AWSã§ãªã¼ãã¹ã±ã¼ã«ããè¨å®ã§AWS Configã使ãã¨ãã¯æ³¨æ
AWSã§ä»¥åããæ°ã«ãªã£ã¦ããSecurity Hubã試ãã¦ã¿ããã¨æããã£ããã1é±éå¾ã«Cost Explorerãè¦ããäºæ³å¤ã«ã³ã¹ããããã£ã¦ãã¦é©ããã
Security Hubãã®ãã®ã¯åå30æ¥éç¡æãªã®ã ããSecurity Hubã®ç¨¼åã«å¿ è¦ãªConfig (AWS Config)ã¯ç¡ææéãªããªã®ã§è©¦ãã¨è¨ã£ã¦ãè²»ç¨ãããã£ã¦ãã¾ããConfigã¯AWSã®ãããããµã¼ãã¹ã®æä½ãã°ã¨è¨å®ã®ã¹ãããã·ã§ãããåã£ã¦ãéç¨ããªã·ã¼ï¼ã«ã¼ã«ï¼ã«åããè¨å®ãåå¨ããã¨ãã«è¦åãåºããããèªåçã«ä¿®å¾©ãããã¨ãã§ããããããSecurity Hubã¯ãã®ä»çµã¿ã使ã£ã¦AWSå ã®è¨å®ã§ã»ãã¥ãªãã£ä¸åé¡ããããã®ãéç´ã表示ããã¨ãããã®ã
ã§ãAWSã§æä½ããªãéãConfigã®ãã°ã¯ããããå¢ããªãã¯ããªã®ã ãã©ãEC2ã§ãªã¼ãã¹ã±ã¼ãªã³ã°ããããã«ãã¦ããã¨ããã§ã¯ãªãã®ã ãã¤ã³ã¹ã¿ã³ã¹ãä½ã£ã¦èµ·åãã¦åæ¢ãã¦åé¤ãã¦ã¨ããæä½ã®ã¿ã¤ãã³ã°ã§ãã¡ãã¡Configã®ãã°ãå¢ãã¦ãããããã¦æ°ãããã°ã«å¯¾ãã¦åé¡ããããã©ãã審æ»ããªãããã
Configã®æéä½ç³»ã¯ãAWS ã¢ã«ã¦ã³ãã«è¨é²ãããè¨å®é ç®ããã 0.003USDãã¨ãã«ã¼ã«è©ä¾¡ãã¨ã« 0.001USDï¼æåã®10ä¸ä»¶ï¼ã0.0008USDï¼æ¬¡ã®40ä¸ä»¶ï¼ã0.0005USDï¼50ä¸ä»¶è¶ ï¼ãã¨ãªã£ã¦ãããSecurity Hubãä½æããã«ã¼ã«ã¯å ¨é¨ã§191件ãã£ãããã£ã1é±éã§2ä¸ä»¶ã»ã©ã®è¨é²ããªããã¦ããã2ä¸ä»¶â60ãã«â7000åãããï¼ãªã¼ãã¹ã±ã¼ãªã³ã°ã§ã¤ã³ã¹ã¿ã³ã¹ãå¢ãããæ¶ããããããã³ã«èª²éããã¦ããã®ã ãããå ·ä½çã«ã©ãããã«ã¦ã³ãã«ãªã£ã¦ãããã¾ã 調ã¹åãã¦ããªããConfigãéãããã°ã¯S3ãã±ããã«ä¿åãããã®ã§æéãããã°è©³ç´°ã調ã¹ã¦ã¿ããã
ææã¨è¨ã£ã¦ãããé«ããã®ã§ã¯ãªãã ããã¨æã£ã¦ããããæ³å®å¤ã®ã³ã¹ããããã£ã¦ãã¾ã£ã¦é©ããããªã¼ãã¹ã±ã¼ãªã³ã°ãæå¹ã«ãªã£ã¦ããã¨èª²éã¿ã¤ãã³ã°ãå¢ãã¦ä½åãªã³ã¹ããããã£ã¦ãã¾ãããã ã¨æ¨æ¸¬ããã
åèæ å ±
