ãããã«æè¿ã§ã¯èšãããªããªã£ãããéå»ã«ã¯ãŒã ã«ææããéšããèµ·ããŠãIISã¯å±éº!ããšãã䞻匵ãåºåã£ãããšããã£ããããããçµéšããåœåº§ã®ã»ãã¥ãªãã£åŒ·åçãšããŠã®ãIIS Lockdown Toolã®é åžããããã®åŸã®IISã®æ¹è¯ããšãã£ã話ã«ã€ãªãã£ãŠããã
çŸåšã§ã¯éå»ã®ããã«ãIISã¯å±ãªãããšå¹èŽãã声ã¯ãªããªã£ãããããã¯ãã£ãŠãè åšãã©ãã©ãé²åããŠããã®ã宿 ãããã§ãIISãå®å šã«å©çšããããã®åºæ¬çãªèãæ¹ã«ã€ããŠãŸãšããŠã¿ãã
éåã¯æ¬åœã«å¿ èŠãªåœ¹å²ãµãŒãã¹ã ãã远å ããããš
ãããããéå»ã«IISãããã¯WindowsãµãŒãã§åé¡èŠãããã®ã¯ãã»ããã¢ããçŽåŸã®ç¶æ ã§ãã§ã«ããŸããŸãªãµãŒãæ©èœãåäœããŠããŠããããããããŠãŒã¶ãŒãèŠéãããã¡ã ã£ãç¹ã ã£ãã
ã ãããWindows Server 2003ããã¯ãåæç¶æ ã§ã¯å¿ èŠæäœéã®æ©èœã ããåäœãããŠãããå¿ èŠã«å¿ããŠãŠãŒã¶ãŒãæç€ºçã«è¿œå ããããšãã圢ãåãå ¥ãããWindows Server 2008ã¯ãããããã«æ·±åºŠåãããŠããµãŒããŒãããŒãžã£ã§ã圹å²ããã圹å²ãµãŒãã¹ãããæ©èœããåå¥ã«è¿œå ããããã«ããŠããã
IISãããã®ã圹å²ãã®1ã€ã§ãããIISãæ§æããããŸããŸãªãµãŒãæ©èœãªã©ãåå¥ã®ã圹å²ãµãŒãã¹ãã«ãªã£ãŠãããããã§èªåãæ¬åœã«å¿ èŠãšãã圹å²ãµãŒãã¹ã ãã远å ããããã«å¿æãããããäžãäžã®å¯èœæ§ã®é倧è©äŸ¡ããšãããã€ã§ããã²ãã£ãšãããšäœ¿ããããããªããã¯ããŠããŠã䜿ããã«çµããããã®ã§ããã
ãã ãããã圹å²ãµãŒãã¹ã远å ããæãèªåçã«éé£ãã«ãªã£ãŠè¿œå ãã圹å²ãµãŒãã¹ãçºçããããšããããããã¯å¿ èŠãªãã®ã ãããçå µæ³ã§åé€ããŠããŸã£ãŠã¯ãããªãã
ãã®ä»ã®ã»ãã¥ãªãã£åŒ·åçãããã
äžèŠãªåœ¹å²ãµãŒãã¹ãçãã ãã§ãªããIISã«ã¯ããã«ãããããšå®å šæ§ãé«ããããã®ãã€ã³ããããã
IISã¯ãã¡ã€ã³ ã³ã³ãããŒã©ã«ããªã
ãããªãã®ãŠãŒã¶ãŒæ°ãæã€äŒæ¥ãããã¯ãŒã¯ãªããActive Directoryãå°å ¥ããã»ããåççã ããå€éšã«å ¬éãããµãŒãã¯è©±ãå¥ã§ãããã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ããå Žæã«ãã¡ã€ã³ã³ã³ãããŒã©ãé 眮ãããšããŠãŒã¶ãŒæ å ±ãªã©ãæŒæŽ©ããåå ã«ã€ãªããããã®ãããã€ã³ã¿ãŒãããåãã«å ¬éãããµãŒãã¯ãã¡ã€ã³ã³ã³ãããŒã©ã«ããªãã§ãã¹ã¿ã³ãã¢ãã³ãµãŒããšããŠéçšããå¿ èŠãããã
