FreeBSD ¤Ï̵µö²Ä¤Î¥Ç¡¼¥¿¥¢¥¯¥»¥¹¤ËÂФ¹¤ëÍ¥¤ì¤¿¥ª¥ó¥é¥¤¥óÊݸǽ¤òÄ󶡤·¤Þ¤¹¡£ ¥Õ¥¡¥¤¥ë¤Î¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤ª¤è¤Ó¶¯À©Åª¥¢¥¯¥»¥¹¥³¥ó¥È¥í¡¼¥ë (MAC: Mandatory Access Control) (Mandatory Access Control (MAC) ¤ò»²¾È) ¤Ï¡¢¥³¥ó¥Ô¥å¡¼¥¿¤¬Æ°ºîÃæ¤Ç¡¢OS ¤¬¼Â¹ÔÃæ¤Ç¤¢¤ë¤È¤¤Ë¡¢ ̵µö²Ä¤ÎÂè»°¼Ô¤¬¥Ç¡¼¥¿¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤Î¤òËɤ°¤³¤È¤ËÌòΩ¤Á¤Þ¤¹¡£ ¤·¤«¤·¤Ê¤¬¤é¡¢¹¶·â¼Ô¤¬¥³¥ó¥Ô¥å¡¼¥¿¤ËʪÍýŪ¤Ë¥¢¥¯¥»¥¹¤·¡¢ µ¡Ì©¥Ç¡¼¥¿¤ò¥³¥Ô¡¼¤·Ê¬ÀϤ¹¤ë¤¿¤á¤Ë¥³¥ó¥Ô¥å¡¼¥¿¤Î¥Ï¡¼¥É¥É¥é¥¤¥Ö¤òÊ̤Υ·¥¹¥Æ¥à¤Ë°ÜÆ°¤µ¤»¤ë¤³¤È¤¬¤Ç¤¤ì¤Ð¡¢ OS ¤Ë¤è¤Ã¤Æ¶¯²½¤µ¤ì¤¿µö²Ä°À¤Ï°ÕÌ£¤ò¤Ê¤µ¤Ê¤¯¤Ê¤ê¤Þ¤¹¡£
¹¶·â¼Ô¤¬ÅŸ»¤ÎÍî¤Á¤¿¥³¥ó¥Ô¥å¡¼¥¿¤ä ¥Ï¡¼¥É¥É¥é¥¤¥Ö¤ò¼ê¤Ë¤¤¤ì¤ë¼êÃʤˤ«¤«¤ï¤é¤º¡¢ GEOM ¥Ù¡¼¥¹¤Î¥Ç¥£¥¹¥¯°Å¹æ²½ (gbde: GEOM Based Disk Encryption) ¤Ï¡¢Ãø¤·¤¤»ñ¸»¤ò»ý¤ÁËܵ¤¤Ç¹¶·â¤ò»Å³Ý¤±¤ë¤Ä¤â¤ê¤Ç¤ä¤Ã¤Æ¤¤¿¹¶·â¼Ô¤«¤é¤µ¤¨¤â¥³¥ó¥Ô¥å¡¼¥¿¤Î¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¾å¤Ë¤¢¤ë¥Ç¡¼¥¿¤òÊݸ¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£ ¸Ä¡¹¤Î¥Õ¥¡¥¤¥ë¤À¤±¤ò°Å¹æ²½¤¹¤ëÈѤ路¤¤ÊýË¡¤È°Û¤Ê¤ê¡¢ gbde ¤ÏÁ´¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤òÆ©²áŪ¤Ë°Å¹æ²½¤·¤Þ¤¹¡£ ʿʸ¥Æ¥¥¹¥È¤Ï·è¤·¤Æ¥Ï¡¼¥É¥É¥é¥¤¥Ö¤Î¥×¥é¥Ã¥¿¤Ë´Ø·¸¤·¤Þ¤»¤ó¡£
root ¤Ë¤Ê¤ë
gbde ¤ÎÀßÄê¤ò¤¹¤ë¤Ë¤Ï¥¹¡¼¥Ñ¥æ¡¼¥¶¤Î¸¢¸Â¤¬É¬Íפˤʤê¤Þ¤¹¡£ °Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ¡¢ root ¤Ë¤Ê¤Ã¤Æ¤¯¤À¤µ¤¤¡£
% su - Password:
¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¥·¥¹¥Æ¥à¤Î¥Ð¡¼¥¸¥ç¥ó¤ò³Î¤«¤á¤ë
gbde(4) ¤¬Æ°ºî¤¹¤ë¤Ë¤Ï FreeBSD 5.0 °Ê¹ß¤¬É¬ÍפǤ¹¡£ °Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤·¤Æ¡¢ ¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¥·¥¹¥Æ¥à¤Î¥Ð¡¼¥¸¥ç¥ó¤ò³Îǧ¤·¤Æ¤¯¤À¤µ¤¤¡£
# uname -r 5.0-RELEASE
¥«¡¼¥Í¥ë¥³¥ó¥Õ¥£¥®¥å¥ì¡¼¥·¥ç¥ó¥Õ¥¡¥¤¥ë¤Ë gbde(4) Âбþ¤òÄɲ乤ë
¤ª¹¥¤ß¤Î¥Æ¥¥¹¥È¥¨¥Ç¥£¥¿¤ò»ÈÍѤ·¤Æ¡¢ °Ê²¼¤Î¹Ô¤ò¥«¡¼¥Í¥ë¥³¥ó¥Õ¥£¥®¥å¥ì¡¼¥·¥ç¥ó¥Õ¥¡¥¤¥ë¤Ë²Ã¤¨¤Þ¤¹¡£
