

http://www.sun.com/blueprints

ÀÌ Àå¿¡¼­´Â ´ÙÀ½ ÁÖÁ¦¸¦ ´Ù·ì´Ï´Ù.


°èȹ ¹× Áغñ

ÀÌ »ç·Ê ¿¬±¸¿¡¼­ ¼³¸íµÈ °Íó·³ ÃÖ¼ÒÈ­ ¹× º¸¾ÈµÈ ½Ã½ºÅÛÀ» È¿°úÀûÀ¸·Î ±×¸®°í È¿À²ÀûÀ¸·Î Àü°³ÇÏ·Á¸é °èȹ°ú Áغñ°¡ Áß¿äÇÕ´Ï´Ù. ±âÃÊÀûÀÎ ³×Æ®¿öÅ© ±â¹Ý±¸Á¶, ¹æÄ§ ¹× ÀýÂ÷°¡ Á¦´ë·Î ÁغñµÇ¾î ÀÖ¾î¾ß ÇÕ´Ï´Ù. ¶ÇÇÑ, ½Ã½ºÅÛÀÇ Áö¿ø ¹× À¯Áö¿¡ ´ëÇØ Á¤ÀÇÇϰí ÀÌÇØÇØ¾ß ÇÕ´Ï´Ù. °èȹ ¹× Áغñ¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸´Â 2 ÀåÀ» ÂüÁ¶ÇϽʽÿÀ. ÀÌ Àå¿¡ ¼³¸íµÈ ½Ã³ª¸®¿À´Â ½Ã½ºÅÛ °ü¸®ÀÚ(SA)°¡ ¹æÈ­º® ½Ã½ºÅÛÀ» À§ÇØ Solaris OS À̹ÌÁöÀÇ ÃÖ¼ÒÈ­ ¹× °­È­¸¦ À§ÇØ ¼öÇàÇÒ °úÁ¤ ¹× ÀÛ¾÷¿¡ ´ëÇØ »ó¼¼È÷ ¼³¸íÇÕ´Ï´Ù.

ÀÌ ½Ã³ª¸®¿À¿¡¼­, ½Ã½ºÅÛ °ü¸®ÀÚ´Â °í°´¿¡°Ô ¹æÈ­º® ¼­ºñ½º¸¦ Á¦°ø·Á´Â ¼­ºñ½º Á¦°øÀÚ¸¦ À§ÇØ Check PointFirewall-1 NG ½Ã½ºÅÛÀ» ±¸Ãà ¹× Àü°³Çϱâ À§ÇÑ ÀÚµ¿È­µÇ°í È®Àå °¡´ÉÇÑ ¼Ö·ç¼ÇÀ» ¸¸µå´Â ÀÛ¾÷À» ÇÕ´Ï´Ù. ÀÌ ½Ã³ª¸®¿ÀÀÇ °æ¿ì, ¼­ºñ½º Á¦°øÀÚÀÇ ¿ä±¸»çÇ×°ú °í·Á»çÇ×Àº ´ÙÀ½°ú °°½À´Ï´Ù.

ÀÌ·¯ÇÑ ¿ä±¸»çÇ׿¡ ±Ù°ÅÇÏ¿© ½Ã½ºÅÛ °ü¸®ÀÚ´Â JumpStart ±â¼ú°ú Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¸¦ »ç¿ëÇÏ¿© OS À̹ÌÁöÀÇ ¼³Ä¡, ÃÖ¼ÒÈ­ ¹× °­È­¸¦ ÀÚµ¿È­Çϱâ·Î °áÁ¤ÇÕ´Ï´Ù.

°¡Á¤ ¹× Á¦ÇÑ»çÇ×

ÀÌ ÀåÀº ÀÌ¹Ì ÀÛµ¿ ÁßÀÎ Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿Í JumpStart ±â¼ú ¼³Ä¡¸¦ »ç¿ë ÁßÀ̶ó°í °¡Á¤ÇÕ´Ï´Ù. ÀÌ ¹®¼­ÀÇ ´Ù¸¥ Àå¿¡ ¼ÒÇÁÆ®¿þ¾î ¼³Ä¡¸¦ À§ÇÑ Áö½Ã¿Í ÁöħÀÌ Á¦°øµÇ¾î ÀÖ½À´Ï´Ù. ÇØ´çµÇ´Â ÀåÀ» ÂüÁ¶ÇϽʽÿÀ.

ÀÌ ÀåÀº ƯÁ¤ ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ ÃÖ¼ÒÈ­ ¹× °­È­¸¦ À§ÇØ »ç¿ëÀÚ Á¤ÀÇ ±¸¼ºÀ» °³¹ß ÁßÀ̶ó°í °¡Á¤ÇÕ´Ï´Ù. Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿¡´Â ÇØ´ç ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ´ëÇÑ µå¶óÀ̹ö³ª JumpStart ÇÁ·ÎÆÄÀÏÀÌ ¾ø½À´Ï´Ù. µû¶ó¼­, ÀÌ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ´ëÇØ »ç¿ëÀÚ Á¤ÀÇµÈ µå¶óÀ̹ö ¹× ÇÁ·ÎÆÄÀÏÀ» ÀÛ¼ºÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ÀÛ¾÷Àº ±âÁ¸ µå¶óÀ̹ö¿Í ÇÁ·ÎÆÄÀÏÀ» º¹»çÇÑ ÈÄ, ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¸Â°Ô ¼öÁ¤ÇÏ¸é µË´Ï´Ù.

ÀÌ »ç·Ê ½Ã³ª¸®¿ÀÀÇ °æ¿ì, ½Ã½ºÅÛ °ü¸®ÀÚÀÇ ±â¼ú ·¹º§Àº ´ÙÀ½°ú °°½À´Ï´Ù.

½Ã½ºÅÛ È¯°æ

¿¹Á¦ ½Ã³ª¸®¿À´Â ´ÙÀ½ Çϵå¿þ¾î ¹× ¼ÒÇÁÆ®¿þ¾î ȯ°æÀ» ±âÃÊ·Î ÇÕ´Ï´Ù.

º¸¾È ¿ä±¸»çÇ×

ÀÌ ½Ã³ª¸®¿ÀÀÇ °æ¿ì, ³ôÀº ·¹º§ÀÇ ¿ä±¸»çÇ× ¹× ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö°¡ È®ÀεǾúÀ¸³ª, ¸ðµç ÆÐŰÁöÀÇ Æ¯Á¤ ±¸¼º ¿ä¼Ò ¹× ¼­ºñ½º°¡ È®ÀεǾî¾ß ÇÕ´Ï´Ù. ¶ÇÇÑ, ½Ã½ºÅÛÀ» °ü¸®Çϱâ À§ÇØ ÇÊ¿äÇÑ Solaris OS ±â´ÉÀÌ È®ÀεǾî¾ß ÇÕ´Ï´Ù.

´ÙÀ½ ¸ñ·ÏÀº ¼ÒÇÁÆ®¿þ¾î ±¸¼º¿ä¼Ò°¡ »ç¿ëµÈ ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ º¸±â¸¦ Á¦°øÇÕ´Ï´Ù.

ÀÌ ¸ñ·Ï¿¡¼­ º¸¾È ÇÁ·ÎÆÄÀÏÀ» °³¹ßÇÒ ¼ö ÀÖ½À´Ï´Ù. º¸¾È ÇÁ·ÎÆÄÀÏ °³¹ß°ú ÇÁ·ÎÆÄÀÏ ÅÛÇø´ »ç¿ë¿¡ ´ëÇÑ »ó¼¼ Á¤º¸´Â Solaris Security Toolkit ÇÁ·ÎÆÄÀÏ °³¹ß ¹× ±¸ÇöÀ» ÂüÁ¶ÇϽʽÿÀ.


º¸¾È ÇÁ·ÎÆÄÀÏ ÀÛ¼º

º¸¾È ÇÁ·ÎÆÄÀÏÀº Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î°¡ ½Ã½ºÅÛÀÇ º¸¾È ±¸¼ºÀ» °­È­Çϰí ÃÖ¼ÒÈ­ÇÒ ¶§ ¼öÇàÇÏ´Â º¸¾È ¼öÁ¤»çÇ×À» Á¤ÀÇÇÕ´Ï´Ù. Solaris Security Toolkit¿¡ Æ÷ÇÔµÈ Ç¥ÁØ º¸¾È ÇÁ·ÎÆÄÀÏ ¶Ç´Â µå¶óÀ̹ö´Â ÃÖ¼ÒÈ­µÈ Check PointFirewall-1 NG ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ä±¸»çÇ׿¡ ºÎÇÕµÇÁö ¾Ê½À´Ï´Ù. µû¶ó¼­, »ç¿ëÀÚ Á¤ÀÇ º¸¾È ÇÁ·ÎÆÄÀÏÀ» ÀÛ¼ºÇÏ¿© ÀûÀýÇÑ ½Ã½ºÅÛ ¼öÁ¤»çÇ×À» Àû¿ëÇØ¾ß ÇÕ´Ï´Ù.

