ãåå.comã®VPSãåãã & è²ã
ãµãŒãèšå®ãè¡ã£ã vol.01
ãµãŒãèšå®ã®ãå匷ããŠããåå.comã®VPSãåããŸããã
ãåå.comã®èšå®ã«ã€ããŠã®æ
å ±ã£ãŠçµæ§å°ãªãã®ã§ãããåŒã£ãããã®ã¯ãããã®VPSã®æ
å ±ã°ãã...ã
ä»åŸVPSã®èšå®ãè¡ãæ¹ã®ã圹ã«ç«ãŠãã°ãšæããä»è¡ã£ãŠããããšã諞ã
ã¡ã¢ããŠãããŸãã
é·ãã®ã§è€æ°ã®èšäºã«åããŸãã
ãšããããŸã èšå®ãçµãã£ãŠããªãã®ã§éäžãŸã§ããæžããªãã®ã§ã...ã
ãåå.com VPS(KVM) 2Gãã©ã³ãå¥çŽ
äœæ¥ã¯Macã®ã¿ãŒããã«ã䜿çš
以äžã®äœæ¥ã¯ãµãŒãå¥çŽæã®ã¡ãŒã«ã«èšèŒããããŠãã®ã§çç¥ããŸãã
VPSã®åæã»ããã¢ãã
rootæš©éã§SSHæ¥ç¶ãã
次ãããã£ãããšãã€ãã€ãæžããŠãããŸãã
ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŠããããã±ãŒãžã®ã¢ããããŒããè¡ã
SSHæ¥ç¶åŸãã·ã¹ãã ã«äºãã€ã³ã¹ããŒã«ãããŠããã·ã¹ãã ã®ã¢ããããŒããè¡ããŸãã
ãããšã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŠããããã±ãŒãžãç¶ã
ã¢ããããŒããããŠãããŸãã
å®è¡äžã¯äžèšã®ãããªç»é¢ãæµããŸãã
æå€ãšæéããããã®ã§æ°é·ã«åŸ
ã¡ãŸãããã
oaded plugins: fastestmirror, security Determining fastest mirrors epel/metalink | 4.9 kB 00:00 * base: ftp.tsukuba.wide.ad.jp * epel: ftp.kddilabs.jp * extras: ftp.tsukuba.wide.ad.jp * updates: ftp.tsukuba.wide.ad.jp base | 3.7 kB 00:00 base/primary_db | 4.6 MB 00:00 ... ãäžç¥ã ...
äœæ¥çšãŠãŒã¶ãäœæãã
rootæš©éã§äœæ¥ããã®ã¯ã»ãã¥ãªãã£äžããŸããããããªãã®ã§ãäœæ¥çšã®ãŠãŒã¶ãäœæããŸãã
åŸã»ã©rootã«ãªãããŠãŒã¶ãå¶éããããã«wheelã°ã«ãŒãã«æå±ãããŠãããŸãã
# /usr/sbin/useradd -d /home/{äœæ¥çšãŠãŒã¶åãæå®} -s /bin/bash {äœæ¥çšãŠãŒã¶åãæå®} # passwd {ä»»æã®ãã¹ã¯ãŒããèšå®} # usermod -G wheel
ãŠãŒã¶ã®å
¬ééµãç»é²ãã
äœæ¥çšãŠãŒã¶ããªã¢ãŒãã§å
¥ããããã«å
¬ééµãç»é²ããŸãã
# su - {äœæ¥çšãŠãŒã¶å} $ ssh-keygen -t rsa $ vi ~/.ssh/authorized_key
authorized_keyã®ç·šéç»é¢ãéããŸãã
ããŒã«ã«ã§äœæããŠããå
¬ééµãã³ããããŠä¿åããŸãã
ããŒã«ã«ã«å
¬ééµãäœã£ãŠããªãæ¹ã¯ãããæ©ã«äœã£ãŠãããšè¯ãããšæããŸãã
$ chmod ~/.ssh/authorized_key
sshdã®èšå®ã倿Žãã
ã»ãã¥ãªãã£ãé«ããããã«ãã¹ã¯ãŒãã§ã®èªèšŒããããå
¬éèªèšŒéµã§ã®ãã°ã€ã³ã®ã¿ã«å€æŽããŸãã
# vi /etc/ssh/sshd_config // äžèšã®é
ç®ã no ã«ããŸã PermitRootLogin no PasswordAuthentication no UserPAM no
èšå®ãå®äºãããä¿åããŠçµäºããŸãã
ããã§è©Šãã«ã¿ãŒããã«ã®å¥ã¿ããéããäœæ¥çšãŠãŒã¶ã§ãã°ã€ã³ããŠã¿ãŸãã
â»ãã®æãrootæš©éã§ãã°ã€ã³ããŠããã¿ãã¯éããªãã§äžããã
$ ssh {äœæ¥çšãŠãŒã¶å}@{ãµãŒãã®IPã¢ãã¬ã¹}
ç¡äºã«ãã°ã€ã³åºæ¥ãããã§ãããä»ã®ãšããé èª¿ã«æåã§ãã ãã®æç¹ã§
ãªã¢ãŒãããã®ãã¹ã¯ãŒãèªèšŒäžå¯
å
¬ééµã«å¯Ÿããç§å¯éµãæã£ãã¯ã©ã€ã¢ã³ãããã®ãã°ã€ã³ä»¥å€äžå¯
äœæ¥çšãŠãŒã¶ã§sudoåºæ¥ãããã«èšå®ã倿Žãã
rootæš©éã§ãã°ã€ã³ã§ããªããªã£ãŠããŸãã®ã§ãäœæ¥çšãŠãŒã¶ã§sudoåºæ¥ãããã«èšå®ã倿ŽããŸãã
sudoã®èšå®ãã¡ã€ã«ãéããŸãã
