Windows Server 2003¿¡¼­ ·ÎÄ÷Π¶Ç´Â ±×·ì Á¤Ã¥À» »ç¿ëÇÏ¿© À̺¥Æ® ·Î±× º¸¾ÈÀ» ¼³Á¤ÇÏ´Â ¹æ¹ý

±â¼ú ÀÚ·á: 323076 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¿ä¾à

Windows Server 2003¿¡¼­ °ü¸®ÀÚ´Â À̺¥Æ® ·Î±×¿¡ ´ëÇÑ º¸¾È ¾×¼¼½º ±ÇÇÑÀ» »ç¿ëÀÚ ÁöÁ¤ÇÒ ¼ö ÀÖÀ¸¸ç ·ÎÄ÷Π¶Ç´Â ±×·ì Á¤Ã¥À» ÅëÇØ ÀÌ·¯ÇÑ ¼³Á¤À» ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®¼­¿¡¼­´Â ÀÌ·¯ÇÑ µÎ °¡Áö ¹æ¹ýÀ» ¸ðµÎ ¼³¸íÇÕ´Ï´Ù.

»ç¿ëÀÚ¿¡°Ô À̺¥Æ® ·Î±×¿¡ ´ëÇÑ ´ÙÀ½ ¾×¼¼½º ±ÇÇÑ Áß Çϳª ÀÌ»óÀ» ºÎ¿©ÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • Àбâ
  • ¾²±â
  • Áö¿ì±â
Áß¿ä?°°Àº ¹æ¹ýÀ¸·Î º¸¾È ·Î±×¸¦ ±¸¼ºÇÒ ¼ö ÀÖÁö¸¸ ÀÐ±â ¹× Áö¿ì±â ¾×¼¼½º ±ÇÇѸ¸ º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù. º¸¾È ·Î±×¿¡ ´ëÇÑ ¾²±â ¾×¼¼½º ±ÇÇÑÀº Windows LSA(·ÎÄà º¸¾È ±â°ü)¿ëÀ¸·Î¸¸ ¿¹¾àµÇ¾î ÀÖ½À´Ï´Ù.

·ÎÄ÷ΠÀ̺¥Æ® ·Î±× º¸¾È ±¸¼º

°æ°í ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ À߸ø »ç¿ëÇÏ¸é ½É°¢ÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖÀ¸¸ç ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇØ ¿î¿µ üÁ¦¸¦ ´Ù½Ã ¼³Ä¡ÇØ¾ß ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. Microsoft´Â ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ À߸ø »ç¿ëÇÏ¿© ¹ß»ýÇÏ´Â ¹®Á¦¿¡ ´ëÇØ ÇØ°áÀ» º¸ÁõÇÏÁö ¾Ê½À´Ï´Ù. ·¹Áö½ºÆ®¸® ÆíÁý±â »ç¿ë¿¡ µû¸¥ ¸ðµç Ã¥ÀÓÀº »ç¿ëÀÚ¿¡°Ô ÀÖ½À´Ï´Ù.
°¢ ·Î±×ÀÇ º¸¾ÈÀº ´ÙÀ½ ·¹Áö½ºÆ®¸® Ű °ªÀ» ÅëÇØ ·ÎÄ÷Π±¸¼ºµË´Ï´Ù.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog
¿¹¸¦ µé¾î, ÀÀ¿ë ÇÁ·Î±×·¥ ·Î±× º¸¾È ¼³¸íÀÚ´Â ´ÙÀ½ ·¹Áö½ºÆ®¸® °ªÀ¸·Î ±¸¼ºµË´Ï´Ù.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\CustomSD
½Ã½ºÅÛ ·Î±× º¸¾È ¼³¸íÀÚ´Â ´ÙÀ½À» ÅëÇØ ±¸¼ºµË´Ï´Ù.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\System\CustomSD
°¢ ·Î±× º¸¾È ¼³¸íÀÚ´Â SDDL(Security Descriptor Definition Language) ±¸¹®À» »ç¿ëÇÏ¿© ÁöÁ¤µË´Ï´Ù. SDDL ±¸¹®¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Ç÷§Æû SDK¸¦ ÂüÁ¶Çϰųª ÀÌ ¹®¼­ÀÇ "ÂüÁ¶" Àý¿¡ ³ª¿Í ÀÖ´Â Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.

