SSL証ææ¸ããä¿¡é ¼ãããªããã¨HTTPSãµã¤ã表示æã«ã¨ã©ã¼ãçãã æåã«ãSSL証ææ¸ãä¿¡é ¼ãããªããã¨ã¯ã©ããããã¨ã説æãããã Chromeã«éããWebãã©ã¦ã¶ã¯ãHTTPSã®Webãµã¤ãã«æ¥ç¶ããéãSSL証ææ¸ãæ£å½ãªãã®ãã©ããæ¤è¨¼ãããããæå¹æéãå ±éåï¼ã³ã¢ã³ãã¼ã ï¼ãçºè¡å ï¼èªè¨¼å±ï¼ãªã©ã«ä½ãããç°å¸¸ãè¦ã¤ãã£ãå ´åãã¢ãã¬ã¹ãã¼å·¦ç«¯ã®ã¢ã¤ã³ã³ããã©ã¦ã¶ãã¤ã³ã«ãã®æ¨ã®ã¨ã©ã¼ã表示ãã¦ã¨ã³ãã¦ã¼ã¶ã¼ã«ç¥ãããã ãã®ç¶æ ã§ã¯HTTPSã«ããæå·åã¯ä¿¡é ¼ã§ãããéä¿¡ä¸ã«çè´ãæ¹ããããªããã¾ãã®è¢«å®³ãåããå±éºãããã ã¤ã¾ããè¿ãå°æ¥ãSymantecã®èªè¨¼å±ããçºè¡ãããSSL証ææ¸ãçµã¿è¾¼ãã§ããWebãµã¤ãã«å¯¾ããChromeã§é²è¦§ããã¨ã³ãã¦ã¼ã¶ã¼ã«ã¯ããããã¨ã©ã¼ã表示ãããããã«ãªããã¨ãããã¨ã ãWebãµã¤ãéå¶ã»ç®¡çå´ã¨ãã¦ã¯ä½ã¨ãã¦ãé¿ããã¹ã
VeriSignãGeoTrustãRapidSSLãªã©Symatecåä¸ã®èªè¨¼å±ãçºè¡ãã証ææ¸ã¯ãChrome 66ãã段éçã«ç¡å¹åãããã ç±³Googleã¯3æ7æ¥ãå社ããä¿¡é ¼ã§ããªããã¨å¤æããSymantecåä¸ã®èªè¨¼å±ã®è¨¼ææ¸ã«ã¤ãã¦ãWebãã©ã¦ã¶ã®Chrome 66ãã段éçã«å¤±å¹ãããæªç½®ã«ã¤ãã¦æ¹ãã¦èª¬æããã失å¹å¯¾è±¡ã®è¨¼ææ¸ãã¾ã 使ã£ã¦ããWebãµã¤ãã§ã¯ãã§ããã ãæ©ã対å¿ããããä¿ãã¦ããã 失å¹ã®å¯¾è±¡ã¨ãªãã®ã¯ãSymantecåä¸ã®èªè¨¼å±ï¼CAï¼ã®ThawteãVeriSignãEquifaxãGeoTrustãRapidSSLãªã©ãçºè¡ããSSL/TLS証ææ¸ããããã証ææ¸ã®å ¥ãæ¿ããè¡ã£ã¦ããªãWebãµã¤ãã¯ãChromeãå«ã主è¦ãã©ã¦ã¶ã®æ´æ°çã§ãã¨ã©ã¼è¦åã表示ãããããã«ãªãã 2016å¹´6æ1æ¥ããåã«çºè¡ããã証ææ¸ã«ã¤ãã¦ã¯ãChrom
Googleã®ãChromeããã¼ã ã¯ãSymantecãçºè¡ãã¦ããTransport Layer Securityï¼TLSï¼è¨¼ææ¸ã«å¯¾ããä¿¡é ¼åº¦ãå¼±ãããã¨ãææ¡ããããã®æªç½®ã¯æ®µéçã«è¡ãã2018å¹´åãã«ã¯ãSymantecã¨ãã®åä¸ã®èªè¨¼å±ãçºè¡ãã証ææ¸ã®ãã¡ããGoogle Chrome 64ãã§ä¿¡é ¼ãããã®ã¯æå¹æéã279æ¥ä»¥å ã®è¨¼ææ¸ã®ã¿ã«ããã¨ãããã®ã ã Googleã®ã¨ã³ã¸ãã¢ã§ããRyan Sleeviæ°ã¯ããBlinkãéçºãã¼ã ã®ã¡ã¼ãªã³ã°ãªã¹ãã¸ã®æ稿ã®ä¸ã§ãSymantecã«ãããæ°ã ã®ä¸å ·åããåãã¦ãGoogleã¯ã¦ã¼ã¶ã¼ãé大ãªãªã¹ã¯ã«ç´é¢ããã¨èãã¦ããã¨è¿°ã¹ãã Sleeviæ°ã¯æ¬¡ã®ããã«ææãã¦ãããããã®èª¿æ»ãéãã¦ããGoogle Chromeããã¼ã ã®ã¡ã³ãã¼ãåãåããããã³ã«ãSymantecã説æããä¸æ£çºè¡ã®è¦æ¨¡ã¯å¤§ãããªã£ã¦ã
