ã©ã®SSLè¨¼ææ¸ãè²·ãã°è¯ããããç¸è«ããã¾ã AWSé¢é£ã®ãä»äºãããããã«ãªã£ã¦ãã客æ§ããããç¸è«ããããã¨ã®ç¬¬3ä½ãããã«SSLè¨¼ææ¸ã®è³¼å ¥ãããã¾ããæ¯ååã説æããã®ãé¢åãªã®ã§wãããã°ã§ã¾ã¨ãããã¨æãã¾ãã SSLè¨¼ææ¸ã®å®å¿æ SSLè¨¼ææ¸ã«ã¯å¤§ããåãã¦3ã¤ï¼+1ã¤ï¼ã®å®å¿æã¬ãã«ãåå¨ãã¾ãã EV SSLè¨¼ææ¸ EV SSLï¼Extended Validation SSLï¼è¨¼ææ¸ã¯ãä»ã®ã¨ããæãå®å¿æã®ããè¨¼ææ¸ã§ãããããåå¾ããããã«ã¯ã伿¥ãå®éã«åå¨ãã¦ãããã¨çãä¸ççµ±ä¸ã®èªè¨¼ããã»ã¹ããããæ¥æ¬ã§ã¯åå¾ããããã«ä¼æ¥ã®ç»è¨ç°¿è¬æ¬ã¨å°éè¨¼ææ¸çã®å ¬çãªææ¸ãå¿ è¦ã«ãªãã¾ãããã©ã¦ã¶ã®ã¢ãã¬ã¹ãã¼ãç·è²ã«ãªã£ãããã®è¨¼ææ¸ã使ã£ã¦ãããã¨ã«ãªãã¾ããæãæ°ããè¨¼ææ¸ã®ç¨®é¡ã§ãã伿¥ãèªç¤¾ã®å®å¿æã証æãããã®ã¨ãã¦ä½¿ããããã夿®µãããªãé«ãã§ãã 伿¥
â EV SSLãç·è²ã ã¨ããã ãã§ä¿¡ç¨ãã¦ã¯ãããªãå®ä¾ EV SSLã«é¢ãã¦ä»¥åããæ¸å¿µããã¦ãããã¨ãæ¢ã«ç¾å®ã«ãªã£ã¦ããã䏿æãEVè¨¼ææ¸ãçºè¡ããä¸é¨ã®CAäºæ¥è ããEV SSLã®å®£ä¼ã§ãç·è²ã«ãªã£ããå®å ¨ããªã©ã¨ããããããªåºåãæã£ã¦ãã¦ã誤ã£ãçè§£ãåºã¾ããããªãã¨å¿é ããã¦ããããã ãããç·è²ã«ãªã£ããå®å ¨ãã¨ããçè§£ããªãé§ç®ãªã®ãããã®çç±ã®ä¸ã¤ã¯ããããããå ±ç¨SSLããµã¼ãã¹ã«EV SSLã使ãããããªãã¨ããæ¸å¿µã ã£ãã ããã¦ããã®å®ä¾ãæ¢ã«åå¨ãã¦ãããã¨ã«æ°ä»ãããå³1ã¯ç§ãä½ã£ãWebãã¼ã¸ã§ããã ã¢ãã¬ã¹ãã¼ã¯ç·è²ã«ãªã£ã¦ããããããã«å ¥åããããã¼ã¿ã¯ç§å®ã«ã¡ã¼ã«ã§éä¿¡*1ããã¦ãããï¼ãã®ãã¼ã¸ã¯æ¢ã«ééãã¦ãããï¼ æªæããè ããããããã¼ã¸ã使*2ããä½ããã®æ¹æ³ã§ãã®ãã¼ã¸ã«äººã ãèªå°*3ããã°ããã£ãã·ã³ã°ã®è¢«å®³ãåºãããããããã
(2013.06.17追è¨) ãã®ã¨ã³ããªã®èå¯ã¯ééã£ã¦ãã®ã§åèã«ããªãã§ãã ããã å é±ã®åææ¥ã«æ¸ããã¨ã³ããª(æªæ¤è¨¼ãªã®ã§ä¿¡ææ§ã¯ãªãããiã¢ã¼ãã«ãããgmailã®ã»ãã·ã§ã³ç®¡çãè§£æãã¦ã¿ã)ã®ç¶ããã¡ãã£ã¨å®é¨ãã¦ã¿ã¾ãããåãã£ãã¨ããããå ±åã 1. ãªãã¼ã¹ãããã·(*1)ç°å¢ã§ã¯SSL_SESSION_IDãç°å¢å¤æ°ã§åå¾ã§ããªã 試ãã¦ã¿ã¦åãã£ããã¨ã§ããããªãã¼ã¹ãããã·ããã§ã¯SSL_SESSION_IDãåå¾ã§ãã¾ããã§ãããçç±ã¯mod_sslããªãã¼ã¹ãããã·ä¸ã§åãã¦ãããããèå¾ã®Webãµã¼ãã«ã¾ã§SSL_SESSION_IDãæ¸¡ã£ã¦ããªãããã§ãã åèã«ã次ã®ãããªæ å ±ãããã¾ãã [Apache-Users] ãªãã¼ã¹ãããã·ç°å¢ã§ç°å¢å¤æ°ã渡ãã«ã¯ 2002/2/12(*2) (*1) ããã®æ£å£«ãæã£ãæããããããããã¾ãããä»ã®ãªãã§
