auã®SSLã§ã®Cookieã®æåããããã
auã¯Cookieã使ããã¨ãåºæ¥ãããã£ãªã¢ã®å
¬å¼æ
å ±ã¨ãã¦ãå
¬éããã¦ããã
ã404 Not Foundã
EZweb対å¿ç«¯æ«ã«ããã¦Cookieã¯ãEZãµã¼ãã«ä¿ç®¡ããã¾ãã
ãã ããWAP2.0ãã©ã¦ã¶æè¼ç«¯æ«ã§ã¯End to Endã®SSLéä¿¡æã¯ç«¯æ«ã«ä¿ç®¡ããã¾ãã
ãªããEZãµã¼ãã«ä¿ç®¡ãããCookieã¯KDDIè¨åã®ã¡ã³ããã³ã¹ãªã©ã«ãããªã»ãããããå ´åãããã¾ãã
ã¤ã¾ã
- httpã®éSSLé åã§ã¯ãã²ã¼ãã¦ã§ã¤ï¼EZãµã¼ãï¼ãCookieãä¿ç®¡ãã
- httpsã®Ent to Endã®SSLé åã§ã¯ã端æ«ãCookieãä¿ç®¡ãã
ã¨ãããã¨ã ã
ãããçµæ§æ²è ã§ããã
ããã«ãå ¬å¼ãªè³æã¯ãªããã©ã端æ«ã®æåããæ³åããã«ä»¥ä¸ã®ãããªæåãããã
- httpé åã§ã¯ãGWã¨ç«¯æ«ã®ä¸¡æ¹ã®Cookieãéã£ã¦ãã
- httpé åã§ãGWã¨ç«¯æ«ã«åãååã§Cookieãè¨å®ããã¦ããå ´åã端æ«ã®Cookieãåªå ãã
- httpé åããã¯ã端æ«ã®Cookieãæä½ãããã¨ã¯åºæ¥ãªã
- httpsé åã§ã¯ãå½ç¶GWã®Cookieã¯åç §ã§ããªã
å®é¨
ãããã«ä»¥ä¸ã®ãããªãã¡ã¤ã«ãåä¸ãã¡ã¤ã³ã® http 㨠https
é åã«ç½®ãã¦ã確èªããã¦ã¿ãã
<html> <head> <meta http-equiv="Pragma" content="no-cache"> </head> <body> <pre> <?php print_r($_COOKIE); $value = "test:".date('H:i:s').' '.$_SERVER['SERVER_PORT']; $timeout = time() + 30; setcookie("test",$value,$timeout); setcookie("test".$_SERVER['SERVER_PORT'],$value,$timeout); ?> </pre> <hr> <a href="http://example.com/?nocache=<?php echo md5(microtime()) ?>">http</a><br> <a href="https://example.com/?nocache=<?php echo md5(microtime()) ?>">https</a><br> </body> </html>
httpãhttps é åã§ããããè¨å®ãã cookie
ãããããã®ç°å¢ã§ç¢ºèªãã¦ã¿ãã¨ãããã®ã ã
Cookie
ã®æå¹æéãæå®ããªãå ´åã«ã¯ãããã©ã«ãã§1æ¥ã«ãªãããããã¹ãã®ããã«çãã«æéè¨å®ããã¦ããã
確èªæé
1.httpå´ã«ã¢ã¯ã»ã¹
2.ãªãã¼ã
3.httpså´ã¸é·ç§»
4.ãªãã¼ã
5.httpå´ã¸é·ç§»ï¼2ãã30ç§ä»¥å
ã«ï¼
6.ãªãã¼ãï¼2ãã30ç§ä»¥å
ã«ï¼
7.ãªãã¼ãï¼2ãã30ç§ä»¥éã«ï¼
ãããã次ã®ããã«ãªãã
è§æ¬å¼§ã®ä¸ã¯ãã¢ã¯ã»ã¹ããæéã§ãã
1.[12:00:00]httpå´ã«ã¢ã¯ã»ã¹
Array ( )
2.[12:00:05]ãªãã¼ã
Array ( [test] => test:12:00:00 80 [test80] => test:12:00:00 80 )
3.[12:00:10]httpså´ã¸é·ç§»
Array ( )