- AWS Config ã§è¨é²ããããªã½ã¼ã¹ãéå®ãã | 空æ³ããã°
Security Hubã§ã¯ãªãConfig Rulesã§ã®è¨äºã ãåºæ¬çã«ã¯åããã¨ãConfigã§è¨é²ãã対象ãéå®ãã¦ã³ã¹ããããã¾ãªãæ¹æ³ãç´¹ä»ãã¦ãã -
AWS Security Hub ãæå¹ã«ãã㨠AWS Config ã®å©ç¨æãåå¢ãã話 - ãµã¼ãã¼ã¯ã¼ã¯ã¹ã¨ã³ã¸ãã¢ããã°
AWSãµãã¼ãã¨ã®ããã¨ãã§Configã®ã³ã¹ãå¢ã®åå ã調ã¹ãããã®S3ãã±ããã®ã¯ã¨ãªãè¼ã£ã¦ãããEC2ã¤ã³ã¹ã¿ã³ã¹ã100å°ä»¥ä¸å¤éåæ¢ãã¦ãããã¨ã«ãããã®ã ããã -
AWS Configã®è«æ±éé¡ãé«ããªã£ãåå ã調ã¹ã¦ã¿ã - Qiita
ãªã¼ãã¹ã±ã¼ãªã³ã°ã§ã³ã³ããã®å¢æ¸ãããã¨ã³ã¹ãããããã¨ã®ãã¨ããã¡ããConfigã®ãã°ã®ã¯ã¨ãªãããConfigã®å¯¾è±¡ããç¹å®ã®AWSãªã½ã¼ã¹ãé¤å¤ããæ¹æ³ã«ã¤ãã¦ããä¸çªããã¾ã¨ã¾ã£ã¦ãããÂ
èªåã®é»è©±çªå·ãè©æ¬ºãµã¤ãã®ãµãã¼ãã»ã³ã¿ã¼ã¨ãã¦æ²è¼ããã¦ãã件
å§ã¾ãã¯çªç¶ã«ï¼
å æãããããå¿å½ããã®ãªãé»è©±çªå·ããçä¿¡ãã¨ãã©ãæ¥ãããã«ãªã£ãã
大æ¹ä½ãã®å§èªãã¨æã£ã¦åããã«ããã®ã ããã©ãå æ¥ä½ãã®æ°ãåãã¦åã£ã¦ã¿ããã¨ã«ãããããã¨çªç¶ããã¡ãã§æ³¨æããè»ã®ãã¼ãã®ãã¨ãªãã§ãããã¨è©±ãå§ãããä½ã®ãã¨ãããããããªãããã¨ããããä¸éãèããå¾ã§ãã©ãã§æ³¨æããããã§ããï¼ãã¨èãã¦ã¿ãã¨ãµã¤ãåãæãã¦ãããããµã¤ãåãªã®ããã¡ã¤ã³ãªã®ãããèãåããªãã£ãããã©ããããã®é販ãµã¤ãã§è³¼å ¥ããããããããã§ãã®é販ãµã¤ãã«è¼ã£ã¦ããé»è©±çªå·ã«é»è©±ããã¨ã®ãã¨ã§ãã£ãã
ã¨ããããèªåã¯è»ã®ãã¼ã販売ããã¦ããªããã ã®å人ã§ãããã¨ãä¼ããé»è©±çªå·ãééãã¦ããã®ã§ã¯ãªããã¨ä¼ããã¨ç¸æãç´å¾ããã®ãã話ã¯çµããã¨ãªã£ãã
ããã§çµããã°ããã ã®ééãé»è©±ã ã£ããã ãªã§çµããã®ã ãããã§ã¯ãªãã£ããåå¾ã«ãªã£ã¦å度å¥ã®äººããããã¡ãã§æ³¨æããè»ã®ãã¼ãã®çºéã¯ãã¤ãªã®ããã¨ããé»è©±ããã£ããããã¯ç©ããã§ã¯ãªããªã¨æããå ã»ã©ã¨åãããã«ãµã¤ãåãå°ãããä½åº¦ãèãè¿ããªããå¤æããã®ã¯ãââ.xyzãã¨ãããã¡ã¤ã³åã