Security+ Academy · पाठ

निर्देशिका सेवाएँ: LDAP और Active Directory

समझिए कि LDAP निर्देशिकाएँ और Active Directory उपयोगकर्ताओं, समूहों व कंप्यूटरों को कैसे व्यवस्थित करते हैं और Group Policy बड़े पैमाने पर सुरक्षा सेटिंग कैसे लागू करती है।

पाठ 1, कुल 4 में से13 चरण

निर्देशिका सेवाएँ: LDAP और Active Directory, CoddyKit पर Security+ Academy का एक निःशुल्क पाठ है। यह 4 में से 1वाँ पाठ है। इस अध्ययन पथ के 3 तक कोई भी पाठ पूरा पढ़ना निःशुल्क है — इसके बाद CoddyKit PRO हर पाठ अनलॉक करता है, साथ ही अंतर्निर्मित कोड संपादक और चौबीसों घंटे एआई शिक्षक के साथ व्यावहारिक अभ्यास भी उपलब्ध कराता है। यह Security+ Academy सीखने के मार्ग का हिस्सा है और आपकी प्रगति वेब तथा CoddyKit ऐप पर सिंक होती रहती है। Security+ Academy पाठ्यक्रम में कुल 4 पाठ शामिल हैं।

Directory Services क्या हैं

directory service एक centralized repository है जो network resources — Users, groups, computers, printers और policies — से संबंधित Information को संग्रहीत और व्यवस्थित करती है। प्रत्येक system पर अलग-अलग user databases बनाए रखने के बजाय, organizations identity Information के लिए directory service को single source of truth के रूप में उपयोग करती हैं। सभी Authentication requests को directory के विरुद्ध validate किया जाता है और access policies पूरे enterprise में एकसमान रूप से लागू की जाती हैं।

LDAP: Lightweight Directory Access Protocol

LDAP (Lightweight Directory Access Protocol) directory services को query और modify करने के लिए industry-standard protocol है। LDAP entries को Directory Information Tree (DIT) नामक hierarchical tree में व्यवस्थित करता है और entries की पहचान Distinguished Name (DN) से होती है। LDAP port 389 (cleartext) और port 636 (LDAPS — LDAP over TLS) पर चलता है। LDAP protocol है; directory स्वयं एक अलग product है।

# LDAP Distinguished Name structure
cn=John Smith,ou=Engineers,dc=corp,dc=example,dc=com

# cn  = Common Name (user's name)
# ou  = Organizational Unit
# dc  = Domain Component

# LDAP search query example
ldapsearch -H ldap://dc.corp.example.com \
  -b 'dc=corp,dc=example,dc=com' \
  '(sAMAccountName=jsmith)' mail memberOf

Active Directory Architecture

Active Directory (AD) Microsoft की enterprise directory service है, जो LDAP और Kerberos पर आधारित है। यह resources को Domains में व्यवस्थित करता है, जो मिलकर Trees बनाते हैं, और Trees मिलकर Forests बनाते हैं। एक domain controller (DC) AD database (NTDS.dit) को host करता है और Authentication संभालता है। अधिकांश Windows enterprise environments में AD identity management की रीढ़ है।

# Active Directory hierarchy
# Forest: corp.example.com (trust boundary)
#   Tree: corp.example.com
#     Domain: corp.example.com
#       OU: Engineering
#         User: jsmith
#         Group: Dev-Team
#       OU: Finance
#         Computer: FIN-PC-01

Active Directory में Kerberos Authentication

Active Directory अपने default Authentication protocol के रूप में Kerberos का उपयोग करता है। यह प्रक्रिया ticket-granting के माध्यम से काम करती है: Client Key Distribution Center (KDC) के साथ authenticate होता है और Ticket-Granting Ticket (TGT) प्राप्त करता है। जब User को किसी resource तक पहुँच चाहिए होती है, तो वह उस विशिष्ट resource के लिए Service Ticket प्राप्त करने हेतु TGT प्रस्तुत करता है। Passwords network पर कभी नहीं भेजे जाते — केवल encrypted tickets भेजे जाते हैं। Kerberoasting जैसे हमलों को समझने के लिए यह design केंद्रीय है।

# Kerberos authentication flow (simplified)
# 1. Client -> KDC: Authentication Request (AS-REQ)
# 2. KDC  -> Client: Ticket-Granting Ticket (AS-REP)
# 3. Client -> KDC: Service Ticket Request (TGS-REQ) + TGT
# 4. KDC  -> Client: Service Ticket (TGS-REP)
# 5. Client -> Server: Access Request + Service Ticket
# 6. Server validates ticket -> Access granted

Group Policy Objects (GPOs)

Group Policy Objects (GPOs) हजारों machines पर एक साथ Security settings लागू करने के लिए AD का mechanism हैं। GPOs Password complexity requirements, screen lock timeouts, software installation, firewall rules और registry settings configure कर सकते हैं। GPOs AD containers (sites, domains, OUs) से linked होते हैं और उस container के भीतर सभी Users और computers पर लागू होते हैं। GPO settings default रूप से हर 90 minutes में refresh होती हैं, जिससे उन machines पर भी compliance बनी रहती है जो policy से भटक जाती हैं।