options GEOM_BDE
FreeBSD ¥«¡¼¥Í¥ë¤òÀßÄê¡¢ºÆ¥³¥ó¥Ñ¥¤¥ë¡¢¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£ ¤³¤Î¼ê½ç¤Ï 第9章 ¤ÇÀâÌÀ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
¿·¤·¤¤¥«¡¼¥Í¥ë¤ÇºÆµ¯Æ°¤·¤Þ¤¹¡£
°Ê²¼¤ÎÎã¤Ç¤Ï¡¢¥·¥¹¥Æ¥à¤Ë¿·¤·¤¤¥Ï¡¼¥É¥Ç¥£¥¹¥¯¤òÄɲ䷤褦¤È¤·¤Æ¤¤¤Þ¤¹¡£¤³¤Î¥·¥¹¥Æ¥à¤Ïñ°ì¤Î°Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤òÊÝ»ý¤¹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£ ¤³¤Î¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤Ï /private ¤È¤·¤Æ¥Þ¥¦¥ó¥È¤µ¤ì¤Þ¤¹¡£gbde ¤Ï /home ¤ª¤è¤Ó /var/mail ¤ò°Å¹æ²½¤¹¤ë¤Î¤Ë¤â»ÈÍѤǤ¤Þ¤¹¤¬¡¢ ¤è¤êÊ£»¨¤Ê»Ø¼¨¤òɬÍפȤʤë¤Î¤Ç¤³¤Î²òÀâ¤ÎÈÏáƤò±Û¤¨¤Æ¤¤¤Þ¤¹¡£
¿·¤·¤¤¥Ï¡¼¥É¥É¥é¥¤¥Ö¤òÄɲ乤ë
項16.3 ¤ÇÀâÌÀ¤µ¤ì¤Æ¤¤¤ëÄ̤ê¤Ë¿·¤·¤¤¥É¥é¥¤¥Ö¤ò¥·¥¹¥Æ¥à¤ËÀßÃÖ¤·¤Þ¤¹¡£ ¤³¤ÎÎã¤Ç¤Ï¡¢¿·¤·¤¤¥Ï¡¼¥É¥É¥é¥¤¥Ö¤Ï /dev/ad4s1c ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤Ë ²Ã¤¨¤é¤ì¤¿¤â¤Î¤È¤·¤Þ¤¹¡£ /dev/ad0s1* ¥Ç¥Ð¥¤¥¹¤Ï¡¢¤³¤ÎÎã¤Î¥·¥¹¥Æ¥à¾å¤Ë¸ºß¤¹¤ëɸ½àŪ¤Ê FreeBSD ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤òɽ¤·¤Þ¤¹¡£
# ls /dev/ad* /dev/ad0 /dev/ad0s1b /dev/ad0s1e /dev/ad4s1 /dev/ad0s1 /dev/ad0s1c /dev/ad0s1f /dev/ad4s1c /dev/ad0s1a /dev/ad0s1d /dev/ad4
gbde ¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤òÊÝ»ý¤¹¤ë¥Ç¥£¥ì¥¯¥È¥ê¤òºîÀ®¤¹¤ë
# mkdir /etc/gbde
gbde ¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤Ë¤Ï¡¢ °Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤Î¤ËɬÍפȤʤë¾ðÊ󤬳ÊǼ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£ ¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤Ë¥¢¥¯¥»¥¹¤·¤Ê¤¤¾ì¹ç¡¢ gbde ¤Ï ËÄÂç¤Ê¼êÆ°¤Ë¤è¤ë²ðºß¤Ê¤·¤Ë¤Ï (¥½¥Õ¥È¥¦¥§¥¢¤ÏÂбþ¤·¤Æ¤¤¤Þ¤»¤ó)¡¢°Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤Ë´Þ¤Þ¤ì¤ë¥Ç¡¼¥¿¤ò²òÆɤ¹¤ë¤³¤È¤Ï¤Ç¤¤Ê¤¤¤Ç¤·¤ç¤¦¡£ ¤½¤ì¤¾¤ì¤Î°Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ÏÊÌ¡¹¤Î¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤ò»ÈÍѤ·¤Þ¤¹¡£
