au,SoftBankã§SSLã§Cookieã»ãã·ã§ã³ã使ç¨ããå ´åã®åé¡ç¹
ååããauのSSLでのCookieの挙動がおかしい - maru.cc@はてなãã¨ããã¨ã³ããªãæ¸ããã¨ãã @suzukiãããã次ã®ãããªçºè¨ãããã ãã¾ããã
http://twitter.com/suzuki/statuses/809076312
@maru_cc https+Cookieã§ã®ã»ãã·ã§ã³ç®¡çã«ã¯secureå±æ§ä»ãããã説ãåºæ¬ã¨ã®ã㨠http://www.ipa.go.jp/security/ciadr/20030808cookie-secure.html
http://www.ipa.go.jp/security/ciadr/20030808cookie-secure.html
(ä¸é¨æç²)
SSL/TLS ã§ã¯ããã¼ã使ãã¨ãã¯secure å±æ§ãä»ããã®ãåºæ¬ã¨ãã
ã»æ¹æ³ Aï¼ ãã¹ã¦ã®ãã¼ã¸ã https://...ã«ãã¦ã»ãã·ã§ã³ç®¡çç¨ã®ã¯ããã¼ã« secure å±æ§ãã¤ãã
ã»æ¹æ³ Bï¼ 2ã¤ã®ã¯ããã¼ã使ãåãã
ã¡ãã£ã¨ãèªåã®SSLãã¾ããã ã»ãã·ã§ã³ãèãæ¹ãåéããã¦ããã®ãã¨æããååã«ç¢ºèªãããããã®ã§ãããä¸è¨ã®æ¹æ³ã§ããã¨ãæ¹æ³Bãä¸è¬çã ã¨æãã¾ããå
¨ã¦ã®ãã¼ã¸ãSSLã«ããã®ã¯ãè² è·çãªæå³ã§ããã¾ãæ¡ç¨ããã¦ããªãã®ã§ã¯ãªãã§ããããï¼ã¾ããã¢ãã¤ã«ã®å ´åãSSLãã¼ã¸ãéãã¨ãé½åº¦ã¡ãã»ã¼ã¸ãåºã端æ«ãããã®ã§ãå¿
è¦æä½éã®é å以å¤ã¯ãéSSLã§ä½æããã®ãä¸è¬çã ã¨æãã¾ãã
Cookieã使ãåããå ´å
http://www.ipa.go.jp/security/ciadr/20030808cookie-secure.html
ã»æ¹æ³ Bï¼ 2ã¤ã®ã¯ããã¼ã使ãåãã
ãµã¤ãã®è¨è¨ä¸ãhttp://... ã®ç»é¢ã¨ https://... ã®ç»é¢ãã¾ããã£ã¦ã»ãã·ã§ã³ç®¡çãè¡ãå¿ è¦ãããå ´åã¯ã2ã¤ã®ã¯ããã¼ãçºè¡ããä¸æ¹ããsecure å±æ§ãªããã«ããä¸æ¹ããsecure å±æ§ä»ããã«ãã¾ããhttp://... ã®ç»é¢ã§ã¯ã»ãã·ã§ã³ç®¡çã«åè ã®ã¯ããã¼ã使ç¨ããhttps://... ã®ç»é¢ã§ã¯å¾è ã®ã¯ããã¼ã使ãããã«ãã¾ãããã®ã¨ããæå·åã§ä¿è·ãå¿ è¦ãªç»é¢ï¼https:// ã使ããã¨ã«ããç»é¢ï¼ã«å¯¾ãã¦ãhttp:// ã§ã¢ã¯ã»ã¹ããã¦ãæ å ±ã表示ããªãããã«ä½ãå¿ è¦ãããã¾ããããããªãã¨ãæ»æè ããçè´ã§çã¿åºãã http:// ç¨ã®ã¯ããã¼ã使ã£ã¦ãéè¦æ å ±ã«ã¢ã¯ã»ã¹ã§ãã¦ãã¾ãããã§ãã
SSLç¨ã®secureå±æ§ä»ãã®Cookieã»ãã·ã§ã³
SoftBankã¯ãããããSSLé åã®Cookieããhttpé åã§åå¾ã§ããªãã®ã§ãããæå³secureä»ãã®ãããªåä½ã«ãªãã¾ãã
auã®ä»æ§ã¯ãsecureå±æ§ãä»ããã°ãhttpé åã§Cookieã¯éã£ã¦ãã¾ããã
ã§ãã®ã§ãSSLé åã ãã§ä½¿ç¨ãããsecureä»ãã®Cookieã使ç¨ããã»ãã·ã§ã³ã¯åé¡ãªããã¨ã«ãªãã¾ãã
éSSLãSSLå ±éã®secureå±æ§ç¡ãã®Cookieã»ãã·ã§ã³
ãã¡ãã大åé¡ã
ã¾ããSoftBankã¯ãããã£ã使ãæ¹ãåºæ¥ã¾ããããã¡ã¤ã³ãéããããSSLã¨éSSL㧠Cookieãç¶æãããã¨ãåºæ¥ã¾ããããSoftBankã®å ´åã«ã¯ãããããå ±æã§ããªãã®ã§ãå¥ã®æ¹æ³ã模索ããå¿ è¦ãããã¾ãããããæå³ã使ããªããã ãã ã¨ãè¨ãããã¨æãã¾ãã
ä¸æ¹ãauã®å ´åã«ã¯ãä¸è¦å
±æãã¦ä½¿ãã¦ããããã«æããã¨ãããè½ã¨ãç©´ã§ãã
ä¾ãã°ãSSLé åã§ä»¥ä¸ã®ãã㪠Cookieã使ç¨ããã»ãã·ã§ã³IDãæ¯ãåºããã¨ãã¾ãã
- 1. secureå±æ§ä»ãã® SSLç¨ã®Cookieã»ãã·ã§ã³
- 2. secureå±æ§ç¡ãã® éSSL/SSLå ±æã®Cookieã»ãã·ã§ã³
2ã®éSSL/SSLå ±æã®Cookieã»ãã·ã§ã³ã¯ã前回æ¸ããä»æ§ã®éãã«ãéSSLé åãããåç §ã§ãã¾ããã次ã®ãããªåé¡ãããã¾ãã
- éSSLå´ã§ãCookieã®å¤æ´ãç ´æ£ãåºæ¥ãªããåæ§ã«æå¹æéãªã©ã®å¤æ´ãåºæ¥ãªã
- SSLå´ã§ã®ç«¯æ«Cookieã®æå¹æéãåããå ´åãéSSLé åã§æ°ããCookieãæ¯ãåºããã¦ãã¾ã
å®éã«ã¢ããªãä½ãæã«ãçµæ§è´å½çãªæããããã®ã§ããããããã§ããããï¼