èšå®ãã¡ã€ã«ã以äžã®ããã«å€æŽããŸãã
## Allows people in group wheel to run all commands # %wheel ALL=(ALL) ALL // ã³ããããŠã³ã¡ã³ããå€ã %wheel ALL=(ALL) ALL
ãã¡ã€ã¢ãŠã©ãŒã«ãèšå®ãã
ããã«ã»ãã¥ãªãã£ãé«ããããã«ã䜿çšããªãããŒãã¯éããŠãããŸãã
ããŒãã®èšå®ã¯ iptables ãç·šéããŸãã
# vi /etc/sysconfig/iptables
ä»åã¯ä»¥äžã®æ§ãªèšå®ã«ããŠããŸãã
*filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :RH-Firewall-1-INPUT - [0:0] -A INPUT -j RH-Firewall-1-INPUT -A FORWARD -j RH-Firewall-1-INPUT -A RH-Firewall-1-INPUT -i lo -j ACCEPT -A RH-Firewall-1-INPUT -p icmp --icmp-type any -j ACCEPT -A RH-Firewall-1-INPUT -p 50 -j ACCEPT -A RH-Firewall-1-INPUT -p 51 -j ACCEPT -A RH-Firewall-1-INPUT -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT -A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT -A RH-Firewall-1-INPUT -p tcp -m tcp --dport 631 -j ACCEPT -A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT # SSH, HTTP, FTP1, FTP2, MySQL -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT -A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT -A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited COMMIT
ãã£ããèšããš SSH(22)ãHTML(80)ãFTP(20/21)ãMySQL(3306)ã®ã¿èš±å¯ããŸããã
2015/04/08远èš
â»äŸãšããŠããã©ã«ãã®ããŒãçªå·ãæžããŠããŸãã å®éã«äœ¿çšããéã¯ããŒãçªå·ãå€ããŠãããšã»ãã¥ãªãã£äžå®å¿ã§ãã
â»SCPã䜿çšã§ããã®ã§FTPã¯å¿
èŠãªããšã®ãææãé ããŸãããèšå®ããåé€ããããŸããã
2015/04/09远èš
â»MySQLã®ããŒããå€éšããã®ã¢ã¯ã»ã¹ã¯å¿
èŠãªãã®ãªãéããŠãããŠãè¯ããšããææãããã ããMySQLã®ããŒãèšå®éšåãåé€ããŸãã
ä»ã®è©³ãã説æã¯äžèšã®ããŒãžã埡芧ãã ããã
ããããã®VPSãå°å
¥è§£èª¬ ãã®10ïŒiptablesã®èšå® | Sabakura Blog
å
¥åãå®äºãããä¿åããŠçµäºããŸãã
èšå®ãåæ ããããã«iptablesãåèµ·åããŸãã
/etc/rc.d/init.d/iptables restart
次ã®ãããªæèšã衚瀺ãããã°åèµ·åå®äºã§ãã
iptables: Setting chains to policy ACCEPT: filter [ OK ] iptables: Flushing firewall rules: [ OK ] iptables: Unloading modules: [ OK ] iptables: Applying firewall rules: [ OK ]
èšå®ãåæ ãããŠããã確èªããŸãã
æå®ããããŒããACCEPTã«ãªã£ãŠããã°å®äºã§ãã
仿¥ã¯ãããŸã§è¡ããŸããã
ããããªèšäºãè¡ã£ããæ¥ããããªããã®èšå®ã¯å€§å€ã§ãã...ã
次ã¯Apache, PHP, MySQLã®èšå®ãè¡ãäºå®ã§ãã
ä»ååèã«ããããŒãž
ãããVPS(CentOS6.5)ã«ææ°ããŒãžã§ã³ã®LAMPç°å¢ãæ§ç¯ãã(åå¿é²) - Qiita
ãååVPSã«CentOS 7ãã€ã³ã¹ããŒã«ããŠWebãµã€ããäœã£ãŠã¿ã - Qiita
myfinder's blog: ãããã®VPSãåãããçã£å
ã«ããã¹ãsshèšå®
VPSã§WordPressãåãããç°å¢ãã³ã³ãœãŒã«ããæ§ç¯ããïŒ | æ ªåŒäŒç€ŸLIG
ããããã®VPSãå°å
¥è§£èª¬ ãã®10ïŒiptablesã®èšå® | Sabakura Blog