gbde ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ò½é´ü²½¤¹¤ë
gbde ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤Ï»ÈÍѤ¹¤ëÁ°¤Ë½é´ü²½¤µ¤ì¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£ ¤³¤Î½é´ü²½¤Ï°ìÅÙ¤À¤±¼Â¹Ô¤µ¤ì¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£
# gbde init /dev/ad4s1c -i -L /etc/gbde/ad4s1c
¥¨¥Ç¥£¥¿¤¬³«¤¯¤Î¤Ç¡¢ ¥Æ¥ó¥×¥ì¡¼¥È¤ò¤â¤È¤Ë¤µ¤Þ¤¶¤Þ¤Ê¥ª¥×¥·¥ç¥ó¤òÀßÄꤷ¤Æ¤¯¤À¤µ¤¤¡£ UFS1 ¤Þ¤¿¤Ï UFS2 ¤Ç»ÈÍѤ¹¤ë¤Ë¤Ï¡¢sector_size ¤ò 2048 ¤ËÀßÄꤷ¤Æ¤¯¤À¤µ¤¤¡£
$FreeBSD: src/sbin/gbde/template.txt,v 1.1 2002/10/20 11:16:13 phk Exp $ # # Sector size is the smallest unit of data which can be read or written. # Making it too small decreases performance and decreases available space. # Making it too large may prevent filesystems from working. 512 is the # minimum and always safe. For UFS, use the fragment size # sector_size = 2048 [...]
gbde(8) ¤Ï¥Ç¡¼¥¿¤òÊݸ¤ë¤Î¤Ë»ÈÍѤ¹¤ë¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆóÅÙ¿Ò¤Þ¤¹¡£ ¥Ñ¥¹¥Õ¥ì¡¼¥º¤Ï¤½¤ì¤¾¤ìƱ¤¸¤Ç¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£ ¥Ç¡¼¥¿¤òÊݸ¤ë gbde ¤ÎǽÎϤϡ¢ ¤¢¤Ê¤¿¤¬ÁªÂò¤·¤¿¥Ñ¥¹¥Õ¥ì¡¼¥º¤ÎÉʼÁ¤Ë´°Á´¤Ë°Í¸¤·¤Þ¤¹¡£ [1]
gbde init ¥³¥Þ¥ó¥É¤Ï gbde ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ËÂФ¹¤ë¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤òºîÀ®¤·¤Þ¤¹¡£¤³¤ÎÎã¤Ç¤Ï /etc/gbde/ad4s1c ¤Ë³ÊǼ¤µ¤ì¤Þ¤¹¡£
注意gbde ¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤Ï¡¢ ¤¹¤Ù¤Æ¤Î°Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ÎÆâÍƤȤȤâ¤Ë¥Ð¥Ã¥¯¥¢¥Ã¥×¤µ¤ì¤Ê¤±¤ì¤Ð ¤Ê¤ê¤Þ¤»¤ó¡£ ¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤À¤±¤òºï½ü¤·¤Æ¤¤¤ë´Ö¡¢ ¥í¥Ã¥¯¥Õ¥¡¥¤¥ë¤Ê¤·¤Ç¤Ï¿®Ç°¤Î¸Ç¤¤¹¶·â¼Ô¤¬ gbde ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ò²òÆɤ¹¤ë¤³¤È¤òËɤ°¤³¤È¤¬¤Ç¤¤Ê¤¤°ìÊý¤Ç¡¢ ÀµÅö¤Ê½êͼԤϡ¢gbde(8) ¤ª¤è¤Ó¤³¤ÎÀ߷׼Ԥˤޤ俤¯»Ù»ý¤µ¤ì¤Ê¤¤ËÄÂç¤ÊÎ̤κî¶È¤Ê¤·¤Ë¤Ï¡¢ °Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¾å¤Î¥Ç¡¼¥¿¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤³¤È¤¬¤Ç¤¤Ê¤¤¤Ç¤·¤ç¤¦¡£
