Mozilla SSL Configuration Generator Redirecting to the updated SSL Configuration Generatorâ¦
Mozilla SSL Configuration Generator Redirecting to the updated SSL Configuration Generatorâ¦
å¿ è¦ãªæ å ±ã¯ http://heartbleed.com/ ã«ã¾ã¨ã¾ã£ã¦ããã®ã§ãããè±èªã ãé·ããã£ã¦äººã®ããã«æçã«ã¾ã¨ãã¦ããã¾ãã ã©ãããã°ããã®ã OpenSSL 1.0.1ã1.0.1fã使ã£ã¦ããªããã°ã»ã¼ã ãã¦ã¯ã¾ãå ´åã«ã¯ãä¸å»ãæ©ããã¼ã¸ã§ã³ã¢ãããã¦ããµã¼ããã¨åèµ·å(ãããã²ã¨ã¯ãµã¼ãã¹åä½ã§ãOKããã ãreloadã§ã¯ã ããªãã¨ã) SSL証ææ¸ã§ãµã¼ããå ¬éãã¦ãããªããç§å¯éµããä½ãç´ãã¦è¨¼ææ¸ãåçºè¡ããéå»ã®è¨¼ææ¸ã失å¹ããã(æ«å°¾ã«é¢é£ãªã³ã¯ãã)ã ãµã¼ããå ¬éãã¦ããªãå ´åããå¤é¨ã¸ã®SSLéä¿¡ãããã°å½±é¿ãåããã®ã§ã詳ããç²¾æ»ããã PFS(perfect forward secrecy)ãå©ç¨ãã¦ããªãå ´åãéå»ã®éä¿¡å 容ã復å·ãããå¯è½æ§ãããããã詳ããç²¾æ»ããã æ¼æ´©ããæ å ±ã®å ·ä½ä¾ã¯ãOpenSSLã®èå¼±æ§ã§æ³å®ããããªã¹ã¯ã¨ãã¦
# openssl.cnf æ¥æ¬èªè§£èª¬ç 2005/1/31 # ãã®ããã¥ã¡ã³ãã¯openssl projectã¨ã¯é¢ä¿ããã¾ãã # æ¥æ¿ããå®é¨å®¤ã®ç®¡ç人ãæã¤ã¶ãã«ç¿»è¨³ãã¦æ¡å¼µãããã®ã§ãã # ãã®ããã¥ã¡ã³ãã«é¢ãã質åãææã¯openssl projectã«ã¯ããªãã§ãã ãã # ééãã®ææãªã©ã¯ãã¡ãã¸ãé¡ããã¾ã # URL:http://www.yggdrasil.jp/ # Mailto:meguro at yggdrasil.jp s/ at /@/ #################################################################### [ ca ] default_ca = CA_default # ããã©ã«ãã®CAã»ã¯ã·ã§ã³ãæå® ########################################
åã®ãã¼ã¸ ç®æ¬¡ 次ã®ãã¼ã¸ æçµæ´æ°æ¥ï¼2002å¹´12æ12æ¥ 3.3 é»å証ææ¸ 3.3.1 X.509 証ææ¸ è¨¼ææ¸ï¼å ¬ééµè¨¼ææ¸ï¼ã®æ¨æºã¨ãã¦ãITU-T ãçå®ãã X.509 ãããã¾ããX.509 㯠X.500 ãã£ã¬ã¯ããªã·ãªã¼ãºã®1ã¤ã§ãããISO/IEC ã®å½éæ¨æºã¨ãã¦è¦å®ããã¦ãã¾ãã X.509 ã®æåã®ãã¼ã¸ã§ã³(X.509v1)㯠1988å¹´ã«çºè¡ããã¾ãããããã« 1997å¹´ã«çºè¡ãããææ°ãã¼ã¸ã§ã³(X.509v3) ã«ããã¦ã¯ã証ææ¸ã«æ¡å¼µé åãè¨ãããä»»æã®æ¡å¼µãå¯è½ã«ãªãã¾ãããX.509v3 㯠2000å¹´ã«æ¹å®ãããå¾è¿°ãããã«ã¿ CRL ã¨å±æ§è¨¼ææ¸ã®å®ç¾©ãæ確ã«ãªã£ã¦ãã¾ãã X.509v3 ãã¤ã³ã¿ã¼ãããã§å©ç¨ãããã¨ãç®çã¨ãã¦ãIETF ã® PKIX ä½æ¥é¨ä¼ã«ãã£ã¦ RFC2459 ã 1999å¹´ã«çå®ããã¾ãããRFC245
