git: d37975ff27 - main - Finish the sync of japanase handbook
Sergio Carlavilla Delgado
carlavilla at FreeBSD.org
Sun Feb 28 10:49:17 UTC 2021
The branch main has been updated by carlavilla:
URL: https://cgit.FreeBSD.org/doc/commit/?id=d37975ff27c7efe0ca351cb7c24c6c9a8243d6ff
commit d37975ff27c7efe0ca351cb7c24c6c9a8243d6ff
Author: Sergio Carlavilla Delgado <carlavilla at FreeBSD.org>
AuthorDate: 2021-02-28 10:48:21 +0000
Commit: Sergio Carlavilla Delgado <carlavilla at FreeBSD.org>
CommitDate: 2021-02-28 10:48:21 +0000
Finish the sync of japanase handbook
Chapters: X11, multimedia, security, l10n and cutting-edge.
With this last sync, all the handbook is finished.
---
.../ja/books/handbook/cutting-edge/_index.adoc | 20 +-
.../content/ja/books/handbook/l10n/_index.adoc | 28 +-
.../ja/books/handbook/multimedia/_index.adoc | 61 ++--
.../content/ja/books/handbook/security/_index.adoc | 326 +++++++++++----------
.../content/ja/books/handbook/x11/_index.adoc | 54 ++--
5 files changed, 269 insertions(+), 220 deletions(-)
diff --git a/documentation/content/ja/books/handbook/cutting-edge/_index.adoc b/documentation/content/ja/books/handbook/cutting-edge/_index.adoc
index b4b366b197..0ecc55b09a 100644
--- a/documentation/content/ja/books/handbook/cutting-edge/_index.adoc
+++ b/documentation/content/ja/books/handbook/cutting-edge/_index.adoc
@@ -71,7 +71,7 @@ toc::[]
[[updating-upgrading-freebsdupdate]]
== FreeBSD Update
-ãã¿ããã«ã»ãã¥ãªãã£ããããé©ç¨ãã ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ãæ°ãããªãªã¼ã¹ã«ã¢ããã°ã¬ã¼ããããã¨ã¯ã ã·ã¹ãã 管çã«ãããéè¦ãªå´é¢ã§ãã FreeBSD ã«ã¯ããããã®å¦çãè¡ãããã« `freebsd-update` ã¨å¼ã°ããã¦ã¼ãã£ãªãã£ãç¨æããã¦ãã¾ãã
+ãã¿ããã«ã»ãã¥ãªãã£ããããé©ç¨ãã ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ãã¢ããã°ã¬ã¼ããã¦ã ææ°ã®ãªãªã¼ã¹ã«ä¿ã¤ãã¨ã¯ãã·ã¹ãã 管çã«ãããéè¦ãªå´é¢ã§ãã ãããã®å¦çãè¡ãããã« FreeBSD ã«ã¯ `freebsd-update` ã¨å¼ã°ããã¦ã¼ãã£ãªãã£ãç¨æããã¦ãã¾ãã
ãã®ã¦ã¼ãã£ãªãã£ãç¨ããã¨ãFreeBSD ã®ã»ãã¥ãªãã£ããã³ eratta ã¢ãããã¼ãããã¤ããªã«ãã£ã¦è¡ããã¨ãã§ãã¾ãã æåã§ããããããã¯æ°ããã«ã¼ãã«ãã³ã³ãã¤ã«ãã ã¤ã³ã¹ãã¼ã«ããå¿
è¦ã¯ããã¾ããã ãã¤ããªã¢ãããã¼ãã¯ã ã»ãã¥ãªãã£ãã¼ã ããµãã¼ããã¦ãããã¹ã¦ã®ã¢ã¼ããã¯ãã£ã¨ãªãªã¼ã¹ã§å©ç¨ã§ãã¾ãã https://www.FreeBSD.org/ja/security/[https://www.FreeBSD.org/ja/security/] ã«ã¯ã ãµãã¼ããè¡ããã¦ãããªãªã¼ã¹ãä¿å®çµäºäºå®æ¥ã®ä¸è¦§ãããã¾ãã
@@ -198,7 +198,7 @@ Uninstalling updates... done.
[[freebsdupdate-upgrade]]
=== ã¡ã¸ã£ã¼ããã³ãã¤ãã¼ãã¼ã¸ã§ã³ã®ã¢ããã°ã¬ã¼ããè¡ã
-FreeBSD ã®ãã¤ãã¼ãã¼ã¸ã§ã³éã®ã¢ããã°ã¬ã¼ãã ãã¨ãã°ãFreeBSD 9.0 ãã FreeBSD 9.1 ã¸ã®ã¢ããã°ã¬ã¼ãã¯ã _ãã¤ãã¼ãã¼ã¸ã§ã³_ ã¢ããã°ã¬ã¼ãã¨å¼ã°ãã¾ãã _ã¡ã¸ã£ã¼ãã¼ã¸ã§ã³_ ã¢ããã°ã¬ã¼ãã¯ã FreeBSD 9.X ãã FreeBSD 10.X ã¸ã®ã¢ããã°ã¬ã¼ãã¨ãã£ãã FreeBSD ã®ã¡ã¸ã£ã¼ãã¼ã¸ã§ã³ãå¤ãããããªã¢ããã°ã¬ã¼ãã®ãã¨ã§ãã ã©ã¡ãã®ã¢ããã°ã¬ã¼ãããªãªã¼ã¹çªå·ã®ã¿ã¼ã²ãããæå®ããäºã§ã `freebsd-update` ã«ãã£ã¦è¡ãäºãã§ãã¾ãã
+FreeBSD ã®ãã¤ãã¼ãã¼ã¸ã§ã³éã®ã¢ããã°ã¬ã¼ãã ãã¨ãã°ãFreeBSD 9.0 ãã FreeBSD 9.1 ã¸ã®ã¢ããã°ã¬ã¼ãã¯ã _ãã¤ãã¼ãã¼ã¸ã§ã³_ ã¢ããã°ã¬ã¼ãã¨å¼ã°ãã¾ãã _ã¡ã¸ã£ã¼ãã¼ã¸ã§ã³_ ã¢ããã°ã¬ã¼ãã¯ã FreeBSD 9.X ãã FreeBSD 10.X ã¸ã®ã¢ããã°ã¬ã¼ãã¨ãã£ãã FreeBSD ã®ã¡ã¸ã£ã¼ãã¼ã¸ã§ã³ãå¤ãããããªã¢ããã°ã¬ã¼ãã®ãã¨ã§ãã ã©ã¡ããã¢ããã°ã¬ã¼ããã`freebsd-update` ã«ãªãªã¼ã¹çªå·ã®ã¿ã¼ã²ãããæå®ããäºã§å®è¡ã§ãã¾ãã
[NOTE]
====
@@ -270,7 +270,6 @@ before running "/usr/sbin/freebsd-update install"
[WARNING]
====
-
[.filename]#GENERIC# ã«ã¼ãã«ã§åèµ·åããåã«ã ã«ã¼ãã«ã«ã·ã¹ãã ãé©åã«èµ·åããããã«å¿
è¦ãªãã¹ã¦ã®ãã©ã¤ããå«ã¾ãã¦ãããã¨ã ããã¢ãããã¼ããã¦ããã³ã³ãã¥ã¼ã¿ããªã¢ã¼ãã§ã¢ã¯ã»ã¹ãã¦ããã®ã§ããã°ã ãããã¯ã¼ã¯æ¥ç¶ã«å¿
è¦ãªãã¹ã¦ã®ãã©ã¤ããå«ã¾ãã¦ãããã¨ã確èªãã¦ãã ããã ç¹ã«ãããã¾ã§å®è¡ãã¦ããã«ã¹ã¿ã ã«ã¼ãã«ãã ã«ã¼ãã«ã¢ã¸ã¥ã¼ã«ã¨ãã¦æä¾ããã¦ãããã«ãã¤ã³ã®æ©è½ãå«ãã§ããã®ã§ããã°ã ãããã®ã¢ã¸ã¥ã¼ã«ã䏿çã« [.filename]#/boot/loader.conf# ã®æ©è½ãç¨ãã¦ã [.filename]#GENERIC# ã«èªã¿è¾¼ãã§ãã ããã ã¢ããã°ã¬ã¼ãããã»ã¹ãçµããã¾ã§ã¯ã éè¦ã§ã¯ãªããµã¼ãã¹ãç¡å¹ã«ããã¨ã¨ãã«ã å¿
è¦ã®ãªããã£ã¹ã¯ããããã¯ã¼ã¯ã®ãã¦ã³ããªã©ãé¿ãããã¨ãæ¨å¥¨ããã¦ãã¾ãã
====
@@ -298,7 +297,7 @@ before running "/usr/sbin/freebsd-update install"
[[freebsd-update-custom-kernel-9x]]
==== FreeBSD 9.X 以éã®ã·ã¹ãã ã«ãããã«ã¹ã¿ã ã«ã¼ãã«
-`freebsd-update` ã使ãåã«ã [.filename]#GENERIC# ã«ã¼ãã«ã [.filename]#/boot/GENERIC# ã«ç½®ããã¦ãããã¨ã確èªãã¦ãã ããã ãã ä¸åº¦ã ãã«ã¹ã¿ã ã«ã¼ãã«ãæ§ç¯ããã®ã§ããã°ã [.filename]#/boot/kernel.old# 㯠[.filename]#GENERIC# ã«ã¼ãã«ãã®ãã®ã§ãã ãã®ãã£ã¬ã¯ããªã®ååã [.filename]#/boot/kernel# ã¸ã¨å¤æ´ãã¦ãã ããã
+`freebsd-update` ã使ãåã«ã [.filename]#GENERIC# ã«ã¼ãã«ã [.filename]#/boot/GENERIC# ã«ç½®ããã¦ãããã¨ã確èªãã¦ãã ããã ãã ä¸åº¦ã ãã«ã¹ã¿ã ã«ã¼ãã«ãæ§ç¯ããã®ã§ããã°ã [.filename]#/boot/kernel.old# 㯠[.filename]#GENERIC# ã«ã¼ãã«ãã®ãã®ã§ãã ãã®ãã£ã¬ã¯ããªã®ååã [.filename]#/boot/GENERIC# ã¸ã¨å¤æ´ãã¦ãã ããã
ããã2 å以ä¸ã«ã¹ã¿ã ã«ã¼ãã«ãæ§ç¯ããå¾ã§ãã£ããã ã«ã¹ã¿ã ã«ã¼ãã«ãæ§ç¯ããåæ°ãããããªããã°ã ç¾å¨ã®ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ã®ãã¼ã¸ã§ã³ã® [.filename]#GENERIC# ã«ã¼ãã«ãå
¥æãã¦ãã ããã ã³ã³ãã¥ã¼ã¿ã¸ã®ç©ççãªã¢ã¯ã»ã¹ãå¯è½ã§ããã°ã ã¤ã³ã¹ãã¼ã«ã¡ãã£ã¢ãã [.filename]#GENERIC# ã«ã¼ãã«ãã¤ã³ã¹ãã¼ã«ã§ãã¾ãã
@@ -360,7 +359,6 @@ before running "/usr/sbin/freebsd-update install"
[WARNING]
====
-
ãã®ã³ãã³ãã¯ãpackage:security/snort[] ã®ãããªæ¬å½ã® IDS ã®ç½®ãæãã«ãªããã®ã§ã¯ããã¾ããã `freebsd-update` ã¯ãã¼ã¿ããã£ã¹ã¯ã«ä¿åããã®ã§ã 䏿£ãªå¤æ´ãè¡ãããå¯è½æ§ãããã¾ãã `kern.securelevel` ã¨ã `freebsd-update` ã®ãã¼ã¿ã使ç¨ããªãã¨ãã«ã èªã¿åãã®ã¿ã®è¨±å¯å±æ§ã«è¨å®ããã¦ãããã¡ã¤ã«ã·ã¹ãã ã«ç½®ããã¨ã§ã 䏿£ãªå¤æ´ã®å¯è½æ§ãä½ãã§ãã¾ããã ããããè§£æ±ºæ¹æ³ã¯ã DVD ã¾ãã¯å®å
¨ã«ä¿åããã¦ããå¤é¨ USB ãã£ã¹ã¯ã®ãããªå®å
¨ãªãã£ã¹ã¯ã¨ã·ã¹ãã ãæ¯è¼ãããã¨ã§ãã çµã¿è¾¼ã¾ãã¦ããã¦ã¼ãã£ãªãã£ãç¨ãããå¥ã®æ¹æ³ã«ãã IDS æ©è½ã«ã¤ãã¦ã¯ã crossref:security[security-ids,FreeBSD ãã¤ããªã«ããæ¤åº] ã®ç¯ãã覧ãã ããã
====
@@ -460,7 +458,7 @@ before running "/usr/sbin/freebsd-update install"
ãã«ããè¡ããã©ã¼ããããã¾ãã¯åºåãã©ã¼ãããã®ä¸è¦§ã ç¾å¨ã¯ `html`, `html-split`, `txt`, `ps` ãã㦠`pdf` ã«å¯¾å¿ãã¦ãã¾ãã
`DOCDIR`::
-ããã¥ã¡ã³ããã¤ã³ã¹ãã¼ã«ããå ´æãããã©ã«ã㯠[.filename]#/usr/shared/doc# ã§ãã
+ããã¥ã¡ã³ããã¤ã³ã¹ãã¼ã«ããå ´æãããã©ã«ã㯠[.filename]#/usr/share/doc# ã§ãã
FreeBSD ã®ã·ã¹ãã å
¨è¬ã®ãªãã·ã§ã³ã«é¢é£ãããã£ã¨å¤ãã® `make` 夿°ã«ã¤ãã¦ã¯ã man:make.conf[5] ãã覧ãã ããã
@@ -511,7 +509,7 @@ HTML å½¢å¼ãæ§ç¯ãã¾ãã åããã¥ã¡ã³ãã«å¯¾ããåä¸çã® H
æ´å½¢ãããããã¥ã¡ã³ãã¯ã [.filename]#article.pdf# ã [.filename]#book.pdf# ã¨ãã£ãååã§ã¤ã³ã¹ãã¼ã«ããã¾ãã
`DOCBASE`::
-ããã¥ã¡ã³ãã®ã¤ã³ã¹ãã¼ã«å
ãè¨å®ãã¾ãã ããã©ã«ãã®ã¤ã³ã¹ãã¼ã«å
㯠[.filename]#/usr/local/shared/doc/freebsd# ã§ãã
+ããã¥ã¡ã³ãã®ã¤ã³ã¹ãã¼ã«å
ãè¨å®ãã¾ãã ããã©ã«ãã®ã¤ã³ã¹ãã¼ã«å
㯠[.filename]#/usr/local/share/doc/freebsd# ã§ãã
以ä¸ã¯ãä¸è¨ã®å¤æ°ãç¨ãã¦ãã³ã¬ãªã¼èªã®ããã¥ã¡ã³ãã PDF å½¢å¼ã§ã¤ã³ã¹ãã¼ã«ããæ¹æ³ã§ãã
@@ -535,6 +533,8 @@ FreeBSD ã«ã¯äºã¤ã®éçºãã©ã³ããããã¾ãã ãã㯠FreeBSD-CU
ãã®ç¯ã§ã¯ããããã®ãã©ã³ãã¨å¯¾è±¡ã¨ãã¦ããèªè
ã«ã¤ãã¦ã®èª¬æã¨ã ã©ã®ããã«ãã¦ã·ã¹ãã ã®å¯¾å¿ãããã©ã³ããææ°ã®ç¶æ
ã«ä¿ã¤ãã«ã¤ãã¦èª¬æãã¾ãã
+_訳: ã1996 å¹´ 11 æ 6 æ¥_
+
[[current]]
=== FreeBSD-CURRENT ã使ã
@@ -566,6 +566,8 @@ FreeBSD-CURRENT ãã³ã³ãã¤ã« ããåã« [.filename]#/usr/src/Makefile#
[[stable]]
=== FreeBSD-STABLE ã使ã
+__訳: __
+
FreeBSD-STABLE ã¨ã¯å®æçã«å
¬éããããªãªã¼ã¹ã使ããããã®éçºãã©ã³ãã§ãã ãã®ãã©ã³ãã«å ãããã夿´ã¯ FreeBSD-CURRENT ãããã£ããã§ã ååã¨ãã¦ãäºåã« FreeBSD-CURRENT ã§è©¦é¨ãã¿ã§ããã¨ããç¹å¾´ãããã¾ãã ãã __ããã§ãã£ã¦ã__ã ããã¯éçºç¨ãã©ã³ãã®ä¸ã¤ã§ãããããæç¹ã«ããã FreeBSD-STABLE ã®ã½ã¼ã¹ãã©ããªå ´åã«ã使ãããã®ã§ããã¨ã¯éãã¾ããã ãã®ãã©ã³ãã¯ããä¸ã¤ã®éçºã®æµãã¨ããã ãã§ãã£ã¦ã ã¨ã³ãã¦ã¼ã¶åãã®ãã®ã§ã¯ããã¾ããã ãã試é¨ãããè³æºçãªä½è£ããªãå ´åã¯ã代ããã«ææ°ã® FreeBSD ãªãªã¼ã¹ã使ã£ã¦ãã ããã
FreeBSD ã®éçºããã»ã¹ã«èå³ããã£ããã ããã«å¯¾ããè²¢ç®ãèãã¦ãã¦ãç¹ã«ãããæ¬¡åã® FreeBSD ã®ãªãªã¼ã¹ã«é¢ä¿ãããã®ã§ãããªã FreeBSD-STABLE ã追ããã¨ãèããã¨è¯ãã§ãããã
@@ -609,7 +611,7 @@ check /usr/src/UPDATING <.>
# cd /usr/src <.>
# make installworld <.>
# mergemaster -Ui <.>
-# shutdown -r now 1<.>
+# shutdown -r now <.>
....
<.> +ææ°çã®ã½ã¼ã¹ãå
¥æãã¦ãã ããã ã½ã¼ã¹ã®å
¥æããã³ã¢ãããã¼ãã«é¢ããæ
å ±ã«ã¤ãã¦ã¯ <<updating-src-obtaining-src>> ãã覧ãã ããã
@@ -707,7 +709,6 @@ man:uname[1] ã使ã£ã¦ FreeBSD ã®ãã¼ã¸ã§ã³ã確èªãã¦ãã ãã
....
<.> ãã®å¤ããã£ã¬ã¯ããªãã éªéã«ãªããªãããã«ç§»åãã¦ãã ããã ãã®ãã£ã¬ã¯ããªä»¥ä¸ã«å¯¾ãã¦å¤æ´ãè¡ã£ã¦ãªããã°ã åé¤ãã¦ãæ§ããªãã§ãããã
-
<.> ãªãã¸ããªã® URL ã« <<updating-src-obtaining-src-repopath>> ã«è¨è¼ããã¦ãããã¹ã追å ãã¾ãã 3 çªç®ã®ãã©ã¡ã¼ã¿ã«ã¯ã ãã¼ã«ã«ã·ã¹ãã ä¸ã§ã½ã¼ã¹ã³ã¼ããç½®ããããã£ã¬ã¯ããªãæå®ãã¾ãã
====
@@ -777,7 +778,6 @@ FreeBSD æ¨æºã®ã«ã¼ãã«ã¯ã [.filename]#GENERIC# ã¨å¼ã°ãã _ã«ã¼
[TIP]
====
-
[.filename]#/usr/src# ã¯ã åé¤ããããä½ãç´ããããããå¯è½æ§ãããããã ã«ã¹ã¿ã ã«ã¼ãã«ã®ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ãã¡ã¤ã«ã¯ã [.filename]#/root# ã®ãããªå¥ã®ãã£ã¬ã¯ããªã§ç®¡çãããã¨ã好ã¾ããã§ãã ã«ã¼ãã«ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ãã¡ã¤ã«ã¯ã [.filename]#conf# ãã£ã¬ã¯ããªã«ãªã³ã¯ãã¾ãã ãã®ãã£ã¬ã¯ããªãåé¤ããããã䏿¸ããããå ´åã«ã¯ã ã«ã¼ãã«ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ãã¡ã¤ã«ãæ°ãããã£ã¬ã¯ããªã«ããä¸åº¦ãªã³ã¯ãã¦ãã ããã
====
diff --git a/documentation/content/ja/books/handbook/l10n/_index.adoc b/documentation/content/ja/books/handbook/l10n/_index.adoc
index 090941d805..b468ed258e 100644
--- a/documentation/content/ja/books/handbook/l10n/_index.adoc
+++ b/documentation/content/ja/books/handbook/l10n/_index.adoc
@@ -75,7 +75,7 @@ internationalization ã¯ãi18n ã¨ç縮ãã¦è¡¨è¨ããã¾ãã ãã㯠`
è¨èªã³ã¼ã_å½ã³ã¼ã.ã¨ã³ã³ã¼ãã£ã³ã°
....
-__è¨èªã³ã¼ã__ ããã³ __å½ã³ã¼ã__ ã¯ã å½ã¨è¨èªãç¹å®ããããã«ç¨ãããã¾ãã <<locale-lang-country>> ã§ã¯ã __è¨èªã³ã¼ã_å½ã³ã¼ã__ ã®ä¾ã示ãã¾ã
+_è¨èªã³ã¼ã_ ããã³ _å½ã³ã¼ã_ ã¯ã å½ã¨è¨èªãç¹å®ããããã«ç¨ãããã¾ãã <<locale-lang-country>> ã§ã¯ã _è¨èªã³ã¼ã___å½ã³ã¼ã_ ã®ä¾ã示ãã¾ã
[[locale-lang-country]]
.è¨èªããã³å½ã³ã¼ã
@@ -127,9 +127,7 @@ FreeBSD ã§ã¯ãXorg äºæã®ãã±ã¼ã«ç¬¦å·ãç¨ãã¦ãã¾ãã
以ä¸ã®äºã¤ã®ç°å¢å¤æ°ãè¨å®ããå¿
è¦ãããã¾ãã
* `LANG`: ãã±ã¼ã«ãè¨å®ãã¾ãã
-*
-+
-`MM_CHARSET`: ã¢ããªã±ã¼ã·ã§ã³ã§ä½¿ç¨ããã MIME æåã»ãããæå®ãã¾ãã
+* `MM_CHARSET`: ã¢ããªã±ã¼ã·ã§ã³ã§ä½¿ç¨ããã MIME æåã»ãããæå®ãã¾ãã
ãããã®å¤æ°ã¯ãã¦ã¼ã¶ã®ã·ã§ã«ã®è¨å®ãã¡ã¤ã«ã«å ãã ã¢ããªã±ã¼ã·ã§ã³åºæã®è¨å®ãã¡ã¤ã«ã ããã³ Xorg ã®è¨å®ãã¡ã¤ã«ã«ããã¦ãæå®ãããå¿
è¦ãããã¾ãã
@@ -215,7 +213,7 @@ user:password:1111:11:language:0:0:User Name:/home/user:/bin/sh
[source,bash]
....
-Enter login class: default []:
+Enter login class: default []:
....
ãããã¯ã`adduser` ãå®è¡ããéã«ãã±ã¼ã«ãæå®ãã¦ãã ããã
@@ -242,7 +240,7 @@ Enter login class: default []:
[[startup-file]]
==== ã·ã§ã«ã®åæåãã¡ã¤ã«ã«ããæ¹æ³
-ãã® 2 çªç®ã®æ¹æ³ã¯ã 使ç¨ããã·ã§ã«ãã¨ã«æåã§ã®è¨å®ãå¿
è¦ãªãããæ¨å¥¨ããã¾ããã ã·ã§ã«æ¯ã«è¨å®ãã¡ã¤ã«ãåå¨ãããã®æ§æã¯ã·ã§ã«ã«ä¾åãã¾ãã ãã¨ãã°ã`sh` ã·ã§ã«ã«å¯¾ãããã¤ãèªã®è¨å®ã§ã¯ã ãã®ã¦ã¼ã¶ã®ã·ã§ã«ãè¨å®ããããã ãã«ã [.filename]#~/.profile# ã«ä»¥ä¸ã®è¡ã追å ã¾ãã ãããã®è¡ã [.filename]#/etc/profile# ã¾ãã¯ã [.filename]#/usr/shared/skel/dot.profile# ã«è¿½å ããã¨ã ãã¹ã¦ã®ã¦ã¼ã¶ã®ã·ã§ã«ãè¨å®ãããã¨ãå¯è½ã§ãã
+ãã® 2 çªç®ã®æ¹æ³ã¯ã 使ç¨ããã·ã§ã«ãã¨ã«æåã§ã®è¨å®ãå¿
è¦ãªãããæ¨å¥¨ããã¾ããã ã·ã§ã«æ¯ã«è¨å®ãã¡ã¤ã«ãåå¨ãããã®æ§æã¯ã·ã§ã«ã«ä¾åãã¾ãã ãã¨ãã°ã`sh` ã·ã§ã«ã«å¯¾ãããã¤ãèªã®è¨å®ã§ã¯ã ãã®ã¦ã¼ã¶ã®ã·ã§ã«ãè¨å®ããããã ãã«ã [.filename]#~/.profile# ã«ä»¥ä¸ã®è¡ã追å ã¾ãã ãããã®è¡ã [.filename]#/etc/profile# ã¾ãã¯ã [.filename]#/usr/share/skel/dot.profile# ã«è¿½å ããã¨ã ãã¹ã¦ã®ã¦ã¼ã¶ã®ã·ã§ã«ãè¨å®ãããã¨ãå¯è½ã§ãã
[.programlisting]
....