ã£ãããã¯ããã£ãã®äººã¨åãããã«ãã®é»è©±çªå·ãåãåããå ã¨ãã¦æ²è¼ããã¦ããã¨è¨ããé»è©±å ã®äººã«åæ ãã¤ã¤ãèªåããã®ãµã¤ãã®ãªã¼ãã¼ã§ã¯ãªããã¨ãä½ã®é¢ä¿ããªãå人ã§ãããã¨ãä¼ããååãå±ããªãã¨ãããã¨ã§ããã°è¦å¯ã«ç¸è«ããæ¹ãããã®ã§ã¯ãªããã¨è¨ã£ããã¨ãä¼ããã
çªç¶ã®ãã¨ã§ç¶æ³ãåã¿è¾¼ããé©ããããã ã£ããããã«ç¶æ³ãç解ããããã§ãè¦å¯ã«ç¸è«ããæ¹åã§è©±ãé²ãã ããã®éã«ãã®é»è©±çªå·ãä¼ãã¦ãåé¡ãªããã¨èãããã®ã§ãã¡ããã¨åæãã¦è©±ã¯çµãã£ãã
2人ã¨ãèªåãè©æ¬ºãµã¤ãã®è¢«å®³è ãããããªãã®ã«ããããªãã¨ç´å¾ãã¦ãããã®ã§ããã£ããããéãããããæ»ã£ã¦ããªããã¨ãæãã¨ãããããã«æããã©ã¡ããåè¯ãããªæãã§ãã£ããä¼¼ããããªè¨ãããã£ãã®ã¯å¶ç¶ã ãããã
ãµã¤ããè¦ã¦ã¿ã
åé¡ã®ãµã¤ãã®ãã¡ã¤ã³ãåãã£ãã®ã§ã¢ã¯ã»ã¹ãã¦ã¿ããã¨ã«ãããèªåã®ãã½ã³ã³ã§ã¢ã¯ã»ã¹ããã¨ã»ãã¥ãªãã£ã½ããã«ãããå±éºãµã¤ãã®è¦åãåºãããã®æç¹ã§ãããå¯ãã§ããã
è¦åãç¡è¦ãã¦ãµã¤ãã«ã¢ã¯ã»ã¹ããã¨ãã©ããã®é販ãµã¤ããã¾ããããã§ããªãCMSã®ããã©ã«ããã®ãããªã·ã³ãã«ãªé販ãµã¤ãã表示ããããè»ã®ãã¼ããµã¤ãã¨ããããã§ã¯ãªãããã¨ãããããã®ãæ±ã£ã¦ããããã ï¼è¦ããä¸ã¯ï¼ããã£ããã©ããã¦ãã®ãµã¤ãã§è³¼å ¥ãããã¨æãã®ã ãããã¨ããé ãæ±ãããããããã©ããã£ãããã®ãµã¤ãã«ãã©ãçãã®ã ãããä¸ã®ä¸ã«ã¯ãããããµã¤ãã§ã注æãã人ããããªãã«ããã®ã§ããã
ãä¸å¯§ã«ç¹å®ååå¼æ³ã®è¡¨ç¤ºãããããã®åãåããå é»è©±çªå·ã¨ãã¦ãããã«èªåã®é»è©±çªå·ã表示ããã¦ãããã¨ã確èªãããã¾ããå ¨ãã¼ã¸ã®ããã¿ã¼ã«ãµãã¼ãã»ã³ã¿ã¼ã®è¨è¼ãããããã®é»è©±çªå·ãèªåã®é»è©±çªå·ã¨ãªã£ã¦ãããããããããè¦ãã°ãã®é»è©±çªå·ã«ããã¾ãããè³¼å ¥åã«é»è©±ãã¦ãã°ããã£ãã®ã«ã¨æããªãããªãã
責任è æ°åã¨æå¨å°ãæ¸ããã¦ãããã§ãããã ãããæå¨å°ã«ããã£ã¦ã¯ãé½å ãããä½æãæ¸ããã¦ããããæ¤ç´¢ãã¦ã¿ãã¨ãããã®åºã«ãã®çºåã¯åå¨ããªãããã ã£ãã
ãã¦ã©ãããããéå ±ããª
