Docs Menu

mongokerberos

์ด ํŽ˜์ด์ง€์˜ ๋‚ด์šฉ

MongoDB Enterprise ๋Š” mongokerberos MongoDB Kerberos ์‹คํ–‰ Kerberos ๋ฐฐํฌ์„œ๋ฒ„ ์— ๋Œ€ํ•ด ์˜ ๋ฐ GSSAPI ๊ตฌ์„ฑ ์˜ต์…˜ ์„ ํ…Œ์ŠคํŠธํ•˜๊ธฐ ์œ„ํ•ด ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. mongokerberos ์€(๋Š”) ์„œ๋ฒ„ ๋ฐ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์ค‘ ํ•˜๋‚˜๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“œ
์„ค๋ช…

์„œ๋ฒ„

์„œ๋ฒ„ ๋ชจ๋“œ ์—์„œ ๋Š” ์„œ๋ฒ„ ์˜ Kerberos ๊ด€๋ จ ๊ตฌ์„ฑ์„ ๋ถ„์„ํ•˜๊ณ  ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” ๋ชจ๋“  ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€๊ฐ€ ํฌํ•จ๋œ ๋ณด๊ณ ์„œ๋ฅผmongokerberos ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ๋ฒ•์€ ์„œ๋ฒ„ ๋ชจ๋“œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

๊ณ ๊ฐ

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์—์„œ ๋Š”mongokerberos ์ œ๊ณต๋œ ์‚ฌ์šฉ์ž ์ด๋ฆ„ ์— ๋Œ€ํ•ด Kerberos ์ธ์ฆ ํ…Œ์ŠคํŠธํ•˜๊ณ  Kerberos ์ธ์ฆ ์ ˆ์ฐจ์˜ ๊ฐ ๋‹จ๊ณ„์˜ ์„ฑ๊ณต ๋˜๋Š” ์‹คํŒจ๊ฐ€ ํฌํ•จ๋œ ๋ณด๊ณ ์„œ๋ฅผ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ๋ฒ•์€ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

๋‘ ๋ชจ๋“œ์— ๋Œ€ํ•œ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€์—๋Š” ๋ฐœ์ƒํ•œ ํŠน์ • ์˜ค๋ฅ˜์— ๋Œ€ํ•œ ์ •๋ณด์™€ ์˜ค๋ฅ˜ ํ•ด๊ฒฐ์„ ์œ„ํ•œ ์ž ์žฌ์ ์ธ ์กฐ์–ธ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

mongokerberos ์„œ๋ฒ„ ๋ชจ๋“œ์™€ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ๋ชจ๋‘์—์„œ ๋‹ค์Œ ๋ฐฐํฌ ์œ ํ˜•์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ๊ณ 

MongoDB Enterprise ๋ฐ ๋Š” mongokerberos MIT ๊ตฌํ˜„ ๋งŒ ์ง€์› Kerberos ํ•ฉ๋‹ˆ๋‹ค. ์˜ .

์ผ๋ฐ˜์ ์œผ๋กœ Kerberos ์ธ์ฆ ๊ณผ ๊ด€๋ จ๋œ ์˜ต์…˜์„ ๊ตฌ์„ฑํ•  ๋•Œ๋Š” mongokerberos ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ตฌ์„ฑ์„ ํ™•์ธํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

mongokerberos ์€(๋Š”) ํ…Œ์ŠคํŠธ ๋ฐ ๊ฒ€์ฆ ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. ํŒŒ์ผ์„ ํŽธ์ง‘ํ•˜๊ฑฐ๋‚˜ ์„œ๋น„์Šค๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ”Œ๋žซํผ์—์„œ Kerberos๋ฅผ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด MIT Kerberos ์„ค๋ช…์„œ ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”. ๋˜๋Š” ํ•ด๋‹น ํ”Œ๋žซํผ์˜ ์„ค๋ช…์„œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”. Kerberos๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆํ•˜๋„๋ก MongoDB๋ฅผ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ๋‹ค์Œ ํŠœํ† ๋ฆฌ์–ผ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์ด ๋ฌธ์„œ์—์„œ๋Š” mongokerberos ์— ๋Œ€ํ•œ ๋ชจ๋“  ๋ช…๋ น์ค„ ์˜ต์…˜์— ๋Œ€ํ•œ ์ „์ฒด ๊ฐœ์š”๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

mongokerberos ๋„๊ตฌ๋Š” MongoDB database ๋„๊ตฌ ์ถ”๊ฐ€ ํŒจํ‚ค์ง€์˜ ์ผ๋ถ€์ด๋ฉฐ, MongoDB Server์™€ ํ•จ๊ป˜ ๋˜๋Š” ๋…๋ฆฝํ˜• ์„ค์น˜๋กœ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