Update 2015/5/8: ææé ããã¿ã¤ãã誤訳ãªã©ãæ´æ°ãã¾ããã 2015/5/8: æ§æãä¸é¨ä¿®æ£ãã¾ããã Intro 4/30 mozaiila ã®ã»ãã¥ãªãã£ããã°ã«ä¸è¨ã®ãããªã¨ã³ããªãæ稿ããã¾ããã Deprecating Non-Secure HTTP | Mozilla Security Blog ã¨ã³ããªã¯ããã¾ã§é·ããªãã®ã§ãããã«ç¿»è¨³ã®å ¨æãè¨è¼ãã¾ãã ããã¦ãå ã¨ã³ããªã®ã©ã¤ã»ã³ã¹ã§ãã CC BY-SA 3.0 ã«åãã æ¬ã¨ã³ããªãåãã CC BY-SA 3.0 ã¨ãã¾ãã Deprecating Non-Secure HTTP åæ: Deprecating Non-Secure HTTP ä»æ¥ã¯ã non-secure 㪠HTTP ãããå¾ã ã«å»æ¢ãã¦ããã¨ããæ¹éã«ã¤ãã¦ã¢ãã¦ã³ã¹ãã¾ãã HTTPS ã Web ãåé²ãããæ段ã§ãã
Steven J. Vaughan-Nichols ï¼Special to ZDNET.comï¼Â ç¿»è¨³æ ¡æ£ï¼Â ç·¨éé¨ 2015-03-04 16:45 1990年代ã®åãã«ã¯åæ¡ã®ããã«æããããã®ãããããªããSecure-Socket Layerï¼SSLï¼ã¨ããæå·åæè¡ãç£å£°ãä¸ããå½æãç±³å½å®¶å®å ¨ä¿éå±ï¼NSAï¼ã¯å¤å½ã§ããåãããããã»ãã¥ã¢ããªã¦ã§ããã©ãã£ãã¯ã®å 容ã確å®ã«ååãããã¨èãã¦ããããã®ããNSAã¯ãNetscape Navigatorãã®ã¤ã³ã¿ã¼ãã·ã§ãã«çã«ã¯40ãããæå·ã使ç¨ããããå®å ¨ãª128ãããæå·ã¯ç±³å½çã§ã®ã¿ä½¿ç¨ããããNetscapeã説ãä¼ããããã®å¾ã2000å¹´1æã«æå·è¼¸åºç®¡çè¦åãæ¹æ£ãããã©ã®ãããªãã©ã¦ã¶ã§ãããã»ãã¥ã¢ãªSSLã使ç¨ã§ããããã«ãªã£ããããããæ§æ¥ã®ã»ãã¥ã¢ã§ãªãã³ã¼ãã¯ã15å¹´ãçµéããä»ã§ã使ç¨ããã¦ãããã
æè¿ãæ¥éã«ã常æSSLï¼HTTPSï¼åï¼å¸¸ææå·åããåºãã£ã¦ãããWebãµã¤ãã¨Webãã©ã¦ã¶ã¼éã®éä¿¡ã常ææå·åãããã¨ã§éä¿¡ã®å®å ¨æ§ãé«ãããã¨ãããã®ã ã éä¿¡ã®çè´ãé²ããä¸æ¹ã§ãSSLãé§ä½¿ããå·§å¦ãªãµã¤ãã¼æ»æã®âé ãã¿ã®âã«æªç¨ããããªã¹ã¯ããããä¼æ¥ãªã©ã®æ å ±ã·ã¹ãã é¨éã«ã¨ã£ã¦ã¯ããã¾ã§ã¨ã¯ç°ãªãã»ãã¥ãªãã£å¯¾çãè¿«ãããã 常æSSLã¨ã¯ãéä¿¡ã常ææå·åãããã¨ãæãããã°ã¤ã³ãä¼´ãå¤ãã®Webãµã¤ãã§ã¯ãé¨åçã«SSLãæ¡ç¨ãã¦ãããä¾ãã°ITproã®å ´åãè¨äºé²è¦§æã®éä¿¡ãã©ãã£ãã¯ã¯å¹³æï¼éSSLãHTTPï¼ã§æµããï¼åç1ï¼ã