ãã¾ã®ã¨ããèªåã¯ä½ä»¶ãééãé»è©±ãããã£ã¦ããã¨ããã ãã§ãç´æ¥å¤å¤§ãªè¢«å®³ãåããããã§ã¯ãªããã ããã¨è¨ã£ã¦ãã®ç¶æ³ãæ¾ç½®ãã¦ããããã¯ãªãã ãããã§ããã°èªåã®é»è©±çªå·ã®è¨è¼ãããã¦ã»ããããè©æ¬ºãµã¤ãã®åå¨ããããã¹ãæ©é¢ã«å±ãã¦å¯¾å¦ãã¦ãããããã¨æãã
èªåã注æãã¦ããã°è©æ¬ºã®è¢«å®³è ã¨ãã¦ãæ¶è²»è åºãçæ´»ç¸è«ã»ã³ã¿ã¼ãè¦å¯ã«ç¸è«ããã被害å±ãåºãããã¨ãããã¨ã«ãªãããèªåã®ç«å ´ã ã¨ã©ãããã°ããã®ãã
ã¨ãããã#9110ããªã¨æã£ã¦é»è©±ãããã¦ã¿ããã¤ãªãããªãã®ã§å¥ã®æ段ãåããã¨ã«ããããã°ããæ¤ç´¢ãã¦ã¿ãããèªåã®å ´åã¯è¦è¦åºã®ãµã¤ãã¼ç¯ç½ªã«é¢ããæ å ±æä¾ããé£çµ¡ããã°ãããããªã®ã§ãããããã¨ã«ããã
ä»ã«ãããã¨ã¯
ã©ããè©æ¬ºãµã¤ããCloudflareã使ã£ã¦ããããã ã£ãã®ã§ãCloudflareã®éå ±ãã©ã¼ã ãããé£çµ¡ãããã¨ã«ãããCommentsã«ã¯ã·ã³ãã«ã«"Stop this website."ã¨æ¸ããã
ãã¨ã¯ç¡é§ã ã¨æããªããããå½è©²è©æ¬ºãµã¤ãã®ãã©ã¼ã ã¨é£çµ¡å ã®ã¡ã¼ã«ã¢ãã¬ã¹ã«ããã®é»è©±çªå·ã®æ²è¼ãæ¢ããããé£çµ¡ããã
ããã¨â¦
ç¿æ¥ååä¸ã«æå¯ãã®è¦å¯ç½²ã®çæ´»å®å ¨èª²ããé»è©±ããã£ãããç¸è«ãã¨ãã¦æ¿ãã¨ã®ãã¨ã ã£ããã被害å±ãã®æ±ãã¨ã¯ããªãã¨ãããã¨ã ãããç¹ã«ç®ç«ã£ã被害ã¯ãªãã®ã§ããã§åæãããè¦å¯ã¨ãã¦ç¹ã«ããããã¨ã¯ãªãããã§ãå¼ãç¶ãé»è©±ãããã£ã¦ãããããªãé»è©±çªå·ã®å¤æ´ãæ¤è¨ããããã«è¨ãããããããã¯å¤§ããªãä¸è©±ã ãããæ å½è ã¯ãã¾ããã®æã®ãã¨ã«ç¥èããªãããã§ãè¦åãåºãã®ã§ã¢ã¯ã»ã¹ã§ããªããçµæã¨ãã¦ãµã¤ãã®å 容ã確èªã§ããªãã¨ã®ãã¨ã ã£ããã¾ã使ãããé»è©±çªå·ã¯050ã®IPé»è©±ãªã®ã ããæºå¸¯é»è©±ã®çªå·ãªã®ãã¨ãèãããããµã¤ãã«ã¤ãã¦ã¯å¥ã®é¨ç½²ãªã©ã§è©³ãã調ã¹ãã¨ã¯è¨ã£ã¦ããããã¨ããããè¦å¯å ã§ä¸éãã®æ±ãã¯ãã¦ãããããã§ã¯ãã£ããé£çµ¡ãããã¨ã¯æã£ã¦ãªãã£ãã®ã§ãæã£ã¦ããããã¯ãã¡ãã¨å¯¾å¿ãã¦ããããã¨ããå°è±¡ã