¥«¡¼¥Í¥ë¤Ë°Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤òÀܳ¤¹¤ë
# gbde attach /dev/ad4s1c -l /etc/gbde/ad4s1c
°Å¹æ²½¤µ¤ì¤¿¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ò½é´ü²½¤¹¤ëºÝ¤ËÁªÂò¤·¤¿¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ¹¤ë¤è¤¦¤Ëµá¤á¤é¤ì¤Þ¤¹¡£ ¿·¤·¤¤°Å¹æ²½¥Ç¥Ð¥¤¥¹¤Ï /dev ¤Ë /dev/device_name.bde ¤È¤·¤Æ¸½¤ì¤Þ¤¹¡£
# ls /dev/ad* /dev/ad0 /dev/ad0s1b /dev/ad0s1e /dev/ad4s1 /dev/ad0s1 /dev/ad0s1c /dev/ad0s1f /dev/ad4s1c /dev/ad0s1a /dev/ad0s1d /dev/ad4 /dev/ad4s1c.bde
°Å¹æ²½¥Ç¥Ð¥¤¥¹¾å¤Ë¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤òºîÀ®¤¹¤ë
¥«¡¼¥Í¥ë¤Ë°Å¹æ²½¥Ç¥Ð¥¤¥¹¤¬Àܳ¤µ¤ì¤ë¤È¡¢
¥Ç¥Ð¥¤¥¹¾å¤Ë¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤òºîÀ®¤Ç¤¤Þ¤¹¡£
°Å¹æ²½¥Ç¥Ð¥¤¥¹¾å¤Ë¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤òºîÀ®¤¹¤ë¤Ë¤Ï newfs(8)
¤ò»ÈÍѤ·¤Þ¤¹¡£½¾Íè¤Î UFS1 ¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤Ç½é´ü²½¤¹¤ë¤è¤ê¡¢ ¿·¤·¤¤ UFS2
¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤Ç½é´ü²½¤·¤¿Êý¤¬¹â®¤Ê¤Î¤Ç¡¢ -O2
¥ª¥×¥·¥ç¥ó¤È¤È¤â¤Ë newfs(8)
¤ò»ÈÍѤ¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
注意: FreeBSD 5.1-RELEASE °Ê¹ß¤Ç¤Ï¡¢
-O2
¥ª¥×¥·¥ç¥ó¤Ï¥Ç¥Õ¥©¥ë¥È¤Ç¤¹¡£
# newfs -U -O2 /dev/ad4s1c.bde
注意: newfs(8) ¤Ï¡¢¥Ç¥Ð¥¤¥¹Ì¾¤Ë *.bde ³ÈÄ¥»Ò¤Ë¤è¤Ã¤Æǧ¼±¤µ¤ì¤ë¡¢ Àܳ¤µ¤ì¤¿ gbde ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ËÂФ·¤Æ¼Â¹Ô¤µ¤ì¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£
°Å¹æ²½¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ò¥Þ¥¦¥ó¥È¤¹¤ë
°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤ËÂФ¹¤ë¥Þ¥¦¥ó¥È¥Ý¥¤¥ó¥È¤òºîÀ®¤·¤Þ¤¹¡£