1. iã¢ã¼ãã«ãããSSLäºæ iã¢ã¼ãã¯SSLéä¿¡ä¸ãä¸è¨ã®ã©ã®æ¹æ³ã§ãã¦ã¼ã¶ã¼ã䏿ã«èå¥ããæ å ±ãåå¾ããäºãã§ãã¾ããã ã»utn ã»NULLGWDOCOMO ã»guid=ON ã»cookie(iã¢ã¼ãã¯æªå¯¾å¿) ãã®ãããiã¢ã¼ãã§SSLéä¿¡ä¸ã«ã¦ã¼ã¶ã¼ã䏿ã«èå¥ãããå ´å(*1)ã¯URLã«session_id=*****ã¨ãããããªã»ãã·ã§ã³æ å ±ãä»å ãã¦å¼ãåããªãã¨ããã¾ãããããããããããã¨ã»ãã·ã§ã³æ å ±ãä»å ãããç¶æ ã®URLãä½ããã®çç±ã§ä»äººã®æã«æ¸¡ã£ãå ´å(*2)ãã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ã®æããåºã¦ãã¾ãã *1 ECãµã¤ãã®æ±ºæ¸ç»é¢ãªã© *2 ã¦ã¼ã¶ã¼ãã¡ã¼ã«ã§ä»äººã«éã£ã¦ãã¾ã£ãããéä¿¡ãçè´ãããã... 2. gmailã®ä¸æè° ã¾ãå ã«çµè«ãè¿°ã¹ã¦ããã¨ãiã¢ã¼ãã§gmailãé²è¦§ããæã®SSLéä¿¡ä¸ã®URLããä»ã®ç«¯æ«ã«è»¢éãã¦ãã»ãã·ã§ã³ãã¤ã¸
[Perl] LWP::UserAgentãå©ç¨ããã°WEBãã¼ã¿ãåå¾ã§ãã¾ããGETã¡ã½ããã®ã¿ã§ãããLWP::Simpleã®æ¹ãç°¡åã§ããã¡ãªã¿ã«httpsã§ã®åå¾ãå¯è½ã§ãããCrypt::SSLeayãã¤ã³ã¹ãã¼ã«ããã¦ããå¿ è¦ãããã [ãµã³ãã«] #!/usr/bin/perl use LWP::UserAgent; my $ua = LWP::UserAgent->new; #ã¿ã¤ã ã¢ã¦ããè¨å® $ua->timeout(10); #ã¦ã¼ã¶ã¨ã¼ã¸ã§ã³ããè¨å® $ua->agent('Mozilla'); #GETãPUTãPOSTãDELETEãHEADã®ãããããæå®ï¼httpsã®å ´åã¯httpsã«ããã ãï¼ my $req = HTTP::Request->new(GET => 'http://www.ksknet.net'); #ãªãã¡ã©ã¼ãè¨å® $req->ref
OpenSSLã¯ããªã¼ã®SSLå®è£ ã§ãmod_sslãApache-SSLããããã¯OpenSSHãªã©ã§å¿ è¦ã«ãªãã¾ããApacheã§SSLã使ãããå ´åã¯ãOpenSSLã®ã»ãã«ãmod_sslã¾ãã¯Apache-SSLãå°å ¥ããå¿ è¦ãããã¾ãã Apache 1.3.20 + mod_ssl 2.8.4ã¤ã³ã¹ãã¼ã«ã¡ã¢ Apache 1.3.6 + SSL 1.3.2 (Apache-SSL)ã¤ã³ã¹ãã¼ã«ã¡ã¢ INSTALLã®æé éãã³ã³ãã¤ã«ãã¾ãã $ tar xvfz openssl-0.9.6b.tar.gz $ cd openssl-0.9.6b $ ./config $ make $ make test rootã«ãªã£ã¦ã¤ã³ã¹ãã¼ã«ãã¾ãã $ su # make install éµã®ä½æã¨ãµã¤ãè¨¼ææ¸ã®çºè¡ ãã¹ãã¬ã¼ãºã§ä¿è·ãããç§å¯éµãçæãã¾ãã $ su # cd
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}