[Splunk] LDAP ์—ฐ๋™ ์ดํ•ดํ•˜๊ธฐ
๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

Splunk

[Splunk] LDAP ์—ฐ๋™ ์ดํ•ดํ•˜๊ธฐ

728x90
๋ฐ˜์‘ํ˜•

๐ŸŒณ LDAP ๊ธฐ๋ณธ ๊ตฌ์กฐ

LDAP(Lightweight Directory Access Protocol)์€ ๋ง ๊ทธ๋Œ€๋กœ ๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋น„์Šค์— ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•œ ํ”„๋กœํ† ์ฝœ์ด๋‹ค.

  • ๋””๋ ‰ํ„ฐ๋ฆฌ(Directory):
    ์กฐ์ง์˜ ์‚ฌ์šฉ์ž, ๊ทธ๋ฃน, ์ž์› ์ •๋ณด๋ฅผ ํŠธ๋ฆฌ ๊ตฌ์กฐ๋กœ ์ €์žฅํ•˜๋Š” ๋ฐ์ดํ„ฐ ์ €์žฅ์†Œ
  • ๋Œ€ํ‘œ ๊ตฌํ˜„์ฒด:
    • OpenLDAP (์˜คํ”ˆ์†Œ์Šค)
    • Microsoft Active Directory (๊ฐ€์žฅ ํ”ํ•˜๊ฒŒ ์‚ฌ์šฉ๋จ)

 

๐Ÿงฉ ํŠธ๋ฆฌ ๊ตฌ์กฐ ์˜ˆ์‹œ

 
 
dc=splunk,dc=com
 โ”œโ”€ ou=groups
 โ”‚   โ”œโ”€ cn=admins
 โ”‚   โ”œโ”€ cn=powerusers
 โ”‚   โ””โ”€ cn=users
 โ””โ”€ ou=people
     โ”œโ”€ cn=admin1
     โ”œโ”€ cn=power1
     โ””โ”€ cn=user1
 
  • DC (Domain Component): ๋„๋ฉ”์ธ ์ด๋ฆ„ (์˜ˆ: dc=splunk,dc=com)
  • OU (Organizational Unit): ์กฐ์ง ๋‹จ์œ„ ์ปจํ…Œ์ด๋„ˆ (์˜ˆ: ou=people)
  • CN (Common Name): ์‹ค์ œ ์‚ฌ์šฉ์ž๋‚˜ ๊ทธ๋ฃน ์ด๋ฆ„ (์˜ˆ: cn=user1)
  • DN (Distinguished Name): ํŠธ๋ฆฌ ์•ˆ์—์„œ์˜ ๊ณ ์œ  ์‹๋ณ„์ž
    • ์˜ˆ: cn=user1,ou=people,dc=splunk,dc=com

๐Ÿ‘‰ DN์„ ์˜ค๋ฅธ์ชฝ์—์„œ ์™ผ์ชฝ์œผ๋กœ ์ฝ์œผ๋ฉด, ํ•ด๋‹น ์‚ฌ์šฉ์ž๊ฐ€ ์–ด๋–ค ํŠธ๋ฆฌ์— ์†ํ•ด ์žˆ๋Š”์ง€ ํ•œ๋ˆˆ์— ์•Œ ์ˆ˜ ์žˆ์Œ


๐Ÿ” LDAP ์ธ์ฆ ์ ˆ์ฐจ (2๋‹จ๊ณ„ ๋ฐ”์ธ๋”ฉ)

Splunk๊ฐ€ LDAP์„ ํ†ตํ•ด ์ธ์ฆ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ณผ์ •์€ ์กฐ๊ธˆ ํŠน๋ณ„ํ•จ.

  1. ์‚ฌ์šฉ์ž๊ฐ€ Splunk Web ๋กœ๊ทธ์ธ ์‹œ๋„ (์•„์ด๋””/๋น„๋ฐ€๋ฒˆํ˜ธ ์ž…๋ ฅ)
  2. Splunk๊ฐ€ Bind DN ๊ณ„์ •์œผ๋กœ LDAP ์„œ๋ฒ„์— ๋จผ์ € ์—ฐ๊ฒฐ
  3. LDAP ์„œ๋ฒ„์—์„œ User Base DN ์•„๋ž˜์—์„œ ์‚ฌ์šฉ์ž์˜ DN ๊ฒ€์ƒ‰
  4. ์ฐพ์€ DN๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ๋‹ค์‹œ LDAP ์„œ๋ฒ„์— ๋ฐ”์ธ๋”ฉ
  5. ์„ฑ๊ณตํ•˜๋ฉด Splunk์— ๋กœ๊ทธ์ธ ์™„๋ฃŒ