@@ -250,7 +248,7 @@ LANG=de_DE.ISO8859-1; export LANG
MM_CHARSET=ISO-8859-1; export MM_CHARSET
....
-ããããªããã`csh` ã·ã§ã«ã§ã¯ã è¨å®ãã¡ã¤ã«ã®ååãæ§æã¯ç°ãªãã¾ãã [.filename]#~/.csh.login#, [.filename]#/etc/csh.login# ã¾ã㯠[.filename]#/usr/shared/skel/dot.login# ã§ã¯åãè¨å®ã§ãã
+ããããªããã`csh` ã·ã§ã«ã§ã¯ã è¨å®ãã¡ã¤ã«ã®ååãæ§æã¯ç°ãªãã¾ãã [.filename]#~/.csh.login#, [.filename]#/etc/csh.login# ã¾ã㯠[.filename]#/usr/share/skel/dot.login# ã§ã¯åãè¨å®ã§ãã
[.programlisting]
....
@@ -273,7 +271,7 @@ setenv LANG de_DE.ISO8859-1
[[setting-console]]
=== ã³ã³ã½ã¼ã«ã®è¨å®
-ã³ã³ã½ã¼ã«ã§å©ç¨å¯è½ãªå°ååããããã©ã³ããããã¾ãã å©ç¨ã§ãããã©ã³ãã®ä¸è¦§ã調ã¹ãã«ã¯ã `ls /usr/shared/syscons/fonts` ã¨å
¥åãã¦ãã ããã ã³ã³ã½ã¼ã«ã®ãã©ã³ããè¨å®ããã«ã¯ã [.filename]#.fnt# ã¨ããæ¡å¼µåãé¤ãã _ãã©ã³ãå_ ãã [.filename]#/etc/rc.conf# ã«è¨å®ãã¦ãã ããã
+ã³ã³ã½ã¼ã«ã§å©ç¨å¯è½ãªå°ååããããã©ã³ããããã¾ãã å©ç¨ã§ãããã©ã³ãã®ä¸è¦§ã調ã¹ãã«ã¯ã `ls /usr/share/syscons/fonts` ã¨å
¥åãã¦ãã ããã ã³ã³ã½ã¼ã«ã®ãã©ã³ããè¨å®ããã«ã¯ã [.filename]#.fnt# ã¨ããæ¡å¼µåãé¤ãã _ãã©ã³ãå_ ãã [.filename]#/etc/rc.conf# ã«è¨å®ãã¦ãã ããã
[.programlisting]
....
@@ -291,9 +289,9 @@ keymap=ãã¼ãããå
keychange="ãã¡ã³ã¯ã·ã§ã³ãã¼çªå·ã®ä¸¦ã³"
....
-å©ç¨å¯è½ãªã¹ã¯ãªã¼ã³ãããã®ä¸è¦§ã調ã¹ãã«ã¯ã `ls /usr/shared/syscons/scrnmaps` ã¨å
¥åãã¦ãã ããã [.filename]#/etc/rc.conf# ã§ _ã¹ã¯ãªã¼ã³ãããå_ ãæå®ããæã¯ã [.filename]#.csm# ã¨ããæ¡å¼µåãé¤ãã¦ãã ããã ã¹ã¯ãªã¼ã³ãã©ã³ãã bit 8 åã使ã£ã¦ããæã«æåãçä¼¼ã°ã©ãã£ã¯ã¹é åããå¤ã«ç§»åããããã«ã VGA ã¢ããã¿ããã©ã³ãæåãããªã¯ã¹ã§ bit 8 ã bit 9 ã«æ¡å¼µãããã¨ã«å¯¾å¦ããããã ãã©ã³ãã«é©åã«ããããããã¹ã¯ãªã¼ã³ããããå¿
è¦ã¨ãªãã¾ãã
+å©ç¨å¯è½ãªã¹ã¯ãªã¼ã³ãããã®ä¸è¦§ã調ã¹ãã«ã¯ã `ls /usr/share/syscons/scrnmaps` ã¨å
¥åãã¦ãã ããã [.filename]#/etc/rc.conf# ã§ _ã¹ã¯ãªã¼ã³ãããå_ ãæå®ããæã¯ã [.filename]#.csm# ã¨ããæ¡å¼µåãé¤ãã¦ãã ããã ã¹ã¯ãªã¼ã³ãã©ã³ãã bit 8 åã使ã£ã¦ããæã«æåãçä¼¼ã°ã©ãã£ã¯ã¹é åããå¤ã«ç§»åããããã«ã VGA ã¢ããã¿ããã©ã³ãæåãããªã¯ã¹ã§ bit 8 ã bit 9 ã«æ¡å¼µãããã¨ã«å¯¾å¦ããããã ãã©ã³ãã«é©åã«ããããããã¹ã¯ãªã¼ã³ããããå¿
è¦ã¨ãªãã¾ãã
-å©ç¨å¯è½ãªãã¼ãããã®ä¸è¦§ã調ã¹ãã«ã¯ã `ls /usr/shared/syscons/keymaps` ã¨å
¥åãã¦ãã ããã [.filename]#/etc/rc.conf# ã§ _ãã¼ãããå_ ãæå®ããæã«ã¯ã [.filename]#.kbd# ã¨ããæ¡å¼µåãé¤ãã¦ãã ããã åèµ·åããã«ãã¼ãããã試ãã«ã¯ã man:kbdmap[1] ã使ã£ã¦ãã ããã
+å©ç¨å¯è½ãªãã¼ãããã®ä¸è¦§ã調ã¹ãã«ã¯ã `ls /usr/share/syscons/keymaps` ã¨å
¥åãã¦ãã ããã [.filename]#/etc/rc.conf# ã§ _ãã¼ãããå_ ãæå®ããæã«ã¯ã [.filename]#.kbd# ã¨ããæ¡å¼µåãé¤ãã¦ãã ããã åèµ·åããã«ãã¼ãããã試ãã«ã¯ã man:kbdmap[1] ã使ã£ã¦ãã ããã
ãã¡ã³ã¯ã·ã§ã³ãã¼ã®ä¸¦ã³ã¯ãã¼ãããã§å®ç¾©ããã¦ããªãã®ã§ã 端æ«ã¿ã¤ãã«åããããã¡ã³ã¯ã·ã§ã³ãã¼ãè¨å®ããããã« `keychange` ã®ã¨ã³ããªãå¿
è¦ã¨ãªãã¾ãã
@@ -535,7 +533,7 @@ lp|Russian local line printer:\
詳ããã¯ãman:mount_msdosfs[8] ãåç
§ãã¦ãã ããã
-Xorg ã«ãã·ã¢èªã®ãã©ã³ããè¨å®ããã«ã¯ã package:x11-fonts/xorg-fonts-cyrillic[] ããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ãã¦ãã ããã ãã®å¾ã[.filename]#/etc/X11/xorg.conf# ã® `"Files"` ã»ã¯ã·ã§ã³ã確èªãã¦ãã ããã æ¢åã® `FontPath` ã¨ã³ããªã®__åã«__以ä¸ã®è¡ã追å ããªããã°ãªãã¾ããã
+Xorg ã«ãã·ã¢èªã®ãã©ã³ããè¨å®ããã«ã¯ã package:x11-fonts/xorg-fonts-cyrillic[] ããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ãã¦ãã ããã ãã®å¾ã[.filename]#/etc/X11/xorg.conf# ã® `"Files"` ã»ã¯ã·ã§ã³ã確èªãã¦ãã ããã æ¢åã® `FontPath` ã¨ã³ããªã®_åã«_以ä¸ã®è¡ã追å ããªããã°ãªãã¾ããã
[.programlisting]
....
@@ -575,13 +573,13 @@ Xorg ã¢ããªã±ã¼ã·ã§ã³ãå°ååããæ¹æ³ã«ã¤ãã¦ã¯ãlink:http
ãã®ç¯ã§ã¯ã ä»è¨èªã¸ã®ãã±ã¼ã«ã®è¨å®ã«é¢ãããªã½ã¼ã¹ã®ä¸è¦§ã示ãã¾ãã
å°æ¹¾åãã®ç¹ä½åä¸å½èªã¸ã®å°åå::
-FreeBSD-Taiwan ããã¸ã§ã¯ãã¯ã FreeBSD ãä¸å½èªåããããã®æå¼ã http://netlab.cse.yzu.edu.tw/\~statue/freebsd/zh-tut/[http://netlab.cse.yzu.edu.tw/~statue/freebsd/zh-tut/] ãæä¾ãã¦ãã¾ãã
+FreeBSD-Taiwan ããã¸ã§ã¯ãã¯ã FreeBSD ãä¸å½èªåããããã®æå¼ã link:http://netlab.cse.yzu.edu.tw/\~statue/freebsd/zh-tut/[http://netlab.cse.yzu.edu.tw/~statue/freebsd/zh-tut/] ãæä¾ãã¦ãã¾ãã
ã®ãªã·ã£èªã¸ã®å°åå::
-FreeBSD ã«ãããã®ãªã·ã£èªã®ãµãã¼ãã«ã¤ãã¦ã®è¨äºã¯ã å
¬å¼ã® FreeBSD ã®ãªã·ã£èªããã¥ã¡ã³ãã¼ã·ã§ã³ã®ä¸é¨ã¨ã㦠https://www.FreeBSD.org/doc/el/articles/greek-language-support/[ãã] ã§èªããã¨ãã§ãã¾ãã ãã®ææ¸ã¯ãã®ãªã·ã£èªã§æ¸ããã¦ãã¾ãã
+FreeBSD ã«ãããã®ãªã·ã£èªã®ãµãã¼ãã«ã¤ãã¦ã®è¨äºã¯ã å
¬å¼ã® FreeBSD ã®ãªã·ã£èªããã¥ã¡ã³ãã¼ã·ã§ã³ã®ä¸é¨ã¨ã㦠link:https://docs.FreeBSD.org/el/articles/greek-language-support/[ãã] ã§èªããã¨ãã§ãã¾ãã ãã®ææ¸ã¯ãã®ãªã·ã£èªã§æ¸ããã¦ãã¾ãã
æ¥æ¬èª/éå½èªã¸ã®å°åå::
-æ¥æ¬èªã«é¢ãã¦ã¯ http://www.jp.FreeBSD.org/[http://www.jp.FreeBSD.org/] ããéå½èªã«é¢ãã¦ã¯ http://www.kr.FreeBSD.org/[http://www.kr.FreeBSD.org/] ãåç
§ãã¦ãã ããã
+æ¥æ¬èªã«é¢ãã¦ã¯ link:http://www.jp.FreeBSD.org/[http://www.jp.FreeBSD.org/] ããéå½èªã«é¢ãã¦ã¯ link:http://www.kr.FreeBSD.org/[http://www.kr.FreeBSD.org/] ãåç
§ãã¦ãã ããã
è±èªä»¥å¤ã® FreeBSD ããã¥ã¡ã³ã::
-FreeBSD ã®ææ¸ã®ä¸é¨ãä»ã®è¨èªã«ç¿»è¨³ãã¦ããã¦ããè²¢ç®è
ãã¡ããã¾ãã ããã㯠link:https://www.FreeBSD.org/ja/[FreeBSD ã¦ã§ããµã¤ã] ã®ãªã³ã¯ã辿ãã [.filename]#/usr/shared/doc# ããå
¥æã§ãã¾ãã
+FreeBSD ã®ææ¸ã®ä¸é¨ãä»ã®è¨èªã«ç¿»è¨³ãã¦ããã¦ããè²¢ç®è
ãã¡ããã¾ãã ããã㯠link:https://www.FreeBSD.org/ja/[FreeBSD ã¦ã§ããµã¤ã] ã®ãªã³ã¯ã辿ãã [.filename]#/usr/share/doc# ããå
¥æã§ãã¾ãã
diff --git a/documentation/content/ja/books/handbook/multimedia/_index.adoc b/documentation/content/ja/books/handbook/multimedia/_index.adoc
index 895d171bda..497311eea8 100644
--- a/documentation/content/ja/books/handbook/multimedia/_index.adoc
+++ b/documentation/content/ja/books/handbook/multimedia/_index.adoc
@@ -179,7 +179,6 @@ pcm2: <Conexant CX20590 (Analog 2.0+HP/2.0)> (play/rec) default
[WARNING]
====
-
ãªã¼ãã£ãª CD ã¯ç¹å¥ãªã¨ã³ã³ã¼ãã£ã³ã°ãè¡ããã¦ããããã man:mount[8] ã使ã£ã¦ãã¦ã³ããã¹ãã§ã¯ããã¾ããã
====
@@ -679,11 +678,11 @@ zoom=yes
åºåããã [.filename]#out.vob# ãã¡ã¤ã«ã¯ MPEG å½¢å¼ã§ãã
-UNIX(R) ãããªã«ã¤ãã¦ã é«ã¬ãã«ã®ãã¦ãã¦ãå¾ããã¨èãã¦ããæ¹ã¯ http://www.mplayerhq.hu/DOCS/[mplayerhq.hu/DOCS] ãã覧ãã ãããæè¡çãªæ
å ±ãããã¾ãã ãã®ããã¥ã¡ã³ãã¯ã ãã°ãå ±åããåã«ãèªãã¹ããã®ã§ãã
+UNIX(R) ãããªã«ã¤ãã¦ã é«ã¬ãã«ã®ãã¦ãã¦ãå¾ããã¨èãã¦ããæ¹ã¯ link:http://www.mplayerhq.hu/DOCS/[mplayerhq.hu/DOCS] ãã覧ãã ãããæè¡çãªæ
å ±ãããã¾ãã ãã®ããã¥ã¡ã³ãã¯ã ãã°ãå ±åããåã«ãèªãã¹ããã®ã§ãã
`mencoder` ã使ãåã«ãlink:http://www.mplayerhq.hu/DOCS/HTML/en/mencoder.html[mplayerhq.hu/DOCS/HTML/en/mencoder.html] ãèªãã§ãªãã·ã§ã³ã«æ
£ãã¦ããã®ã¯ããèãã§ãã å質åä¸ãä½ãããã¬ã¼ããå½¢å¼å¤æãããæ¹æ³ãç¡æ°ã«ããã¾ãã ãããã®è¦ç´ ã®èª¿ç¯å
·åã§ãæ§è½ãè¯ãã£ããæªãã£ãããããªã©ã çµæã«éããåºãããããã¾ããã ã³ãã³ãã©ã¤ã³ãªãã·ã§ã³ãä¸é©åã«çµåããã¨ã `mplayer` ã§ããåçã§ããªãåºåãã¡ã¤ã«ã使ãã¦ãã¾ãã¾ãã
-ã¯ããã¯åç´ãªãã¡ã¤ã«ã®ã³ãã¼ã§ãã
+ ã¯ããã¯åç´ãªãã¡ã¤ã«ã®ã³ãã¼ã§ãã
[source,bash]
....
@@ -720,7 +719,7 @@ xine ã¯ã åçãããã¡ã¤ã«åãæå®ãããã¨ã§ã ã³ãã³ã
% xine -g -p mymovie.avi
....
-http://www.xine-project.org/faq[xine-project.org/faq] ã«ã¯ãããå¤ãã®æ
å ±ããã©ãã«ã·ã¥ã¼ãã£ã³ã°ãããã¾ãã
+link:http://www.xine-project.org/faq[xine-project.org/faq] ã«ã¯ãããå¤ãã®æ
å ±ããã©ãã«ã·ã¥ã¼ãã£ã³ã°ãããã¾ãã
[[video-ports-transcode]]
==== Transcode ã¦ã¼ãã£ãªãã£
@@ -824,9 +823,9 @@ FreeBSD ã«ããã¯ã¨ã³ãã¨ããã³ãã¨ã³ãã®ä¸¡æ¹ãã¤ã³ã¹ãã¼
=== ãã¼ãã¦ã§ã¢
-MythTV ã¯ã ã¨ã³ã³ã¼ãããã¥ã¼ããªã©ã®ãããªå
¥åããã¤ã¹ã¸ã®ã¢ã¯ã»ã¹ã« Video for Linux (V4L) ãç¨ãã¾ãã FreeBSD ã§ã¯ãUSB DVB-S/C/T ã«ã¼ãã«ããã¦æãããåä½ãã¾ãã ãªããªãã°ããã®ã«ã¼ãã¯ã V4L ã¦ã¼ã¶ã©ã³ãã¢ããªã±ã¼ã·ã§ã³ãæä¾ãã package:multimedia/webcamd[] package ã¾ã㯠port ã«ããè¯ããµãã¼ãããã¦ããããã§ãã webcamd ã«ãã対å¿ãã¦ãã Digital Video Broadcasting (DVB) ã«ã¼ãã¯ãMythTV ã§åä½ããã¯ãã§ãã åä½ãããã¨ãç¥ããã¦ããã«ã¼ãã®ä¸è¦§ã http://wiki.freebsd.org/WebcamCompat[wiki.freebsd.org/WebcamCompat] ã«ããã¾ãã Hauppauge ã«ã¼ãã®ãã©ã¤ããã¾ãã package:multimedia/pvr250[] ããã³ package:multimedia/pvrxxx[] port ã¨ãã¦å©ç¨å¯è½ã§ããã æ¨æºçã§ã¯ãªããã©ã¤ãã®ã¤ã³ã¿ãã§ã¼ã¹ãæä¾ãã¦ããã 0.23 ããå¾ã® MythTV ã§ã¯åä½ãã¾ããã ã
©ã¤ã»ã³ã¹ã®å¶éã«ãããpackage ã¯å©ç¨ã§ãã¾ããã ãã®ããããããã® ports ã¯ã³ã³ãã¤ã«ãããªããã°ãªãã¾ããã
+MythTV ã¯ã ã¨ã³ã³ã¼ãããã¥ã¼ããªã©ã®ãããªå
¥åããã¤ã¹ã¸ã®ã¢ã¯ã»ã¹ã« Video for Linux (V4L) ãç¨ãã¾ãã FreeBSD ã§ã¯ãUSB DVB-S/C/T ã«ã¼ãã«ããã¦æãããåä½ãã¾ãã ãªããªãã°ããã®ã«ã¼ãã¯ã V4L ã¦ã¼ã¶ã©ã³ãã¢ããªã±ã¼ã·ã§ã³ãæä¾ãã package:multimedia/webcamd[] package ã¾ã㯠port ã«ããè¯ããµãã¼ãããã¦ããããã§ãã webcamd ã«ãã対å¿ãã¦ãã Digital Video Broadcasting (DVB) ã«ã¼ãã¯ãMythTV ã§åä½ããã¯ãã§ãã åä½ãããã¨ãç¥ããã¦ããã«ã¼ãã®ä¸è¦§ã link:http://wiki.freebsd.org/WebcamCompat[wiki.freebsd.org/WebcamCompat] ã«ããã¾ãã Hauppauge ã«ã¼ãã®ãã©ã¤ããã¾ãã package:multimedia/pvr250[] ããã³ package:multimedia/pvrxxx[] port ã¨ãã¦å©ç¨å¯è½ã§ããã æ¨æºçã§ã¯ãªããã©ã¤ãã®ã¤ã³ã¿ãã§ã¼ã¹ãæä¾ãã¦ããã 0.23 ããå¾ã® MythTV ã§ã¯åä½ãã¾ããã
ã©ã¤ã»ã³ã¹ã®å¶éã«ãããpackage ã¯å©ç¨ã§ãã¾ããã ãã®ããããããã® ports ã¯ã³ã³ãã¤ã«ãããªããã°ãªãã¾ããã
-http://wiki.freebsd.org/HTPC[wiki.freebsd.org/HTPC] ãã¼ã¸ã¯ãDVB ãã©ã¤ãã®ãã¹ã¦ã®ä¸è¦§ãæä¾ãã¦ãã¾ãã
+link:http://wiki.freebsd.org/HTPC[wiki.freebsd.org/HTPC] ãã¼ã¸ã¯ãDVB ãã©ã¤ãã®ãã¹ã¦ã®ä¸è¦§ãæä¾ãã¦ãã¾ãã
=== MythTV ããã¯ã¨ã³ãã®è¨å®
@@ -849,7 +848,7 @@ http://wiki.freebsd.org/HTPC[wiki.freebsd.org/HTPC] ãã¼ã¸ã¯ãDVB ãã©ã¤
[source,bash]
....
-# mysql -uroot -p < /usr/local/shared/mythtv/database/mc.sql
+# mysql -uroot -p < /usr/local/share/mythtv/database/mc.sql
....
ãã®å¾ãããã¯ã¨ã³ããè¨å®ãã¦ãã ããã
@@ -887,6 +886,7 @@ device usb
device uhci
device ohci
device ehci
+device xhci
....
USB ã¹ãã£ããèªèããããã確èªããã«ã¯ã ã¹ãã£ããæ¥ç¶ãã¦ã`dmesg` ãå©ç¨ãã ã·ã¹ãã ã¡ãã»ã¼ã¸ãããã¡ã§ã ã¹ãã£ããèªèããã¦ãããã©ããã確èªãã¦ãã ããã èªèããã¦ãããã以ä¸ã®ãããªã¡ãã»ã¼ã¸ã表示ããã¾ãã
@@ -941,22 +941,20 @@ FreeBSD ã«ããã SCSI ããã¤ã¹ã«ã¤ãã¦ã®è©³ç´°ã¯ã man:scsi[4]
=== SANE ã®è¨å®
-SANE ã·ã¹ãã ã¯ã äºã¤ã®é¨åãããªãã¡ããã¯ã¨ã³ã (package:graphics/sane-backends[]) ã¨ããã³ãã¨ã³ã (package:graphics/sane-frontends[] ãããã¯ãpackage:graphics/xsane[]) ã«åå²ããã¦ãã¾ãã ããã¯ã¨ã³ãã¯ã¹ãã£ãã«å¯¾ããã¢ã¯ã»ã¹ãæä¾ãã¾ãã ã©ã®ããã¯ã¨ã³ããç»åã¹ãã£ãã«å¯¾å¿ãã¦ãããã«ã¤ãã¦ã¯ãlink:http://www.sane-project.org/sane-supported-devices.html[http://www.sane-project.org/sane-supported-devices.html] ãåç
§ãã¦ãã ããã ããã³ãã¨ã³ãã¯ã°ã©ãã£ã«ã«ãªã¹ãã£ãã³ã°ã¤ã³ã¿ãã§ã¼ã¹ãæä¾ãã¾ãã package:graphics/sane-frontends[] ã¯ã xscanimage ãã¤ã³ã¹ãã¼ã«ãã䏿¹ã package:graphics/xsane[] ã¯ã xsane ãã¤ã³ã¹ãã¼ã«ãã¾ãã
+SANE ã·ã¹ãã ã¯ã ããã¯ã¨ã³ã (package:graphics/sane-backends[]) ãçµç±ãã¦ã¹ãã£ãã«å¯¾ããã¢ã¯ã»ã¹ãæä¾ãã¾ãã ããã¯ã¨ã³ãã対å¿ãã¦ããç»åã¹ãã£ãã«ã¤ãã¦ã¯ãlink:http://www.sane-project.org/sane-supported-devices.html[http://www.sane-project.org/sane-supported-devices.html] ãåç
§ãã¦ãã ããã ã°ã©ãã£ã«ã«ãªã¹ãã£ãã³ã°ã¤ã³ã¿ãã§ã¼ã¹ã¯ã Kooka (package:graphics/kooka[]) ã¾ã㯠XSane (package:graphics/xsane[]) ã¨ãã£ããµã¼ããã¼ãã£è£½ã®ã¢ããªã±ã¼ã·ã§ã³ã«ãã£ã¦æä¾ããã¦ãã¾ãã SANE ã®ããã¯ã¨ã³ãã¯ã ã¹ãã£ãã試ãã«ã¯ååã§ãã
-ãã¤ã㪠package ãããåå²ãããäºã¤ã®ä¸¡æ¹ãã¤ã³ã¹ãã¼ã«ããã«ã¯ã 以ä¸ã®ããã«å®è¡ãã¦ãã ããã
+ãã¤ã㪠package ãããããã¯ã¨ã³ããã¤ã³ã¹ãã¼ã«ããã«ã¯ã 以ä¸ã®ããã«å®è¡ãã¦ãã ããã
[source,bash]
....
-# pkg install xsane sane-frontends
+# pkg install sane-backends
....
ãããã¯ãPorts Collection ããã¤ã³ã¹ãã¼ã«ããã«ã¯ã 以ä¸ã®ããã«å®è¡ãã¦ãã ããã
[source,bash]
....
