40代å¾åã§éçºã¨ã³ã¸ãã¢ããã¯ã©ã¦ãã¤ã³ãã©ã¨ã³ã¸ãã¢ã«ãã£ãªã¢ãã§ã³ã¸ããçãæ®ããèªä¿¡ãããããæã¦ã話
40代å¾åã§éçºã¨ã³ã¸ãã¢ããã¯ã©ã¦ãã¤ã³ãã©ã¨ã³ã¸ãã¢ã«ãã£ãªã¢ãã§ã³ã¸ããçãæ®ããèªä¿¡ãããããæã¦ã話
Chrome58ã§ãHTTPSã®èªå·±è¨¼ææ¸ã NET::ERR_CERT_COMMON_NAME_INVALID ã«ãªãå ´åã®å¯¾å¿ Google Chrome ããã¼ã¸ã§ã³58 ã«ã¢ãããã¼ãããã¨ãSSLèªå·±è¨¼ææ¸ã使ã£ã¦ãããµã¤ããè¦ããªããªãå ´åãããã¾ãã èªå·±è¨¼ææ¸(ãªã¬ãªã¬è¨¼ææ¸)ã使ã£ã¦ãããµã¤ãã« HTTPS ã§ã¢ã¯ã»ã¹ããã¨ã ãã®æ¥ç¶ã§ã¯ãã©ã¤ãã·ã¼ãä¿è·ããã¾ãã æ»æè ããtech.torico-corp.com ä¸ã®ããªãã®æ å ±ï¼ãã¹ã¯ã¼ããã¡ãã»ã¼ã¸ãã¯ã¬ã¸ãã ã«ã¼ãæ å ±ãªã©ï¼ã ä¸æ£ã«åå¾ãããã¨ãã¦ããå¯è½æ§ãããã¾ãã NET::ERR_CERT_COMMON_NAME_INVALID ã»ãã¥ãªãã£ã«é¢ããäºè±¡ã«ã¤ãã¦ã®è©³ç´°ã Google ã«èªåéä¿¡ããããã©ã¤ãã·ã¼ ããªã·ã¼ ã»ãã¥ãªãã£ã§ä¿è·ããããã¼ã¸ã«æ»ã詳細æ å ±ã表示ããªã ãã®ãµã¼ãã¼ã
ãå¤æ´å±¥æ´ 2018å¹´2æ15æ¥ãå½åã®è¨äºã¿ã¤ãã«ã¯ããã¾ãªãHTTPSåãªã®ãï¼ æè¡è ãç¥ã£ã¦ããããSEOãããã£ã¨å¤§åãªã㨠â TLSã®æ´å²ã¨æè¡èæ¯ãã§ããããç¾è¡ã®ãã®ã«å¤æ´ãã¾ãããç¾å¨Googleã§ã¯Webãµã¤ãã®HTTPS対å¿ã¨æ¤ç´¢çµæã®é¢ä¿ã強調ãã¦ããããæ¬è¨äºã®è¶£æ¨ã®ä¸ã¤ã«ãæ¬æ¥ã¯ç¬ç«ããåé¡ã§ããSEOã¨HTTPSåãé¢é£ä»ããã¨ããæ ¹å¼·ã誤解ã解ããã¨ãããã¾ãããå½åã®ã¿ã¤ãã«ã§ã¯ããã£ã¦SEOã¨HTTPSãé¢é£ä»ãã¦èªã¾ãããããããããã¾ãåæ§ã®ææãããã ãããã¨ããå¤æ´ãããã¾ããã HTTPã¨HTTPSã¯ãå ±ã«TCPéä¿¡ä¸ã§åä½ãã¾ãããããã£ã¦ãããããTCPãã³ãã·ã§ã¤ã¯ã§éä¿¡ãéå§ãã¾ãã HTTPéä¿¡ã®å ´åã«ã¯ããã®TCPãã³ãã·ã§ã¤ã¯ç´å¾ã«ãHTTPãªã¯ã¨ã¹ãã¨ã¬ã¹ãã³ã¹ã®ããåããå§ã¾ãã¾ãããã®HTTPã®ããåãã¯å¹³æéä¿¡ã§ãããé
