大家论坛-大家学习网论坛计算机专区Linux论坛Linux高级应用 → LinuxCBT Security Edition之 LinuxCBT PAM Edition

意见反馈-google提供的广告

  共有1930人关注过本帖树形打印

主题:LinuxCBT Security Edition之 LinuxCBT PAM Edition

帅哥哟,离线,有人找我吗?
leapApple
  1楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网高中一年级 贴子:607 金钱:2409 金币:0 积分:359 魅力:250 精华:14 注册:2007-10-11 10:21:00
LinuxCBT Security Edition之 LinuxCBT PAM Edition  发贴心情 Post By:2008-6-24 16:08:00

LinuxCBT Security Edition - LinuxCBT PAM Edition


图片点击可在新窗口打开查看此主题相关图片如下linuxcbt_security_edition_c.jpg:
图片点击可在新窗口打开查看

建议大家使用下载工具下载,这个是bin文件类型的虚拟光盘文件。
[replyview]LinuxCBT.PAM.Edition[www.TopSage.com].bin[/replyview]

LinuxCBT PAM Edition encompasses: 1. Pluggable Authentication Modules (PAM) Security.


LinuxCBT PAM Edition entails 6-hours, or ~1-day of classroom training. LinuxCBT PAM Edition prepares you or your organization for successfully securing GNU/Linux & Open Source-based solutions.


图片点击可在新窗口打开查看此主题相关图片如下pam.png:
图片点击可在新窗口打开查看

PAM Security - Module 1

  • Introduction - Topology - Features
    • Discuss course outline
    • Explore system configuration
    • Explore network topology
    • Identify primary PAM systems
    • Enumerate and discuss key PAM features

  • PAM Rules Files & Syntax
    • Identify key PAM configuration files
    • Explain the purpose of the /etc/pam.d/other PAM rules file
    • Discuss PAM's 4 management tasks
    • Identify the 4 tokens supported within PAM rules files
    • Explain possible values for the 4 supported rules file tokens
    • Discuss PAM's stacking of rules for the 4 management tasks
    • Examine the /etc/pam.d/sshd PAM rules file for the SSHD service/daemon
    • Explore the contents of included PAM rules files

  • Common PAMs - Identify & Discuss Commonly Implemented PAMs
    • Explain the purpose and implementation of pam_echo
    • Test pam_echo using SSH
    • Explain the purpose and implementation of pam_warn
    • Explain the purpose and implementation of pam_deny
    • Identify instances of pam_warn and pam_deny modules
    • Explain the purpose and implementation of pam_unix2
    • Identify instances of pam_unix2 module
    • Explain the purpose and implementation of pam_env
    • Explain the purpose and implementation of pam_ftp
    • Peruse /etc/pam.d/vsftpd and discuss the implemenation of pam_ftp
    • Explain the purpose and implementation of pam_lastlog
    • Explain the purpose and implementation of pam_limits
    • Explain the purpose and implementation of pam_listfile
    • Explain the purpose and implementation of pam_nologin

  • Account Policies with PAM
    • Explain authentication flow when using PAM
    • Discuss account policies features
    • Identify and peruse the default account policies file: /etc/login.defs
    • Discus PAM's usage of /etc/login.defs as it pertains to system security
    • Discuss pam_pwcheck is maintaining system policy
    • Configure pam_pwcheck to support minimum password length
    • Correlate pam_pwcheck system policy to user accounts database
    • Configure pam_pwcheck to support password history
    • Use chage to enumerate and change user accounts' attributes associated with system policy

  • PAM Tally
    • Explain applications of pam_tally
    • Identify failed logins log file: /var/log/faillog
    • Identify PAM authentication messages in /var/log/messages
    • Compare and contrast pam_tally with faillog
    • Use pam_tally to display user's tally
    • Enable pam_tally system-wide with desired policy
    • Fail to login multiple times, exceeding the system policy and evaluate results
    • Reset user's login count using pam_tally and faillog
    • Redirect PAM log messages using Syslog-NG

  • PAM Password Quality Check (pam_passwdqc)
    • Identify pam_passwdqc using RPM
    • Discuss features
    • Enumerate the supported password character classes - Complex passwords
    • Replace pam_pwcheck with pam_passwdqc using at least 2 character classes
    • Test password policy in non-enforcing mode
    • Evaluate the effects
    • Enable password policy in enforcing mode and evaluate
    • Alter character class and length (complexity) requirements and evaluate

  • PAM Time - Time-based Access Control
    • Discuss features
    • Explain configuration file syntax
    • Impose restrictions on common services
    • Evaluate results

  • PAM Nologin
    • Discuss features
    • Explain configuration file syntax
    • Implement nologin module via /etc/nologin
    • Evaluate results

  • PAM Limits - System Resource Limits Controlled by PAM
    • Discuss features
    • Explain configuration file syntax
    • Impose restrictions on system resources
    • Evaluate results

  • PAM Authentication with Apache
    • Discuss features and desired result
    • Install Apache and development modules providing apxs support
    • Download PAM Apache module
    • Compile and install PAM Apache module
    • Configure Apache web site to support PAM
    • Evaluate results



[本帖被加为精华]
0  回到顶部
帅哥哟,离线,有人找我吗?
huichrist
  2楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网幼儿园 贴子:2 金钱:102 金币:0 积分:10 魅力:0 精华:0 注册:2008-6-25 15:37:00
好东东  发贴心情 Post By:2008-6-25 15:40:00

 支持支持

0  回到顶部
帅哥哟,离线,有人找我吗?
huichrist
  3楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网幼儿园 贴子:2 金钱:102 金币:0 积分:10 魅力:0 精华:0 注册:2008-6-25 15:37:00
  发贴心情 Post By:2008-6-25 15:59:00

 无法下载!


0  回到顶部
帅哥哟,离线,有人找我吗?
lelo
  4楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网幼儿园 贴子:7 金钱:107 金币:0 积分:0 魅力:0 精华:0 注册:2008-6-26 12:43:00
  发贴心情 Post By:2008-6-26 12:45:00

很好的资料,正想好好学习一下,谢谢楼主!


0  回到顶部
帅哥哟,离线,有人找我吗?
bbSUSE
  5楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网小学三年级 贴子:52 金钱:252 金币:0 积分:6 魅力:0 精华:0 注册:2008-6-13 10:06:00
  发贴心情 Post By:2008-6-27 13:55:00

安全的,那有没有防火墙iptables的啊,那个比较头疼

0  回到顶部
帅哥哟,离线,有人找我吗?
leapApple
  6楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网高中一年级 贴子:607 金钱:2409 金币:0 积分:359 魅力:250 精华:14 注册:2007-10-11 10:21:00
  发贴心情 Post By:2008-6-27 14:00:00

以下是引用bbSUSE在2008-6-27 13:55:00的发言:
安全的,那有没有防火墙iptables的啊,那个比较头疼

安全套件里有的,LinuxCBT的Security相关的教程有basic security, selinux, nids, openssh, pam, firewall(iptables)的等等

还在收集中...

0  回到顶部
帅哥哟,离线,有人找我吗?
wyltonwyj
  7楼 个性首页 | 信息 | 搜索 | 邮箱 | 主页 | UC


加好友 发短信
等级:大家网幼儿园 贴子:2 金钱:102 金币:0 积分:1 魅力:0 精华:0 注册:2008-7-1 16:27:00
  发贴心情 Post By:2008-7-1 16:45:00


0  回到顶部