ÀÌ ½Ã³ª¸®¿ÀÀÇ °æ¿ì, º¸¾È ÇÁ·ÎÆÄÀÏÀÇ ÀÛ¼º ÇÁ·Î¼¼½º°¡ ÇØ´ç ½Ã³ª¸®¿À¿¡ ÀûÇÕÇÒ °æ¿ì ÀÌ ÀåÀÇ ¿©·¯ Àý¿¡ ¼³¸íµÇ¾î ÀÖ½À´Ï´Ù. ù ¹øÂ°, ±âÁ¸ µå¶óÀ̹ö¿¡ ±âÃÊÇÏ¿© »õ µå¶óÀ̹ö ÆÄÀÏÀ» ÀÛ¼ºÇÕ´Ï´Ù. ±×·± ´ÙÀ½ ÀÌÀü¿¡ ¿ä¾àµÈ º¸¾È ¿ä±¸»çÇ×À» ÁؼöÇϵµ·Ï »õ µå¶óÀ̹ö¸¦ ¼öÁ¤ÇÕ´Ï´Ù. ÃÖ¼ÒÈ­´Â ¼ÒÇÁÆ®¿þ¾î ¼³Ä¡¿¡¼­ ¼³¸íµÇ°í °­È­ ¼öÁ¤Àº °­È­ ±¸¼º »ç¿ëÀÚ Á¤ÀÇ¿¡¼­ ¼³¸íµË´Ï´Ù.


¼ÒÇÁÆ®¿þ¾î ¼³Ä¡

ÀÌ ÀýÀº ¼ÒÇÁÆ®¿þ¾î ¼³Ä¡ ÇÁ·Î¼¼½º¸¦ ¼³¸íÇÕ´Ï´Ù. ¿¹Á¦ ½Ã³ª¸®¿À¸¦ À§ÇØ ¸ðµç ¿¹¿Ü»çÇ× ¶Ç´Â ½Ã³ª¸®¿À °ü·Ã ÁöħÀ» Á¦°øÇÕ´Ï´Ù. ¼ÒÇÁÆ®¿þ¾î ¼³Ä¡¿¡ ´ëÇÑ ÀÏ¹Ý ÁöħÀ» º¸·Á¸é ÀÌ ¾È³»¼­ÀÇ ´Ù¸¥ ºÎºÐÀ» ÂüÁ¶ÇϽʽÿÀ.



ÁÖ - ´ÙÀ½¿¡ ÀÖ´Â Áö½Ã¸¦ °ü·Ã »óȲÀ» Ãë±ÞÇϱâ À§ÇÑ ÅÛÇø®Æ®·Î¼­ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.



ÀÌ Àý¿¡´Â ´ÙÀ½ ÀÛ¾÷ÀÌ Æ÷ÇԵ˴ϴÙ.

º¸¾È ¼ÒÇÁÆ®¿þ¾î ´Ù¿î·Îµå ¹× ¼³Ä¡

¾Æ·¡¿Í °°ÀÌ JumpStart ¼­¹ö¿¡ Solaris Security Toolkit°ú ÆÐÄ¡¸¦ Æ÷ÇÔÇÑ Ãß°¡ º¸¾È ¼ÒÇÁÆ®¿þ¾î¸¦ ´Ù¿î·Îµå ¹× ¼³Ä¡ÇϽʽÿÀ.


procedure icon  º¸¾È ¼ÒÇÁÆ®¿þ¾î ´Ù¿î·Îµå ¹× ¼³Ä¡

1. Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿Í Ãß°¡ º¸¾È ¼ÒÇÁÆ®¿þ¾î¸¦ ´Ù¿î·Îµå ¹× ¼³Ä¡ÇϽʽÿÀ.

º¸¾È ¼ÒÇÁÆ®¿þ¾î ´Ù¿î·Îµå¸¦ ÂüÁ¶ÇϽʽÿÀ.

2. ´Ù¿î·ÎµåÇÑ Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿Í Ãß°¡ º¸¾È ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇϽʽÿÀ.

¼ÒÇÁÆ®¿þ¾î ¼³Ä¡ ¹× ½ÇÇàÀ» ÂüÁ¶ÇϽʽÿÀ.



caution icon

ÁÖÀÇ - ¾ÆÁ÷ Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¸¦ ½ÇÇàÇÏÁö ¸¶½Ê½Ã¿À. ¿ì¼± ´ÙÀ½ Àý¿¡ ¼³¸íµÇ¾î ÀÖ´Â Ãß°¡ ±¸¼º ¹× »ç¿ëÀÚ Á¤ÀǸ¦ ¼öÇàÇϽʽÿÀ.



ÆÐÄ¡ ¼³Ä¡

OS ÆÐÄ¡´Â º¸¾È Ãë¾à¼º, °¡¿ë¼º ¹®Á¦, ¼º´É °ü·Ã »çÇ× ¶Ç´Â ½Ã½ºÅÛÀÇ ´Ù¸¥ Ãø¸éÀ» ´Ù·ê ¼ö ÀÖ½À´Ï´Ù. »õ·Î¿î OS ¼³Ä¡½Ã, ±×¸®°í OS ¼³Ä¡ÈÄ Áö¼ÓÀûÀ¸·Î ÀûÀýÇÑ ÆÐÄ¡°¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇϽʽÿÀ.

Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î´Â SunSolve Online¿¡¼­ ÀÌ¿ë °¡´ÉÇÑ Recommended and Security Patch ClusterÀÇ ¼³Ä¡ ¹æ¹ýÀ» Á¦°øÇÕ´Ï´Ù. OS °ü·Ã Ŭ·¯½ºÅÍ ÆÐÄ¡¿¡´Â °¡Àå ÀϹÝÀûÀ¸·Î »ç¿ëµÇ´Â ÆÐÄ¡°¡ µé¾îÀÖ½À´Ï´Ù.


procedure icon  ÆÐÄ¡ ¼³Ä¡

1. ÃÖ¼ÒÇÑ Recommended and Security Patch Cluster¸¦ Patches µð·ºÅ丮¿¡ ´Ù¿î·ÎµåÇÏ°í ¾ÐÃàÀ» ÇØÁ¦ÇÕ´Ï´Ù.

install-recommended-patches.fin ½ºÅ©¸³Æ®°¡ °­È­ µå¶óÀ̹ö¿¡ Æ÷ÇԵǴ °æ¿ì ÇØ´ç ÆÐÄ¡ Ŭ·¯½ºÅͰ¡ ÀÚµ¿À¸·Î ¼³Ä¡µË´Ï´Ù.

Check PointFirewall-1 NG¿¡ Ãß°¡ ¹®Á¦Á¡ÀÌ ÀÖ½À´Ï´Ù. ÀÌ ÀÀ¿ë ÇÁ·Î±×·¥Àº Recommended and Security Patch Cluster¿¡ µé¾îÀÖÁö ¾ÊÀº ƯÁ¤ ÆÐÄ¡°¡ ÇÊ¿äÇÕ´Ï´Ù. Check PointFirewall-1 NG´Â ´ÙÀ½ ÆÐÄ¡¸¦ ÇÊ¿ä·Î ÇÕ´Ï´Ù.

2. ÆÐÄ¡ 108434 ¹× 108435ÀÇ ¼³Ä¡¸¦ ÀÚµ¿È­Çϱâ À§ÇØ, SunSolve OnLine¿¡¼­ ÃֽйöÀüÀ» ´Ù¿î·ÎµåÇÏ¿© Patches µð·ºÅ丮¿¡ ÀúÀåÇÕ´Ï´Ù.

3. °¢ ÆÐÄ¡ÀÇ À̸§°ú ÇÔ²² add_patch Áö¿ø ÇÁ·Î±×·¥ ±â´ÉÀ» È£ÃâÇÏ´Â »õ·Î¿î Á¾·á ½ºÅ©¸³Æ®(¿¹: fw1-patch-install.fin)¸¦ ÀÛ¼ºÇÕ´Ï´Ù.

ÀÌ Á¾·á ½ºÅ©¸³Æ®´Â µÎ °³ÀÇ Check PointFirewall-1 NG Çʼö ÆÐÄ¡ ID¿Í ÇÔ²² ÀûÀýÇÑ Áö¿ø ÇÁ·Î±×·¥ ±â´ÉÀ» È£ÃâÇÕ´Ï´Ù. ¿¹¸¦ µé¸é,


#!/bin/sh
# add_patch 108434-10
# add_patch 108435-10

 

OS Cluster ÁöÁ¤ ¹× ¼³Ä¡

OS ¼³Ä¡¸¦ À§ÇÑ µð½ºÅ© ·¹À̾ƿôÀ» Á¤ÀÇÇÑ ÈÄ, ¼³Ä¡ÇÒ Solaris OS Ŭ·¯½ºÅ͸¦ ÁöÁ¤ÇÕ´Ï´Ù. Solaris OS¿Í ÇÔ²² »ç¿ë °¡´ÉÇÑ ´Ù¼¸ °³ÀÇ ¼³Ä¡ Ŭ·¯½ºÅÍ SUNWCreq, SUNWCuser, SUNWCprog, SUNWCall ¹× SUNWCXall Áß Çϳª¸¦ ¼±ÅÃÇϽʽÿÀ.


procedure icon  OS Ŭ·¯½ºÅÍ ÁöÁ¤ ¹× ¼³Ä¡

1. ¼³Ä¡ÇÒ OS Ŭ·¯½ºÅ͸¦ ÁöÁ¤ÇÕ´Ï´Ù.