-# cd /usr/ports/graphics/sane-frontends
-# make install clean
-# cd /usr/ports/graphics/xsane
+# cd /usr/ports/graphics/sane-backends
# make install clean
....
@@ -985,7 +983,7 @@ device `snapscan:/dev/pass3' is a AGFA SNAPSCAN 600 flatbed scanner
device 'epson2:libusb:/dev/usb:/dev/ugen0.2' is a Epson GT-8200 flatbed scanner
....
-2 çªç®ã®åºåã®ä¸ã§ã `'epson2:libusb:/dev/usb:/dev/ugen0.2'` ãã¹ãã£ãã使ç¨ããããã¯ã¨ã³ãå (`epson2`) ããã³ `/dev/ugen0.2` ã¯ãããã¤ã¹ãã¼ãã§ãã
+2 çªç®ã®åºåã«ããã¦ã `epson2` ãããã¯ã¨ã³ãåã§ã `libusb:000:002` 㯠`/dev/ugen0.2` ãæå³ãã ã¹ãã£ãã使ç¨ããããã¤ã¹ãã¼ãã§ãã
`scanimage` ãã¹ãã£ãã®èªèã«å¤±æããå ´åã«ã¯ã 以ä¸ã®ãããªã¡ãã»ã¼ã¸ã表示ããã¾ãã
@@ -1011,14 +1009,12 @@ usb /dev/ugen0.2
[source,bash]
....
# scanimage -L
-device 'epson2:libusb:/dev/usb:/dev/ugen0.2' is a Epson GT-8200 flatbed scanner
+device 'epson2:libusb:000:002' is a Epson GT-8200 flatbed scanner
....
`scanimage -L` ãå®è¡ãã¦ã¹ãã£ããèªèããããã¨ããããã°ãè¨å®ã¯çµäºã§ãã ã¹ãã£ãã使ç¨ããæºåãã§ãã¾ããã
-`scanimage` ã使ç¨ãã¦ã³ãã³ãã©ã¤ã³ããç»åãåå¾ãããã¨ãã§ãã¾ããã GUI ã使ç¨ãã¦ç»åãåå¾ã§ããã¨ããæã¾ããã§ãããã package:graphics/sane-frontends[] package ããã³ port ã¯ãã·ã³ãã«ã§ããã å¹ççãªã°ã©ãã£ã«ã«ã¤ã³ã¿ãã§ã¼ã¹ xscanimage ãã¤ã³ã¹ãã¼ã«ãã¾ãã
-
-䏿¹ãpackage:graphics/xsane[] package ã¾ã㯠port ããã¤ã³ã¹ãã¼ã«ããã xsane ã¯ã åºã使ããã¦ããããä¸ã¤ã®ã°ã©ãã£ã«ã«ãªã¹ãã£ãã³ã°ããã³ãã¨ã³ãã§ãã Xsane ã«ã¯ããã¾ãã¾ãªã¹ãã£ãã³ã°ã¢ã¼ãã è²è£æ£ããããã¹ãã£ã³ãªã©å
é²çãªæ©è½ãããã¾ãã ãããã®ã¢ããªã±ã¼ã·ã§ã³ã®ä¸¡æ¹ã¨ã GIMP ã®ãã©ã°ã¤ã³ã¨ãã¦ä½¿ç¨ãããã¨ãã§ãã¾ãã
+`scanimage` ã使ç¨ãã¦ã³ãã³ãã©ã¤ã³ããç»åãåå¾ãããã¨ãã§ãã¾ããã GUI ã使ç¨ãã¦ç»åãåå¾ã§ãããã¨ãæã¾ããã§ãããã Kooka ã xsane ã¨ãã£ãã¢ããªã±ã¼ã·ã§ã³ã¯ã åºã使ããã¦ããã¹ãã£ãã³ã°ããã³ãã¨ã³ãã§ãã ãããã«ã¯ããã¾ãã¾ãªã¹ãã£ãã³ã°ã¢ã¼ãã è²è£æ£ããããã¹ãã£ã³ãªã©å
é²çãªæ©è½ãããã¾ãã XSane ã¯ãGIMP ã®ãã©ã°ã¤ã³ã¨ãã¦ä½¿ç¨ãããã¨ãã§ãã¾ãã
=== ã¹ãã£ãã®è¨±å¯å±æ§
@@ -1040,6 +1036,35 @@ add path ugen0.2 mode 0660 group usb
add path usb/0.2.0 mode 0666 group usb
....
+[NOTE]
+====
+ããã¤ã¹ã追å ãããå¤ããã¨ã«ããã ããã¤ã¹ãã¼ããå¤ãããã¨ãããã¾ãã ãã®ããããã¹ã¦ã® USB ããã¤ã¹ã«ã¢ã¯ã»ã¹ãããå ´åã«ã¯ã 代ããã«ä»¥ä¸ã®ã«ã¼ã«ã»ããã使ã£ã¦ãã ããã
+
+[.programlisting]
+....
+[system=5]
+add path 'ugen*' mode 0660 group usb
+add path 'usb/*' mode 0666 group usb
+....
+
+====
+
+ãã®ãã¡ã¤ã«ã®è©³ç´°ã«ã¤ãã¦ã¯ã man:devfs.rules[5] ãåç
§ãã¦ãã ããã
+
+ã¤ãã«ã/etc/rc.conf ã§ã«ã¼ã«ã»ãããæå¹ã«ãã¦ãã ããã
+
+[.programlisting]
+....
+devfs_system_ruleset="system"
+....
+
+ããã¦ãman:devfs[8] ã·ã¹ãã ãåèµ·åãã¦ãã ããã
+
+[source,bash]
+....
+# service devfs restart
+....
+
æå¾ã«ãã¹ãã£ããå©ç¨ããã¦ã¼ã¶ã `_usb_` ã°ã«ã¼ãã«è¿½å ãã¦ã¹ãã£ããå©ç¨ã§ããããã«ãã¦ãã ããã
[source,bash]
diff --git a/documentation/content/ja/books/handbook/security/_index.adoc b/documentation/content/ja/books/handbook/security/_index.adoc
index e5322906ac..7c6972f6c1 100644
--- a/documentation/content/ja/books/handbook/security/_index.adoc
+++ b/documentation/content/ja/books/handbook/security/_index.adoc
@@ -48,9 +48,9 @@ toc::[]
[[security-synopsis]]
== ãã®ç« ã§ã¯
-ãã®ç« ã§ã¯ãåºæ¬çãªã·ã¹ãã ã»ãã¥ãªãã£ã®èãæ¹ã è¦ãã¦ããã¹ãä¸è¬çãªã«ã¼ã«ãç´¹ä»ãã FreeBSD ã«ãããé«åº¦ãªè©±é¡ã«ã¤ãã¦ç°¡åã«èª¬æãã¾ãã ããã§æ±ã話é¡ã®å¤ãã¯ã ä¸è¬çãªã·ã¹ãã ãã¤ã³ã¿ã¼ãããã»ãã¥ãªãã£ã«ããã¦ã¯ã¾ãã¾ãã ã·ã¹ãã ãå®å
¨ã«ä¿ã¤ãã¨ã¯ããã¼ã¿ãç¥ç財ç£ãæéããã®ä»ãã ããã«ã¼ããã®åé¡ããå®ãããã«ã¯æ¬ ããã¾ããã
+ç©ççãããã¯ä»®æ³çã«é¢ãããã ã»ãã¥ãªãã£ã¯å¹
åºããããã¯ã§ããã æ¥çå
¨ä½ãã»ãã¥ãªãã£ã¨ã¨ãã«æé·ãã¦ãã¾ãã ã·ã¹ãã ããã³ãããã¯ã¼ã¯ãå®å
¨ã«ããæ¨æºçãªæ¹æ³ã¯æ°å¤ãææ¸åããã¦ããã FreeBSD ã®ã¦ã¼ã¶ãã æ»æãä¾µå
¥è
ããå®ãæ¹æ³ãçè§£ããªããã°ãªãã¾ããã
-FreeBSD ã¯ã ã·ã¹ãã ã¨ãããã¯ã¼ã¯ã®æ´åæ§ããã³å®å
¨æ§ãä¿è·ããä»çµã¿ã¨ä¸é£ã®ã¦ã¼ãã£ãªãã£ãæä¾ãã¦ãã¾ãã
+ãã®ç« ã§ã¯ãã»ãã¥ãªãã£ã®åºç¤ãæè¡ã«ã¤ãã¦èª¬æãã¾ãã FreeBSD ã·ã¹ãã ã¯ãè¤æ°ã®ã¬ã¤ã¤ã«é¢é£ããã»ãã¥ãªãã£ãæä¾ãã¾ãã ããã¦ãå®å
¨æ§ãé«ããããã«ãµã¼ããã¼ãã£è£½ã®ã¦ã¼ãã£ãªãã£ãå©ç¨ãããã¨ãã§ãã¾ãã
ãã®ç« ãèªãã¨ã以ä¸ã®ãã¨ããããã¾ãã
@@ -74,188 +74,220 @@ FreeBSD ã¯ã ã·ã¹ãã ã¨ãããã¯ã¼ã¯ã®æ´åæ§ããã³å®å
¨æ§
[[security-intro]]
== ã¯ããã«
-ã»ãã¥ãªãã£ã¨ã¯ãã·ã¹ãã 管çè
ããã¤ãæ©ã¾ããä»äºã®ä¸ã¤ã§ãã FreeBSD ã¯ãåºæã®ã»ãã¥ãªãã£æ©æ§ãåãã¦ãã¾ããã 追å ã®ã»ãã¥ãªãã£æ©æ§ãè¨å®ãä¿å®ããä»äºã¯ããããã ã·ã¹ãã 管çè
ã¨ãã¦ãã£ã¨ã大ããªè²¬åã®ä¸ã¤ã§ãããã
+ã»ãã¥ãªãã£ãé«ãããã¨ã¯ãã¹ã¦ã®äººã®è²¬ä»»ã§ãã ã·ã¹ãã ã«å¼±ãä¾µå
¥ãã¤ã³ããåå¨ããã¨ãä¾µå
¥è
ã¯éè¦ãªæ
å ±ãå¾ããã ãããã¯ã¼ã¯å
¨ä½ã«è¢«å®³ãåã¼ããã¨ãã§ããããã«ãªãã¾ãã å¤ãã®ã»ãã¥ãªãã£ã®ãã¬ã¼ãã³ã°ã§ã¯ã æ
å ±ã·ã¹ãã ã®æ©å¯æ§ (confidentiality)ã å®å
¨æ§ (integrity) ããã³å¯ç¨æ§ (availability) ãæå³ããã»ãã¥ãªãã£ã® 3 è¦ç´ ã§ãã CIA ãåãæ±ããã¾ãã
-ã¾ããã·ã¹ãã ã»ãã¥ãªãã£ã«ã¯ã ãã¾ãã¾ãªå½¢ã§ã®æ»æã«å¯¾å¦ãããã¨ã¨ãé¢ä¿ãã¦ãã¾ãã æ»æã®ä¸ã«ã¯ `root` 権éã奪ããã¨ã¯ããªãããã©ãã ã¯ã©ãã·ã¥ãã·ã¹ãã ã®ä¸å®å®ç¶æ
ãå¼ãèµ·ãããã¨ãããã®ãããã¾ãã ãã®ã»ãã¥ãªãã£åé¡ã¯ãããã¤ãã«åé¡ãããã¨ãå¯è½ã§ãã
+CIA ã® 3 è¦ç´ ã¯ã ã³ã³ãã¥ã¼ã¿ã»ãã¥ãªãã£ã®åºæ¬ã¨ãªãèãã§ãã 顧客ãã¨ã³ãã¦ã¼ã¶ã¯ããã¼ã¿ã®ãã©ã¤ãã·ã¼ãæå¾
ãã¾ãã å½¼ãã¯ããã¼ã¿ã夿´ãããªããã¨ãã æ
å ±ãé ããã¦ãããã¨ãæå¾
ãã¾ãã å½¼ãã¯ã¾ãããã¤ã§ãæ
å ±ã«ã¢ã¯ã»ã¹ã§ãããã¨ãæå¾
ãã¾ãã ãããã¯ãã·ã¹ãã ã®æ©å¯æ§ãå®å
¨æ§ãå¯ç¨æ§ãæ§æãã¾ãã
-. ãµã¼ãã¹å¦¨å®³æ»æ (denial of service attack)
-. ã¦ã¼ã¶ã¢ã«ã¦ã³ãã®ä¸æ£å©ç¨ (user account compromise)
-. ã¢ã¯ã»ã¹å¯è½ãªãµã¼ãã¹ã使ã£ã root 権éã®ä¸æ£å©ç¨
-. ã¦ã¼ã¶ã¢ã«ã¦ã³ããçµç±ãã root 権éã®ä¸æ£ä½¿ç¨
-. ããã¯ãã¢ã®è¨ç½®
+ã»ãã¥ãªãã£ã®ãããã§ãã·ã§ãã«ã¯ãCIA ãå®ãããã«ãå¤å±¤é²è¡ã®æ¦ç¥ãæ¡ç¨ãã¾ãã ãã®å¤å±¤é²è¡æ¦ç¥ã§ã¯ã»ãã¥ãªãã£ã®ã¬ã¤ã¢ãè¤æ°ç¨æãããã¨ã§ã ä¸ã¤ã®ã¬ã¤ã¤ãç ´ããã¦ãã ã»ãã¥ãªãã£ã·ã¹ãã å
¨ä½ãç ´ããããã¨ãé²ãã¾ãã ã·ã¹ãã ã®ç®¡çè
ã¯ããã¡ã¤ã¢ã¦ã©ã¼ã«ãåã«æå¹ã«ããã ãã§ã¯ãªãã ãããã¯ã¼ã¯ãããã¯ã·ã¹ãã ãå®å
¨ã«ä¿ã¤å¿
è¦ãããã¾ãã ã¢ã«ã¦ã³ããç£æ»ãããã¤ããªã®å®å
¨æ§ã æªæã®ãããã¼ã«ãã¤ã³ã¹ãã¼ã«ããã¦ããªããã¨ã確èªããå¿
è¦ãããã¾ãã ãã®ããã«ã 管çè
ã¯è
å¨ãã©ã®ãããªãã®ããçè§£ããå¿
è¦ãããã¾ãã
-ãµã¼ãã¹å¦¨å®³æ»æ (DoS æ»æ) ã¨ã¯ã ãã·ã³ããå¿
è¦ãªè³æºã奪ãè¡çºã§ãã é常ããµã¼ãã¹å¦¨å®³æ»æã¯ãã®ãã·ã³ã§å®è¡ããããµã¼ãããããã¯ã¼ã¯ã¹ã¿ãã¯ãéè² è·ç¶æ
ã«ãã¦ã ãã·ã³ãã¯ã©ãã·ã¥ããããã ãã·ã³ã使ããªãããããããããªåä»»ãã®æ¹æ³ã§ãã ãµã¼ãããã»ã¹ã«å¯¾ããæ»æã¯ããªãã·ã§ã³ãé©åã«æå®ãããã¨ã«ãã£ã¦ã æ»æããã¦ããç¶æ³ã§ãµã¼ãããã»ã¹ã®è² è·ä¸æã«éçãè¨å®ãããã¨ã§å¯¾å¿ã§ããå ´åãå¤ãã§ãããããã«æ¯ã¹ãã¨ã ãããã¯ã¼ã¯ã¸ã®åä»»ãã®æ»æã¸ã®å¯¾å¿ã¯ãã£ã¨é£ãããªãã¾ãã ãã®æ»æã«ãã£ã¦ããã·ã³ãè½ã¨ãã¦ãã¾ããã¨ã¯ã§ããªãããããã¾ãããã æ¥ç¶ãã¦ããã¤ã³ã¿ã¼ãããåç·ã飽åããã¦ãã¾ããã¨ã¯ã§ãã¾ãã
+[[security-threats]]
+=== è
å¨
-ã¦ã¼ã¶ã¢ã«ã¦ã³ãã®ä¸æ£å©ç¨ã¯ã DoS æ»æããããã£ã¨ããããåé¡ã§ãã ãã®ãæå¢ã§ãã æå·åããã¦ããªããµã¼ãã¹ãå®è¡ããã¦ããã·ã¹ãã 管çè
ã¯å¤ãã ãã®ããããªã¢ã¼ããããã°ã¤ã³ãã¦ããã¦ã¼ã¶ã¯ã ãã¹ã¯ã¼ããè¦ãè¦ããã¦ãã¾ãå±éºæ§ãããã¾ãã ã·ã¹ãã 管çè
ãæ³¨ææ·±ã人ãªãã°ã ãªã¢ã¼ãã¢ã¯ã»ã¹ãã°ãè§£æãã¦ã çãããéä¿¡å
ã¢ãã¬ã¹ãçããããã°ã¤ã³ãæ¢ããã®ã§ãã
+ã³ã³ãã¥ã¼ã¿ã»ãã¥ãªãã£ãããè
å¨ã¨ã¯ä½ã§ããããï¼ é·å¹´ãè
å¨ã¯ãªã¢ã¼ãã®æ»æè
ã ããªãã¡é éããã®è¨±å¯ã®ãªãã·ã¹ãã ã¸ã®ã¢ã¯ã»ã¹ãä¼ã¦ã人ã
ã¨èãããã¦ãã¾ããã 仿¥ã§ã¯ããã®å®ç¾©ã¯å¾æ¥å¡ãæªæã®ããã½ããã¦ã§ã¢ã 䏿£ãªãããã¯ã¼ã¯ããã¤ã¹ãèªç¶ç½å®³ãã»ãã¥ãªãã£ã®èå¼±æ§ã ããã¦ç«¶åããä¼ç¤¾ã§ãããå«ããããã«æ¡å¼µããã¦ãã¾ãã
-ã»ãã¥ãªãã£ãååç¶æãã æå
¥ãã®è¡ãå±ããã·ã¹ãã ã«ããã¦ã¯ã ããã¦ã¼ã¶ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ãå¯è½ã¨ãªã£ã¦ãã å¿
ãããæ»æè
ã« `root` ã¸ã®ã¢ã¯ã»ã¹æ¨©ãä¸ããã¨ã¯éãã¾ããã `root` ã¸ã®ã¢ã¯ã»ã¹æ¨©ããªããã°ã æ»æè
ã¯èªåã®ä¾µå
¥ã®çè·¡ãé è½ãããã¨ãã§ãã¾ãããã ãã®ã¦ã¼ã¶ã®ãã¡ã¤ã«ãå¼ã£ããåãããã ãã·ã³ãã¯ã©ãã·ã¥ããããããã®ãããããã§ãã ã¦ã¼ã¶ã¢ã«ã¦ã³ãã®ä¸æ£å©ç¨ã¯ããããããã¨ã§ã¯ããã¾ããã ãªããªãä¸è¬ã¦ã¼ã¶ã¯ã ã·ã¹ãã 管çè
ã»ã©æ³¨æãæããªãå¾åãããããã§ãã
+æ¯æ¥ãæ°åãã®ã·ã¹ãã ããã³ãããã¯ã¼ã¯ãæ»æããã æ°ç¾ãã®ã·ã¹ãã ã許å¯ãªãã¢ã¯ã»ã¹ããã¦ãã¾ãã ç°¡åãªã¢ã¯ã·ãã³ãã¨ãã£ããã®ããããªã¢ã¼ãããã®æ»æã ç£æ¥ã¹ãã¤ã§ãã£ããã以ååãã¦ãã徿¥å¡ããã®æ»æã¨ãã£ãã±ã¼ã¹ãããã¾ãã ã·ã¹ãã ã®ã¦ã¼ã¶ã¨ãã¦ã¯ã ééããã»ãã¥ãªãã£éåã«ç¹ãã£ãå ´åã«ã¯ã å¯è½æ§ã®ããåé¡ãã»ãã¥ãªãã£ãã¼ã ã«å ±åãããã¨ãéè¦ã§ãã 管çè
ã¨ãã¦ã¯ãè
å¨ãææ¡ãã ãã®è
å¨ã®å½±é¿ãå°ããããããã«æºåããã¦ãããã¨ãéè¦ã§ãã
-`root` 権éã奪åããæ¹æ³ã¯ãæ½å¨çã«ä½éããããã¾ãã æ»æè
㯠`root` ã®ãã¹ã¯ã¼ããç¥ã£ã¦ããããããã¾ãããã æ»æè
ã `root` 権éã§å®è¡ããã¦ãããµã¼ãã¹ã®ãã°ã®èå¼±æ§ãå©ç¨ã§ããããããã¾ããã ã¾ããæ»æè
㯠SUID-root ããã°ã©ã ã«åå¨ãããã°ãç¥ã£ã¦ããããããã¾ããã æ»æè
ã¯ã ããã¯ãã¢ã¨ãã¦ç¥ããã¦ããããã°ã©ã ã使ã£ã¦èå¼±æ§ãªã·ã¹ãã ãæ¢ãããã ä¿®æ£ããã¦ããªãèå¼±æ§ãå©ç¨ãã¦ã¢ã¯ã»ã¹ãããã æ»æè
ã«ããéæ³è¡çºã®çè·¡ãæ¶ããã¨ãããããããããã¾ããã
+[[security-groundup]]
+=== ããã ã¢ããã¢ããã¼ã
-ã»ãã¥ãªãã£ãæ¹åããæ¹æ³ã¯ã常ã«ã ã¿ããã®ã®ç®ã®ããã«é層åããææ³ (a multi-layered "onion peel" approach) ã§å®è£
ãããã¹ãã§ãããããã¯æ¬¡ã®ããã«åé¡ã§ãã¾ãã
+ã»ãã¥ãªãã£ãèããä¸ã§ã ãã°ãã°ããã ã¢ããã¢ããã¼ããä¸çªè¯ãæ¹æ³ã¨ãªãã¾ãã ãã®èãã§ã¯ã管çè
ãåºæ¬çãªã¢ã«ã¦ã³ããã·ã¹ãã è¨å®ãè¡ã£ã¦ããã ãµã¼ããã¼ãã£è£½ã¦ã¼ãã£ãªãã£ã®è¨å®ã ããã¦ãããã¯ã¼ã¯ã¬ã¤ã¤ã«è¨å®ãåºãã¦ããã¾ãã ã·ã¹ãã ããªã·ã¼ããã³æç¶ããè¡ãä¸ã§ã¯ã ãã®ãããªè¨å®ã®å´é¢ãããã¾ãã
-. `root` ã¨ã¹ã¿ããã®ã¢ã«ã¦ã³ãã®å®å
¨æ§ãé«ããã
-. `root` ã®å®å
¨æ§ãé«ãã - `root` 権éã§åä½ãããµã¼ã㨠SUID/SGID ãã¤ããªã
-. ã¦ã¼ã¶ã¢ã«ã¦ã³ãã®å®å
¨æ§ãé«ããã
-. ãã¹ã¯ã¼ããã¡ã¤ã«ã®å®å
¨æ§ãé«ããã
-. ã«ã¼ãã«ã®ã³ã¢ãraw ããã¤ã¹ã ãã¡ã¤ã«ã·ã¹ãã ã®å®å
¨æ§ãé«ããã
-. ã·ã¹ãã ã«å¯¾ãã¦è¡ãªãããã ä¸é©åãªå¤æ´ããã°ããæ¤åºããã
-. å¿
è¦ã¨æããã以ä¸ã®å¯¾å¿ãã¨ã (paranoia)ã
+ãã¸ãã¹ã®å¤ãã®ç°å¢ã§ã¯ã 使ç¨ããããã¤ã¹ã®è¨å®ã«å¯¾ããã»ãã¥ãªãã£ããªã·ããã§ã«çå®ããã¦ãã¾ãã ãã®ããªã·ã«ã¯ãæä½éã¨ã³ãã¦ã¼ã¶ã®ã¯ã¼ã¯ã¹ãã¼ã·ã§ã³ã ãã¹ã¯ããããæºå¸¯é»è©±ãã©ãããããã¨ãã£ãã¢ãã¤ã«ããã¤ã¹ããã㳠製åããã³éçºãµã¼ãã®ä¸¡æ¹ã«å¯¾ããã»ãã¥ãªãã£ã®è¨å®ãå«ã¾ãã¦ããã¹ãã§ãã å¤ãã®å ´åã«ã¯ãã³ã³ãã¥ã¼ã¿ã®ã»ãã¥ãªãã£ãèããéã«ã æ¨æºä½æ¥æç¶æ¸ (SOP) ããã§ã«åå¨ãã¾ãã ããããªããã°ãã»ãã¥ãªãã£ãã¼ã ã«å°ãã¦ãã ããã
-次ã®ç¯ã§ã¯ãä¸è¨ã®é
ç®ã«ã¤ãã¦ããæ·±ãæãä¸ãã¦ããã¾ãã
+[[security-accounts]]
+=== ã·ã¹ãã ããã³ã¦ã¼ã¶ã¢ã«ã¦ã³ã
-[[securing-freebsd]]
-== FreeBSD ã®å®å
¨æ§ãé«ãã
+ã·ã¹ãã ãå®å
¨ã«ããã«ããããæãé©åãªåºçºç¹ã¯ã ã¢ã«ã¦ã³ãã®ç£æ»ã§ãã ã«ã¼ãã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ããå¼·åã§ãããã¨ã ã·ã§ã«ã¢ã¯ã»ã¹ãå¿
è¦ã¨ããªãã¢ã«ã¦ã³ãã¯ç¡å¹ã«ãããã¨ã確å®ã«ãããªã£ã¦ãã ããã ã¾ããæ¨©éãå¿
è¦ã¨ããã¦ã¼ã¶ã«å¯¾ãã¦ã¯ã package:security/sudo[] ãã¤ã³ã¹ãã¼ã«ãã¦ã ã¢ã¯ã»ã¹ãå¿
è¦ã¨ãªãã¢ããªã±ã¼ã·ã§ã³ã®ã¿ã«ã¢ã¯ã»ã¹ã許å¯ããããã«ãã¦ãã ããã root ã¦ã¼ã¶ã®ãã¹ã¯ã¼ãã¯ã決ãã¦å
±æãã¹ãã§ã¯ããã¾ããã
-ãã®ç¯ã§ã¯ã<<security-intro,åç¯>> ã§ã¨ãããã FreeBSD ã·ã¹ãã ã®å®å
¨æ§ãé«ããæ¹æ³ã«ã¤ãã¦èª¬æãã¾ãã
-
-[[securing-root-and-staff]]
-=== `root` ã¢ã«ã¦ã³ãã®å®å
¨æ§ãé«ãã
-
-ã»ã¨ãã©ã®ã·ã¹ãã ã§ã¯ã `root` ã¢ã«ã¦ã³ãã«å²ãå½ã¦ããã¹ã¯ã¼ãã 1 ã¤ããã¾ãã ãã®ãã¹ã¯ã¼ãã¯__ãã¤ã§ã__䏿£å©ç¨ã®å±éºã«æããã¦ããã¨èãã¦ãã ããã ããã¯ãã¹ã¯ã¼ããç¡å¹ã«ãã¹ãã ã¨è¨ã£ã¦ããã®ã§ã¯ããã¾ããã ãã¹ã¯ã¼ãã¯ããã·ã³ã«ã³ã³ã½ã¼ã«ããã¢ã¯ã»ã¹ããã®ã«ã¯ã ã»ã¨ãã©ãã¤ã§ãå¿
è¦ãªãã®ã§ãã ããããªãããã³ã³ã½ã¼ã«ä»¥å¤ããã¯ã ããã¦å¯è½ãªã man:su[1] ã³ãã³ããå®è¡ããå ´åããã¹ã¯ã¼ãã使ããªãããã«ããã¹ãã§ãã ãã¨ãã°ã[.filename]#/etc/ttys# ã®ã¨ã³ããªã«ããã¦ã ç¹å®ã®ã¿ã¼ããã«ã«å¯¾ã `root` ã§ãã°ã¤ã³ã§ããªãããã« `insecure` ã¨è¨å®ãã¦ãã ããã FreeBSD ã§ã¯ãããã©ã«ãã§ã [.filename]#/etc/ssh/sshd_config# ã«ãã㦠`PermitRootLogin` ã `no` ã¨è¨å®ããã¦ããã®ã§ãman:ssh[1] ã使ã£ã
`root` ã¸ãã°ã¤ã³ã¯ç¡å¹ã«ãªã£ã¦ãã¾ãã ãã¹ã¦ã®ã¢ã¯ã»ã¹ææ®µããã¨ãã° FTP ãããªãµã¼ãã¹ã¯ãè¯ãã¯ã©ãã¯ã®å¯¾è±¡ã¨ãªããã¨ãçè§£ãã¦ãã ããã `root` ã¸ã®ç´æ¥ãã°ã¤ã³ã¯ã ã·ã¹ãã ã³ã³ã½ã¼ã«çµç±ã§ã®ã¿å¯è½ã§ããã¹ããªã®ã§ãã
-
-ã·ã¹ãã 管çè
㯠`root` ã«ãªããããã«ãã¦ããå¿
è¦ãããã®ã§ã 追å ã®ãã¹ã¯ã¼ãèªè¨¼ã®è¨å®ãå¿
è¦ã¨ãªãã¾ãã ã²ã¨ã¤ã¯ãé©åãªã¦ã¼ã¶ã¢ã«ã¦ã³ãã [.filename]#/etc/group# ä¸ã® `wheel` ã«å ããæ¹æ³ã§ãã `wheel` ã®ã¡ã³ãã¯ãman:su[1] ã使ã£ã¦ `root` ã«ãªããã¨ã許ããã¾ãã å®éã« `root` ã¢ã¯ã»ã¹ã®å¿
è¦ãªã¦ã¼ã¶ã®ã¿ `wheel` ã«ç½®ãããã«ãã¹ãã§ãã Kerberos ã使ç¨ãã¦èªè¨¼è¡ãå ´åã«ã¯ã `root` ã®ãã¼ã ãã£ã¬ã¯ããªã« [.filename]#.k5login# ã使ãããã¨ã§ã 誰ã `wheel` ã«ç½®ãå¿
è¦ãªã man:ksu[1] ãããã¨ã許å¯ã§ãã¾ãã
-
-ã¢ã«ã¦ã³ããå®å
¨ã«ããã¯ããã«ã¯ã man:pw[8] ã使ã£ã¦ãã ããã
+ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ãç¡å¹ã«ããæ¹æ³ã¯äºéãããã¾ãã ä¸ã¤ç®ã®æ¹æ³ã¯ãã¢ã«ã¦ã³ããããã¯ããæ¹æ³ã§ããä¾ã¨ãã¦ã toor ã¢ã«ã¦ã³ããããã¯ããæ¹æ³ã以ä¸ã«ç¤ºãã¾ãã
[source,bash]
....
