PASSWD

åå
æ¸å¼
説æ
ãªãã·ã§ã³
ä¸è¨ã®2ååãå¿ãããª
ãããååã®ä¸é¨ã¯ã·ã¹ãã ã«ãã£ã¦å¼·å¶ããã¦ããããä¸é¨ã®ã¿ã§ãããèªåã®æ¹ã§ãæ°ãã¤ããäºãã·ã¹ãã ãããã»ã-ã¥ã¢ã«ãããã¨ãå¯è½ã«ãªããè¿ãå¤
æºæ 
ãã¡ã¤ã«
ãã°
é¢é£äºé 
èè


åå

passwd − ã¦ã¼ã¶ãã¹ã¯ã¼ãã夿´ãã

æ¸å¼

passwd [-k] [-l] [-u [-f]] [-d] [-e] [-n mindays] [-x maxdays] [-w warndays] [-i inactivedays] [-S] [–stdin] [username]

説æ

Passwd ã¯ã¦ã¼ã¶ã¢ã«ã¦ã³ãã»ã°ã«ã¼ãã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ãã夿´ããã

Passwd 㯠Linux-PAM 㨠Libuser APIãéãã¦æ©è½ããããã«è¨å®ããã¦ããã

Passwd ã¯ã”passwd” ãµã¼ãã¹ã¨ã㦠Linux-PAM ã§åæåãèªè¨¼ããããã«ãè¨å®ãã password ã¢ã¸ã¥ã¼ã«ã使ç¨ããããã®å¾ãã¦ã¼ã¶ã®ãã¹ã¯ã¼ããæ´æ°ããã

Linux-PAM è¨å®ãã¡ã¤ã«ã®ç°¡åãªã¨ã³ããªã¯ä»¥ä¸ã«è¨è¿°ããã

#
# passwd service entry that does strength checking of
# a proposed password before updating it.
#
passwd password requisite
/usr/lib/security/pam_cracklib.so retry=3
passwd password required
/usr/lib/security/pam_unix.so use_authtok
#

注æ:ãä»ã®ã¢ã¸ã¥ã¼ã«ã¿ã¤ãã¯ãã®ããã°ã©ã ãé©åã«æ©è½ãããããã«ã¯å¿è¦ãªãã

ãªãã·ã§ã³

-k

ãªãã·ã§ã³ -k ã¯å¤±å¹ããèªè¨¼ãã¼ã¯ã³(ãã¹ã¯ã¼ã)ã ããæ´æ°ããäºãæããã¦ã¼ã¶ã失å¹åã®ãã¼ã¯ã³ããã®ã¾ã¾ä½¿ç¨ãããå ´åã

-l

ãã®ãªãã·ã§ã³ã¯ç¹å®ã®ã¢ã«ã¦ã³ããããã¯ãããå ´åã«ä½¿ç¨ãããroot ã®ã¿ä½¿ç¨å¯è½ãããã¯ã¯æå·åããããã¹ã¯ã¼ãã䏿£ãªæå- åã¨ãã¦å¦çãã(æå·åããããã¹ã¯ã¼ãã®åã«!ãä»ãã)äºã§å®è¡ãããã

–stdin

ãã®ãªãã·ã§ã³ã¯ passwd ãæ¨æºå¥åããæ°ãããã¹ã¯ã¼ããèª- ã¿è¾¼ãå ´åãæãããã¤ãããã§ãå¯è½ã§ããã

-u

ãã®ãªãã·ã§ã³ã¯ -l ãªãã·ã§ã³ã®éã§ããããã¬ãã£ãã¯ã¹ ! ãåé¤ããäºã«ãã£ã¦ã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ããè§£é¤ãããroot ã®ã¿ä½¿ç¨å¯è½ã æ¨æºã§ã¯ passwd ã¯ãã¹ã¯ã¼ããç¡ãã¢ã«ã¦ã³ããæå¦ãã(“!” ã®ã¿ãã¹ã¯ã¼ãã¨ãã¦ããå ´åã¯ã¢ã«ã¦ã³ããè§£é¤ããªã)ãå¼·å¶ãªãã·ã§ã³ -f ã¯ãã®ä¿è·ãç¡å¹ã«ããã

-d

ãã®ãªãã·ã§ã³ã¯ã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ããç¡å¹ã«ããããã®ææ©ãæ¹æ³ã§ãããæå®ã®ã¢ã«ã¦ã³ãããã¹ã¯ã¼ããªãã«è¨- å®ãããroot ã®ã¿ä½¿ç¨å¯è½ã