ÀÌ »ç·Ê ½Ã³ª¸®¿ÀÀÇ ¸ñÇ¥°¡ ÃÖ¼ÒÈ­ ¹× Àü¿ë ¹æÈ­º® µð¹ÙÀ̽º¸¦ ±¸ÃàÇÏ´Â °ÍÀ̱⠶§¹®¿¡ »ç¿ë °¡´ÉÇÑ Solaris OS Ŭ·¯½ºÅÍ Áß °¡Àå ÀÛÀº SUNWCreq¸¦ ¼±ÅÃÇÕ´Ï´Ù. ÀÌ ÆÐŰÁö¸¦ CoreÇÏ°íµµ ÇÕ´Ï´Ù.

ÀÌ Å¬·¯½ºÅÍ´Â »ó´ëÀûÀ¸·Î ÀûÀº ¼öÀÇ ÆÐŰÁö¸¦ Æ÷ÇÔÇϹǷΠ´Ù¸¥ ÆÐŰÁö°¡ ÇÊ¿äÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ´Ù¸¥ Çʼö ÆÐŰÁö°¡ Solaris OS Ŭ·¯½ºÅÍ Á¤Àǰ¡ ÀÖ´Â ÇÁ·ÎÆÄÀÏ¿¡ Æ÷ÇԵǾî¾ß ÇÕ´Ï´Ù.

±âÁØ ÇÁ·ÎÆÄÀÏ Á¤ÀÇ´Â ´ÙÀ½À» ÀÌÀü¿¡ Á¤ÀÇµÈ ÇÁ·ÎÆÄÀÏ¿¡ Ãß°¡ÇÕ´Ï´Ù.


cluster SUNWCreq


 

SUNWCreq ¼³Ä¡ Ŭ·¯½ºÅÍ´Â ¹æÈ­º® Sun ¼­¹ö°¡ ¿Ã¹Ù¸£°Ô ±â´ÉÇϱâ À§ÇØ ÇʼöÀûÀÌÁö ¾ÊÀº ÆÐŰÁö¸¦ Æ÷ÇÔÇÕ´Ï´Ù. ÀÛ¾÷ ±âÁØÀ» Á¤ÇÑ ÈÄ ÀÌ·¯ÇÑ ¿©ºÐÀÇ ÆÐŰÁö¸¦ Á¦°ÅÇϽʽÿÀ. Sun BluePrints OnLine ±â»ç "Minimizing the Solaris Operating Environment for Security: Updated for the Solaris 9 Operating Environment"¸¦ ÂüÁ¶ÇϽʽÿÀ.

2. ÀûÀýÈ÷ Á¤ÀÇµÈ º¸¾È ÇÁ·ÎÆÄÀϰú ÇÔ²² ¼³Ä¡¸¦ ½ÇÇàÇÏ¿© ÆÐŰÁö Á¾¼Ó ¹®Á¦°¡ ÀÖ´ÂÁö ÆÇº°ÇϽʽÿÀ.

ÀϺΠÆÐŰÁö Á¾¼Ó¼ºÀÌ ¼³Ä¡½Ã ¹ß»ýµÇ¾ú°í, ´ÙÀ½ Solaris OS ÆÐŰÁö°¡ Check PointFirewall-1 NG¿¡ ÇÊ¿äÇÏ´Ù°í °áÁ¤ÇÏ¿´½À´Ï´Ù.

ÇÁ·ÎÆÄÀÏÀÇ Àüü ÆÐŰÁö ¸ñ·ÏÀº ´ÙÀ½°ú °°½À´Ï´Ù.


cluster SUNWCreq

package SUNWter add

package SUNWlibC add

package SUNWlibCx add

package SUNWadmc add

package SUNWadmfw add


 

ÀÌ ¸ñ·ÏÀº º» »ç·Ê ¿¬±¸¿¡´Â ¿Ïº®ÇÏÁö¸¸, ÀÌ ±¸¼ºÀÌ Àü°³µÉ ½ÇÁ¦ ȯ°æ¿¡ µû¶ó Ãß°¡ ÆÐŰÁö¸¦ Ãß°¡ ¶Ç´Â Á¦°ÅÇØ¾ß ÇÒ ¼ö ÀÖ½À´Ï´Ù.

ǰÁú º¸Áõ °Ë»ç¿¡ ¼³¸íµÈ °Íó·³ ½Ã½ºÅÛÀÌ ±â´É ¹× º¸¾È Ãø¸é ¸ðµÎ¿¡¼­ °ËÁõµÉ ¶§±îÁö ÆÐŰÁöÀÇ ÃÖÁ¾ ¸ñ·ÏÀº ¼öÁ¤ÀÌ ÇÊ¿äÇÒ ¼ö ÀÖ½À´Ï´Ù. ¼öÁ¤ÀÌ ÇÊ¿äÇÑ °æ¿ì ÇÁ·ÎÆÄÀÏÀ» ¼öÁ¤ÇÏ°í ½Ã½ºÅÛÀ» À缳ġÇÑ ÈÄ Å×½ºÆ®¸¦ ¹Ýº¹ÇϽʽÿÀ.

3. ÀÌÀü µÎ ´Ü°èÀÇ ÆÐŰÁö Á¾¼Ó¼ºÀ» ±âÃÊ·Î minimize-firewall.fin ½ºÅ©¸³Æ®¸¦ ÀÛ¼ºÇÕ´Ï´Ù.


JumpStart ¼­¹ö ¹× Ŭ¶óÀÌ¾ðÆ® ±¸¼º

ÀÌ ÀýÀº ÃÖ¼ÒÈ­¸¦ À§ÇØ »ç¿ëÀÚ Á¤ÀÇ º¸¾È ÇÁ·ÎÆÄÀÏÀ» »ç¿ëÇϵµ·Ï JumpStart ¼­¹ö ¹× Ŭ¶óÀÌ¾ðÆ®¸¦ ±¸¼ºÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. JumpStart ȯ°æ¿¡¼­ Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î »ç¿ë¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸´Â 5 ÀåÀ» ÂüÁ¶ÇϽʽÿÀ.

ÀÌ Àý¿¡´Â ´ÙÀ½ ÀÛ¾÷ÀÌ Æ÷ÇԵ˴ϴÙ.

±â¹Ý±¸Á¶ Áغñ

±â¹Ý±¸Á¶¸¦ ÁغñÇÏ·Á¸é ´ÙÀ½ ÀÛ¾÷À» ¼öÇàÇϽʽÿÀ. ´ÙÀ½ ÀÛ¾÷Àº ±âÁ¸ µå¶óÀ̹ö, ÇÁ·ÎÆÄÀÏ ¹× Á¾·á ½ºÅ©¸³Æ®¸¦ »ç¿ëÇϴ Ŭ¶óÀÌ¾ðÆ®¸¦ À§ÇÑ ±âÁØ ±¸¼º ÀÛ¼º ÇÁ·Î¼¼½º¸¦ ¼³¸íÇÕ´Ï´Ù. ÀÌ ±âÁØÀÌ Àû¿ëµÈ ÈÄ, Á¦´ë·Î ÀÛµ¿ÇÏ´ÂÁö È®ÀÎÇÏ°í ¼±ÅÃµÈ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¸Â°Ô »ç¿ëÀÚ Á¤ÀÇÇϽʽÿÀ.


procedure icon  ±â¹Ý±¸Á¶ Áغñ

1. JumpStart ¼­¹ö ¹× ȯ°æÀ» ±¸¼ºÇÕ´Ï´Ù.

ÀÚ¼¼ÇÑ Áöħ¿¡ ´ëÇØ¼­´Â 5 ÀåÀ» ÂüÁ¶ÇϽʽÿÀ.

2. add-client ¸í·ÉÀ» »ç¿ëÇÏ¿© JumpStart ¼­¹ö¿¡ Ŭ¶óÀÌ¾ðÆ®¸¦ Ãß°¡ÇÕ´Ï´Ù.


ÄÚµå ¿¹ 7-1 JumpStart ¼­¹ö¿¡ Ŭ¶óÀÌ¾ðÆ® Ãß°¡

# pwd
/jumpstart
# bin/add-client -c jordan -o Solaris_8_2002-02 -m sun4u -s nomex-jumpstart
cleaning up preexisting install client "jordan"
removing jordan from bootparams
updating /etc/bootparams

 

3. ÀûÀýÇÑ JumpStart ÇÁ·ÎÆÄÀÏ ¹× Á¾·á ½ºÅ©¸³Æ®¸¦ ÁöÁ¤ÇÏ¿© Ŭ¶óÀÌ¾ðÆ®¸¦ À§ÇÑ rules ÆÄÀÏ Ç׸ñÀ» ÀÛ¼ºÇÕ´Ï´Ù. ¿¹¸¦ µé¸é,


hostname jordan - Profiles/xsp-minimal-firewall.profile \
  Drivers/xsp-firewall-secure.driver

 

4. Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿Í ÇÔ²² Á¦°øµÈ ÆÄÀÏÀ» º¹»çÇÏ¿© xsp-minimal-firewall.profileÀ̶ó´Â ÇÁ·ÎÆÄÀÏ ÆÄÀÏ ¹× xsp-firewall-secure.driver¶ó´Â µå¶óÀ̹ö ÆÄÀÏÀ» ÀÛ¼ºÇÕ´Ï´Ù.

