2009/11/06 SSL/TLSã«MITMãå¯è½ã«ããèå¼±æ§ SSL 3.0/TLS ãããã³ã«ã§åãã´ã·ã¨ã¼ã·ã§ã³ãå©ç¨ãã¦ãMITMæ»æãå¯è½ã«ããã»ãã¥ãªãã£ã®èå¼±æ§ãè¦ã¤ãã£ãããã (BID 36935)ãMITMæ»æã«æåããã¨ãä»»æã®ããã¹ããå ¥ãããã¨ãã§ããããã®èå¼±æ§ã¯å®è£ ã®åé¡ã¨ãããããè¨è¨ä¸ã®åé¡ããèµ·ããããããææ°ã® Microsoft IISãApache httpdãOpenSSL ã§ãèµ·ãããBen Laurieæ°ã«ãã£OpenSSLç¨ã®ããããä½æããã¦ããããåãã´ã·ã¨ã¼ã·ã§ã³ãæ¢ããªãã¨ãããªãããã ãæä¹ çãªè§£æ±ºçãä»ãæ¤è¨ããã¦ããããIETFã®TLS Channel Bindings WG ã解決çãRFC 5056ã¨ãã¦çºè¡¨ãã¦ããã Marsh Ray | Authentication Gap in TLS Renegotiation
{{#tags}}- {{label}}
{{/tags}}