| 両方とも前のリビジョン 前のリビジョン 次のリビジョン | 前のリビジョン |
| ja:documentation:pandorafms:cybersecurity:07_safety_functions [2026/07/25 21:44] – [Active Directory] junichi | ja:documentation:pandorafms:cybersecurity:07_safety_functions [2026/09/11 23:15] (現在) – [ユーザパスワードポリシー] junichi |
|---|
| * <wrap :en>**Login attribute**</wrap> and <wrap :en>**Secondary Login attribute**</wrap>: Both fields are case sensitive. | * <wrap :en>**Login attribute**</wrap> and <wrap :en>**Secondary Login attribute**</wrap>: Both fields are case sensitive. |
| * <wrap :en>**Fallback to local authentication**</wrap>: Should this option be enabled, [[#ks1_1|local authentication]] will be performed if LDAP fails. Administrator users will always have //fallback// enabled, in order not to lose access to Pandora FMS in case of remote authentication system failure. | * <wrap :en>**Fallback to local authentication**</wrap>: Should this option be enabled, [[#ks1_1|local authentication]] will be performed if LDAP fails. Administrator users will always have //fallback// enabled, in order not to lose access to Pandora FMS in case of remote authentication system failure. |
| * <wrap :en>**Automatically create remote users**</wrap>: It enables or disables remote user automatic creation. This option allows Pandora FMS to create the users automatically once they have logged in (//login//) using LDAP. | * <wrap :en>**Automatically create remote users**</wrap>: This option enables Pandora FMS to automatically create remote users once they have logged in using LDAP. If this feature is enabled, the //token// <wrap :en>**Save Password**</wrap> will be available to save LDAP passwords in the local Pandora FMS database. //If// <wrap :en>**Fallback to local authentication**</wrap> //was previously enabled, then// <wrap :en>**Save Password**</wrap> //will also be enabled//. \\ \\ |
| * <wrap :en>**LDAP function**</wrap>: When searching LDAP, you may choose whether to use the native PHP function or the local ''ldapsearch'' command. It is recommended to use the local command for those environments that have an LDAP with many elements. | * <wrap :en>**LDAP function**</wrap>: When searching LDAP, you may choose whether to use the native PHP function or the local ''ldapsearch'' command. It is recommended to use the local command for those environments that have an LDAP with many elements. |
| |
| * **ログインアトリビュート(Login attribute)** および **セカンダリログインアトリビュート(Secondary Login attribute)**: どちらのフィールドも大文字と小文字が区別されます。 | * **ログインアトリビュート(Login attribute)** および **セカンダリログインアトリビュート(Secondary Login attribute)**: どちらのフィールドも大文字と小文字が区別されます。 |
| * **ローカル認証にフォールバック(Fallback to local Authentication)**: このオプションを有効にすると、LDAPリモート認証が失敗した場合に、ローカル認証にフォールバックします。管理者ユーザは、リモート認証システムに障害が発生した場合でも Pandora FMS へのアクセスを失わないように、常にフォールバックが有効になります。 | * **ローカル認証にフォールバック(Fallback to local Authentication)**: このオプションを有効にすると、LDAPリモート認証が失敗した場合に、ローカル認証にフォールバックします。管理者ユーザは、リモート認証システムに障害が発生した場合でも Pandora FMS へのアクセスを失わないように、常にフォールバックが有効になります。 |
| * **リモートユーザの自動作成(Autocreate remote users)**: リモートユーザの自動作成を有効化/無効化します。このオプションで、LDAP を使ってログインしたユーザを自動的に作成できます。 | * **リモートユーザの自動作成(Autocreate remote users)**: このオプションを有効にすると、LDAP を使用してログインしたリモートユーザを Pandora FMS が自動的に作成できるようになります。この機能が有効な場合、LDAP パスワードを Pandora FMS のローカルデータベースに保存するための「パスワードを保存 (Save Password)」機能が利用可能になります。なお、「ローカル認証へのフォールバック (Fallback to local authentication)」が以前に有効化されていた場合、「パスワードを保存」機能も有効になります。 |