-# pw lock staff
+# pw lock toor
....
-ããã«ãããæå®ãããã¦ã¼ã¶ã¯ãman:ssh[1] ãå«ããããªãæ¹æ³ã§ããã°ã¤ã³ã§ããªããªãã¾ãã
+ãã®ã³ãã³ãã¯ãã¢ã«ã¦ã³ãã®è¨å®ã "toor:*:0:0::0:0:Bourne-again Superuser:/root:" ãã "toor:*LOCKED**:0:0::0:0:Bourne-again Superuser:/root:" ã¸ã¨å¤æ´ãã¾ãã
-ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ããããã¯ããããä¸ã¤ã®æ¹æ³ã¯ã æå·åããããã¹ã¯ã¼ãã "`*`" 1 æåã«ç½®ãæãããã¨ã§ãã ãã®æåã¯ãæå·åããããã¹ã¯ã¼ãã«ããããããã¨ã¯ãªãã®ã§ã ã¦ã¼ã¶ã¢ã¯ã»ã¹ããããã¯ãã¾ãã ãã¨ãã°ã次ã®ã¢ã«ã¦ã³ãã®ã¨ã³ããªãã
+ã¨ãã«ã¯ (ãããã追å ã®ãµã¼ãã¹ã®ããã«)ã ãã®æ¹æ³ã使ããªãå ´åãããã¾ãã ãã®ãããªå ´åã«ã¯ã以ä¸ã®ä¾ã®ããã«ã ã·ã§ã«ã /sbin/nologin ã«å¤æ´ãããã¨ã§ã ãã°ã¤ã³ã¢ã¯ã»ã¹ãæå¦ã§ãã¾ãã
-[.programlisting]
+[source,bash]
....
-foobar:R9DT/Fa1/LV9U:1000:1000::0:0:Foo Bar:/home/foobar:/usr/local/bin/tcsh
+# chsh -s /usr/sbin/nologin toor
....
-man:vipw[8] ã使ã£ã¦ä»¥ä¸ã®ããã«å¤æ´ãã¾ãã
+[NOTE]
+====
+ä»ã®ã¦ã¼ã¶ã®ã·ã§ã«ã¯ãã¹ã¼ãã¼ã¦ã¼ã¶ã®ã¿ã夿´ã§ãã¾ãã é常ã®ã¦ã¼ã¶ãè¡ããã¨ããã¨å¤±æãã¾ãã
+====
+
+ã¢ã«ã¦ã³ãæ
å ±ã¯ã以ä¸ã®ããã«æå¾ã®ã¨ã³ããªã "nologin" ã·ã§ã«ã¨ãªãã¾ãã
[.programlisting]
....
-foobar:*:1000:1000::0:0:Foo Bar:/home/foobar:/usr/local/bin/tcsh
+toor:*:0:0::0:0:Bourne-again Superuser:/root:/usr/sbin/nologin
....
-ãã®å¤æ´ã«ãã£ã¦ `foobar` ã¯ã é常ã®ãã°ã¤ã³ã¯ã§ããªããªãã¾ãã ãã®ãããªã¢ã¯ã»ã¹å¶éãããå¾ã¯ã ãµã¤ãã§ Kerberos ãã»ããã¢ãããããã ã¦ã¼ã¶ã man:ssh[1] ã®éµãè¨å®ãããªã©ã¨ãã£ãèªè¨¼ææ®µãå©ç¨ããªããã°ãªãã¾ããã
-
-ãããã®ã»ãã¥ãªãã£ã®ä»çµã¿ã§ã¯ã å¶éã®å¼·ããµã¼ãããå¶éã®å¼±ããµã¼ãã¸ãã°ã¤ã³ãããã¨ãåæã¨ãã¦ãã¾ãã ãã¨ãã°ããµã¼ãããããã¯ã¼ã¯ãµã¼ãã¹ãå®è¡ããã¦ããå ´åã ã¯ã¼ã¯ã¹ãã¼ã·ã§ã³ã§ã¯ãããã®ãµã¼ãã¹ãå®è¡ããã¦ã¯ãªãã¾ããã ã¯ã¼ã¯ã¹ãã¼ã·ã§ã³ãååã«å®å
¨ã«ãã¦ããããã«ã¯ã å®è¡ãããµã¼ãã¹ãã¼ãã«ããããå¯è½ãªéãæ¸ããã ãã¹ã¯ã¼ãã§ä¿è·ãããã¹ã¯ãªã¼ã³ã»ã¼ããèµ°ããã¦ããã¹ãã§ãã ã·ã¹ãã ã¸ã®ç©ççã¢ã¯ã»ã¹ãä¸ããããã¨ããã¨ã ãã¡ããè¨ãã¾ã§ããªãã æ»æè
ã¯ãããªã種é¡ã®ã»ãã¥ãªãã£ãããã¡ç ´ããã¨ãã§ããã®ã§ãã 幸ãã«ããã·ã¹ãã ç ´ãã®å¤§å¤æ°ã¯ããããã¯ã¼ã¯çµç±ã§ãªã¢ã¼ãããã ã·ã¹ãã ã¸ã®ç©ççã¢ã¯ã»ã¹ææ®µãæããªã人ã
ã«ãã£ã¦è¡ããã
¦ãã¾ãã
+[.filename]#/usr/sbin/nologin# ã·ã§ã«ã¯ã man:login[1] ã³ãã³ãããã®ã¦ã¼ã¶ã«ã·ã§ã«ãå²ãå½ã¦ããã¨ããããã¯ãã¾ãã
-Kerberos ã使ããã¨ã§ã ã¦ã¼ã¶ã®ãã¹ã¯ã¼ãã®å¤æ´ãããã¯åæ¢ãä¸ç®æã§è¡ãªããã¨ã¨ã ã¦ã¼ã¶ãã¢ã«ã¦ã³ããæã¤ãã¹ã¦ã®ãã·ã³ã«å³æã«ãã®å¹æãåã¼ããã¨ãå¯è½ã¨ãªãã¾ãã ã¢ã«ã¦ã³ããå±éºã«æãããã¨ãã«ã ãã¹ã¦ã®ãã·ã³ä¸ã®é¢é£ãããã¹ã¯ã¼ããå³åº§ã«å¤æ´ããè½åãéå°è©ä¾¡ãã¦ã¯ããã¾ããã Kerberos ã§ã¯ãKerberos ãã±ããã«ã¿ã¤ã ã¢ã¦ããè¨å®ã§ãã è¨å®ããæéãçµéããã¨ã¦ã¼ã¶ã«æ°ãããã¹ã¯ã¼ããé¸ã¶ããã«è¦æ±ããã¨ãã£ã追å ã®å¶éã課ãããã¨ãã§ãã¾ãã
+[[security-sudo]]
+=== ã¢ã«ã¦ã³ãã®æ¨©éãæ¡å¤§ãã
-=== root 権éã§å®è¡ããã¦ãããµã¼ã㨠SUID/SGID ãã¤ããªã®å®å
¨æ§ãé«ãã
+å ´åã«ãã£ã¦ã¯ã ã·ã¹ãã 管çè
ã¸ã®ã¢ã¯ã»ã¹ãä»ã®ã¦ã¼ã¶ã¨å
±æããå¿
è¦ãããã¾ãã FreeBSD ã¯ãã®ããã«äºã¤ã®æ¹æ³ãç¨æãã¦ãã¾ãã 第ä¸ã®æ¹æ³ã¯æ¨å¥¨ããã¾ãããã ã«ã¼ãã®ãã¹ã¯ã¼ããå
±æããã¦ã¼ã¶ã `wheel` ã°ã«ã¼ãã«å ããæ¹æ³ã§ãã ãããè¡ãã«ã«ã¯ã[.filename]#/etc/group# ãç·¨éãã æåã®ã°ã«ã¼ãã®æå¾ã«ã¦ã¼ã¶ã追å ãã¦ãã ããã ã¦ã¼ã¶ã¯ã«ã³ãåºåãã§ç®¡çããã¦ãã¾ãã
-ç¨å¿æ·±ãã·ã¹ãã 管çè
ã¯ãå¿
è¦ãªãµã¼ãã¹ã ããæå¹ã«ãã ãµã¼ããã¼ãã£è£½ã®ãµã¼ãã¯ã ãããã°ãæã£ã¦ããã¡ã ã¨ãããã¨ã«æ³¨æãã¦ãããã®ã§ãã æ³¨ææ·±ããã§ãã¯ãã¦ããªããµã¼ãã¯ã決ãã¦å®è¡ãã¦ã¯ããã¾ããã å¤ãã®ãã¼ã¢ã³ã¯ããµã¼ãã¹å°ç¨ã®ã¢ã«ã¦ã³ããããã㯠_ç å ´ (sandbox)_ ã§èµ·åããããã¨ãã§ããã®ã§ã `root` 権éã§ãµã¼ãã¹ãå®è¡ããåã«ã¯ãããèãã¦ãã ããã man:telnetd[8] ã¾ã㯠man:rlogind[8] ã®ãããªå®å
¨ã§ã¯ãªããµã¼ãã¹ã¯æå¹ã«ããªãã§ãã ããã
+権éã®æ¡å¤§ãããé©åãªæ¹æ³ã¯ã package:security/sudo[] port ãä½¿ãæ¹æ³ã§ãã ãã® port ã¯ã追å ã®ç£æ»ãããããç´°ããã¦ã¼ã¶ç®¡çãããã³ ã¦ã¼ã¶ã man:service[8] ã®ãããªæ¨©éãä¸ããããã³ãã³ã®ã¿ã®å®è¡ã«å¶éãããã¨ãã§ãã¾ãã
-ä»ã®ã·ã¹ãã ã®æ½å¨çãªã»ãã¥ãªãã£ãã¼ã«ã«ã¯ã SUID-root ããã³ SGID ãã¤ããªãããã¾ãã ãããã®ãã¤ããªã¯ã man:rlogin[1] ã®ããã«ã[.filename]#/bin#, [.filename]#/sbin#, [.filename]#/usr/bin# ã¾ã㯠[.filename]#/usr/sbin# ã«åå¨ãããã®ãã»ã¨ãã©ã§ãã 100% å®å
¨ãªãã®ã¯åå¨ããªãã¨ã¯ããã ã·ã¹ãã ããã©ã«ãã® SUID/SGID ãã¤ããªã¯æ¯è¼çå®å
¨ã¨ããã¾ãã SUID ãã¤ããªã¯ã ã¹ã¿ããã®ã¿ãã¢ã¯ã»ã¹å¯è½ãªç¹å¥ãªã°ã«ã¼ãã«å¶éãã 使ããªã SUID ãã¤ããªã¯åé¤ãããã¨ãæ¨å¥¨ããã¾ãã SGID ãã¤ããªãã»ã¨ãã©åæ§ã®å±éºãªåå¨ã«ãªãå¾ã¾ãã ä¾µå
¥è
ã kmem ã« SGID ããããã¤ããªãç ´ããã¨ãã§ããå ´åã ãã®ä¾µå
¥è
㯠[.filename]#/dev/kmem# ãèªã¿åºããã¨ãã§ããããã«ãªãã§ããããã¤ã¾ãã æå·åããããã¹ã¯ã¼ããã¡ã¤ã«ãèªã¿åºããã¨ã
ã§ããããã«ãªãã®ã§ã ã¦ã¼ã¶ã¢ã«ã¦ã³ãããæ½å¨çãªå±éºã«æããã¨ã«ãªãã¾ããä»ã«ãã `kmem` ã°ã«ã¼ããç ´ã£ãä¾µå
¥è
ã pty ãéãã¦éããããã¼ã¹ããã¼ã¯ãç£è¦ã§ããã¨ããå±éºãããã¾ãã ãã¼ã¹ããã¼ã¯ã«ã¯ãå®å
¨ãªæ¹æ³ã§ãã°ã¤ã³ããã¦ã¼ã¶ã使ã£ã¦ãã pty ãå«ã¾ãã¾ãã `tty` ã°ã«ã¼ããç ´ã£ãä¾µå
¥è
ã¯ãã»ã¼ä»»æã®ã¦ã¼ã¶ã® tty ã¸æ¸ãè¾¼ã¿ãã§ãã¾ãã ã¦ã¼ã¶ã端æ«ããã°ã©ã ããã¼ãã¼ããã·ãã¥ã¬ã¼ã·ã§ã³ããæ©è½ãæã£ãã¨ãã¥ã¬ã¼ã¿ã使ã£ã¦ããå ´åã ä¾µå
¥è
ã¯æ½å¨çã«ã çµå±ãã®ã¦ã¼ã¶ã¨ãã¦å®è¡ãããã³ãã³ããã¦ã¼ã¶ã®ç«¯æ«ã«ã¨ã³ã¼ããããã¼ã¿ã¹ããªã¼ã ãçæã§ããå¯è½æ§ãããã¾ãã
+ã¤ã³ã¹ãã¼ã«ãçµãã£ããã `visudo` ã¤ã³ã¿ãã§ã¼ã¹ã使ã£ã¦ [.filename]#/usr/local/etc/sudoers# ãã¡ã¤ã«ãç·¨éãã¦ãã ããã 以ä¸ã®ä¾ã§ã¯ãæ°ãã webadmin ã°ã«ã¼ãã使ããã `trhodes` ã¦ã¼ã¶ããã®ã°ã«ã¼ãã«è¿½å ããã¾ãã ãã®å¾ãã¦ã¼ã¶ã« package:apache24[] ãåèµ·åããã¢ã¯ã»ã¹æ¨©éãä¸ãã¾ãã ãã®æç¶ãã¯ä»¥ä¸ã®ããã«ãªãã¾ãã
-[[secure-users]]
-=== ã¦ã¼ã¶ã¢ã«ã¦ã³ãã®å®å
¨æ§ãé«ãã
-
-ã¦ã¼ã¶ã¢ã«ã¦ã³ãã¯ãæ®éãå®å
¨æ§ãé«ãããã¨ãæãå°é£ã§ãã æ°ãé
ã£ã¦ã¦ã¼ã¶ã¢ã«ã¦ã³ããç£è¦ããããã»ãããã¾ããã ã¦ã¼ã¶ã¢ã«ã¦ã³ãã«å¯¾ã man:ssh[1] ã Kerberos ãå©ç¨ããã«ã¯ã ã·ã¹ãã 管çãããã«å¢ããããã¯ãã«ã«ãµãã¼ããå¿
è¦ã«ãªãã¾ããã æå·åãã¹ã¯ã¼ããã¡ã¤ã«ã¨æ¯è¼ããã¨ã¯ããã«è¯ãæ¹æ³ãæä¾ãã¾ãã
-
-=== ãã¹ã¯ã¼ããã¡ã¤ã«ã®å®å
¨æ§ãé«ãã
-
-ã§ããã ãå¤ãã®ãã¹ã¯ã¼ããã¢ã¹ã¿ãªã¹ã¯ã§å¤ãã ãããã®ã¢ã«ã¦ã³ãã®ã¢ã¯ã»ã¹ã«ã¯ man:ssh[1] ã Kerberos ã使ãããã«ãããã¨ããå¯ä¸ã®ç¢ºå®ãªæ¹æ³ã§ãã æå·åãã¹ã¯ã¼ããã¡ã¤ã« ([.filename]#/etc/spwd.db#) 㯠`root` ã§ã®ã¿èªã¿åºãå¯è½ã ããã©ãã ãã¨ããä¾µå
¥è
ã root ã®æ¸ãè¾¼ã¿æ¨©éã¯å¾ãããªãã¨ãã èªã¿åºãã¢ã¯ã»ã¹æ¨©éãå¾ããã¨ã¯å¯è½ããããã¾ããã
-
-<<security-integrity,ãã¡ã¤ã«ã®å®å
¨æ§ã®ãã§ãã¯>> ç¯ã§èª¬æããã¦ããããã«ã ã»ãã¥ãªãã£ã¹ã¯ãªããã§ãã¹ã¯ã¼ããã¡ã¤ã«ã®å¤æ´ããã§ãã¯ãã å ±åããããã«ãã¹ãã§ãã
-
-=== ã«ã¼ãã«ã®ã³ã¢ãraw ããã¤ã¹ã ãã¡ã¤ã«ã·ã¹ãã ã®å®å
¨æ§ãé«ãã
-
-æè¿ã®ã«ã¼ãã«ã¯ãçµã¿è¾¼ã¿ã®ãã±ããè¦ãè¦ããã¤ã¹ (packet sniffing device) ãã©ã¤ããåãã¦ãããã®ãã»ã¨ãã©ã§ãã FreeBSD ã§ã¯ [.filename]#bpf# ã¨å¼ã°ãã¦ãã¾ãã ãã®ããã¤ã¹ã¯ DHCP ã§å¿
è¦ã¨ãªãããã DHCP ãæä¾ããã使ãå¿
è¦ã®ãªãã·ã¹ãã ã§ã¯ã ã«ã¹ã¿ã ã«ã¼ãã«ã³ã³ãã£ã°ã¬ã¼ã·ã§ã³ãã¡ã¤ã«ããå¤ããã¨ãã§ãã¾ãã
-
-[.filename]#bpf# ãå¤ãã¦ãã [.filename]#/dev/mem# ããã³ [.filename]#/dev/kmem# ã¨ããåé¡ãã¾ã æ®ã£ã¦ãã¾ãã ä¾µå
¥è
㯠raw ãã£ã¹ã¯ããã¤ã¹ã«æ¸ãè¾¼ããã¨ãã§ãã¾ãã ããæ°ã¾ãã¾ãã®ä¾µå
¥è
ã¯ãman:kldload[8] ã使ã£ã¦èªåç¬èªã® [.filename]#bpf#ã ãããã¯ä»ã®è¦ãè¦ããã¤ã¹ãåä½ä¸ã®ã«ã¼ãã«ã«ã¤ã³ã¹ãã¼ã«ã§ãã¾ãã ãã®åé¡ãé¿ãããããã«ã¼ãã«ãããé«ãã»ãã¥ãªãã£ã¬ãã«ã å°ãªãã¨ãã»ãã¥ãªãã£ã¬ãã« 1 ã§å®è¡ãããå¿
è¦ãããã¾ãã
-
-ã«ã¼ãã«ã®ã»ãã¥ãªãã£ã¬ãã«ã¯ããã¤ãã®æ¹æ³ã§è¨å®ã§ãã¾ãã ç¾å¨åãã¦ããã«ã¼ãã«ã®ã»ãã¥ãªãã£ã¬ãã«ãé«ããæãç°¡åãªæ¹æ³ã¯ã `kern.securelevel` ãè¨å®ããæ¹æ³ã§ãã
+[source,bash]
+....
+# pw groupadd webadmin -M trhodes -g 6000
+....
[source,bash]
....
-# sysctl kern.securelevel=1
+# visudo
....
-ããã©ã«ãã§ã¯ãFreeBSD ã®ã«ã¼ãã«ã¯ã»ãã¥ãªãã£ã¬ãã« -1 ã§èµ·åãã¾ãã ãã®ã»ãã¥ãªãã£ã¬ãã«ã¯ã 夿´ä¸å¯ã®ãã¡ã¤ã«ãã©ã°ãå¤ãããã ãã¹ã¦ã®ããã¤ã¹ã«å¯¾ãã¦èªã¿è¾¼ã¿ããã³æ¸ãè¾¼ã¿ãã§ãããããã®ã§ã "insecure mode" ã¨å¼ã°ãã¾ãã ãã®ã»ãã¥ã¢ã¬ãã«ã¯ã管çè
ã¾ã㯠man:init[8] ã«ããèµ·åæã®ã¹ã¯ãªããã«ãã夿´ãããªãéã -1 ã®ã¾ã¾ã§ãã [.filename]#/etc/rc.conf# ã«ããã¦ã `kern_securelevel_enable` ã `YES` ã¨ãã `kern_securelevel` ã«å¿
è¦ã¨ããå¤ãè¨å®ãããã¨ã§ã ã·ã¹ãã èµ·åæã«ã»ãã¥ã¢ã¬ãã«ãé«ãããã¨ãã§ãã¾ãã
+[.programlisting]
+....