SDDL ¹®ÀÚ¿­À» ±¸¼ºÇÏ´Â °æ¿ì À̺¥Æ® ·Î±×¿Í °ü·ÃµÈ ¼¼ °¡Áö ±ÇÇÑ(Àбâ, ¾²±â, Áö¿ì±â)ÀÌ ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ±ÇÇÑÀº ACE ¹®ÀÚ¿­ÀÇ ¾×¼¼½º ±ÇÇÑ Çʵ忡¼­ ´ÙÀ½ ºñÆ®¿¡ ÇØ´çÇÕ´Ï´Ù.
  • 1= Àбâ
  • 2 = ¾²±â
  • 4 = Áö¿ì±â
´ÙÀ½Àº ÀÀ¿ë ÇÁ·Î±×·¥ ·Î±×ÀÇ ±âº» SDDL ¹®ÀÚ¿­À» º¸¿©ÁÖ´Â ¿¹Á¦ SDDLÀÔ´Ï´Ù. ¾×¼¼½º ±ÇÇÑ(16Áø¼ö)Àº ±½Àº ±Û²Ã·Î Ç¥½ÃµË´Ï´Ù.
O:BAG:SYD:(D;; 0xf0007;;;AN)(D;; 0xf0007;;;BG)(A;; 0xf0007;;;SY)(A;; 0x5;;;BA)(A;; 0x7;;;SO)(A;; 0x3;;;IU)(A;; 0x2;;;BA)(A;; 0x2;;;LS)(A;; 0x2;;;NS)
¿¹¸¦ µé¾î, ù ¹øÂ° ACE´Â ·Î±×¿¡ ´ëÇÑ ÀÍ¸í »ç¿ëÀÚÀÇ Àбâ, ¾²±â ¹× Áö¿ì±â ¾×¼¼½º¸¦ °ÅºÎÇÕ´Ï´Ù. ¿©¼¸ ¹øÂ° ACE´Â ´ëÈ­Çü »ç¿ëÀÚ°¡ ·Î±×¸¦ Àаųª ¾²µµ·Ï Çã¿ëÇÕ´Ï´Ù.

·ÎÄà Á¤Ã¥À» ¼öÁ¤ÇÏ¿© À̺¥Æ® ·Î±× º¸¾ÈÀÇ »ç¿ëÀÚ ÁöÁ¤ Çã¿ë

  1. %WinDir%\Inf\Sceregvl.inf ÆÄÀÏÀ» ¾Ë±â ½¬¿î À§Ä¡¿¡ ¹é¾÷ÇÕ´Ï´Ù.
  2. ¸Þ¸ðÀå¿¡¼­ %WinDir%\Inf\Sceregvl.inf¸¦ ¿±´Ï´Ù.
  3. ÆÄÀÏ Áß°£À¸·Î ½ºÅ©·ÑÇÑ ´ÙÀ½ [Strings] ¹Ù·Î ¾Õ¿¡ Æ÷ÀÎÅ͸¦ ³õ½À´Ï´Ù.
  4. ´ÙÀ½ ÁÙÀ» »ðÀÔÇÕ´Ï´Ù.
    MACHINE\System\CurrentControlSet\Services\Eventlog\Application\CustomSD,1,%AppLogSD%,2

    MACHINE\System\CurrentControlSet\Services\Eventlog\System\CustomSD,1,%SysLogSD%,2
  5. ÆÄÀÏ ³¡À¸·Î ½ºÅ©·ÑÇÏ°í ´ÙÀ½ ÁÙÀ» »ðÀÔÇÕ´Ï´Ù.
    AppLogSD="Event log: Specify the security of the application log in Security Descriptor Definition Language (SDDL) syntax"

    SysLogSD="Event log: Specify the security of the System log in Security Descriptor Definition Language (SDDL) syntax"
  6. ÆÄÀÏÀ» ÀúÀåÇÏ°í ´Ý½À´Ï´Ù.
  7. ½ÃÀÛ, ½ÇÇàÀ» Â÷·Ê·Î ´©¸£°í ¿­±â »óÀÚ¿¡ regsvr32 scecli.dllÀ» ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´©¸¨´Ï´Ù.
  8. DllRegisterServer in scecli.dll succeeded ´ëÈ­ »óÀÚ¿¡¼­ È®ÀÎÀ» ´©¸¨´Ï´Ù.