# Common GPO security settings
# Computer Configuration -> Windows Settings -> Security Settings:
#   Password Policy:
#     - Minimum password length: 14
#     - Password complexity: Enabled
#     - Maximum password age: 90 days
#   Account Lockout Policy:
#     - Lockout threshold: 5 attempts
#     - Lockout duration: 30 minutes

AD Security Groups और Least Privilege

Active Directory access permissions को सामूहिक रूप से manage करने के लिए Security Groups का उपयोग करता है। Individual Users को permissions देने के बजाय, administrators groups को permissions grant करते हैं और Users को उपयुक्त groups में जोड़ते हैं। Security+ के लिए समझने योग्य प्रमुख built-in groups हैं: Domain Admins (पूर्ण domain control), Enterprise Admins (पूरे forest का control), Schema Admins (AD schema को modify करना) और Administrators (local machine admin)। इन high-privilege groups की membership को कड़ाई से नियंत्रित किया जाना चाहिए।

LDAP Injection Attacks

LDAP injection directory services में SQL injection के समकक्ष है। Attacker user input में special characters (*, (, ), \, NUL) डालकर LDAP query में हेरफेर करता है, जब उस input को सीधे LDAP filter में concatenate किया जाता है। सफल attack से Authentication bypass हो सकता है, सभी directory entries निकाली जा सकती हैं या directory objects modify किए जा सकते हैं। रोकथाम के लिए input validation और string concatenation के बजाय parameterized LDAP APIs का उपयोग आवश्यक है।

# Vulnerable LDAP filter (DO NOT use)
filter = '(uid=' + user_input + ')'
# Attacker input: *)(&
# Result: (uid=*)(&) -- returns ALL users

# Defense: escape special chars before including in filter
# LDAP special chars: ( ) * \ NUL
# Use LDAP library escaping functions

AD Replication और Domain Controllers

Enterprises redundancy और geographic distribution के लिए कई domain controllers deploy करती हैं। AD replication Directory Replication Service (DRS) का उपयोग करके सभी DCs को synchronized रखता है। Attackers DCSync attack के लिए replication का दुरुपयोग करते हैं — replication permissions का उपयोग करके किसी DC पर वास्तव में log on किए बिना उससे सभी Password hashes का अनुरोध करते हैं। Replication permissions की सुरक्षा AD hardening का एक महत्वपूर्ण चरण है।

# DCSync attack detection query (PowerShell)
# Detect accounts with dangerous replication permissions:
Get-ObjectAcl -DistinguishedName 'DC=corp,DC=example,DC=com' |
  Where-Object { $_.ActiveDirectoryRights -match 'DS-Replication' } |
  Select-Object IdentityReference, ActiveDirectoryRights

LDAP को सुरक्षित करना: LDAPS और साइनिंग

पोर्ट 389 पर साधारण LDAP डेटा — जिसमें bind credentials भी शामिल हैं — स्पष्ट-पाठ में भेजता है, जिससे वह अवरोधन के प्रति संवेदनशील हो जाता है। संगठनों को सभी directory traffic को एन्क्रिप्ट करने के लिए पोर्ट 636 पर LDAPS (LDAP over TLS) लागू करना चाहिए। इसके अतिरिक्त, relay attacks को रोकने के लिए LDAP signing and channel binding अनिवार्य किया जाना चाहिए। ऐसे हमलों में हमलावर LDAP authentication messages को अवरोधित करके दोबारा चलाता है और अनधिकृत पहुँच प्राप्त करता है।

# Verify LDAP signing requirement (Windows)
# Registry key:
# HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
# LDAPServerIntegrity = 2 (Require signing)

# Or via GPO:
# Security Settings -> Local Policies -> Security Options
# 'Domain controller: LDAP server signing requirements' = Require signing

AD का आक्रमण क्षेत्र: सामान्य गलत कॉन्फ़िगरेशन

Active Directory वातावरणों में वर्षों के संचालन के दौरान गलत कॉन्फ़िगरेशन जमा होते जाते हैं। AD की सामान्य सुरक्षा कमजोरियों में ये शामिल हैं: unconstrained delegation (जो किसी भी User का रूप धारण करने की अनुमति देता है), कमजोर पासवर्ड वाले Kerberoastable service accounts, AS-REP roasting targets (वे accounts जिनमें pre-authentication अक्षम है), अत्यधिक Domain Admin membership, और AdminSDHolder की ऐसी गलत कॉन्फ़िगरेशन जो छिपी हुई उन्नत अनुमतियाँ प्रदान करती हैं। BloodHound जैसे tools का उपयोग करके नियमित AD security assessments इन पहुँच-मार्गों की पहचान करने में सहायता करते हैं।

