æ¸è©ï¼ãããã§ãã·ã§ãã«SSL/TLS
ããããªãããæ¸ãã¦ããé·ããªã£ã¦ãã¾ãã¾ãããé·æå«ããªæ¹ã¯é¿ãã¦ä¸ããã
鹿éããã®ååãééãã¦ã¾ããã大å¤å¤±ç¤¼ãã¾ãããï¼ï¼¿O_ï¼
1. ã¯ããã«ãæ¥æ¬èªç¿»è¨³çåè¡ã«ããã¦ã
æ¨å¹´10æãVãããã
ã Bulletproof SSL and TLS 翻訳æ¬ã®ã¬ãã¥ã¼ãã¾ãï¼æé¨å ãåºè³ãã¦ãåºçä¼ç¤¾ã翻訳権ãåã¡åã£ãã®ã§ããã
ã¨ãèªããåããã®ããããããã®å§ã¾ãã§ããã
ãã¨ãã¨ãããã®æ¥æ¬èªç¿»è¨³ãåºãã®ããã§ããã³ã大ä¸å¤«ãï¼ å 容ã®æ¿ãããããã¨ãªãããã®åéã¨ã¯ãªãªãã£ãè¨è¿°ã®æ£ç¢ºããå³å¯ãã«å¯¾ãã¦ç¹ã«é«ããã®ãè¦æ±ãããã»ãã¥ãªãã£åéããããåå¿è åãã§ã¯ãªãã¨ãã¹ãã¼ãåãããã®æ¬ã®ç¿»è¨³ãåºãã¨ã¯â¦ ãªãã¨å¤§èãå°ãç¡è¬ãªãã¨ã§ã¯ãªããï¼ã
ã¨ã®æããæ£ç´é ããããã¾ããã
èªåãã¡ããã©17å¹´åå¤ããåè·ãè¾ãã¦è»¢è·ããç´å¾ãæ°ä»»æ©ã ãããªãã¨ãã¦ã許ãããã®ãï¼ æãæãé æ ®ãã¡ã«ä¸å¸ã«ä¼ºã£ãã¨ãããã£ããOKã®è¿äºããããã£ãç解ã®ããä¸å¸ã§è¯ãã£ãããã³ãæè¬ãã¾ãã
ç·¨éã®é¹¿éããããã®ä¾é ¼ã¯ã
ãã¬ãã¥ã¼ã«ã¤ãã¦ã¯ãä¸æä¸æãéä¸çã«ã§ã¯ãªãããã£ã¨è¦ã¦ããã ããããªãã®ãã
ã¨æ§ãç®ãªãã®ã
ãããããããã®æ¬ããã£ããã¬ãã¥ã¼ãã失礼ã§ãããã£ããè¦ããã¦ããã ãã¾ããã
ã¨ãå°ãèªåã«ãã¬ãã·ã£ã¼ãããã¤ã¤èªã¿å§ãã¾ããã
ããã¦ä¸æ©ä½æ¥ãã¦ã¿ã¦ç§ããã®è¿äºã
ã第ä¸å°è±¡ã¨ãã¦ãã¾ã æ¥æ¬èªè¨³ã¨ãã¦ããªãã¦ãªãé¨åãå¤ããªã¨æãã¾ãããç¹ã«2ç« ã§æè¡çã«é£ããè¨è¿°ã«ãªãã¨è±æã®è¡¨ç¾ã«å¼ããããã¦æ¥æ¬èªã®ææãåãã¥ãããªã¨æããé¨åãå¤ããªãã¾ããã æ¥æ¬èªè¨³ãèªã¿ãªããè©°ã¾ã£ãããæ°ã«ãªã£ãã¨ããã«ã³ã¡ã³ããå·®ãè¾¼ãã ã®ã§ãããçµå±29ãã¼ã¸ã§100åè¿ãã®ã³ã¡ã³ãã«ãªã£ã¦ãã¾ãã¾ãããã
ã¾ãæ£ç´ãªææ³ã§ããã§ããããããå ¨ç¶å ã«é²ã¾ãªãã
