Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?
ããã¤ãã®ã¢ã³ãã¦ã£ã«ã¹ã渡ãæ©ãã¦æ¨å¹´ããKaspersky 14ã使ç¨ãã¦ãã¾ããï¼2æããã«ã©ã¤ã»ã³ã¹ãåããããï¼3å¹´5å°åã®ã©ã¤ã»ã³ã¹ãè³¼å ¥ãï¼ã¤ãã§ã«ã¤ã³ã¹ãã¼ã«ãã¦ãããã®ãKaspersky 15ã¸æ´æ°ãã¦ã¿ã¾ããï¼ ã«ã¹ãã«ã¹ãã¼ 2015 ãã«ããã©ãããã©ã¼ã ã»ãã¥ãªã㣠3å¹´5å°ç(ææ°) Firefoxãçªç¶è¦åãåºãããã«ãªã£ãï¼ï¼ æ®æ®µã¯Chromeã常ç¨ãã¦ããããããã«æ°ã¥ããªãã£ãã®ã§ããï¼ã¤ã³ã¹ãã¼ã«ããæ°æ¥å¾ï¼Firefoxãèµ·åãã¦æ°ã¥ããã®ã§ããGoogleã使ããã¨ããã¨è¦åãåºãããã«ãªã£ã¦ãã¾ã£ã¦ãã¾ããï¼ ã©ãè¦ã¦ãåä¸å «ä¹ï¼è¨¼ææ¸é¢é£ã§åé¡ãçºçãã¦ããâ¦ãããã¨æãè¦ãã¦ã¿ãã¨â¦ ã¯ãâ¦ã¢ã¦ãã§ããâ¦ã½ããã¦ã§ã¢ã®æ§æ ¼ä¸ãµã¼ãã¼ã¨ãã©ã¦ã¶ã¼ã®éã«å ¥ã£ã¦ã³ã³ãã³ãã®ç£è¦ãããå¿ è¦ããããããã®ããã«ãªã£ã¦ããã®ã§ãããâ¦ã§ãã ãããã
ååã®opensslã§RSAæå·ã¨éã¶ã§RSAæå·ãç§å¯éµã«ã¤ãã¦ä¸èº«ãè²ã ã¨ããã£ã¦ã¿ããç¶ãã¦ä»åã¯ãApacheã§ä½¿ããªã¬ãªã¬è¨¼ææ¸ãä½ã£ã¦ã¿ãã ç´°ãããã¨ã¯ããããããªã¬ãªã¬è¨¼ææ¸ãä½ãã³ãã³ãã ãç¥ããã ãæ¥ãã®æ¹ã¯ã以ä¸3ã¤ã ãããã°è¯ããããã§10å¹´é(3650æ¥)æå¹ãªãªã¬ãªã¬è¨¼ææ¸ãã§ããããã $ openssl genrsa 2048 > server.key $ openssl req -new -key server.key > server.csr $ openssl x509 -days 3650 -req -signkey server.key < server.csr > server.crtã§ãããã£ãserver.crtã¨server.keyããä¾ãã°/etc/httpd/conf/ é ä¸ã®ssl.crt/ 㨠ssl.key/ ãã£ã¬ã¯ããªã«è¨ç½®
