Secure XDMCP ์ ‘์†

Secure XDMCP๋Š” ์›๊ฒฉ ํ˜ธ์ŠคํŠธ์— ์ ‘์†ํ•˜๋Š” ์ƒˆ๋กœ์šด ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค Secure XDMCP๋ฅผ ์ด์šฉํ•˜๋ฉด SSH ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•ด ๋ณด๋‹ค ์•ˆ์ „ํ•˜๊ณ  ๊ฐ„๋‹จํ•œ XDMCP ์ ‘์†์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. SSH ํ”„๋กœํ† ์ฝœ์„ ์ด์šฉํ•˜๋ฉด ์•ˆ์ „ํ•œ ์—ฐ๊ฒฐ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๋ฐฉํ™”๋ฒฝ, ๋งˆ์Šคํฌ๋ ˆ์ด๋”ฉ ์„œ๋ฒ„, NAT ๊ฒŒ์ดํŠธ์›จ์ด ๋“ฑ์œผ๋กœ ๋ง‰ํ˜€ ์žˆ๋Š” ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ์—์„œ๋„ ์‰ฝ๊ฒŒ X11 ์—ฐ๊ฒฐ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. 

์›๊ฒฉ ์žฅ๋น„๊ฐ€ ๋ฆฌ๋ˆ…์Šค์ด๊ณ  XDMCP ๋ฐ๋ชฌ์œผ๋กœ์„œ gdm(gdm-binary)๊ฐ€ ๊ตฌ๋™ ์ค‘์ด๋ผ๋ฉด SecureXDMCP ์ ‘์†์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.(GDM์„ ์‚ฌ์šฉํ•  ๋•Œ Secure XDMCP ์ ‘์†์„ ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค..)

UNIX/Linux OS๋ณ„ ์„ค์ •์„ ์ฐธ๊ณ ํ•˜์—ฌ ๋ฆฌ๋ˆ…์Šค ๋ฐฐํฌํŒ๊ณผ ๋ฒ„์ „์— ๋”ฐ๋ฅธ lightdm์„ ์„ค์น˜ํ•˜๊ณ  ๊ทธ์— ๋งž๋Š” ์„ค์ •์„ ํ•  ํ•„์š”๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.


์ฃผ์˜:
Secure XDMCP๋Š” SSH ํ”„๋กœํ† ์ฝœ์„ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด๋ฏ€๋กœ ์›๊ฒฉ ์„œ๋ฒ„์— SSH ์„œ๋ฒ„๊ฐ€ ๊ตฌ๋™ ์ค‘์ด์–ด์•ผ ํ•˜๊ณ , X11Forwarding ๊ธฐ๋Šฅ์ด ์ผœ์ ธ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
OpenSSH ์„œ๋ฒ„์ธ ๊ฒฝ์šฐ ์„ค์ • ํŒŒ์ผ (/etc/ssh/sshd_config)์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

X11Forwarding yes

Secure Shell Communications Security ์„œ๋ฒ„์ธ ๊ฒฝ์šฐ ์„ค์ • ํŒŒ์ผ (/etc/ssh2/sshd2_config)์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

AllowX11Forwarding yes


1 ๋‹จ๊ณ„: Secure XDMCP ์„ธ์…˜ ๋งŒ๋“ค๊ธฐ

  1. Xmanager๋ฅผ ์‹คํ–‰์‹œํ‚ต๋‹ˆ๋‹ค. 



  2. ํŒŒ์ผ ๋ฉ”๋‰ด์—์„œ "์ƒˆ๋กœ ๋งŒ๋“ค๊ธฐ"๋ฅผ ์„ ํƒํ•˜์—ฌ "Xmanager ์„ธ์…˜(๊ณ ์ • ์„ธ์…˜)"์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ๋ฐ”๋กœ ์ง„ํ–‰๋˜๋Š” ์„ธ์…˜ ๋“ฑ๋ก ์ •๋ณด ๋Œ€ํ™” ์ƒ์ž์—์„œ "์—ฐ๊ฒฐ ๋ฐฉ๋ฒ•"์„ "Secure XDMCP"๋กœ ์„ ํƒํ•œ ํ›„ ์ ‘์†์— ํ•„์š”ํ•œ ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    (์ž๋™ ์„ธ์…˜ ๋ณด๊ธฐ ์ƒํƒœ์—์„œ ์ ‘์†ํ•˜๊ณ ์ž ํ•˜๋Š” ํ˜ธ์ŠคํŠธ๊ฐ€ ๋ณด์ธ๋‹ค๋ฉด ํ•ด๋‹น ์•„์ด์ฝ˜์˜ ์ฝ˜ํ…์ŠคํŠธ ๋ฉ”๋‰ด์—์„œ SSH ์—ฐ๊ฒฐ๋กœ ์ €์žฅ์„ ์„ ํƒํ•˜๋Š” ๋ฐฉ๋ฒ•์œผ๋กœ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.)