ÀÌ·¯ÇÑ ÆÄÀÏÀ» ÀÛ¼ºÇØ¾ß ´ÙÀ½ ´Ü°è¸¦ ¼º°øÀûÀ¸·Î ¿Ï·áÇÒ ¼ö ÀÖ½À´Ï´Ù. óÀ½¿¡ ÀÌ·¯ÇÑ ÆÄÀÏÀº Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿Í ÇÔ²² ¹èÆ÷µÈ ÆÄÀÏÀÇ »çº»ÀÏ ¼ö ÀÖ½À´Ï´Ù. Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿Í ÇÔ²² ¹èÆ÷µÈ ¿øº» ÆÄÀÏÀ» Àý´ë ¼öÁ¤ÇÏÁö ¸¶½Ê½Ã¿À. ´ÙÀ½ ¿¹Á¦´Â ÆÄÀÏÀ» ÀÛ¼ºÇÏ´Â ¹æ¹ýÀ» º¸¿©ÁÝ´Ï´Ù.


ÄÚµå ¿¹ 7-2 ÇÁ·ÎÆÄÀÏ ÀÛ¼º

# pwd
/jumpstart/Drivers
# cp install-Sun_ONE-WS.driver xsp-firewall-secure.driver
# cp hardening.driver xsp-firewall-hardening.driver
[...]
# pwd 
/jumpstart/Profiles
# cp minimal-Sun_ONE-WS-Solaris8-64bit.profile \
     xsp-minimal-firewall.profile

 

ÀÌ ¿¹Á¦´Â Àü¿ë ¹æÈ­º®À» °³¹ßÇϱâ ÁÁÀº ±âÁؼ±À̹ǷΠÀü¿ë À¥ ¼­¹ö ±¸¼ºÀ» ±âÁØÀ¸·Î ÇÕ´Ï´Ù.

5. ÇÁ·ÎÆÄÀÏ ¹× µå¶óÀ̹ö ÆÄÀÏÀ» ÀÛ¼ºÇÑ ÈÄ ´ÙÀ½°ú °°ÀÌ ÆÄÀÏÀ» ¼öÁ¤ÇÕ´Ï´Ù.

a. hardening.driver¿¡ ´ëÇÑ xsp-firewall-secure.driver ÂüÁ¶¸¦ xsp-firewall-hardening.driver·Î ±³Ã¼ÇÕ´Ï´Ù.

b. JASS_SCRIPTS¿¡ Á¤ÀÇµÈ µÎ Á¾·á ½ºÅ©¸³Æ®¸¦ minimize-firewall.fin¿¡ ´ëÇÑ ÂüÁ¶ ¹× »ç¿ëÀÚÀÇ Á¾·á ½ºÅ©¸³Æ®(¿¹: fw1-patch-install.fin)·Î ±³Ã¼ÇÕ´Ï´Ù.

¼öÁ¤µÈ ½ºÅ©¸³Æ®´Â ´ÙÀ½°ú À¯»çÇØ¾ß ÇÕ´Ï´Ù.


ÄÚµå ¿¹ 7-3 ¼öÁ¤µÈ ½ºÅ©¸³Æ®ÀÇ Ãâ·Â ¿¹Á¦

DIR="'/bin/dirname $0'"
export DIR
. ${DIR}/driver.init
. ${DIR}/config.driver
JASS_SCRIPTS="
                minimize-firewall.fin
                fw1-patch-install.fin"
. ${DIR}/driver.run
. ${DIR}/xsp-firewall-hardening.driver

 

6. ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© rules ÆÄÀÏ Ç׸ñÀÌ ¿Ã¹Ù¸¥Áö È®ÀÎÇϽʽÿÀ.


ÄÚµå ¿¹ 7-4 rules ÆÄÀÏÀÇ Á¤È®¼º °Ë»ç

# pwd
/jumpstart
# ./check
Validating rules...
Validating profile Profiles/end-user.profile...
Validating profile Profiles/xsp-minimal-firewall.profile...
Validating profile Profiles/test.profile...
Validating profile Profiles/entire-distribution.profile...
Validating profile Profiles/oem.profile...
The custom JumpStart configuration is ok.

 

ÀÌ ½ÃÁ¡¿¡¼­, ÀÌ ¿¹Á¦ÀÇ jordan Ŭ¶óÀÌ¾ðÆ®¿¡¼­ JumpStart ¼³Ä¡¸¦ ½ÃÀÛÇÏ´Â °ÍÀÌ °¡´ÉÇØ¾ß ÇÕ´Ï´Ù. ÀÛ¼ºÇÑ JumpStart ±¸¼º°ú Solaris Security Toolkit µå¶óÀ̹ö, Á¾·á ½ºÅ©¸³Æ® ¹× ÇÁ·ÎÆÄÀÏÀ» »ç¿ëÇÕ´Ï´Ù.

7. rules ÆÄÀÏÀ» °Ë»çÇÒ ¶§ ¹®Á¦Á¡ÀÌ ¹ß»ýÇÏ´Â °æ¿ì Rules ÆÄÀÏ È®ÀÎ ¹× °Ë»ç¸¦ ÂüÁ¶ÇϽʽÿÀ.

8. Ŭ¶óÀ̾ðÆ®ÀÇ ok ÇÁ·ÒÇÁÆ®¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÏ¿© JumpStart ±â¹Ý±¸Á¶¸¦ »ç¿ëÇϴ Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇÕ´Ï´Ù.


ok> boot net - install

 

Ŭ¶óÀÌ¾ðÆ®°¡ ¼³Ä¡µÇÁö ¾Ê´Â °æ¿ì ±¸¼ºÀ» °ËÅäÇÏ¿© ÀûÀýÈ÷ µ¿ÀÛÇÒ ¶§±îÁö ±¸¼ºÀ» ¼öÁ¤ÇϽʽÿÀ. ÀÌ Àý¿¡¼­ JumpStart ±¸¼ºÀÇ ¸ðµç ºÎºÐÀÌ ¾ð±ÞµÇÁö´Â ¾Ê½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Sun BluePrint ¼³¸í¼­ JumpStart Technology: Effective Use in the Solaris Operating Environment¸¦ ÂüÁ¶ÇϽʽÿÀ.

rules ÆÄÀÏÀÇ ¿Ã¹Ù¸¥ ½ÇÇàÀ» ´Þ¼ºÇÏ°í ÆÐÄ¡°¡ Á¦´ë·Î ¼³Ä¡µÇ¾úÀ½À» È®ÀÎÇÑ ´ÙÀ½, Ŭ¶óÀÌ¾ðÆ® ½Ã½ºÅÛÀÇ ±âº» ·¹º§ ¼³Ä¡ ¹× ±×ÀÇ ÃÖ¼ÒÈ­ ¹× °­È­¸¦ ½ÃÀÛÇÒ ¼ö ÀÖ½À´Ï´Ù.

Rules ÆÄÀÏ È®ÀÎ ¹× °Ë»ç

rules ÆÄÀÏÀÇ Á¤È®¼ºÀ» È®ÀÎÇÒ ¶§, ´Ù¾çÇÑ ¹®Á¦Á¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀϹÝÀûÀÎ ¹®Á¦ ¸î °¡Áö°¡ ÀÌ Àý¿¡¼­ ¾ð±ÞµË´Ï´Ù.

rules ÆÄÀÏÀ» óÀ½ ½ÇÇàÇÏ¸é ´ÙÀ½ Ãâ·ÂÀÌ ³ªÅ¸³³´Ï´Ù.


ÄÚµå ¿¹ 7-5 rules ÆÄÀÏÀÇ ¿¹Á¦ Ãâ·Â

# pwd
/jumpstart
# ./check
Validating rules...
Validating profile Profiles/xsp-minimal-firewall.profile...
Error in file "rules", line 20
hostname jordan - Profiles/xsp-minimal-firewall.profile Drivers/xsp-firewall-secure.driver
¿À·ù: Profile missing: 
   Profiles/xsp-minimal-firewall.profile

 

ÀÌ ¿¹Á¦¿¡¼­, jordan¿¡ ´ëÇÑ rules Ç׸ñ¿¡ ÁöÁ¤µÈ ÇÁ·ÎÆÄÀÏÀÌ Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù. xsp-minimal-firewall.profile ÇÁ·ÎÆÄÀÏÀº profiles µð·ºÅ丮¿¡ Á¸ÀçÇÏÁö ¾Ê¾Ò½À´Ï´Ù. ÀϹÝÀûÀ¸·Î ÀÌ ¿À·ù´Â ÆÄÀÏ À̸§ÀÇ À߸øµÈ öÀÚ, ÇÁ·ÎÆÄÀÏÀÇ ¿Ã¹Ù¸¥ µð·ºÅ丮 ÁöÁ¤ »ý·« ¶Ç´Â ÇÁ·ÎÆÄÀÏÀ» ÀÛ¼ºÇÏÁö ¾ÊÀº ÀÌÀ¯·Î ¹ß»ýµË´Ï´Ù. ¹®Á¦Á¡À» ¼öÁ¤ÇÏ°í °Ë»ç¸¦ Àç½ÇÇàÇϽʽÿÀ.