| * **LDAP 機能(LDAP function)**: LDAP を検索するときに、PHP のネイティブ機能を使うか **ldapsearch** コマンドを使うかを選択できます。LDAP に多くの要素がある環境では、ローカルコマンドを利用することをお勧めします。 | * **LDAP 機能(LDAP function)**: LDAP を検索するときに、PHP のネイティブ機能を使うか **ldapsearch** コマンドを使うかを選択できます。LDAP に多くの要素がある環境では、ローカルコマンドを利用することをお勧めします。 |
| |
| ==== 二段階認証 ==== | ==== 二段階認証 ==== |
| |
| To use this feature the administrator must activate double authentication in the authentication section of Pandora FMS Web Console global configuration: | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%><wrap :en>**Management → Settings → System Settings → Authentication → Double authentication**</wrap> menu.</WRAP> |
| | </WRAP> |
| | <WRAP half column>To use this feature, the administrator must activate double authentication in the authentication section of the Pandora FMS Web Console global setup. |
| | </WRAP> |
| | </WRAP> |
| |
| この機能を使用するには、管理者は Pandora FMS Web コンソールのグローバル設定の認証セクションで二段階認証を有効にする必要があります。 | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%>**管理(Management) → セットアップ(Settings) → システム設定(System Settings) → 認証(Authentication) → 二段階認証(Double authentication)**</wrap> メニュー。</WRAP> |
| | </WRAP> |
| | <WRAP half column>この機能を使用するには、管理者が Pandora FMS Web コンソールのグローバル設定にある「認証」セクションで、二段階認証を有効にする必要があります。 |
| | </WRAP> |
| | </WRAP> |
| |
| <wrap :en>**Management → Settings → System Settings → Authentication → Double authentication**</wrap>. | Users will be able to choose whether to enable //two-step authentication// on their accounts by accessing the [[:en:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_1_1|Edit my user]] option. |
| |
| <wrap :ja>**管理(Management) → セットアップ(Settings) → システム設定(System Settings) → 認証(Authentication) → 二段階認証(Double authentication)**</wrap>。 | ユーザは、[[:ja:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_1_1|ユーザ情報編集]] オプションにアクセスすることで、アカウントでの//二段階認証//を有効にするかどうかを選択できます。 |
| |
| Users may choose whether to enable //two-step authentication// on their accounts by accessing the [[:en:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_1_1|Edit my user]] option. | <WRAP center round tip 90%> |
| |
| ユーザは、[[:ja:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_1_1|ユーザの編集]] オプションにアクセスして、自分のアカウントで //二段階認証// を有効にするかどうかを選択できます。 | You can use the [[:en:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_1_2|PFMS notification system]] to inform all users that 2FA is available and how to activate this personal option. To do this, in the <wrap :en>**Operation → Workspace → Messages → New message**</wrap> menu, write a message to the ''All'' group similar to this: |
| | |
| | </WRAP> |
| |
| <WRAP center round info 90%> | <WRAP center round info 90%> |
| |
| This feature requires for **PFMS server** and the [[:en:documentation:pandorafms:technical_annexes:36_pfms_double_authentication_setup|mobile devices]] to have an accurately synchronized date and time. | [[:ja:documentation:pandorafms:management_and_operation:11_managing_and_administration#ks1_1_2|PFMS 通知システム]]を使用して、二段階認証(2FA)が利用可能であることや、その個人用オプションを有効にする方法を全ユーザに知らせることができます。これを行うには、<wrap :ja>**操作(Operation) → ワークスペース(Workspace) → メッセージ(Messages) → 新規メッセージ(New message)**</wrap> メニューで、"すべて" (''All'') グループ宛てに以下のようなメッセージを作成してください。 |
| |
| </WRAP> | </WRAP> |
| | |
