Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?
Yahoo! Japan ãã2018å¹´6æ1æ¥ãã TLS1.0 㨠TLS1.1 ã®ãµãã¼ããé 次çµäºã㦠TLS1.2 ã®ã¿ã®ãµãã¼ãã«åãæ¿ãã¦ãã¾ããããæ°å¹´ãå社ã¦ã§ããµã¼ãã¹ã§ã TLS1.0 㨠TLS1.1 ãç¡å¹åããåãããããä»å¾ SSL/TLS ã®ãããã³ã«ã¯ TLS1.2 以ä¸ã«è¨å®ãããã¨ãæ¨æºã«ãªãã§ããããããã§ä»åã¯ãApache httpd ãµã¼ãã¼ã§ TLS1.0 㨠TLS1.1 ãç¡å¹ã«ããè¨å®ã確èªããæ¹æ³ãã¡ã¢ãã¦ããã¾ããã åèè³æï¼Yahoo!ã»ãã¥ãªãã£ã»ã³ã¿ã¼ TLS1.0 㨠TLS1.1 ãç¡å¹åããçç±ç¡å¹åããçç±ã¯ãTLS1.0 㨠TLS1.1(å®è£ ã«ããã)ã« POODLEï¼ãã¼ãã«ï¼ã¨ããæå·åéä¿¡ã解èªããã¦ãã¾ãèå¼±æ§ãããããã§ãã POODLE ãçºè¦ãããå½åã¯ãSSL3.0 ã®ã¿ããã®èå¼±æ§ã®å¯¾è±¡ã¨æãã
Google ã®ã¦ã§ããã°å ¬éãã¼ã«ã使ã£ã¦ãããã¹ããåçãåç»ãå ±æã§ãã¾ãã
SSLãµã¼ãã¼è¨¼ææ¸ãè³¼å ¥ãè¨ç½®ãè¡ã£ãã®ã§ããã®æ©ä¼ã«SSLã¾ããã®è¨å®ãè¦ãªããã¦ã¿ããã¨ã«ããã ï¼2014/10/21追è¨ï¼POODLE attack ã«å¯¾å¿ãããããSSLProtocol ã« -SSLv3 ã追å ãï¼ ï¼2016/03/03追è¨ï¼å¤ãè¨äºãªã®ã§ä»é¢¨ã®CipherSuiteã«ã¤ãã¦ãææ«ã«è¿½è¨ãã¾ãããï¼ ç¾ç¶ã®ç¢ºèª ã¾ãã¯Qualys SSL Labs SSL Server Testã¨ãããµã¤ãã¸è¡ã£ã¦ãç¾ç¶ããã§ãã¯ã æè¿ãã§ãã¯ããããã¡ã¤ã³ãªã¹ãã«ååãåºã¦ãã¾ãã®ã§ããã¡ã¤ã³åå ¥åæ¬ã®ä¸ã«ãããã§ãã¯ããã¯ã¹ããªã³ã«ãã¦ãªã¹ãæ²è¼ãæå¦ããã æ°åå¾ ã¤ã¨çµæã表示ãããã Beastæ»æãã©ãã ã¨ããæå·å¼·åº¦ãä½ãã ã¨ããããããã¨ææããã¦ãã¾ãã ã¾ãããã¼ã¸ã®ä¸ã®æ¹ã¸è¡ãã¨ãã¡ã¸ã£ã¼ãªãã©ã¦ã¶ã¨ã®æ¥ç¶ç¢ºèªãå¯è½ã ã è¨å®ã®å¤æ´ SSLã¾ããã®ç¥è
ããã«ã¡ã¯ï¼ã¤ã³ãã©ã¨ã³ã¸ãã¢ã®å°å ´ã§ãã 趣å³ããä»äºã§Webãµã¤ããéç¨ããã¦ããæ¹ã¯ããã£ãããã¾ããï¼ ãã®Webãµã¤ãã¯SSL証ææ¸ã使ã£ã¦ãã¾ããï¼ SSL証ææ¸ã使ã£ã¦ããã¨çããã¢ãã¿ï¼ ä¸è¨ã®ãªã³ã¯ã«ããªãã®ç®¡çããWebãµã¤ãã®URLã ãºã£ã¡ããã¨è²¼ãä»ããã¹ãã£ã³ãå®è¡ãã¦ã¿ã¦ãã ããã https://sslcheck.globalsign.com/ja/ ãããã§ãããï¼ ã©ã³ã¯ã¯Aã§ãããï¼Bã§ãããï¼ããã¨ãEãFï¼ ã¡ãªã¿ã«ãç§ãã»ãã¼ãã¨Webãµã¤ããéç¨ãã¦ãããã¤ãå æ¥SSL証ææ¸ãå ¥ãã¾ããã å¿ãããè¨ã訳ã«ãåæè¨å®ã®ã¾ã¾æ¾ç½®ãã¦ãã¾ããã ãããªã ãããªãç§ã®Webãµã¤ãã®è©ä¾¡ã¯ã覧ã®ã¨ããã â»æ¥ããããã®ã§URLã¯ä¼ãã¦ãã¾ã/// ããã¯ããã ã¨ãããã¨ã§ããã£ã¡ãæ¬æ°ãåºãã¦ã¿ã¾ããã®ã§ããã®è¨å®å 容ãæãããã¨æãã¾ãï¼ Webãµ
SSL 3.0ã®èå¼±æ§ CVE-2014-3566 aka POODLE ã®å¯¾å¿ã§SSL v3ãç¡å¹ã«ããå¿ è¦ãã http://www.itmedia.co.jp/news/articles/1410/15/news054.html http://googleonlinesecurity.blogspot.jp/2014/10/this-poodle-bites-exploiting-ssl-30.html https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/ https://www.openssl.org/~bodo/ssl-poodle.pdf Apache httpd + mod_sslãªã http://httpd.apache.org/docs/2.2/mod
ã¡ã¢ã¨ã³ããªã¼ã§ãã ã·ã³ããªãã¯ãªã³ã¯ã追å ln -s /usr/share/munin/plugins/apache_accesses /etc/munin/plugins/apache_accesses ln -s /usr/share/munin/plugins/apache_processes /etc/munin/plugins/apache_processes ln -s /usr/share/munin/plugins/apache_volume /etc/munin/plugins/apache_volume httpd.confã«ä»¥ä¸ã追å ï¼ããããå¿ããã»ã»ï¼ ExtendedStatus On locationã§è¨å®åºæ¥ãªãã±ã¼ã¹ãããã®ã§ãã¼ãã£ã«ãã¹ãã§å®ç¾©ãã¦ãã¾ã #status <VirtualHost *:80> ServerName 127.0.0.
ã¯ããã« Apache2.2ã®åºæ¬è¨å®ããã¼ãã£ã«ãã¹ãè¨å®ããã°è¨å®çã¯Apache2.2ã®è¨å®ã«ã¾ã¨ãã¦ãã¾ãã®ã§åç §ãã¦ã¿ã¦ä¸ããã ã¾ããMaxclientsã«ã¤ãã¦ã¯Apache2.2ã®ããã©ã¼ãã³ã¹ãã¥ã¼ãã³ã°(ãã®2)ã«ã¾ã¨ãã¦ãã¾ãã 使ç¨ãã¦ããMPMã¨è¨å®ã®ç¢ºèª Apacheã§ä»£è¡¨çãªMPM(Multi Processing Module)ã¨ãã¦ã¯ä»¥ä¸ã®äºã¤ãããã¾ãã ãã«ãã¹ã¬ããã§ããworkerã®æ¹ããã¹ã¬ãããã¡ã¢ãªç©ºéãå ±æãã¦ããããã¹ã¬ããåãæ¿ãæã«ã¡ã¢ãªå ±æãã¦ããããåãæ¿ãã®ããã®ã³ã¹ããå°ãªãçãªã©ã®çç±ã«ãããå§ãã®ããã§ãããæ¬ãµã¤ãã®ããã«å¤§éã®ã¢ã¯ã»ã¹ãããããã§ã¯ãªãç°å¢ã§ã¯ã©ã¡ããæ¡ç¨ãã¦ããã¾ãããããªããã§ã(ã¡ãªã¿ã«ãã«ãããã»ã¹ããã«ãã¹ã¬ããã®æ¯è¼ã«ã¤ãã¦ã¯Linuxãããã¯ã¼ã¯ããã°ã©ãã³ã°(ã·ã³ã°ã«ããã»ã¹ãã·ã³ã°ã«ã¹