幸ãã«ãæè¡çã«ééã£ã¦è¨³ãã¦ããç®æã¯ããªãå°ãªããã¡ããã¨å 容ãç解ãã¦ç¿»è¨³ãããã¦ããã®ããããã¾ãããããªããã£ã¨åæ¸ã®ã¯ãªãªãã£ãä¿ã£ãã¾ã¾ç¿»è¨³æ¬ã«ã§ããã¯ãããã確信ãã¾ããã
ããããã®å¾ãä½ç« ãåããã¼ã¹ã§ã³ã¡ã³ããå ¥ãé²ããã®ã§ããããã®ãã¡æ¬æ¥ã®æ¹ãç«ã¦è¾¼ãã§ãã¾ãéä¸ã§ã¬ãã¥ã¼ãæ¢ã¾ã£ã¦ãã¾ãã¾ããããã¿ã¾ããã
ãã®éã鹿éããããç§ã®ã³ã¡ã³ãã«å¯¾ããè¿äºãé ããã®ã§ãããé©ãããã¨ã«ç£è¨³ã®æ¹ã«ä¸¸æãããããã§ã¯ãªããã¡ããã¨ãèªèº«ã§å¤æããã¦ä¿®æ£å¯¾å¿ããã¦ã¾ããç§ã®ã³ã¡ã³ããééã£ã¦ãããã¨ããã°ãã°ã§ãéã«é¹¿éããããææãåããå§æ«ãæ¥ãããããããã£ï¼ã¨ã³ã¸ãã¢ã®æ¹ãç·¨éè ãã¦ãããããªããï¼ãã¸ããæãã¾ããã
ãããªã¾ã¾æ°ã¶æçµã£ãå¾ããå稿ãæ´æ°ãã¾ãããã¨ã®ãé£çµ¡ããã ããã£ããã¡ã¼ã«è¦è½ã¨ãã¦ããç´ã¡ã«æªã¬ãã¥ã¼ç« ãçä»ããªãã¨ã¾ãããæ©éã¬ãã¥ã¼éå§ãããã¨ã
ãããã£ããã¡ããã¡ãèªã¿ãããããã®ç« ã®ã¬ãã¥ã¼ã³ã¡ã³ããã¼ããã
ãããã以åãªããããªãã¨ã¯ãªãã¯ãããããããã
ãæéãããã¦ããä¸åº¦èªã¿ç´ãããã
ç¿æ¥ãããã£ã±ãã¼ãã ãä½ãèµ·ãããã ï¼ã
鹿éããæ°ãããæãåã£ãç·¨éæ¹éã«åãæ¿ãã¾ãããã
ããã¼ãï¼ èªãã§é²ããé²ãããããããã®ã¾ã¾ããæ¬å½ã«ã¬ãã¥ã¼ãã¦ããã®ãçããã¦ãã¾ããããããå¿é ãã¦ãã¾ããããã®ç´ æ´ãããåºæ¥ã«ãªãã¾ããã
ã¾ããããªãããªã®ãªã®ãªã¾ã§ãã¿ãã¿ã®ã¬ãã¥ã¼ãããã£ã¦ãã¾ãããè¿·æãããããã¾ãããããã¦ç¡äºããããã§ãã·ã§ãã« SSL/TLSããåè¡ããã¾ããããã§ãããã¨ã§ãã
ä½è«ã¯ãã®ãããã«ãã¦æ©éæ¬ã®ä¸èº«ã«ã¤ãã¦æ¸ãã¦ã¿ã¾ãã
2. ãã®æ¬ã®æ±ãç¯å²
ç§ã¯éå»ï¼å¹´(2015/16)ãã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼ã§TLSãæããè¬ç¾©ãæ å½ãã¦ãã¾ãããåå°ããéã¾ãè¥ãåªç§ãªå¦çããã«å¯¾ãã¦TLSãã©ãæããã®ããæãæ©ãã¨ããã§ãã
çµå±ã¯ãããæ©ãã§ããTLSã®ãã³ãã·ã§ã¤ã¯ã®ä»çµã¿ãå¦ãã§ããããã¨ã«è½ã¡çãã¦ãã¾ãã¾ãããã£ã±ãTLSã¯é£ããã