Web ãµã¤ãã常æ SSL åããå ´åã«ãæä½éç¥ã£ã¦ãããªããã°ãªããªãç¥èãã注æç¹ãå®éã®è¨å®æ¹æ³ã¾ã§ãã²ã¨éãã¾ã¨ãã¦ã¿ã¾ãããã¡ãªããããã¡ãªããã証ææ¸ã®ç¨®å¥ãããªãã¤ã¬ã¯ãè¨å®ãªã©ã«ã¤ãã¦ã解説ãã¦ãã¾ãã HTTPS ãã©ã³ãã³ã°ã·ã°ãã«ã«ä½¿ç¨ãã¾ã㨠Google ãå ¬å¼ã«çºè¡¨ããããããããWeb ãµã¤ãã® SSL 対å¿ãç¹ã« Google ãæ¨å¥¨ãã¦ãã Web ãµã¤ãããã¹ã¦ HTTPS ã§é ä¿¡ãããæè¬ ã常æ SSL åã ã«ã¤ãã¦ã®è©±ãèããããå®éã«ã客æ§ããç¸è«ããããããã±ã¼ã¹ãå¢ãã¦ãã¾ããã ããã§ãããæ©ä¼ã ããã®è¾ºã«é¢ããæ å ±ãã¾ã¨ãã¦ãããããªï½ ã¨æã£ã¦æ¸ãã¦ã¿ããæä¾ã® ï¼ï¼ï¼ 5åã§ãããã·ãªã¼ãºãæ¸ãçµãã£ã¦è¦ãã¨ãã絶対㫠5åããç¡çã£ã¦ããæç« éã«ãªã£ã¦ã¦ã©ããããããªãã¨ãæã£ããã§ãããæ°ã«ããå ¬éãã¦ã¿ã¾ãã 常æ SSL
HTTPS(SSLå©ç¨)ãµã¤ããSEOçã«åªéããããã¬ã³ãã§ãä¸éçã«ãHTTPSæ¥ç¶ã§ãµã¤ãéç¨ãããµã¼ãã¹ãå¢ãã¦ãã¦ãã¾ãã ãããããã¤ãã©ãã£ãã¯ãµã¤ãã«ãªã£ã¦ããã¨ããã®ããã³ãã¨ã³ãã§SSLå¦çããããã¨ãè² è·çã«ããªããªãè¾ãã®ã§ãã ã§ãApache 2.3以éã§ã¯ãShared Object Cache Providerã¨ãã¦ãmemcachedãé¸æã§ããããã«ãªã£ã¦ãã¾ãã ãã®ä»çµã¿ãå©ç¨ãã¦ãApacheã¨memcachedã並ã¹ããã¨ã§ãåãµã¼ãã§ã¦ã¼ã¶ã®SSL Session Cacheãå ±æããªããHTTPSãªã¯ã¨ã¹ããè² è·åæ£ã§ããæ§æãä½ã£ã¦ã¿ã¾ããã Webãµã¼ãã§SSLãªããã¼ã 常æSSLãå©ç¨ããWebãµã¤ããéç¨ããããã«ãSSLã¢ã¯ã»ã©ã¬ã¼ã¿ã¨ãã£ãã¢ãã©ã¤ã¢ã³ã¹è£½åã ã¨ããã½ããã¦ã§ã¢ã ã¨ApacheãNginxã®SSLã¢ã¸ã¥ã¼ã«ã使ã
Spring Bootã«ããAPIããã¯ã¨ã³ãæ§ç¯å®è·µã¬ã¤ã 第2ç ä½å人ãã®éçºè ããInfoQã®ããããã¯ãPractical Guide to Building an API Back End with Spring BootããããSpring Bootã使ã£ãREST APIæ§ç¯ã®åºç¤ãå¦ãã ããã®æ¬ã§ã¯ãåºçæã«æ°ãããªãªã¼ã¹ããããã¼ã¸ã§ã³ã§ãã Spring Boot 2 ã使ç¨ãã¦ãããããããSpring Boot3ãæè¿ãªãªã¼ã¹ãããéè¦ãªå¤...