๐Ÿ‘‰ ์ฆ‰, LDAP ์ธ์ฆ์€ ๋‹จ์ˆœํžˆ “ํ•œ ๋ฒˆ ๋น„๋ฐ€๋ฒˆํ˜ธ ํ™•์ธ”์ด ์•„๋‹ˆ๋ผ ๋‘ ๋‹จ๊ณ„ ๋ฐ”์ธ๋”ฉ ๊ณผ์ •์„ ๊ฑฐ์นจ


๐ŸŽญ LDAP ๊ถŒํ•œ ๋ถ€์—ฌ (Authorization)

LDAP์€ ์ธ์ฆ๋งŒ ์ฒ˜๋ฆฌ
์‹ค์ œ ๊ถŒํ•œ ๋ถ€์—ฌ๋Š” Splunk์—์„œ ๊ทธ๋ฃน(Group)๊ณผ ์—ญํ• (Role)์„ ๋งคํ•‘ํ•ด์•ผ ํ•จ.

  • ์‚ฌ์šฉ์ž๊ฐ€ ์†ํ•œ LDAP ๊ทธ๋ฃน ํ™•์ธ
  • Splunk๊ฐ€ ํ•ด๋‹น ๊ทธ๋ฃน๊ณผ ๋งคํ•‘๋œ Role์„ ๋ถ€์—ฌ
  • Role์— ๋”ฐ๋ผ ๊ฒ€์ƒ‰, ๋Œ€์‹œ๋ณด๋“œ ์ ‘๊ทผ ๊ถŒํ•œ ๊ฒฐ์ •

๐Ÿ‘‰ ํ•ต์‹ฌ! Splunk Role ์—†์ด๋Š” ๋กœ๊ทธ์ธํ•ด๋„ ์•„๋ฌด๊ฒƒ๋„ ํ•  ์ˆ˜ ์—†๋‹ค


โš–๏ธ LDAP ์šฐ์„ ์ˆœ์œ„ (Precedence)

  • Splunk๋Š” ์—ฌ๋Ÿฌ LDAP ์„œ๋ฒ„๋ฅผ ๋™์‹œ์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Œ
  • ํ•˜์ง€๋งŒ ์‚ฌ์šฉ์ž๋ฅผ ์ฒซ ๋ฒˆ์งธ๋กœ ์ฐพ์€ ์„œ๋ฒ„์—์„œ ๊ฒ€์ƒ‰ ์ข…๋ฃŒ
  • ์ˆœ์„œ๋Š” authentication.conf ์„ค์ •๊ฐ’์œผ๋กœ ์กฐ์ • ๊ฐ€๋Šฅ
  • ์ค‘์š”: ๋‚ด๋ถ€ Splunk ๊ณ„์ •์ด LDAP ๊ณ„์ •๋ณด๋‹ค ํ•ญ์ƒ ์šฐ์„ 

๐Ÿ‘‰ ์ด ๋ถ€๋ถ„์€ ํ˜„์—…์—์„œ ํ”ํžˆ ๋ฌธ์ œ๋ฅผ ์ผ์œผํ‚ฌ ์ˆ˜ ์žˆ์Œ...
์˜ˆ๋ฅผ ๋“ค์–ด, LDAP์—๋„ admin ๊ณ„์ •์ด ์žˆ์ง€๋งŒ Splunk ๋‚ด๋ถ€์—๋„ admin ๊ณ„์ •์ด ์žˆ๋‹ค๋ฉด

๋ฌด์กฐ๊ฑด Splunk ๊ณ„์ •์ด ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.


๐Ÿ›  LDAP ๋„๊ตฌ ํ™œ์šฉ

LDAP ์†์„ฑ์„ ์ œ๋Œ€๋กœ ์ดํ•ดํ•˜๋ ค๋ฉด ๋„๊ตฌ๋ฅผ ํ™œ์šฉํ•˜๋Š” ๊ฒŒ ํ•„์ˆ˜

  • GUI ๋„๊ตฌ:
    • Apache Directory Studio
    • Softerra LDAP Browser
    • ADSI Edit (Windows)
  • CLI ๋„๊ตฌ:
    • ldapsearch
    • ์˜ˆ์‹œ:
ldapsearch -x -b "dc=splunk,dc=com" "(uid=user1)"

 

  • LDIF (LDAP Data Interchange Format):
    • LDAP ์—”ํŠธ๋ฆฌ๋ฅผ ํ…์ŠคํŠธ ํŒŒ์ผ๋กœ export
    • ๊ทธ๋ฃน/์‚ฌ์šฉ์ž ์†์„ฑ์„ ํ™•์ธํ•  ๋•Œ ์œ ์šฉ

 

  • User Base DN
  • Group Base DN
  • uid (๋กœ๊ทธ์ธ ์•„์ด๋””)
  • mail (์ด๋ฉ”์ผ)
  • dn (๊ทธ๋ฃน ๋งคํ•‘ ์†์„ฑ)

 

728x90
๋ฐ˜์‘ํ˜•