èªåã®ä¸ã§ã¯æ¨æ¥ä¸éãã®éå ±ããã¦æ¸ãã ãã¨ã®ã¤ããã ã£ãããè¦å¯ããé»è©±ãããããã®ããã¨ãã®ä¸ã®ã¢ã¯ã»ã¹ã§ããªãã®ä¸è¨ãæ°ã«ãªã£ãã®ã§ãå度ã¢ã¯ã»ã¹ãã¦ã¿ããã¨ã«ãããããã¨ãè¦åãåºã¦ã¢ã¯ã»ã¹ã§ããªãã¨ãã§ã¯ãªãã確ãã«ã¢ã¯ã»ã¹ã§ããªããã©ããDNSã¬ã³ã¼ããåé¤ãããããã ãCloudflareã¸ã®éå ±ãå¹ããã®ã ãããããããªç´ ç´ãªä¼ç¤¾ã«ã¯æããªãã£ããããµã¤ããªã¼ãã¼ãéããã¨ãããã¨ã ãããã
èªåã®é»è©±çªå·ã®æ²è¼ãæ¢ã¾ã£ãã¨ããç¹ã§ã¯åã°ãããã被害ã«éã£ã人ã®èª¿æ»ãé£èªããã®ã§ã¯ãªããã¨ããå°æããçµæ«ã¨ãªã£ãã
追è¨
ã¤ã³ã¿ã¼ãããã»ãããã©ã¤ã³ã»ã³ã¿ã¼ã«ãéå ±ãã¦ãã¾ããã
ãã¨ãã¦ã§ãéæãåããã¨ãããã©robots.txtã«ãã£ã¦ç¦æ¢ããã¦ãã¦ã§ããªãã¨ã®ãã¨ã§ããã
elFinderã¯PHPã®post_max_sizeã¨upload_max_filesizeãç¡è¦ãã
elFinderã¯ãã©ã¦ã¶ã§åä½ãããã¡ã¤ã«ããã¼ã¸ã£ã¼ã§ããµã¼ãã¼ãAWS S3ãDropboxã®ãã¡ã¤ã«ãæ±ãããã¼ã«ã§ããããµã¼ãã¼å´ã¯PHPã§åä½ããããã«ãªã£ã¦ããã
ã¿ã¤ãã«ã®ãç¡è¦ãããã¨ãã表ç¾ã¯æ£ç¢ºã§ã¯ãªãããã¢ãããã¼ããããã¡ã¤ã«ã®å¤§ãããå¶éãããã¨æã£ãã¨ãã«ããµã¼ãã¼å´ãPHPã§åãã¦ããã®ã ããphp.iniãªã©ã§post_max_sizeã¨upload_max_filesizeãè¨å®ããã®ãæ®éã®çºæ³ã ã¨æããããããå¹ããããã£ã¨å¤§ããªãµã¤ãºã®ãã¡ã¤ã«ãelFinderã§ã¢ãããã¼ãã§ãã¦ãã¾ãããªããã¨è¨ãã¨ãelFinderã¯åå²ã¢ãããã¼ãã«å¯¾å¿ãã¦ããããã§ããã
post_max_sizeã¨upload_max_filesizeã¯ä½ã
ã©ã¡ããPHPã®è¨å®é ç®ã§ãpost_max_sizeã¯POSTããéã®ãã¼ã¿ãåãå ¥ãå¯è½ãªæ大ãµã¤ãºããupload_max_filesizeã¯ãã¡ã¤ã«ãã¢ãããã¼ãããéã®ãã¡ã¤ã«ãµã¤ãºã®ä¸éãå®ãã¦ãããpost_max_sizeã¯ãã®POSTã§ã®åè¨ãã¼ã¿ãµã¤ãºãªã®ã§ãupload_max_filesizeãpost_max_sizeãã大ãããã¦ãæå³ã¯ãªããè¤æ°ãã¡ã¤ã«ãåæã¢ãããã¼ãããã¨ãã¯ã1å1åãupload_max_filesizeããå°ãããªãã¨ãããªãããåè¨ãµã¤ãºãpost_max_sizeããå°ãããªãã¨ãããªããæ®éã«<input type="file">ã§ãã©ã¼ã ãä½ãã¨ãã®å¶éã«å¾ããªãã¦ã¯ãããªãã
