ã»ãã¥ãªãã£æ å½è ããè¦ã re:Invent 㨠AWS Security Hub / Impression of re:Invent and AWS Security Hub

ã»ãã¥ãªãã£æ å½è ããè¦ã re:Invent 㨠AWS Security Hub / Impression of re:Invent and AWS Security Hub
ãµããªDNSã«ããèªè¨¼(DNS-01)ã§ãã¡ã¤ã³ãèªè¨¼ããLetâs EncryptããSSL証ææ¸ãåå¾ãããã¨ãã§ããã®ã§ãã¡ã¢ã¨ãã¦ã¾ã¨ãã¾ããã¯ã©ã¤ã¢ã³ãã¯ãµã¼ããã¼ãã£è£½ã®letsencrypt.shã使ç¨ãã¾ããDNSã§èªè¨¼ããã«ã¯ããã¡ã¤ã³ã«èªè¨¼å°ç¨ã®ãµããã¡ã¤ã³ã追å ãããµããã¡ã¤ã³ã«å¯¾ãã¦TXTã¬ã³ã¼ããè¨å®ã§ããå¿ è¦ãããã¾ããHTTPã«ããèªè¨¼ã§ã¯ãªããããWebãµã¼ãã¯å¿ è¦ããã¾ããããã®ããHTTPã«ããèªè¨¼ã¨æ¯è¼ãã¦ã¨ã¦ãç°¡åã«è¨¼ææ¸ãåå¾ã§ãã¾ããHTTPã«ããèªè¨¼ã¨æéãªã¨ããç¡æã§DVã®SSL証ææ¸ãåå¾ã§ããLetâs Encryptã話é¡ã§ãã Letâs Encryptã§è¨¼ææ¸ã®åå¾ãè¡ãå ´åãHTTPã使ç¨ãã¦ãã¡ã¤ã³ãèªè¨¼ãæ¹æ³(HTTP-01)ãç´¹ä»ããããã¨ãå¤ãããã§ãã ãã®æ¹æ³ã§ãã¡ã¤ã³ãèªè¨¼ããä»çµã¿ã¯ããã£ãã説æããã¨ä»¥ä¸ã®ã¨ãã
ããæè¿è¨äºæ¸ãã®ããµãã£ã¦ã¾ããï¼ãã¿ã¾ããï¼ä»åã¯SSL redirectã®è©±ï¼ Rails 3.1以éã§ã¯force_sslã使ããã¨ã§ï¼ãµã¤ãå ¨ä½ãç¹å®ã®actionã«ã¤ãã¦ï¼SSLãå¼·å¶ãããã¨ãã§ãã¾ãï¼ ãããï¼force_sslã§ã¯HTTP -> HTTPSã¸ã®ãªãã¤ã¬ã¯ãã¯ã§ããã®ã§ããï¼ãã®éã®HTTPS -> HTTPã¸ã®ãªãã¤ã¬ã¯ãããµãã¼ããã¦ãã¾ããï¼ ã¤ã¾ãï¼force_sslã使ã£ãå ´åï¼ä¸åº¦httpsã®URLã«å ¥ã£ã¦ãã¾ã£ãå¾ã«ç¸å¯¾ãã¹ã§ãªã³ã¯ãé·ç§»ããã¨ï¼httpã¢ã¯ã»ã¹ã§æ§ããªããã¼ã¸ãhttpsã§ã¢ã¯ã»ã¹ãã¦ãã¾ããã¨ã«ãªãã¾ãï¼ å ´åã«ãã£ã¦ã¯HTTPSã§ã¢ã¯ã»ã¹ããå¿ è¦ã®ç¡ããã¼ã¸ã¯ã§ããã ãHTTPã§ã¢ã¯ã»ã¹ãã¦ã»ããï¼ã¨ããã±ã¼ã¹ãããã®ã§ï¼ä»åã¯ãããã£ããã¨ãå®ç¾ããããï¼ã¨ãã話ã§ãï¼ ãã®ãããªå¦çãå¿ è¦ã¨ãããã±ã¼ã¹ã¨ãã¦ã¯ä»¥ä¸ã®ã
ç°å¢ã¯ãrails 3.2.6ãruby 1.9.3ãGoogle Chrome 22.0ãMac 10.7.5 ã§ãã ä¸è¡ç®ã®ruby.exeãrubyã¨å¤æ´ãscript/sslrailsã追å ãã¾ãã ï¼ããã©ã«ãã§script/railsã¨ãããã¡ã¤ã«ãããã¾ãããããã¨ã¯å¥ã«è¿½å ãã¾ãï¼ â»ä½è«ã§ãããç§ã¯ã¨ãã£ã¿ãEsppressoãå©ç¨ãã¦ãã¾ãã¦ãEsppressoä¸ã§script/railsãè¤è£½ãããããUnixå®è¡ãã¡ã¤ã«ã¨ãã¦è¤è£½ããã¾ããã§ããããªã®ã§ãFinderã§è¤è£½ãããã¨ãã§ãã¾ãããsslrailsã¯ãUnixå®è¡ãã¡ã¤ã«ãã§ãªãã¨åä½ãã¾ããã®ã§ãã注æä¸ããã #!/usr/bin/env ruby # This command will automatically be run when you run "rails" with Rails 3
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}