4.[12:00:15]ãªãã¼ã
Array ( [test] => test:12:00:10 443 [test443] => test:12:00:10 443 )
5.[12:00:20]httpå´ã¸é·ç§»ï¼2ãã30ç§ä»¥å ã«ï¼
Array ( [test] => test:12:00:15 443 [test80] => test:12:00:05 80 [test443] => test:12:00:15 443 )
6.[12:00:25]httpå´ã¸é·ç§»ï¼2ãã30ç§ä»¥å ã«ï¼
Array ( [test] => test:12:00:15 443 [test80] => test:12:00:20 80 [test443] => test:12:00:15 443 )
7.[12:00:45]ãªãã¼ãï¼2ãã30ç§ä»¥éã«ï¼
Array ( [test] => test:12:00:25 80 [test80] => test:12:00:25 80 )
ãã®å¤ãªæåããããã ãããï¼
6ã®å¦çã®æã«ãhttpså´ã®å¤ãæ¸ãæããããªãã®ã§ããã¼ããtestãã®å¤ãæ´æ°ã§ããªãã§ããã
(追è¨:7ã®å¤ãå¤ã ã£ãã®ã§ä¿®æ£)
åé¡ç¹
http<->https ãã¾ãã㧠Cookie ããç´æ¥ä½¿ããã¨ã¯ãªãã¨æãããã»ãã·ã§ã³ã§
Cookieã使ç¨ããåé¡ãåºããã¨ã大ãã«ããããã ã
èããããå¯è½æ§ã¨ãã¦åãã»ãã·ã§ã³åã使ã£ã¦ããã¨ãã¦
- httpå´ã§çºè¡ãã Cookieã使ç¨ããã»ãã·ã§ã³ããhttpså´ã§ç¶ç¶ã§ããªã
- éã«httpsã§çºè¡ããã»ãã·ã§ã³IDããhttpå´ã§ãéã£ã¦ãã
- http,httpsã§éãã»ãã·ã§ã³IDãçºè¡ãã¦ããå ´åã«ãhttpsãçµç±ããhttpå´ã«æ»ã£ã¦ããå ´åã«httpå´ã®ã»ãã·ã§ã³IDåå¾ã§ããªã
- httpsãçµç±ããã¨ãhttpå´ã§æå¹æéã®æ´æ°ãªã©ãã§ããªã
ã¾ã¨ã
- auã® Cookieã®ä»æ§ã¯ãSSLããããã¨ããªãå¾®å¦ãªåããããã®ã§è¦æ³¨æã
- Cookieã使ç¨ããã»ãã·ã§ã³ã使ãå ´åã«ã¯ãhttpã¨httpsã§éãã»ãã·ã§ã³åã«ããã®åã
ã£ã¦ããæè¿ã»ãã¥ãªãã£é¢é£ã®ä¸ã§ãCookieã使ç¨ããã»ãã·ã§ã³ä½¿ããããã¿ãããªã®ãç®ã«ãããã©ãã©ããªã®ã ãããï¼
ã¤ãã§ã«
SoftBankã®å ´åã«ã¯ãSSLé åã§ã¯ãsecure.softbank.ne.jp ã¨ãããã¡ã¤ã³ã使ç¨ããã¾ãã
ãã¡ã¤ã³ãéãã®ã§ãããããCookieãå¼ãç¶ããã¨ãåºæ¥ãªãã
â»ã¡ã¼ã«æé¢ããèµ·åããã¨ãhttps://example.com/ ã§éãããã©ã
ä¸è¬çãªãSSLé åã§ãã°ã¤ã³ãã¦ããã®ã»ãã·ã§ã³ãå¼ãç¶ãã§éSSLãµã¤ãå´ã§ä¼å¡åã表示ã¨ãã£ã使ãæ¹ãåºæ¥ãªãã
ã§ãçµå±
Cookieãã¼ã¹ã®ã»ãã·ã§ã³ä½¿ã£ã¦ãSSLãã¼ã¸ãããã¢ãã¤ã«ãµã¤ãä½ã£ã¦ãã¨ãã£ã¦ããã®ã§ããããï¼
追è¨
SSLãã¾ããã ã»ãã·ã§ã³ã§ä½¿ç¨ããå ´åã®åé¡ç¹ãèãã¦ã¿ã¾ããã
ãau,SoftBankでSSLでCookieセッションを使用する場合の問題点 - maru.cc@はてなã
追è¨
docomoã®å ´åã調ã¹ã¦ã¿ã¾ãã
ãDoCoMo iモードブラウザ2.0でCookie - maru.cc@はてなã