+%webadmin ALL=(ALL) /usr/sbin/service apache24 *
+....
-ã»ãã¥ãªãã£ã¬ãã«ã 1 以ä¸ã«è¨å®ããã¨ã 追å å°ç¨ããã³å¤æ´ä¸å¯ãã¡ã¤ã«ã®ãã©ã°ãå¤ããã¨ã¯ã§ããªããªãã ã¾ã raw ããã¤ã¹ã¸ã®ã¢ã¯ã»ã¹ãæå¦ããã¾ãã ããé«ãã¬ãã«ã«è¨å®ããã¨ãããå¤ãã®æä½ã«å¶éããããã¾ãã åã»ãã¥ãªãã£ã¬ãã«ã®å®å
¨ãªèª¬æã«ã¤ãã¦ã¯ã man:security[7] ããã³ man:init[8] ãã覧ãã ããã
+ãã¼ã«ã«ã®ã¦ã¼ã¶ç®¡çã«ããã¦ã package:security/sudo[] ã¯ã é常ã«è²´éãªãªã½ã¼ã¹ãæä¾ãã¾ãã ã¾ãããã¹ã¯ã¼ããä¸å¿
è¦ã«ãã¦ãããã©ã«ãã man:ssh[1] éµã®æ¹æ³ã ãã«ãããã¨ãã§ãã¾ãã man:sshd[8] çµç±ã®ãã¹ã¯ã¼ãã«ãããã°ã¤ã³ãç¡å¹ã«ãã `sudo` ã¸ã®ãã¼ã«ã«ãã¹ã¯ã¼ãã®ã¿ã使ãããã«ããã«ã¯ã <<openssh>> ãã覧ãã ããã
+
+[[security-passwords]]
+=== ãã¹ã¯ã¼ã
+
+ãã¹ã¯ã¼ãã¯ããã¯ããã¸ã¼ã«ãããå¿
è¦æªã§ãã ãã¹ã¯ã¼ãã¯æ¥µãã¦è¤éã§ããã ãã§ã¯ãªãã ãã¹ã¯ã¼ããä¿è·ããå¼·åãªããã·ã¥ã¡ã«ããºã ãã¾ãå¿
è¦ã¨ãªãã¾ãã ãã®ææ¸ãæ¸ãã¦ããæç¹ã§ã¯ã FreeBSD 㯠`crypt()` ã©ã¤ãã©ãªã§ DES, MD5, Blowfish, SHA256 ããã³ SHA512 ã«å¯¾å¿ãã¦ãã¾ãã ããã©ã«ã㯠SHA512 ã§ããã 強度ã®å¼±ãæå·ã¸ã¯å¤æ´ãã¹ãã§ã¯ããã¾ããã ããããªãããBlowfish ã好ãã¦ã¼ã¶ãããã¾ãã DES ãé¤ãåã¡ã«ããºã ã§ã¯ã éå§ã®æåã使ç¨ãã¦ããããã·ã¥ã¡ã«ããºã ãèå¥å¯è½ãªç¹å¾´ãæã£ã¦ãã¾ãã MD5 ã¡ã«ããºã ã§ã¯ãã·ã³ãã«ã¯ "$" ã®ç¬¦å·ã§ãã SHA256 ã¾ãã¯ã SHA512 ã§ã¯ãã·ã³ãã«ã¯ "$6$"ã ãã㦠Blowfish 㯠"$2a$" ã§ãã æå·å¼·åº¦ã®å¼±ããã¹ã¯ã¼ãã使ç¨ãã¦ããå ´åã«ã¯ã 次åã®ãã°ã¤ã³æã«ã¦ã¼ã¶ã
man:passwd[1] ãå®è¡ãã¦åããã·ã¥åãããã¨ãä¿ãã¹ãã§ãã
[NOTE]
====
-ã»ãã¥ãªãã£ã¬ãã«ã 1 以ä¸ã«è¨å®ããå ´åã«ã¯ã [.filename]#/dev/io# ã¸ã®ã¢ã¯ã»ã¹ããããã¯ãããããã Xorg ãã `installworld` ã®ããã»ã¹ã§ã¯ã ããã¤ãã®ãã¡ã¤ã«ã®è¿½å å°ç¨ããã³å¤æ´ä¸å¯ã®ãã©ã°ã¯ä¸æçã«ãªã»ãããããããã ã½ã¼ã¹ãã FreeBSD ãæ§ç¯ãã¦ã¤ã³ã¹ãã¼ã«ããã¨ããªã©ã§åé¡ãå¼ãèµ·ããããå¯è½æ§ãããã¾ãã Xorg ã®åé¡ã«ã¤ãã¦ã¯ã èµ·åããã»ã¹åæã®ã»ãã¥ã¢ã¬ãã«ãååä½ãã¨ãã« man:xdm[1] ãèµ·åãããã¨ã§ããã®åé¡ã«å¯¾å¿ã§ãã¾ãã ãã®ãããªå¿æ¥å¦ç½®ã¯ã ãã¹ã¦ã®ã»ãã¥ãªãã£ã¬ãã«ãããããèª²ãæ½å¨çãªãã¹ã¦ã®å¶éã«ã¯å¯¾å¿ã§ããªãã§ãããã å°ãå
ãè¦è¶ããè¨ç»çãªå¯¾å¿ããã¹ãã§ãã åã»ãã¥ãªãã£ã¬ãã«ã§èª²ãããå¶éã¯ã ã·ã¹ãã ã使ç¨ãããã¨ã«ããå©ä¾¿æ§ãèããæ¸ããã¦ã
ã¾ãããã ãã®å¶éãçè§£ãããã¨ã¯éè¦ã§ãã ã¾ããåã»ãã¥ãªãã£ã¬ãã«ã®å¶éãçè§£ãããã¨ã§ã ããã©ã«ãã®è¨å®ãããã·ã³ãã«ã«ã§ãã è¨å®ã«é¢ããæå¤æ§ãå°ãªãã§ããã§ãããã
+ãã®ææ¸ãæ¸ãã¦ããæç¹ã§ãBlowfish 㯠AES ã§ãªããã°ã FIPS (Federal Information Processing Standards) ã«æºæ ããã¦ãã¾ããã ãã®ããã使ç¨ã§ããªãç°å¢ãããã¾ãã
====
-ã«ã¼ãã«ã®ã»ãã¥ãªãã£ã¬ãã«ã 1 以ä¸ã«è¨å®ããå ´åã«ã¯ã ã·ã¹ãã èµ·åã«é¢ããéè¦ãªãã¤ããªããã£ã¬ã¯ããªã ã¹ã¯ãªãããã¡ã¤ã«ãããã¦ã ã»ãã¥ãªãã£ã¬ãã«ãè¨å®ãããã¾ã§ã®éã«å®è¡ããããã¹ã¦ã®ãã®ã«å¯¾ãã¦ã `schg` ãã©ã°ãè¨å®ãããã¨ã¯æç¨ã§ãããã ã·ã¹ãã ãããé«ãã»ãã¥ãªãã£ã¬ãã«ã§å®è¡ãããããã«ãããã `schg` ãã©ã°ãè¨å®ããªãã¨ããã¨ããã§å¦¥åããã¨ããæãããã¾ãã ããä¸ã¤ã®å¯è½æ§ã¨ãã¦ã¯ãåç´ã« [.filename]#/# ããã³ [.filename]#/usr# ãèªã¿è¾¼ã¿å°ç¨ã§ãã¦ã³ããããã¨ã§ãã ããã§ç¹çãã¹ããã¨ã¯ãã·ã¹ãã ãå®ããã¨ãã¦å³ããããããã¨ã ä¾µå
¥ãæ¤åºãããã¨ãã§ããªããªã£ã¦ãã¾ãã¨ãããã¨ã§ãã
+ãããã¯ã¼ã¯ã«æ¥ç¶ãã¦ããã·ã¹ãã ã«ã¤ãã¦ã¯ã äºè¦ç´ èªè¨¼ã使ç¨ãã¹ãã§ãã ãã®èªè¨¼ã§ã¯ãé常ããªããææããè¦ç´ ã¨ç¥ã£ã¦ããè¦ç´ ãç¨ãããã¾ãã FreeBSD ã®ãã¼ã¹ã·ã¹ãã ã«å«ã¾ãã¦ãã OpenSSH ããã³ ssh-keys ã§ã¯ã ãããã¯ã¼ã¯ã¸ã®ãã¹ã¦ã®ãã°ã¤ã³ã«ãããäºè¦ç´ èªè¨¼ã®äº¤æã§ã ãã¹ã¯ã¼ãã使ç¨ãã¹ãã§ã¯ããã¾ããã ããè©³ç´°ãªæ
å ±ã«ã¤ãã¦ã¯ããã³ãããã¯ã® <<openssh>> ç¯ãã覧ãã ããã Kerberose ã®ã¦ã¼ã¶ã¯ããããã¯ã¼ã¯ã§ OpenSSH ãå®è£
ããããã«è¿½å ã®å¤æ´ãå¿
è¦ã«ãªãã§ãããã
-[[security-integrity]]
-=== ãã¡ã¤ã«ã®å®å
¨æ§ã®ãã§ãã¯
+[[security-rkhunter]]
+=== ããã¯ãã¢ããã³ã«ã¼ãããã
-ã·ã¹ãã 管çè
ã«ã§ãããã¨ã¯ã 便å©ãã¨ããè¦ç´ ããã®éãé ãä¸ããªãç¨åº¦ã«ã ã³ã¢ã·ã¹ãã ã®è¨å®ã¨å¶å¾¡ãã¡ã¤ã«ãé²å¾¡ãããã¨ã ãã§ãã ãã¨ãã°ã[.filename]#/# ããã³ [.filename]#/usr# ã«ãã大é¨åã®ãã¡ã¤ã«ã« `schg` ããããè¨å®ããããã« man:chflags[1] ã使ç¨ããã®ã¯ãããããé广ã§ãããã ãªããªãããããããã¨ã§ãã¡ã¤ã«ã¯ä¿è·ã§ãã¾ããã ä¾µå
¥ãæ¤åºããçªãéããã¦ãã¾ããã¨ã«ããªãããã§ãã ã»ãã¥ãªãã£å¯¾çã¯ã ä¾µå
¥ã®å¯è½æ§ãæ¤åºã§ããªããã°ãæç¨ã§ã¯ãªãã ãã£ã¨æªããã°ãå®å
¨æ§ã«å¯¾ããééã£ãæè¦ãæ¤ãä»ãã¦ãã¾ãã¾ãã ã»ãã¥ãªãã£ã«å¯¾ããä»äºã®ååã¯ã æ»æè
ãæ»æã®æä¸ã«æããããã«ããããã«ã æ»æè
ãé£ãæ¢ããã®ã§ã¯ãªãä¾µå
¥ãé
ããããã¨ãªã®ã§ãã
+ããã¯ãã¢ããã³ã«ã¼ããããã¯ã ããããã¤ã³ã¹ãã¼ã«ãããå¾ã«è
å¨ã¨ãªãã¾ãã ã¤ã³ã¹ãã¼ã«ãããã¨ããã®æªæã®ããã½ããã¦ã§ã¢ã¯ã æ»æè
ã®ããã«ä¾µå
¥å£ãè¨ç½®ãã¾ãã å®éçã«ã¯ãã·ã¹ãã ãä¸åº¦æ±æãããå¾ã«ã調æ»ãè¡ããã æ¶å»ããã¾ãã æ
éãªã»ãã¥ãªãã£ãã·ã¹ãã ã¨ã³ã¸ãã¢ã§ãããã æ»æè
ãæ®ããã½ããã¦ã§ã¢ãè¦éãã¦ãã¾ãã¨ããæããããªã¹ã¯ãåå¨ãã¦ãã¾ãã
-ä¾µå
¥ãæ¤åºããæãè¯ãæ¹æ³ã¯ã夿´ããã¦ãããã æ¶ãã¦ããããå
¥ããè¦ãããªãã®ã«å
¥ã£ã¦ãããã¡ã¤ã«ãæ¢ããã¨ã§ãã 夿´ããããã¡ã¤ã«ãæ¢ãã®ã«æãè¯ãæ¹æ³ã¯ãããä¸ã¤ã® ãã°ãã°ä¸å¤®ã«éããããã ã¢ã¯ã»ã¹ãå¶éãããã·ã¹ãã ããè¡ãªããã®ã§ãã ããã«å®å
¨ã§ã¢ã¯ã»ã¹å¶éãããã·ã¹ãã ä¸ã§ã»ãã¥ãªãã£ç¨ã¹ã¯ãªãããæ¸ãã°ã ã¹ã¯ãªããã¯æ½å¨çãªæ»æè
ããã¯ã»ã¼è¦ããªããªãã¾ãã ãã®æå¹æ§ãæå¤§éã«æ´»ç¨ããããã«ã¯ã ã¢ã¯ã»ã¹ã®å¶éããããã·ã³ããä»ã®ãã·ã³ã¸ã®ããªãã®ã¢ã¯ã»ã¹ã許å¯ããå¿
è¦ãããã¾ãã æ®éã¯ãèªã¿è¾¼ã¿å°ç¨ã® NFS ã¨ã¯ã¹ãã¼ãããããã man:ssh[1] éµã®ãã¢ãè¨å®ããããã¾ãã ãããã¯ã¼ã¯ã®ãã©ãã£ãã¯ãå¥ã«ãã¦ã NFS ã¯æãå¯è¦æ§ã®ãªãæ¹æ³ã§ãã 管çè
ã
¯ãåã¯ã©ã¤ã¢ã³ãä¸ã®ãã¡ã¤ã«ã·ã¹ãã ãã äºå®ä¸æ¤åºãããã«ç£è¦ã§ããããã«ãªãã¾ãã ã¢ã¯ã»ã¹å¶éããããµã¼ããã¹ã¤ãããéãã¦ã¯ã©ã¤ã¢ã³ãã«æ¥ç¶ããã¦ããå ´åã ããã¦ã NFS ãããè¯ã鏿è¢ã§ãã ã¢ã¯ã»ã¹å¶éããããµã¼ããã ããã¤ãã®ã«ã¼ãã£ã³ã°å±¤ãéãã¦ã¯ã©ã¤ã¢ã³ãã«æ¥ç¶ãã¦ããå ´åã NFS ã¯ãã¾ãã«ãå±éºãªã®ã§ã man:ssh[1] ã®æ¹ãè¯ãæ¹æ³ã§ãããã
+ããã¯ãã¢ã¾ãã¯ã«ã¼ããããã½ããã¦ã§ã¢ã¯ã 管çè
ã«ã¨ã£ã¦å½¹ã«ç«ã¤ãã¨ãä¸ã¤ããã¾ãã ããã¯ãä¸åº¦æ¤åºããã¨ã ã·ã¹ãã ã®ã©ãããå±éºã«åããã¦ãããã¨ã®çè·¡ã¨ãªãã¾ãã ããããé常ãã®ç¨®ã®ã¢ããªã±ã¼ã·ã§ã³ã¯ãã¨ã¦ããã¾ãé ãã¦ãã¾ãã ããã¯ãã¢ããã³ã«ã¼ãããããæ¤åºãããã¼ã«ãåå¨ãã¦ããã ãããã¡ã®ä¸ã¤ãã package:security/rkhunter[] ã§ãã
-ã¢ã¯ã»ã¹å¶éããããã·ã³ã«ã ç£è¦ãããã¨ããã¯ã©ã¤ã¢ã³ãã·ã¹ãã ã¸ã®å°ãªãã¨ãèªã¿è¾¼ã¿ã®ã¢ã¯ã»ã¹æ¨©ãä¸ãããã æ¬¡ã«ç£è¦ããããã®ã¹ã¯ãªãããæ¸ããªãã¦ã¯ããã¾ããã NFS ãã¦ã³ããããã°ãman:find[1] ã man:md5[1] ãªã©ã®åç´ãªã·ã¹ãã ã¦ã¼ãã£ãªãã£ã§ã¹ã¯ãªãããæ¸ããã¨ãã§ãã¾ãã å°ãªãã¨ã 1 æ¥ 1 åãã¯ã©ã¤ã¢ã³ãã®ã·ã¹ãã ãã¡ã¤ã«ãç´æ¥ man:md5[1] ã«ããã ããã«ãã£ã¨é »ç¹ã« [.filename]#/etc# ããã³ [.filename]#/usr/local/etc# ã«ãããããªã³ã³ããã¼ã«ç¨ãã¡ã¤ã«ã試é¨ããã®ãä¸çªã§ãã ã¢ã¯ã»ã¹å¶éããããã·ã³ãæ£ããã¨ç¥ã£ã¦ããã åºã¨ãªã md5 æ
å ±ã¨æ¯ã¹ã¦éããè¦ã¤ãã£ãå ´åã ã·ã¹ãã 管çè
ã«è¦åããããã«ãã¹ãã§ãã åªããã»ãã¥ãªãã£ç¨ã¹ã¯ãªããã¯ã [.filename]#/# ããã³ [.filename]#/usr# ãªã©ã
®ã·ã¹ãã ãã¼ãã£ã·ã§ã³ä¸ã§ä¸é©å½ã« SUID ããããã¤ããªãã æ°ãã«ä½æããããã¡ã¤ã«ãåé¤ããããã¡ã¤ã«ããªããã©ããã調ã¹ãã§ãããã
+ã¤ã³ã¹ãã¼ã«å¾ã以ä¸ã®ã³ãã³ãã§ã·ã¹ãã ããã§ãã¯ã§ãã¾ãã å®è¡ããã¨å¤ãã®æ
å ±ãåºåããã¾ãã
-NFS ã§ã¯ãªããman:ssh[1] ã使ç¨ããå ´åã¯ã ã»ãã¥ãªãã£ç¨ã¹ã¯ãªãããæ¸ãã®ã¯ããé£ãããã¨ã§ãã ãã¨ãã°ãã¹ã¯ãªãããåããããã«ã¯ãã¯ã©ã¤ã¢ã³ãã«å¯¾ãã¦ã¹ã¯ãªããã man:scp[1] ããªãã¦ã¯ããã¾ãããã ã¯ã©ã¤ã¢ã³ããã·ã³ã® man:ssh[1] ã¯ã©ã¤ã¢ã³ãã¯ãã§ã«æ»æããã¦ãã¾ã£ã¦ããããããã¾ããã å®å
¨ã§ãªããªã³ã¯ä¸ã®å ´å㯠man:ssh[1] ã¯å¿
è¦ããããã¾ãããã æ±ãã¯ã¨ã¦ã大å¤ã«ãªãã¾ãã
+[source,bash]
+....
+# rkhunter -c
+....
-åªããã»ãã¥ãªãã£ç¨ã¹ã¯ãªããã¯ã [.filename]#.rhosts#, [.filename]#.ssh/authorized_keys# ãªã©ã®é ãè¨å®ãã¡ã¤ã«ã®å¤æ´ããã§ãã¯ãããã®ã§ãã ããã㯠`MD5` ãã§ãã¯ã®ç¯å²å¤ã«ãªã£ã¦ãã¾ãã§ããããã¡ã¤ã«ç¾¤ã§ãã
+ãã®ããã»ã¹ãå®è¡ä¸ã« kbd:[ENTER] ãã¼ãä½åº¦ãæ¼ãå¿
è¦ãããã¾ãã å®äºããã¨ãã¹ãã¼ã¿ã¹ã¡ãã»ã¼ã¸ãç»é¢ã«è¡¨ç¤ºããã¾ãã ãã®ã¡ãã»ã¼ã¸ã¯ããã§ãã¯ãããã¡ã¤ã«ã®éãçããããã¡ã¤ã«ã®æ°ã å¯è½æ§ã®ããã«ã¼ããããçã®æ
å ±ãå«ã¿ã¾ãã ãã§ãã¯ã®æä¸ãé ããããã¡ã¤ã«ã OpenSSH ãããã³ã«ã®é¸æãããã¦ã æã«ã¯ãã¤ã³ã¹ãã¼ã«ããã¦ããã½ããã¦ã§ã¢ã®æ¼¸å¼±æ§ã®ãã¼ã¸ã§ã³ã«é¢ããä¸è¬çãªã»ãã¥ãªãã£ã®è¦åãåºåããã¾ãã ããã«ããããã¯ãã詳細ãªè§£æãè¡ãããå¾ã«ã対å¿ãå¯è½ã§ãã
-ã¦ã¼ã¶ç¨ã®ãã£ã¹ã¯å®¹éãé常ã«å¤§ããå ´åã¯ã ãã¼ãã£ã·ã§ã³ä¸ã®åãã¡ã¤ã«ãè¦ã¦åãã®ã«å¤§å¤ãªæéããããããããã¾ããã ãã®å ´åã¯ãman:mount[8] ã«ãã `nosuid` ã使ããã¨ã§ããã¦ã³ããã©ã°ãè¨å®ãã¦ã SUID ããããã¤ããªãç½®ããªãããã«ããã®ãè¯ãèãã§ãã å°ãªãã¨ãé±ã« 1 度ã¯ãã¡ã¤ã«ã·ã¹ãã ãã¹ãã£ã³ããã¹ãã§ãã ãªããªããç®çã¯ãä¾µå
¥ãæåãããã©ããã«é¢ãããã 䏿£ä¾µå
¥ã®è©¦ã¿ããã£ããã¨ã®æ¤åºããããã¨ã ããã§ãã
+管çè
ã¯çã æ
å½ãã¦ããã·ã¹ãã ä¸ã§ä½ãå®è¡ããã¦ããããææ¡ãã¦ããå¿
è¦ãããã¾ãã rkhunter, lsof ã man:netstat[1] ããã³ man:ps[1] ã¨ãã£ããã¤ãã£ãã®ãã¼ã«ã¯ã ã·ã¹ãã ã«é¢ããããªãå¤ãã®æ
å ±ãä¸ãã¦ããã¾ãã æ£å¸¸ãªç¶æ
ãã©ã®ãããªç¶æ
ã§ããããææ¡ãã¦ããã æ¬æ¥ã¨éãç¶æ³ã«ãªã£ãå ´åã«ã¯ã質åããããã çãæ·±ããªã£ã¦ãã ããã ã»ãã¥ãªãã£ãç ´ããããã¨ãé¿ãããã¨ã¯çæ³ã§ããã ç ´ããããã¨ãææ¡ãããã¨ã¯å¿
é ã§ãã
-ããã»ã¹ã¢ã«ã¦ã³ãã£ã³ã° (man:accton[8] åç
§) ã¯ã ãã·ã³ã¸ã®ä¾µå
¥ãæ¤åºããããã®ã¡ã«ããºã ã¨ãã¦æ¨å¥¨ã§ããã æ¯è¼çãªã¼ããããã®å°ãªã FreeBSD ã®æ©è½ã§ãã ä¾µå
¥ãåããå¾ã§ãå½è©²ãã¡ã¤ã«ãç¡å·ã§ããå ´åã«ã ä¾µå
¥è
ãã©ã®ããã«ãã¦ã·ã¹ãã ã«ä¾µå
¥ãããã追跡ããã®ã«ç¹ã«å½¹ç«ã¡ã¾ãã
+[[security-ids]]
+=== ãã¤ããªæ¤è¨¼
-æå¾ã«ã ã»ãã¥ãªãã£ã¹ã¯ãªããã¯ãã°ãã¡ã¤ã«ãå¦çããããã«ãã ãã°ãã¡ã¤ã«èªä½ãã§ããã ãå®å
¨æ§ã®é«ãæ¹æ³ã§çæããããã«ãã ãªã¢ã¼ãã® syslog ãµã¼ãã«éä¿¡ããããã«ãã¹ãã§ãã ä¾µå
¥è
ã¯èªåã®ä¾µå
¥ã®çè·¡ãè¦ãé ããã¨ãã¾ãããã¾ãã ãã°ãã¡ã¤ã«ã¯ã·ã¹ãã 管çè
ãæåã®ä¾µå
¥ã®æå»ã¨æ¹æ³ã追跡ãã¦ããããã«æ¥µãã¦éè¦ã§ãã ãã°ãã¡ã¤ã«ãæ°¸ä¹
ã«æ®ãã¦ããããã® 1 ã¤ã®æ¹æ³ã¯ã ã·ã¹ãã ã³ã³ã½ã¼ã«ãã·ãªã¢ã«ãã¼ãã«ã¤ãªãã§èµ°ããã ã³ã³ã½ã¼ã«ãç£è¦ãã¦ããå®å
¨ãªãã·ã³ã«æ
å ±ãéãããã¨ã§ãã
+ã·ã¹ãã ãã¡ã¤ã«ããã³ãã¤ããªã®æ¤è¨¼ã¯ã ã·ã¹ãã 管çè
ããã³ã»ãã¥ãªãã£ãã¼ã ã«å¯¾ãã¦ã ã·ã¹ãã ã®å¤æ´ã«é¢ããæ
å ±ãæä¾ãã¦ãããããéè¦ã§ãã ãããªãã·ã¹ãã ã«ããã¦ããã·ã¹ãã 管çãã¼ã ã®ç¥ããªãã¨ããã§ã å
é¨ã®ã³ãã³ããã¢ããªã±ã¼ã·ã§ã³ã¯å¤æ´ãã¹ãã§ã¯ããã¾ããã ã·ã¹ãã ã®å¤æ´ããã¢ãã¿ãªã³ã°ããã½ããã¦ã§ã¢ã¢ããªã±ã¼ã·ã§ã³ã¯ã ä¾µå
¥æ¤ç¥ã·ã¹ãã (Intrusion Detection System) ã¾ã㯠IDS ã¨å¼ã°ãã¾ãã
-=== åå·ççæ¹æ³
+FreeBSD ã¯ãåºæ¬ç㪠IDS ã·ã¹ãã ããã¤ãã£ãã§æä¾ãã¦ãã¾ãã å®éã«ãæ¯æ©ã® man:periodic[8] ã»ãã¥ãªãã£ã«é¢ããã¡ã¼ã«ã®ä¸ã§ã¯ã 管çè
ã«å¤æ´ç¹ãéç¥ãã¾ãã æ
å ±ã¯ãã¼ã«ã«ã«ä¿åããã¦ããã®ã§ã æªæã®ããã¦ã¼ã¶ã夿´ããæ
å ±ã "欺ã" å¯è½æ§ãããã¾ãã ãã®ããããã¤ããªã®ç½²åã®å¥ã®ã»ããã使ãã¦ã èªã¿åãå°ç¨ã® root ææã®ãã£ã¬ã¯ããªãã§ããã°ã USB ãã£ã¹ã¯ã¾ã㯠rsync ãµã¼ãã¨ãã£ãã·ã¹ãã ã¨ã¯å¥ã®ã·ã¹ãã ã«ä¿åãã¦ãã ããã
-å¤å°åå·ççã«ãªã£ã¦ã決ãã¦æªããã¨ã«ã¯ãªãã¾ããã ååçã«ãã·ã¹ãã 管çè
ã¯ã 便å©ãã«å½±é¿ãä¸ããªãç¯å²ã§ããã¤ã§ãã»ãã¥ãªãã£æ©è½ã追å ãããã¨ãã§ãã¾ãã ã¾ããããããèæ
®ããçµæã 便å©ãã«__å½±é¿ãä¸ãã__ã»ãã¥ãªãã£æ©è½ã追å ãããã¨ãã§ãã¾ãã ããéè¦ãªãã¨ã¯ã ã»ãã¥ãªãã£ç®¡çè
ã¯ãããå¤å°æ··ãããã«ãã¦ä½¿ãã¹ãã ã¨ãããã¨ã§ãã ãããã®ç« ã§æ¸ããã¦ããæ¨å¥¨ãããæ¹æ³ããã®ã¾ã¾ä½¿ç¨ããå ´åã¯ã äºæ³ãããæ»æè
ã¯ãã¯ããã®ææ¸ãèªãã§ããããã§ãããã é²å¾¡çãæãã¦ãã¾ããã¨ã«ãªãã¾ãã
+ã¾ãæåã«ãã·ã¼ããçæããå¿
è¦ãããã¾ãã ããã¯ãæ°å¤å®æ°ã§ãããã·ã¥å¤ã®çæãããã·ã¥å¤ã®æ¤è¨¼ã§ä½¿ããã¾ãã ãã®ã·ã¼ãããªãã¨ã ãã¡ã¤ã«ã®ãã§ãã¯ãµã ã®å¤ãå½ã£ããæ¤è¨¼ãå¯è½ã«ãªãã¾ãã 以ä¸ã®ä¾ã§ã¯ãã·ã¼ã㯠`-s` ãã©ã°ã§æå®ããã¦ãã¾ãã æåã«ä»¥ä¸ã®ã³ãã³ããç¨ã㦠[.filename]#/bin# ã®ããã·ã¥å¤ããã³ãã§ãã¯ãµã ãçæãã¦ãã ããã
-=== ãµã¼ãã¹å¦¨å®³æ»æ
+[source,bash]
+....