å¹³ç´ ããQAï¼ ITããå©ç¨ããã ããèª ã«ãããã¨ããããã¾ãã QAï¼ ITã¯ã質åãåçããå ±æãããç·¨éããã¦ãããã¨ã§ãã¹ããªQAãèç©ã§ãããITã¨ã³ã¸ãã¢ã®ããã®åé¡è§£æ±ºã³ãã¥ããã£ã¼ãã¨ãã¦ç´7å¹´ééå¶ããã¦ãã¾ãããããã¾ã§ãµã¼ãã¹ãç¶ãããã¨ãã§ããã®ã¯ãQAï¼ ITã®ã³ã³ã»ããã«å ±æãããã ããé©åãªè³ªåãåçããå¯ãããã ããçãã¾ã®ãæ¯æ´ããã£ãããããã¨èãã¦ããã¾ããéãã¦å¾¡ç¤¼ç³ãä¸ãã¾ãã ããããªãããã¨ã³ã¸ãã¢ã®æ å ±å ¥ææ¹æ³ã®å¤æ§åãQAãµã¼ãã¹å¸å ´ã®ç¶æ³ãï¼ ITã®ä»å¾ã®ã¡ãã£ã¢éå¶æ¹éãªã©ãæ¤è¨ããçµæã2020å¹´2æ28æ¥ï¼éï¼15:00ããã¡ã¾ãã¦QAï¼ ITã®ãµã¼ãã¹ãçµäºãããã¨ã«ãã¾ããã ããã¾ã§ãå©ç¨ãããã ãã¾ããçãã¾ã«ã¯æ®å¿µãªãç¥ããã¨ãªããèª ã«å¿è¦ããæã£ã¦ããã¾ããä½ã¨ãããç解ãããã ãã¾ãã¨å¹¸ãã§ãã QAï¼ ITã®7å¹´éã§çãã¾ã®ç¥è
ã¯ã©ã¤ã¢ã³ã証ææ¸ã§èªè¨¼ãã¦ãããµã¤ãã«å¯¾ãã¦ãwgetã§ã¢ã¯ã»ã¹ããæ¹æ³ãç´¹ä»ãã¾ãã ã¯ã©ã¤ã¢ã³ãèªè¨¼ãè¦æ±ãããµã¤ãã«ã¢ã¯ã»ã¹ãããå ´åãé常ã§ããã°ã¯ã©ã¤ã¢ã³ã証ææ¸ãWebãã©ã¦ã¶ã«ç»é²ãã¦å©ç¨ãã¾ãã ãããwgetã§å©ç¨ããå ´åãç§å¯éµã»CA証ææ¸ã»ã¯ã©ã¤ã¢ã³ã証ææ¸ã®3ã¤ãå¥ã ã®ãã¡ã¤ã«ã¨ãã¦åãåºãå¿ è¦ãããã¾ãã å©ç¨ããã¯ã©ã¤ã¢ã³ã証ææ¸ã¯PKCS12ãã©ã¼ãããã®client-cert.p12ã§ããã¨ãã¾ãããããã®å ´åã«ç§å¯éµã¨è¨¼ææ¸ãåãåºãæ¹æ³ã¯æ¬¡ã®éãã§ãã $ openssl pkcs12 -in client-cert.p12 -clcerts -nokeys -out client-cert.crt.pem Enter Import Password: MAC verified OK $ openssl pkcs12 -in client-cert.p
apache ã§SSLã使ã£ã¦ã¿ã(ã¯ã©ã¤ã¢ã³ãèªè¨¼ç·¨)
SSLã¯ã©ã¤ã¢ã³ãèªè¨¼ã®è¨å® æ»ã SSLã¯ã©ã¤ã¢ã³ãèªè¨¼ã¨ã¯ SSLã¯ã©ã¤ã¢ã³ãèªè¨¼ã¨ã¯ãç¹å®ã®èªè¨¼å±ãçºè¡ãã証ææ¸ãæ示ããã¯ã©ã¤ã¢ã³ãã«å¯¾ãã¦ã®ã¿ãµã¼ãã¸ã®ã¢ã¯ã»ã¹ã許ããããªä»çµã¿ã®ãã¨ã§ããSSLå ¨ä½ã®èª¬æãè¨å®æ¹æ³ã«ã¤ãã¦ã¯ãSSLã®è¨å®ãåç §ãã¦ä¸ãããEsehttpdã§ã¯ã¯ã©ã¤ã¢ã³ã証ææ¸ã®æ£å½æ§ã¯ãã§ãã¯ã§ãã¾ããããã®è¨¼ææ¸ã®å 容ã«ãã£ã¦ã¢ã¯ã»ã¹ã³ã³ããã¼ã«ããæ©è½ã¯æªã ãµãã¼ããã¦ãã¾ããã ã¯ã©ã¤ã¢ã³ãèªè¨¼ã®ããã«å¿ è¦ãªãã® Esehttpdã§ã¯ã©ã¤ã¢ã³ãèªè¨¼ããããªãã«ã¯ããµã¼ããä¿¡é ¼ããã¨èªããèªè¨¼å±ã®è¨¼ææ¸ãç¨æããªããã°ãªãã¾ããããã®è¨¼ææ¸ãesehttpdã®è¨å®ãã¡ã¤ã«ã®SSLCACertificateFileãã£ã¬ã¯ãã£ãã«æå®ããã°ãã¯ã©ã¤ã¢ã³ãèªè¨¼ãå¯è½ã¨ãªãã¾ãããã¨ãã°SSLã®è¨å®ã§èª¬æããæ¹æ³ã§èªåã§èªè¨¼å±ãç«ã¦ãå ´åã¯ããã®èªè¨¼å±ã®è¨¼ææ¸
ååã¯èãããã¨ãã£ã¦ãä½ã ãè¯ãåãããªãã£ãOpenSSLã ãããªOpenSSLãçªç¶ä½¿ããã¨ã«ãªãæ§ç¯ããã¾ã§ã®ã¡ã¢ã ä¼ç¤¾ã«ã¦ ã²ãã > ä»äºãç¡ãï¼ä»äºï¼ é¨é· > ããããéµãç¡ãã¨ã¢ã¯ã»ã¹åºæ¥ãªããµã¤ããæ§ç¯ãã¦ã¼ ã²ãã > ã¯ããããã¾ãï¼ ãããã¦è¨¼ææ¸èªè¨¼ãå¿ è¦ãªãµã¤ããæ§ç¯ããäºã«ã(âæ¤è¨¼ç¨ã«ä½¿ãããï¼) ããã§èª¿ã¹ã¦ã¿ããOpenSSLã使ãã°è¯ãããã(´ã»Ïã»ï½) ãµã¼ãOSã®æå®ã¯ç¹ã«ç¡ãã£ãã®ã§ãä¸çªå¥½ããªCentOSã§ã ã¯ã©ã¤ã¢ã³ãOSã¯Windowsã # cat /etc/redhat-release CentOS release 5.6 (Final) # uname -r 2.6.18-238.9.1.el5 çµå±OpenSSLã£ã¦ä½ï¼ ããªãã¿ã®wikipediaã«ããã¨... OpenSSLã¯ãSSLãããã³ã«ã»TLSãããã³ã«ã®ãªã¼
Charles Web ProxyãFiddlerãªã©ã®HTTPã¹ãããã¡ã¯HTTPãªã¯ã¨ã¹ãã¯ãã¡ããHTTPSãªã¯ã¨ã¹ããä¸èº«ã¯è¦ããªããªããããªã¯ã¨ã¹ãèªèº«ã¯è¡¨ç¤ºãããã¨æã£ã¦ãããããã§ã¯ãªãã¨ããã¨ãä»æ¥åãã£ãã HTTPSã§ã¯ãã¯ã©ã¤ã¢ã³ãï¼ãã©ã¦ã¶ï¼ã¨ãµã¼ãã¼ããã³ãã·ã§ã¤ã¯ï¼æå·éµã®äº¤æï¼ããããã¨ã¯æå·ã§éä¿¡ãè¡ããããæå·éµã®äº¤æã¯ãªã¯ã¨ã¹ãæ¯ã«è¡ãããããã§ã¯ãªããè¤æ°ã®ãªã¯ã¨ã¹ãã«æ¸¡ã£ã¦åãæå·éµã使ããããCharles ãFiddlerãªã©ã®ãããã·æ¹å¼ã®HTTPã¹ãããã¡ã¯æå·åãããä¸èº«ãè¦ããã¨ãã§ããªãã®ã§ï¼ãªããã¾ããã§ããããããã§ã¯è©±ã®ç°¡åã®ãã触ããªãï¼ãå¤å´ã ããè¦ã¦HTTPSãªã¯ã¨ã¹ããå¤æããªãã¨ãããªããå¤å´ãã¨ããã®ã¯æå·åãããSSLãã¼ã¿ãéã¶å±¤ãããªãã¡TCPã¨ãããã¨ã«ãªãã ããã§åé¡ãªã®ã¯ãä¸ã¤ã®HTTPãããã¯HTTPS