ã2018/11/16 追è¨ã æ¬è¨äºã¯ã2016 å¹´ 4 æã« Google Public DNS ãµã¼ãã«å®è£ ããããå®é¨ç㪠DNS over HTTPS ãããã³ã«ã«ã¤ãã¦ç´¹ä»ãã¦ãã¾ããDNS over HTTPS ãããã³ã«ã¯ãã®å¾ IETF ã® doh ã¯ã¼ãã³ã°ã°ã«ã¼ãã«ã¦æ¨æºåãé²ãããã2å¹´åå¾ã® 2018 å¹´ 10 æã« RFC8484 ã¨ãã¦åºçããã¾ãããæ¬è¨äºã§ç´¹ä»ãããããã³ã«ã¯ RFC8484 ã«è¦å®ããããããã³ã«ã¨ã¯ããã¤ãã®ç¹ã§ç°ãªã£ã¦ãããã¨ã«ã注æãã ããã Google Inc. ãå ¬é DNS ãµã¼ããéå¶ãã¦ãããã¨ã¯ãåç¥ã§ãããã? Google Public DNS ã¨å¼ã°ãããã®å ¬é DNS ãµã¼ãã¯ãâ8.8.8.8â³ ã¨ããç¹å¾´ç㪠IP ã¢ãã¬ã¹ã§å ¨ä¸çã®ã¤ã³ã¿ã¼ãããã¦ã¼ã¶ã«å¯¾ãã¦ç¡æã® DNS ãµã¼ã(ãã«ã¬ã¾ã«ã)ãæä¾ã
æ¦è¦ 社å ãããã·ã«æ§ã ãªãµã¤ãã¸ã®ã¢ã¯ã»ã¹ããããã¯ããããã社å¤ãµã¼ãã«sshã§ããªãã£ãããã人åãã«ç¤¾å¤ãããã·ãç«ã¦ã¦ãããããµã¤ãã«ã¢ã¯ã»ã¹ããæ¹æ³ã®ã¾ã¨ãã§ãã(å¾è¿°ãã¾ããååããããã¿ãã¹ãã§ãã) ä»ã«ã以ä¸ã®ãããªå¹æãããã¾ãã®ã§ããããã·ããªã¼ãªä¼ç¤¾ã«ãå¤ãããè¯ãã£ããåèã«ãã¦é ããã°ã¨æãã¾ãã ãªãã2015å¹´ã«ãªã£ã¦ãåå¨ããã«ãã§ã¨ãããã«ã¨ãã§ã®ä¿è·ããã¦ããªãã£ããããç¡ç·wifiã使ã£ã¦ãçè´ãããªãã æ¥æ¬ããã¢ã¯ã»ã¹ã§ããªããµã¤ãã«ã¢ã¯ã»ã¹ã§ããã(æµ·å¤ã®ãã¼ã¿ã»ã³ã¿ä¸ã®VMã使ã£ãå ´å) ãªããéèªè¨¼ãããã·ãä¾ã«ãã¦ã¾ããèªè¨¼ãããã·ã§ããã¾ãå¤ãããªãã¨ã¯æãã¾ãããç°å¢ãç¡ãããæªç¢ºèªã§ããã¾ãããããã·ã®æåãè¨å®æ¹æ³ã¯ãããã·ãµã¼ãã®ç¨®é¡ãè¨å®ã«ãã£ã¦å¤å²ã«æ¸¡ããããå ¨ã¦ã®ãããã·ã§åãæ¹æ³ã使ããã¨ã¯éããªãã¨ã¯æãã¾ãã æå¾
社å æ¥åã·ã¹ãã ãWebã«ç§»è¡ä¸ã§ãã ããã«ä¼´ãSSLæå·åãèæ ®ãã¦ãã¾ãã 社å ã·ã¹ãã ã®å ´åã 第ä¸è ãçºè¡ããCAç½²ååã¨ã èªåã§çºè¡ããèªå·±è¨¼æåã® ã©ã¡ããä¸è¬çã§ããããï¼ ééçãªã¡ãªãã以å¤ã«ãèªæ¼ã§ããèªå·±è¨¼æåã®ã¡ãªãããä»ä¸ã¤åããã¾ããã 社å æ¥åã·ã¹ãã ã§ã¯ãå©ç¨è ã社å ã®å¾æ¥å¡ã«éå®ãããã®ã§ èªå·±è¨¼æåã§ãè¯ããã¨ããèãæ¹ãããã§ããããï¼ ãªã«ã¶ãåãã¦ãªãã®ã§ããã®è¾ºãã®ãæè¦ããã ããã°å¹¸ãã§ãã ã©ããå®ãããé¡ãè´ãã¾ãã