+# mtree -s 3483151339707503 -c -K cksum,sha256digest -p /bin > bin_chksum_mtree
+....
-DoS æ»æã¯ãæ®éã¯ããã±ããæ»æã§ãã ãããã¯ã¼ã¯ã飽åãããæå
端ã®å½é ãã±ãã (spoofed packet) æ»æã«å¯¾ãã¦ã·ã¹ãã 管çè
ãæã¦ãæã¯ããã»ã©å¤ãããã¾ãããã ä¸è¬çã«ã以ä¸ã®ãããªæ¹æ³ã«ããã ãã®ç¨®ã®æ»æã«ãã£ã¦ãµã¼ãããã¦ã³ããªããã¨ã確å®ã«ãããã¨ã§ã 被害ãããé度ã«é£ãæ¢ãããã¨ã¯ã§ãã¾ãã
+ãã®ã³ãã³ãã®åºåã¯ä»¥ä¸ã®ããã«ãªãã¾ãã
-. ãµã¼ãã® fork ã®å¶éã
-. ICMP å¿çæ»æãping broadcast ãªã©ã®è¸ã¿å°æ»æã®å¶éã
-. ã«ã¼ãã«ã®çµè·¯æ
å ±ã®ãã£ãã·ã¥ãéå°ã«ç¨æããã
+[source,bash]
+....
+# mtree: /bin checksum: 3427012225
+....
-ãããã DoS æ»æã¯ãfork ãããµã¼ãã«å¯¾ãã¦æ»æãããã®ã§ã å¤ãã®åããã»ã¹ãèµ·åããããã¨ã«ããã ã¡ã¢ãªããã¡ã¤ã«è¨è¿°åãªã©ã使ãã¤ããã ãã¹ãã·ã¹ãã ãæçµçã«åæ¢ããã¾ãã man:inetd[8] ã«ã¯ã ãã®ç¨®ã®æ»æãå¶éãããªãã·ã§ã³ãããã¤ãããã¾ãã ãã·ã³ããã¦ã³ãããã¨ã鲿¢ãããã¨ã¯å¯è½ã§ããã ãã®ç¨®ã®æ»æã«ãããµã¼ãã¹ã䏿ãããã¨ã鲿¢ãããã¨ã¯ä¸è¬çã«è¨ã£ã¦ã§ããªããã¨ã«æ³¨æããå¿
è¦ãããã¾ãã man:inetd[8] ãæ³¨ææ·±ãèªãã§ä¸ãããç¹ã«ã `-c`, `-C`, `-R` ã«æ³¨æãã¦ä¸ãããIP å½é æ»æ (spoofed-IP attack) 㯠man:inetd[8] ã® `-C` ã®è£ããããã®ã§ã ä¸è¬ã«ãªãã·ã§ã³ãçµã¿åããã¦ä½¿ç¨ãã¹ãã§ãã ã¹ã¿ã³ãã¢ãã³ãµã¼ãã®ä¸ã«ã¯ãèªåèªèº«ã§ fork ãå¶éãããã©ã¡ã¼ã¿ãæã£ã¦ãããã®ããã
ã¾ãã
+[.filename]#bin_cksum_mtree# ãã¡ã¤ã«ãè¦ãã¨ã 以ä¸ã®ãããªåºåã¨ãªãã¾ãã
-Sendmail ã«ã¯ã `-OMaxDaemonChildren` ãããã¾ãã ã·ã¹ãã è² è·ã®å¤å¤åã«ã¯é
ããããã®ã§ã Sendmail ã®è² è·éçæå®ãªãã·ã§ã³ã使ããããã ãã®ãªãã·ã§ã³ãä½¿ãæ¹ãã¾ã¨ãã«åä½ããå¯è½æ§ã¯ã¯ããã«é«ãã§ãã Sendmail ãéå§ããéã¯ã é常è¦è¾¼ã¾ããè² è·ãæ±ããç¨åº¦ã«ååé«ããã ã³ã³ãã¥ã¼ã¿ãæä½ã§ããªãæ°ã® Sendmail ã¤ã³ã¹ã¿ã³ã¹ã®å¤ããã¯ä½ãå¤ã« `MaxDaemonChildren` ãè¨å®ãã¦ãã ããã Sendmail ã `-ODeliveryMode=queued` ã使ã£ã¦ã ãã¥ã¼å¦çã¢ã¼ãã§å®è¡ãããã ãã¼ã¢ã³ (`sendmail -bd`) ããã¥ã¼å¦çç¨ããã»ã¹ (`sendmail -q15m`) ã¨å¥ã«å®è¡ãããã¨ããç¨å¿æ·±ããã¨ã¨è¨ãã¾ãã ãªã¢ã«ã¿ã¤ã ã§ã®é
éãæãã®ã§ããã°ã `-q1m` ã®ããã«ãããã¨ã§ã ãã¥ã¼å¦çãã¯ããã«çãæéééã§è¡ããã¨ãã§ãã¾ãã ãããã«ãã¦ãã`M
axDaemonChildren` ã«åççãªå¤ã確å®ã«æå®ãã¦ã ãªã ãããã£ã¦å¤±æãããã¨ããªãããã«ãã¦ä¸ããã
+[.programlisting]
+....
+# user: root
+# machine: dreadnaught
+# tree: /bin
+# date: Mon Feb 3 10:19:53 2014
+# .
+/set type=file uid=0 gid=0 mode=0555 nlink=1 flags=none
+. type=dir mode=0755 nlink=2 size=1024 \
+ time=1380277977.000000000
+ \133 nlink=2 size=11704 time=1380277977.000000000 \
+ cksum=484492447 \
+ sha256digest=6207490fbdb5ed1904441fbfa941279055c3e24d3a4049aeb45094596400662a
+ cat size=12096 time=1380277975.000000000 cksum=3909216944 \
+ sha256digest=65ea347b9418760b247ab10244f47a7ca2a569c9836d77f074e7a306900c1e69
+ chflags size=8168 time=1380277975.000000000 cksum=3949425175 \
+ sha256digest=c99eb6fc1c92cac335c08be004a0a5b4c24a0c0ef3712017b12c89a978b2dac3
+ chio size=18520 time=1380277975.000000000 cksum=2208263309 \
+ sha256digest=ddf7c8cb92a58750a675328345560d8cc7fe14fb3ccd3690c34954cbe69fc964
+ chmod size=8640 time=1380277975.000000000 cksum=2214429708 \
+ sha256digest=a435972263bf814ad8df082c0752aa2a7bdd8b74ff01431ccbd52ed1e490bbe7
+....
+
+ã³ã³ãã¥ã¼ã¿ã®ãã¹ãåãç¾å¨ã®æ¥ä»ã¨æéãman:mtree[8] ãå®è¡ããã¦ã¼ã¶ã®æ
å ±ãã¹ã¦ããã®ã¬ãã¼ãã«ã¯å«ã¾ãã¦ãã¾ãã ã¾ããåãã¤ããªã«å¯¾ãããã§ãã¯ãµã ããµã¤ãºãã¿ã¤ã ã¹ã¿ã³ãããã³ SHA256 ãã¤ã¸ã§ã¹ããå«ã¾ãã¦ãã¾ãã
+
+ãã¤ããªç½²åã®æ¤è¨¼ã®ããã«ã 以ä¸ã®ã³ãã³ããå®è¡ããã¨ãç¾å¨ã®ç½²åã®ãªã¹ããèªã¿è¾¼ã¿ã çµæãåºåãã¾ãã
-man:syslogd[8] ã¯ç´æ¥æ»æãããå¯è½æ§ãããã®ã§ãå¯è½ãªãã°ãã¤ã§ã `-s` ãç¨ãããã¨ãå¼·ãæ¨å¥¨ãã¾ãã ãããã§ããªããªãã `-a` ã使ã£ã¦ä¸ããã
+[source,bash]
+....
+# mtree -s 3483151339707503 -p /bin < bin_chksum_mtree >> bin_chksum_output
+....
-é identd ãªã©ã®æ¥ç¶è¿ã (connect-back) ãè¡ããµã¼ãã¹ã«ã¤ãã¦ã¯ç´æ¥æ»æãåããå¯è½æ§ãããã®ã§ã ååæ³¨æãæãããã«ããã¹ãã§ãã ããããäºæ
ãããã®ã§ãTCP wrapper ã®é ident æ©è½ã使ããã¨ã¯æ¨å¥¨ããã¾ããã
+ãã®ã³ãã³ããå®è¡ããã¨ããã§ã«ãã§ãã¯ãµã ãçæãã¦ãã [.filename]#/bin# ã«å¯¾ãã¦ãåæ§ã®ãã§ãã¯ãµã ãçæãã¾ãã ãã®ã³ãã³ããå®è¡ãã¦ãã夿´ãè¡ããã¦ããªãã®ã§ã [.filename]#bin_chksum_output# ã¸ã®ä¸»åã¯ç©ºã¨ãªãã¾ãã 夿´ãè¡ãããå ´åãã·ãã¥ã¬ã¼ãããããã«ã [.filename]#/bin/cat# ãã¡ã¤ã«ã®æ¥ä»ã man:touch[1] ã使ã£ã¦å¤æ´ãã¦ã å度æ¤è¨¼ã®ã³ãã³ããå®è¡ãã¦ã¿ã¾ãã
-å¢çã«ã¼ã¿ã®ã¨ããã§ãã¡ã¤ã¢ã¦ã©ã¼ã«ãè¨ãã¦ã å¤é¨ããã®ã¢ã¯ã»ã¹ã«å¯¾ãã¦å
é¨ãµã¼ãã¹ãé²å¾¡ãããã¨ã¯æ¨å¥¨ããã¾ãã ããã¯ãLAN ã®å¤é¨ããã®é£½åæ»æãé²ããã¨ã«ããã å
é¨ãµã¼ãã¹ããããã¯ã¼ã¯ãã¼ã¹ã® `root` 権éã¸ã®æ»æããé²å¾¡ãããã¨ã«ã¯ãã¾ãèæ
®ãæã£ã¦ãã¾ããã ãã¡ã¤ã¢ã¦ã©ã¼ã«ã¯ãããã©ã«ãã§ã¯ãã¹ã¦ã®éä¿¡ãç¦æ¢ãã 許å¯ããéä¿¡ã®ã¿ãæç¤ºãã¦è¨å®ããããã«ãå¸¸ã«æä»çã«è¨å®ãã¦ä¸ããã FreeBSD ã§ã¯ã`net.inet.ip.portrange` man:sysctl[8] 夿°ã«ããã åçãã¤ã³ãã«ä½¿ç¨ããããã¼ãçªå·ã®ç¯å²ãå¶å¾¡ã§ãã¾ãã
+[source,bash]
+....
+# touch /bin/cat
+....
-ã¾ãå¥ã®ãããã DoS æ»æã¨ãã¦ã è¸ã¿å°æ»æã¨å¼ã°ãããã®ãããã¾ããããã¯ã ãããµã¼ããæ»æãããã®çµæã¨ãã¦çæãããå¿çããµã¼ãèªèº«ã ãã¼ã«ã«ãããã¯ã¼ã¯ã ãããã¯ä»ã®ãã·ã³ãéè² è·ã«è¿½ãè¾¼ãããã«ããæ»æã§ãã ãã®ç¨®ã®æ»æã®ä¸ã§æããããµãããã®ã«ã __ICMP ping broadcast æ»æ__ãããã¾ãã æ»æè
ã¯ãæ»æãããã·ã³ã®ã¢ãã¬ã¹ãéä¿¡å
ã¢ãã¬ã¹ã«è¨å®ãã ping ãã±ãããå½é ãã¦ã対象㮠LAN ã®ããã¼ããã£ã¹ãã¢ãã¬ã¹ã«åãã¦ãã±ãããéä¿¡ãã¾ãã å¢çã«ããã«ã¼ã¿ãããã¼ããã£ã¹ãã¢ãã¬ã¹ã«å¯¾ãã ping ãã±ãããããããããããã«è¨å®ããã¦ããªãå ´åãLAN ã¯ã è©ç§°ãããéä¿¡å
ã¢ãã¬ã¹ã«åãã¦ã ç ç²ã¨ãªããã·ã³ã飽åããã¾ã§å¿çãã±ãããçæãã¾ãã ç°ãªããããã¯ã¼ã¯ä¸
ã®ããã¤ãã®ããã¼ããã£ã¹ãã¢ãã¬ã¹ã«å¯¾ãã¦åæã«æ»æããå ´åã«ã¯ã ã¨ãã«ã²ã©ããã¨ã«ãªãã¾ãã 2 çªç®ã®è¸ã¿å°æ»æã¯ã ãµã¼ãã®åä¿¡ãããã¯ã¼ã¯ã飽åããããã㪠ICMP ã¨ã©ã¼å¿çãçæãããã±ãããçæãã ãã®çµæã¨ãã¦ãµã¼ããéä¿¡ãããã¯ã¼ã¯ã ICMP å¿çã§é£½åããã¦ãã¾ãæ»æã§ãã ã¡ã¢ãªãæ¶è²»ãå°½ãããããã¨ã«ããã ãã®ç¨®ã®æ»æã§ãµã¼ããã¯ã©ãã·ã¥ããããã¨ãå¯è½ã§ãã ãµã¼ããçæãã ICMP å¿çãååéãéä¿¡ã§ããªãå ´åã ã¨ãã«ã²ã©ããã¨ã«ãªãã¾ãã ãã®ç¨®ã®æ»æã®å¹æãæå¶ããã«ã¯ã man:sysctl[8] 夿°ã® `net.inet.icmp.icmplim` ã使ã£ã¦ãã ããã è¸ã¿å°æ»æã® 3 ã¤ãã®ä¸»è¦ãªã¯ã©ã¹ã«å±ããæ»æã¯ã UDP echo ãµã¼ãã¹ã®ãããªãç¹å®ã® man:inetd[8] å
é¨ãµã¼ãã¹ã«é¢é£ãããã®ã§ãã æ»æè
ã¯ãéä¿¡å
ã¢ãã¬ã¹ããµã¼ã A ã!
® echo ãã¼ãã§ãããéä¿¡å
ã¢ãã¬ã¹ããµã¼ã B ã® echo ãã¼ãã§ããããã« UDP ãã±ãããå½é ãã¾ãã ããã§ãµã¼ã A, B ã¯ã¨ãã«åã LAN ã«æ¥ç¶ããã¦ãã¾ãããã® 2 ã¤ã®ãµã¼ãã¯ã ãã®ä¸ã¤ã®ãã±ããã両è
ã®éã§äºãã«ç¸æã«å¯¾ãã¦æã¡è¿ãããã¾ãã æ»æè
ã¯ããã®ãããªãã±ãããã»ãã®ããã¤ã注å
¥ããã ãã§ã 両æ¹ã®ãµã¼ã㨠LAN ãéè² è·ç¶æ
ã«ãããã¨ãã§ãã¾ãã åæ§ã®åé¡ã chargen ãã¼ãã«ãåå¨ãã¾ãã ãã®æã® inetd å
é¨ãã¹ããµã¼ãã¹ã¯ç¡å¹ã«ãã¦ãã ããã
+[source,bash]
+....
+# mtree -s 3483151339707503 -p /bin < bin_chksum_mtree >> bin_chksum_output
+....
-å½é ãã±ããæ»æã¯ã ã«ã¼ãã«ã®çµè·¯æ
å ±ãã£ãã·ã¥ã«éè² è·ãçããããããã«ç¨ãããããã¨ãããã¾ãã `net.inet.ip.rtexpire`, `rtminexpire`, `rtmaxcache` ã® man:sysctl[8] ãã©ã¡ã¼ã¿ãåç
§ãã¦ä¸ããã ã§ããããªéä¿¡å
IP ã¢ãã¬ã¹ãç¨ããå½é ãã±ããæ»æã«ããã ã«ã¼ãã«ã¯ã䏿çãªãã£ãã·ã¥çµè·¯ãçµè·¯æ
å ±ãã¼ãã«ã«çæãã¾ãã ãã㯠`netstat -rna | fgrep W3` ã§è¦ããã¨ãã§ãã¾ãã ãããã®çµè·¯ã¯ãæ®é㯠1600 ç§ç¨åº¦ã§ã¿ã¤ã ã¢ã¦ãã«ãªãã¾ãã ã«ã¼ãã«ããã£ãã·ã¥çµè·¯ãã¼ãã«ã大ãããªãéãããã¨ãæ¤ç¥ããã¨ã ã«ã¼ãã«ã¯åçã« `rtexpire` ãæ¸ããã¾ããã`rtminexpire` ããå°ãããªãããã«ã¯æ±ºãã¦æ¸ããã¾ããã ããã«ãã 2 ã¤ã®åé¡ãå¼ãèµ·ãããã¾ãã
+[source,bash]
+....
+# cat bin_chksum_output
+....
-. è² è·ã®è»½ããµã¼ããçªç¶æ»æãããå ´åã ã«ã¼ãã«ãååç´ æ©ãåå¿ã§ããªããã¨ã
-. ã«ã¼ãã«ãæç¶çæ»æã«èããããã»ã©åå `rtminexpire` ãä½ãè¨å®ããã¦ããªããã¨ã
+[.programlisting]
+....
+cat changed
+ modification time expected Fri Sep 27 06:32:55 2013 found Mon Feb 3 10:28:43 2014
+....