MongoDB Server ์„ค์น˜์˜ ์ผ๋ถ€๋กœ ์„(๋ฅผ) ์„ค์น˜ํ•˜๋ ค๋ฉด mongokerberos MongoDB Enterprise ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

  • ํ”Œ๋žซํผ์— ๋งž๋Š” ์ง€์นจ์„ ๋”ฐ๋ฅด์„ธ์š”: MongoDB Enterprise MongoDB Server ์„ค์น˜

  • ์„ค์น˜๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด mongokerberos ๋ฐ ๊ธฐํƒ€ ํฌํ•จ๋œ ๋„๊ตฌ๋ฅผ MongoDB Server์™€ ๋™์ผํ•œ ์œ„์น˜์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    ์ฐธ๊ณ 

    Windows .msi ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ ๋งˆ๋ฒ•์‚ฌ์˜ ๊ฒฝ์šฐ Complete ์„ค์น˜ ์˜ต์…˜์—๋Š” mongokerberos ๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

mongokerberos ๋ฅผ ๋…๋ฆฝํ˜• ์„ค์น˜๋กœ ์„ค์น˜ํ•˜๋ ค๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

  • MongoDB Enterprise ๋‹ค์šด๋กœ๋“œ ๋งํฌ๋ฅผ ๋”ฐ๋ผ๊ฐ€์„ธ์š”: MongoDB Enterprise ๋‹ค์šด๋กœ๋“œ ์„ผํ„ฐ

  • ๋“œ๋กญ๋‹ค์šด ๋ฉ”๋‰ด์—์„œ Platform (์šด์˜ ์ฒด์ œ)๋ฅผ ์„ ํƒํ•œ ๋‹ค์Œ, ๋‹ค์Œ ์ฐจํŠธ์— ๋”ฐ๋ผ ํ”Œ๋žซํผ์— ์ ํ•ฉํ•œ Package ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    OS
    ํŒจํ‚ค์ง€

    Linux

    tgz ํŒจํ‚ค์ง€

    Windows

    zip ํŒจํ‚ค์ง€

    macOS

    tgz ํŒจํ‚ค์ง€

  • ๋‹ค์šด๋กœ๋“œ๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด ์•„์นด์ด๋ธŒ์˜ ์••์ถ•์„ ํ’€๊ณ  mongokerberos ๋ฅผ ํ•˜๋“œ ๋“œ๋ผ์ด๋ธŒ์˜ ์œ„์น˜์— ๋ณต์‚ฌํ•ฉ๋‹ˆ๋‹ค.

    ํŒ

    Linux ๋ฐ macOS ์‚ฌ์šฉ์ž๋Š” mongokerberos ๋ฅผ $PATH ํ™˜๊ฒฝ ๋ณ€์ˆ˜์— ์ •์˜๋œ ํŒŒ์ผ ์‹œ์Šคํ…œ ์œ„์น˜(์˜ˆ: /usr/bin)์— ๋ณต์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ํ•˜๋ฉด ์ „์ฒด ๊ฒฝ๋กœ๋ฅผ ์ง€์ •ํ•˜๊ฑฐ๋‚˜ ๋จผ์ € ์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ด๋™ํ•˜์ง€ ์•Š๊ณ ๋„ ๋ช…๋ น์ค„์—์„œ mongokerberos ๋ฅผ ์ด๋ฆ„์œผ๋กœ ์ง์ ‘ ์ฐธ์กฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ํ•ด๋‹น ํ”Œ๋žซํผ์˜ ์„ค์น˜ ๊ฐ€์ด๋“œ ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

mongokerberos ๋Š” ์„œ๋ฒ„ ๋ฐ ํด๋ผ์ด์–ธํŠธ ์˜ ๋‘ ๊ฐ€์ง€ ๋ชจ๋“œ๋กœ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

mongosh๊ฐ€ ์•„๋‹Œ ์‹œ์Šคํ…œ ๋ช…๋ น์ค„์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ .

์„œ๋ฒ„ ๋ชจ๋“œ ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ์ ์ ˆํ•œ DNS ํ™•์ธ ํ™•์ธ, Kerberos ์‹œ์Šคํ…œ ํ‚คํƒญ ํŒŒ์ผ ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ , mongod ๋˜๋Š” mongos ์— ๋Œ€ํ•œ MongoDB ์„œ๋น„์Šค ์ฃผ์ฒด์— ๋Œ€ํ•œ ํ…Œ์ŠคํŠธ ๋“ฑ ์‹œ์Šคํ…œ์˜ Kerberos ๊ตฌ์„ฑ์— ๋Œ€ํ•ด ์ผ๋ จ์˜ ํ™•์ธ ๋‹จ๊ณ„๊ฐ€ ์ˆ˜ํ–‰๋ฉ๋‹ˆ๋‹ค. ์ธ์Šคํ„ด์Šค.

์„œ๋ฒ„ ๋ชจ๋“œ์—์„œ mongokerberos ๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๋จผ์ € ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  1. ํ”Œ๋žซํผ์˜ ์„ค๋ช…์„œ์— ๋”ฐ๋ผ ํ”Œ๋žซํผ์—์„œ Kerberos ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

  2. ๋‹ค์Œ ๋‹จ๊ณ„์— ์„ค๋ช…๋œ ๋Œ€๋กœ mongod ๋˜๋Š” mongos ์ธ์Šคํ„ด์Šค ์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  MongoDB ์„œ๋น„์Šค ์ฃผ์ฒด๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

์ด ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด --server ํ”Œ๋ž˜๊ทธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„ ๋ชจ๋“œ ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

mongokerberos --server

์„œ๋ฒ„ ์— Kerberos ๊ฐ€ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ตฌ์„ฑ๋˜๊ณ  ์„œ๋น„์Šค ์ฃผ์ฒด๊ฐ€ ์„ฑ๊ณต์ ์œผ๋กœ ์ƒ์„ฑ๋œ ๊ฒฝ์šฐ ์ถœ๋ ฅ์€ ๋‹ค์Œ๊ณผ ์œ ์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Resolving kerberos environment...
[OK] Kerberos environment resolved without errors.
Verifying DNS resolution works with Kerberos service at <hostname>...
[OK] DNS test successful.
Getting MIT Kerberos KRB5 environment variables...
* KRB5CCNAME: not set.
* KRB5_CLIENT_KTNAME: not set.
* KRB5_CONFIG: not set.
* KRB5_KTNAME: not set.
* KRB5_TRACE: not set.
[OK]
Verifying existence of KRB5 keytab FILE:/etc/krb5.keytab...
[OK] KRB5 keytab exists and is populated.
Checking principal(s) in KRB5 keytab...
Found the following principals for MongoDB service mongodb:
* mongodb/server.example.com@SERVER.EXAMPLE.COM
Found the following kvnos in keytab entries for service mongodb:
* 3
[OK] KRB5 keytab is valid.
Fetching KRB5 Config...
KRB5 config profile resolved as:
<Your Kerberos profile file will be output here>
[OK] KRB5 config profile resolved without errors.
Attempting to initiate security context with service credentials...
[OK] Security context initiated successfully.

๋งˆ์ง€๋ง‰ ๋ฉ”์‹œ์ง€๋Š” ์‹œ์Šคํ…œ์˜ Kerberos ๊ตฌ์„ฑ์„ MongoDB ์—์„œ ์‚ฌ์šฉํ•  ์ค€๋น„๊ฐ€ ๋˜์—ˆ์Œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ๊ตฌ์„ฑ์— ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด ์œ„ ์ถœ๋ ฅ์˜ ์ผ๋ถ€๋กœ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ์‹œ์Šคํ…œ์˜ Kerberos ํ™˜๊ฒฝ์— ๋Œ€ํ•œ ์ธ์ฆ์„ ํ…Œ์ŠคํŠธํ•˜๊ณ , ์ ์ ˆํ•œ DNS ํ™•์ธ ํ™•์ธ, Kerberos ํด๋ผ์ด์–ธํŠธ ํ‚คํƒญ ํŒŒ์ผ ํ™•์ธ, ํ‹ฐ์ผ“์ด ์„ฑ๊ณต์ ์œผ๋กœ ๋ถ€์—ฌ๋  ์ˆ˜ ์žˆ๋Š”์ง€ ํ…Œ์ŠคํŠธ ๋“ฑ Kerberos ์ธ์ฆ ํ”„๋กœ์„ธ์Šค์˜ ๊ฐ ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด mongosh ์˜ ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ ์ ˆ์ฐจ๋ฅผ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ํ•ฉ๋‹ˆ๋‹ค.