# mkdir /private
°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤ò¥Þ¥¦¥ó¥È¤·¤Þ¤¹¡£
# mount /dev/ad4s1c.bde /private
°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤¬ÍøÍѲÄǽ¤«³Î¤«¤á¤ë
¤³¤ì¤Ç°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤Ï df(1) ¤Ç¸«¤ë¤³¤È¤¬¤Ç¤¡¢ ÍøÍѤ¹¤ë½àÈ÷¤¬¤Ç¤¤Þ¤·¤¿¡£
% df -H Filesystem Size Used Avail Capacity Mounted on /dev/ad0s1a 1037M 72M 883M 8% / /devfs 1.0K 1.0K 0B 100% /dev /dev/ad0s1f 8.1G 55K 7.5G 0% /home /dev/ad0s1e 1037M 1.1M 953M 0% /tmp /dev/ad0s1d 6.1G 1.9G 3.7G 35% /usr /dev/ad4s1c.bde 150G 4.1K 138G 0% /private
¥·¥¹¥Æ¥à¤òµ¯Æ°¤¹¤ëÅ٤ˡ¢¤¹¤Ù¤Æ¤Î°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤Ï »ÈÍÑÁ°¤Ë¥«¡¼¥Í¥ë¤ËÀܳ¤·¡¢ ¥¨¥é¡¼¤ÎÍ̵¤ò¥Á¥§¥Ã¥¯¤·¡¢¥Þ¥¦¥ó¥È¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£ ɬÍפʥ³¥Þ¥ó¥É¤Ï root ¥æ¡¼¥¶¤È¤·¤Æ¼Â¹Ô¤µ¤ì¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£
¥«¡¼¥Í¥ë¤Ë gbde ¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤òÀܳ¤¹¤ë
# gbde attach /dev/ad4s1c -l /etc/gbde/ad4s1c
¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤Î°Å¹æ²½¤ò½é´ü²½¤¹¤ëºÝ¤ËÁªÂò¤·¤¿¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÆþÎϤ¹¤ë¤è¤¦¤Ëµá¤á¤é¤ì¤ë¤Ç¤·¤ç¤¦¡£
¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤Î¥¨¥é¡¼¤ò¥Á¥§¥Ã¥¯¤¹¤ë
°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤ò¼«Æ°Åª¤Ë¥Þ¥¦¥ó¥È¤¹¤ë¤¿¤á¤Ë /etc/fstab ¤ËÀßÄê¤ò·ÇºÜ¤¹¤ë¤³¤È¤Ï¤Þ¤À¤Ç¤¤Ê¤¤¤¿¤á¡¢ ¥Þ¥¦¥ó¥È¤¹¤ëÁ°¤Ë fsck(8) ¤ò¼Â¹Ô¤·¤Æ¡¢ ¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤Î¥¨¥é¡¼¤ò¥Á¥§¥Ã¥¯¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£
# fsck -p -t ffs /dev/ad4s1c.bde
°Å¹æ²½¥Õ¥¡¥¤¥ë¤ò¥Þ¥¦¥ó¥È¤¹¤ë
# mount /dev/ad4s1c.bde /private
¤³¤ì¤Ç°Å¹æ²½¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤¬ÍøÍѤǤ¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿¡£
