9. LDAP ã«ãããã¸ã¿ã«è¨¼ææ¸ã®çºè¡ãã®ç« ã®ç¦ç¹ã¯ããã¸ã¿ã«è¨¼ææ¸ã LDAP ãµã¼ãå ã«çºè¡ããæ¹æ³ã«ããã¾ãã Certification Authority (èªè¨¼å±) ãéå¶ãããªããã¸ã¿ã«è¨¼ææ¸ãçºè¡ããå¿ è¦ã ããã¾ããLDAP ã¸ã®çºè¡ã¯ããã®æ å ±ããããã¯ã¼ã¯å ã§å©ç¨ã§ããããã«ãã ã·ã³ãã«ãªæ¹æ³ã®ã²ã¨ã¤ã§ããã¾ãã証ææ¸å¯¾å¿ã½ããã¦ã§ã¢ã®å¤ããã æã¾ããã¬ãã¸ããªã¨ãã¦ãã¦ã¼ã¶è¨¼ææ¸ã« LDAP ãç¨ãã¦ãã¾ãããã®æ¹æ³ã§ã¯ã¦ã¼ã¶è¨¼ææ¸ãä»ã®ã¦ã¼ã¶æ å ±ã¨ä¸ç·ã«ãã¦ãããã®ã§ã ãã¼ã¿ã®ç¡é§ãªè¤è£½ãå¿ è¦ãªããªãã¾ãã証ææ¸ãåãæ±ãã«ã¯æå·ãã¼ã«ããããå¿ è¦ã§ãã ããã§ä½¿ç¨ããã®ã¯ OpenSSL ã§ãã 9.1. LDAP ãµã¼ãã®è¨å®ããã§ä½¿ç¨ãã LDAP ãµã¼ã㯠OpenLDAP 2.0.x ã§ããLDAP ãµã¼ãã¯ã証ææ¸ãè¨é²ããããã®å±æ§ãæã¦ã
google:èªè¨¼å±+CA é·ãã®ã§ãçé¢ç®ã«CAãç«ã¦ãã¤ãããç¡ããã°ããçµè«ãã ãèªãã°okã ç¨èªå®ç¾©ãã©ã¤ãã¼ãCAãä½ãç§å¯éµãä½ããªã¯ã¨ã¹ããä½ã証ææ¸ãä½ãç§å¯éµã¨è¨¼ææ¸ãåæããpkcs#12å½¢å¼ã®ã¯ã©ã¤ã¢ã³ã証ææ¸ãä½ãçæããCA証ææ¸ããµã¼ã証ææ¸ãã¯ã©ã¤ã¢ã³ã証ææ¸ã使ã£ã¦ã¿ããã®ä»ãã¼ããããã©ã¤ãã¼ãCAã®ãã¡ãªããçµè«åèã«ãããªã³ã¯ ç¨èªå®ç¾© CA, èªè¨¼å± ã証ææ¸ããå¿ è¦ã¨ãã人ãæåºããããªã¯ã¨ã¹ãããããCAã®ç½²åå ¥ãã証ææ¸ããçæãããä½ããã®ã·ã¹ãã ã èªè¨¼ãè¡ãã·ã¹ãã ãªã®ã§ãCAèªèº«ã«ãä¿¡ç¨/ä¿¡é ¼ã¨ãã£ãç©ãå¿ è¦ã èªè¨¼å±ã¯ã大ä¼ç¤¾ã ã£ãããåã«ãã¡ã¤ã«ä¸å¼ãå ¥ã£ãã ãã®ãã£ã¬ã¯ããªã ã£ããããã å°ãCAããããªã¯ã¨ã¹ããããç½²åå ¥ãã証ææ¸ããçºè¡ããçºã«ã¯ãCAèªåèªèº«ã®ç§å¯éµã¨è¨¼ææ¸ãå¿ è¦ã¨ãªãã ç§å¯éµ ã³ã¬ãããã¨ãå ¬ééµã«ã