ã¯ããã« Apache2.2ã®åºæ¬è¨å®ããã¼ãã£ã«ãã¹ãè¨å®ããã°è¨å®çã¯Apache2.2ã®è¨å®ã«ã¾ã¨ãã¦ãã¾ãã®ã§åç §ãã¦ã¿ã¦ä¸ããã Apache MPM preforkã®Maxclients以å¤ã®ãã©ã¡ã¼ã¿(StartServersãMinSpareServersãMaxSpareServersãMaxRequestsPerChild)ã«ã¤ãã¦ã¯Apache2.2ã®ããã©ã¼ãã³ã¹ãã¥ã¼ãã³ã°(ãã®1)ã«ã¾ã¨ãã¦ãã¾ãã®ã§åç §ãã¦ã¿ã¦ä¸ããã æ¬è¨äºã«ã¤ã㦠ãã¾ãããªãããµã¼ã/ã¤ã³ãã©ãæ¯ããæè¡ã«è¼ã£ã¦ããApache2ã®ãã¥ã¼ãã³ã°ããã¦ã¿ããã¨ã«ãã¾ãã(ããã«æ¸ãã¦ãããã¨ã¯ééãã ããããããã¾ããâ¦ããäºæ¿ä¸ãã)ã ãã¥ã¼ãã³ã°ãããæå³ãããã»ã©ã®ã¢ã¯ã»ã¹ã¯å½ãµã¤ãã«ã¯ããã¾ãããããã·ã³ãªã½ã¼ã¹ã使ãåãã»ã©ã®æ»æãåããªãã¨ãéãã¾ããã®ã§ãæ¬è¨äºã§ã¯MaxC
ãªãã¡ã¬ã³ã¹ãèªãã§ããã¾ãã¡ãã³ã¨æ¥ãªãmod_rewriteã®RewriteRuleãã£ã¬ã¯ãã£ãã®QSAãã©ã°ã«é¢ããã¡ã¢ã 1. ãªãã¡ã¬ã³ã¹åæ'qsappend|QSA' (query string append) This flag forces the rewriting engine to append a query string part in the substitution string to the existing one instead of replacing it. Use this when you want to add more data to the query string via a rewrite rule. ãã®ãã©ã°ã¯ãç½®ææååã®ä¸ã«ããã¯ã¨ãªæååé¨åãç½®ãæããã®ã§ã¯ãªãã追å ããããããã¯ãrewriteã«ã¼ã«ãéãã¦ã¯ã¨ãªæå
nginxãvarnishãªã©ãã¢ããã§ãããApacheãã¾ã ã¾ã å®ç¸¾ãå®å®æ§ããæ¡ç¨ããã¦ããã¨æãã¾ããããã§ã¯ããã©ã«ãã¨ã¯ç°ãªãå¤ã«å¤æ´ãããµã¼ãè¨å®ãä¸å¿ã«ãããã©ã¼ãã³ã¹æ¹åãå®å ¨æ§åä¸ã®ããã®Apacheã®è¨å®ãç´¹ä»ãã¾ãã mpmã®ç¢ºèª > /path/to/bin/httpd -V Server version: Apache/2.2.19 (Unix) Server built: Jun 23 2011 17:13:13 Server's Module Magic Number: 20051115:28 Server loaded: APR 1.4.5, APR-Util 1.3.12 Compiled using: APR 1.4.5, APR-Util 1.3.12 Architecture: 64-bit Server MPM: Worker PreforkãW