| | {{ :wiki:pfms-management-settings-system_settings-authentication-2fa_enabled_notification.png }} |
| |
| <WRAP center round info 90%> | <WRAP center round info 90%> |
| |
| この機能を使用するには、**PFMS サーバ** と [[:ja:documentation:pandorafms:technical_annexes:36_pfms_double_authentication_setup|モバイルデバイス]] の日付と時刻が正確に同期されている必要があります。 | This feature requires the **PFMS server** and [[:en:documentation:pandorafms:technical_annexes:36_pfms_double_authentication_setup|mobile devices]] to have their date and time accurately synchronized. |
| |
| </WRAP> | </WRAP> |
| |
| It will also be necessary to have the code generator application on a mobile device owned by each user. To find out where and how to download it: | <WRAP center round info 90%> |
| |
| また、各ユーザが所有するモバイルデバイスにコードジェネレーターアプリケーションをインストールする必要があります。ダウンロード場所と方法については、以下をご覧ください。 | この機能を使用するには、**PFMS サーバ**と[[:ja:documentation:pandorafms:technical_annexes:36_pfms_double_authentication_setup|モバイルデバイス]]の日時が正確に同期されている必要があります。 |
| | |
| | </WRAP> |
| | |
| | It will also be necessary to have the code generator application **on a mobile device owned by each user**. To find out where and how to download it: |
| | |
| | また、**各ユーザが所有するモバイル端末**にコード生成アプリを用意する必要があります。ダウンロード場所や方法については、以下をご確認ください。 |
| |
| <WRAP center round download 90%> | <WRAP center round download 90%> |
| |
| [[https://support.google.com/accounts/answer/1066447|https://support.google.com/accounts/answer/1066447]] | [[https://support.google.com/accounts/answer/1066447]] |
| |
| </WRAP> | </WRAP> |
| <WRAP center round tip 90%> | <WRAP center round tip 90%> |
| |
| The PFMS notification system may be used to inform all users that 2FA is available and how to activate this personal option. To do this in the menu <wrap :en>**Operation → Workspace → Messages → New message**</wrap> you type in a message for group ''All'' similar to this one: | It is recommended to set a display name so that users can differentiate Pandora FMS from their other multiple authentication factors for other applications: |
| | |
| {{ :wiki:pfms-management-settings-system_settings-authentication-2fa_enabled_notification.png }} | |
| |
| </WRAP> | </WRAP> |
| <WRAP center round tip 90%> | <WRAP center round tip 90%> |
| |
| PFMS通知システムを使用して、2FA が利用可能であること、およびこの個人オプションを有効にする方法をすべてのユーザに通知できます。これを行うには、メニュー<wrap :ja>**操作(Operation) → ワークスペース(Workspace) → メッセージ(Message) → 新規メッセージ(New message)**</wrap>で、グループ ''All'' 宛てに次のようなメッセージを入力します。 | 他のアプリケーションの認証要素と Pandora FMS を区別できるよう、表示名を設定することをお勧めします。 |
| | |
| {{ :wiki:pfms-management-settings-system_settings-authentication-2fa_enabled_notification.png }} | |
| |
| </WRAP> | </WRAP> |
| |
| <wrap :en>**Force 2FA for all users is enabled**</wrap> | {{ :wiki:pfms_server_for_america-node-786_version.png }} |
| | |
| **すべてのユーザに対して二段階認証を強制する(Force 2FA for all users is enabled)** | |
| |
| Enabling this option will force all users to use the //two-step authentication//. | * <wrap :en>**Force 2FA for all users is enabled**</wrap>: Enabling this option **will force all users** to use //two-step authentication//. |
| |
| このオプションを有効にすると、すべてのユーザが 2 段階認証を使用するよう強制されます。 | * <wrap :ja>**すべてのユーザに対して二段階認証を強制する(Force 2FA for all users is enabled)**</wrap>: このオプションを有効にすると、**すべてのユーザ**に//二段階認証//の利用が強制されます。 |
| |
| <WRAP center round info 90%> | <WRAP center round info 90%> |