2014å¹´ã¯ãµã¼ãã§ãµãã¼ããããæè¡ã®ã»ãã¥ãªãã£åé¡ãããã¤ãçºè¦ãã¦ãããããã®ææ°ã®ãã®ããSSL 3.0ã®æ·±å»ãªèå¼±æ§ãPOODLEãã ãPOODLEï¼ã¾ãã¯ãCVE-2014-3556ãã¨ãã¦è¡¨ãããï¼ã¯ãPadding Oracle On Downgraded Legacy Encryptionãã®é åèªã§ããã®èå¼±æ§ãå ¬è¡¨ããGoogleã®ç 究è ã®Bodo Mölleræ°ã¨Thai Duongæ°ãããã³Krzysztof Kotowiczæ°ã«ãã£ã¦å½åãããããPOODLEããçºè¦ããããã¨ãåãã¦ãã·ã¹ãã ãªãã¬ã¼ã¿ã¼ã¯ãµã¼ãå´ã§SSL 3.0ã®ãµãã¼ããåæ¢ãã¦ãããå¤ããªã£ãåãããã³ã«ã ãããµãã¼ãããã·ã¹ãã ã¯åãæ¨ã¦ããããã¨ãã¦ããã POODLEã¯ãã©ã¦ã¶ãæå·åãå¦çããä»çµã¿ã«åå¨ããèå¼±æ§ã ãæ»æè ã¯SSL 3.0ã«ããéä¿¡ãè¡ãããã«ä»åãããã¨ã§ã
Environment Red Hat Enterprise Linux 5, 6, 7 Red Hat JBoss Enterprise Application Platform (EAP) 5, 6 JBoss Enterprise Web Server (EWS) 1, 2 Inktank Ceph Enterprise (ICE) 1 Red Hat Storage Console Red Hat Enterprise Virtualization Issue How do I avoid impact to httpd from CVE-2014-3566? How do I disable SSL 3.0 in httpd (using mod_ssl or mod_nss)? To avoid this vulnerability, Red Hat recommends di
SSL 3.0 ãããã³ã«ã«ã¯ãéä¿¡ã®ä¸é¨ã第ä¸è ã«è§£èªå¯è½ãªèå¼±æ§ãåå¨ãã¾ãããµã¼ããã¯ã©ã¤ã¢ã³ãéã®éä¿¡ã«ããã¦ãSSL 3.0 ã使ç¨ãã¦ããå ´åãéä¿¡ã®ä¸é¨ã第ä¸è ã«æ¼ããããå¯è½æ§ãããã¾ãã ãã ããæ»æã«ã¯è¤æ°ã®æ¡ä»¶ãå¿ è¦ã§ãä¾ãã°ãä¸éè æ»æããæ»æ対象ã«å¤§éã®éä¿¡ãçºçããããªã©ä¸å®ã®æ¡ä»¶ãå¿ è¦ã«ãªãã¾ãããã®ãããã ã¡ã«æªç¨å¯è½ãªèå¼±æ§ã§ã¯ããã¾ããã ãµã¼ã管çè ããã³å©ç¨è ã¯å¯¾çã®è¦å¦ãæ¤è¨ããå¿ è¦ã«å¿ãã¦å¾è¿°ã®å¯¾çãå®æ½ãã¦ãã