锘??xml version="1.0" encoding="utf-8" standalone="yes"?>国产成人久久激情91 ,日产精品久久久一区二区,亚洲国产精品久久久久婷婷老年http://www.shnenglu.com/alexhappy/category/10784.htmlFaith Firstzh-cnWed, 10 Jun 2009 09:53:54 GMTWed, 10 Jun 2009 09:53:54 GMT60Linux搴旂敤浣跨敤TSIG鍜孌NSSEC鍔犲浐鍩熷悕鏈嶅姟鍣?/title><link>http://www.shnenglu.com/alexhappy/articles/86748.html</link><dc:creator>alexhappy</dc:creator><author>alexhappy</author><pubDate>Thu, 04 Jun 2009 06:15:00 GMT</pubDate><guid>http://www.shnenglu.com/alexhappy/articles/86748.html</guid><wfw:comment>http://www.shnenglu.com/alexhappy/comments/86748.html</wfw:comment><comments>http://www.shnenglu.com/alexhappy/articles/86748.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.shnenglu.com/alexhappy/comments/commentRss/86748.html</wfw:commentRss><trackback:ping>http://www.shnenglu.com/alexhappy/services/trackbacks/86748.html</trackback:ping><description><![CDATA[<p>姝ょ瘒鏂囩珷涓鴻漿杞斤紒<br><br>涓銆丏NS鏈嶅姟鍣ㄧ殑閲嶈鎬?/p> <p>DNS鏄洜鐗圭綉寤鴻鐨勫熀紜錛屽嚑涔庢墍鏈夌殑緗戠粶搴旂敤錛岄兘蹇呴』渚濊禆DNS緋葷粺鍋氱綉鍧鏌ヨ鐨勬寚寮曞姩浣溿傚鏋淒NS緋葷粺榪愪綔涓嶆甯革紝鍗充嬌Web鏈嶅姟鍣ㄩ兘瀹屽ソ濡傚垵錛岄槻鐏緋葷粺閮藉杽灝藉叾鑱岋紝鐩稿叧鐨勫悗绔簲鐢ㄦ湇鍔″櫒浠ュ強鏁版嵁搴撶郴緇熻繍浣滄甯革紝鍥犱負鏃犳硶鍦ㄦ湡闄愭椂闂村唴鏌ュ緱鍒扮綉鍧錛屽皢浼氬鑷寸數瀛愰偖浠舵棤娉曚紶閫掞紝鎯寵浣跨敤緗戝煙鍚嶇О鍘昏繛鎺ユ煇涓綉欏碉紝涔熶細鍥犳煡涓嶅嚭緗戠粶鍦板潃錛屼互鑷磋仈鏈哄け璐ャ?001騫?鏈?4鏃ワ紝緹庡浗寰蔣鍏徃鎵綆$悊鐨勭浉鍏崇綉緇滅郴緇燂紝閬彈緗戠粶榛戝鐨勬嫆緇濇湇鍔℃敾鍑誨悗瀵艱嚧鍏ㄧ悆鍚勫湴鐨勭敤鎴鋒帴榪?4灝忔椂鐨勬椂闂存棤娉曡繛涓婅鍏徃鐩稿叧鐨勭綉绔欙紝閫犳垚璇ュ叕鍙哥浉褰撲弗閲嶇殑鍟嗕笟鎹熷け銆傛牴鎹互寰鐨勭粡楠屼箣涓紝緗戠粶鏀誨嚮鐨勫璞″鏁頒富瑕侀泦涓湪鎺у埗緗戠粶璺敱鐨勮澶?璺敱鍣紝闃茬伀澧欑瓑)鍜屽悇綾誨簲鐢ㄦ湇鍔″櫒(Web銆侀偖浠剁瓑)銆傚洜姝わ紝鐩墠澶氭暟鐨勭綉緇滅郴緇熷畨鍏ㄤ繚鎶わ紝閫氬父閮介泦涓湪璺敱璁懼鍜屽簲鐢ㄦ湇鍔″櫒鏈韓銆傜劧鑰岋紝榪欎竴嬈$殑寰蔣鍏徃琚敾鍑諱簨浠訛紝涓庝互寰鍏跺畠緗戠珯鏀誨嚮浜嬩歡鐨勬渶澶т笉鍚岋紝灝卞湪浜庤繖涓嬈¤鏀誨嚮鐨勫璞℃槸DNS鏈嶅姟鍣ㄨ屼笉鏄疻EB鏈嶅姟鍣ㄦ湰韜傝繖嬈$殑浜嬩歡瀹e憡鍙︿竴縐嶆柊鍨嬬殑緗戠粶鏀誨嚮綾誨埆錛屽線鍚庡皢鍙兘鎴愪負甯告併?/p> <p>浜掕仈緗戜笂DNS鏈嶅姟鍣ㄧ殑浜嬪疄鏍囧噯灝辨槸ISC錛?a >http://www.isc.org/</a> 錛夊叕鍙哥殑Berkeley Internert Name Domain(BIND)錛屽畠鍏鋒湁騫挎硾鐨勪嬌鐢ㄥ熀紜錛屼簰鑱旂綉涓婄殑緇濆ぇ澶氭暟DNS鏈嶅姟鍣ㄩ兘鏄熀浜庤繖涓蔣浠剁殑銆侼etcraft鍦ㄥ煙鍚嶆湇鍔″櫒涓婄殑緇熻(<a >http://www.netcraft.com/</a> )鏄劇ず 2003騫寸浜屽搴﹁繘琛岀殑涓涓皟鏌ュ彂鐜幫紝鍦ㄤ簰鑱旂綉涓婅繍琛岀潃鐨凞NS鏈嶅姟鍣ㄤ腑錛孖SC鐨凚IND鍗犳嵁浜?5%鐨勫競鍦轟喚棰濄備簰鑱旂綉鏄敱寰堝涓嶅彲瑙佺殑鍩虹鏋勪歡緇勬垚銆傝繖鍏朵腑灝卞寘鍚簡DNS錛屽畠緇欑敤鎴鋒彁渚涗簡鏄撲簬璁板繂鐨勬満鍣ㄥ悕縐?