ãã°ä¿åãã©ã«ãã®ã¢ã¯ã»ã¹æš©ã匷åãã:
æ»æè ãäŸµå ¥ã®èšŒæ ãæ¶ãããã«ãã°ã现工ããäºæ ãé²ãããããã°ãä¿åãããã©ã«ãã®ã¢ã¯ã»ã¹æš©ã峿 ŒåããŠã管çè 以å€ã¯ã¢ã¯ã»ã¹ã§ããªãããã«ããæ¹æ³ãèãããããå ·äœçã«ã¯ããAdministrators - ãã«ã³ã³ãããŒã«ããSystem - ãã«ã³ã³ãããŒã«ãã®2çš®é¡ãšããããã£ãšãã管çè ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã奪åãããªãããšãåæã§ããã
ãŠãŒã¶ãŒãIUSR_ãã®ã¢ã«ãŠã³ãèšå® :
IISãå¿åã¢ã¯ã»ã¹ã«çšãããŠãŒã¶ãŒã¢ã«ãŠã³ããIUSR<ã³ã³ãã¥ãŒã¿å>ããäžæ£äŸµå ¥ã«å©çšãããããšãé²ãããããã¹ã¯ãŒãããŠãŒã¶ãŒèªèº«ã倿Žã§ããªãããã«ããæ¹æ³ãèãããããããã«ãããæ»æè ãåæã«ãã¹ã¯ãŒããå€ããããªãããã«ããããŸãããIUSR<ã³ã³ãã¥ãŒã¿å>ãã«ããããŒã«ã«ãã°ãªã³ãçŠæ¢ããæ¹æ³ãèããããã
ã€ã³ã¿ãŒãããåãã®WebãµãŒãã§ã¯å¿åæ¥ç¶ãè¡ãå Žåã倧åãå ããã ãããããŠãŒã¶ãŒèªèšŒãè¡ããµã€ãã§å¿åæ¥ç¶ãå¿ èŠãšããªãå Žåã«ã¯ããã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã¯ç¡å¹åããããšãã§ããã
ã³ã³ãã³ãã®é çœ®å Žæå€æŽ :
IISã®ã³ã³ãã³ãé çœ®å Žæã¯ãæ¢å®å€ã§ãC:\InetPubã以äžãšãªã£ãŠããããšããããšã¯ããã®ããŒã«ã«ãã¹ãæå®ããã°Webã³ã³ãã³ãã«ã¢ã¯ã»ã¹ã§ãããšããããšã«ãªãã
ãã®è£ããããŠãã³ã³ãã³ãé 眮çšã®ãã©ã«ããå¥ã®å Žæã«èšå®ãçŽãããšã§ãäžæ£äŸµå ¥ã®è¢«å®³ã«éã£ãéã®è¢«å®³æ¡å€§ãæå¶ã§ãããWebãµã€ãã§äœ¿çšããããŒã¿ããŒã¹ãã¹ã¯ãªãããªã©ãä»®æ³ãã£ã¬ã¯ããªæ©èœã§ãC:\Inetpubã以äžãšã¯ç°ãªããã©ã«ãã«é 眮ããæ¹æ³ã䜿ããã
ãããã¯ãŒã¯èšå®ã®å€æŽ
ãŸãããããã¯ãŒã¯é¢é£èšå®ããµãŒãã¹ã®åäœå 容倿Žããäžæ£äŸµå ¥ã«è²¢ç®ã§ããå Žåãããã