elFinderã§ã¯ï¼
elFinderã§ãã¡ã¤ã«ãã¢ãããã¼ãããå ´åã¯ãããã®å¶éãå®è³ªç¡è¦ã§ãããã¨ã«ãªãããã¡ããpost_max_sizeãupload_max_filesizeã®ã©ã¡ããã0ã«ãªã£ã¦ãã¦ãä¸åã¢ãããã¼ããã§ããªãè¨å®ã®å ´åã¯elFinderã§ãã¢ãããã¼ãã¯ã§ããªããªãããããå°ããªãã¡ã¤ã«ãã¢ãããã¼ãã§ããè¨å®ã«ãªã£ã¦ããã°ãelFinderã¯ãã®è¨å®ãæ¤ç¥ãã¦ãã¢ãããã¼ãå¯è½ãªãã¡ã¤ã«ãµã¤ãºã«åå²ãã¦ã¢ãããã¼ããããã¨ããï¼chunked uploadingï¼*1ãããã«ããã©ããªã«å¤§ãããã¡ã¤ã«ã§ãã¢ãããã¼ãã§ãããã¨ã«ãªã*2
ã§ã¯elFinderã§ã¢ãããã¼ããµã¤ãºãå¶éãããå ´åã¯ï¼
ãã®ã¾ã¾ã ã¨ä¾ãã°elFinderã«ã¢ã¯ã»ã¹å¯è½ãªäººã«æªæããã£ããããµã¨ãããããæãã¤ããããã¦ã1TBã®ãã¡ã¤ã«ãã¢ãããã¼ãããã¨ããå¯è½ã«ãªã£ã¦ãã¾ãã®ã§ãã¢ãããã¼ãã§ãããã¡ã¤ã«ãµã¤ãºã®ä¸éãè¨å®ãã¦ãããæ¹ããããuploadMaxSizeã¨ããé ç®ã§è¨å®ã§ãããããã¯ãµã¼ãã¼å´ã«è¨ç½®ããphpã¹ã¯ãªããå ã§æå®ããã
Â
PHPã®æ¹ã§ä¸éãè¨å®ãã¦ããã®ã«elFinderã ã¨ãã以ä¸ã®ãã¡ã¤ã«ããããã§ãã¢ãããã¼ãã§ãã¦ãã¾ãããªãã§ï¼ï¼ï¼ã¨ãªã£ãã®ã§ãããã«èª¿ã¹ãå 容ãã¾ã¨ãã¦ãããä¸éã«å¼ã£ããã£ã¦ã¢ãããã¼ãã§ããªããå°ã£ãã¿ãããªæ å ±ã¯ãããã§ãåºã¦ããã®ã ããä¸éã®è¨å®ãå¹ããªãã¦å°ã£ãã¨ãã話ã¯ãã¾ãè¦ãããªãã£ããããããåå²ã¢ãããã¼ãããµãã¼ããå§ããã®ãããã¨æè¿ãªã®ã ããã
*1:å®éã®ã¨ãããè¥å¹²ã®ãã¼ã¸ã³ãåã£ã¦ããã®ã§ãä¾ãã°post_max_sizeã1ã¨ãã ã¨ã¢ãããã¼ãã¯ã§ããªãã
*2:ãã¡ããå®éã¯PHP_INT_MAXãä¸éã¨ãªããæ®éã¯ãã®åã«ãµã¼ãã¼ã®ã¹ãã¬ã¼ã¸ãµã¤ãºãåé¡ã«ãªããã©ã
ãã°ä¿®æ£ã®ãã2020å¹´3æ4æ¥ã«Let's Encryptã®è¨¼ææ¸ã®ä¸é¨ãå¼·å¶çã«å¤±å¹ãã件