-e

ãã®ãªãã·ã§ã³ã¯ã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ãã®æå¹æéãç¡å¹ã«ããããã®ææ©ãæ¹æ³ã§ããã該å½ã®ã¦ã¼ã¶ã¼ã¯æ¬¡åã- ã°ã¤ã³æã«ãã¹ã¯ã¼ãã®å¤æ´ãæ±ãããããroot ã®ã¿ä½¿ç¨å¯è½ã

-f

ãã®ãªãã·ã§ã³ã¯åæã«æå®ãããªãã·ã§ã³ãå¼·å¶å®è¡ããã

-n

ãã®ãªãã·ã§ã³ã¯ã¦ã¼ã¶ã®ã¢ã«ã¦ã³ãããã¹ã¯ã¼ãæå¹æéã«å¯¾å¿ãã¦ããå ´åããã¹ã¯ã¼ã夿´å¾ã«ååº¦å¤æ´ãå¯è½ã«ãªãã¾ã§ãæ¥åä½ã§è¨- å®ãããroot ã®ã¿ä½¿ç¨å¯è½ã

-x

ãã®ãªãã·ã§ã³ã¯ã¦ã¼ã¶ã®ã¢ã«ã¦ã³ãããã¹ã¯ã¼ãæå¹æéã«å¯¾å¿ãã¦ããå ´åããã¹ã¯ã¼ãæå¹æéãæ¥åä½ã§è¨- å®ãããroot ã®ã¿ä½¿ç¨å¯è½ã

-w

ãã®ãªãã·ã§ã³ã¯ã¦ã¼ã¶ã®ã¢ã«ã¦ã³ãããã¹ã¯ã¼ãæå¹æéã«å¯¾å¿ãã¦ããå ´åããã¹ã¯ã¼ã失å¹åã«ãã¦ã¼ã¶ã¸è- ¦åãæ¥åä½ã§äºåããããã«è¨å®ãããroot ã®ã¿ä½¿ç¨å¯è½ã

-i

ãã®ãªãã·ã§ã³ã¯ã¦ã¼ã¶ã®ã¢ã«ã¦ã³ãããã¹ã¯ã¼ãæå¹æéã«å¯¾å¿ãã¦ããå ´åããã¹ã¯ã¼ããæå¹æéã«éãã¦ç¡å¹ã¨ãã¹ãå ´åããã¹ã¯ã¼ããç¡å¹ã«ããã¾ã§ã®ç¶äºæéãæ¥åä½ã§è¨- å®ãããroot ã®ã¿ä½¿ç¨å¯è½ã

è¨³æ³¨ï¼æå®ããæ¥æ°ãè¶ãã¦ãã¹ã¯ã¼ãæéåãç¶æã®ã¾ã¾ã«ããã¨ã ã¦ã¼ã¶ã¯ãã®ã¢ã«ã¦ã³ãã«å¥ããªããªãã

-S

ãã®ãªãã·ã§ã³ã¯ã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ãã®ç¶æã«ã¤ãã¦ç- ãæå ±ãåºåãããrootã®ã¿ä½¿ç¨å¯è½ã

ä¸è¨ã®2ååãå¿ãããª

ãã¹ã¯ã¼ããä¿è·ããã

ãã¹ã¯ã¼ããæ¸ããã«è¨æ¶ããã ç¹ã«ããã¹ã¯ã¼ããã¡ã¢ããç´ããããããã«æ¾ç½®ãã¦ã¯ãããªããæå·åããã¦ããªããã¡ã¤ã«ã«è¨å¥ãã¦ã¯ãããªããä»çµç¹ã«ãã£ã¦å¶å¾¡ããã¦ããã·ã¹ãã ã¨ã¯ç¡é¢ä¿ã®ãã¹ã¯ã¼ãã使ç¨ããã

ç¹ã«ã³ã³ãã¥ã¼ã¿ãµãã¼ãããã³ãã¼ã¨åä¹ãèã«ã¯ãèªåã®ãã¹ã¯ã¼ãã屿ãä»ä¸ãã¦ã¯ãããªãã

ãã¹ã¯ã¼ããå¥åãã¦ããã®ã誰ãã«ã®ãããã¦ã¯ãããªãã

ä¿¡é ¼ã§ããªãã³ã³ãã¥ã¼ã¿ã«ãã¹ã¯ã¼ããå¥åãã¦ã¯ãããªããã¾ããä½ãããæªããã å ´åã誰ãããã¹ã¯ã¼ãããã¤ã¸ã£ãã¯ãããã¨ãã¦ãããããããªãã