https://caddyserver.com/ ãªã«ãã大å¤ä¾¿å©ãããªãã®ãããã¾ããã HTTP/HTTPS ãµã¼ãã¼TLS 証ææ¸ã®èªåæ´æ°ãå¯è½ (HTTP, DNS 両æ¹å¯¾å¿)HTTP2, QUIC, WebSocket ã«ã対å¿Go ã§æ¸ããã¦ããã®ã§ãã«ããã©ãããã©ã¼ã 対å¿åç´ãªãã£ã¬ã¯ããªã®å ¬éMarkdown ã®ã¬ã³ããªã³ã°ãå¯è½ãã¤ãããã¯ãªè¨¼ææ¸åå¾ (Letâs Encrypt ã¯ã¯ã¤ã«ãã«ã¼ã証ææ¸ã«å¯¾å¿ãã¦ããªããããªã¯ã¨ã¹ããåããæç¹ã§ãã®ãã¡ã¤ã³ã®è¨¼ææ¸ãåå¾ããã¨ãããã¨ã§ã¯ã¤ã«ãã«ã¼ãã£ã½ã使ãã)ãªãã¼ã¹ãããã·ãã¼ããã©ã³ã¹Basicèªè¨¼ä»Plugin ã«ããæ¡å¼µIPã¢ãã¬ã¹å¶ératelimitãã¡ã¤ã«ã¢ãããã¼ããåé¤CGIãªã©ãªã©https://github.com/caddyserver/examples ããã«å種è¨å®ä¾ãããã¾ããã§ã
[toc] Certbot(æ§Let's Encrypt)ã¯ç¡æã§SSL/TLS証ææ¸ãçºè¡ã§ããèªè¨¼å±(CA)ã§ããæå¹æéã90æ¥(ç´3ã¶æ)ã¨çãã§ãããã³ãã³ãã«ããèªååãå¯è½ã§å®æçã«å®è¡ãããã¨ã§å¸¸ã«è¨¼ææ¸ãæ´æ°ãç¶ãããã¨ãã§ãã¾ãã 証ææ¸ãåå¾ããã«ãããããã¡ã¤ã³ãèªåã§ç®¡çãã¦ãããã®èªè¨¼æ¹å¼ã以ä¸ã®ä¸ã¤ããµãã¼ãããã¦ãã¾ãã HTTP-01 Let's Encryptã®èªè¨¼å±ããã¯ã³ã¿ã¤ã ãã¼ã¯ã³ãçºè¡ãã¦ããããWebãµã¼ãã«èªè¨¼ç¨ãã¡ã¤ã«ãè¨ç½®ããã èªè¨¼å±ããHTTP(80çªãã¼ã)ã§ã¢ã¯ã»ã¹ãã¦ããããã¯ã³ã¿ã¤ã ãã¼ã¯ã³ã¨èªè¨¼ç¨ãã¡ã¤ã«ã¨ã®å¦¥å½æ§ãæ¤è¨¼ããã TLS-SNI-01 HTTP-01ã¨åãæ¹æ³ã ããHTTPS(443ãã¼ã)ã使ç¨ããã DNS-01 Let's Encryptã®èªè¨¼å±ããçºè¡ãã¦ããã£ãã¯ã³ã¿ã¤ã ãã¼ã¯ã³ã対象ãã¡ã¤ã³ã®TX
Apache 2.2.* 系㨠OpenSSL ã§ã® HTTPS ã®å©ç¨ - Linux ãµã¼ãèªè¨¼ ç·¨ - ããã§ã¯ãApache 2.2.* 系㨠OpenSSL ã使ç¨ã㦠HTTPS éä¿¡ãè¡ãã¾ãã ãµã¼ãèªè¨¼ã«ã¤ãã¦ç°¡åã«èª¬æãããã¾ãã ä¸è¬çã« HTTPS éä¿¡ ( éä¿¡çµè·¯ã®æå·å ) ã使ç¨ããå ´é¢ã¨ããã®ã¯ã å人æ å ±ã®éä¿¡ã ã¯ã¬ã¸ããã«ã¼ãã®æ å ±ãªã©ã®éä¿¡ã«ããã¦å¿ è¦ã«ãªãã¨æãã¾ãã ãªãå¿ è¦ãã¨ããã¨ããããã®æ å ±ã¯ä»ã«æ¼ãã¦ã¯ãããªãæ å ±ã§ãããããå¹³æã§éä¿¡ãããªãã°ã éä¸ã®éä¿¡çµè·¯ã®ã©ããã§ç¬¬ä¸è ã«ããã®æ å ±ãè¦ããã¦ãã¾ãå¯è½æ§ããããé大ãªçµæãæãããã¾ããã ãã®ãããªçµæãé²ãç®çããããHTTPS éä¿¡ãè¡ãã¾ãã ããããããã§ä»¥ä¸ã®æ¡ä»¶ãæºããå¿ è¦ãããã¾ãã ã»éä¿¡çµè·¯ã®æå·å ã»æ å ±ãéä¿¡ãããµã¼ããæ¬å½ã«å®å¨ããèªåãé
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}