ä¹ çã§ãã 証ææ¸çºè¡ã«ä½¿ç¨ããopensslã³ãã³ãã®å¼æ°ãã¾ã¨ãã¦ã¿ã¾ããã ================================================================= ï¼ã¿ã¤ã ã¾ã¼ã³ã®è¨å® set tz=jst-09 ã»ã«ããµã¤ã³ã®CA証ææ¸çºè¡ openssl req -keyout (CA証ææ¸ã®ç§å¯éµãã¡ã¤ã«å) -x509 -config (opensslã®è¨ å®ãã¡ã¤ã«å) -out (CA証ææ¸ãã¡ã¤ã«å) -days (CA証ææ¸ã®æå¹æé(æ¥)) -new -outform pem ã»ã«ããµã¤ã³ã®CA証ææ¸ã®PKCS#12ãã¼ã¿ä½æ openssl pkcs12 -export -in (CA証ææ¸ãã¡ã¤ã«å) -inkey (CA証ææ¸ç§å¯éµãã¡ã¤ ã«å) -out (PKCS#12ãã¼ã¿ã®ãã¡ã¤ã«å) ã¦ã¼ã¶è¨¼ææ¸ã®è¨¼ææ¸çº
Apacheã§SSLãå©ç¨ããã«ã¯ãã¢ã¸ã¥ã¼ã«ãçµã¿è¾¼ããããããé©ç¨ããå¿ è¦ãããããã®ãããApacheã®ã¤ã³ã¹ãã¼ã«æã«SSLåãè¡ããªããã°ãªããªããä»åã¯ãOpenSSLã使ãæ¹æ³ã¨ãApacheã¤ã³ã¹ãã¼ã«å¾ã«æå°éãã£ã¦ããã¹ãç°å¢è¨å®ã«ã¤ãã¦ç´¹ä»ããã ååã¯Apacheã®åºæ¬çãªã¤ã³ã¹ãã¼ã«æ¹æ³ãç´¹ä»ãã¦çµãã£ãããä»åã¯ãã®ç¶ãã¨ãã¦ãSSLï¼Secure Sockets Layerï¼ã¨Apacheãé£æºãããå ´åã®ã¤ã³ã¹ãã¼ã«ããã¤ã³ã¹ãã¼ã«å¾ã«è¡ã£ã¦ããã¹ã便å©ãªè¨å®ã«ã¤ãã¦ç´¹ä»ããã Apacheã§SSLã使ãã«ã¯ ã¯ã¬ã¸ããã«ã¼ãçªå·ã«éããããã©ã¤ãã¼ããªæ å ±ã®å ¥åãæ±ããWebãµã¤ãã§ã¯ãéä¿¡ãæå·åããæè¡ãæ¬ ãããªãããããå®ç¾ããã®ãSSLã ï¼SSLã«ã¤ãã¦ã¯æºå¸¯éä¿¡æè¡ãã¬ã³ã第2åãåç §ãã¦ããã ãããï¼ãæ¬ç¨¿ã§ã¯ãApacheã¨SSLãçµã¿åãã
OpenSSLãå©ç¨ãããèªå·±èªè¨¼å±(CA)ã®æ§ç¯ã¨ããµã¼ã証ææ¸ã®ä½ææé ã¨Apache+mod_SSLã§ã®è¨å®æ¹æ³ã«ã¤ãã¦ããç´¹ä»ãã¾ãã Section.1ã§ã¯ãé常ã®httpséä¿¡ãå¯è½ã¨ããããã以ä¸ã®æé ãè¡ãã¾ãã 1.èªå·±èªè¨¼å±(CA)ã®æ§ç¯ 2.ãµã¼ãã®è¨¼ææ¸ã®ä½æ 3.èªå·±èªè¨¼å±ã«ãããµã¼ã証ææ¸ã¸ã®ç½²å 4.Apache+mod_sslã®è¨å®ä¾ Section.2ã§ã¯ãSection.1ã«å ãã¦ã¯ã©ã¤ã¢ã³ãèªè¨¼ã«å©ç¨ãã証ææ¸ã®çºè¡æ¹æ³ã¨Apacheã®è¨å®ä¾ã示ãã¾ãã 1.ã¯ã©ã¤ã¢ã³ãèªè¨¼ç¨è¨¼ææ¸ã®ä½æ 2.Apache+mod_sslã§ã®è¨å®ä¾ æåã«ãèªå·±èªè¨¼å±(以ä¸CA)ã®æ§ç¯ãè¡ãã¾ãããªããCAã®æ§ç¯ã¯/usr/local/CAã«è¡ãã¾ãã CAãä½æããã«ã¯ãOpenSSLä»å±ã®CA.shãå©ç¨ãã¾ãã (CA.shã¯ãOpenSS