姣斿sina.com)錛屽茍涓斿皢瀹冧滑緲昏瘧鎴愭暟瀛楀湴鍧鐨勫艦寮忋傚浜庨偅浜涚敤浜庡叕鍏辨湇鍔$殑鏈哄櫒涓鑸繕鎻愪緵“鍙嶅悜鏌ヨ”鐨勫姛鑳斤紝榪欑鍔熻兘鍙互鎶婃暟瀛楄漿鎹㈡垚鍚嶅瓧銆傜敱浜庡巻鍙茬殑鍘熷洜錛岃繖縐嶅姛鑳戒嬌鐢ㄧ殑鏄闅愯棌鐨?#8220;in-addr.arpa”鍩熴傚in-addr鍩熺殑璋冩煡錛屽彲浠ヨ鎴戜滑鏇村姞浜嗚В鏁翠釜Internet鏄浣曡繍浣滅殑銆侭ill Manning瀵筰n-addr鍩熺殑璋冩煡鍙戠幇錛屾湁95%鐨勫煙鍚嶆湇鍔″櫒(2鐨?000嬈℃柟涓湇鍔″櫒涓?浣跨敤鐨勬槸鍚勭鐗堟湰鐨?#8220;bind”銆傝繖鍏朵腑鍖呮嫭浜嗘墍鏈夌殑DNS鏍規湇鍔″櫒錛岃岃繖浜涙牴鏈嶅姟鍣ㄥ鏁翠釜鏈嶅姟鍣ㄧ殑姝e父榪愯漿璧風潃鑷沖叧閲嶈鐨勪綔鐢ㄣ傚浣曡兘鍔犲己紜繚 DNS 緋葷粺鐨勮繍浣滄甯革紝 鎴栬呭綋DNS緋葷粺鍦ㄩ伃鍙楃綉緇滄敾鍑繪椂鍊欙紝 鑳藉璁╃鐞嗚呭強鏃╁彂鐜版槸鏃ョ泭閲嶈鐨勭郴緇熷畨鍏ㄧ殑璇鵑銆傞鍏堟垜浠浜嗚ВDNS鏈嶅姟闈復鐨勫畨鍏ㄩ棶棰樸?/p> <p>浜屻丏NS鏈嶅姟闈復鐨勫畨鍏ㄩ棶棰橈細</p> <p>DNS鏈嶅姟闈復鐨勫畨鍏ㄩ棶棰樹富瑕佸寘鎷細DNS嬈洪獥錛圖NS Spoffing錛夈佹嫆緇濇湇鍔★紙Denial of service錛孌oS錛夋敾鍑匯佸垎甯冨紡鎷掔粷鏈嶅姟鏀誨嚮鍜岀紦鍐插尯婕忔礊婧㈠嚭鏀誨嚮錛圔uffer Overflow錛夈?/p> <p>1銆丏NS嬈洪獥</p> <p>DNS嬈洪獥鍗沖煙鍚嶄俊鎭楠楁槸鏈甯歌鐨凞NS瀹夊叏闂銆傚綋涓涓狣NS鏈嶅姟鍣ㄦ帀鍏ラ櫡闃憋紝浣跨敤浜嗘潵鑷竴涓伓鎰廌NS鏈嶅姟鍣ㄧ殑閿欒淇℃伅錛岄偅涔堣DNS鏈嶅姟鍣ㄥ氨琚楠椾簡銆侱NS嬈洪獥浼氫嬌閭d簺鏄撳彈鏀誨嚮鐨凞NS鏈嶅姟鍣ㄤ駭鐢熻澶氬畨鍏ㄩ棶棰橈紝渚嬪錛氬皢鐢ㄦ埛寮曞鍒伴敊璇殑浜掕仈緗戠珯鐐癸紝鎴栬呭彂閫佷竴涓數瀛愰偖浠跺埌涓涓湭緇忔巿鏉冪殑閭歡鏈嶅姟鍣ㄣ傜綉緇滄敾鍑昏呴氬父閫氳繃涓夌鏂規硶榪涜DNS嬈洪獥銆傚浘1鏄竴涓吀鍨嬬殑DNS嬈洪獥鐨勭ず鎰忓浘銆?/p> <p><img height=243 alt="" src="http://www.shnenglu.com/images/cppblog_com/alexhappy/1.jpg" width=400 border=0></p> <p>鍥? 鍏稿瀷DNS嬈洪獥榪囩▼</p> <p>錛?錛夌紦瀛樻劅鏌?/p> <p>榛戝浼氱啛緇冪殑浣跨敤DNS璇鋒眰錛屽皢鏁版嵁鏀懼叆涓涓病鏈夎闃茬殑DNS鏈嶅姟鍣ㄧ殑緙撳瓨褰撲腑銆傝繖浜涚紦瀛樹俊鎭細鍦ㄥ鎴瘋繘琛孌NS璁塊棶鏃惰繑鍥炵粰瀹㈡埛錛屼粠鑰屽皢瀹㈡埛寮曞鍒板叆渚佃呮墍璁劇疆鐨勮繍琛屾湪椹殑Web鏈嶅姟鍣ㄦ垨閭歡鏈嶅姟鍣ㄤ笂錛岀劧鍚庨粦瀹粠榪欎簺鏈嶅姟鍣ㄤ笂鑾峰彇鐢ㄦ埛淇℃伅銆?/p> <p>錛?錛塂NS淇℃伅鍔寔</p> <p>鍏ヤ鏡鑰呴氳繃鐩戝惉瀹㈡埛绔拰DNS鏈嶅姟鍣ㄧ殑瀵硅瘽錛岄氳繃鐚滄祴鏈嶅姟鍣ㄥ搷搴旂粰瀹㈡埛绔殑DNS鏌ヨID銆傛瘡涓狣NS鎶ユ枃鍖呮嫭涓涓浉鍏寵仈鐨?6浣岻D鍙鳳紝DNS鏈嶅姟鍣ㄦ牴鎹繖涓狪D鍙瘋幏鍙栬姹傛簮浣嶇疆銆傞粦瀹㈠湪DNS鏈嶅姟鍣ㄤ箣鍓嶅皢铏氬亣鐨勫搷搴斾氦緇欑敤鎴鳳紝浠庤屾楠楀鎴風鍘昏闂伓鎰忕殑緗戠珯銆?/p> <p>錛?錛塂NS澶嶄綅瀹氬悜</p> <p>鏀誨嚮鑰呰兘澶熷皢DNS鍚嶇О鏌ヨ澶嶄綅鍚戝埌鎭舵剰DNS鏈嶅姟鍣ㄣ傝繖鏍鋒敾鍑昏呭彲浠ヨ幏寰桪NS鏈嶅姟鍣ㄧ殑鍐欐潈闄愩?/p> <p>2銆佹嫆緇濇湇鍔℃敾鍑?/p> <p>榛戝涓昏鍒╃敤涓浜汥NS杞歡鐨勬紡媧烇紝濡傚湪BIND 9鐗堟湰錛堢増鏈?.2.0浠ュ墠鐨?9緋誨垪錛夊鏋滄湁浜哄悜榪愯BIND鐨勮澶囧彂閫佺壒瀹氱殑DNS鏁版嵁鍖呰姹傦紝BIND灝變細鑷姩鍏抽棴銆傛敾鍑昏呭彧鑳戒嬌BIND鍏抽棴錛岃屾棤娉曞湪鏈嶅姟鍣ㄤ笂鎵ц浠繪剰鍛戒護銆傚鏋滃緱涓嶅埌DNS鏈嶅姟錛岄偅涔堝氨浼氫駭鐢熶竴鍦虹伨闅撅細鐢變簬緗戝潃涓嶈兘瑙f瀽涓篒P鍦板潃錛岀敤鎴峰皢鏃犳柟璁塊棶浜掕仈緗戙傝繖鏍鳳紝DNS浜х敓鐨勯棶棰樺氨濂藉儚鏄簰鑱旂綉鏈韓鎵浜х敓鐨勯棶棰橈紝榪欏皢瀵艱嚧澶ч噺鐨勬販涔便?