TLSä»æ§(RFC5246)èªä½ã¯ããã³ãã·ã§ã¤ã¯ããããã³ã«ãã©ã¼ããããè¦å®ããã ãã§ãå®ã¯X.509証ææ¸ãªã©PKIãAESãRSAãªã©æå·æè¡ã®ä»æ§ã«ã¤ãã¦ã¯ãTLSã§å ·ä½çãªä¸èº«ã¯ã»ã¨ãã©å«ã¾ãã¦ãã¾ããããããã¯ä»ã¸ã®é¢é£ä»æ§ã¨ãã¦åç §ããã¦ãããIETFã§æ±ãWGãéãã¾ãã
å¾ã髪å¼ãããã®ã¯ãç義ç(RFC5246)ãªè¦æ¹ã§ã¯ããã£ã³ãã§ã¯ããããå¤é¨ä»æ§ã¨ãã¦TLSãæ¯ããåå°ã¨ãã¦ã¹ã³ã¼ãå¤ã«ãããå¾ãªããã¨ã§ããæéçã«ãããã£ãçã«ããå ¨é¨çãè¾¼ãã®ã¯ç¡çãããã¾ãããªã®ã§æçµçã«ã¯ãã®ã¹ã©ã¤ãã§ãã¾ããã¦ãã¾ãã ããã«å¯¾ãæ¬æ¸ã§ã¯ããããå ¨é¨å¼ã£ãããã¦TLSã»ãã¥ãªãã£ã解説ãã¦ãã¾ãããããããã§ãã
æ¬æ¸ã§ã¯ãä¸å³ã®åé ç®ã«å¯¾å¿ããç« ã¨ãã¦ã
TLSã®ã»ãã¥ãªãã£:
ã第ï¼ç« ãããã³ã«ããã第ï¼ç« å®è£
ã®åé¡ããã第ï¼ç« ãããã³ã«ã«å¯¾ããæ»æã
æå·æè¡:
ã第ï¼ç« SSL/TLS ã¨æå·æè¡ããã第ï¼ç« å®è£
ã®åé¡ããã第ï¼ç« ãããã³ã«ã«å¯¾ããæ»æã
ä¹±æ°çæ:
ã第ï¼ç« å®è£
ã®åé¡ããã第ï¼ç« ãããã³ã«ã«å¯¾ããæ»æã
PKI:
ã第ï¼ç« å
¬ééµåºç¤ããã第4ç« PKIã¸ã®æ»æã
ç§å¯éµã®ç®¡ç:
ã第ï¼ç« ãããã¤ã
ãªé¢ä¿ã«ãªãã¾ãã
å ¨é¨ãç¶²ç¾ ããã®ã§æ±ãæè¡é åã®å¹ ãä¸æ°ã«å¢ãããããããæ·±ãå 容ãå«ã¿ã¾ãã ã¾ãã©ããªå°é家ã§ãé ã§ããã£ã¦ããã¤ãããªã ãã§ãããã¡ããã¨ããææç©ã¾ã§ä»ä¸ããã¨ãªãã¨ä¸¦å¤§æµã®å´åã§ã¯ãã¾ãªãã§ãããã
ããããããã«ç§ã®è¬ç¾©ã®ç¯å²ã®å³ã«ãå ¥ã£ã¦ããªãã
ä¸ä½ã¬ã¤ã¤ã¼(HTTPS)ã®ã»ãã¥ãªãã£:
第5ç« HTTPãã©ã¦ã¶åé¡ã10ç« ãHSTSãCSPãããã³ã°
æ§è½:
第9ç« ããã©ã¼ãã³ã¹æé©å
ã¾ã§ã«ãã¼ãã¦ãããããããåãã§ãããã¨ææããããããã¾ããã
æ¢ã«æ¬æ¸ãè³¼å ¥ãèªã¿å§ããæ¹ã¯ããã®åºå¤§ãªæè¡é åã¨è¨å¤§ãªéã«å§åããã人ãå¤ããã¨æãã¾ãã
