Mozilla SSL Configuration Generator Redirecting to the updated SSL Configuration Generatorâ¦
Mozilla SSL Configuration Generator Redirecting to the updated SSL Configuration Generatorâ¦
In order to assist folks upgrading, we maintain a document describing information critical to existing Apache HTTP Server users. These are intended to be brief notes, and you should be able to find more information in either the New Features document, or in the src/CHANGES file. Application and module developers can find a summary of API changes in the API updates overview. This document describes
SSLãµã¼ãã¼è¨¼ææ¸ãè³¼å ¥ãè¨ç½®ãè¡ã£ãã®ã§ããã®æ©ä¼ã«SSLã¾ããã®è¨å®ãè¦ãªããã¦ã¿ããã¨ã«ããã ï¼2014/10/21追è¨ï¼POODLE attack ã«å¯¾å¿ãããããSSLProtocol ã« -SSLv3 ã追å ãï¼ ï¼2016/03/03追è¨ï¼å¤ãè¨äºãªã®ã§ä»é¢¨ã®CipherSuiteã«ã¤ãã¦ãææ«ã«è¿½è¨ãã¾ãããï¼ ç¾ç¶ã®ç¢ºèª ã¾ãã¯Qualys SSL Labs SSL Server Testã¨ãããµã¤ãã¸è¡ã£ã¦ãç¾ç¶ããã§ãã¯ã æè¿ãã§ãã¯ããããã¡ã¤ã³ãªã¹ãã«ååãåºã¦ãã¾ãã®ã§ããã¡ã¤ã³åå ¥åæ¬ã®ä¸ã«ãããã§ãã¯ããã¯ã¹ããªã³ã«ãã¦ãªã¹ãæ²è¼ãæå¦ããã æ°åå¾ ã¤ã¨çµæã表示ãããã Beastæ»æãã©ãã ã¨ããæå·å¼·åº¦ãä½ãã ã¨ããããããã¨ææããã¦ãã¾ãã ã¾ãããã¼ã¸ã®ä¸ã®æ¹ã¸è¡ãã¨ãã¡ã¸ã£ã¼ãªãã©ã¦ã¶ã¨ã®æ¥ç¶ç¢ºèªãå¯è½ã ã è¨å®ã®å¤æ´ SSLã¾ããã®ç¥è
ã»ãã¥ãªãã£ã©ã³ã¯ã®ç¢ºèª OpenSSLãå©ç¨ããã¦ããæ¹ã¯ä¸è¨ãµã¤ãã§ã»ãã¥ãªãã£ã©ã³ã¯ã確èªãã¦ã¿ãã¨è¯ãã§ãããã https://sslcheck.globalsign.com/ja/ apacheã®è¨å® /etc/httpd/conf.d/ssl.confãªã©ã«ä¸è¨ã追å ãã¾ãããã $ sudo vim /etc/httpd/conf.d/ssl.conf SSLHonorCipherOrder ON ##è¿½è¨ SSLCipherSuite EECDH+HIGH:EDH+HIGH:HIGH:MEDIUM:+3DES:!ADH:!RC4:!MD5:!aNULL:!eNULL:!SSLv2:!LOW:!EXP:!PSK:!SRP:!DSS:!KRB5 ##è¿½è¨ [許å¯ããã¦ãæå·æ¹å¼ã®ç¢ºèªæ¹æ³] $ openssl ciphers -v [å¶éããã¨ãã®æå·æ¹å¼ã®ç¢ºèª] $ ope