ãã¹ã¯ã¼ããç¹å®æéã®ã¿ä½¿ç¨ãã宿çã«å¤æ´ããã

äºæ¸¬å°é£ãªãã¹ã¯ã¼ãã鏿ããã

passwd ã¯æ¬å½ã«æªããã¹ã¯ã¼ãã鏿ããäºã黿- ¢ãããã¨ãããã絶対å®å¨ã§ã¯ãªããè³¢ããã¹ã¯ã¼ãã使ãããè¾æ¸ã«è¼ã£ã¦ãããã®ã使ç¨ãã¦ã¯ãããªã(ãããªãè¨èªãå°éç¨èªã§ãã£ã¦ããããªã)ãåå(éå¶èã親ãå- ããããããã¡ã³ã¿ã·ã¼ã®ã- ã£ã©ã¯ã¿ãæå人ãå°å)ãã¾ãã¯èªåã«é¢é£ããããããå人çãªååããã¢ã«ã¦ã³ãåã使ç¨ãã¦ã¯ãããªãã奿å¯è½ãª(é»è©±çªå·ãè»ã®ãã³ãã¼ãã¾ãã¯ç¤¾ä¼ä¿éçªå·)å人æå ±ãèªåãã¨ãã¾ãç°å¢ã®æå ±ã使ç¨ãã¦ã¯ãããªãã

èªçæ¥ãåç´ãªãã¿ã¼ã³(ä¾ã¨ã㦠qwerty abc ã¾ã㯠aaa )ã使ç¨ãã¦ã¯ãããªãããããã®éèªã¿ã«åå¾ãã¦ç¶ãã¦æ°å- ã使ç¨ãã¦ã¯ãããªããããããã大æåãå°æåãæ°åãã¾ãã¯å¥èª- ç¹ãæ··ãã¦ä½¿ç¨ãããæ°è¦ã®ãã¹ã¯ã¼ãã鏿ããéã«ã¯ä»ã¾ã§ä½¿ç¨ãã¦ããã©ã®ãã¹ã¯ã¼ãã«ãé¢é£ãªãããã«æ³¨æãããé·ããã¹ã¯ã¼ã(ä¾ãã°8æå- )ã使ç¨ãããåèªã®ãã¢ãå¥èª- ç¹ã¨ä¸ç·ã«ãããããã¹ãã¬ã¼ãº(çè§£å¯è½ãªè¤æ°ã®åèªã®ã·ã¼ã±ã³ã¹)ãã¾ãã¯åãã¹ãã¬ã¼ãºã®é æå- ã使ç¨ãã¦ãè¯ãã

ãããååã®ä¸é¨ã¯ã·ã¹ãã ã«ãã£ã¦å¼·å¶ããã¦ããããä¸é¨ã®ã¿ã§ãããèªåã®æ¹ã§ãæ°ãã¤ããäºãã·ã¹ãã ãããã»ã-ã¥ã¢ã«ãããã¨ãå¯è½ã«ãªããè¿ãå¤

ç®çãæåãã¦çµäºããå¾ã« passwd ã¯è¿ãå¤ 0 ãåºåãã¦çµäºãããè¿ãå¤ 1 ã¯ã¨ã©ã¼ãçºçãããã¨ãæå³ãããã¨ã©ã¼ã¡ãã»ã¼ã¸ã¯æ¨æºã¨ã©ã¼åºåã«åºåãããã

æºæ 

Linux-PAM (Linux ã® Pluggable Authentication ã¢ã¸ã¥ã¼ã«)ã
注æã使ç¨ãã¦ãããã£ã¹ããªãã¥ã¼ã·ã§ã³ã® Linux-PAM ãLinuxãã¡ã¤ã«ã·ã¹ãã æ¨æºã«æºæ ãã¦ããå ´åãä¾ç¤ºããæ§ã«ã/usr/lib/security/ ã§ã¯ãªãã /lib/security/ ã«ã¢ã¸ã¥ã¼ã«ãããã

ãã¡ã¤ã«

/etc/pam.d/passwd – the Linux-PAMã è¨å®ãã¡ã¤ã«

ãã°

æ¢ç¥ã®ãã°ã¯ç¡ãã

é¢é£äºé 

pam(8), pam.d(5), libuser.conf(5), 㨠pam_chauthtok(3)ã

Linux-PAM ã«ã¦ãã®ããã°ã©ã ãè¨å®ããããã®ã¾ã¨ã¾ã£ãæå ±ã¯ã /usr/share/doc/pam… ã«ãã Linux-PAM System Administrators’ Guide ã
åç§ã®ãã¨ã

èè

Cristian Gafton