µÎ ¹øÂ° ½ÇÇàÀº ´Ù¸¥ µÎ °³ÀÇ ¹®Á¦Á¡À» º¸ÀÔ´Ï´Ù. ù ¹øÂ° ¹®Á¦Á¡Àº xsp-firewall-secure.driver¿¡¼­ È£ÃâµÇ´Â µå¶óÀ̹öÀÔ´Ï´Ù. xsp-firewall-hardening.driver¸¦ È£ÃâÇÏ´Â ´ë½Å, xsp-firewall-secure.driver°¡ ¿©ÀüÈ÷hardening.driver¸¦ È£ÃâÇϰí ÀÖ½À´Ï´Ù.

µÎ ¹øÂ° ¹®Á¦Á¡Àº JASS_SCRIPTS º¯¼ö°¡ minimize-firewall.fin ´ë½Å¿¡ minimize-Sun_ONE-WS.finÀ¸·Î À߸ø ¼³Á¤µÈ´Ù´Â °ÍÀÔ´Ï´Ù.

´ÙÀ½Àº À߸øµÈ ½ºÅ©¸³Æ®ÀÔ´Ï´Ù.


ÄÚµå ¿¹ 7-6 À߸øµÈ ½ºÅ©¸³Æ®ÀÇ ¿¹Á¦

#!/bin/sh

DIR="`/bin/dirname $0`"

export DIR

. ${DIR}/driver.init

. ${DIR}/config.driver

JASS_SCRIPTS="minimize-Sun_ONE-WS.fin"

. ${DIR}/driver.run

. ${DIR}/hardening.driver


 

´ÙÀ½Àº ¿Ã¹Ù¸¥ ½ºÅ©¸³Æ®ÀÇ ¿¹Á¦ÀÔ´Ï´Ù.


ÄÚµå ¿¹ 7-7 ¿Ã¹Ù¸¥ ½ºÅ©¸³Æ®ÀÇ ¿¹Á¦

#!/bin/sh

DIR="`/bin/dirname $0`"

export DIR

. ${DIR}/driver.init

. ${DIR}/config.driver

JASS_SCRIPTS="

minimize-firewall.fin"

. ${DIR}/driver.run

. ${DIR}/xsp-firewall-hardening.driver


 


°­È­ ±¸¼º »ç¿ëÀÚ Á¤ÀÇ

Á¦¾ÈµÈ ¹æÈ­º®ÀÇ °­È­ ±¸¼ºÀº »ç¿ëÀÚ Á¤Àǵǰí Á¤±³ÇÏ°Ô Á¶ÀýµÉ Áغñ°¡ µÇ¾ú½À´Ï´Ù. Ãʱ⠽ºÅ©¸³Æ®´Â hardening.driver¸¦ ±âÃÊ·Î ÇÕ´Ï´Ù. ÀÌ´Â ½Ã½ºÅÛÀÌ ¸ðµç ¼­ºñ½º¸¦ »ç¿ëÇÒ ¼ö ¾ø´Â "warm-brick" »óÅÂÀÓÀ» ÀǹÌÇÕ´Ï´Ù.

Solaris 8 OS¿¡ Secure Shell Ŭ¶óÀÌ¾ðÆ®°¡ Æ÷ÇԵǾî ÀÖÁö ¾ÊÀ¸¹Ç·Î, ¹æÈ­º®ÀÇ ¿ø°Ý ³×Æ®¿öÅ© ±â¹Ý °ü¸®°¡ °¡´ÉÇϵµ·Ï ¼öÁ¤ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ »ç·Ê ½Ã³ª¸®¿ÀÀÇ ¹æÈ­º®ÀÇ °æ¿ì, FTP ¼­ºñ½º°¡ »ç¿ë °¡´É »óÅ·Π³²¾ÆÀÖ°í ¿ø°Ý °ü¸®¸¦ À§ÇØ Secure Shell Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. ÀÌµé ¼­ºñ½º¸¦ ¸ðµÎ °³ÀÎ °ü¸® ³×Æ®¿öÅ©¸¸À¸·Î Á¦ÇÑÇÔÀ¸·Î½á ´Ù¸¥ ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽º¿¡¼­ Á¢¼ÓÇÏÁö ¸øÇϵµ·Ï ÇϽʽÿÀ. ÀÌ·¯ÇÑ ¼­ºñ½º Á¦ÇÑ¿¡ ´ëÇÑ Á¤º¸¿¡ ´ëÇØ¼­´Â, Sun BluePrints OnLine ±â»ç "Solaris Operating Environment Security: Updated for the Solaris 9 Operating Environment"¸¦ ÂüÁ¶ÇϽʽÿÀ.

ÀÌµé µÎ ¼­ºñ½º¸¦ »ç¿ë °¡´ÉÇÑ »óÅ·ΠµÎ´Â °Í ¿Ü¿¡, µð½ºÅ© ¹Ì·¯¸µÀ» À§ÇØ Solstice DiskSuite¸¦ ±¸¼ºÇÏ´Â µ¥ Solstice DiskSuite ±×·¡ÇÈ »ç¿ëÀÚ ÀÎÅÍÆäÀ̽º(GUI)¸¦ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï RPC ¼­ºñ½º¸¦ »ç¿ë °¡´ÉÇÑ »óÅ·ΠµÎ½Ê½Ã¿À. Solstice DiskSuite GUI¸¦ »ç¿ëÇÏÁö ¾ÊÀ» °æ¿ì, RPC ¼­ºñ½º´Â ÇÊ¿äÇÏÁö ¾Ê½À´Ï´Ù. ÀÌ ¿¹Á¦¿¡¼­´Â GUI°¡ ÇÊ¿äÇϹǷΠRPC ¼­ºñ½º´Â »ç¿ë °¡´ÉÇÑ »óÅ·Π³²¾ÆÀÖ½À´Ï´Ù. Solstice DiskSuiteÀÇ ¼³Ä¡ ¹× ±¸¼ºÀº ÀÌ ¼³¸í¼­¿¡¼­ ´Ù·çÁö ¾Ê½À´Ï´Ù.

ÀÌ Å¬¶óÀÌ¾ðÆ®¿¡ ÇÊ¿äÇÑ ÃÖÁ¾ ¼öÁ¤Àº xSP(¼­ºñ½º Á¦°øÀÚ)ÀÇ Áß¾Ó ÁýÁßµÈ SYSLOG ¼­¹ö¸¦ »ç¿ëÇÏ´Â »ç¿ëÀÚ Á¤ÀÇµÈ syslog.conf°¡ Á¤±³ÇÏ°Ô ¸¸µé¾îÁö´Â °ÍÀÔ´Ï´Ù. ÀÌ »ç¿ëÀÚ Á¤ÀÇµÈ syslog.conf ÆÄÀÏÀÌ °¢ ¹æÈ­º® ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ¾î¾ß ÇÕ´Ï´Ù.

ÀÌ ¼öÁ¤À» À§Çؼ­´Â Solaris Security ToolkitÀÇ ±¸¼º ¿É¼ÇÀ» º¯°æÇØ¾ß ÇÕ´Ï´Ù. ÇÊ¿äÇÑ °¢ ¼öÁ¤»çÇ×ÀÌ ´ÙÀ½ Àý¿¡¼­ »ó¼¼È÷ ¼³¸íµË´Ï´Ù.

FTP ¼­ºñ½º »ç¿ë

ÀÌ »ç·Ê ½Ã³ª¸®¿ÀÀÇ ¹æÈ­º®ÀÇ °æ¿ì FTP ¼­ºñ½º¸¦ »ç¿ë °¡´ÉÇÏ°Ô ÇϽʽÿÀ.


procedure icon  FTP ¼­ºñ½º »ç¿ë

1. FTP¸¦ »ç¿ë °¡´ÉÇÑ »óÅ·ΠµÎ±â À§ÇØ, JASS_SVCS_DISABLE ¹× JASS_SVCS_ENABLE º¯¼ö¸¦ ¼³Á¤ÇÏ¿© update-inetd-conf.fin ÆÄÀÏÀÇ ±âº» µ¿ÀÛÀ» ¼öÁ¤ÇÕ´Ï´Ù.

FTP¸¦ Á¦¿ÜÇÑ ¸ðµç Ç¥ÁØ Solaris OS ¼­ºñ½º¸¦ »ç¿ë ºÒ°¡´ÉÇÏ°Ô ÇÏ·Á¸é, º» »ç·Ê ½Ã³ª¸®¿À¿¡ ´ëÇÑ ÃÖ¼±ÀÇ ¹æ¹ýÀº JASS_SVCS_DISABLEÀÌ finish.init ½ºÅ©¸³Æ®¿¡¼­ ¹ÞÀº ±âº»°ªÀ¸·Î ³²¾ÆÀÖ´ÂÁö È®ÀÎÇϸ鼭 JASS_SVCS_ENABLEÀÌ ftp°¡ µÇµµ·Ï Á¤ÀÇÇÏ´Â °ÍÀÌ´Ù. Solaris Security Toolkit 4.1 Reference ManualÀ» ÂüÁ¶ÇϽʽÿÀ.