WindowsãµãŒãã®åæç¶æ ã§ã¯ããã¡ã€ã«/ããªã³ã¿å ±ææ©èœã¯åäœããŠããããã®ç¶æ ã§ããµãŒãæ©èœã¯ServerãµãŒãã¹ãã¯ã©ã€ã¢ã³ãæ©èœã¯WorkstatonãµãŒãã¹ã§åäœããŠãããããã«ãå ±ææ©èœã䜿çšãããããã³ã«ãããªãã¡NBT(NetBIOS over TCP/IP)ãšãã€ã¬ã¯ããã¹ãã£ã³ã°SMBã¯ããããã¯ãŒã¯æ¥ç¶èšå®ã®ããããã£ç»é¢ã§ããã€ã³ããããŠããã
ãšããããã€ã³ã¿ãŒãããåãã«å ¬éããWebãµãŒãã§Windowsãã¡ã€ã«å ±æã䜿çšããå¿ ç¶æ§ã¯ãªãããã³ã³ãã³ãã®ã¢ããããŒããFTPãµãŒãæ©èœã䜿ãã°å®çŸã§ãããããããFTPãµãŒãã§ããã°IPã¢ãã¬ã¹ãçšããã¢ã¯ã»ã¹å¶éãè¡ããã®ã§ããŠãŒã¶ãŒèªèšŒã«é Œããããç¢ºå®æ§ãé«ãã
ããã§ããã°ãWindowsãã¡ã€ã«å ±æã®æ©èœãæ¢ããŠãããã«ãããã¯ãŒã¯æ¥ç¶èšå®ã§ãã€ã³ããå€ãããšãã§ããã
ãŸããWindowsãã¡ã€ã«å ±æã®æ©èœãæ¢ããã«ã¯ã[ãµãŒãã¹]管çããŒã«ã䜿ã£ãŠServerãµãŒãã¹ãšWorkstatoinãµãŒãã¹ã忢ãããäžã§ãããã«ã¹ã¿ãŒãã¢ããã®èšå®ã[ç¡å¹]ã«å€æŽãããããã§ãWindowsãã¡ã€ã«å ±æã¯å©çšã§ããªããªããäžæ¹ãWindowsãã¡ã€ã«å ±ææ©èœã®ãã€ã³ããåãã«ã¯ããããã¯ãŒã¯æ¥ç¶èšå®ã®ããããã£ç»é¢ã§[Microsoftãããã¯ãŒã¯çšã¯ã©ã€ã¢ã³ã]ãš[Microsoftãããã¯ãŒã¯çšãã¡ã€ã«ãšããªã³ã¿å ±æ]ã®ãã§ãã¯ããªãã«ããã
ããã§äœè«ãã²ãšã€ããã®ãã€ã¢ãã°ããTCP/IPã®ããããã£ç»é¢ãåŒã³åºããŠãããã«[詳现èšå®]ãã¯ãªãã¯ãããç¶ããŠè¡šç€ºãããã€ã¢ãã°ã§ã[WINS]ã¿ãã«ç§»åãããšã[NetBIOS over TCP/IPãç¡å¹ã«ãã]ãéžæããããšã§NBTã ããç¡å¹åããŠããã€ã¬ã¯ããã¹ãã£ã³ã°SMBã ããåäœããç¶æ ã«èšå®ã§ãããã€ã³ã¿ãŒãããåãã®ãµãŒãã§ã¯çæ¹ã ãåã£ãŠãæå³ã¯ãªãããã ããããããªããšãã§ããããšããããšã§èŠããŠãããšãäœã圹ç«ã€ããšãããããç¥ããªãã
![]() |
ãããã¯ãŒã¯æ¥ç¶èšå®ã®ããããã£ç»é¢ã§ãWindowsãã¡ã€ã«å ±æé¢é£æ©èœã®ãã€ã³ããå€ããšãåœç¶ãªããWindowsãã¡ã€ã«å ±æã¯å©çšã§ããªããªã |
ãã®ã»ããã€ã³ã¿ãŒãããåãã«èšçœ®ãããµãŒãã§ã¯åºå®IPã¢ãã¬ã¹ãå²ãåœãŠãŠããã®IPã¢ãã¬ã¹ãšãã¹ãåãDNSã«ç»é²ããã®ãæ®éã ãããDNSãµãŒãã«å¯ŸããåçæŽæ°æ©èœãå¿ èŠãªãããã®ããã[ãã®æ¥ç¶ã®ã¢ãã¬ã¹ãDNSã«ç»é²ãã]ãã§ãã¯ããã¯ã¹ã¯ãªãã«ããã