Webã®è¡¨ç¤ºé度ãé ããããSSLãã³ãã·ã§ã¤ã¯ãã¨ã¯ï¼ç¾å ´ã«ãããWebã·ã¹ãã ã®åé¡è§£æ±ºãã¦ãã¦ï¼3ï¼ æ¬é£è¼ã¯ãæ¥ç«è£½ä½æãæä¾ããã¢ããªã±ã¼ã·ã§ã³ãµã¼ããCosminexusãã®éçºæ å½è ã¸ã®ã¤ã³ã¿ãã¥ã¼ãéãã¦ãWebã·ã¹ãã ã«ãããããã¾ãã¾ãªåé¡ï¼ãã©ãã«ã®è§£æ±ºã«å¹ããã¦ãã¦ã注æç¹ãç´¹ä»ãã¦ãããç¾å¨èµ·ãã¦ããåé¡ã®è§£æ±ºããä»å¾ã®éçºã®ãåèã«ï¼ç·¨éé¨ï¼ ç¥ã£ã¦ãã¾ããï¼ SSLãã³ãã·ã§ã¤ã¯ Webã¢ããªã±ã¼ã·ã§ã³ã§æä¾ããWebãã¼ã¸ã«SSLãé©ç¨ããå ´åãSSLã§ã¯éä¿¡ç¸æã®èªè¨¼ï¼éä¿¡å 容ã®æå·åãªã©ã®è² è·ã®é«ãå¦çãå®è¡ããããããWebãã¼ã¸ã®Webãã©ã¦ã¶ã«è¡¨ç¤ºãããé度ãé ããªããã¨ãããããã®ç¾è±¡ã¯ãSSLã»ãã·ã§ã³ãåå©ç¨ãã¦ããSSLãã³ãã·ã§ã¤ã¯ãï¼ä¸è¨ã®èªè¨¼ï¼æå·åãå«ãã ä¸é£ã®å¦çï¼ãç°¡ç¥åãããã¨ã§ã解決ã§ããå ´åãããã ä»åã¯ããããã®åé¡ã
è² è·è©¦é¨ããããã£ãã®ã§ab(apache bench)ãèµ·åããã®ã§ããï¼SSL read failedã¨è¨ããã¦çµäºãã¦ãã¾ãã¾ãï¼ ãªã¬ãªã¬è¨¼ææ¸ããããªãã®ããªï¼ã¨æãã¾ãããä»ã®ãªã¬ãªã¬è¨¼ææ¸ãµã¼ãã§ã¯åé¡ããã¾ããï¼ ã°ã°ãã¨ã©ãããéApacheãªãµã¼ãç¸æã«ã¯ãã®åé¡ãçºçãã模æ§ï¼ ä»ååé¡ã«ãªã£ã¦ãã®ãpoundç¸æã§ãï¼åã証ææ¸ã使ã£ãApacheç¸æã«ã¯æåãã¾ãï¼ â Bug 49382 â ab says "SSL read failed" 2.2.1ããã¦ã³ãã¼ããã¦ãã¦./configure âenable-ssl; makeãã段éã§support/ab ãèµ·åãã¦ã¿ã¾ããçç¶ã¯ä¸ç·ï¼ 2.3.14-betaã¯ä»åã®ç°å¢(CentOS5)ã§ã¯ä¾åé¢ä¿ã§ä½¿ããï¼ ãªãã¨ã代æ¿æ¡ã¯ãªããã®ãããï¼ â â ApacheBenchã使ããããã©Apacheãå ¥ãã