| |
| To disable this feature to a specific user without using the graphical interface, [[:en:documentation:pandorafms:technical_reference:03_anexo_cli#disable_double_auth|an administrator can use the PFMS CLI]]. | To disable this feature for a specific user //without using the graphical interface//, [[:en:documentation:pandorafms:technical_reference:03_anexo_cli#disable_double_auth|an administrator can use the PFMS CLI]]. |
| |
| </WRAP> | </WRAP> |
| 暗号化の手順は次の通りです。 | 暗号化の手順は次の通りです。 |
| |
| * Stop the server, both in **Command Center (Metaconsole)** and in the **nodes**. | * [[:en:documentation:pandorafms:installation:06_server_management#ks1|Stop the server]], both in **Command Center** and in the **nodes**. |
| |
| * **コマンドセンター (メタコンソール)** と **ノード** の両方でサーバを停止します。 | * **コマンドセンター** と **ノード** の両方で[[:ja:documentation:pandorafms:installation:06_server_management#ks1|サーバを停止]]します。 |
| |
| * Update the ''encryption_passphrase'' fields in ''/etc/pandora/pandora_server.conf'' and ''/var/www/html/pandora_console/include/config.php'', both in **Command Center (Metaconsole)** and in **nodes**. | * Update the ''encryption_passphrase'' fields in ''/etc/pandora/pandora_server.conf'' and ''/var/www/html/pandora_console/include/config.php'', both in **Command Center (Metaconsole)** and in **nodes**. |
| * ''/etc/pandora/pandora_server.conf'' 内の **encryption_passphrase** および、**ノード** および **コマンドセンター(メタコンソール)** 双方の ''/var/www/html/pandora_console/include/config.php'' を更新します。 | * ''/etc/pandora/pandora_server.conf'' 内の **encryption_passphrase** および、**ノード** および **コマンドセンター(メタコンソール)** 双方の ''/var/www/html/pandora_console/include/config.php'' を更新します。 |
| |
| <code> | <file | /etc/pandora/pandora_server.conf> |
| $config["encryption_passphrase"]="passphrase"; | encryption_passphrase "your encryption passphrase" |
| </code> | </file> |
| | |
| | <file | /var/www/html/pandora_console/include/config.php> |
| | $config["encryption_passphrase"]="your encryption passphrase"; |
| | </file> |
| |
| * Launch the encryption script both in **Command Center (Metaconsole)** and in the **nodes**. | * Launch the encryption script both in **Command Center (Metaconsole)** and in the **nodes**. |
| <WRAP center round tip 90%> | <WRAP center round tip 90%> |
| |
| The Pandora FMS server should be restarted after making the changes and launching the script. | The [[:en:documentation:pandorafms:installation:06_server_management#ks1|Pandora FMS Server must be restarted]] after having made the changes and executed the //script//. |
| |
| </WRAP> | </WRAP> |
| <WRAP center round tip 90%> | <WRAP center round tip 90%> |
| |
| 変更を加えてスクリプトを実行した後、Pandora FMS サーバを再起動する必要があります。 | 変更を加えてスクリプトを実行した後、[[:ja:documentation:pandorafms:installation:06_server_management#ks1|Pandora FMS サーバを再起動]]する必要があります。 |
| |
| </WRAP> | </WRAP> |
| * **コマンドセンター (メタコンソール)** と **ノード** の両方で、''/etc/pandora/pandora_server.conf'' と ''/var/www/html/pandora_console/include/config.php'' の **encryption_passphrase** をコメントアウトします。 | * **コマンドセンター (メタコンソール)** と **ノード** の両方で、''/etc/pandora/pandora_server.conf'' と ''/var/www/html/pandora_console/include/config.php'' の **encryption_passphrase** をコメントアウトします。 |
| |
| <code> | <file | /etc/pandora/pandora_server.conf> |
| | # encryption_passphrase "your encryption passphrase" |
| | </file> |
| | |