ããã å³ï¼èå¼±æ§ãæªç¨ããæ»æã®ã¤ã¡ã¼ã¸ ãµã¼ããããã¯ã¯ã©ã¤ã¢ã³ãã®ã©ã¡ããä¸æ¹ã§ãSSL 3.0 ãç¡å¹åãããã¨ã§å¯¾çã§ãã¾ãã ãªããSSL 3.0 ãç¡å¹åãããã¨ã§æ¬¡ã®å½±é¿ãåããå¯è½æ§ãããã¾ãã ãµã¼ãå´ã§ SSL 3.0 ãç¡å¹ã«ããå ´å ä¸é¨ã®ã¯ã©ã¤ã¢ã³ãããæ¥ç¶ãã§ããªããªãå¯è½æ§ãããã¾ãã ã¯ã©ã¤ã¢ã³ãå´ã§ S
Googleã®ã»ãã¥ãªãã£ãã¼ã ã¯ç±³å½æé10æ14æ¥ãSecure Sockets Layerï¼SSLï¼ 3.0ã«æ·±å»ãªã»ãã¥ãªãã£èå¼±æ§ããããã¨ãæããã«ãããSSL 3.0ã¯ããªãåã«å°å ¥ãããæå·åãããã³ã«ã§ãããªãããä¾ç¶ã¨ãã¦å¤ã使ç¨ããã¦ããã åãã¼ã ã®Bodo Mölleræ°ã«ããã¨ãããã®èå¼±æ§ã«ãããã»ãã¥ã¢ãªæ¥ç¶ã®ãã¬ã¼ã³ããã¹ãããããã¯ã¼ã¯æ»æè ã«ãã£ã¦å²ãåºãããæãããããã¨ããã SSL 3.0ã¯TLS 1.0ãTLS 1.1ãTLS 1.2ã«å¼ãç¶ããã¦ããããTLSå®è£ ã®å¤ããã¬ã¬ã·ã¼ã·ã¹ãã ã«å¯¾å¿ããã¦ã¼ã¶ã¼ã¨ã¯ã¹ããªã¨ã³ã¹ãåæ»åããããã«ãSSL 3.0ã¨ã®ä¸ä½äºææ§ãç¶æãã¦ããã é常ããã®ã»ãã¥ãªãã£ãããã³ã«ã®ãã³ãã·ã§ã¼ã¯ã¯ãèªè¨¼ããããã¼ã¸ã§ã³ã®ãã´ã·ã¨ã¼ã·ã§ã³ãè¡ãããã®ããã«ãã¦ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã®ä¸¡æ¹ã«å ±éããææ°ã®ãã
[English] æçµæ´æ°æ¥: Mon, 16 Jun 2014 18:21:23 +0900 CCS Injection Vulnerability æ¦è¦ OpenSSLã®ChangeCipherSpecã¡ãã»ã¼ã¸ã®å¦çã«æ¬ é¥ãçºè¦ããã¾ããã ãã®èå¼±æ§ãæªç¨ãããå ´åãæå·éä¿¡ã®æ å ±ãæ¼ããããå¯è½æ§ãããã¾ãã ãµã¼ãã¨ã¯ã©ã¤ã¢ã³ãã®ä¸¡æ¹ã«å½±é¿ããããè¿ éãªå¯¾å¿ãæ±ãããã¾ãã æ»ææ¹æ³ã«ã¯å åãªåç¾æ§ããããæ¨çåæ»æçã«å©ç¨ãããå¯è½æ§ã¯é常ã«é«ãã¨èãã¾ãã 対ç åãã³ãããæ´æ°ããªãªã¼ã¹ãããã¨æãããã®ã§ããããã¤ã³ã¹ãã¼ã«ãããã¨ã§å¯¾çã§ãã¾ãã ï¼éææ´æ°ï¼ Ubuntu Debian FreeBSD CentOS Red Hat 5 Red Hat 6 Amazon Linux AMI åå OpenSSLã®ChangeCipherSpecã¡ãã»ã¼ã¸ã®å¦çã«çºè¦