CRLSetã§ã¯ZIP復å å¦çã2åããã®ã§CRLã®ASN.1ã® å¦çã³ã¹ãã¨æ¯è¼ãã¦5å5åã¨ãã£ãã¨ããã ãããã ã¡ãªã¿ã«ãç¾å¨ããã·ã¥ãã¦ããCRLSetã¯ãã£ã35ã®ã«ã¼ãCA,ä¸éCAãããµãã¼ããã¦ããªãã ImperialVioletã®ããã°ã®ä¸»å¼µã®ããããªç¹ ããªã³ã©ã¤ã³å¤±å¹æ¤è¨¼ãã§ããªãå ´åæ§ã ãªåé¡ãèµ·ãããã¨ãã¦å¹¾ã¤ãåé¡ç¹ãè¿°ã¹ã¦ããã ã"captive portal"(ããã«ã®ã¤ã³ã¿ã¼ããããªã©ã§ã¦ã§ããã©ã¦ã¶ã§èªè¨¼ãã¦ãã ãããã使ããããã«ãªãä»çµã¿ã®äº)ãªã©ã§ã¯æ¥ç¶åã¯ãªã³ã©ã¤ã³ã®å¤±å¹æ¤è¨¼ã ã§ããªããã¨ãã¦ãããããã®æç¹ã§ã¯ããã«ã®ãµã¼ãã¹ã®èªè¨¼ã®ãã¼ã¸ããç¹ãã å¿ è¦ãç¡ãã®ã§ãã¾ã大ããªãªã¹ã¯ã¨ãæããªããç¹å®ã®åé¡ãªã®ã§ å¥ã«è§£æ±ºçãããã¨æãã ãèªè¨¼å±ã®CRLãæä¾ãããªãã¸ããªãOCSPã¬ã¹ãã³ãããã¦ã³ããå ´åã ãããåä¸é害ç¹ã«ãª
2005/10/02æ´æ° é«æ¨æµ©å ï¼ èªå® ã®æ¥è¨ãæè¦ããã«ã¤ããPKI ã¨ãã¦ã® SSL ã ä¸éå端ãªç解ã«ããå°ç¡ãã«ããã¦ããå ´é¢ãå¤ãããã«æãã¾ããããã§ï¼ã»ãã¥ãªãã£ã®å°é家ã§ã¯ãªããã®ã®ï¼ç§ãç解ãã¦ããç¯å²ã§èªåãªãã«å ¥é解説ãæ¸ãã¦ã¿ã¾ããã ã¡ãªã¿ã«ãSSL v3 ã«å°ãã®æ¹è¯ãå ãããã®ã TLS v1.0 ã§ãããæè¡çãªç´°ããç¹ãæ°ã«ããªã å ´åã¯ãSSLã¨ç·ç§°ããã¦ãã¾ãã ããã§ãããããªç´°ãããã¨ã¯æ°ã«ãã¦ããªãã®ã§ SSL ã¨ç·ç§°ãã¦ãã¾ãã SSLããã¿è§£èª¬ ã¾ããSSLãç解ããããã«å¿ è¦ãªç¨èªã解説ãã次㫠SSLã PKI ã¨ãã¦ã©ã®ãããªæ§æè¦ç´ ã§å®å ¨ãªéä¿¡è·¯ãå½¢æãã¦ããã解説ãã¾ãã æå·åã¨å¾©å·å ã³ã³ãã¥ã¼ã¿ã¼ã§æå·åã¨ããã¨ãæå·åããåã®ãã¼ã¿ ï¼ä»¥ä¸ããå¹³æï¼ã²ãã¶ãï¼ãã¨å¼ã³ã¾ãï¼ã¨éµã¨ãªããã¼ã¿ï¼ä»¥ä¸ãéµãã¨å¼ã³ã¾ãï¼ ã使ã£ã¦
OpenSSLã¯ããªã¼ã®SSLå®è£ ã§ãmod_sslãApache-SSLããããã¯OpenSSHãªã©ã§å¿ è¦ã«ãªãã¾ããApacheã§SSLã使ãããå ´åã¯ãOpenSSLã®ã»ãã«ãmod_sslã¾ãã¯Apache-SSLãå°å ¥ããå¿ è¦ãããã¾ãã Apache 1.3.20 + mod_ssl 2.8.4ã¤ã³ã¹ãã¼ã«ã¡ã¢ Apache 1.3.6 + SSL 1.3.2 (Apache-SSL)ã¤ã³ã¹ãã¼ã«ã¡ã¢ INSTALLã®æé éãã³ã³ãã¤ã«ãã¾ãã $ tar xvfz openssl-0.9.6b.tar.gz $ cd openssl-0.9.6b $ ./config $ make $ make test rootã«ãªã£ã¦ã¤ã³ã¹ãã¼ã«ãã¾ãã $ su # make install éµã®ä½æã¨ãµã¤ã証ææ¸ã®çºè¡ ãã¹ãã¬ã¼ãºã§ä¿è·ãããç§å¯éµãçæãã¾ãã $ su # cd
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}