å人çã«ã¯ãããããï¼ç« ããèªã¿å§ãããã¨ã«ãã¦ããå¿ ãTLSã®æè¡é åã«é¢ããåå°åãæèãããã¨ã大åã ã¨èãã¾ãããã£ã¨èªãé¨åã»æ·±ãç²¾èªããé¨åãªã©ã決ãã¦ãããç¨åº¦ã¡ãªããªã®ããèªã¿æ¹ããããã¨ããå§ããã¾ãã
3. ãã®æ¬ã®åãã¨ãã
話ãããã¾ãããå®ã¯å æ¥ç¤¾å ããä¾é ¼ãåãã¦ãæè¡ã®ã¹ãã«ã¢ãããç§ã®ããæ¹ãã¨ããã»ããã¼ãå é¨ã§éå¬ãã¾ããã
èªåã®ããã¾ã§ã®åãçµã¿ãæ¯ãè¿ããªããããããã¡ã³ãã¼ã¨å ±ã«è©±ãããå®ã«æ¥½ããæéã§ããããã®ä¸ã§ãã¢ã¦ããããæ¹æ³ ããã°ã®æ¸ãæ¹ãã¨ããã»ãã·ã§ã³ãè¨ããæã¡ã³ãã¼ã®ããã°ã®ããã©ã¼ã»ã¢ãã¿ã¼ãç´¹ä»ããªããããã°ã®æ¸ãæ¹ãã¢ã¦ããããã®éè¦æ§ãªã©ã®è©±ããã¾ããã
ãã®æã®ã¹ã©ã¤ãã®ä¸é¨ãããã§ãã èªåãæãã«ãä»åã®æ¬ã¯ã¾ãã«ãããªãã§ãããã
ãã®æ¬ã«å¯¾ãã¦ç§ã®ã¹ã©ã¤ããæ¯è¼ããã®ã¯ã»ãã¨å¤±ç¤¼ã ã¨æãã¾ããããã®æ¬ã®åãã¨ããããã®å³ã«é¢é£ä»ãã¦æ¸ãã¦ã¿ã¾ãã
3.1 å縮ãããå 容
åºæã§èè èªèº«ããã®æ¬ã®ç®çã
ãèè ãæéããããåèªè ã®æéã¯ç¯ç´ã§ãããããèè ãç¥ã£ã¦ãããã¨ã®ä¸ã§ãç¹ã«éè¦ãªå 容ãè©°ãè¾¼ã¿ãå ããªæéã§åãå 容ãç解ãã¦ããããã¨ã§ãããã
ã¨æ¸ãã¦ãã¾ãã
ã¾ãã«ãç¹ã«éè¦ãªå 容ããè©°ãè¾¼ãã§ãããä¸å³ã®æ§ã«ããããèè ã¯ãã®10åããããã¯ãã以ä¸ã®åéã調ã¹ä¸ãã¦ããã¯ãã§ãããã®ä¸ããèæ¸ã®ã³ã³ããã¹ãã«åããã¦çµãè¾¼ã¿ãä½ç³»åããå 容ã«ãã¦æ¸ãã¦ããã®ã ã¨æãã¾ãã
ãã®ä½æ¥èªä½ã¯ä»ã®æ¬ã§ãè¡ããã¦ãããç¹å¥ãªãã¨ã§ããªãã§ãããããTLSãPKIãªã©éå»20å¹´åãã£ã¡ãããã£ã¡ããããæè¡é åãåºãç¶²ç¾ ããç¯å²ã§è¡ã£ãã®ã¯åãã§ãã
ãã®æ¬ãè³¼å ¥ãããã¨ã¯ãTLS/PKIã«é¢é£ã«éè¦ãªæ å ±ã«è¾¿ãçãã¾ã§ã®èª¿æ»ã¨ãããç解ããããã®æéãè²·ã£ã¦ããã¨æã£ã¦è¯ãã§ãããã æ¬å½ã®ã¨ãã¹ãã¼ããç®æã人ã¯ãããã«æ¸ãã¦ãããã¨ãå ¨ã¦ã§ã¯ãªãããã®è£ã«åºå¤§ãªæè¡é åãåºãã£ã¦ããã¨æã£ã¦ä¸ããã