Apache mod_headersã§ã§ãã¾ã Header set X-Content-Type-Options nosniff Nginx add_header X-Content-Type-Options nosniff; ä½ããä¸è¨ã ã¨proxyãªããã§æ¢ã«X-Content-Type-Options: nosniff;ãä»ãã¦ãã㨠X-Content-Type-Options: nosniff, nosniff ã®ãããªãããã«ãªã£ã¦ãã¾ããåé¡ãªããããããªããæ°ã«ãªãå ´åã¯NginxHttpHeadersMoreModuleã使ã£ã¦ more_set_headers 'X-Content-Type-Options: nosniff'; ã¨ããã¨è¯ãã®ããã Plack Plack::Middleware::Headerã使ãã¨ç°¡åã§ãã enable 'Header', s
2011-01-06: IE8ã¨ãããã¨ãè¿½è¨ & ã¡ãã£ã¨ééããä¿®æ£ãããã¾ãã¦ããã§ã¨ããããã¾ãã å¹´æãæ©ã ã§ãããInternet Explorerã®è©±é¡ã§ããIEã¯ãåãã®éããContent-Type ã ãã§ãªãã³ã³ãã³ãã®å 容ãªã©ã sniff ãããã¨ã§ãã¡ã¤ã«ã¿ã¤ãã決å®ãã¦ãããããç»åãã¡ã¤ã«ãããã¹ããã¡ã¤ã«ãHTMLã¨å¤å®ãã¦ãã¾ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ãçºçãããã¨ãæãããã³ãã³å ±åããã¦ãã¾ãã*1ãç¾å¨ã¯å¹¾åãã·ã«ãªã£ãã¨ã¯ãããIEã®ãã¡ã¤ã«ã¿ã¤ãã®å¤å®ã¢ã«ã´ãªãºã ã¯é常ã«é£è§£ã§ãããç¾å¨ã§ãç¶æ³ã«ãã£ã¦ã¯Webãµã¤ãéå¶è ã®ã¾ã£ããæå³ãã¦ããªãããã¡ã§ã®XSSãçºçããå¯è½æ§ããã£ãããã¾ããããããããã§ãIEãã³ã³ãã³ãã sniff ãã¦HTML以å¤ã®ãã®ãHTMLæ±ããã¦ãã¾ããã¨ãé²ãããã«ãåçã«ã³ã³ãã³ããçæãã¦ããå ´åã«
ããã«ã¡ã¯ nakamura ã§ããæè¿ãã«ã·ã¨ãããã¬ãåºããããããã¾ããï¼ã¦ã£ã¤ã¬ã¤ãã¦ã¨ããªããµã¤ããã¨ï¼ ãã¦ãã¦ä»åã¯æå¤ã¨ç¥ããã¦ãªããã©ããµã¤ããã¤ã³ã¿ã¼ãããã«å ¬éããéã«ã¯ç¥ã£ã¦ãããæ¹ãè¯ã Apache ã®è¨å®ãããã¤ããç´¹ä»ãã¾ãï¼ä¸é¨ PHP ã®è¨å®ãããã¾ããï¼ããã®è¨å®ããã¦ããªãããã¨ãã£ã¦å³å±éºã«ãããããã¨ãã訳ã§ãããã¾ãããããªã¹ã¯ã®è½ã¯æãã§ããã«è¶ããäºã¯ããã¾ããããã ç¡é§ãª HTTP ããããè¿ããªã ãã£ã¹ããªãã¥ã¼ã·ã§ã³ã«ããç°ãªãããããã¾ããããCentOS ããã©ã«ãã®è¨å®ã®å ´å Apache ãè¿ãã¦ãã HTTP ãããã¯ä»¥ä¸ã®ãããªãã®ã§ãã HTTP/1.1 200 OK Date: Mon, 05 Jul 2010 01:01:14 GMT Server: Apache/2.2.3 (CentOS) X-Powered
