Cloud Engineering/Linux ๐Ÿง

[Linux] POSIX ACL ์„ค์ •ํ•˜๊ธฐ - ์ผ๋ฐ˜ ACL ์„ค์ •

minjiwoo 2023. 1. 3. 18:01
728x90

 

๋ณดํ†ต ์ „ํ†ต์ ์œผ๋กœ ๋ฆฌ๋ˆ…์Šค์—์„œ ์‚ฌ์šฉํ•˜๋Š” ํผ๋ฏธ์…˜ (permision)์€ ์šฐ๋ฆฌ์—๊ฒŒ ์ต์ˆ™ํ•œ drwxrwxr-x ์ด๋Ÿฌํ•œ ํ˜•ํƒœ๋กœ ํ™•์ธ์ด ๋œ๋‹ค. 
๊ทธ๋Ÿฐ๋ฐ ์ „ํ†ต์ ์ธ ํผ๋ฏธ์…˜์œผ๋กœ๋Š” others ์— ํ•ด๋‹นํ•˜๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ๊ถŒํ•œ์„ ์„ธ๋ถ€์ ์œผ๋กœ ์ฃผ๋Š” ๊ฒƒ์— ํ•œ๊ณ„๊ฐ€ ์žˆ๋‹ค. 
์ด๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ๊ฒƒ์ด posix ACL์ด๋‹ค. 

1. ํŒŒ์ผ์— posix acl ๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ช…๋ น์–ด 

setfacl [OPTION] FILE


๋ช…๋ น์–ด) setfacl -m u:user01:rw userfile3 
ํŠน์ • ์œ ์ € (=user01)์—๊ฒŒ userfile3 ๋ผ๋Š” ํŒŒ์ผ์— ๋Œ€ํ•ด read write๋ฅผ ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ๋ถ€์—ฌ. 

์ฃผ์˜ํ•ด์•ผ ํ•  ์ ์€, POSIX ACL๋กœ ๊ถŒํ•œ์„ ์„ค์ •ํ•œ ์ดํ›„์— ์ผ๋ฐ˜ ํผ๋ฏธ์…˜ (chmod ๊ฐ™์€ ๋ช…๋ น์–ด) ์„ ์ฃผ๋ฉด ์ถฉ๋Œ์ด ์ผ์–ด๋‚  ์ˆ˜๋„ ์žˆ๋‹ค. rmission์—์„œ ์‚ฌ์šฉ๋˜๋Š” ํ•„๋“œ ์ผ๋ถ€๊ฐ€ POSIX ACL ์—์„œ๋Š” ๋‹ค๋ฅธ ์˜๋ฏธ๋กœ ์‚ฌ์šฉ๋˜๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค. ๊ทธ๋Ÿฌ๋‹ˆ POSIX ACL๋กœ ๊ถŒํ•œ์„ ์„ค์ •ํ•œ ํ›„์—๋Š” ๊ณ„์† POSIX ACL๋กœ ์„ค์ •ํ•˜์ž 

2. ํŒŒ์ผ์— ์ ์šฉ๋œ posix acl ์„ ํ™•์ธํ•˜๋Š” ๋ช…๋ น์–ด 

getfacl FILE


๋ช…๋ น์–ด) getfacl userfile1 
๊ฒฐ๊ณผ)
file: userfile1
owner: user
group: user
user::rw- user:user01:rw- group::rw- mask::rw- other::r--

3. ACL_ENTRY options 

u:: PERMS
u:USER:PERMS →ํŠน์ • ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด ACL entry๋ฅผ ์ง€์ •ํ•˜๋Š” ๊ฒƒ
g::PERMS
g:GROUP:PERMS
o:PERMS

4. ACL ์ข…๋ฅ˜

์ผ๋ฐ˜ ACL: ๊ฐœ๋ณ„ ํŒŒ์ผ / ๋””๋ ‰ํ† ๋ฆฌ์— ์ ์šฉํ•˜๋Š” ACL

๊ธฐ๋ณธ ACL (default ACL): ๋””๋ ‰ํ† ๋ฆฌ์—๋งŒ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ACL๋กœ ํ•˜์œ„ ํŒŒ์ผ์— ACL๋ฅผ ์ƒ์†ํ•จ.


5. ์ผ๋ฐ˜ ACL

(์ผ๋ฐ˜ ACL) ACL ENTRY ๊ฐœ๋ณ„ ์—”ํŠธ๋ฆฌ ์‚ญ์ œ

setfacl -x ACL_ENTRY FILE

[user@localhost dir3]$ setfacl -x g:user02 userfile3
user02 ์— ๋Œ€ํ•ด userfile3 ์— ๋Œ€ํ•œ ๊ถŒํ•œ์„ ์‚ญ์ œํ•œ๋‹ค. 

(์ผ๋ฐ˜ ACL) ACL ENTRY ๋ชจ๋‘ ์‚ญ์ œ

setfacl -b FILE

[user@localhost dir3]$ setfacl -b userfile3 
userfile3์— ์„ค์ •๋˜์—ˆ๋˜ ๋ชจ๋“  ACL ๋“ค์ด ์‚ญ์ œ๋œ๋‹ค ! -> ์ดํ›„์—๋Š” ๊ธฐ๋ณธ ํผ๋ฏธ์…˜์„ ์‚ฌ์šฉํ•ด๋„ ๊ดœ์ฐฎ์„ ๊ฒƒ์ด๋‹ค. 

(์ผ๋ฐ˜ ACL) ACL mask ์„ค์ •

setfacl -m m::PERMS FILE

 

 

728x90