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์—์„œ mongokerberos ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๋จผ์ € ํ”Œ๋žซํผ์˜ ์„ค๋ช…์„œ์— ๋”ฐ๋ผ ํ”Œ๋žซํผ์— Kerberos ๋ฅผ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์„ ํƒ ์‚ฌํ•ญ์œผ๋กœ,mongokerberos ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์ „์— ๋จผ์ € ์„œ๋ฒ„ ๋ชจ๋“œ ์—์„œ ๋ฅผ ์‹คํ–‰ ํ•˜์—ฌ ํ”Œ๋žซํผ์˜ Kerberos ๊ตฌ์„ฑ์ด ์œ ํšจํ•œ์ง€ ํ™•์ธํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•œ ํ›„์—๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด --client ํ”Œ๋ž˜๊ทธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ ํ•˜์—ฌ ์‚ฌ์šฉ์ž ์ธ์ฆ ์„ ํ…Œ์ŠคํŠธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

mongokerberos --client --username <username>

์ธ์ฆ ์ ˆ์ฐจ์˜ ์ผ๋ถ€๋กœ Kerberos ํ‹ฐ์ผ“์„ ์š”์ฒญํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์œ ํšจํ•œ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ์ œ๊ณตํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ”Œ๋žซํผ์˜ Kerberos ์ธํ”„๋ผ๋Š” ์ด ์‚ฌ์šฉ์ž๋ฅผ ์•Œ๊ณ  ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ œ๊ณต๋œ ์ž๊ฒฉ ์ฆ๋ช… ์ด ์œ ํšจํ•˜๊ณ  ๊ตฌ์„ฑ ํŒŒ์ผ์˜ Kerberos ์˜ต์…˜์ด ์œ ํšจํ•œ ๊ฒฝ์šฐ ์ถœ๋ ฅ์€ ๋‹ค์Œ๊ณผ ์œ ์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Resolving kerberos environment...
[OK] Kerberos environment resolved without errors.
Verifying DNS resolution works with Kerberos service at <hostname>...
[OK] DNS test successful.
Getting MIT Kerberos KRB5 environment variables...
* KRB5CCNAME: not set.
* KRB5_CLIENT_KTNAME: not set.
* KRB5_CONFIG: not set.
* KRB5_KTNAME: not set.
* KRB5_TRACE: not set.
[OK]
Verifying existence of KRB5 client keytab FILE:/path/to/client.keytab...
[OK] KRB5 client keytab exists and is populated.
Checking principal(s) in KRB5 keytab...
[OK] KRB5 keytab is valid.
Fetching KRB5 Config...
KRB5 config profile resolved as:
<Your Kerberos profile file will be output here>
[OK] KRB5 config profile resolved without errors.
Attempting client half of GSSAPI conversation...
[OK] Client half of GSSAPI conversation completed successfully.

์ตœ์ข… ๋ฉ”์‹œ์ง€๋Š” ์ œ๊ณต๋œ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ์ด ์„ฑ๊ณต์ ์œผ๋กœ ์™„๋ฃŒ๋˜์—ˆ์Œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์ธ์ฆ ๋‹จ๊ณ„ ์ค‘์— ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด ์œ„ ์ถœ๋ ฅ์˜ ์ผ๋ถ€๋กœ ์˜ค๋ฅ˜๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

--server

์„œ๋ฒ„ ๋ชจ๋“œ ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ํ”Œ๋žซํผ์˜ Kerberos ๊ตฌ์„ฑ์ด MongoDB ์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•˜๊ธฐ์— ์œ ํšจํ•œ์ง€ ํ…Œ์ŠคํŠธํ•ฉ๋‹ˆ๋‹ค.

์‚ฌ์šฉ ์˜ˆ์‹œ ๋ฐ ์˜ˆ์ƒ ์ถœ๋ ฅ์€ ์„œ๋ฒ„ ๋ชจ๋“œ ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

--client

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์‹œ์Šคํ…œ์˜ Kerberos ํ™˜๊ฒฝ์— ๋Œ€ํ•ด ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ ์„ ํ…Œ์ŠคํŠธํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์—์„œ ์‹คํ–‰ ๋•Œ --username ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์œ ํšจํ•œ ์‚ฌ์šฉ์ž ์ด๋ฆ„ ์„ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. mongokerberos ๋Š” ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ์ ˆ์ฐจ์˜ ์ผํ™˜์œผ๋กœ ์ด ์‚ฌ์šฉ์ž ์ด๋ฆ„ ์— ๋Œ€ํ•œ Kerberos ํ‹ฐ์ผ“ ์„ ์š”์ฒญ ํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ์—์„œ mongokerberos ๋ฅผ ์‹คํ–‰ํ•˜๋ฉดmongosh์˜ ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ ์ ˆ์ฐจ๋ฅผ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ํ•ฉ๋‹ˆ๋‹ค