| | <file | /var/www/html/pandora_console/include/config.php> |
| # $config["encryption_passphrase"]="your encryption passphrase"; | # $config["encryption_passphrase"]="your encryption passphrase"; |
| </code> | </file> |
| |
| <WRAP center round tip 90%> | <WRAP center round tip 90%> |
| |
| The Pandora FMS server should be restarted after making the changes and launching the script. | The [[:en:documentation:pandorafms:installation:06_server_management#ks1|Pandora FMS Server must be restarted]] after having made the changes and executed the //script//. |
| |
| </WRAP> | </WRAP> |
| <WRAP center round tip 90%> | <WRAP center round tip 90%> |
| |
| 変更を加えてスクリプトを実行した後は、Pandora FMS サーバを再起動することを忘れないでください。 | 変更を加えてスクリプトを実行した後は、[[:ja:documentation:pandorafms:installation:06_server_management#ks1|Pandora FMS サーバを再起動]]することを忘れないでください。 |
| |
| </WRAP> | </WRAP> |
| ===== ユーザパスワードポリシー ===== | ===== ユーザパスワードポリシー ===== |
| |
| | <WRAP group> |
| <WRAP left round box 50%> | <WRAP half column><WRAP center round box 90%><wrap :en>**Management → Settings → {{:wiki:pfms-general_settings-general_setup.svg?nolink&21x21}} System Settings → Password policy**</wrap> menu.</WRAP> |
| | </WRAP> |
| <wrap :en>**Management → Settings → System Settings → Password policy**</wrap> {{:wiki:pfms-general_settings-password.png?nolink&21x21}}menu. | <WRAP half column>To activate the password policy, you must have an administrator profile (<wrap :en>**Pandora administrator**</wrap>) or be a ** [[:en:documentation:pandorafms:introduction:03_glossary#superadmin|superadmin]]**. |
| </WRAP> | </WRAP> |
| \\ \\ \\ \\ \\ | |
| |
| <WRAP left round box 50%> | |
| |
| <wrap :ja>**管理(Management) → セットアップ(Setup) → セットアップ(Setup) → パスワードポリシー(Password policy)**</wrap> {{:wiki:pfms-general_settings-password.png?nolink&21x21}} メニュー | |
| |
| </WRAP> | </WRAP> |
| \\ \\ \\ \\ \\ | |
| |
| To activate the password policy, you must have an administrator profile (<wrap :en>**Pandora administrator**</wrap>) or be a **[[:en:documentation:pandorafms:introduction:03_glossary#superadmin|superadmin]]**. | <WRAP group> |
| | <WRAP half column><WRAP center round box 90%><wrap :ja>**管理(Management) → セットアップ(Settings) → {{:wiki:pfms-general_settings-general_setup.svg?nolink&21x21}} システム設定(System Settings) → パスワードポリシー(Password policy)**</wrap> メニュー。</WRAP> |
| パスワード ポリシーを有効にするには、管理者プロファイル (<wrap :en>**Pandora 管理者**</wrap>) を持っているか、**[[:ja:documentation:pandorafms:introduction:03_glossary#スーパー管理者|スーパー管理者]]** である必要があります。 | </WRAP> |
| | <WRAP half column>パスワードポリシーを有効にするには、管理者プロファイル(<wrap :ja>**Pandor administrator**</wrap>)を持っているか、** [[:ja:documentation:pandorafms:introduction:03_glossary#superadmin|スーパー管理者]]** である必要があります。 |
| | </WRAP> |
| | </WRAP> |
| |
| Important fields: | Important fields: |
| * <wrap :en>**Activate reset password**</wrap>: Disabled by default, if enabled, it allows users to recover forgotten passwords. | * <wrap :en>**Activate reset password**</wrap>: Disabled by default, if enabled, it allows users to recover forgotten passwords. |
| * <wrap :en>**Exclusion word list for passwords**</wrap>: It allows you to add a list of passwords explicitly excluded from use in Pandora FMS. | * <wrap :en>**Exclusion word list for passwords**</wrap>: It allows you to add a list of passwords explicitly excluded from use in Pandora FMS. |
