Use HTTPS for local development Stay organized with collections Save and categorize content based on your preferences. Most of the time, http://localhost behaves like HTTPS for development purposes. However, there are some special cases, such as custom hostnames or using secure cookies across browsers, where you need to explicitly set up your development site to behave like HTTPS to accurately rep
talked at builderscon tokyo 2018
sshã¨ããã¨22çªãã¼ããå©ç¨ãããã®ã ããç°å¢ã«ãã£ã¦ã¯å©ç¨ã§ããªãäºãããã ã§ããããã£ãå ´åã ã¨443çªãã¼ã(SSL)ãå©ç¨ããå ´åãå¤ãã®ã ããWebãµã¼ããªããã®å ´åã ã¨ãã§ã«httpsã§ä½¿ç¨ãã¦ããå ´åãå¤ãã ãããªã¨ããsshã¨sslã443çªãã¼ãã§åå± ããã¦ãããããã®ãã±ããã®ã¨ãã¯é©åã«å²ãæ¯ãããã¦ããããªãã¼ã¹ãããã·ã®ãããªåä½ããã¦ãããã®ããSSLHãã«ãªãã 1. ã¤ã³ã¹ãã¼ã« CentOSãDebianç³»ã®OSã使ã£ã¦ããå ´åã¯ç°¡åã§ãyum(epelãå¿ è¦)ãaptããã¤ã³ã¹ãã¼ã«ãå¯è½ã ã Debian/Ubuntuç³»ã®å ´å sudo apt install sslh CentOSã®å ´å sudo yum install epel-release sudo yum install sslh 2. è¨å®ãã ã¤ã³ã¹ãã¼ã«ã§ãããã諸ã ã®è¨å®ãè¡
Let's Encrypt is Trusted!! ã¤ãã«Let's Encryptã§ä½ã£ããµã¼ã証ææ¸ãä¿¡ç¨ã§ãã証ææ¸ã¨è¨ããã¨ã«ãªã£ãã ãã§ã«Let's Encryptã®ãã¼ã¸ã«ç¨æããã¦ãã Hello Worldãã¼ã¸ã¯è¨¼ææ¸ã®ã¨ã©ã¼ã«ãªããã¨ããªã表示ããã¾ãã ããã¯ãã¨ã¦ãè¨å¿µãã¹ãæ¥ã§ã¯ãªããã¨å人çã«ã¯èãã¦ãã¾ã æè¿ã§ã¯ããWebãµã¼ãã¹ã¯ãã¹ã¦httpsåããã¹ãããã¨è¨ãæµãã§ãããµã¼ã証ææ¸ã«å¤§éã使ããªãå ´åãããã»ã»ã» ãããªä¸ãã¾ãã«æä¸ä¸»ã¨å人çã«ã¯æãã¦ãã¾ãã æè¿httpså¿ é ã ãªã¨æããç¹ iOS 9ãEl Capitanã§å°å ¥ãããApp Transport Security(ATS)åé¡ åãã£ãªã¢ã®ãéä¿¡ã®æé©åãåé¡ googleæ§ã®httpsåªå åé¡ ãªã©ãªã©ããã Let's Encryptã§çºè¡ããããµã¼ã証ææ¸ã¯ãããã¡ã¤ã³
Update 2015/5/8: ææé ããã¿ã¤ãã誤訳ãªã©ãæ´æ°ãã¾ããã 2015/5/8: æ§æãä¸é¨ä¿®æ£ãã¾ããã Intro 4/30 mozaiila ã®ã»ãã¥ãªãã£ããã°ã«ä¸è¨ã®ãããªã¨ã³ããªãæ稿ããã¾ããã Deprecating Non-Secure HTTP | Mozilla Security Blog ã¨ã³ããªã¯ããã¾ã§é·ããªãã®ã§ãããã«ç¿»è¨³ã®å ¨æãè¨è¼ãã¾ãã ããã¦ãå ã¨ã³ããªã®ã©ã¤ã»ã³ã¹ã§ãã CC BY-SA 3.0 ã«åãã æ¬ã¨ã³ããªãåãã CC BY-SA 3.0 ã¨ãã¾ãã Deprecating Non-Secure HTTP åæ: Deprecating Non-Secure HTTP ä»æ¥ã¯ã non-secure 㪠HTTP ãããå¾ã ã«å»æ¢ãã¦ããã¨ããæ¹éã«ã¤ãã¦ã¢ãã¦ã³ã¹ãã¾ãã HTTPS ã Web ãåé²ãããæ段ã§ãã