-ãµã¼ãã T3 ãããã¯ããããé«éã®åç·ã§ã¤ã³ã¿ã¼ãããã«æ¥ç¶ããã¦ããå ´åã man:sysctl[8] ãç¨ã㦠`rtexpire` 㨠`rtminexpire` ãæåã§ä¸æ¸ããã¦ãããã¨ãææ
®æ·±ããã¨ã¨ããã¾ãã ãã ããã©ã¡ãã䏿¹ã§ã 0 ã«ã¯æ±ºãã¦ããªãã§ä¸ããã ã³ã³ãã¥ã¼ã¿ãã¯ã©ãã·ã¥ããã¦ãã¾ããã¨ã«ãªãã¾ãã 両ãã©ã¡ã¼ã¿ã 2 ç§ã«è¨å®ããã°ã æ»æããçµè·¯æ
å ±ãã¼ãã«ãå®ãã«ã¯ååã§ãããã
+package:security/aide[] ã®ãããªã ããé«åº¦ãª IDS ã·ã¹ãã ãããã¾ããã ã»ã¨ãã©ã®ã±ã¼ã¹ã«ããã¦ã man:mtree[8] ã¯ç®¡çè
ãå¿
è¦ã¨ããæ©è½ãæä¾ãã¾ãã æªæã®ããã¦ã¼ã¶ãã ã·ã¼ãå¤ããã³ãã§ãã¯ãµã ã®åºåãè¦ããªãããã«ãããã¨ãéè¦ã§ãã
-=== Kerberos ããã³ man:ssh[1] ãç¨ããã¢ã¯ã»ã¹ã®åé¡
+[[security-tuning]]
+=== ã»ãã¥ãªãã£ã®ããã®ã·ã¹ãã ã®èª¿æ´
-ãããKerberos 㨠man:ssh[1] ã使ãããã®ã ã¨ãããã 両è
ã«é¢ãã¦è¨ã£ã¦ãããã°ãªããªãåé¡ãããã¤ãããã¾ãã Kerberos ã¯å¤§å¤åªããèªè¨¼ãããã³ã«ã§ãããKerberos åããã man:telnet[1] ããã³ man:rlogin[1] ã«ã¯ã ãã¤ããªã¹ããªã¼ã ãæ±ãã®ã«ä¸åãã«ãªã£ã¦ãã¾ããããªãã°ãããã¾ãã ããã©ã«ãã§ã¯ãKerberos 㯠`-x` ã使ããªãéãã»ãã·ã§ã³ãæå·åãã¦ããã¾ããã 䏿¹ man:ssh[1] ã§ã¯ã ããã©ã«ãã§ãã¹ã¦ãæå·åãã¦ããã¾ãã
+ã·ã¹ãã ã®æ©è½ã®å¤ãã¯ãman:sysctl[8] ã使ã£ã¦èª¿æ´ã§ãã¾ãã Denial of Service (DOS) ã¹ã¿ã¤ã«ã®æ»æãé¿ããããã®ã»ãã¥ãªãã£æ©è½ã«å¯¾ãã¦ãåæ§ã§ãã ãã®ç¯ã§ã¯ãããéè¦ãªèª¿æ´ã«ã¤ãã¦ã触ãã¦ãã¾ãã man:sysctl[8] ã«ãããè¨å®ã夿´ãããæã¯ãã¤ã§ãã æã¾ãªãå±å®³ãèµ·ããå¯è½æ§ã¯é«ã¾ãã ã·ã¹ãã ã®å¯ç¨æ§ã«å½±é¿ãã¾ãã ã·ã¹ãã å
¨ä½ã®è¨å®ã夿´ããæã«ã¯ã ã·ã¹ãã ã® CIA ãèããå¿
è¦ãããã¾ãã
-man:ssh[1] ã¯ã¨ã¦ãè¯ãåãã¦ããã¾ããã ããã©ã«ãã§æå·éµã転éãã¦ãã¾ãã¾ãã ããã¯ãå®å
¨ãªã¯ã¼ã¯ã¹ãã¼ã·ã§ã³ããã å®å
¨ã§ãªããã·ã³ã¸ã®ã¢ã¯ã»ã¹ã« man:ssh[1] ã使ã£ã¦ããã¦ã¼ã¶ã«ã»ãã¥ãªãã£ãªã¹ã¯ãå¼ãèµ·ããã¾ãã éµãã®ãã®ãè¦ãã¦ãã¾ãããã§ã¯ããã¾ãããã man:ssh[1] 㯠login ãã¦ããéã転éç¨ãã¼ããä½ãã¾ãã æ»æè
ãå®å
¨ã§ãªããã·ã³ã® `root` ãç ´ã£ããã ãã®ãã¼ãã使ã£ã¦ã ãã®æå·éµã§ããã¯ãå¤ããä»ã®ãã·ã³ã¸ã®ã¢ã¯ã»ã¹ãå¾ã¦ãã¾ãã¾ãã
+以ä¸ã§ã¯ãman:sysctl[8] ã®ä¸è¦§ã ããã³å¤æ´ãã·ã¹ãã ã«ã©ã®ããã«å½±é¿ãããã説æãã¾ãã
-å¯è½ãªæã¯ãã¤ã§ããã¹ã¿ããã®ãã°ã¤ã³ã«ã¯ Kerberos ãçµã¿åãã man:ssh[1] ã使ç¨ãããã¨ãå§ãã¾ãã man:ssh[1] ã¯ãKerberos å¯¾å¿æ©è½ã¨ä¸ç·ã«ã³ã³ãã¤ã«ã§ãã¾ãã ããããã¨ãè¦ãã¦ãã¾ããããããªã SSH éµããã¾ããã¦ã«ããªãã§è¯ãããã«ãªãã 䏿¹ã§ãKerberos çµç±ã§ãã¹ã¯ã¼ããä¿è·ããã¾ãã éµã¯ãå®å
¨ãªãã·ã³ããã®èªååãããã¿ã¹ã¯ã®ã¿ã«ä½¿ç¨ããã¹ãã§ãã Kerberos ã¯ãã®ç¨éã«ã¯ä¸åãã§ãã ã¾ããSSH ã®è¨å®ã§éµè»¢éãããªãããã«ãããã ããã㯠[.filename]#authorized_keys# ã® `from=IP/DOMAIN` ã使ç¨ãã¦ã ç¹å®ã®ãã·ã³ãããã°ã¤ã³ãã¦ããã¨ãã®ã¿éµãæå¹ã§ããããã«ãããã¨ãå§ãã¾ãã
+ããã©ã«ãã§ã¯ãFreeBSD ã®ã«ã¼ãã«ã¯ã»ãã¥ãªãã£ã¬ãã« -1 ã§èµ·åãã¾ãã ãã®ã»ãã¥ãªãã£ã¬ãã«ã¯ã 夿´ä¸å¯ã®ãã¡ã¤ã«ãã©ã°ãå¤ãããã ãã¹ã¦ã®ããã¤ã¹ã«å¯¾ãã¦èªã¿è¾¼ã¿ããã³æ¸ãè¾¼ã¿ãã§ãããããã®ã§ã "insecure mode" ã¨å¼ã°ãã¾ãã ãã®ã»ãã¥ã¢ã¬ãã«ã¯ã管çè
ã¾ã㯠man:init[8] ã«ããèµ·åæã®ã¹ã¯ãªããã«ãã夿´ãããªãéã -1 ã®ã¾ã¾ã§ãã [.filename]#/etc/rc.conf# ã«ããã¦ã `kern_securelevel_enable` ã `YES` ã¨ãã `kern_securelevel` ã«å¿
è¦ã¨ããå¤ãè¨å®ãããã¨ã§ã ã·ã¹ãã èµ·åæã«ã»ãã¥ã¢ã¬ãã«ãé«ãããã¨ãã§ãã¾ãã ãããã®è¨å®ã«ã¤ãã¦ã®ããè©³ç´°ãªæ
å ±ã«ã¤ãã¦ã¯ã man:security[7] ããã³ man:init[8] ãã覧ãã ããã
-[[crypt]]
-== DES, Blowfish, MD5, SHA256, SHA512 ããã³ Crypt
+[WARNING]
+====
+`securelevel` ã大ããããããã¨ã Xorg ãåããªããªã£ãããä»ã®åé¡ãèµ·ããå¯è½æ§ãããã¾ãã ãããã°ã®å¿ã¥ããããã¦ãã ããã
+====
-UNIX(R) ã·ã¹ãã ã«ããããã¹ã¦ã®ã¦ã¼ã¶ã¯ã ãã®ã¢ã«ã¦ã³ãã«å¯¾å¿ããä¸ã¤ã®ãã¹ã¯ã¼ããæã£ã¦ãã¾ãã ãããã®ãã¹ã¯ã¼ããç§å¯ã«ä¿ã£ã¦ããããã«ã ãã¹ã¯ã¼ã㯠"䏿¹åããã·ã¥" ã¨ãã¦ç¥ãããæ¹å¼ã§æå·åããã¾ãã 䏿¹åããã·ã¥ã¨ã¯ã ç°¡åã«æå·åã¯ã§ãããè§£èªã¯é£ããã¨ããæ¹æ³ã§ãã ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã èªèº«ã¯ãã¹ã¯ã¼ããç¥ãã¾ããã ãã®ä»£ããã« _æå·åããã_ å½¢ã§ã®ã¿ãã¹ã¯ã¼ããç¥ã£ã¦ãã¾ãã "ç´ ã®ããã¹ã" ã¨ãã¦ãã¹ã¯ã¼ããå¾ãå¯ä¸ã®æ¹æ³ã¯ã å¯è½ãªéãã®ãã¹ã¯ã¼ã空éãæ¤ç´¢ããã¨ããåä»»ãã®æ¹æ³ã§ãã
+ã¤ãã«å¤æ´ãæ¤è¨ãã¹ã man:sysctl[8] ã¯ã net.inet.tcp.blackhole ããã³ net.inet.udp.blackhole ã§ãã ããããè¨å®ããã¨ãéãããã¼ãã«å¯¾ãã¦å±ã SYN ãã±ããã¯ããããããã RST ã¬ã¹ãã³ã¹ãè¿ãã¾ããã é常ã¯ãRST ãè¿ãã ãã®ãã¼ããéãããã¦ãããã¨ãä¼ãã¾ãã ããã«ãããã·ã¹ãã ã«å¯¾ãã "ã¹ãã«ã¹" ã¹ãã£ã³ã«å¯¾ããããç¨åº¦ã®é²å¾¡ã¨ãªãã¾ãã net.inet.tcp.blackhole ã "2"ã net.inet.udp.blackhole ã "1" ã«è¨å®ãã¦ãã ããã è©³ç´°ãªæ
å ±ã«ã¤ã㦠man:blackhole[4] ãã覧ãã ããã
-å
ã
ãUNIX(R) ã«ããã¦ãã¹ã¯ã¼ããå®å
¨ãªå½¢ã§æå·åã§ããæ¹å¼ã¯ Data Encryption Standard (DES) ã«åºã¥ãããã®ã ãã§ãããDES ã®ã½ã¼ã¹ã³ã¼ããç±³å½å¤ã«è¼¸åºãããã¨ã¯ã§ããªãã¨ããåé¡ããã£ãããã FreeBSD ã¯ãç±³å½ã®æ³å¾ãå®ããã¨ã¨ã æªã ã« DES ã使ã£ã¦ããä»ã® UNIX(R) 䏿ã¨ã®äºææ§ãä¿ã¤ãã¨ã¨ã両ç«ããæ¹æ³ãæ¢ãåºãå¿
è¦ãããã¾ããã ãã®è§£æ±ºæ¹æ³ã¯ãDES ãããå®å
¨ã§ããã¨èãããã¦ãã MD5 ã使ããã¨ã§ããã
+ããã«ãnet.inet.icmp.drop_redirect ããã³ net.inet.ip.redirect ãè¨å®ãã¹ãã§ãã ããã 2 ã¤ã® man:sysctl[8] ã¯ããªãã¤ã¬ã¯ãæ»æãé²ãå©ãã¨ãªãã§ãããã ãªãã¤ã¬ã¯ãæ»æã¯ã æ
æã«é常ã®ãããã¯ã¼ã¯ã§ã¯å¿
è¦ã¨ããªããããªå¤§éã® ICMP ã¿ã¤ã 5 ã®ãã±ãããçºçãã¾ãã ãã®ãã net.inet.icmp.drop_redirect ã "1"ã net.inet.ip.redirect ã "0" ã«è¨å®ãã¦ä¸ããã
-=== æå·åæ©æ§ãçè§£ãã
+ã½ã¼ã¹ã«ã¼ãã£ã³ã°ã¯ã å
é¨ãããã¯ã¼ã¯ä¸ã§ã«ã¼ãã£ã³ã°ã§ããªãã¢ãã¬ã¹ãæ¤åºãããã¢ã¯ã»ã¹ããããã®æ¹æ³ã§ãã é常ã«ã¼ãã£ã³ã°ã§ããªãã¢ãã¬ã¹ã¯ã æå³ãã¦ã«ã¼ãã£ã³ã°ã§ããªãããã«ãã¦ããã®ã§ã ãã®è¨å®ã¯ããããç¡å¹ã«ãã¹ãã§ãã ãã®æ©è½ãç¡å¹ã«ããã«ã¯ã net.inet.ip.sourceroute ããã³ net.inet.ip.accept_sourceroute ã "0" ã«è¨å®ãã¦ãã ããã
-ç¾å¨ã§ã¯ãã©ã¤ãã©ãªã¯ DES, MD5, Blowfish, SHA256 ããã³ SHA512 ããã·ã¥é¢æ°ã«å¯¾å¿ãã¦ãã¾ããFreeBSD ãã©ã®æå·åæ¹å¼ã使ãããã«ã»ããã¢ããããã¦ãããã夿ããã«ã¯ã [.filename]#/etc/master.passwd# ã®æå·åããããã¹ã¯ã¼ãã調ã¹ã¦ãã ããã MD5 ããã·ã¥ã§æå·åããããã¹ã¯ã¼ãã¯ãDES ããã·ã¥ã§æå·åããããã¹ã¯ã¼ããããé·ãã `$1$` ã¨ããæåã§å§ã¾ãã¨ããç¹å¾´ãæã£ã¦ãã¾ãã `$2a$` ã§å§ã¾ããã¹ã¯ã¼ãã¯ãBlowfish ããã·ã¥é¢æ°ã§æå·åããã¦ãã¾ãã DES ã®ãã¹ã¯ã¼ãã¯ããã¨ãã£ã¦èå¥å¯è½ãªç¹å¾´ã¯æã£ã¦ãã¾ãããã MD5 ã®ãã¹ã¯ã¼ãããã¯çãããã㦠`$` ã¨ããæåãå«ã¾ãªã 64 æåã®ã¢ã«ãã¡ãããã使ã£ã¦è¡¨ç¾ããã¦ããã®ã§ã æ¯è¼ççãæååã§ãã«è¨å·ã§å§ã¾ã£ã¦ããªããã®ã¯ãããã DES ã®ãã¹ã¯ã¼ãã
§ãããã SHA256 㨠SHA512 ã®å ´åã¯ã`$6$` ããå§ã¾ãã¾ãã
+ããã¼ããã£ã¹ãã¢ãã¬ã¹ã«å¯¾ãããã¹ã¦ã® ICMP ã¨ã³ã¼ãªã¯ã¨ã¹ãã¯ããããããã¦ãã ããã ãããã¯ã¼ã¯ä¸ã®ã³ã³ãã¥ã¼ã¿ããµããããã«ãããã¹ã¦ã®ãã¹ãã«ã¡ãã»ã¼ã¸ãéãå¿
è¦ãããå ´åã«ã¯ã ã¡ãã»ã¼ã¸ã¯ããã¼ããã£ã¹ãã¢ãã¬ã¹ã«éããã¾ãã å¤é¨ã®ãã¹ãã«ã¤ãã¦ã¯ã ãã®ãããªéä¿¡ãããå¿
è¦ã¯ãªãã®ã§ã å¤é¨ããããã¼ããã£ã¹ãã¸ã®ãªã¯ã¨ã¹ãããã¹ã¦æå¦ããããã«ã net.inet.icmp.bmcastecho ã "0" ã«è¨å®ãã¦ãã ããã
-æ°è¦ãã¹ã¯ã¼ããã©ã¡ãã®ãã¹ã¯ã¼ãå½¢å¼ã«ãªããã¯ã [.filename]#/etc/login.conf# ã®ä¸ã® `passwd_format` ãã°ã¤ã³ã±ã¼ãããªãã£ã«ãã£ã¦å¶å¾¡ããã¾ãã ãã®å¤ã¨ãã¦ã¯ã `des`, `md5`, `blf`, `sha256` ã¾ã㯠`sha512` ãè¨å®ãããã¨ãã§ãã¾ãã ãã°ã¤ã³ã±ã¼ãããªãã£ã«é¢ããããè©³ç´°ãªæ
å ±ã¯ã man:login.conf[5] ãã覧ãã ããã
+ã¾ã å¤ãã® man:sysctl[8] ã man:security[7] ã§èª¬æããã¦ãã¾ãã ããã«å¤ãã®æ
å ±ã調ã¹ããã¨ãæ¨å¥¨ããã¾ãã
[[one-time-passwords]]
== ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ã
@@ -452,7 +484,6 @@ ALL : ALL \
[WARNING]
====
-
æ»æè
ãæ»æè
ã®ã°ã«ã¼ãã¯ã ãããã®ãã¼ã¢ã³ã®æ¥ç¶ã®ãªã¯ã¨ã¹ãã§ããµãããããã¨ã«ããã ãµã¼ãã«å¯¾ã㦠DoS æ»æã仿ãããã¨ãã§ãã¾ãã
====
@@ -462,7 +493,7 @@ ALL : ALL \
....
# We do not allow connections from example.com:
ALL : .example.com \
- : spawn (/bin/echo %a from %h attempted to access %d \
+ : spawn (/bin/echo %a from %h attempted to access %d >> \
/var/log/connections.log) \
: deny
....
@@ -483,7 +514,6 @@ sendmail : PARANOID : deny
[CAUTION]
====
-
ã¯ã©ã¤ã¢ã³ããããã¯ãµã¼ãã® DNS ã®è¨å®ãééã£ã¦ããå ´åã«ã `PARANOID` ã¯ã¤ã«ãã«ã¼ãã使ãã¨ã ãµã¼ããã¨ã¦ã使ãã¥ãããªãã¾ãã 管çè
ã®æ
éããæ±ãããã¾ãã
====
@@ -715,7 +745,7 @@ jdoe at example.org
* ãã¨ãã°ä¸é±éã¨ãã£ãé·ãæå¹æéã®ãã±ããã使ãããå ´åã§ã OpenSSH ã使ã£ã¦ã ãã±ãããä¿åããã¦ããã³ã³ãã¥ã¼ã¿ã«æ¥ç¶ãããã¨ããå ´åã¯ã Kerberos `TicketCleanup` ã [.filename]#sshd_config# ã«ãã㦠`no` ã¨è¨å®ããã¦ãããã ãã±ãããããã°ã¢ã¦ãæã«åé¤ããããã¨ã確èªãã¦ãã ããã
* ãã¹ãããªã³ã·ãã«ã¯é·ãæå¹æéã®ãã±ãããæã¤ãã¨ãã§ãã¾ãã ãããã¦ã¼ã¶ããªã³ã·ãã«ã 1 é±éã®æå¹æéãæã¡ã æ¥ç¶ãã¦ãããã¹ããã9 æéã®æå¹æéãæã£ã¦ããå ´åã«ã¯ã ã¦ã¼ã¶ãã£ãã·ã¥ã¯æå¹æéãåãããã¹ãããªã³ã·ãã«ãæã¤ãã¨ã«ãªãã æ³å®ããããã«ã ãã±ãããã£ãã·ã¥ãæ¯ãèããªããã¨ãèµ·ãããã¾ãã
-* man:kadmind[8] ã§èª¬æããã¦ãããããªã ç¹å®ã®åé¡ã®ãããã¹ã¯ã¼ãã使ããããã¨ãé¿ããããã« [.filename]#krb5.dict# ãè¨å®ããæã«ã¯ã ãã¹ã¯ã¼ãããªã·ãå²ãå½ã¦ãããããªã³ã·ãã«ã«ã®ã¿é©ç¨ããããã¨ãè¦ãã¦ãã¦ãã ããã [.filename]#krb5.dict# ã§ä½¿ããã¦ããå½¢å¼ã§ã¯ã ä¸è¡ã«ä¸ã¤ã®æååãç½®ããã¦ãã¾ãã [.filename]#/usr/shared/dict/words# ã«ã·ã³ããªãã¯ãªã³ã¯ã使ãããã¨ã¯ãæå¹ã§ãã
+* man:kadmind[8] ã§èª¬æããã¦ãããããªã ç¹å®ã®åé¡ã®ãããã¹ã¯ã¼ãã使ããããã¨ãé¿ããããã« [.filename]#krb5.dict# ãè¨å®ããæã«ã¯ã ãã¹ã¯ã¼ãããªã·ãå²ãå½ã¦ãããããªã³ã·ãã«ã«ã®ã¿é©ç¨ããããã¨ãè¦ãã¦ãã¦ãã ããã [.filename]#krb5.dict# ã§ä½¿ããã¦ããå½¢å¼ã§ã¯ã ä¸è¡ã«ä¸ã¤ã®æååãç½®ããã¦ãã¾ãã [.filename]#/usr/share/dict/words# ã«ã·ã³ããªãã¯ãªã³ã¯ã使ãããã¨ã¯ãæå¹ã§ãã
=== MIT port ã¨ã®éãã«ã¤ãã¦
@@ -725,7 +755,7 @@ MIT 㨠Heimdal çã®å¤§ããªéãã¯ã man:kadmin[8] ã«é¢é£ãã¦ãã¾
[NOTE]
====
-FreeBSD ã® MITpackage:security/krb5[] port ã«ããã¦ã man:telnetd[8] ããã³ `klogind` çµç±ã§ã®ãã°ã¤ã³ãå¥å¦ãªæ¯ãèãããããã¨ãçè§£ããã«ã¯ã port ããã¤ã³ã¹ãã¼ã«ããã [.filename]#/usr/local/shared/doc/krb5/README.FreeBSD# ãèªãã§ä¸ããã "incorrect permissions on cache file" ã®æ¯ãèããä¿®æ£ããã«ã¯ã ãã©ã¯ã¼ããããã¯ã¬ãã³ã·ã£ãªã³ã°ã®æææ¨©ãé©åã«å¤æ´ã§ããããã«ã `login.krb5` ãã¤ããªãèªè¨¼ã«ä½¿ãããå¿
è¦ãããã¾ãã
+FreeBSD ã® MITpackage:security/krb5[] port ã«ããã¦ã man:telnetd[8] ããã³ `klogind` çµç±ã§ã®ãã°ã¤ã³ãå¥å¦ãªæ¯ãèãããããã¨ãçè§£ããã«ã¯ã port ããã¤ã³ã¹ãã¼ã«ããã [.filename]#/usr/local/share/doc/krb5/README.FreeBSD# ãèªãã§ä¸ããã "incorrect permissions on cache file" ã®æ¯ãèããä¿®æ£ããã«ã¯ã ãã©ã¯ã¼ããããã¯ã¬ãã³ã·ã£ãªã³ã°ã®æææ¨©ãé©åã«å¤æ´ã§ããããã«ã `login.krb5` ãã¤ããªãèªè¨¼ã«ä½¿ãããå¿
è¦ãããã¾ãã
====
[.filename]#rc.conf# ã以ä¸ã®ããã«å¤æ´ããå¿
è¦ãããã¾ãã
@@ -765,9 +795,17 @@ kadmind5_server_enable="YES"
Kerberos ã¯ã ã¦ã¼ã¶ããã¹ãããã³ãµã¼ãã¹ã®éã§ã®èªè¨¼ãå¯è½ã«ãã¾ããã KDC ã¨ã¦ã¼ã¶ã ãã¹ãã¾ãã¯ãµã¼ãã¹ã¨ã®éã®èªè¨¼ã®ã¡ã«ããºã ã¯æä¾ãã¾ããã ããã¯ãããã¤ã®æ¨é¦¬ã® man:kinit[1] ãã ãã¹ã¦ã®ã¦ã¼ã¶åã¨ãã¹ã¯ã¼ããè¨é²ã§ãããã¨ãæå³ãã¦ãã¾ãã package:security/tripwire[] ã®ãããªããã¡ã¤ã«ã·ã¹ãã ã®å®å
¨æ§ã確èªããããã®ãã¼ã«ã«ããã ãã®å±éºæ§ã軽æ¸ãããã¨ãã§ãã¾ãã
+=== Kerberos ããã³ man:ssh[1] ãç¨ããã¢ã¯ã»ã¹ã®åé¡
+
+Kerberos 㨠man:ssh[1] ã使ãå ´åã«ã¯ã 両è
ã«é¢ãã¦ç¥ã£ã¦ãããã°ãªããªãåé¡ãããã¤ãããã¾ãã Kerberos ã¯å¤§å¤åªããèªè¨¼ãããã³ã«ã§ãããKerberos åããã man:telnet[1] ããã³ man:rlogin[1] ã«ã¯ã ãã¤ããªã¹ããªã¼ã ãæ±ãã®ã«ä¸åãã«ãªããããªãã°ãããã¾ãã ããã©ã«ãã§ã¯ãKerberos 㯠`-x` ã使ããªãéãã»ãã·ã§ã³ãæå·åãã¦ããã¾ããã 䏿¹ man:ssh[1] ã§ã¯ã ããã©ã«ãã§ãã¹ã¦ãæå·åãã¦ããã¾ãã
+
+man:ssh[1] ã¯ã¨ã¦ãè¯ãåä½ãã¾ããã ããã©ã«ãã§æå·éµã転éãã¦ãã¾ãã¾ãã ãã®ãããman:ssh[1] ãå®å
¨ãªã¯ã¼ã¯ã¹ãã¼ã·ã§ã³ããã å®å
¨ã§ãªããã·ã³ã¸ã®ã¢ã¯ã»ã¹ã«ä½¿ã£ã¦ããã¦ã¼ã¶ã«ã ã»ãã¥ãªãã£ãªã¹ã¯ãå¼ãèµ·ããã¾ãã éµãã®ãã®ãè¦ãã¦ãã¾ãããã§ã¯ããã¾ãããã man:ssh[1] 㯠login ãã¦ããéã転éç¨ãã¼ããä½ãã¾ãã æ»æè
ãå®å
¨ã§ãªããã·ã³ã® `root` ãç ´ã£ããã ãã®ãã¼ãã使ã£ã¦ã ãã®æå·éµã§ããã¯ãå¤ããä»ã®ãã·ã³ã¸ã®ã¢ã¯ã»ã¹ãå¾ã¦ãã¾ãã¾ãã
+
+å¯è½ãªæã¯ãã¤ã§ããã¹ã¿ããã®ãã°ã¤ã³ã«ã¯ Kerberos ãçµã¿åãã man:ssh[1] ã使ç¨ãããã¨ãå§ãã¾ãã man:ssh[1] ã¯ãKerberos å¯¾å¿æ©è½ã¨ä¸ç·ã«ã³ã³ãã¤ã«ã§ãã¾ãã ãã®ããã«ãããã¨ã§ãè¦ãã¦ãã¾ãå¯è½æ§ã®ãã SSH éµã¸ã®ä¾åãæ¸ããã 䏿¹ã§ãKerberos çµç±ã«ãããã¹ã¯ã¼ããä¿è·ããã¾ãã éµã¯ãå®å
¨ãªãã·ã³ããã®èªååãããã¿ã¹ã¯ã®ã¿ã«ä½¿ç¨ãã¹ãã§ãã Kerberos ã¯ãã®ç¨éã«ã¯ä¸åãã§ãã ã¾ããSSH ã®è¨å®ã§éµè»¢éãããªãããã«ãããã ããã㯠[.filename]#authorized_keys# ã® `from=IP/DOMAIN` ã使ç¨ãã¦ã ç¹å®ã®ãã·ã³ãããã°ã¤ã³ãã¦ããã¨ãã®ã¿éµãæå¹ã«ãããã¨ããå§ããã¾ãã
+
=== ãªã½ã¼ã¹ããã³ä»ã®æ
å ±æº
-* http://www.faqs.org/faqs/Kerberos-faq/general/preamble.html[ The Kerberos FAQ]
+* http://www.faqs.org/faqs/Kerberos-faq/general/preamble.html[The Kerberos FAQ]
* http://web.mit.edu/Kerberos/www/dialogue.html[Designing an Authentication System: a Dialog in Four Scenes]
* http://www.ietf.org/rfc/rfc1510.txt?number=1510[RFC 1510, The Kerberos Network Authentication Service (V5)]
* http://web.mit.edu/Kerberos/www/[MIT Kerberos home page]
@@ -929,7 +967,7 @@ IPsec ã¯ãç´æ¥äºã¤ã®ãã¹ãéã®ãã©ãã£ãã¯ãæå·åãã _
[source,bash]
....