/p> <p>3銆佸垎甯冨紡鎷掔粷鏈嶅姟鏀誨嚮</p> <p>DDOS 鏀誨嚮閫氳繃浣跨敤鏀誨嚮鑰呮帶鍒剁殑鍑犲崄鍙版垨鍑犵櫨鍙拌綆楁満鏀誨嚮涓鍙頒富鏈猴紝浣垮緱鏈嶅姟鎷掔粷鏀誨嚮鏇撮毦浠ラ槻鑼冿細浣挎湇鍔℃嫆緇濇敾鍑繪洿闅句互閫氳繃闃誨鍗曚竴鏀誨嚮婧愪富鏈虹殑鏁版嵁嫻侊紝鏉ラ槻鑼冩湇鍔℃嫆緇濇敾鍑匯係yn Flood鏄拡瀵笵NS鏈嶅姟鍣ㄦ渶甯歌鐨勫垎甯冨紡鎷掔粷鏈嶅姟鏀誨嚮銆?/p> <p>4銆佺紦鍐插尯婕忔礊</p> <p>Bind杞歡鐨勭己鐪佽緗槸鍏佽涓繪満闂磋繘琛屽尯鍩熶紶杈擄紙zone transfer錛夈傚尯鍩熶紶杈撲富瑕佺敤浜庝富鍩熷悕鏈嶅姟鍣ㄤ笌杈呭煙鍚嶆湇鍔″櫒涔嬮棿鐨勬暟鎹悓姝ワ紝浣胯緟鍩熷悕鏈嶅姟鍣ㄥ彲浠ヤ粠涓誨煙鍚嶆湇鍔″櫒鑾峰緱鏂扮殑鏁版嵁淇℃伅銆備竴鏃﹁搗鐢ㄥ尯鍩熶紶杈撹屼笉鍋氫換浣曢檺鍒訛紝寰堝彲鑳戒細閫犳垚淇℃伅娉勬紡錛岄粦瀹㈠皢鍙互鑾峰緱鏁翠釜鎺堟潈鍖哄煙鍐呯殑鎵鏈変富鏈虹殑淇℃伅錛屽垽鏂富鏈哄姛鑳藉強瀹夊叏鎬э紝浠庝腑鍙戠幇鐩爣榪涜鏀誨嚮銆?/p> <p>搴斿浠ヤ笂榪欎簺瀹夊叏闂鏈変袱涓瘮杈冩湁鏁堟柟娉曪細TSIG鍜孌NSSEC鎶鏈?/p> <p>浜屻乀SIG鎶鏈?/p> <p>DNS鐨勪簨鍔$鍚嶅垎涓?TSIG (Transaction Signatures) 涓?SIG0 (SIGnature)涓ょ銆傝濡備綍閫夋嫨鍛? 棣栧厛錛岃鍏堝垽鏂鎴風涓庢湇鍔″櫒闂寸殑淇′換鍏崇郴涓轟綍錛岃嫢鏄彲淇′換鑰咃紝鍙夋嫨瀵圭О寮忕殑 TSIG銆俆SIG 鍙湁涓緇勫瘑鐮侊紝騫舵棤鍏紑/縐佸瘑閲戦挜涔嬪垎錛涜嫢鏄潪瀹屽叏淇′換鑰咃紝鍙夋嫨闈炲縐板紡閲戦挜鐨?SIG0錛岃櫧鏈夊叕寮/縐佸瘑閲戦挜涔嬪垎錛岀浉瀵圭殑錛岃瀹氫笂涔熻緝澶嶆潅銆傝嚦浜庤閫夌敤鍝杈冮傚悎錛屽氨鐢辮嚜宸辨潵鍒ゆ柇銆傞氬父鍖哄甫浼犺緭鏄富鍩熷悕鏈嶅姟鍣ㄥ埌杈呭姪鍩熷悕鏈嶅姟鍣ㄣ傞氬父鍦ㄤ富鍩熷悕鏈嶅姟鍣ㄩ厤緗枃浠?etc/named.conf鐨刣ns-ip-list鐨勮闂帶鍒跺垪琛紙ACL錛宎ccess control list錛変細鍒楀嚭涓浜汭P鍦板潃錛屽畠浠彧鑳戒負涓誨煙榪涜浼犺緭鍖哄甫淇℃伅銆備竴涓吀鍨嬩緥瀛愬涓嬶細<br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>acl “dns-ip-list” { <br>172.20.15.100; <br>172.20.15.123; <br>}; <br>zone “yourdomain.com” { <br>type master; <br>file “mydomain.dns”; <br>allow-query { any; }; <br>allow-update { none; }; <br>allow-transfer { dns-ip-list; }; };</p> <p> </p> <p>閮芥槸榛戝浼氬埄鐢↖P嬈洪獥涓涓狣NS鏈嶅姟鍣紝榪嬌鍏惰繘琛岄潪娉曞尯甯︿紶杈撱俆SIG鎶鏈彲浠ヨ繘琛屾湁鏁堥槻鑼冦?br> <br>1銆乀SIG鎶鏈?/p> <p>浜ゆ槗絳劇珷 (TSIGRFC 2845)錛屾槸涓轟簡淇濇姢 DNS瀹夊叏鑰屽彂灞曠殑銆備粠BIND 8.2鐗堟湰寮濮嬪紩鍏?TSIG 鏈哄埗錛屽叾楠岃瘉 DNS 璁伅鏂瑰紡鏄嬌鐢ㄥ叡浜噾閽?Secret Key) 鍙婂崟鍚戞潅鍑戝嚱寮?One-way hash function) 鏉ユ彁渚涜鎭殑楠岃瘉鍜屾暟鎹殑瀹屾暣鎬с備富瑕侀拡瀵瑰尯甯︿紶杈擄紙ZONE Transfer錛夎繘琛屼繚鎶ょ殑浣滅敤錛屽埄鐢ㄥ瘑鐮佸緙栫爜鏂瑰紡涓洪氳浼犺緭淇℃伅鍔犲瘑浠ヤ繚璇?DNS 璁伅鐨勫畨鍏紝鐗瑰埆鏄搷搴斾笌鏇存柊鐨勮鎭暟鎹備篃灝辨槸璇村湪DNS鏈嶅姟鍣ㄤ箣闂磋繘琛岃緰鍖轟紶閫佹椂鎵鎻愪緵淇濇姢鐨勬満鍒訛紝浠ョ‘淇濅紶杈撴暟鎹笉琚獌鍙栧強鐩戝惉銆備笅闈互BIND 9.21涓轟緥錛?/p> <p>棣栧厛鍦ㄥ紑濮嬭緗紝蹇呴』涓轟富鍩熷悕鏈嶅姟鍣紙master DNS錛夊拰杈呭姪鍩熷悕錛?slave DNS錛?榪涜鏃墮棿鍚屾錛屽惁鍒欎細閫犳垚鍖哄甫浼犺緭鐨勫け璐ャ傚彲浠ヤ嬌鐢╪tp鎴栬卹date宸ュ叿榪涜鏈嶅姟鍣ㄦ椂闂村悓姝ャ?