TLSæ¡å¼µï¼RFC4366ï¼ä»æ§ã®ä¸ã¤ Server Name Indicationï¼SNIï¼ã«ãã£ã¦ååãã¼ã¹ã®ãã¼ãã£ã«ãã¹ãã§ãSSLã使ãã¾ããããããããªããååãã¼ã¹ã®ãã¼ãã£ã«ãã¹ãã§SSLã使ããªãã®ããã®çç±ã¨ãSNIã®ä»çµã¿ã¨è¨å®æ¹æ³ã«ã¤ãã¦èª¿ã¹ã¦ã¿ã¾ããã 以åãWEBãã£ã¬ã¯ã¿ã¼ã®æ¹ãããSSLã使ã£ã¦ãããµã¤ãã®ãã¼ãã£ã«ãã¹ãã®è¨å®ä¾é ¼ãåãã¦ãSSL使ã£ã¦ãã¨ãã¼ãã£ã«ãã¹ãã¯ä½¿ããªãã£ãããã¨ãã¤é¡ã§çãã¦ãã¾ããå°ãæ¥ããããæãããã¾ããã(^^;) æã®ä¸å¸ã®è¨èã常ã«ã¢ã³ãããå¼µã£ã¦ããï¼ããæãåºãã¾ãã SNIã®ä»çµã¿ SSLã使ã£ã¦ããã¨å½ç¶ã§ããHTTPãããã¯æå·åããã¦ããã®ã§ãã¯ã©ã¤ã¢ã³ããã©ã®ãã¹ãåãæå®ãã¦ããã®ãå¤æã§ããªããããå é ã®ãã¼ãã£ã«ãã¹ãï¼å³ã®å ´å㯠lamp-svï¼ã表示ããã¦ãã¾ãã¾ãã SNIã§ã¯SSL/TL
AWSã¢ããã³ã¹ãã³ã³ãµã«ãã£ã³ã°ãã¼ããã¼ã®ä¸å¡ã¨ãã¦æ´»åããæ ªå¼ä¼ç¤¾ã¹ã¿ã¤ã«ãºããAWSå°å ¥ã移è¡ãéçºãã»ãã¥ãªãã£ãéç¨ä¿å®ãªã©ããã¹ã¦ã®ãç¸è«ã«ä¹ããã¦ããã ãã¾ãã AWSãå°å ¥ããããä½ããå§ããããããããããªã æ¢åã®ãã³ãã¼ãæ°æè¡ã«å¼±ããè¯ãææ¡ãããããªã ã¯ã©ã¦ãã®å°å ¥ã«ã»ãã¥ãªãã£ã®ä¸å®ããã AWSãã¨ããããå°å ¥ããããããã«æ´»ç¨ãã¦ãããã 社å ã«AWSã®ç¥è¦ãæã£ã¦ãã人ãããªã AWSãªãã§ã¯ã®ã·ã¹ãã éçºã詳ããç¥ããã
Apache ãå©ç¨ãã¦ãã Web ã·ã¹ãã ããçªç¶ã¬ã¹ãã³ã¹ãè¿ã£ã¦ããªããªãããããã¯ç°å¸¸ã«é ãããããªãã©ãã«ã«ééããçµé¨ã¯ãªãã§ããããï¼ ã»ãµã¼ããæ»ãã§ããããã§ã¯ãªãã ã»ãµã¼ãè² è·ãé«ãããã§ããªãã ã»ãã©ã¦ã¶ã§ã¢ã¯ã»ã¹ããã¨ãã¯ãã¬ã¹ãã³ã¹ããªããªãè¿ã£ã¦ããªãã ãã®ãããªã¬ã¹ãã³ã¹é 延ã®çç¶ãåºãã¨ããèããããåå ã¯ããã¤ãããã®ã§ãããå¯è½æ§ãé«ãåå ã¨ã㦠Apache ã®Â KeepAliveTimeout ã®è¨å®ãããã¾ãã KeepAliveTimeout ã¯ãï¼ã¤ã®ã¯ã©ã¤ã¢ã³ãï¼ãã©ã¦ã¶ï¼ããã³ãã¯ã·ã§ã³ãå æã§ããæéãè¨å®ãã¾ããé常ãã©ã¦ã¶ã Web ãã¼ã¸ã«ã¢ã¯ã»ã¹ããã¨ãã¯ãHTML ãã¼ã¸ããã¼ãããå¾ãããããåç §ããã CSS ãç»åçã®ãã¡ã¤ã«ã次ã ã¨èªã¿è¾¼ããã¨ã«ãªãã¾ãããã®ã¨ããæåã® HTML ãã¼ã¸ããã¼ãããéã«ä½¿ç¨ãã¦