-options IPSEC IP security
+options IPSEC #IP security
device crypto
....
@@ -937,7 +975,7 @@ IPsec ã®ãããã°ãµãã¼ããå¿
è¦ã§ããã°ã 以ä¸ã®ã«ã¼ãã«
[source,bash]
....
-options IPSEC_DEBUG debug for IP security
+options IPSEC_DEBUG #debug for IP security
....
=== å®¶åºã¨ä¼ç¤¾éã® VPN
@@ -979,15 +1017,15 @@ VPN ã®æ§æã«ã¤ãã¦ã®æ¨æºã¯ããã¾ããã VPN ã¯ãæ°å¤ãã®
Gateway 1:
gif0: flags=8051 mtu 1280
-tunnel inet 172.16.5.4 -- 192.168.1.12
+tunnel inet 172.16.5.4 --> 192.168.1.12
inet6 fe80::2e0:81ff:fe02:5881%gif0 prefixlen 64 scopeid 0x6
-inet 10.246.38.1 -- 10.0.0.5 netmask 0xffffff00
+inet 10.246.38.1 --> 10.0.0.5 netmask 0xffffff00
Gateway 2:
gif0: flags=8051 mtu 1280
-tunnel inet 192.168.1.12 -- 172.16.5.4
-inet 10.0.0.5 -- 10.246.38.1 netmask 0xffffff00
+tunnel inet 192.168.1.12 --> 172.16.5.4
+inet 10.0.0.5 --> 10.246.38.1 netmask 0xffffff00
inet6 fe80::250:bfff:fe3a:c1f%gif0 prefixlen 64 scopeid 0x4
....
@@ -1162,11 +1200,11 @@ Foreground mode.
2006-01-30 01:35:55: INFO: received Vendor ID: KAME/racoon
n2006-01-30 01:36:04: INFO: ISAKMP-SA established 172.16.5.4[500]-192.168.1.12[500] spi:623b9b3bd2492452:7deab82d54ff704a
2006-01-30 01:36:05: INFO: initiate new phase 2 negotiation: 172.16.5.4[0]192.168.1.12[0]
-2006-01-30 01:36:09: INFO: IPsec-SA established: ESP/Tunnel 192.168.1.12[0]-172.16.5.4[0] spi=28496098(0x1b2d0e2)
-2006-01-30 01:36:09: INFO: IPsec-SA established: ESP/Tunnel 172.16.5.4[0]-192.168.1.12[0] spi=47784998(0x2d92426)
+2006-01-30 01:36:09: INFO: IPsec-SA established: ESP/Tunnel 192.168.1.12[0]->172.16.5.4[0] spi=28496098(0x1b2d0e2)
+2006-01-30 01:36:09: INFO: IPsec-SA established: ESP/Tunnel 172.16.5.4[0]->192.168.1.12[0] spi=47784998(0x2d92426)
2006-01-30 01:36:13: INFO: respond new phase 2 negotiation: 172.16.5.4[0]192.168.1.12[0]
-2006-01-30 01:36:18: INFO: IPsec-SA established: ESP/Tunnel 192.168.1.12[0]-172.16.5.4[0] spi=124397467(0x76a279b)
-2006-01-30 01:36:18: INFO: IPsec-SA established: ESP/Tunnel 172.16.5.4[0]-192.168.1.12[0] spi=175852902(0xa7b4d66)
+2006-01-30 01:36:18: INFO: IPsec-SA established: ESP/Tunnel 192.168.1.12[0]->172.16.5.4[0] spi=124397467(0x76a279b)
+2006-01-30 01:36:18: INFO: IPsec-SA established: ESP/Tunnel 172.16.5.4[0]->192.168.1.12[0] spi=175852902(0xa7b4d66)
....
ãã³ããªã³ã°ãé©åã«è¡ããã¦ãããã©ããã確èªããããã å¥ã®ã³ã³ã½ã¼ã«ä¸ã§ man:tcpdump[1] ã使ãã 以ä¸ã®ãããªã³ãã³ãã§ãããã¯ã¼ã¯ã®éä¿¡ã確èªãã¦ãã ããã ãã ãã以ä¸ã®ä¾ã® `em0` ã®é¨åã¯ã å¿
è¦ã«å¿ãã¦ä½¿ç¨ãã¦ãããããã¯ã¼ã¯ã¤ã³ã¿ãã§ã¼ã¹ã«ç½®ãæãã¦ãã ããã
@@ -1180,9 +1218,9 @@ n2006-01-30 01:36:04: INFO: ISAKMP-SA established 172.16.5.4[500]-192.168.1.12[5
[.programlisting]
....
-01:47:32.021683 IP corporatenetwork.com 192.168.1.12.privatenetwork.com: ESP(spi=0x02acbf9f,seq=0xa)
-01:47:33.022442 IP corporatenetwork.com 192.168.1.12.privatenetwork.com: ESP(spi=0x02acbf9f,seq=0xb)
-01:47:34.024218 IP corporatenetwork.com 192.168.1.12.privatenetwork.com: ESP(spi=0x02acbf9f,seq=0xc)
+01:47:32.021683 IP corporatenetwork.com > 192.168.1.12.privatenetwork.com: ESP(spi=0x02acbf9f,seq=0xa)
+01:47:33.022442 IP corporatenetwork.com > 192.168.1.12.privatenetwork.com: ESP(spi=0x02acbf9f,seq=0xb)
+01:47:34.024218 IP corporatenetwork.com > 192.168.1.12.privatenetwork.com: ESP(spi=0x02acbf9f,seq=0xc)
....
ããã§ 2 ã¤ã®ãããã¯ã¼ã¯ã¯ã 1 ã¤ã®ãããã¯ã¼ã¯ã®ããã«å©ç¨ã§ãã¾ãã å¤ãã®å ´åã 両æ¹ã®ãããã¯ã¼ã¯ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«ã«ããä¿è·ããã¦ãã¾ãã 両æ¹ãæµããéä¿¡ã許å¯ããã«ã¯ã ãã±ããã両æ¹ãè¡ãæ¥ã§ããããã«ã«ã¼ã«ã追å ããå¿
è¦ãããã¾ãã man:ipfw[8] ã使ã£ããã¡ã¤ã¢ã¦ã©ã¼ã«ã®å ´åã¯ã ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®è¨å®ãã¡ã¤ã«ã«ã以ä¸ã®è¡ã追å ãã¦ãã ããã
@@ -1285,7 +1323,7 @@ COPYRIGHT 100% |*****************************| 4735
ååã®ä¾ã§ãã®ãã¹ãã®æç´ããã§ã«ä¿åããã¦ããã° ãã® man:scp[1] ã使ãæã«æ¤è¨¼ãè¡ãªããã¾ãã
-man:scp[1] ã«æ¸¡ããã弿°ã¯ãman:cp[1] ã®ãã®ã¨ä¼¼ã¦ãããã³ãã¼ãããã¡ã¤ã« (1 ã¤ã¾ãã¯è¤æ°) ã 1 ã¤ãã®å¼æ°ã«ãªããã³ãã¼å
ã 2 ã¤ãã®å¼æ°ã«ãªãã¾ãã ãã¡ã¤ã«ã¯ãããã¯ã¼ã¯è¶ãã« SSH æ¥ç¶ãéãã¦éãããã®ã§ã 弿°ã«æå®ãããã¡ã¤ã«ã« `user at host:path_to_remote_file` ã¨ããå½¢å¼ãã¨ããã®ãããã¾ãã
+man:scp[1] ã«æ¸¡ããã弿°ã¯ãman:cp[1] ã®ãã®ã¨ä¼¼ã¦ãããã³ãã¼ãããã¡ã¤ã« (1 ã¤ã¾ãã¯è¤æ°) ã 1 ã¤ãã®å¼æ°ã«ãªããã³ãã¼å
ã 2 ã¤ãã®å¼æ°ã«ãªãã¾ãã ãã¡ã¤ã«ã¯ãããã¯ã¼ã¯è¶ãã« SSH æ¥ç¶ãéãã¦éãããã®ã§ã 弿°ã«æå®ãããã¡ã¤ã«ã« `user at host:<path_to_remote_file>` ã¨ããå½¢å¼ãã¨ããã®ãããã¾ãã
=== è¨å®
@@ -1318,7 +1356,6 @@ man:ssh-keygen[1] ã¯èªè¨¼ã«ä½¿ãçºã®å
¬ééµã¨ç§å¯éµã®ãã¢ãä½
[WARNING]
====
-
å¤ãã®ã¦ã¼ã¶ã¯ãéµãè¨è¨ä¸å®å
¨ã¨ä¿¡ãã ãã¹ãã¬ã¼ãºãªãã«éµãå©ç¨ãã¦ãã¾ãã ãã®ãããªä½¿ç¨æ¹æ³ã¯ _å±éº_ ã§ãã 管çè
ãéµã«ãã¹ãã¬ã¼ãºãè¨å®ããã¦ãããã確èªããæ¹æ³ã¯ã æåã§éµã調ã¹ãæ¹æ³ã§ãã ç§å¯éµã®ãã¡ã¤ã«ã« `ENCRYPTED` ã¨ããåèªãå«ã¾ãã¦ããå ´åã«ã¯ã éµã®ææè
ã¯ããã¹ãã¬ã¼ãºã使ç¨ãã¦ãã¾ãã å¼±ããã¹ãã¬ã¼ãºã使ããã¦ããéã å°ãªãã¨ãã·ã¹ãã ãå±éºã«ããããã¦ããã¨ãã«ã¯ã ä»ã®ãµã¤ãã¸ã®ã¢ã¯ã»ã¹ã«ã¯ã ããã¬ãã«ã§ã®ãã¹ã¯ã¼ã顿¨ãå¿
è¦ã¨ãªãã¾ãã ããã«ãå
¬ééµãã¡ã¤ã«ã« `from` ãå«ãããã¨ã§ã ã¨ã³ãã¦ã¼ã¶ãããå®å
¨ã«ã§ãã¾ãã ãã¨ãã°ã `ssh-rsa` ã¾ã㯠`rsa-dsa` ã®åã«ã `from="192.168.10.5` ãå ãããã¨ã§ã ãã® IP ãæã¤ãã¹ãããã®ã¦ã¼ã¶ã®ã¿ãã¢ã¯ã»ã¹ã§ãã
ããã«ãªãã¾ãã
====
@@ -1326,7 +1363,6 @@ man:ssh-keygen[1] ã§ãã¹ãã¬ã¼ãºã使ã£ã¦ããå ´åã¯ã ç§å¯éµ
[WARNING]
====
-
OpenSSH ã®ãã¼ã¸ã§ã³ã«ãã£ã¦ã ãªãã·ã§ã³ããã¡ã¤ã«ã«éããåºã¦ãããã¨ãããã¾ãã man:ssh-keygen[1] ãåç
§ãã¦ã åé¡ãèµ·ãããã¨ãé¿ãã¦ãã ããã
====
@@ -1567,7 +1603,7 @@ Ports Collection ãã portaudit ãã¤ã³ã¹ãã¼ã«ããã«ã¯ã以ä¸ã®
[source,bash]
....
-# cd /usr/ports/ports-mgmt/portaudit make install clean
+# cd /usr/ports/ports-mgmt/portaudit && make install clean
....
ã¤ã³ã¹ãã¼ã«ã®éä¸ã§ã man:periodic[8] ã®è¨å®ãã¡ã¤ã«ã¯ã¢ãããã¼ãããã æ¯æ¥ã®ã»ãã¥ãªãã£ã«é¢ããã¹ã¯ãªããã®å®è¡ä¸ã« portaudit ãåºåããããã«è¨å®ããã¾ãã æ¯æ¥ã®ã»ãã¥ãªãã£ã«é¢ããã¹ã¯ãªããã®å®è¡çµæã®ã¡ã¼ã«ãèªãããã¨ã確èªãã¦ãã ããã ãã®ã¡ã¼ã«ã¯ã`root` ã¢ã«ã¦ã³ãã«éããã¾ãã ä»ã®è¨å®ã¯å¿
è¦ããã¾ããã
@@ -1597,7 +1633,7 @@ portaudit ã¯ãã¤ã³ã¹ãã¼ã«ããã¦ãã package ã®ä¸ã§ã èå¼±æ§
....
Affected package: cups-base-1.1.22.0_1
Type of problem: cups-base -- HPGL buffer overflow vulnerability.
-Reference: http://www.FreeBSD.org/ports/portaudit/40a3bca2-6809-11d9-a9e7-0001020eed82.html
+Reference: <http://www.FreeBSD.org/ports/portaudit/40a3bca2-6809-11d9-a9e7-0001020eed82.html>
1 problem(s) in your installed packages found.
@@ -1645,51 +1681,43 @@ CVE Name: CVE-XXXX-XXXX <.>
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit
-http://www.FreeBSD.org/security/<.>
+http://www.FreeBSD.org/security/.
I. Background <.>
+
II. Problem Description <.>
+
III. Impact <.>
+
IV. Workaround <.>
+
V. Solution <.>
+
VI. Correction details <.>
+
VII. References <.>
....
<.> `Topic` ãã£ã¼ã«ãã§ã¯ã åé¡ã«ã¤ãã¦æè¨ããã¦ãã¾ãã ã»ãã¥ãªãã£å§åã®å°å
¥é¨ã§ããã èå¼±æ§ã«å½±é¿ãããã¦ã¼ãã£ãªãã£ã示ãã¾ãã
-
<.> `Category` ãã£ã¼ã«ãã§ã¯ã èå¼±æ§ãã·ã¹ãã ã®ã©ã®é¨åã«å½±é¿ãããã示ãã¾ãã `core`, `contrib` ã¾ã㯠`ports` ã®ã©ããã示ããã¾ãã `core` ã«ãã´ãªã¯ã FreeBSD ãªãã¬ã¼ãã£ã³ã°ã·ã¹ãã ã® `core` ã³ã³ãã¼ãã³ãã«å½±é¿ããèå¼±æ§ã§ãããã¨ãæå³ãã¾ãã `contrib` ã«ãã´ãªã¯ã Sendmail ã®ããã«ãFreeBSD ã®å¤ã§éçºãããFreeBSD ããã¸ã§ã¯ãã«åãè¾¼ã¾ããã½ããã¦ã§ã¢ã«å½±é¿ããèå¼±æ§ã§ãããã¨ãæå³ãã¾ãã `ports` ã«ãã´ãªã¯ãPorts Collection ããã¤ã³ã¹ãã¼ã«ãããã½ããã¦ã§ã¢ã«å½±é¿ããèå¼±æ§ã§ãããã¨ã示ãã¦ãã¾ãã
-
<.> `Module` ãã£ã¼ã«ãã¯ã å½±é¿ããã³ã³ãã¼ãã³ãã«ã¤ãã¦è¨åãã¾ãã ãã®ä¾ã§ã¯ã`sys` ã¢ã¸ã¥ã¼ã«ã«å½±é¿ãããã¨ããããã¾ãã ãã®ããããã®èå¼±æ§ã¯ã ã«ã¼ãã«ã®ä¸ã§ä½¿ãããã³ã³ãã¼ãã³ãã«å½±é¿ãã¾ãã
-
<.> `Announced` ãã£ã¼ã«ãã¯ã ã»ãã¥ãªãã£å§åãçºè¡ãããæ¥ã ã¾ãã¯ã¢ãã¦ã³ã¹ãããæ¥ãè¨è¼ããã¦ãã¾ãã ã»ãã¥ãªãã£ãã¼ã ã«ãããã®åé¡ãåå¨ãããã¨ã確èªããã ãããã FreeBSD ã½ã¼ã¹ã³ã¼ããªãã¸ããªã«ã³ãããããããã¨ãæå³ãã¾ãã
-
<.> `Credits` ãã£ã¼ã«ãã¯ã èå¼±æ§ãéç¥ããå ±åããå人ã¾ãã¯çµç¹ã示ãã¾ãã
-
<.> `Affects` ãã£ã¼ã«ãã¯ããã®èå¼±æ§ãã©ã® FreeBSD ãªãªã¼ã¹ã«å½±é¿ãããã説æãã¾ãã ã«ã¼ãã«ã§ã¯ãå½±é¿ãããã¡ã¤ã«ã«å¯¾ã㦠man:ident[1] ãå®è¡ããã¨ã ãã®åºåãããªãã¸ã§ã³ãç°¡åã«ç¢ºèªã§ãã¾ãã ports ã®å ´åã«ã¯ã [.filename]#/var/db/pkg# ã® port ã®ååã®å¾ã«ããã¼ã¸ã§ã³çªå·ã示ããã¦ãã¾ãã ãããã·ã¹ãã ã FreeBSD Subversion ãªãã¸ããªã¨åæãã¦ããªãã£ããã åæ§ç¯ãæ¯æ¥è¡ããã¦ãããããªç¶æ³ã§ãªããã°ã ããããããã®ã·ã¹ãã ã«ã¯å½±é¿ãã¦ããã§ãããã
-
<.> `Corrected` ãã£ã¼ã«ãã¯ã èå¼±æ§ãä¿®æ£ãããæ¥ãæéã ã¿ã¤ã ã¾ã¼ã³ãããã³ãªãªã¼ã¹ã示ããã¾ãã
-
-<.> link:http://cve.mitre.org[Common Vulnerabilities and Exposures] ãã¼ã¿ãã¼ã¹ã«ããã¦ã èå¼±æ§ãæ¢ãããã«ä½¿ç¨ã§ããè奿
å ±ã示ãã¾ãã
-
+<.> http://cve.mitre.org[Common Vulnerabilities and Exposures] ãã¼ã¿ãã¼ã¹ã«ããã¦ã èå¼±æ§ãæ¢ãããã«ä½¿ç¨ã§ããè奿
å ±ã示ãã¾ãã
<.> `Background` ãã£ã¼ã«ãã¯ã å½±é¿ãã¦ããã¦ã¼ãã£ãªãã£ã«é¢ããæ
å ±ã示ãã¾ãã 大ä½ã®å ´åã¯ããªãã¦ã¼ãã£ãªãã£ã FreeBSD ã«åå¨ãããã ä½ã®ããã«ä½¿ããã¦ãããã ã©ã®ããã«ç¨ããããããã«ãªã£ã¦ãããã ã¨ãã£ãæ
å ±ã示ããã¾ãã
-
<.> `Problem Description` ãã£ã¼ã«ãã¯ã ããæ·±ãã»ãã¥ãªãã£ãã¼ã«ã«ã¤ãã¦èª¬æãã¾ãã åé¡ã®ããã³ã¼ãã®æ
å ±ãã ãã®ã¦ã¼ãã£ãªãã£ãæªæã®ããä½¿ãæ¹ã«ããã ã©ã®ããã«ã»ãã¥ãªãã£ãã¼ã«ãéããããã¨ãã£ããã¨ã示ããã¾ãã
-
<.> `Impact` ãã£ã¼ã«ãã¯ã ãã®åé¡ãã·ã¹ãã ã«å¯¾ãã¦ã ã©ã®ãããªå½¢å¼ã®å½±é¿ãä¸ãããã«ã¤ãã¦ç¤ºãã¾ãã ãã¨ãã°ãDoS æ»æã«ãããã®ãã ã¦ã¼ã¶ã«å¯¾ãã¦æå³ããªãç¹æ¨©ãæããã¦ãã¾ããã®ãã ã¾ãã¯ãæ»æè
ã«ã¹ã¼ãã¦ã¼ã¶ã®ã¢ã¯ã»ã¹ãä¸ãããããªãã®ãã ã¨ãã£ããã¨ã示ããã¾ãã
-
<.> `Workaround` ãã£ã¼ã«ãã¯ã æéã«ããå¶éãããããã¯ã¼ã¯ã®å¯ç¨æ§ã¾ãã¯ä»ã®çç±ã«ããã ã·ã¹ãã ãã¢ããã°ã¬ã¼ãã§ããªãã·ã¹ãã 管çè
ã«å¯¾ãã¦ã åé¿æ¹æ³ãæä¾ãã¾ãã ã»ãã¥ãªãã£ãçãè¦ãã¹ãã§ã¯ãªãã å½±é¿ããã·ã¹ãã ã«ã¯ããããå½ã¦ããã ã»ãã¥ãªãã£ãã¼ã«ã®åé¿æ¹æ³ãå®è¡ãã¹ãã§ãã
-
<.> `Solution` ãã£ã¼ã«ãã¯ã å½±é¿ã®ããã·ã¹ãã ã«ããããå½ã¦ãæé ãæä¾ãã¾ãã ããã§ã¯ã¹ããããã¨ã«ã·ã¹ãã ã«ããããå½ã¦ã å®å
¨ã«åä½ããããã«ã 試é¨ããæ¤è¨¼ãããæ¹æ³ãè¨è¼ããã¾ãã
-
<.> `Correction Details` ãã£ã¼ã«ãã¯ã Subversion ãã©ã³ãã¾ãã¯ãªãªã¼ã¹åã®ããªãªããã¢ã³ãã¼ã¹ã³ã¢ã«ç½®ãæãããã®ã示ãã¾ãã ããã§ã¯ã åãã©ã³ãã«ããã¦å½±é¿ãããã¡ã¤ã«ã®ãªãã¸ã§ã³çªå·ã示ãã¾ãã
-
<.> `References` ãã£ã¼ã«ãã¯ã é常ãã¦ã§ããã¼ã¸ã® URL, books, ã¡ã¼ãªã³ã°ãªã¹ãããã³ãã¥ã¼ã¹ã°ã«ã¼ãã¨ãã£ãã ã»ãã®æ
å ±ã¸ã®ã½ã¼ã¹ãæä¾ãã¾ãã
[[security-accounting]]
diff --git a/documentation/content/ja/books/handbook/x11/_index.adoc b/documentation/content/ja/books/handbook/x11/_index.adoc
index c981f40a5f..c8993db1f2 100644
--- a/documentation/content/ja/books/handbook/x11/_index.adoc
+++ b/documentation/content/ja/books/handbook/x11/_index.adoc
@@ -52,10 +52,10 @@ bsdinstall ãç¨ãã FreeBSD ã®ã¤ã³ã¹ãã¼ã«ã§ã¯ã ã°ã©ãã£ã«
[NOTE]
====
-Xorg ãèªåçã«è¨å®ããã¤ã³ã¹ãã¼ã«æ¹æ³ã叿ããã¦ã¼ã¶ã¯ã https://www.furybsd.org[FuryBSD], https://ghostbsd.org[GhostBSD] ããã³ https://www.midnightbsd.org[MidnightBSD] ãåç
§ãã¦ãã ããã
+Xorg ãèªåçã«è¨å®ããã¤ã³ã¹ãã¼ã«æ¹æ³ã叿ããã¦ã¼ã¶ã¯ã link:https://www.furybsd.org[FuryBSD], link:https://ghostbsd.org[GhostBSD] ããã³ link:https://www.midnightbsd.org[MidnightBSD] ãåç
§ãã¦ãã ããã
====
-Xorg ã対å¿ãããããªãã¼ãã¦ã§ã¢ã«ã¤ãã¦ã®ããå¤ãã®æ
å ±ã¯ã http://www.x.org/[x.org] ã®ã¦ã§ããµã¤ããã覧ãã ããã
+Xorg ã対å¿ãããããªãã¼ãã¦ã§ã¢ã«ã¤ãã¦ã®ããå¤ãã®æ
å ±ã¯ã link:http://www.x.org/[x.org] ã®ã¦ã§ããµã¤ããã覧ãã ããã
ãã®ç« ãèªãã°ä»¥ä¸ã®ãã¨ããããã¾ãã
@@ -134,13 +134,11 @@ Xorg ã¯ã æ¨æºçãªã»ã¨ãã©ã®ãããªã«ã¼ãã ãã¼ãã¼ãã
[TIP]
====
-
ãããªã«ã¼ãããã¼ãã¼ããå
¥åããã¤ã¹ã¯ã èªåçã«æ¤åºãããã®ã§ãæåã®è¨å®ã¯å¿
è¦ããã¾ããã èªåèªèã«å¤±æããã¨ã以å¤ã¯ã[.filename]#xorg.conf# ã使ãããã`-configure` ããã»ã¹ã®å®è¡ã¯è¡ããªãã§ãã ããã
====
[.procedure]
====
-
*** 196 LINES SKIPPED ***
More information about the dev-commits-doc-all
mailing list