    XDMCP ์ ‘์†์„ ํ•˜๊ณ ์ž ํ•˜๋Š” ์žฅ๋น„์™€ SSH ์„œ๋ฒ„๊ฐ€ ๊ฐ™์ง€ ์•Š์„ ๊ฒฝ์šฐ:

    1. ํ•ด๋‹น XDMCP ์„ธ์…˜์˜ ์ฝ˜ํ…์ŠคํŠธ ๋ฉ”๋‰ด์—์„œ "๋“ฑ๋ก ์ •๋ณด"๋ฅผ ์„ ํƒํ•˜์—ฌ ์„ธ์…˜ ๋“ฑ๋ก ์ •๋ณด ๋Œ€ํ™” ์ƒ์ž๋ฅผ ์—ฝ๋‹ˆ๋‹ค. 

       

    2. "์—ฐ๊ฒฐ ๋ฐฉ๋ฒ•" ์˜†์˜ ์„ค์ • ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ Secure XDMCP ์„ค์ • ๋Œ€ํ™” ์ƒ์ž๋ฅผ ์—ฝ๋‹ˆ๋‹ค. 



    3. "SSH ์„œ๋ฒ„๊ฐ€ XDMCP ํ˜ธ์ŠคํŠธ์™€ ๋‹ค๋ฆ…๋‹ˆ๋‹ค." ์˜ต์…˜์„ ์„ ํƒํ•˜์—ฌ "ํ˜ธ์ŠคํŠธ" ํ•„๋“œ๋ฅผ ํ™œ์„ฑํ™”์‹œํ‚ต๋‹ˆ๋‹ค.
    4. SSH ์„œ๋ฒ„์˜ IP ์ฃผ์†Œ๋‚˜ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    5. "์‚ฌ์šฉ์ž ์ธ์ฆ" ์˜์—ญ์—์„œ๋Š” ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    6. ํ™•์ธ์„ ๋ˆŒ๋Ÿฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

      ์ฃผ์˜: SSH ์„œ๋ฒ„์™€ XDMCP ํ˜ธ์ŠคํŠธ๊ฐ€ ๋‹ค๋ฅผ ๊ฒฝ์šฐ์—๋Š” SSH ์„œ๋ฒ„๊ฐ€ ์™ธ๋ถ€ ํฌํŠธ์— ๋Œ€ํ•ด์„œ๋„ ๋ฐ”์ธ๋”ฉ์„ ํ•  ์ˆ˜ ์žˆ๋„๋ก SSH ์„œ๋ฒ„ ์„ค์ • ํŒŒ์ผ์—์„œ GatewayPorts๋ผ๋Š” ๊ฐ’์„ yes๋กœ ์„ค์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

2 ๋‹จ๊ณ„. Secure XDMCP ์„ธ์…˜์œผ๋กœ ์ ‘์†ํ•˜๊ธฐ:

  1. Xmanager๋ฅผ ์—ฝ๋‹ˆ๋‹ค.
  2. ํ•ด๋‹น Secure XDMCP ์„ธ์…˜์„ ๋งˆ์šฐ์Šค๋กœ ๋”๋ธ” ํด๋ฆญ ํ•ฉ๋‹ˆ๋‹ค.
  3. Secure XDMCP ์„ธ์…˜์„ ๋งŒ๋“ค ๋•Œ "์‚ฌ์šฉ์ž ์ธ์ฆ" ์˜์—ญ์—์„œ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ์ž…๋ ฅํ•˜์ง€ ์•Š์•˜์„ ๊ฒฝ์šฐ SSH ์‚ฌ์šฉ์ž ์ด๋ฆ„ ๋Œ€ํ™” ์ƒ์ž๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. SSH ์„œ๋ฒ„์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•œ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.



  4. Secure XDMCP ์„ธ์…˜์„ ๋งŒ๋“ค ๋•Œ "์‚ฌ์šฉ์ž ์ธ์ฆ" ์˜์—ญ์—์„œ ๋น„๋ฐ€ ๋ฒˆํ˜ธ๋‚˜ ํ‚ค ์•”ํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜์ง€ ์•Š์•˜์„ ๊ฒฝ์šฐ SSH ์‚ฌ์šฉ์ž ์ธ์ฆ ๋Œ€ํ™” ์ƒ์ž๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. SSH ์„œ๋ฒ„์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•œ ์ธ์ฆ ๋ฐฉ๋ฒ•์„ ์„ ํƒํ•˜๊ณ  ๊ทธ์— ๋งž๋Š” ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค. ๊ณต๊ฐœ ํ‚ค(Public Key) ์‚ฌ์šฉ์ž ์ธ์ฆ์— ๋Œ€ํ•ด์„œ๋Š” ๋‹ค์Œ์„ ์ฐธ๊ณ ํ•˜์‹ญ์‹œ์˜ค. 




  5. Xmanager์— ์›๊ฒฉ ๋กœ๊ทธ์ธ ํ™”๋ฉด์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. 



  6. XDMCP ํ˜ธ์ŠคํŠธ์˜ ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•œ ํ›„ ์›๊ฒฉ ์œ ๋‹‰์Šค/๋ฆฌ๋ˆ…์Šค ๋ฐ์Šคํฌํ†ฑ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.