対çãæ¸ã¾ããã¯ãã®Webãµã¤ãã®ä¸ã«ãçã¾ãããããããªãç§å¯éµãå¤æ´ããã«æ°ãã証ææ¸ã«ä½¿ã£ã¦ããWebãµã¤ãããããã¨ãåãã£ãã ãªã¼ãã³ã½ã¼ã¹ã®SSLï¼TLSæå·åã©ã¤ãã©ãªãOpenSSLãã«é大ãªèå¼±æ§ãè¦ã¤ãã£ã¦ãã1ã«æãå½±é¿ãåããWebãµã¤ãã対å¿ã«è¿½ãããä¸ã§ãSSL証ææ¸ãå ¥ãæ¿ãã¦å¤ã証ææ¸ã失å¹ããã¦ãããªãããç§å¯éµãå¤æ´ããã«æ°ãã証ææ¸ã«ã使ã£ã¦ãã¾ãã¨ãããè´å½çãªãã¹ããç¯ãã¦ããWebãµã¤ãããããã¨ãåãã£ãã¨ãã»ãã¥ãªãã£ä¼æ¥ã®è±Netcraftã5æ9æ¥ã®ããã°ã§å ±åããã ãHeartbleedãã¨å¼ã°ããä»åã®èå¼±æ§ã§ã¯ãSSLæå·åéä¿¡ã«å©ç¨ãã¦ããç§å¯éµãã¦ã¼ã¶ã¼ã®æ å ±ãªã©ãé大ãªæ å ±ãæµåºããæããããããããæ»æãåããã¨ãã¦ããçè·¡ã¯æ®ãã«ããã¨ããã Netcraftã«ããã¨ããã®èå¼±æ§ã®å½±é¿ãåããWebãµã¤ãã®ãã¡ã証ææ¸
JVNãJPCERT/CCã®è¨äºããã¾ãã«ãããã£ã¨æ¸ããã¦ãã¦ãå ·ä½çãªãªã¹ã¯ãæ³åãã¥ããã¨æãã®ã§èª¬æãã¾ãã ä»åç£æ¥ (ä»ãã¥ã¼ã¹è¦ã¦æ¥ãããä¸è¡ã§æãã¦æ¬²ããã¨ãã人åãã®ã¾ã¨ã) ã¤ã³ã¿ã¼ãããä¸ã®ãæå·åãã«ä½¿ããã¦ããOpenSSLã¨ããã½ããã¦ã§ã¢ã2å¹´éå£ãã¦ãã¾ããã ãã®ã½ããã¦ã§ã¢ã¯ä¾¿å©ãªã®ã§ãFacebookã ã¨ãYouTubeã ã¨ãããã¡ãã¡ã®ã¦ã§ããµã¤ãã§ä½¿ã£ã¦ãã¾ããã ä»ã®äººã®å ¥åããIDã¨ããã¹ã¯ã¼ãã¨ãã¯ã¬ã«çªå·ã¨ãããæªã人ãè¦ããã¨ãã§ãã¦ãã¾ãã¾ãã(å®éã«æ¼ãã¦ãä¾) ä»ã«ãè²ã æ¼ãã¦ã¾ãããã¨ããããã¨ã³ã¸ãã¢ä»¥å¤ã®äººãè¦ãã¦ããã¹ãã¯ããã¾ã§ã§OKã§ããããå°ãåãããããæ å ±ã以ä¸ã«ããã¾ãã OpenSSL ã®èå¼±æ§ã«å¯¾ãããã¦ã§ããµã¤ãå©ç¨è ï¼ä¸è¬ã¦ã¼ã¶ï¼ã®å¯¾å¿ã«ã¤ã㦠ã¾ã ç´ã£ã¦ããªãã¦ã§ããµã¤ããããã°ãå ã å£ãã¦ããªãã¦ã§ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}