ã»ãã·ã§ã³ã®ãã¥ã¼ãã³ã° ããã¾ã§ã®ãã¥ã¼ãã³ã°ã¯ãå¿ è¦ãå¿ è¦ã§ãªãããå¤æããã°ãããææ¢ãã§æé©ãªå¤ãæ¢ãåºãã¨ãããã®ã§ã¯ãªãã£ããããããããããç´¹ä»ãããã»ãã·ã§ã³ã®ãã¥ã¼ãã³ã°ãã¯ããããããªããããç¨åº¦ã®è¦éãã¯ç«ã¦ããã¦ããæé©ãªçããè¦ã¤ããã®ã«ã¯æéãããã£ã¦ãã¾ãã KeepAliveã¨ã»ãã·ã§ã³ã®åæ ã»ãã·ã§ã³ã®ãã¥ã¼ãã³ã°ã®æå§ãã¨ãã¦ããKeepAliveãã«ã¤ãã¦èãããã¨ã«ããããKeepAliveã¯HTTP/1.1ããç¨æããããã®ã§ãã¯ã©ã¤ã¢ã³ãã¨ã®æ¥ç¶ãä¿æããä»çµã¿ã§ãããHTTPã¯ãã¹ãã¼ãã¬ã¹ã»ãããã³ã«ãã¨å¼ã°ããã¨ããã1åã®è¦æ±ï¼ãªã¯ã¨ã¹ãï¼ãã¨ã«æ¥ç¶ãåæããããããããä»æ¥ã§ã¯1ã¤ã®Webãã¼ã¸ã表示ããããã«è¤æ°ã®ãã¡ã¤ã«ãå¿ è¦ã¨ãªãå ´åãã»ã¨ãã©ãªã®ã§ã1ãªã¯ã¨ã¹ããã¨ã«æ¥ç¶ãåã£ã¦ããã®ã§ã¯å¹çãæªããããã§èãåºãããã®ãKe
å ãã¿ã¯ãã¡ãã Apache AddHandler madness all over the place Gentoo Bug 538822 ã©ããããã¨ã 次ã®ãããªæå®ã¯å±éºã§ããã AddHandler php5-script .php ãã®æã«æå®ããã.phpã¯ãã¡ã¤ã«åã®æ«å°¾ã§ããå¿ è¦ã¯ãªããä¾ãã°ã aaa.php.html bbb.php.pngãªã©ãphp5-scriptã¨ãã¦è§£éããã¦ãã¾ãã®ã ãããã¯.XXX.YYYã¨è¤æ°ã®æ¡å¼µåãæ¸ãããå ´åã.XXXã¨.YYYãAddHandlerã®å¯¾è±¡ã¨ãªããã¨ãåå ã ã¡ãªã¿ã«æ¬¡ã®ãããªå ´åã«ã¯php5-scriptã¨ãã¦è§£éãããªãã ccc.php_foo (.php_fooã¨ãã¦è§£éããããã) ddd.php_bar.html (.php_barã¨.htmlã¨ãã¦è§£éããããã)å®ã¯ãã®ãã¨ã¯Apacheã®ããã¥ã¡ã³
å ¸åçã§å¤ç«ããWebã¢ããªã±ã¼ã·ã§ã³ã¯ãããã¤ãã®I/Oãã£ãã«ããHTTPãªã¯ã¨ã¹ããåãå ¥ããå é¨ã§ãããå¦çããHTTPã¬ã¹ãã³ã¹ãåºåãããããã¯ã©ã¤ã¢ã³ãã«éãè¿ãã¾ããããã¯ãã¢ããªã±ã¼ã·ã§ã³ãçµäºãå½ä»¤ãããã¾ã§ç¹°ãè¿ãè¡ããã¾ãã ãã®äºã¯ãWebã¢ããªã±ã¼ã·ã§ã³ãHTTPãç´æ¥çã«è©±ãå¿ ç¶æ§ããªãäºãæå³ãã¾ã: Webã¢ããªã±ã¼ã·ã§ã³ã¯ããHTTPãªã¯ã¨ã¹ãã®ä½ç¨®é¡ãã®è¡¨ç¾ãåãå ¥ããäºãæå³ãã¾ãã