/p> <p>鍋囪瑕侀檺鍒秠ourdomain.com鐨勪富鍩熷埌IP鍦板潃鍒嗗埆鏄?72.20.15.100 (ns1.yourdomain. com) 鍜?172.20.15.123 (ns2.yourdomain.com). 鐨勪袱涓緟鍔╁煙鍚嶆湇鍔″櫒涔嬮棿榪涜鍖哄甫浼犺緭銆傚湪姝ゅ皢璇﹁堪 TSIG 鐨勫疄闄呮搷浣滐紝鍙互闃叉DNS鏈嶅姟鍣ㄥ拰榛戝鐨凞NS鏈嶅姟鍣ㄤ箣闂翠笉浼氬彂鐢烮P嬈洪獥銆?/p> <p>姝ラ涓錛氭墽琛?dnssec-keygen function 浜х敓鍔犲瘑閲戦挜錛屼竴涓負 public key 鏂囦歡錛屽彟涓涓負 private key 鏂囦歡錛?/p> <p>浜х敓鍔犲瘑閲戦挜錛?/p> <p>dnssec-keygen -a hmac-md5 -b 128 -n HOST zone-xfr-key</p> <p>璇ユ枃浠朵腑鍏紑閲戦挜錛坧ublic key錛夋槸錛?Kzone-xfr-key.+157+08825.key錛涚鏈夐噾閽ワ紙private key錛夋槸Kzone-xfr-key.+157+08825.private銆傛鏃舵煡鐪嬫枃浠墮氬父鍖呮嫭浠ヤ笅鍐呭錛?br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>Private-key-format: v1.2 <br>Algorithm: 157 (HMAC_MD5) <br>Key: YH8Onz5x0/twQnvYPyh1qg==</p> <p><br>姝ラ浜岋細浣跨敤TSIG 閲戦挜鍦ㄤ富鍩熷悕鏈嶅姟鍣ㄥ拰杈呭姪鍩熷悕鏈嶅姟鍣ㄧ殑璁劇疆鏂囦歡named.conf璁懼畾錛?br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>key zone-xfr-key { <br>algorithm hmac-md5; <br>secret “YH8Onz5x0/twQnvYPyh1qg==”; <br>};</p> <p> </p> <p>姝ラ涓夛細灝嗕笅闈㈢殑澹版槑鍔犲叆鏈嶅姟鍣╪s1.yourdomain.com鐨勮緗枃浠?etc/named.conf涓細<br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>server 172.20.15.123 { <br>keys { zone-xfr-key; }; <br>};</p> <p><br>姝ラ鍥涳細灝嗕笅闈㈢殑澹版槑鍔犲叆鏈嶅姟鍣╪s2.yourdomain.com鐨勮緗枃浠?etc/named.conf涓細<br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>server 172.20.15.100 { <br>keys { zone-xfr-key; }; <br>};</p> <p> </p> <p>姝ラ浜旓細涓轟富鍩熷悕鏈嶅姟鍣╪s1.yourdomain.com鐨剏ourdomain.com鍖哄甫鐨勮緗枃浠?etc/named.conf鍐欏叆浠ヤ笅閰嶇疆錛?br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>acl “dns-ip-list” { <br>172.20.15.100; <br>172.20.15.123; <br>}; <br>key zone-xfr-key { <br>algorithm hmac-md5; <br>secret “YH8Onz5x0/twQnvYPyh1qg==”; <br>}; <br>server 172.20.15.123 { <br>keys { zone-xfr-key; }; <br>}; <br>zone “yourdomain.com” { <br>type master; <br>file “mydomain.dns”; <br>allow-query { any; }; <br>allow-update { none; }; <br>allow-transfer { dns-ip-list; }; <br>};</p> <p><br>姝ラ鍏細涓鴻緟鍔╁煙鍚嶆湇鍔″櫒ns2.yourdomain.com鐨剏ourdomain.com鍖哄甫鐨勮緗枃浠?etc/named.conf鍐欏叆浠ヤ笅閰嶇疆錛?br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>acl “dns-ip-list” { <br>172.20.15.100; <br>172.20.15.123; <br>}; <br>key zone-xfr-key { <br>algorithm hmac-md5; <br>secret “YH8Onz5x0/twQnvYPyh1qg==”; <br>}; <br>server 172.20.15.100 { <br>keys { zone-xfr-key; }; <br>}; <br>zone “yourdomain.com” { <br>type master; <br>file “mydomain.dns”; <br>allow-query { any; }; <br>allow-update { none; }; <br>allow-transfer { dns-ip-list; }; <br>};</p> <p> </p> <p>姝ラ涓冿細鍐嶆閲嶆柊鍚姩涓誨煙鍚嶆湇鍔″櫒鍜岃緟鍔╁煙鍚嶆湇鍔″櫒銆?/p> <p>璇存槑涓虹‘淇濆畨鍏ㄦх殑闂錛孴SIG 鍙‘璁?DNS 涔嬩俊鎭槸鐢辨煇鐗瑰畾 DNS Server 鎵鎻愪緵銆傞氬父TSIG 搴旂敤浜庡煙鍚嶆湇鍔″櫒闂寸殑鍖哄甫浼犺緭錛岀‘淇濇暟鎹笉浼氳綃℃敼鎴栦駭鐢?dns spoofing銆?/p> <p>姝ラ鍏細</p> <p>楠岃瘉TSIG鎶鏈槸鍚︾敓鏁堬紝姝ラ濡備笅錛?/p> <p>鍒犻櫎杈呭姪鍩熷悕鏈嶅姟鍣?ns2.yourdomain.com)鐨勫尯甯︽枃浠躲?/p> <p>閲嶆柊鍚姩杈呭姪鍩熷悕鏈嶅姟鍣ㄣ?/p> <p>媯鏌ヨ緟鍔╁煙鍚嶆湇鍔″櫒鐨勫尯甯︽枃浠舵槸鍚﹁嚜鍔ㄥ緩绔嬨傝緟鍔╁煙鍚嶆湇鍔″櫒鐢ㄦ潵浠庝富鏈嶅姟鍣ㄤ腑杞Щ涓鏁村鍩熶俊鎭傚尯甯︽枃浠舵槸浠庝富鏈嶅姟鍣ㄨ漿縐誨嚭鐨勶紝浣滀負紓佺洏鏂囦歡淇濆瓨鍦ㄨ緟鍔╁煙鍚嶆湇鍔″櫒涓?/p> <p>娉ㄦ剰浜嬮」錛氬鏋滀負鍩熷悕鏈嶅姟鍣ㄩ厤緗簡TSIG錛岄偅涔堣紜繚鏅氱敤鎴蜂笉鑳芥帴瑙︿富鍩熷悕鏈嶅姟鍣ㄥ拰杈呭姪鍩熷悕鏈嶅姟鍣ㄧ殑閰嶇疆鏂囦歡/etc/named.conf銆傚彟澶栦篃涓嶈兘淇敼涓ゅ彴鏈嶅姟鍣ㄧ殑鍏變韓鐨凾SIG瀵嗛挜銆?/p> <p>2銆丼IG0 鎶鏈畝浠?/p> <p>SIG0鏄竴涔濅節涔濆勾涓夋湀 鐢?IBM鍏徃鐨凞. Eastlake 鎻愬嚭鎴愪負鏍囧噯銆傚叾鏄埄鐢ㄥ叕寮閲戦挜鏈哄埗涓鴻緰鍖鴻祫鏂欒繘琛屾暟瀛楃绔犵殑鍔ㄤ綔錛屼互淇濊瘉姣忕瑪浼犺緭鐨?source record 鍏鋒湁鍙獙璇佹т笌涓嶅彲鍚﹁鎬с傚疄闄呬笂 SIG0 鎵嶆槸闃叉 DNS Spoofing 鍙戠敓鏈涓昏鐨勬妧鏈紝SIG0 鏄嬌鐢ㄥ叕寮閲戦挜鍔犲瘑娉曪紝璁╄緰鍖虹鐞嗚呬負鍏惰緰鍖烘暟鎹姞涓婃暟瀛楃绔狅紝鐢辨璇佹槑杈栧尯璧勬枡鐨勫彲淇¤禆鎬с傞櫎姝や箣澶栵紝SIG0 淇濇湁鏄惁閫夋嫨璁よ瘉鏈哄埗鐨勫脊鎬э紝浠ュ強鍙伒媧誨湴閰嶅悎鑷鐨勫畨鍏ㄦ満鍒躲?/p> <p>涓夈丏NSSEC鎶鏈?/p> <p>DNS嬈洪獥鏄鐩墠緗戠粶搴旂敤錛屾渶澶х殑鍐插嚮鍦ㄤ簬鍐掑悕鑰呭熺潃鎻愪緵鍋囩殑緗戝煙鍚嶇О涓庣綉鍧鐨勫鐓т俊鎭紝鍙互灝嗕笉鐭ユ儏鐢ㄦ埛鐨勭綉欏佃仈鏈猴紝瀵煎紩鍒伴敊璇殑緗戠珯錛屽師鏈睘浜庣敤鎴風殑鐢靛瓙閭歡涔熷彲鑳藉洜鑰岄仐澶憋紝鐢氳岃繘涓姝ョ┖寮鎴愪負闃繪柇鏈嶅姟鐨勬敾鍑匯傛墍騫革紝鐩墠杈冩柊鐨?BIND 鐗堟湰錛岄拡瀵硅繖涓綾婚棶棰橈紝宸茬粡鏈夊姞鍏ヨ澶氭敼榪涚殑鏂規硶錛屼笉榪囩湡姝g殑瑙e喅鏂規錛屽垯鏈夎禆灝佸寘璁よ瘉鏈哄埗鐨勫緩绔嬩笌鎺ㄥ姩銆侱NSSEC灝辨槸璇曞浘瑙e喅榪欎竴綾婚棶棰樼殑鍏ㄦ柊鏈哄埗錛?BIND9 宸茬粡瀹屾暣鍔犱互璁捐騫跺畬鎴愩侱NSSEC寮曞叆涓や釜鍏ㄦ柊鐨勮祫婧愯褰曠被鍨嬶細KEY鍜孲IG錛屽厑璁稿鎴風鍜屽煙鍚嶆湇鍔″櫒瀵逛換浣旸NS鏁版嵁鐨勬潵婧愯繘琛屽瘑鐮侀獙璇併?