åé¡ ã¢ããªã±ã¼ã·ã§ã³å ã§httpsã«ããå¤é¨APIãå©ãã¦ãããµã¼ãã®ã¡ã¢ãªä½¿ç¨éãå¢å ãç¶ãã件ã«ã¤ãã¦èª¿ã¹ãã 該å½ã®ãµã¼ãã§ã¯ã以ä¸ã®ããã«ã¡ã¢ãªã®ä½¿ç¨çãå¾ã ã«ä¸æãã¦ããã ã¾ããã¢ããªã±ã¼ã·ã§ã³ã®ããã»ã¹èªä½ãã¡ã¢ãªãæ¶è²»ãã¦ããããã§ã¯ãªãç¶æ ã åå 調æ»ããã¨ããã®ãã°ä»æ§ãè¸ãã§ããã®ã§ã¯ãªããã¨æããããã¼ã¸ãè¦ã¤ããã https://bugzilla.redhat.com/show_bug.cgi?id=1044666 å 容ã¨ãã¦ã¯ãcurlãå®è¡ããéã« /etc/pki/nssdb/以ä¸ã®åå¨ããªããã¡ã¤ã«(æ¯åéããã¹)ã«å¯¾ãã¦accessã·ã¹ãã ã³ã¼ã«ã大éã«ã³ã¼ã«ããã negative dentry cacheãæºã¾ã£ã¦ãããã¡ã¢ãªä½¿ç¨éãå§è¿«ãããã¨ãããã®ã å®éããã®ç¶æ³ãèµ·ãã¦ãããµã¼ãã調ã¹ãã¨ã¡ã¢ãªä½¿ç¨çã®ãã¡å¤ããå ãã¦ããã®ã¯nega
JavaScriptã§åçã«ãªã³ã¯ãçæããéã«ãDOM-based XSSãé²ãããã«ãªã³ã¯å ãhttpãããã¯httpsã«éå®ããã¦ãããã¨ã確èªãããå ´åããããå ¸åçã«ã¯ä»¥ä¸ã®ãããªã³ã¼ãã¨ãªãã var div, elm; // å¤æ° url ã¯æ»æè ãã³ã³ããã¼ã«å¯è½ãªæåå if( url.match( /^https?:\/\// ) ){ div = document.getElementById( "info" ); elm = document.createElement( "a" ); elm.setAttribute( "href", url ); elm.appendChild( document.createTextNode( url ) ); div.appendChild( elm ); } ãã®å ´åãå¤æ°urlã«ãhttp://example.jpããã
Modern Ciphersuite: ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES1
YouTube: https://www.youtube.com/watch?v=cBT1Are3jXE HTML5 Conference 2013 http://events.html5j.org/conference/2013/11/ ã§å©ç¨ããã¹ã©ã¤ãã§ããæ¬ç·¨45åã ããã©ã¼ãã³ã¹å ¨è¬ ( Network, Render, Compute ) ã«ã¤ãã¦ã¯ High Performance Web Frontend 2013 ç§ https://speakerdeck.com/ahomu/high-performance-web-frontend-2013-qiu ããåèãã ããã
å¤é¨ãµã¤ãã®JSãã¡ã¤ã«ãèªã¿è¾¼ãã¨ãã«ãããããæ¸ãæ¹ããã®ã¯ããã¾ãããã <script src="http://example.com/js/jquery.js"></script> çç± ããªãã®ãµã¤ããããã¤ã®æ¥ãSSLã«å¯¾å¿ãããã¨ã«ãªã£ãã¨ãããã®scriptã¿ã°ããã°ã®åå ã«ãªãã¾ãã ã覧ã®ã¨ãããHTTPSãã¼ã¸ã®ä¸ã§HTTPè¦ç´ ãèªã¿è¾¼ããã¨ããã¨ããã©ã¦ã¶ã«ãã£ã¦ã¯å®å ¨è£ ç½®ãåãã¦èªã¿è¾¼ãã§ãããªãã®ã§ãã ä¸ã®ä¾ã§ã¯jQueryã®èªã¿è¾¼ã¿ã«å¤±æãã¦ãã¾ãããã¨ã©ã¼ã¡ãã»ã¼ã¸ãUncaught ReferenceError: jQuery is not defined ããè¦ã¦ãHTTPS/HTTPã®ãããã³ã«ãåå ã ã¨ã¯ããæ°ã¥ããªãã®ã§ããããã«ãããã°ã«ãªã£ã¦ãã¾ãã¾ãã çµè« JSãã¡ã¤ã«(ã¨ãCSSã¨ãç»åã¨ã)ãèªã¿è¾¼ãã¨ãã¯ã"http:"ã®é¨åãç