Apache/SSLèªå·±è¨¼ææ¸ã®ä½æã¨mod sslã®è¨å® æä¾ï¼maruko2 Note. < Apache 移åï¼ æ¡å , æ¤ç´¢ ç®æ¬¡ 1 æé 2 ç§å¯éµã®ä½æ (server.key) 3 CSRï¼è¨¼ææ¸ã®åºã«ãªãæ å ±ï¼ã®ä½æã(server.csr) 3.1 å ¥åé ç®ã®ä¾ 4 証ææ¸ï¼å ¬ééµï¼ã®ä½æ (server.crt) 5 Apache mod_ssl ã®è¨å® 6 Apache èµ·åæã«ãã¹ãã¬ã¼ãºã®å ¥åãçç¥ãã 6.1 ç§å¯éµ (server.key) ãã¡ã¤ã«ãããããã復å·åãã¦ããæ¹æ³ 6.2 Apacheèµ·åæã®ãã¹ãã¬ã¼ãºå ¥åãèªååããæ¹æ³ 7 åèãã¼ã¸ 8 Apache é¢é£ã®ãã¼ã¸ æé 2017å¹´1æ1æ¥ä»¥éãSSL 証ææ¸ã®ç½²åã¢ã«ã´ãªãºã ã¨ã㦠SHA-1 ã使ç¨ãã¦ãã証ææ¸ã¯ SSL éä¿¡ãã§ããªããªãã ããã¯ãWindows製åãGoog
2. ãã¥ã¼ãã³ã° ⢠KeepAliveã®è¨å® ⢠ã³ã³ãã³ãã®å§ç¸®è»¢é ⢠ä¸è¦ã¢ã¸ã¥ã¼ã«ã®åé¤ â¢ ã·ã³ããªãã¯ãªã³ã¯å ã®åç §è¨±å¯ â¢ TimeOutã®è¨å® ⢠DNSåãåããã®ç¡å¹ ⢠.htaccessã®ç¡å¹å ⢠Prefork MPMã®ãã¥ã¼ãã³ã° ⢠Worker MPMã®ãã¥ã¼ãã³ã° 3. KeepAliveã®è¨å® ãã£ã¬ã¯ãã£ã å¤ èª¬æ KeepAlive On åä¸ã¯ã©ã¤ã¢ã³ãã«å¯¾ã ã³ãã¯ã·ã§ã³ã使ãåã MaxKeepAliveRequests 1ãã¼ã¸ãããã®å¹³å çãªã³ã³ãã³ãæ° + α 1ã¤ã®KeepAliveã§åãä»ã ããªã¯ã¨ã¹ãæ° KeepAliveTimeout 1ãã¼ã¸å½ããã®å¹³å çãªè»¢éæéï¼Î± ã¯ã©ã¤ã¢ã³ãããã®ãªã¯ã¨ ã¹ãããªãã¦ãKeepAliveã ç¶æããç§æ° 5. ä¸è¦ã¢ã¸ã¥ã¼ã«ã®åé¤ ããã©ã«ãã§ã¯å¤ãã®æ¡å¼µã¢ã¸ã¥ã¼ ã«ãçµã¿
1ï¼æ示åã«ã¤ã㦠ãã®ç« ã§ã¯ UNIXç³»ã®OSã§ãã£ã¨ãå©ç¨ããã¦ãã ãApacheã ã¦ã§ããµã¼ãã®è¨å®æ¹æ³ãä¸å¿ã«ãCGI ãå©ç¨ããããã®ç°å¢ä½ãã解説ãã¾ãã ç« ã®æå¾ã« Apacheã®ãã¦ã³ãã¼ãå ´æããã¤ã³ã¹ãã¼ã«æé ãè¨å®æ¹æ³ã®ããã¥ã¡ã³ãã®ãªã³ã¯ãæ²è¼ãã¦ããã®ã§ãã¾ã å°å ¥ããã¦ããªãæ¹ã¯ãããæ©ä¼ã«ãã²ãã£ã¬ã³ã¸ãã¦ã¿ã¦ãã ããã ã¦ã§ããµã¼ãã¨CGIã®é¢ä¿ ã¦ã§ããµã¼ãã®ä¸»è¦ãªæ©è½ã¯ããã©ã¦ã¶ããªã¯ã¨ã¹ãããURLã«è©²å½ãããã¡ã¤ã«ãéä¿¡ãããã¨ã§ãããªã¯ã¨ã¹ããHTMLã§ã¯ãªãCGIããã°ã©ã ã®å ´åã¯ãããã°ã©ã ã®å 容ã表示ãã代ããã«CGIããã°ã©ã ãå®è¡ãã¦ããã®åºåãéä¿¡ãã¾ãã ã¦ã§ããµã¼ãã®è¨å®ã¯è¤éãªé¢ãããã¾ãããå¿ è¦æä½éã®è¨å®ã¯å®ã¯ããã»ã©å¤ãããã¾ãããæåã«HTMLãã¡ã¤ã«ã表示ã§ããããã«è¨å®ãããã¨ããCGIããã°ã©ã ã®èµ·åããã®ã»ããã¾
ServerTokens OS â ServerTokens Prod âå¤æ´(ãµã¼ãã¼ã®æ å ±ãé ã) KeepAlive Off â KeepAlive On âå¤æ´(ã¯ã©ã¤ã¢ã³ãã¨ã®æ¥ç¶ãä¿æãã) ServerAdmin root@localhost â ServerAdmin [email protected] âå¤æ´(管çè ã®ã¡ã¼ã«ã¢ãã¬ã¹ãè¨å ¥) #ServerName www.example.com:80 â ServerName www.server-manual.com:80 âã³ã¡ã³ã解é¤&å¤æ´(ãµã¼ãã¼åãè¨å ¥) <Directory "/var/www/html"> # # Possible values for the Options directive are "None", "All", # or any combination of:
VirtualBoxã«CentOSãã¨ããããã¤ã³ã¹ãã¼ã« ã®ç¶ã Apacheã®ä¸è¨ã®ã»ãã¥ãªãã£å¨ãã®è¨å®ã試ãã¦ã¿ãã ã»ServerTokens ã»ServerSignature ã»Options Indexs Apacheã®ã¤ã³ã¹ãã¼ã« ã¾ãã¯Apacheãã¤ã³ã¹ãã¼ã«ãã¦ããã $ sudo yum -y install httpd $ sudo service httpd start ServerTokens ServerTokens OS ããã©ã«ãã§ã¯ãServerTokensã¯ãOSãã«ãªã£ã¦ããã $ sudo vi /etc/httpd/conf/httpd.conf ServerTokens OS http://ãµã¼ãã¼ã®ã¢ãã¬ã¹/ ã«ã¢ã¯ã»ã¹ããã¨ã ã¬ã¹ãã³ã¹ãããã¼ã®Serverã®ã¨ããã«Apacheã®ãã¼ã¸ã§ã³ã表示ãããã ServerTokens Pr
ãã¨ãã¨ã¯Using MT ( MT = MovableType ) ã¨ããããã°åã§ããããMTã«é¢ãããã¨ããã£ãããããªããªã£ã¦ãã¾ã£ãã®ã§ãUsing Perlã«å¤æ´ãã¾ãããPerl æãã¦ã¾ãã MovableType使ã£ã¦ã¾ãã4ã§ããã5ã¸ã®ç§»è¡ã¯è«¦ãã¦ãã¾ããæè¿ã¯MTãã¿ããããWebç³»ã®ããã°ã©ã é¢é£ã®ãã¿å ¨è¬ã«ã·ãããã¦ãã¾ãã