Apache/SSLèªå·±è¨¼ææ¸ã®ä½æã¨mod sslã®è¨å® æä¾ï¼maruko2 Note. < Apache 移åï¼ æ¡å , æ¤ç´¢ ç®æ¬¡ 1 æé 2 ç§å¯éµã®ä½æ (server.key) 3 CSRï¼è¨¼ææ¸ã®åºã«ãªãæ å ±ï¼ã®ä½æã(server.csr) 3.1 å ¥åé ç®ã®ä¾ 4 証ææ¸ï¼å ¬ééµï¼ã®ä½æ (server.crt) 5 Apache mod_ssl ã®è¨å® 6 Apache èµ·åæã«ãã¹ãã¬ã¼ãºã®å ¥åãçç¥ãã 6.1 ç§å¯éµ (server.key) ãã¡ã¤ã«ãããããã復å·åãã¦ããæ¹æ³ 6.2 Apacheèµ·åæã®ãã¹ãã¬ã¼ãºå ¥åãèªååããæ¹æ³ 7 åèãã¼ã¸ 8 Apache é¢é£ã®ãã¼ã¸ æé 2017å¹´1æ1æ¥ä»¥éãSSL 証ææ¸ã®ç½²åã¢ã«ã´ãªãºã ã¨ã㦠SHA-1 ã使ç¨ãã¦ãã証ææ¸ã¯ SSL éä¿¡ãã§ããªããªãã ããã¯ãWindows製åãGoog
SSLã®éä¿¡ã§å©ç¨ããã«ã¯ãå ¬ééµï¼ç§å¯éµã®ãã¢ã¨ãã¸ã¿ã«è¨¼ææ¸ãå¿ è¦ã§ãããããã¯ãOpenSSLã«ä»å±ããã³ãã³ããå©ç¨ãçæãã¾ãã çæãããã¡ã¤ã«ã¯ãserver.keyï¼ç§å¯éµï¼ãserver.csrï¼CSRãã¡ã¤ã«ï¼å ¬ééµ+証ææ¸ç³è«æ å ±ï¼ãserver.crtï¼ãã¸ã¿ã«è¨¼ææ¸ï¼ã®3ã¤ã¨ãªãã¾ãã ããã§ã¯ãç§å¯éµãçæãã¾ãããããã¼ãä½æããä»»æã®ãã£ã¬ã¯ããªã«ç§»åå¾ãã³ãã³ãã# openssl genrsa -des3 1024 > server.keyããå ¥åããå®è¡ãã¦ãã ããããªããçè ã¯confãã£ã¬ã¯ããªé ä¸ã«ä½æãã¾ãã Windowsã®æ¹ã¯ãC:\Program Files\Apache Software Foundation\Apache2.2\binãé ä¸ã«ãããopenssl.exeãã«é©å®ãã¹ãéããåæ§ã«ã³ãã³ãã> openssl genrs
ç§å¯éµãä½æï¼CSR ãä½ãããã«ï¼ â æå·åæ¹å¼ã¯ DES ã§ãéµé· 1024 ãã¤ãã openssl genrsa -des 1024 > key.pem key.pem ãç§å¯éµã ãã¹ãã¬ã¼ãºãè¨ãããã®ã§ãå ¥åããã â (å¿ è¦ã«å¿ãã¦)ãã¹ãã¬ã¼ãºãåé¤ãã â SSL ãµã¼ããä½ããªã©ã®éãhttpd ãµã¼ãã¹èµ·åæã«ãã¹ãã¬ã¼ãºãè¨ããã¦å°ããã¨ãããã openssl rsa -in key.pem -out key.pem ã¨ããã°ããã¹ãã¬ã¼ãºãªãã®ç§å¯éµã«ãã¦ãã¾ããã¨ãã§ããã httpd-ssl.conf ã«ã SSLPassPhraseDialog exec:/path/to/script ãæ¸ãæ¹æ³ãããããããã ã¨ã該å½ã¹ã¯ãªããã«ãã¹ãã¬ã¼ãºãçã§æ¸ããã¨ã«ãªãã ã©ã¡ãããããã¯ç¶æ³ã«ããã¨æãããç§å¯éµãã®ãã®ã chmod 400 ã«ãã¦ãã¾ã£