/p> <p>DNSSEC涓昏渚濋潬鍏挜鎶鏈浜庡寘鍚湪DNS涓殑淇℃伅鍒涘緩瀵嗙爜絳懼悕銆傚瘑鐮佺鍚嶉氳繃璁$畻鍑轟竴涓瘑鐮乭ash鏁版潵鎻愪緵DNS涓暟鎹殑瀹屾暣鎬э紝騫跺皢璇ash 鏁板皝瑁呰繘琛屼繚鎶ゃ傜/鍏挜瀵逛腑鐨勭閽ョ敤鏉ュ皝瑁卙ash鏁幫紝鐒跺悗鍙互鐢ㄥ叕閽ユ妸hash鏁拌瘧鍑烘潵銆傚鏋滆繖涓瘧鍑虹殑hash鍊煎尮閰嶆帴鏀惰呭垰鍒氳綆楀嚭鏉ョ殑hash鏍戯紝閭d箞琛ㄦ槑鏁版嵁鏄畬鏁寸殑銆備笉綆¤瘧鍑烘潵鐨刪ash鏁板拰璁$畻鍑烘潵鐨刪ash鏁版槸鍚﹀尮閰嶏紝瀵逛簬瀵嗙爜絳懼悕榪欑璁よ瘉鏂瑰紡閮芥槸緇濆姝g‘鐨勶紝鍥犱負鍏挜浠呬粎鐢ㄤ簬瑙e瘑鍚堟硶鐨刪ash鏁幫紝鎵浠ュ彧鏈夋嫢鏈夌閽ョ殑鎷ユ湁鑰呭彲浠ュ姞瀵嗚繖浜涗俊鎭備笅闈㈡垜浠湅鐪嬪浣曚負鍚嶇О鏄痙omain.com鐨勫煙寤虹珛DESSEC閰嶇疆銆?/p> <p>姝ラ涓錛氫負 domain.com 鍩熷緩绔嬩竴瀵瑰瘑閽ャ傚湪 /var/named 鐩綍涓嬶紝浣跨敤鍛戒護錛?“/usr/local/sbin/dnssec-keygen -a DSA -b 768 -n ZONE domain.com” 榪欎釜鍛戒護浜х敓涓瀵歸暱搴?68浣岲SA綆楁硶鐨勭鏈夊瘑閽ワ紙Kdomain.com.+003+29462.private錛夊拰鍏叡瀵嗛挜錛圞domain.com.+003+29462.key錛夈傚叾涓?9462縐頒綔瀵嗛挜鏍囩錛?key tag錛夈?</p> <p>姝ラ浜岋細浣跨敤鍛戒護錛?#8220; /usr/local/sbin/dnssec-makekeyset -t 3600 -e now+30 Kdomain.com.+003+29462“寤虹珛涓涓瘑閽ラ泦鍚堛傝鍛戒護浠?錛?00 seconds 鐨勭敓瀛樻椂闂達紙time-to-live錛夊緩绔嬪瘑閽ラ泦鍚堬紝鏈夋晥鏈熼檺涓夊崄澶╋紝騫朵笖鍒涘緩涓涓枃浠訛細domain.com.keyset銆?/p> <p>姝ラ涓夛細浣跨敤鍛戒護“ /usr/local/sbin/dnssec-signkey domain.com.keyset Kdomain.com.+003+29462 “涓哄瘑閽ラ泦鍚堢瀛椼傜劧鍚庡緩绔嬩竴涓瀛楁枃浠訛細domain.com.signedkey銆?/p> <p>姝ラ鍥涳細浣跨敤鍛戒護 “/usr/local/sbin/dnssec-signzone -o domain.com domain.db command錛?where domain.db ”涓哄尯甯︽枃浠剁瀛椼傜劧鍚庡緩绔嬩竴涓瀛楁枃浠訛細 domain.db.signed銆?/p> <p>姝ラ浜旓細鏇挎崲 閰嶇疆鏂囦歡/etc/named.conf涓?domain.com鐨勫尯甯︽枃浠墮儴鍒嗐傛竻鍗曞涓嬶細<br>浠ヤ笅涓哄紩鐢ㄧ殑鍐呭錛?br>zone “domain.com” IN { <br>type master; <br>file “domain.db.signed”; <br>allow-update { none; }; }; </p> <p><br>浠庝笂闈㈢殑閰嶇疆榪囩▼鎴戜滑涔熺湅鍒癉NSSEC鐨勪竴浜涚己鐐癸細</p> <p>闄や簡閰嶇疆璐熻矗錛岃繕鏈夋爣璁板拰鏍¢獙DNS鏁版嵁鏄劇劧浼氫駭鐢熼澶栫殑寮閿錛屼粠鑰屽獎鍝嶇綉緇滃拰鏈嶅姟鍣ㄧ殑鎬ц兘銆傜鍚嶇殑鏁版嵁閲忓緢澶э紝榪欏氨鍔犻噸浜嗗煙鍚嶆湇鍔″櫒瀵逛簰鑱旂綉楠ㄥ共浠ュ強涓浜涢潪楠ㄥ共榪炴帴鐨勮礋鎷呫備駭鐢熷拰鏍¢獙絳懼悕涔熷崰鐢ㄤ簡寰堝涓ぎ澶勭悊鍣ㄧ殑鏃墮棿銆傛湁鏃跺欙紝涓嶅緱涓嶆妸鍗曞鐞嗗櫒鐨凞NS鏈嶅姟鍣ㄦ崲鎴愬澶勭悊鍣ㄧ殑DNSSEC鏈嶅姟鍣ㄣ傜鍚嶅拰瀵嗛挜鍗犵敤鐨勭鐩樼┖闂村拰RAM瀹歸噺杈懼埌瀹冧滑琛ㄧず鐨勬暟鎹墍鍗犲閲忕殑10鍊嶃傚悓鏃舵暟鎹簱鍜岀鐞嗙郴緇熶篃涓嶅緱涓嶈繘琛岀浉搴旂殑鍗囩駭鍜屾墿瀹廣?/p> <p>鎬葷粨錛氬煙鍚嶇郴緇熺殑閰嶇疆鍜岀鐞嗘槸涓欏規瘮杈冨鏉傚拰綣佺悙鐨勭郴緇熺鐞嗕換鍔★紝瀹冨鏁翠釜緗戠粶鐨勮繍琛屽獎鍝嶆瀬澶с備負浜嗕繚璇丏NS鏈嶅姟鍣ㄧ殑瀹夊叏榪愯錛屼笉浠呰浣跨敤鍙潬鐨勬湇鍔″櫒杞歡鐗堟湰錛岃屼笖瑕佸DNS鏈嶅姟鍣ㄨ繘琛屽畨鍏ㄩ厤緗紝鏈枃浠嬬粛浜員ISG鍜孌NSSEC鎶鏈湁鍔╀簬鍑忓皯 DNS Spoofing 鏀誨嚮鐨勫彂鐢燂紝澧炶繘緗戠粶浣跨敤鑰呭鍥犵壒緗戜嬌鐢ㄧ殑淇′換錛屾潨緇濅俊鎭郴緇熼伃鍙楀叆渚典笌鏀誨嚮鐨勪駭鐢熴?