Macã«ããã©ã«ãã§ã¤ã³ã¹ãã¼ã«ããã¦ããPerlã¨Apacheã§ä¼ç¤¾ã®ãµã¼ãã¹ããã¹ããã¦ãã¾ãã æ§æ MacBook Mac OS X Leopard 10.5 ã·ã¹ãã Perl 5.8 Apache 2 Perlã5.8ãªã®ã§ãMojoliciousã使ããªãã£ãã( 5.10.1以ä¸å¿ é ï¼ ããã«ããã£ã¨ä¸ã®ãã¼ã¸ã§ã³ã®Perlãæã£ã¦ããæ©è½ï¼sayã¨ãï¼ä½¿ãããã£ãã ã§ãããªããªãPerlã®ãã¼ã¸ã§ã³ãä¸ãããã¨ãã§ããªãã£
14:30 | Keep-Alive on / off ã«é¢ããæç®ã®å¤ããææ§ã§ãããã¨ãæ°ã«ãªã£ã¦ããã®ã§ãã¾ã¨ãã¦ã¿ã¾ãããApacheã®ããã¥ã¡ã³ããããKeep-Aliveã®èª¬æãæåãã¾ãã¨ãHTTP/1.0 ã® Keep-Alive æ¡å¼µã¨ HTTP/1.1 ã®æç¶çæ¥ç¶ã®æ©è½ã¯ãè¤æ°ã®ãªã¯ã¨ã¹ããåãTCPã®æ¥ç¶ã§éããããé·æéæç¶ãã HTTP ã»ãã·ã§ã³ãæä¾ãã¾ããã¤ã¾ããKeep-Aliveã¯ããTCP 3ã¦ã§ã¤ãã³ãã·ã§ã¤ã¯ã®ç¯ç´ãã§ããã¨ããç¹ãç解ããªããã°ãªãã¾ãããããã¦ãã®æç®ã¯ãç»åãCSSãå¤ããµã¤ãã§ã¯ãæ¥ç¶ã使ãåããã¨ã«ããç¡é§é£ãããªãããã¨ãã説æããã¦ãã¾ããããã®æ¥ç¶ã使ãåãã¨ãã表ç¾ãææ§ãªæ°ããã¾ããä½ã¨ãªãåãã£ãæ°ã«ãªã£ã¦ãã¾ã人ãå¤ãã®ã§ã¯ãªãã§ãããããããã§ã¯ãã¾ãã¯ä»¥ä¸ã®ãããªhttpd.confã§ãApacheã®å
SSIã使ãã°è¤æ°ã®ãã¼ã¸ã§å ±éé¨åãä¸å åã§ãããªã©ã®ã¡ãªãããããããã ãããµã¼ãã¸ã®è² è·ãã»ãã¥ãªãã£ã¨ãã£ãè¦ç´ ãèããã¨ç¡å¶éã«ä½¿ãã¹ãã§ã¯ãªãããã¡ãªãããæãã¦ã¡ãªããã ãã享åããã«ã¯é©åãªè¨å®ãå¿ è¦ã ã åçãªã³ã³ãã³ãçæãå®ç¾ããSSI çããã¯SSIï¼Server Side Includeï¼ããåãã ããããSSIã¯ãCGIã¨åããåçã«ã³ã³ãã³ãï¼HTMLï¼ãçæããããã®æè¡ã ã Webãµã¤ãã®å¤ãã¯å ¨ãã¼ã¸å ±éã®é¨åãå°ãªãããæã£ã¦ãããä¾ãã°ããã¼ã¸ã®ä¸ã«ã¯ã³ã³ãã³ãã®ããã²ã¼ã·ã§ã³ã¿ãããã¼ã¸ã®ä¸ã«ã¯Copyrightãªã©ã®ã¡ãã»ã¼ã¸ã¨ãã£ãå ·åã§ããããããã®å ±éé¨åã¯ãåãã¡ã¤ã«ã«è¨è¿°ãããããå ±éã®ãã¡ã¤ã«ã«åé¢ãã¦ããæ¹ãå¹çãããããªããªãã°ãå ±éé¨åã«ä½ããã®ä¿®æ£ãçºçããå ´åã«ãè¤æ°ã®ãã¡ã¤ã«ãä¿®æ£ããããã1ã¤ã®ãã¡ã¤ã«ãä¿®æ£ããã ãã§æ¸
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}