1. ã¯ããã« ã¡ããã©ä»æ OpenSSLãã¯ããã¨ããæ§ã ãªTLSå®è£ ã®èå¼±æ§ã®è©³ç´°ãå ¬è¡¨ããã¾ããã ãã® Inriaã¨MSRã®ã°ã«ã¼ãã¯ä»¥åããTLSã®ã»ãã¥ãªãã£ã«é¢ãã¦é常ã«ã¢ã¯ãã£ãã«èª¿æ»ã»æ¤è¨¼ããã¦ããã°ã«ã¼ãã§ãä»åãé©ãã®å 容ã§ããã ãã®ã°ã«ã¼ãã¯ãTLSã®ãã³ãã·ã§ã¤ã¯æã®ç¶æ é·ç§»ãå³å¯ã«ãã§ãã¯ãããã¼ã«ãéçºããæ§ã ãªTLSå®è£ ã®èå¼±æ§ãçºè¦ã»å ±åãè¡ã£ã¦ããããã§ãã ç¹ã«FREAKã¨å¼ã°ããOpenSSLã®èå¼±æ§(CVE-2015-0204)ã«é¢ãã¦ã¯ãã¡ããã©ä¿®æ£ç´å¾ã®1æåãã« Only allow ephemeral RSA keys in export ciphersuites ã§è¦ã¦ãã¾ããããå ·ä½çã«ã©ã®ããã«æ»æããã®ããã£ã±ãã¤ã¡ã¼ã¸ã§ããããã®ã°ã«ã¼ãã ããã¾ãè¶ çµ¶å¤æ ãªææ³ã ããããã¾ãããã»ã©æ·±å»ãããªãã ããã¨è¦è¾¼ãã§ãã¾ããã ä»å
{{#tags}}- {{label}}
{{/tags}}