2. ȯ°æ º¯¼ö¸¦ ÅëÇØ º¯°æÀ» ±¸ÇöÇϱâ À§ÇØ xsp-firewall-hardening.driver¿¡ ´ëÇÑ È£Ãâ Àü¿¡ ´ÙÀ½°ú ºñ½ÁÇÑ Ç׸ñÀ» xsp-firewall-secure.driver¿¡ Ãß°¡ÇÕ´Ï´Ù.


JASS_SVCS_ENABLE="ftp"


 

3. FTP°¡ ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î¸¦ ÅëÇØ ½ÇÇàÇÔÀ¸·Î½á ½Ã½ºÅÛ °ü¸®ÀÚÀÇ °ü¸® ³×Æ®¿öÅ©¿¡¼­¸¸ »ç¿ë °¡´ÉÇÑÁö È®ÀÎÇÕ´Ï´Ù.

¶Ç ´Ù¸¥ ¿ä±¸»çÇ×Àº FTP°¡ ½Ã½ºÅÛ °ü¸®ÀÚÀÇ °ü¸® ³×Æ®¿öÅ©¿¡¼­¸¸ »ç¿ë °¡´ÉÇÑÁö ¿©ºÎÀÔ´Ï´Ù. Solaris 8 OS¿¡¼­ TCP ·¦ÆÛ¸¦ ½Ã½ºÅÛ¿¡ ÅëÇÕÇÔÀ¸·Î½á ¶Ç´Â ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î ÀÚü¸¦ ÅëÇØ¼­ ÀÌ ¿ä±¸»çÇ×À» ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ »ç·Ê ½Ã³ª¸®¿À¿¡¼­´Â ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î¸¦ ÅëÇØ¼­ ¼öÇàÇϽʽÿÀ.

Secure Shell ¼ÒÇÁÆ®¿þ¾î ¼³Ä¡

Solaris 8 OS¿¡´Â Secure Shell Ŭ¶óÀÌ¾ðÆ®°¡ µé¾îÀÖÁö ¾ÊÀ¸¹Ç·Î, ¿ø°Ý °ü¸®¸¦ À§ÇØ Secure Shell Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇϽʽÿÀ.

Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¸¦ ±¸¼ºÇÏ¿© OpenSSH µµ±¸¸¦ ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. xsp-firewall-secure.driver¿¡ ÀÇÇØ »ç¿ëµÈ config.driver ÆÄÀÏ¿¡ ³ª¿­µÇ´Â install-openssh.fin ½ºÅ©¸³Æ®¸¦ »ç¿ëÇϽʽÿÀ.


procedure icon  Secure Shell ¼³Ä¡

1. ±âº» config.driver¸¦ xsp-firewall-config.driver¿¡ º¹»çÇÕ´Ï´Ù.

2. ÆÄÀÏ »çº»¿¡¼­ install-openssh.fin¿¡ ´ëÇÑ Ç׸ñÀ» ÁÖ¼®À¸·Î ó¸®ÇÕ´Ï´Ù.

3. xsp-firewall-config.driver¿¡¼­ config.driver¸¦ È£ÃâÇÏ´Â Ç׸ñÀ» ¼öÁ¤ÇÏ¿© ´ë½Å xsp-firewall-secure.driver¸¦ È£ÃâÇÕ´Ï´Ù.

4. OpenSSHÀÇ ÃֽйöÀüÀ» ±¸ÇÕ´Ï´Ù.

ÆÐÄ¡ ¹× OS ¸±¸®½ºÀÇ °æ¿ì¿Í ¸¶Âù°¡Áö·Î OpenSSHÀÇ ÃֽйöÀüÀ» »ç¿ëÇϽʽÿÀ. ÃֽЏ±¸®½º Á¤º¸´Â ´ÙÀ½ OpenSSH À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇϽʽÿÀ.

http://www.openssh.org

5. OpenSSH ÆÐŰÁö¸¦ ÄÄÆÄÀÏÇϰí, ÀûÀýÇÏ°Ô À̸§À» ÁöÁ¤ÇÑ ÈÄ Packagesµð·ºÅ丮¿¡ ¼³Ä¡ÇÕ´Ï´Ù.

ÀÌ ÆÐŰÁö¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸´Â, Sun BluePrints ¿Â¶óÀÎ ±â»ç "Configuring OpenSSH for the Solaris Operating Environment"¸¦ ÂüÁ¶ÇϽʽÿÀ.

6. ¿Ã¹Ù¸¥ OpenSSH ÆÐŰÁö À̸§À» ¹Ý¿µÇϵµ·Ï install-openssh.fin½ºÅ©¸³Æ®¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.

install-openssh.fin ½ºÅ©¸³Æ®¸¦ ¼öÁ¤ÇØ¾ß ÇÏ´Â °æ¿ì°¡ ÀÖ½À´Ï´Ù. ÀÌ ½ºÅ©¸³Æ®´Â OpenSSH ÆÐŰÁöÀÇ ÆÐŰÁö À̸§À» ´ÙÀ½°ú À¯»çÇÏ°Ô Çü½ÄÈ­µÇµµ·Ï Á¤ÀÇÇÕ´Ï´Ù.


OBSDssh-3.5p1-sparc-sun4u-5.8.pkg


 

¿©±â¼­ ÆÐŰÁö À̸§Àº ¹öÀü ¹øÈ£(3.5p1), ±¸Á¶(sparc), ±¸Á¶ÀÇ ¹öÀü(sun4u), ÆÐŰÁö°¡ ÄÄÆÄÀϵǴ ´ë»ó OS(5.8) ¹× pkg Á¢¹Ì¾îÀÇ Çü½ÄÀ» µû¸¨´Ï´Ù.

7. FTP°¡ ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î¸¦ ÅëÇØ ½ÇÇàÇÔÀ¸·Î½á ½Ã½ºÅÛ °ü¸®ÀÚÀÇ °ü¸® ³×Æ®¿öÅ©¿¡¼­¸¸ »ç¿ë °¡´ÉÇÑÁö È®ÀÎÇÕ´Ï´Ù.

¶Ç ´Ù¸¥ ¿ä±¸»çÇ×Àº FTP°¡ ½Ã½ºÅÛ °ü¸®ÀÚÀÇ °ü¸® ³×Æ®¿öÅ©¿¡¼­¸¸ »ç¿ë °¡´ÉÇÑÁö ¿©ºÎÀÔ´Ï´Ù. Solaris 8 OS¿¡¼­ TCP ·¦ÆÛ¸¦ ½Ã½ºÅÛ¿¡ ÅëÇÕÇÔÀ¸·Î½á ¶Ç´Â ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î ÀÚü¸¦ ÅëÇØ ÀÌ ¿ä±¸»çÇ×À» ±¸ÇöÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ »ç·Ê ½Ã³ª¸®¿ÀÀÇ °æ¿ì, ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î¸¦ ÅëÇØ ±¸ÇöÇÕ´Ï´Ù. ¶ÇÇÑ Secure Shell ¼­¹öÀÇ ±¸¼ºÀ» ¼öÁ¤ÇÏ¿© ±¸ÇöÇÒ ¼öµµ ÀÖ½À´Ï´Ù.

RPC ¼­¹ö »ç¿ë

RPC°¡ ÇÊ¿äÇÑ µð½ºÅ© ¹Ì·¯¸µÀ» À§ÇØ SDS¸¦ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï RPC ¼­ºñ½º¸¦ »ç¿ë °¡´ÉÇÑ »óÅ·ΠµÎ½Ê½Ã¿À.

ÀÌ ¼öÁ¤Àº ƯÁ¤ Á¾·á ½ºÅ©¸³Æ®ÀÎ disable-rpc.fin°¡ Solaris Security Toolkit ½ÇÇà Áß¿¡ RPC ¼­ºñ½º¸¦ »ç¿ë ºÒ°¡´ÉÇÏ°Ô ÇÒ ¼ö Àֱ⠶§¹®¿¡ ºñ±³Àû °£´ÜÇÕ´Ï´Ù.



ÁÖ - ½Ã½ºÅÛÀÇ RPC ¼­ºñ½º¿¡ ¿ø°ÝÀ¸·Î ¾×¼¼½ºÇÏ´Â °ÍÀº ½Ã½ºÅÛ ¹æÈ­º® ±¸¼º¿¡ ÀÇÇØ ¸í¹éÈ÷ °ÅºÎµÇ¾î¾ß ÇÕ´Ï´Ù.




procedure icon  RPC »ç¿ë

single-step bulletxsp-firewall-hardening.driver¿¡¼­ disable-rpc.fin¿¡ ´ëÇÑ Ç׸ñÀ» ÁÖ¼®À¸·Î ó¸®ÇÕ´Ï´Ù.