/p> <img src ="http://www.shnenglu.com/alexhappy/aggbug/86748.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.shnenglu.com/alexhappy/" target="_blank">alexhappy</a> 2009-06-04 14:15 <a href="http://www.shnenglu.com/alexhappy/articles/86748.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item></channel></rss> <footer> <div class="friendship-link"> <p>感谢您访问我们的网站,您可能还对以下资源感兴趣:</p> <a href="http://www.shnenglu.com/" title="精品视频久久久久">精品视频久久久久</a> <div class="friend-links"> </div> </div> </footer> <a href="http://www.m-xc.cn" target="_blank">久久SE精品一区二区</a>| <a href="http://www.s5wow.cn" target="_blank">亚洲综合久久夜AV </a>| <a href="http://www.dongfangmoney.cn" target="_blank">日日躁夜夜躁狠狠久久AV</a>| <a href="http://www.czyhfzc.cn" target="_blank">国产成人无码久久久精品一</a>| <a href="http://www.yxwelding.com.cn" target="_blank">国产一久久香蕉国产线看观看</a>| <a href="http://www.kkfo.cn" target="_blank">亚洲伊人久久综合影院</a>| <a href="http://www.pgos.com.cn" target="_blank">久久久久久曰本AV免费免费</a>| <a href="http://www.lmgv.cn" target="_blank">精品久久久久久亚洲</a>| <a href="http://www.qianhongg.cn" target="_blank">欧洲国产伦久久久久久久</a>| <a href="http://www.m13213.cn" target="_blank">色噜噜狠狠先锋影音久久</a>| <a href="http://www.hx85.cn" target="_blank">久久A级毛片免费观看</a>| <a href="http://www.buzzbee.com.cn" target="_blank">亚洲中文字幕无码久久2020</a>| <a href="http://www.waygoing.com.cn" target="_blank">欧美日韩中文字幕久久久不卡</a>| <a href="http://www.dlygbx.cn" target="_blank">精品熟女少妇AV免费久久 </a>| <a href="http://www.jiangkangcmw.cn" target="_blank">久久WWW免费人成—看片</a>| <a href="http://www.fragrancebeads.cn" target="_blank">99精品国产99久久久久久97</a>| <a href="http://www.zx444.cn" target="_blank">久久精品国产99国产精偷</a>| <a href="http://www.zsputian.com.cn" target="_blank">久久免费看黄a级毛片</a>| <a href="http://www.xiezongjun.cn" target="_blank">99久久精品国产综合一区 </a>| <a