SQL ãã¼ã¿ãã¼ã¹æä½è¨èªSQLã«ã¤ãã¦ãã¾ãRDBMSã®æã¤æ©è½ã«ã¤ãã¦è©³ãã解説ãã¾ãã DBæ¦è¦ãSQLããã¼ãã«æä½ããã¼ã¿æä½ ... ç¹éï¼replication PostgreSQLã®ã¬ããªã±ã¼ã·ã§ã³ã·ã¹ãã ãç´¹ä»ãããããã®æ©è½ãæ¯è¼ãã¦ããã¾ãã ç¹éï¼pgbench PostgreSQLã®ãã³ããã¼ã¯ãã¹ãã«ç¨ããããããã°ã©ã ã§ãã pgbench ã«ã¤ãã¦è§£èª¬ãã¾ãã SQLæ¼ç¿åé¡ åç« ã«ç¨æãããæ¼ç¿åé¡ãéãã¾ããã
証ææ¸ã®å¤±å¹ã¨CRLã®çºè¡ 2003/6/14ä½æ 2004/9/19æ´æ° 主ã«ã¯ã©ã¤ã¢ã³ã証ææ¸ã®å ´åã§ãããçºè¡ãããã¨ã«ç§å¯éµãçã¾ããããç´å¤±ãããã¨ãããã¾ãã å ·ä½çã«ã¯ãpkcs12ã®ãã¡ã¤ã«ãåæã«ã³ãã¼ãããããç§å¯éµããã«ã®OSã¨ä¸ç·ã«å¿ä¸ãã¦ãã¾ããã¨ãããã¾ãã ã¾ããçºè¡ãã人ãæå³çã«èª°ãã«ç§å¯éµãé å¸ããããè²æ¸¡ããå¯è½æ§ãããã¾ãã ãããã£ã証ææ¸ããã¤ã¾ã§ãä¿¡ç¨ããããã«ã¯ãããªãã®ã§ç¡å¹ã¨ãªã£ã証ææ¸ã®ãªã¹ããCAããçºè¡ãã¦ã¯ã©ã¤ã¢ã³ã証ææ¸ã®æ¤è¨¼ãããWebãµã¼ãã«é å¸ãã¾ãã ï¼ï¼è¨¼ææ¸ã®å¤±å¹ ãã£ããã証ææ¸ã失å¹ãã¾ãã CAã§çºè¡ãã証ææ¸ã使ã£ã¦CAã§å¤±å¹æç¶ãããããã¨ã«ãªãã¾ãã -revokeãªãã·ã§ã³ã®ãã¨ã«ãCAãçºè¡ãã証ææ¸ãæå®ãã¾ãã
Windowsç°å¢ã§opensslã«ããå種ã®éµã証ææ¸ã®çºè¡ã«ã¤ãã¦æ´çãã¾ããããLinuxç³»ã¯çµæ§ãããããªãµã¤ãã§ç´¹ä»ããã¦ãã¾ãããWindowsã«ã¤ãã¦ã¯ç°å¢ãç°ãªããã¨ãããªããªããã®ã¾ã¾ã§ã¯ãã¾ãããã¾ãããããããä½åº¦ããã©ã¤ãã¦ã¯å¤±æãã¦ããã®ã§ãããã§æ´çãã¦ãããã¨ã«ãã¾ãããä»åã¯ããã¾ãã¾BBSã§ã¯ã©ã¤ã¢ã³ã証ææ¸ã«é¢ãã話é¡ãããã£ã¦ããã®ã§ãããã«ã¤ãã¦ãæ´çãã¾ããã ãã®å¾ãåãã«æ´çããæ¹æ³ã§ã¯ã¯ã©ã¤ã¢ã³ããInternetExploreã§ã¯åé¡ãªãããNetscape ã§ã¯ãã¾ãã¤ã³ã¹ãã¼ã«ã§ããªããã¨ãå¤æãã¾ãããã¾ããä¸ãä¸ã®å ´åã®è¨¼ææ¸ã®å¤±å¹å¦çãé å¸ããã¦ããopensslã®ãã¤ããªã«ãã°ããããindex.txtãå£ããã¨ããåé¡ããããã¾ãã§ããªããã¨ãå¤æãã¾ãããããããæ¢ãåã£ãã®ã§ãããææ°ã®ãã¤ããªãã©ããã¦ãè¦ã¤ãããªãã£ã