½ºÅ©¸³Æ®¸¦ Á¦°ÅÇÏ´Â ´ë½Å ÁÖ¼®À¸·Î ó¸®ÇÏ¿© µå¶óÀ̹ö¿¡¼­ ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÒ ¼ö ¾øµµ·Ï ÇÕ´Ï´Ù. ÁÖ¼® °ªÀÇ Æ¯Á¤ Á¶ÇÕ¸¸ÀÌ Çã¿ëµÇ±â ¶§¹®¿¡ JASS_SCRIPTS Á¤ÀÇÀÇ Ç׸ñÀ» ÁÖ¼®È­ÇÒ ¶§ ÁÖÀÇÇϽʽÿÀ.

´ÙÀ½Àº Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î°¡ JASS_SCRIPTS Á¤ÀÇ¿¡¼­ ÁÖ¼® Ç¥½Ã±â·Î¼­ Çã¿ëÇÏ´Â °Í¿¡ ´ëÇØ driver.funcs script¿¡ µé¾îÀÖ´Â ÁÖ¼®ÀÔ´Ï´Ù.


#Very rudimentary comment handler. This code will only recognize
#comments where a single `#' is placed before the file name
#(separated by white space or not). It then will only skip the
#very next argument.

 

syslog.conf ÆÄÀÏ »ç¿ëÀÚ Á¤ÀÇ

ÀÌ Å¬¶óÀÌ¾ðÆ®¿¡ ÇÊ¿äÇÑ ÃÖÁ¾ ¼öÁ¤Àº xSP(¼­ºñ½º Á¦°øÀÚ)ÀÇ Áß¾Ó ÁýÁßµÈ SYSLOG ¼­¹ö¸¦ »ç¿ëÇÏ´Â »ç¿ëÀÚ Á¤ÀÇµÈ syslog.conf°¡ Á¤±³ÇÏ°Ô ¸¸µé¾îÁö´Â °ÍÀÔ´Ï´Ù. ÀÌ »ç¿ëÀÚ Á¤ÀÇµÈ syslog.conf ÆÄÀÏÀÌ °¢ ¹æÈ­º® ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ¾î¾ß ÇÕ´Ï´Ù.


procedure icon  syslog.conf ÆÄÀÏ »ç¿ëÀÚ Á¤ÀÇ

1. xSP Ç¥ÁØ syslog.conf ÆÄÀÏÀ» º¹»çÇÑ ÈÄ syslog.conf.jordan·Î À̸§À» ¹Ù²Ù°í Files/etc µð·ºÅ丮¿¡ ÀúÀåÇÕ´Ï´Ù.

Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î´Â ´Ù¾çÇÑ ÆÄÀÏ º¹»ç ¸ðµå¸¦ Áö¿øÇÕ´Ï´Ù. ÀÌ ±¸¼º¿¡ °¡Àå ÀûÇÕÇÑ ¿É¼ÇÀº syslog.conf ÆÄÀÏÀÌ jordan¿¡¸¸ º¹»çµÇµµ·Ï ½Ã½ºÅÛÀÇ È£½ºÆ® À̸§À» ÆÄÀÏ¿¡ Á¢¹Ì¾î·Î Ãß°¡ÇÏ´Â °ÍÀ¸·Î, ±×°ÍÀÌ °íÀ¯ÇÑ ¹æÈ­º® Ư¼º ¼öÁ¤»çÇ×À» °®±â ¶§¹®ÀÔ´Ï´Ù. ÀÌ °æ¿ì, Ŭ¶óÀÌ¾ðÆ®¸¦ jordanÀ̶ó°í ÇϹǷΠFiles/etc¿¡ »ç¿ëµÈ ½ÇÁ¦ ÆÄÀÏ À̸§Àº syslog.conf.jordanÀÔ´Ï´Ù. JASS_FILES Á¤ÀÇ´Â ÀÌ Á¢¹Ì¾î°¡ Ãß°¡µÇÁö ¾Ê¾Æ¾ß ÇÑ´Ù´Â °ÍÀ» ÁÖÀÇÇϽʽÿÀ. Á¢¹Ì¾î¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸´Â, Solaris Security Toolkit 4.1 Reference ManualÀ» ÂüÁ¶ÇϽʽÿÀ.

2. xSP Ç¥ÁØ syslog.conf ÆÄÀÏÀ» »ç¿ëÇÒ ¼ö ¾ø´Â °æ¿ì ´ÙÀ½°ú °°ÀÌ »ç¿ëÀÚ Á¤ÀÇ syslog.conf ÆÄÀÏÀ» ÀÛ¼ºÇÕ´Ï´Ù.

a. Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¿¡ Æ÷ÇÔµÈ syslog.conf ÆÄÀÏÀ» º¹»çÇÏ¿© syslog.conf.jordanÀ¸·Î À̸§À» ¹Ù²Û ´ÙÀ½ Files/etc µð·ºÅ丮¿¡ ÀúÀåÇÕ´Ï´Ù.

b. SYSLOG¿¡ ´ëÇØ xSP Ç¥ÁØÀ» ÁؼöÇϵµ·Ï syslog.conf.jordanÀ» ¼öÁ¤ÇÕ´Ï´Ù.

3. /etc/syslog.conf ÆÄÀÏÀÌ xsp-firewall-hardening.driverÀÇ JASS_FILES Á¤ÀÇ¿¡ ³ª¿­µÇ´ÂÁö È®ÀÎÇÕ´Ï´Ù.

±âº»ÀûÀ¸·Î xsp-firewall-hardening.driverÀÇ ¼öÁ¤µÈ JASS_FILE Á¤ÀÇ´Â ´ÙÀ½°ú °°ÀÌ ³ªÅ¸³³´Ï´Ù.


ÄÚµå ¿¹ 7-8 ¼öÁ¤µÈ xsp-firewall-hardening.driver ÀÇ Ãâ·Â ¿¹Á¦

JASS_FILES="

/etc/dt/config/Xaccess

/etc/init.d/inetsvc

/etc/init.d/nddconfig

/etc/init.d/set-tmp-permissions

/etc/issue

/etc/motd

/etc/notrouter

/etc/rc2.d/S00set-tmp-permissions

/etc/rc2.d/S07set-tmp-permissions

/etc/rc2.d/S70nddconfig

/etc/syslog.conf

"


 

ÀÌÁ¦ ¸ðµç Çʼö ¼öÁ¤»çÇ×ÀÌ ¸¸µé¾îÁ³½À´Ï´Ù. OSÀÇ ¼³Ä¡, ÃÖ¼ÒÈ­ ¹× °­È­´Â ƯÁ¤ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¸Â°Ô »ç¿ëÀÚ Á¤ÀÇµÇ°í ¿ÏÀüÈ÷ ÀÚµ¿È­µÇ¾ú½À´Ï´Ù. ¿ÏÀüÈ÷ ÀÚµ¿È­µÇÁö ¾ÊÀº À¯ÀÏÇÑ ÇÁ·Î¼¼½º´Â ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾î¿Í Solstice DiskSuiteÀÇ ±¸¼º ¹× ¼³Ä¡ÀÔ´Ï´Ù. JumpStart ±â¼úÀ» »ç¿ëÇÏ¿© ÀÌ·¯ÇÑ ±¸¼ºÀ» ¼öÇàÇÒ ¼öµµ ÀÖÁö¸¸, ÀÌ Ã¥¿¡¼­´Â ´Ù·çÁö ¾Ê½À´Ï´Ù. Sun BluePrints ¼³¸í¼­ JumpStart Technology: Effective Use in the Solaris Operating Environment¸¦ ÂüÁ¶ÇϽʽÿÀ.


Ŭ¶óÀÌ¾ðÆ® ¼³Ä¡

µå¶óÀ̹ö¿¡ ´ëÇÑ ¸ðµç ¼öÁ¤»çÇ×À» ÀÛ¼ºÇÑ µÚ ÀÌ Àý¿¡¼­ ¼³¸íÇÑ °Íó·³ Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇϽʽÿÀ.


procedure icon  Å¬¶óÀÌ¾ðÆ® ¼³Ä¡

1. µå¶óÀ̹ö¿¡ ´ëÇÑ ¸ðµç Çʼö ¼öÁ¤»çÇ×À» ÀÛ¼ºÇÑ ÈÄ, JumpStart ±â¹Ý±¸Á¶¸¦ »ç¿ëÇÏ¿© Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇÕ´Ï´Ù.

Ŭ¶óÀ̾ðÆ®ÀÇ ok ÇÁ·ÒÇÁÆ®¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.


ok> boot net - install

 

2. ¿À·ù°¡ ¹ß»ýÇÒ °æ¿ì, ¿À·ù¸¦ ¼öÁ¤Çϰí Ŭ¶óÀÌ¾ðÆ® OS¸¦ À缳ġÇÕ´Ï´Ù.