href="http://www.robuts.com.cn" target="_blank">久久天天躁狠狠躁夜夜网站 </a>| <a href="http://www.airesou.cn" target="_blank">国产一区二区三精品久久久无广告 </a>| <a href="http://www.zhzzbjb.cn" target="_blank">人人狠狠综合久久亚洲88</a>| <a href="http://www.jrtz112.cn" target="_blank">久久成人国产精品免费软件</a>| <a href="http://www.xsq1.cn" target="_blank">中文字幕亚洲综合久久2</a>| <a href="http://www.yushiji505.cn" target="_blank">久久久女人与动物群交毛片</a>| <a href="http://www.ujpy.cn" target="_blank">亚洲Av无码国产情品久久</a>| <a href="http://www.530taiji.cn" target="_blank">久久国产视频99电影</a>| <a href="http://www.usgold.cn" target="_blank">久久亚洲高清综合</a>| <a href="http://www.baikuu.cn" target="_blank">久久人人爽人人爽人人av东京热</a>| <a href="http://www.51maicha.cn" target="_blank">伊人久久大香线蕉影院95</a>| <a href="http://www.sztaoren.cn" target="_blank">精品久久久久久亚洲</a>| <a href="http://www.www5303.cn" target="_blank">99久久99久久久精品齐齐</a>| <a href="http://www.atlasbl.cn" target="_blank">精品国产青草久久久久福利</a>| <a href="http://www.cctt88.cn" target="_blank">久久久久久久尹人综合网亚洲</a>| <a href="http://www.hwaq.cn" target="_blank">国内精品久久久久久久97牛牛</a>| <a href="http://www.yunshujia.cn" target="_blank">亚洲va久久久噜噜噜久久</a>| <a href="http://www.xcfsfl.cn" target="_blank">久久久国产精品福利免费</a>| <a href="http://www.royfq.cn" target="_blank">久久最新精品国产</a>| <a href="http://www.yejw.cn" target="_blank">国产99久久久久久免费看</a>| <a href="http://www.97youbei.cn" target="_blank">久久综合视频网</a>| <a href="http://www.27cv.cn" target="_blank">久久电影网一区</a>| <script> (function(){ var bp = document.createElement('script'); var curProtocol = window.location.protocol.split(':')[0]; if (curProtocol === 'https') { bp.src = 'https://zz.bdstatic.com/linksubmit/push.js'; } else { bp.src = 'http://push.zhanzhang.baidu.com/push.js'; } var s = document.getElementsByTagName("script")[0]; s.parentNode.insertBefore(bp, s); })(); </script> </body>