Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Кіріспе
Unix-ке ұқсас операциялық жүйелерде парольдерді өзгерту құралы
Tool to change passwords on Unix like OSes
passwd – Unix, Plan 9, Inferno және көптеген Unix-ке ұқсас операциялық жүйелерде пайдаланушының паролін өзгертуге арналған команда. Пайдаланушы енгізген пароль жаңа парольдің хэштелген нұсқасын жасау үшін кілт тудыру функциясынан өтеді, және ол сақталады. Тек хэштелген нұсқа ғана сақталады; қауіпсіздік мақсатында енгізілген пароль сақталмайды. Пайдаланушы жүйеге кірген кезде, кіру процесінде енгізген паролі сол кілт тудыру функциясынан өтеді және алынған хэштелген нұсқа сақталған нұсқамен салыстырылады. Егер хэштер сәйкес келсе, енгізілген пароль дұрыс деп есептеледі және пайдаланушы аутентификацияланады. Теориялық тұрғыдан алғанда, екі әртүрлі пароль бірдей хэшті тудыруы мүмкін. Дегенмен, криптографиялық хэш функциялары бірдей хэшті тудыратын парольді табу өте қиын және іс жүзінде мүмкін емес етіп жасалған, сондықтан егер тудырылған хэш сақталған хэшпен сәйкес келсе, пайдаланушы аутентификацияланады. passwd командасы жергілікті тіркелгілер үшін парольдерді өзгертуге қолданылуы мүмкін, сондай-ақ көптеген жүйелерде NIS, Kerberos немесе LDAP сияқты таратылған аутентификация механизмімен басқарылатын парольдерді өзгертуге де қолданылуы мүмкін.
passwd is a command on Unix, Plan 9, Inferno, and most Unix like operating systems used to change a user's password. The password entered by the user is run through a key derivation function to create a hashed version of the new password, which is saved. Only the hashed version is stored; the entered password is not saved for security reasons. When the user logs on, the password entered by the user during the log on process is run through the same key derivation function and the resulting hashed version is compared with the saved version. If the hashes are identical, the entered password is considered to be correct, and the user is authenticated. In theory, it is possible for two different passwords to produce the same hash. However, cryptographic hash functions are designed in such a way that finding any password that produces the same hash is very difficult and practically infeasible, so if the produced hash matches the stored one, the user can be authenticated. The passwd command may be used to change passwords for local accounts, and on most systems, can also be used to change passwords managed in a distributed authentication mechanism such as NIS, Kerberos, or LDAP.
Тарих
Парольді көлеңдеуге дейін Unix пайдаланушысының хэштелген паролі /etc/passwd файлында (жоғарыда сипатталғандай, жеті өрісті форматта) олардың жазбасының екінші өрісінде сақталған. Парольді көлеңдеу Unix жүйелерінде алғаш рет 1980-ші жылдардың ортасында SunOS, 1988 жылы System V Release 3.2 және 1990 жылы BSD4.3 Reno әзірленген кезде пайда болды. Бірақ, UNIX-тің бұрынғы нұсқаларын порттаған өндірушілер әрқашан жаңа парольді көлеңдеу мүмкіндіктерін өз нұсқаларына қоспады, бұл сол жүйелердің пайдаланушыларын пароль файлдарына шабуылдарға осал қалдырды. Жүйе әкімшілері парольдерді әрбір қосылған жүйедегі файлдардың орнына NIS және LDAP сияқты таратылған деректер базасында сақтауға да мүмкіндік береді. NIS жағдайында көлеңкелі пароль механизмі көбінесе NIS серверлерінде қолданылады; ал басқа таратылған механизмдерде әртүрлі пайдаланушы аутентификациясы компоненттеріне қол жеткізу мәселесі негізгі деректер қоймасының қауіпсіздік механизмдерімен шешіледі. 1987 жылы түпнұсқа Shadow Password Suite авторы Джули Хоу компьютерлік бұзушылыққа ұшырады және login, passwd және su командаларын қамтитын Shadow Suite-тің бастапқы нұсқасын жазды. SCO Xenix операциялық жүйесі үшін жазылған бастапқы нұсқа тез арада басқа платформаларға портталды. Shadow Suite 1992 жылы Linux жобасының алғашқы жариялануынан бір жыл өткен соң Linux-қа портталды және көптеген ерте дистрибутивтерге қосылды, сондай-ақ көптеген қазіргі Linux дистрибутивтерінде де қолданылуда. Бұрын, әртүрлі аутентификация схемаларында парольді өзгерту үшін әртүрлі командалар қажет болатын. Мысалы, NIS паролін өзгерту үшін yppasswd командасы қолданылды. Бұл пайдаланушылардан әртүрлі жүйелер үшін парольді өзгертудің әртүрлі әдістерін білуді талап етті, сонымен қатар әртүрлі бағдарламаларда бірдей функцияларды орындайтын кодты қайталауға әкелді. Көптеген іске асыруларда қазір бір ғана passwd командасы бар, ал парольдің нақты қайда өзгертілетіні плагиндік аутентификация модульдері (PAM) арқылы пайдаланушыға көрінбейтін түрде басқарылады. Мысалы, қолданылатын хэш түрі pam unix.so модулінің конфигурациясымен анықталады. Дәстүрлі түрде MD5 хэші қолданылып келді, ал қазіргі модульдер blowfish, SHA256 және SHA512 сияқты күштірек хэштерді де қолдайды.
Prior to password shadowing, a Unix user's hashed password was stored in the second field of their record in the /etc/passwd file (within the seven field format as outlined above). Password shadowing first appeared in Unix systems with the development of SunOS in the mid 1980s, System V Release 3.2 in 1988 and BSD4.3 Reno in 1990. But, vendors who had performed ports from earlier UNIX releases did not always include the new password shadowing features in their releases, leaving users of those systems exposed to password file attacks. System administrators may also arrange for the storage of passwords in distributed databases such as NIS and LDAP, rather than in files on each connected system. In the case of NIS, the shadow password mechanism is often still used on the NIS servers; in other distributed mechanisms the problem of access to the various user authentication components is handled by the security mechanisms of the underlying data repository. In 1987, the author of the original Shadow Password Suite, Julie Haugh, experienced a computer break in and wrote the initial release of the Shadow Suite containing the login, passwd and su commands. The original release, written for the SCO Xenix operating system, quickly got ported to other platforms. The Shadow Suite was ported to Linux in 1992 one year after the original announcement of the Linux project, and was included in many early distributions, and continues to be included in many current Linux distributions. In the past, it was necessary to have different commands to change passwords in different authentication schemes. For example, the command to change a NIS password was yppasswd. This required users to be aware of the different methods to change passwords for different systems, and also resulted in wasteful duplication of code in the various programs that performed the same functions with different back ends. In most implementations, there is now a single passwd command, and the control of where the password is actually changed is handled transparently to the user via pluggable authentication modules (PAMs). For example, the type of hash used is dictated by the configuration of the pam unix. so module. By default, the MD5 hash has been used, while current modules are also capable of stronger hashes such as blowfish, SHA256 and SHA512.