ã¾ã11ç« ä»¥éã¯åå®è£ ã®ä½¿ãæ¹ã«ãªã£ã¦ãã¾ãããããã¯ãå®éã«æ¤è¨¼ãã¦ç¢ºèª(ã¨ãã½ã¼ãè¨æ¶)ãã«è©²å½ããä½æ¥ã§ããããã¾ã§å¦ãã ãã¨ãå®éã©ãè¨å®ã«åæ ãããã®ãããã§çµã³ã¤ãããã¨ãã§ãã¾ããç§ãæãæ¬å½ã«çæ³çãªã¢ã¦ããããã ãªã¨æå¿ãã¾ãã
3.2 ä½äºã«ã代ããããä¸æ¬¡è³æã¸ã®ãã¤ã³ã¿ã¼é
ç§ã¯åèãææãã¦ãã¾ãããå®ã¯ããã¾ã§ãã¾ãä¸èº«ãéãã¦èªãã ãã¨ãããã¾ããã§ããã使ãæã¯ããªã«ã調ã¹ç©ãããæã§ãã
æ°ããèå¼±æ§æ å ±ãå ¬éãããã¨å ¨ã¦æ°è¦ã®ãã®ã¯ç¨ã§ã大æ¦æ°ããææ³ã«éå»ã®èå¼±æ§ãçµã¿åãããããæ¹è¯ããããããã®ãå¤ãã§ãããã®éã¯ãã®æ¬ã大活èºãã¾ããé¢é£ããã¤ã³ã·ãã³ããèå¼±æ§ã楽ã«æ¢ããã¨ãã§ãããã®ä¸æ¬¡ãªã³ã¯ãè注ã«æ°å¤ãæ²è¼ããã¦ããããã§ãã
æ¥ã çºçããèå¼±æ§ãã¤ã³ã·ãã³ãæ å ±ããããããã¯ãã¼ã¯ãã¦ãã¦ãå°ãçµã¤ã¨ããã£ã¨å¿ãã¦ãã¾ãã¾ããæ¤ç´¢ã§æ¢ãå½ã¦ãã«ãã¦ãS/Næ¯ãæªãå¹ççã§ã¯ããã¾ããããã£ããå¿ãã¦ãã¾ã£ãèªåã®ããã°ã«å©ãããããã¨ããã°ãã°ã
ãã®æ¬ã¯æ¬å½ã«ä¸æ¬¡æ å ±ã«ãã ãã£ã¦ãã¾ããæ¸ãã¦ããå 容ã»å³ã»ãã¼ã¿ãããã®å¤ããä¸æ¬¡æ å ±ããã®ã¨ããã³ã¹ããããã®ã¨ãããã¨ãã¯ã£ãããããã¾ãããã®ä¸æ¬¡è³æã¸ã®ãã¤ã³ã¿ã¼ã¯ãä½äºã«ã代ããããæ å ±ã§ãã
ããã«å ããææ°ã®TLS/PKIã®ååãèå¼±æ§ã®æ å ±ã¯ãBulletproof TLS Newsletter ã§åãåããã¨ãã§ãã¾ããè¿ãã¡ã«ååãã¼ã¸ãããªã³ã¯ãè²¼ãããããã§ããæ¯æ1åç¨åº¦TLS/PKI/æå·æè¡ãªã©ã®ææ°æ å ±ã«é¢ããç°¡å㪠解説ããªã³ã¯ãã¡ã«ãã¬ã®ãã¥ã¼ã¹ã¬ã¿ã¼ã¨ãã¦é ä¿¡ããã¦ãã¾ããæ®æ®µããããã¢ã³ãããå¼µã£ã¦ããã¤ããã§ãçµæ§è¦éãã¦ãããã®ãå¤ã ããããã®ãã¥ã¼ã¹ã¬ã¿ã¼ã§å©ãããããã¨ãå¤ãã§ãããã®æ¬ãèªãã§ç¥èãå¾ãæ¹ã¯ãæ¯éããã§ææ°æ å ±ãå¾ã¦ä¸ããã
4. å人çã«æã注æç¹