ãã£ã¨Apacheãç¥ããï¼ãã¾ããèããªã!? Webç³»éçºè ã®ããã®ãµã¼ãç¥èï¼2ï¼ï¼1/3 ãã¼ã¸ï¼ èªåèµ·åã®è¨å® 第1åãWebãµã¼ãããå§ããããã§æé ã追ã£ã¦è¨ç½®ãã/etc/rc.d/init.d/httpdã¨ããApacheã®å¶å¾¡ã¹ã¯ãªããã¯ãã·ã¹ãã èµ·åæã«ãããApacheã®èªåèµ·åã«å©ç¨ã§ãã¾ãã ä»åã¯ãLinuxã®ã·ã¹ãã èµ·åæã«å種ã®ãµã¼ãããã°ã©ã ãèªåçã«èµ·åãããæ¹æ³ããApacheãä¾ã«ç´¹ä»ãã¦ããã¾ãããã ã¾ãã/etc/rc.d/init.d/é ä¸ã«ããµã¼ãå¶å¾¡ã¹ã¯ãªãããè¨ç½®ãã¾ããå¶å¾¡ã¹ã¯ãªããã®å 容ã¯ãµã¼ãããã°ã©ã ã«ããç°ãªãã¾ãããå¤ãã®ããã±ã¼ã¸ã§ã¯ã¤ã³ã¹ãã¼ã«æã«èªåã§è¨ç½®ãããããã¾ãã¯ãµã³ãã«ãæä¾ããã¾ããä»åã®ä¾ã§ã¯ããã§ã«ç´¹ä»ããæé ã§/etc/rc.d/init.d/httpdãè¨ç½®æ¸ã¿ã§ãã 次ã«ã/etc/rc.d/
Apacheã®ãã¼ã¸ã§ã³2.2.12以éã§ã¯ãSNIï¼Server Name Indicationï¼ã¨ãããSSLãããã³ã«ã«å¯¾ããæ¡å¼µæ©è½ããµãã¼ãããã¦ãããããååãã¼ã¹ã®HTTPãµã¤ããè¨å®ããå ´åã¨åãããã«ååãã¼ã¹ã®HTTPSãµã¤ããè¨å®ãããã¨ãå¯è½ã«ãªã£ã¦ãããæ¬è¨äºã§ã¯ãApacheã®ãã®æ©è½ã«ã¤ãã¦ç´¹ä»ããã Apache Webãµã¼ãããã¼ã¸ã§ã³ã¢ããããæçãã¦ããã«ä¼´ããæ°æ©è½ã®è¿½å ããã°ã®ä¿®æ£ãè¡ããã¦ãã¦ãããããã¦ããã¼ã¸ã§ã³2.2.12ã§è¿½å ãããæ©è½ã®ãã¡ãæãéè¦ãªãã®ã¯ãããããåä¸IPã¢ãã¬ã¹ä¸ã§è¤æ°ã®SSLãµã¤ããéç¨ã§ããããã«ããã¨ãããé·ããæã¡æã¾ãã¦ããæ©è½ã ããã ããã¾ã§ã¯ãç¹å®ã®IPã¢ãã¬ã¹ã«å¯¾ãã¦SSL対å¿ã®Webãµã¤ããå²ãå½ã¦ãå ´åããã®ãµã¤ã1ã¤ããSSL対å¿ã®Webãµã¤ããéç¨ãããã¨ãã§ããªãã£ããã¤ã¾ããIPã¢ãã¬