ãã¥ã¼ã¹ã¬ã¿ã¼No.23/2003å¹´3æçºè¡ ã¤ã³ã¿ã¼ããã10åè¬åº§ï¼PKI PKIã¨ã¯ PKIï¼Public-Key Infrastructureï¼ã¯å ¬ééµæå·â»1ãå©ç¨ããèªè¨¼åºç¤ã§ããåºç¤æè¡ã§ãããããPKIã¨ããä¸ã¤ã®ä»çµã¿ããæ§ã ãªèªè¨¼ã®çºã«å©ç¨ã§ãã¾ãããã¨ãã°ã¦ã¼ã¶ã¼èªè¨¼ãã¡ãã»ã¼ã¸ã®æ£å½æ§ç¢ºèªãªã©ã«å¿ç¨ã§ããé»åã¡ã¼ã«ãWebãµã¼ãã¹ã§å©ç¨ããã¦ãã¾ãã PKIã§ã¯éä¿¡ç¸æãæ¬ç©ã§ãããã©ããã®ç¢ºèªï¼èªè¨¼ï¼ã«å ¬ééµè¨¼ææ¸ï¼ä»¥ä¸ã証ææ¸ï¼ãå©ç¨ãã¾ããPKIã«ããã証ææ¸ã¯ãçºè¡è ã®ååã¨ãã£ãæ å ±ãè¨è¿°ããã¦ããã身å証ææ¸ã®å½¹å²ãæããã¾ãã身å証ææ¸ããä¿¡é ¼ã§ãã第ä¸è ï¼TTPï¼Trusted Third Partyï¼ã«çºè¡ãã¦ããããã¨ã§ããã®èº«å証ææ¸ãä¿¡é ¼ã§ããããã«ããã®ãPKIã®ç¹å¾´ã§ãï¼å³1ï¼ããã¨ãã°ããã§ãã身å証ææ¸ãé転å 許証ã§ããã¨ããã¨ãä¿¡é ¼
SSLã¯ãSecure Sockets Layerãã®ç¥ã§ãµã¼ãã¼åã³ã¯ã©ã¤ã¢ã³ãèªè¨¼ã¨æå·åéä¿¡ãè¡ãããã®ãããã³ã«ã§ãã SSLã¨ããã³ãããèãæ £ããªãæ¹ã§ãå®ã¯ç¥ããç¥ããã«ä½¿ã£ã¦ããããããã¾ããã SSLã¯ãã®æ©è½ã®éãæå·åã使ã£ãéä¿¡ãè¡ãã¨ãã«å¨åãçºæ®ãã¾ãã ä¾ãã°ãã¿ãªãããï¼åº¦ã¯ä½¿ã£ããã¨ãããã§ããããªã³ã©ã¤ã³ã·ã§ããã³ã°ã§ã¯å¿ ãã¨è¨ã£ã¦ããã»ã©ãã®SSLã使ç¨ãã¦ãã¾ãã Internet Explorerã§SSLéä¿¡ãè¡ã£ã¦ããã¨ãã¦ã¤ã³ãã¦ã®å³ä¸ã«ä»¥ä¸ã®ãããªéµã®ãã¼ã¯ãåºã¦ãã¾ããã é常ã¤ã³ã¿ã¼ããããé²è¦§ãã¦ããæã«æµãã¦ããã¡ãã»ã¼ã¸ã¯æå·åããã¦ããªããããã¡ãã»ã¼ã¸ã第ï¼è ã«çè´ããã¦ãã¾ãå±éºæ§ãããã¾ãã ã¨ãã«ãªã³ã©ã¤ã³ã·ã§ããã³ã°ãè¡ã£ã¦ããéä¿¡ã§ã¯ã¯ã¬ã¸ããã«ã¼ãã®çªå·ãªã©éè¦ãªã¡ãã»ã¼ã¸ãã¤ã³ã¿ã¼ããããæµããããã®ã¾ã¾ã§ã¯å¤§å¤å±
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}