¥¹¥¯¥ê¥×¥È¤òºîÀ®¤·¤Æ¡¢°Å¹æ²½¥Ñ¡¼¥Æ¥£¥·¥ç¥ó¤ò¼«Æ°Åª¤ËÀܳ¡¢ ¥Á¥§¥Ã¥¯¡¢¥Þ¥¦¥ó¥È¤¹¤ë¤³¤È¤Ï²Äǽ¤Ç¤¹¡£¤·¤«¤·¤Ê¤¬¤é¡¢ °ÂÁ´¾å¤ÎÍýͳ¤Ë¤è¤ê¥¹¥¯¥ê¥×¥È¤Ë gbde(8) ¥Ñ¥¹¥ï¡¼¥É¤ò´Þ¤á¤ë¤Ù¤¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡£¤½¤ÎÂå¤ï¤ê¤Ë¡¢¥³¥ó¥½¡¼¥ë¤Þ¤¿¤Ï ssh(1) ¤Ë¤è¤ëÀܳ¤«¤é¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ¹¤ë¤è¤¦¤Ê¥¹¥¯¥ê¥×¥È¤¬¼êÆ°¤Ç¼Â¹Ô¤µ¤ì¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Þ¤¹¡£
gbde(8) ¤Ï 128bit AES ¤Î CBC ¥â¡¼¥É¤ò»ÈÍѤ·¤Æ¥»¥¯¥¿¥Ú¥¤¥í¡¼¥É¤ò°Å¹æ²½¤·¤Þ¤¹¡£ ¥Ç¥£¥¹¥¯¾å¤Î¤½¤ì¤¾¤ì¤Î¥»¥¯¥¿¤Ï°Û¤Ê¤ë AES ¸°¤Ç°Å¹æ²½¤µ¤ì¤Þ¤¹¡£ ¥»¥¯¥¿¸°¤¬¥æ¡¼¥¶¤¬ÆþÎϤ·¤¿¥Ñ¥¹¥Õ¥ì¡¼¥º¤«¤é¤É¤Î¤è¤¦¤ËƳ¤½Ð¤µ¤ì¤ë¤«¤ò´Þ¤á¡¢ gbde ¤Î°Å¹æ¼êË¡¤ÎÀ߷פˤĤ¤¤Æ¤Î¾ÜºÙ¤Ï¡¢ gbde(4) ¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£
sysinstall(8) ¤Ï gbde °Å¹æ²½¥Ç¥Ð¥¤¥¹¤È¸ß´¹À¤¬¤¢¤ê¤Þ¤»¤ó¡£ sysinstall(8) ¤ò¼Â¹Ô¤¹¤ëÁ°¤Ë *.bde ¥Ç¥Ð¥¤¥¹¤Ï¤¹¤Ù¤Æ¥«¡¼¥Í¥ë¤«¤éÀÚÃǤµ¤ì¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£ ¤½¤¦¤·¤Ê¤¤¤È¡¢sysinstall(8) ¤¬½é¤á¤Ë¥Ç¥Ð¥¤¥¹¤òÁöºº¤¹¤ëºÝ¤Ë¥¯¥é¥Ã¥·¥å¤·¤Æ¤·¤Þ¤¦¤Ç¤·¤ç¤¦¡£ °Å¹æ²½¥Ç¥Ð¥¤¥¹¤òÀÚÃǤ¹¤ë¤Ë¤Ï¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò»ÈÍѤ·¤Þ¤¹¡£
# gbde detach /dev/ad4s1c
vinum(4) ¤Ï geom(4) ¥µ¥Ö¥·¥¹¥Æ¥à¤ò»ÈÍѤ·¤Ê¤¤¤Î¤Ç¡¢ vinum ¥Ü¥ê¥å¡¼¥à¤È gbde ¤òÊ»ÍѤǤ¤Ê¤¤¤³¤È¤Ë¤âÃí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡£
[1] |
µ²±¤¹¤ë¤Î¤¬´Êñ¤Ç¡¢ °ÂÁ´¤Ê¥Ñ¥¹¥Õ¥ì¡¼¥º¤òÁªÂò¤¹¤ëÊýË¡¤Ë¤Ä¤¤¤Æ¤Ï¡¢ Diceware Passphrase ¥¦¥§¥Ö¥µ¥¤¥È¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£ |
ËÜʸ½ñ¡¢¤ª¤è¤Ó¾¤Îʸ½ñ¤Ï ftp://ftp.FreeBSD.org/pub/FreeBSD/doc/ ¤«¤é¥À¥¦¥ó¥í¡¼¥É¤Ç¤¤Þ¤¹¡£
FreeBSD ¤Ë´Ø¤¹¤ë¼ÁÌ䤬¤¢¤ë¾ì¹ç¤Ë¤Ï¡¢¥É¥¥å¥á¥ó¥È ¤òÆɤó¤À¾å¤Ç <questions@FreeBSD.org> ¤Þ¤Ç (±Ñ¸ì¤Ç)
Ï¢Íí¤·¤Æ¤¯¤À¤µ¤¤¡£
ËÜʸ½ñ¤Ë´Ø¤¹¤ë¼ÁÌä¤Ë¤Ä¤¤¤Æ¤Ï¡¢<doc@FreeBSD.org> ¤Þ¤ÇÅŻҥ᡼¥ë¤ò (±Ñ¸ì¤Ç)
Á÷¤Ã¤Æ¤¯¤À¤µ¤¤¡£