opensslã³ãã³ãtips å ã¯ãAirOneã®ã»ãã¥ãªãã£é¢é£ã®ãã¡ã¤ã«ã®èª¬æææ¸ã§ãã opensslã³ãã³ãã®tipsææ¸ã¨ãã¦ä½¿ããã®ã§ãããã¤ã追è¨ãã¦ãå ¬éãã¾ãã * PKIé¢é£ ========= ** identity.pem(ç§å¯éµãã¡ã¤ã«) ** cert.pem(証ææ¸ãã¡ã¤ã«) AirOneã®èµ·åæã«identity.pemã¨cert.pemã®æ´åæ§ãã§ãã¯ãè¡ãã¾ã(airu_cert_validate())ã ãã§ãã¯é ç®ãã¨ã©ã¼ã³ã¼ãã解ææ¹æ³ã説æãã¾ãã ãã§ãã¯é ç® ------------ 1. cert.pemãx509ã®ãã©ã¼ãããã? ã¨ã©ã¼ã³ã¼ã: #0301005 解ææ¹æ³: openssl x509 -text -in cert.pem ã§ã¨ã©ã¼ãã§ãªããã¨ã 2. identity.pemãå ¥åãã¹ã¯ã¼ãã§èªããã? ã¨ã©ã¼ã³ã¼ã:
CAãæ§ç¯ããã¨ã¯ãµã¼ããã¯ã©ã¤ã¢ã³ãèªè¨¼ã®ããã®è¨¼ææ¸ã çºè¡ãããã¨ãã§ããããã«ãããã¨ãæå³ãã¾ã. 誤解ãã¦ã¯ãªããªãã®ã¯ãããã¯ã¼ã¯ãµã¼ãã®ããã« ãããã¯ã¼ã¯ã«æ¥ç¶ããããã¹ãã®ç¹å®ã®ãã¼ãã§æ¥ç¶ãå¾ ã¡åãã¦ã ã¯ã©ã¤ã¢ã³ããããã«æ¥ç¶ãã¦ãã³ãã³ããçºè¡ãã çµæãå¾ãããã®ãµã¼ããä½ãããã§ã¯ãªãã¨ãããã¨ã§ã. 確ãã«ä¾é ¼è ããCSRãåãåããããã«åºã¥ãã¦è¨¼ææ¸ã çºè¡ãã¾ããããã®åã渡ãã®ããã®æé ãå®ãããã¦ãã ããã§ã¯ããã¾ãããWWWã®CGIã§åã渡ããè¡ã£ã¦ãã ã¡ã¼ã«ã§æåã§éã£ã¦ãããããã§ãã ãã®é¨åã¯è¦ç´ãããããã§ã¯ããã¾ããã èªè¨¼å±ãæ§ç¯ããã®ã«å¿ è¦ãªã®ã¯ãéµãã¢ãä½ãã証ææ¸ãä½ã ã½ããã¦ã§ã¢ãç¨æãããã¨ãã¾ãæ§ç¯ããèªè¨¼å±èªèº«ã® CA証ææ¸ãä½ãã®ã«å¿ è¦ãªãã®ãä½æãããã¨ã§ãã OpenSSLã®ã¤ã³ã¹ãã¼ã« ã¤ã³ã¹ãã¼ã«ã¯ç°¡å
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}