ÄÄÇ»ÅÍÀÇ ·ÎÄà ±×·ì Á¤Ã¥À» »ç¿ëÇÏ¿© ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ½Ã½ºÅÛ ·Î±× º¸¾È ¼³Á¤

  1. ½ÃÀÛ, ½ÇÇàÀ» Â÷·Ê·Î ´©¸£°í gpedit.msc¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.
  2. ±×·ì Á¤Ã¥ ÆíÁý±â¿¡¼­ Windows ¼³Á¤, º¸¾È ¼³Á¤, ·ÎÄà Á¤Ã¥À» Â÷·Ê·Î È®ÀåÇÑ ´ÙÀ½ º¸¾È ¿É¼ÇÀ» È®ÀåÇÕ´Ï´Ù.
  3. À̺¥Æ® ·Î±×: ÀÀ¿ë ÇÁ·Î±×·¥ ·Î±× SDDLÀ» µÎ ¹ø ´©¸£°í ·Î±× º¸¾È¿¡ Ãß°¡ÇÒ SDDL ¹®ÀÚ¿­À» ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.
  4. À̺¥Æ® ·Î±×: ½Ã½ºÅÛ ·Î±× SDDLÀ» µÎ ¹ø ´©¸£°í ·Î±× º¸¾È¿¡ Ãß°¡ÇÒ SDDL ¹®ÀÚ¿­À» ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.

±×·ì Á¤Ã¥À» »ç¿ëÇÏ¿© Active Directory¿¡¼­ µµ¸ÞÀÎ, »çÀÌÆ® ¶Ç´Â Á¶Á÷ ±¸¼º ´ÜÀ§ÀÇ ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ½Ã½ºÅÛ ·Î±× º¸¾È ¼³Á¤

Áß¿ä: ±×·ì Á¤Ã¥ ÆíÁý±â¿¡¼­ ÀÌ ¹®¼­¿¡¼­ ¼³¸íÇÏ´Â ±×·ì Á¤Ã¥ ¼³Á¤À» º¸·Á¸é ¿ì¼± ´ÙÀ½ ´Ü°è¸¦ ¿Ï·áÇÑ ´ÙÀ½ "±×·ì Á¤Ã¥À» »ç¿ëÇÏ¿© ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ½Ã½ºÅÛ ·Î±× º¸¾È ¼³Á¤" ÀýÀ» °è¼ÓÇÕ´Ï´Ù.
  1. ¸Þ¸ðÀå°ú °°Àº ÅØ½ºÆ® ÆíÁý±â¸¦ »ç¿ëÇÏ¿© %Windir%\Inf Æú´õ¿¡ ÀÖ´Â Sceregvl.inf¸¦ ¿±´Ï´Ù.
  2. [Register Registry Values] ¼½¼Ç¿¡ ´ÙÀ½ ÁÙÀ» Ãß°¡ÇÕ´Ï´Ù.
    MACHINE\System\CurrentControlSet\Services\Eventlog\Application\CustomSD,1,%AppCustomSD%,2
    MACHINE\System\CurrentControlSet\Services\Eventlog\Security\CustomSD,1,%SecCustomSD%,2
    MACHINE\System\CurrentControlSet\Services\Eventlog\System\CustomSD,1,%SysCustomSD%,2
    MACHINE\System\CurrentControlSet\Services\Eventlog\Directory Service\CustomSD,1,%DSCustomSD%,2
    MACHINE\System\CurrentControlSet\Services\Eventlog\DNS Server\CustomSD,1,%DNSCustomSD%,2
    MACHINE\System\CurrentControlSet\Services\Eventlog\File Replication Service\CustomSD,1,%FRSCustomSD%,2
  3. [Strings] ¼½¼Ç¿¡ ´ÙÀ½ ÁÙÀ» Ãß°¡ÇÕ´Ï´Ù.
    AppCustomSD="Eventlog: Security descriptor for Application event log"
    SecCustomSD="Eventlog: Security descriptor for Security event log"
    SysCustomSD="Eventlog: Security descriptor for System event log"
    DSCustomSD="Eventlog: Security descriptor for Directory Service event log"
    DNSCustomSD="Eventlog: Security descriptor for DNS Server event log"
    FRSCustomSD="Eventlog: Security descriptor for File Replication Service event log"
  4. Sceregvl.inf ÆÄÀÏ¿¡ º¯°æÇÑ ³»¿ëÀ» ÀúÀåÇÑ ´ÙÀ½ regsvr32 scecli.dll ¸í·ÉÀ» ½ÇÇàÇÕ´Ï´Ù.
  5. Gpedit.msc¸¦ ½ÃÀÛÇÏ°í ´ÙÀ½ Ç׸ñÀ» µÎ ¹ø ´­·¯ È®ÀåÇÕ´Ï´Ù.
    ÄÄÇ»ÅÍ ±¸¼º
    Windows ¼³Á¤
    º¸¾È ¼³Á¤
    ·ÎÄà Á¤Ã¥
    º¸¾È ¿É¼Ç
  6. ¿À¸¥ÂÊ Ã¢¿¡¼­ »õ "Eventlog" ¼³Á¤À» ã½À´Ï´Ù.