å®å ¨ã«é£ãã¿ã¤ãã«ã§ããã©ä¸èº«ã¯çé¢ç®ã«æ¸ããã è¿å¹´ãã¦ã§ããµã¤ãã®HTTPSåãæµè¡ã®ããã«ãªã£ã¦ãããç§ã®ç¥ãéããGoogleã®å種ãµã¼ãã¹ãTwitterãFacebookãªã©ãå®å ¨ã«HTTPSã§éä¿¡ãè¡ãããã«ãªã£ã¦ãããHTTPSãã¤ã¾ãSSLã«ããéä¿¡ã®æå·åã«ãã£ã¦ãã¦ã¼ã¶ã«ããã¾ã§ãããå®å ¨ãªã¦ã§ããµã¤ããæä¾ã§ããã ããããããªããä½ã£ã¦ãããµã¤ãããµã¨æãã¤ãã§HTTPSåãã¦ãã¾ãã¨ããã¶ããããã¾ã§ããããµã¤ããé ããªããããã§ã¯ãHTTPSã§éä¿¡ããå ´åã®åé¡ã解説ããã ãªãé ããªãã®ã HTTPã§éä¿¡ããå ´åãã¯ã©ã¤ã¢ã³ãããµã¼ãã¸ã¨æ¥ç¶ããããã«ã¯TCP/IPã®3ã¦ã§ã¤ãã³ãã·ã§ã¤ã¯ã¨ããæé ãå¿ è¦ã«ãªããããã©ãããã®ã§ããã§ã¯è©³ããã¯èª¬æããªãããè¦ããã«ã¯ã©ã¤ã¢ã³ãããªã¯ã¨ã¹ããæããåã«ãã±ãããï¼å¾å¾©ãããªãã¨ãããªãã®ã§ããããã±ããã®å¾å¾©
HTMLãCSSã§ã¯ãããã³ã«è¡¨è¨ï¼http:ãhttps:ï¼ã®çç¥ãå¯è½ã§ãã ã¨ãããã¨ã§ããããã³ã«è¡¨è¨ã®çç¥ã«é¢ãããã¨ãè²ã 調ã¹ã¦ã¿ã¾ããã®ã§ãæ¬ã¨ã³ããªã¼ã§ç´¹ä»è´ãã¾ãã ãã®ã¨ã³ããªã¼ã¯ãããGoogle HTML/CSS Style Guideããé©å½ã«å訳ãã¦ã¿ããã®ä»¥ä¸ã®é¨åã«å¯¾ãã¦ã®ä¾¿ä¹è¨äºã§ãã åãè¾¼ã¿ãªã½ã¼ã¹ãããããã³ã«è¡¨è¨ï¼http:,https:ï¼ãçç¥ããã <!-- Not recommended --> <script src="http://www.google.com/js/gweb/analytics/autotrack.js"></script> <!-- Recommended --> <script src="//www.google.com/js/gweb/analytics/autotrack.js"></script> ï¼ï¼ãããã³
ããã«ã¡ã¯æ¤ç´¢ãµã¼ãã¹éçºï¼ãã¼ã ã®å´çç§ã¨ç³ãã¾ãã ã¤ã³ãã©ãã·ã¹ãã ã¨ã®é£æºãçµ±è¨ã®ããã¯ã¨ã³ããæ å½ãã¦ããã¾ãã ã¢ãã¤ã«ã®ã¦ã§ãç°å¢ã¯PCã®ã¦ã§ã使ç¨ç°å¢ã¨ã¯è²ã ãªéããæãã¾ãã ãããã¯ã¼ã¯ã®é度ã ãã§ã¯ãªãããããªã¼ã®å¹çãèããä»çµã¿ãªã©ãPCã«æ¯ã¹ãªã½ã¼ã¹ãååã§ã¯ãªãããã¢ãã¤ã«ãã©ã¦ã¶ã®åä½ãç°ãªã£ã¦ãããã¨ãæãã¾ãã ä»åã¯ã¢ãã¤ã«ã®ã¦ã§ãApplicationã«ãããSSLé¢ä¿ã®æ§è½ã«é¢ãã工夫ã®å 容ãQ&Aå½¢å¼ã§è§£èª¬ãã¦ããã¾ãã Q. ä½ãåé¡ã§ãããï¼ A. ã¢ãã¤ã«ã¯ã©ã¤ã¢ã³ã(iPhone, Android)ã®ã¢ããªã±ã¼ã·ã§ã³ããã®HTTPãªã¯ã¨ã¹ãã®å¿çæéã«é 延ã®åé¡ãæãã¾ãã æåã¯web access logããã®slow response(ï¼ç§ä»¥ä¸)ã®HTTPãªã¯ã¨ã¹ããçµæ§ããã¾ããã ãã®HTTPãªã¯ã¨ã¹ããprotoc
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}