LDAP और Active Directory का सारांश

संबंध स्पष्ट करने के लिए: LDAP वह protocol है जिसका उपयोग directories से संवाद करने के लिए किया जाता है (जैसे web servers से संवाद करने के लिए HTTP का उपयोग किया जाता है)। Active Directory Microsoft का directory service product है, जो LDAP को अपने access protocol के रूप में उपयोग करता है। LDAP-संगत अन्य directories में OpenLDAP (open source), Oracle Directory Server और Red Hat Directory Server शामिल हैं। सभी LDAP queries का उपयोग करते हैं, लेकिन इनके management interfaces और अतिरिक्त proprietary features अलग-अलग होते हैं।

त्वरित जाँच

इस lesson में शामिल CompTIA Security+ (SY0-701) concepts की अपनी समझ जाँचें।

Lesson का पुनरावलोकन

इस lesson में आपने सीखा: LDAP, Distinguished Names का उपयोग करके hierarchical tree में directory services से query करने का protocol है, Active Directory authentication के लिए Kerberos और domains में security settings लागू करने के लिए GPOs का उपयोग करता है, और अवरोधन तथा relay attacks को रोकने के लिए port 636 पर LDAPS और LDAP signing को अनिवार्य किया जाना चाहिए। अब हम Privileged Access Management (PAM) का अध्ययन करेंगे।

शुरुआत निःशुल्क

एआई शिक्षक के साथ Security+ Academy सीखें — निःशुल्क

अपने ब्राउज़र में वास्तविक कोड लिखें और चलाएँ, चौबीसों घंटे एआई शिक्षक से तुरंत सहायता पाएँ, और वेब या ऐप पर वहीं से शुरू करें जहाँ आपने छोड़ा था।

पाठ्यक्रम
30
पाठ
120

अक्सर पूछे जाने वाले प्रश्न

क्या “निर्देशिका सेवाएँ: LDAP और Active Directory” पाठ निःशुल्क है?

हाँ — Security+ Academy अध्ययन पथ के 3 तक कोई भी पाठ, जिसमें “निर्देशिका सेवाएँ: LDAP और Active Directory” भी शामिल है, यहाँ वेब पर पूरा पढ़ना निःशुल्क है। इसके बाद CoddyKit PRO हर पाठ अनलॉक करता है, साथ ही अंतर्निर्मित कोड संपादक और चौबीसों घंटे एआई शिक्षक के साथ इंटरैक्टिव अभ्यास भी उपलब्ध कराता है। Security+ Academy पाठ्यक्रम में कुल 4 पाठ शामिल हैं।

“निर्देशिका सेवाएँ: LDAP और Active Directory” में मैं क्या सीखूँगा?

समझिए कि LDAP निर्देशिकाएँ और Active Directory उपयोगकर्ताओं, समूहों व कंप्यूटरों को कैसे व्यवस्थित करते हैं और Group Policy बड़े पैमाने पर सुरक्षा सेटिंग कैसे लागू करती है। आप ब्राउज़र में सीधे चलाए जाने वाले व्यावहारिक कोड के साथ Security+ Academy का अभ्यास करते हैं, और पाठ पूरा करते समय 24/7 एआई ट्यूटर आपके प्रश्नों के उत्तर देता है।

क्या Security+ Academy शुरू करने के लिए मुझे किसी अनुभव की आवश्यकता है?

पहले के अनुभव की आवश्यकता नहीं है। CoddyKit पर Security+ Academy शुरुआती से लेकर उन्नत शिक्षार्थियों तक सभी के लिए व्यवस्थित किया गया है, इसलिए आप यहीं से या शुरुआत से सीखना शुरू कर सकते हैं और अपनी गति से आगे बढ़ सकते हैं। यह 4 में से 1वाँ पाठ है।

“निर्देशिका सेवाएँ: LDAP और Active Directory” पाठ पूरा करने में कितना समय लगता है?

CoddyKit का अधिकांश पाठ लगभग 5–10 मिनट में पूरा हो जाता है। हर पाठ छोटा और संवादात्मक है, इसलिए आप लगातार प्रगति करते हैं और वेब या ऐप पर वहीं से सीखना जारी रख सकते हैं जहाँ आपने छोड़ा था।

क्या मैं इस Security+ Academy पाठ में कोड लिख और चला सकता हूँ?

हाँ। हर Security+ Academy पाठ में एक अंतर्निर्मित कोड संपादक शामिल है, जिससे आप सीधे अपने ब्राउज़र में वास्तविक कोड लिख और चला सकते हैं और तुरंत एआई प्रतिक्रिया पा सकते हैं—स्थानीय सेटअप की आवश्यकता नहीं है।

इस पाठ्यक्रम के सभी पाठ

  1. निर्देशिका सेवाएँ: LDAP और Active Directory
  2. विशेषाधिकार प्राप्त अभिगम प्रबंधन (PAM)
  3. पहचान शासन और प्रावधान
  4. समय-विशिष्ट अभिगम और सशर्त अभिगम नीतियाँ
← Security+ Academy पर वापस जाएँ