å宿ã§éã人㫠mod_xsendfile ãæãã¦ããã£ã¦ããããã¦èªã¿ãããã«å ¥ãã¦ã¿ããçµæ§ããæããªã®ã§ã¡ã¢ã â mod_xsendfile ã¨ã¯ PHPãªã©ã®ã¹ã¯ãªããããéçãªãã¡ã¤ã«ï¼ç»åãã¡ã¤ã«ãªã©ï¼ãéä¿¡ããã¨ãã«ä½¿ã便å©ãª apache ã¢ã¸ã¥ã¼ã«ã â ä»çµã¿ header("X-Sendfile: ï¼ç»åãã¡ã¤ã«ãã¹ï¼"); ã¨åºåããã°ãX SendFile ããã¼ã«ã«ããç»åãã¡ã¤ã«ãå¼ã£å¼µã£ã¦ãã¦ãLast-Modified ãªã©ã®ãããæ å ±ãã¤ãã¦å¾ã®å¦çããã¦ãããã ã¤ã¾ããã¹ã¯ãªããã使ã£ã¦ããªããç°¡åã«éçãªãã¡ã¤ã«ãéä¿¡ãã¦ããããã«è¦ãããã¨ãã§ããã ï¼â»ã»ãã¥ãªãã£è¨å®ã«é¢ä¿ãªããä»»æã®ãã¹ãæå®ã§ããã¨ããããã½ï¼ â ããããã¦èªã¿ãããã§ã¯ ããã¾ã§ãLocation: ããããã¤ãã£ã¦ãªãã¤ã¬ã¯ããã¦ç»åã表示ããã¦ããã ãã®æ¹å¼ã®æ¬ ç¹
ããªãã¯èªåã®ä¼ç¤¾ã®ã¦ã§ããµã¤ãããµã¼ãã¹ããApacheãã¤ã³ã¹ãã¼ã«ããã¨ããã ã¨ããããApacheã¯ã¹ã ã¼ãºã«åä½ãã¦ãããä¸ãä¸ã®å ´åã«ãLinuxã®ã»ã¼ããã£ããããå©ãã«ãªãã¯ãã ã¨æããã¨ãããã2é±éã»ã©çµã£ãã¨ããã§ãããããã¨ããããªãã¨ãèµ·ããå§ããããªãã ãããApacheã¨Linuxã使ã£ã¦ããã®ã«ã»ã»ã»ãããããªããã¨ãªã©ããã ãããï¼ ãã¡ããã注æãæããªããã°ããããããªããã¨ã¯ãããã§ãããå¾ããApacheãå®å ¨ã«ããæ¹æ³ã¯ãããããã¡ããä½ãããªããã°å®å ¨ã«ã¯ãªããªãã以ä¸ã«ç¤ºãã®ã¯ãApacheãããå®å ¨ãªã¦ã§ããµã¼ãã«ããããã®ç°¡åãª10ã®æ¹æ³ã ã #1: ã¨ã«ããã¢ãããã¼ã Linuxã§Apacheãåããã¦ããããã¨è¨ã£ã¦ãã¢ãããã¼ããä¸è¦ã ã¨ãããã¨ã«ã¯ãªããªãã常ã«æ°ããã»ãã¥ãªãã£ãã¼ã«ããªã¹ã¯ãç»å ´ãã¦ãããããªãã¯ãææ°ã®ãã
Apache 㧠Digest èªè¨¼ã®è¨å®ã¨ããè¨äºãæ¸ãã¾ããããInternet Explorer 6 㧠hoge.cgi?foo=bar ã®ãã㪠URI ã«ã¢ã¯ã»ã¹ãã㨠400 Bad Request ãçºçãã¦ãã¾ããã¨ãåããã¾ããã Apache ã®ã¨ã©ã¼ãã°ã«ã¯æ¬¡ã®ããã«è¡¨ç¤ºããã¦ãã¾ãã Digest: uri mismatch - <hoge.cgi> does not match request-uri <hoge.cgi?foo=bar> Mozilla ãªã©ä»ã®ãã©ã¦ã¶ã§ã¯åé¡ãªãã®ã§ãIE6 ã®ä¸å ·åã®ããã§ãã apache ã®èªè¨¼ãæå·å#ä¸å ·åã«ããã¨ãApache ã® mod_auth_digest.c ã«ããããå½ã¦ããã¨ã§åé¿ã§ããããã§ãã æ¬æ¥ã¯ IE6 ã対å¿ãã¹ãã ã¨æãã¾ãããä»æ¹ãªãã®ã§ããããå½ã¦ã¦ãRPM ããã±ã¼ã¸ãæ§ç¯ãã¾ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}