ǰÁú º¸Áõ °Ë»ç

ÇÁ·Î¼¼½ºÀÇ ¸¶Áö¸· ÀÛ¾÷Àº ½Ã½ºÅÛÀÌ Á¦°øÇÏ´Â ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ¼­ºñ½º°¡ ¿Ã¹Ù¸£°Ô ±â´ÉÇϰí ÀÖ´ÂÁö È®ÀÎÇÏ´Â °ÍÀÔ´Ï´Ù. ¶ÇÇÑ, ÀÌ ÀÛ¾÷Àº º¸¾È ÇÁ·ÎÆÄÀÏÀÌ Çʼö ¼öÁ¤»çÇ×À» ¼º°øÀûÀ¸·Î ÀÌÇàÇϰí ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.

¸ðµç ÀÌ»ó ¡Èijª ¹®Á¦Á¡ÀÌ °¨ÁöµÇ°í ½Å¼ÓÈ÷ Á¤Á¤µÇµµ·Ï ÇÏ·Á¸é, °­È­ ¹× ÃÖ¼ÒÈ­µÈ Ç÷§ÆûÀ» ÀçºÎÆÃÇÑ ´ÙÀ½ ÀÌ ÀÛ¾÷À» ½Å¼ÓÇÏ°í ²Ä²ÄÇÏ°Ô ¼öÇàÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ÇÁ·Î¼¼½º´Â ÇÁ·ÎÆÄÀÏ ¼³Ä¡ È®ÀÎ ¹× ÀÀ¿ë ÇÁ·Î±×·¥°ú ¼­ºñ½º ±â´É¼º È®ÀÎÀÇ µÎ ÀÛ¾÷À¸·Î ±¸ºÐµË´Ï´Ù.


procedure icon  ÇÁ·ÎÆÄÀÏ ¼³Ä¡ È®ÀÎ

Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î°¡ º¸¾È ÇÁ·ÎÆÄÀÏÀ» ¿À·ù ¾øÀÌ ¿Ã¹Ù¸£°Ô ¼³Ä¡Çß´ÂÁö È®ÀÎÇϱâ À§ÇØ ´ÙÀ½À» °ËÅäÇÏ°í Æò°¡ÇϽʽÿÀ.

1. ¼³Ä¡ ·Î±× ÆÄÀÏÀ» °ËÅäÇÕ´Ï´Ù.

ÀÌ ÆÄÀÏÀº JASS_REPOSITORY/jass-install-log.txt¿¡ ¼³Ä¡µË´Ï´Ù.



ÁÖ - ÀÌ ·Î±× ÆÄÀÏÀº Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î°¡ ½Ã½ºÅÛ¿¡ ¼öÇàÇÑ ÀÛ¾÷À» ÀÌÇØÇϱâ À§ÇÑ ÂüÁ¶·Î¼­ »ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. ½Ã½ºÅÛÀÇ °¢ ½ÇÇà¿¡ ´ëÇØ ½ÇÇà ½ÃÀÛ ½Ã°£À» ±âÃÊ·Î »õ ·Î±× ÆÄÀÏÀÌ µð·ºÅ丮¿¡ ÀúÀåµË´Ï´Ù. ÀÌµé ÆÄÀϰú JASS_REPOSITORY µð·ºÅ丮ÀÇ ´Ù¸¥ ¸ðµç ÆÄÀÏÀº Àý´ë Á÷Á¢ ¼öÁ¤Çؼ­´Â ¾ÈµË´Ï´Ù.



2. °¨»ç ¿É¼ÇÀ» »ç¿ëÇÏ¿© ½Ã½ºÅÛÀÇ º¸¾È ±¸¼ºÀ» Æò°¡ÇÕ´Ï´Ù.

°¨»ç ¿É¼Ç¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸´Â 6 ÀåÀ» ÂüÁ¶ÇϽʽÿÀ. ÀÌ ½Ã³ª¸®¿ÀÀÇ °æ¿ì, Ŭ¶óÀÌ¾ðÆ®¿¡¼­ Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÈ µð·ºÅ丮¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.


ÄÚµå ¿¹ 7-9 º¸¾È ±¸¼º Æò°¡

# ./jass-execute -a xsp-firewall-secure.driver
[NOTE] Executing driver, xsp-firewall-secure.driver
===================================================================
xsp-firewall-secure.driver: Driver started.
===================================================================
 
===================================================================
Solaris Security Toolkit Version:   4.1.0
[...]

 

Solaris Security Toolkit °ËÁõ ½ÇÇà½Ã ºÒÀÏÄ¡°¡ ¹ß°ßµÇ¸é, ÇØ´ç ºÒÀÏÄ¡´Â ±â·ÏµË´Ï´Ù. ½ÇÇà ¿Ï·á½Ã ¹ß°ßµÈ ÃÑ ºÒÀÏÄ¡ ¼ö°¡ ¿ä¾à¿¡¼­ º¸°íµË´Ï´Ù. ½ÇÇàÀÇ Àüü Ãâ·ÂÀº JASS_REPOSITORY µð·ºÅ丮¿¡ ÀÖ½À´Ï´Ù.


procedure icon  ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ¼­ºñ½º ±â´É È®ÀÎ

ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ¼­ºñ½º¿¡ ´ëÇÑ È®ÀÎ ÇÁ·Î¼¼½º¿¡´Â Àß Á¤ÀÇµÈ Å×½ºÆ® ¹× Çã¿ë °èȹÀÇ ½ÇÇàÀÌ Æ÷ÇԵ˴ϴÙ. ÀÌ °èȹÀº ½Ã½ºÅÛ ¶Ç´Â ÀÀ¿ë ÇÁ·Î±×·¥ÀÇ ´Ù¾çÇÑ ±¸¼º¿ä¼Ò¸¦ Á¶»çÇÏ¿© ±¸¼º¿ä¼Ò°¡ »ç¿ë °¡´ÉÇÑ »óÅ ¹× ÀÛ¾÷ ¸í·É »óÅ¿¡ ÀÖ´ÂÁö ÆÇº°Çϴµ¥ »ç¿ëµË´Ï´Ù. ÀÌ·¯ÇÑ °èȹÀÌ »ç¿ë ºÒ°¡´ÉÇÒ °æ¿ì, ½Ã½ºÅÛÀÇ »ç¿ë ¹æ¹ýÀ» ±âÃÊ·Î ½Ã½ºÅÛÀ» ÇÕ¸®ÀûÀ¸·Î °Ë»çÇϽʽÿÀ. °­È­ ÇÁ·Î¼¼½º´Â ÇØ´ç ±â´ÉÀ» ¼öÇàÇϱâ À§ÇØ ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ¼­ºñ½º ±â´É¿¡ ¿µÇâÀ» ¹ÌÄ¡Áö ¾ÊÀ½À» È®ÀÎÇÏ´Â °ÍÀÌ Áß¿äÇÕ´Ï´Ù.

1. ½Ã½ºÅÛÀÌ °­È­µÈ ÈÄ ÀÀ¿ë ÇÁ·Î±×·¥À̳ª ¼­ºñ½º°¡ Á¦´ë·Î ÀÛµ¿ÇÏÁö ¾ÊÀ½À» ¹ß°ßÇÏ´Â °æ¿ì 2 Àå¿¡ ¼³¸íµÈ ±â¹ýÀ» »ç¿ëÇÏ¿© ¹®Á¦Á¡À» ÆÇº°ÇϽʽÿÀ.

¿¹¸¦ µé¾î, truss ¸í·ÉÀ» »ç¿ëÇϽʽÿÀ. ÀÌ ¸í·ÉÀº ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ¹®Á¦°¡ ¹ß»ýÇÏ´Â ÁöÁ¡À» °áÁ¤Çϴµ¥ »ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÁöÁ¡À» ãÀ¸¸é ÀÌ ¹®Á¦¿¡ ´ëÇØ Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î·Î ÀÛ¾÷ÇÑ º¯°æ»çÇ×À» ´Ù½Ã ÃßÀûÇÒ ¼ö ÀÖ½À´Ï´Ù.



ÁÖ - Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î¸¦ Àü°³ÇÑ ¿©·¯ »ç¿ëÀÚÀÇ °æÇèÀ» Åä´ë·Î ÀÌ ¼³¸í¼­¿¡ ³ª¿À´Â Á¢±Ù ¹æ½ÄÀ» »ç¿ëÇÏ¸é ´ë´Ù¼öÀÇ ¹®Á¦Á¡À» ÇØ°áÇÒ ¼ö ÀÖ½À´Ï´Ù.



2. À¯»çÇÑ ¹æ¹ýÀ¸·Î Check PointFirewall-1 NG ¼ÒÇÁÆ®¿þ¾î¸¦ °Ë»çÇϰí, Solaris Security Toolkit ¼ÒÇÁÆ®¿þ¾î ¼öÁ¤À¸·Î ÀÎÇÑ ¸ðµç ¹®Á¦Á¡À» ´Ù½Ã ÃßÀûÇϰí, ¹®Á¦¸¦ Á¤Á¤ÇÕ´Ï´Ù.

3. ÆÐŰÁöÀÇ ÃÖÁ¾ ¸ñ·Ï¿¡ ¼öÁ¤ÀÌ ÇÊ¿äÇÑ °æ¿ì, ÇÁ·ÎÆÄÀÏÀ» ¼öÁ¤ÇÏ°í ½Ã½ºÅÛÀ» À缳ġÇÑ ÈÄ °Ë»ç¸¦ ¹Ýº¹ÇϽʽÿÀ.