æ ã¦ã¦ã¡ã¼ã«ããã¯ã¹ãè¦ã¦ã¿ãã¨Let's encryptãããACTION REQUIRED: Renew these Let's Encrypt certificates by March 4ãã¨ããã¿ã¤ãã«ã®ã¡ã¼ã«ãå±ãã¦ãã¾ãããå·®åºäººï¼FROMï¼ã¯ã[email protected]ãã§ããã3æ4æ¥ã¾ã§ã«ãã®ãã¡ã¤ã³ã®è¨¼ææ¸ãrenewããã£ã¦ãã¨ã§ããã
対å¿ã¨ãã¦ã¯ --force-renew ã§ééããªãããã§ããã¡ã¼ã«æ¬æã«ãããæ¸ããã¦ã¾ããã
Revoking certain certificates on March 4 - Help - Let's Encrypt Community Support ã«ããã°ã2020-03-04 20:00 UTCã¤ã¾ãæ¥æ¬æéã®3æ5æ¥åå5æãã対象ã¨ãªã証ææ¸ã失å¹ãããä½æ¥ãè¡ãã¨ã®ãã¨ã§ãããããªéè¦ãªãã¨ã¯Let's Encryptã®ããããã¼ã¸ã«ãè¼ãã¦ãããâ¦ã
Â
Â
Â
Â
Â
Â
Â
AWS EC2ã§ãã°ã¤ã³æ段ã失ã£ãæ¢åã®ã¤ã³ã¹ã¿ã³ã¹ã«èªåã®SSHå ¬ééµãå ¥ããæ¹æ³
- 対象ã®ã¤ã³ã¹ã¿ã³ã¹ãã[ããªã¥ã¼ã ]ããã¿ãããã
æ»ããããã«ãã©ã®ããªã¥ã¼ã ãã©ã®ã¤ã³ã¹ã¿ã³ã¹ã®ã©ã®ããã¤ã¹ï¼/dev/xvda1ãªã©ï¼ã«ã¢ã¿ããããã¦ããã®ãã¯ã¡ã¢ãã¦ãããã¾ãã¯ããªã¥ã¼ã ã«åããããã«ååãä»ãã¦ããã - ãã°ã¤ã³å¯è½ãªä»ã®EC2ã¤ã³ã¹ã¿ã³ã¹ã«ã¢ã¿ãããã
ã¢ã¿ããå ã®ã¤ã³ã¹ã¿ã³ã¹ã¯runningã§ãåé¡ãªããåãã¢ãã¤ã©ããªãã£ã¾ã¼ã³ã«ããå¿ è¦ããã - ã¢ã¿ããããã¤ã³ã¹ã¿ã³ã¹ã«ãã°ã¤ã³ãã¦ãå
ã»ã©ã¢ã¿ããããããªã¥ã¼ã ãæåã§ãã¦ã³ãããã
ä¾ï¼sudo mount /dev/xvdf /mnt - .ssh/authorized_keysã«å ¬ééµæ å ±ã追å ãã
- ã¢ã³ãã¦ã³ããã
- ãã¿ãããã
- å ã®ã¤ã³ã¹ã¿ã³ã¹ã«ã¢ã¿ãããã
AWS Route 53ã§Googleã®ãã¡ã¤ã³ææè èªè¨¼ããã¤ã¤ãSPFã®è¨å®ãè¡ã
å ã»ã©
ãããã£ã¦ãAWSã®DNSãµã¼ãã¹ã§ããRoute 53ã§ã¯TYPEã«SPFãé¸ã¹ã¦ãã¾ããé¸ãã§ã¯ãããªããTXTã«ããªããã°ãªããªãã
ã¨æ¸ããããRoute 53ã§ã¯TXTã¬ã³ã¼ãã¯ï¼ãã¡ã¤ã³ã«å¯¾ãã¦ï¼ã¤ããè¨å®ã§ããªãã