์‚ฌ์šฉ ์˜ˆ์‹œ ๋ฐ ์˜ˆ์ƒ ์ถœ๋ ฅ์€ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

--config <filename>, -f <filename>

๋Ÿฐํƒ€์ž„ ๊ตฌ์„ฑ ์˜ต์…˜์— ๋Œ€ํ•œ ๊ตฌ์„ฑ ํŒŒ์ผ ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค. ์˜ต์…˜์€ ๋ช…๋ น์ค„ ๊ตฌ์„ฑ ์˜ต์…˜๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ž์ฒด ๊ด€๋ฆฌํ˜• ๊ตฌ์„ฑ ํŒŒ์ผ ์˜ต์…˜ ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

mongokerberos ๋Š” ์ด ํŒŒ์ผ์—์„œ saslHostName ๋ฐ saslServiceName ์— ๋Œ€ํ•œ ๊ฐ’์„ ์ฝ์Šต๋‹ˆ๋‹ค(์žˆ๋Š” ๊ฒฝ์šฐ). ์ด๋Ÿฌํ•œ ๊ฐ’์€ ๋Œ€์‹  --setParameter ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ๋Œ€์‹  ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ตฌ์„ฑ ํŒŒ์ผ์ด ASCII ์ธ์ฝ”๋”ฉ์„ ์‚ฌ์šฉํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. mongokerberos ์ธ์Šคํ„ด์Šค๋Š” UTF-8 ๋ฅผ ํฌํ•จํ•˜์—ฌ ASCII๊ฐ€ ์•„๋‹Œ ์ธ์ฝ”๋”ฉ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ตฌ์„ฑ ํŒŒ์ผ์„ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์„œ๋ฒ„ ๋ชจ๋“œ์—์„œ๋งŒ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค.

--setParameter <options>

๊ตฌ์„ฑ ๊ฐ€๋Šฅํ•œ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ setParameter ํ•„๋“œ๋ฅผ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ง€์›๋˜๋Š” ๋ชจ๋“  ๋งค๊ฐœ ๋ณ€์ˆ˜๋ฅผ setParameter ๊ณผ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์ง€๋งŒ mongokerberos ๋Š” ๋‹ค์Œ ๊ฐ’๋งŒ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ๊ฐ’๋„ ํฌํ•จํ•˜๋Š” ๊ตฌ์„ฑ ํŒŒ์ผ ์— --config ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ setParameter ๊ฐ’์ด ๊ตฌ์„ฑ ํŒŒ์ผ ์˜ ๊ฐ’์„ ์žฌ์ •์˜ํ•ฉ๋‹ˆ๋‹ค.

์„œ๋ฒ„ ๋ชจ๋“œ ์™€ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ ๋ชจ๋‘์—์„œ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค.

--host <hostname>

์ธ์ฆ์„ ํ…Œ์ŠคํŠธํ•  ๋•Œ ์—ฐ๊ฒฐํ•  MongoDB ์„œ๋ฒ„์˜ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

--host ์„(๋ฅผ) ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด mongokerberos ์€(๋Š”) ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์˜ DNS ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ๋ฅผ ์ˆ˜ํ–‰ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค(์ฆ‰, PTR ๊ธฐ๋ก ํ™•์ธ)

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ๋งŒ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค.

--username <username>, -u <username>

Kerberos ์ธ์ฆ์„ ์‹œ๋„ํ•  ๋•Œ ์‚ฌ์šฉํ•  mongokerberos ์˜ ์‚ฌ์šฉ์ž ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์ด ๊ฐ’์€ ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ ์‹คํ–‰ํ•  ๋•Œ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ๋งŒ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค.

--gssapiServiceName <servicename>

๊ธฐ๋ณธ๊ฐ’: 'MongoDB '

GSSAPI/Kerberos๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆํ•  ๋•Œ ์‚ฌ์šฉํ•  ์„œ๋น„์Šค ์ฃผ์ฒด ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ๋งŒ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค.

--gssapiHostName <hostname>

GSSAPI/ Kerberos ์ธ์ฆ ์— ์‚ฌ์šฉํ•  ์›๊ฒฉ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.

ํด๋ผ์ด์–ธํŠธ ๋ชจ๋“œ์—์„œ๋งŒ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€์˜ ๋‚ด์šฉ