±×·ì Á¤Ã¥À» »ç¿ëÇÏ¿© ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ½Ã½ºÅÛ ·Î±× º¸¾È ¼³Á¤

  1. Active Directory »çÀÌÆ® ¹× ¼­ºñ½º ½º³ÀÀÎ ¶Ç´Â Active Directory »ç¿ëÀÚ ¹× ÄÄÇ»ÅÍ ½º³ÀÀο¡¼­ Á¤Ã¥À» ¼³Á¤ÇÒ °³Ã¼¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸¥ ´ÙÀ½ ¼Ó¼ºÀ» ´©¸¨´Ï´Ù.
  2. ±×·ì Á¤Ã¥ ÅÇÀ» ´©¸¨´Ï´Ù.
  3. »õ Á¤Ã¥À» ¸¸µé¾î¾ß ÇÏ´Â °æ¿ì »õ·Î ¸¸µé±â¸¦ ´©¸¥ ´ÙÀ½ Á¤Ã¥ À̸§À» Á¤ÀÇÇÕ´Ï´Ù. ±×·¸Áö ¾ÊÀº °æ¿ì¿¡´Â 5´Ü°è·Î À̵¿ÇÕ´Ï´Ù.
  4. ¿øÇÏ´Â Á¤Ã¥À» ¼±ÅÃÇÑ ´ÙÀ½ ÆíÁýÀ» ´©¸¨´Ï´Ù.

    ·ÎÄà ±×·ì Á¤Ã¥ MMC ½º³ÀÀÎÀÌ ³ªÅ¸³³´Ï´Ù.
  5. ÄÄÇ»ÅÍ ±¸¼º, Windows ¼³Á¤, º¸¾È ¼³Á¤, ·ÎÄà Á¤Ã¥À» Â÷·Ê·Î È®ÀåÇÑ ´ÙÀ½ º¸¾È ¿É¼ÇÀ» ´©¸¨´Ï´Ù.
  6. À̺¥Æ® ·Î±×: ÀÀ¿ë ÇÁ·Î±×·¥ ·Î±× SDDLÀ» µÎ ¹ø ´©¸£°í ·Î±× º¸¾È¿¡ Ãß°¡ÇÒ SDDL ¹®ÀÚ¿­À» ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.
  7. À̺¥Æ® ·Î±×: ½Ã½ºÅÛ ·Î±× SDDLÀ» µÎ ¹ø ´©¸£°í ·Î±× º¸¾È¿¡ Ãß°¡ÇÒ SDDL ¹®ÀÚ¿­À» ÀÔ·ÂÇÑ ´ÙÀ½ È®ÀÎÀ» ´©¸¨´Ï´Ù.


ÂüÁ¶

SDDL ±¸¹®°ú SDDL ¹®ÀÚ¿­À» ±¸¼ºÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
º¸¾È ¼³¸íÀÚ ¹®ÀÚ¿­ Çü½Ä
http://msdn.microsoft.com/library/en-us/secauthz/security/security_descriptor_string_format.asp(¿µ¹®)




Microsoft Á¦Ç° °ü·Ã ±â¼ú Àü¹®°¡µé°ú ¿Â¶óÀÎÀ¸·Î Á¤º¸¸¦ ±³È¯ÇϽ÷Á¸é Microsoft ´º½º ±×·ì¿¡ Âü¿©ÇϽñ⠹ٶø´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 323076 - ¸¶Áö¸· °ËÅä: 2006³â 9¿ù 7ÀÏ ¸ñ¿äÀÏ - ¼öÁ¤: 7.1
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  • Microsoft Windows Server 2003, Standard Edition
Ű¿öµå:?
kbhowtomaster kbmgmtservices KB323076

Çǵå¹é º¸³»±â