ã¡ã¼ã«ã¢ãã¬ã¹ã®ãã¡ã¤ã³ãã¼ãã«ä½¿ç¨ãã¦ãããã¡ã¤ã³ã®TXTã¬ã³ã¼ãã«ãã§ã«Googleã®ãã¡ã¤ã³ææ権確èªã®ããã®å¤ï¼"google-site-verification:xxxxxxxxxxxxxxxxxxxxx"ï¼ãè¨å®æ¸ã¿ã®å ´åã¯ã©ãããã°ããã*1ã
ï¼TXTã¬ã³ã¼ããè¤æ°è¨å®å¯è½ãªDNSãµã¼ãã¹ã§ããã°ãTXTã¬ã³ã¼ããå¥ã«è¨å®ããã°ããï¼
SPFã¬ã³ã¼ãã¯TXTã¬ã³ã¼ãã¨ãã¦è¨å®ããªãã¦ã¯ãããªãã®ã ããããã¡ã¤ã³ã®ææ権確èªãTXTã¬ã³ã¼ãã§ããã®ãããããã¦å¥ã®æ¹æ³ã§ãããããªãã
å¥ã®æ¹æ³ã ã¨ãGoogle Analyticsãªã©ã§ãããªãã¿ã®ããã¥ã¡ã³ãã«ã¼ãã«æå®ããããã¡ã¤ã«ãè¨ç½®ããæ¹æ³ãããããCNAMEを設定する方法もあるã®ã§ããã使ãã
SPFãè¨å®ãããã¨ãã¦ã¿ã¤ãã«SPFã使ç¨ãã¦ã¯ãããªãï¼TXTã使ç¨ããï¼
RFC 4408ã ã¨TXTã¬ã³ã¼ãã§ãSPFã¬ã³ã¼ãã§ããããï¼äºææ§ã®ããã«TXTã¬ã³ã¼ãæ¨å¥¨ï¼ã¨ããæãã ã£ãã¨æãããRFC 7208ã§ã¯
SPF records MUST be published as a DNS TXT (type 16) Resource Record
https://tools.ietf.org/html/rfc7208#section-3.1
(RR) [RFC1035] only.
ã¨TXTã¬ã³ã¼ãã«è¨è¿°ããªããã°ãªããªãï¼MUSTï¼ã¨ãªã£ã¦ãã¦ãSPFã¬ã³ã¼ãã«æ¸ã話ã¯ãªããªã£ã¦ããã
çç±ã¿ãããªã®ã¯https://tools.ietf.org/html/rfc7208#section-14.1ã«æ¸ããã¦ããã
ãããã£ã¦ãAWSã®DNSãµã¼ãã¹ã§ããRoute 53ã§ã¯TYPEã«SPFãé¸ã¹ã¦ãã¾ããé¸ãã§ã¯ãããªããTXTã«ããªããã°ãªããªãã
ä½è«ã ããDNSã®ãªã½ã¼ã¹ã¬ã³ã¼ãã¿ã¤ãï¼Resouce Record Typeï¼ã¨ãã¦ã®SPFã¬ã³ã¼ãã¨SPFã®å¤ã¨ãã¦ã®SPFã¬ã³ã¼ããæ··å¨ãã¦ãã¦ã¨ã¦ãããããããä»åã®è©±ãã¾ã¨ããã¨ãSPFã¬ã³ã¼ãï¼SPFå¤ï¼ã¯SPFã¬ã³ã¼ãï¼RR Type=SPFï¼ã§ã¯ãªãTXTã¬ã³ã¼ãï¼RR Type=TXTï¼ã«æ¸ããã¿ãããªãã¨ã«ãªãã®ããªã
SPFã«é¢ãã¦ããåç §ãããã§ãããSPF(Sender Policy Framework) : 迷惑メール対策委員会ãæ¸ãããæç¹ï¼2010å¹´1æï¼ã§ã¯RFC 7208ï¼2014å¹´4æï¼ã¯åå¨ããããã®ä»¶ã«ã¤ãã¦ã¯å¤ãæ å ±ã¨ãªã£ã¦ãã¾ã£ã¦ããã®ã§æ³¨æãå¿ è¦ã