| | * <wrap :en>**Number of blocked login attempts**</wrap>: Disabled (''0'') by default. Specifies the maximum number of consecutive failed login attempts allowed for a single user. Once a user has been locked out, and whilst the password policy is active, only a [[:en:documentation:pandorafms:introduction:03_glossary#superadmin|superadmin]] user can unlock them. |
| |
| * **パスワードポリシーの有効化(Enable password policy): ** パスワードポリシーを有効化/無効化します。デフォルトでは無効化されています。 | * <wrap :ja>**パスワードポリシーの有効化(Enable password policy)**</wrap>: パスワードポリシーを有効化/無効化します。デフォルトでは無効化されています。 |
| * **最小パスワードサイズ(Min. size Password): ** パスワードの最小の長さです。デフォルトでは 4文字です。 | * <wrap :ja>**最小パスワードサイズ(Min. size Password)**</wrap>: パスワードの最小の長さです。デフォルトでは 4文字です。 |
| * **パスワードの期限切れ(Password Expiration): ** パスワードが期限切れになるまでの期間です。デフォルトでは ''0'' です(期限切れになりません)。 | * <wrap :ja>**パスワードの期限切れ(Password Expiration)**</wrap>: パスワードが期限切れになるまでの期間です。デフォルトでは ''0'' です(期限切れになりません)。 |
| * **パスワードには数値を含む必要があります(Password must have numbers): ** パスワードに数字を含む必要があるかどうかです。デフォルトでは無効化されています。 | * <wrap :ja>**パスワードには数値を含む必要があります(Password must have numbers)**</wrap>: パスワードに数字を含む必要があるかどうかです。デフォルトでは無効化されています。 |
| * **パスワードには記号を含む必要があります(Password must have symbols): ** パスワードに記号を含む必要があるかどうかです。デフォルトでは無効化されています。 | * <wrap :ja>**パスワードには記号を含む必要があります(Password must have symbols)**</wrap>: パスワードに記号を含む必要があるかどうかです。デフォルトでは無効化されています。 |
| * **初回ログイン時にパスワードを変更する(Force change password on first login): ** ユーザ作成後、初回ログイン時にパスワードを変更します。デフォルトでは無効化されています。 | * <wrap :ja>**初回ログイン時にパスワードを変更する(Force change password on first login)**</wrap>: ユーザ作成後、初回ログイン時にパスワードを変更します。デフォルトでは無効化されています。 |
| * **ログインに失敗するとユーザをブロック(Block user if login fails): ** 最大失敗回数パスワードを間違えた場合に、ユーザをブロックする時間(分)です。デフォルトは 5分です。 | * <wrap :ja>**ログインに失敗するとユーザをブロック(Block user if login fails)**</wrap>: 最大失敗回数パスワードを間違えた場合に、ユーザをブロックする時間(分)です。デフォルトは 5分です。 |
| * **管理者ユーザへパスワードポリシーを適用(Apply password policy to admin users): ** 管理者ユーザにもパスワードポリシーを適用します。デフォルトでは無効化されています。 | * <wrap :ja>**管理者ユーザへパスワードポリシーを適用(Apply password policy to admin users)**</wrap>: 管理者ユーザにもパスワードポリシーを適用します。デフォルトでは無効化されています。 |
| * **パスワード履歴の有効化(Enable password history)** と **以前のパスワードとの比較(Compare previous password): ** これらは連携して、ユーザがパスワードを重複して使用することを防ぎます。最初のトークンは有効にし、2番目のトークンは 0(デフォルトは ''3'' )より大きい値に設定する必要があります。これにより、ユーザの新しいパスワードは、同じユーザが以前に使用した ''3''(または指定された回数)と比較されます。 | * <wrap :ja>**パスワード履歴の有効化(Enable password history)** と **以前のパスワードとの比較(Compare previous password)**</wrap>: これらは連携して、ユーザがパスワードを重複して使用することを防ぎます。最初のトークンは有効にし、2番目のトークンは 0(デフォルトは ''3'' )より大きい値に設定する必要があります。これにより、ユーザの新しいパスワードは、同じユーザが以前に使用した ''3''(または指定された回数)と比較されます。 |
| * **パスワードリセットの有効化(Activate reset password)**: デフォルトでは無効になっていますが、有効にすると、ユーザは忘れたパスワードを回復できるようになります。 | * <wrap :ja>**パスワードリセットの有効化(Activate reset password)**</wrap>: デフォルトでは無効になっていますが、有効にすると、ユーザは忘れたパスワードを回復できるようになります。 |
| * **パスワードの除外リスト(Exclusion list for passwords)**: Pandora FMS での使用を明示的に除外するパスワードのリストを追加できます。 | * <wrap :ja>**パスワードの除外リスト(Exclusion list for passwords)**</wrap>: Pandora FMS での使用を明示的に除外するパスワードのリストを追加できます。 |
| | * <wrap :ja>**ブロックされるログイン試行回数**</wrap>: デフォルトでは無効(''0'')に設定されています。単一のユーザに対して許容される、連続したログイン失敗の最大回数を指定します。ユーザがロックアウトされると、パスワードポリシーが有効である限り、[[:ja:documentation:pandorafms:introduction:03_glossary#superadmin|スーパー管理者 (superadmin)]] ユーザのみがロックを解除できます。 |
| |
| <wrap #ks4 /> | <wrap #ks4 /> |