è¯ãäºã°ããæ¸ãã¦ãæ¸è©ã«ãªããªãã®ã§ãããã¤ãã¬ãã¥ã¼ãã¦ãã¦æ°ã¥ãã注æç¹ãã
4.1 11ç« ä»¥éã®å®è£ ãã¼ã¸ã§ã³
11ç« ä»¥éã®å®è£ ã§è§£èª¬ãã¦ããã½ããã¦ã§ã¢ã¯ææ°ã®ãã¼ã¸ã§ã³ã«è¿½éãã¦ããªããã®ãããã¾ãã
ç¹ã« OpenSSL 㯠1.0.1 ããã¼ã¹ã¨ãã¦ããã1.0.1 ã¯æ¨å¹´æ«ã«ãµãã¼ããåãã¦ãã¾ããæå ã§è©¦ããªããã² 1.0.2 ã使ãã¾ããã(å®ã¯ä¸é¨OSãã£ã¹ããªãã¥ã¼ã·ã§ã³ã§ã¯ãã®ã¾ã¾èªç¤¾ãµãã¼ãã®ç¯å²å ã§ç¶ç¶å©ç¨ãã¦ããã¨ãããããã¾ãããå人çã«ã¯ãã¾ããå§ããã¾ããï¼ã
ããã§æ¸ããã¦ããopensslã³ãã³ããåºåã«ã¯ã1.0.2ã§ã大é¨åã¯éãã¯ããã¾ããããcipher suiteç³»ã¯ç°ãªã£ã¦ããå ´åãããã¾ãã
ç¹ã«æ¬æã§è§£èª¬ããã¦ããFREAKæ»æãªã©ã«ãã輸åºã°ã¬ã¼ãCipherã¯å ¨ã¦disableããã¦ãã¾ããããã«SLOTHæ»æã®å½±é¿ã§SSLv2ãå®å ¨ã«åé¤ããã¦ãã¾ãã æè¿ã§ã¯ LOW cipher ããªããªã£ã¦ãããæ¬æ¸ã§è¨è¿°ããã¦ããåºåçµæã¨ç°ãªãå ´åãããã¾ãã®ã§æ³¨æãã¦ä¸ããã
翻訳çã¯åèã®ãã©ã¼ã¯ããããåèã®æ´æ°ãå¾ ã¤ã¨ããããªã·ã¼ã§ãã®ã§ããã°ããã¯æ´æ°ãå¾ ã¡ã¾ãããã
4.2 ææ¸ã«ãã解説ã®éç
ããæ°å¹´ Inria 㨠Microsoft Research ã®ã¸ã§ã¤ã³ãã§FREAK, Logjam, SLOTH ãªã©TLSã«å¯¾ããé常ã«é«åº¦ãªèå¼±æ§ã®çºè¦ã¨å ¬éãããã¦ãã¾ããã
ç§ã¯åè«æãèªãã§ããã®ã§ã翻訳æãèªãã§ããã¨ãã§ãããããã®é¨åã¯ããããè¨è¿°ã«ããã®ããã¨ããããã¯ãã®ãã¨ãæãã¦ãããªãã¨ãã£ããã¨ãæããªããèªããã¨ãã§ããããã»ã©éåæãæãã¾ããã§ããããã®è¨è¿°ã¯æ£ç¢ºæ§ãç ç²ã«ãããã©ãã¾ã§ããããããæ¸ããã¨ãã¦ããããèè ã®å·¥å¤«ãè¦ãããããã§ãã
ãããããµã¨è¨³æã ãããèªãã§ããªãèªè ã ã¨ã©ãã¾ã§ç解ãã§ããã®ããªï¼ã¨å°ã ä¸å®ã«æãã¾ããã
ç¹ã«ã7.6ç¯ ããªãã«ãã³ãã·ã§ã¤ã¯æ»æãã¯ãç解ããã®ã«æé£é¢ã®é¨é¡ã«å ¥ããã®ã§ãã
ããã¯ç¿»è¨³ã®åºæ¥ãä¸åºæ¥ã®ã¬ãã«ã§ã¯ãªããå®ã¯å®¹æãªæè¨ã§è§£èª¬ããã«ã¯ãã®è¾ºãéçãããªããã¨æãã¦ãã¾ãã»ã©ã§ãã
Face-to-Faceã®è¬ç¾©ãåç»ã¢ãã¡ã¼ã·ã§ã³ãªã©é§ä½¿ããã°ããªãã¨ãèªè ã«ãç解ãã¦ããããããããã¾ããããææ¸ã ãã§ã¯ã©ãã§ãããï¼ ãã以ä¸ãã£ã¨ããããããæ¸ãã¦èªè ã«ä¼ãããã¨ãã§ãããï¼èªåã§ãå ¨ãèªä¿¡ãããã¾ããã
ãããã®é¨åã¯ãä¸åº¦èªãã§ãããããªãããã¨è¨ã£ã¦ããããããæ¯éåè«æã«ã§ãããã£ã¦æ¬²ãããªã¨æãã¾ãã
4.3 ç§ä¼ã®ã¿ã¬ã®ãããªå 容
åèã¯ãçºè¡å¾ãæ´æ°ããã¦ãã¾ãããªã®ã§è¨è¼ã®ææã«ãã£ã¦å¾®å¦ã«è¨è¿°ã®ä»æ¹ãå¤ãã£ã¦ããé¨åãããã¾ãã
ãã¡ããæè¡çãªæ´åæ§ã¯åãã¦ããã®ã§åé¡ã¯ãªãã®ã§ãããRC4ã®å±æ®åãBEASTæ»æã«é¢ããé¨åãªã©ååã¨å¾åã§å¾®å¦ã«ãã¥ã¢ã³ã¹ãéã£ã¦ãããªã¨èªãã§ãã¦æããã¨ãããããã¾ããã
ä»ã«ããèè ã®éå»ãã©ã¦ã¶ã®æåã®æ¹åã«ããããåãçµãã æã®çµç·¯ã§ããã©ã¦ã¶ã®ã¤ã³ã¿ã¼ãã§ã¤ã¹ã«ã¯çµæ§å³ãã表ç¾ã§æ¸ãã¦ããã¨ãããè¦ããã¾ããããã®ç¹ãèè ã®åªåã®ç²æããã£ã¦ããã®é åãæè¿ã§ã¯ãã©ã¦ã¶ãã³ãã¼å´ã®æ¹åãèããåéã§ããç¹ã«ã5.7 ã»ãã¥ãªãã£ã¤ã³ã¸ã±ã¼ã¿ã¼ãã§è¨è¼ããã¦ããã»ãã¥ãªãã£ã¢ã¤ã³ã³ã®å¤æ´ã«é¢ãã¦ã¯ã翻訳æ¬ã§ã¯ææ°ãã©ã¦ã¶ã®ç»åã使ã£ã¦ãã¾ãï¼æ¬æã®æ´æ°èªä½ã¯åèéãã§ã)ããããä»å¾ã®æ¹è¨ãæå¾ ãããã¨ããã§ãã
é ããèªãã§ããã¨ææ¸ã®æ´æ°ææãæ³åã§ããã¾ãã§ç¶ã足ãã®ã¿ã¬ãå³ãã£ã¦ããããã§èªãã§ãã¦å³ããæ·±ãã§ãã
5. TLS1.3ã®æ¹è¨ã«åãã¦
17ç« ã®ã¾ã¨ãã®æç« ã¯ãç§ã«ã¨ã£ã¦ãé常ã«èããããããæç« ã§ããã¾ã¨ãã®ç« ã¯ãååãã¼ã¸ã«å ¨é¨ãæ²è¼ããã¦ãã¾ãã®ã§è³¼å ¥åã§ãèªããã¨ãã§ãã¾ãã
èè ã¯ã
ãTLSã¯ããã¾ã§æ¬ é¥ãå¤ãä¿®æ£ãéãããã¦ãããããã¨ãã¨å®ç§ãªãããã³ã«ãªã©ã¯ãªããã©ããªãã®ãåæ§ã®ç¶æ³ã«ãªããããããã¾ã§æ®åãã¦æåãåãããããã³ã«ã«å¸æãæã¨ãã
ã¨æ¸ãã¦ãã¾ãã
TLSã¯ããã¾ã§ã®æ°å¤ãã®æè¡è² åµãæ±ãããã¤æ大ã®å¾æ¹äºæãæ±ãããå®å®çã«åä½ãããã¨ãæ±ãããããããã³ã«ã§ããã¤ãå æ¥ SHA-1 ã®è¡çªèæ§ãç ´ããã¾ããã md5ã®æ´å²ãã2nd-preimageèæ§ãç ´ãããã¾ã§ã¯æéã®åé¡ã§ããããSHA-1証ææ¸ãä»å¾ã©ãããå½éããã©ãã®ããmd5ã®è¡çªãã¤ããã4.5 å½é RapidSSL証ææ¸ããèªãã°äºæ³ã§ãã¾ããå¤å¤§ãªç¤¾ä¼çã³ã¹ããæã£ã¦SHA-2ã®è¨¼ææ¸ã«ç§»è¡ãé²ããã®ã¯ããããéå»ã®æè¨ãè¸ã¾ãã¦ã®ãã¨ã§ããä»ã§ã¯ md5 㯠Flame ãã«ã¦ã§ã¢å ã§è¡çªè¨ç®ãå¯è½ã«ãªãã¾ã§ã«ãªã£ã¦ããããã§ãã
TLS1.3ã§ã¯ãæ§ã ãªæ©è½ã®å»æ¢ãè¦ç´ããè¡ããã¦ãã¾ããä¸èº«ã¯ã»ã¼ã¡ã¸ã£ã¼ãã¼ã¸ã§ã³ã¢ããã¬ãã«ã§ããããããã¼ã¸ã§ã³åãTLS2.0ãTLS4ã«ãããã大ããªè°è«ã«çºå±ãæçµçã«TLS1.3ã®ã¾ã¾ã§æ±ºçãã¾ãããé常ãã®ä»æ§ãèªãã§ãã©ããã¦ãã®ãããªä»æ§ã«ãªã£ãã®ãããã®è°è«ã®çµç·¯ãçç±ãæ確ã«ãã¤è©³ç´°ã«æ¸ããã¦ãããã¨ã¯å°ãªãã§ãã
æ¬æ¸ãèªãã°ãããã«æ¸ãã¦ããèå¼±æ§ãæ»æãæè¨ã¨ãã¦TLS1.3ã®ä»æ§ã決ãããã¦ãããã¨ããããã¯ãã§ããæ´æ°çãæ¥ãã°ãå ¨ã¦ããã®TLSã®æè¡è² åµãï¼å®å ¨ã§ã¯ãªããï¼ããªãä¸æããTLS1.3ã®ä»æ§ã«ã¤ãªãã£ã¦ãããã¨ç解ããæ¥ãæ¥ãã§ãããã
æå¾ã«ã
以ä¸ããã¾ãæ¸è©ã«ããªããªããã¨ãã¤ãã¤ãæ¸ãã¦ãã¾ãã¾ããããå®éãã®æ¬ã翻訳æ¬ã¨ãã¦æ¥æ¬èªã§èªãããã¨ã¯æ¥æ¬ã®ã¨ã³ã¸ãã¢ã«ã¨ã£ã¦æ¬å½ã«åã°ãããã¨ã ã¨æãã¾ãã
å ã«æ¸ããéããããã«æ¸ãã¦æããã¨ã¯æ¬å½ã«éè¦ãªãã¨ã«çµãè¾¼ãã å 容ã§ããããã以å¤ã®é¨åããã®è£ã«é ããã¦ãã¾ãã
ã¨ãããã¨ã¯ãã®æ¬ã使ãã°ãæ®ãã®90%ããããé常ã«è¯ã足ããããã«ãªãã¾ãã ãªã®ã§ãã®æ¬ãææã¨ããåå¼·ä¼ãè¿ããã¡ã«å é¨ã§éå§ããã¤ããã§ãããããã¡ã³ãã¼ãæ®ã9å²ãããããã©ãã¾ã§æ¢ããã¨ãã§ããã®ããä»ãã楽ãã¿ã§ãã