TLS ã®å°å
¥æ¹æ³ãå¤åãã¦ãã¾ã。å
¬ééµè¨¼ææ¸ã®æé·æå¹æé㯠5 å¹´ãã 2 å¹´ã«ãªã(
CA/Browser Forum)、è¿ããã¡ã« 1 å¹´ã«ç縮ãããäºå®ã§ã。æåã§ã®è¨¼ææ¸ã®ç»é²ã«ããåé¡ãæ¸ãããã、Internet Engineering Task Force(IETF)ã¯èªåã§è¨¼ææ¸ã管çãã Automatic Certificate Management Environment(
ACME)ãæ¨æºåãã¾ãã。ACME ãå©ç¨ããã¨、ç¸äºéç¨ãå¯è½ãªå½¢ã§èªè¨¼å±(CA)ããããªã㯠ã¦ã§ãã® TLS è¨¼ææ¸ãèªåã§æä¾ã§ãã¾ã。
æè¿ã® TLS ã®å¤é·ããã©ãä¸ã§ã¯、å
¬çã«ä¿¡é ¼ãããåãã¦ã®éå¶å© CA ã§ãã
Let’s Encrypt ã®åå¨ã«è§¦ããªãããã«ã¯ããã¾ãã。ãã®èªåå㨠TLS ã®ããã©ã«ãåã«åããæ³¨åã¯、TLS ã®å¤§å¹
ãªå©ç¨æ¡å¤§ã®åå°ã¨ãªã£ã¦ãã¾ã。å®é、Let’s Encrypt 㯠10 ååç®(!)ã®è¨¼ææ¸ãçºè¡ããã°ããã§ã。Google 㯠Let’s Encrypt ãç©æ¥µçã«æ¯æ´ãã¦ãã¾ã。TLS ã身è¿ãªãã®ã«ããã¨ãã Let’s Encrypt ã®åãçµã¿ã¯、ã¤ã³ã¿ã¼ããã ã¤ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ãã¬ã¸ãªã¨ã³ã¹ã«ã¨ã£ã¦æ¬ ãããªãã¨ä¿¡ãã¦ããããã§ã。Let’s Encrypt ã®å¥éãç¥ãã¾ã!
Google ã¦ã¼ã¶ã¼ã®è¨¼ææ¸ã©ã¤ããµã¤ã¯ã«ç®¡çãç°¡åã«
以ä¸ã®ãã¨ã¯、ã»ãã¥ãªã㣠ã³ãã¥ããã£å
¨ä½ã§æãéãã大ããéè¦ãªä¸æ©ã§ã。åæã«、ãã®åãçµã¿ã¯、éµã®æå¹æéãç縮ãã¦ã»ãã¥ãªãã£ãæ¹åãããã¨ãæå³ãã¾ã。ããã«ãã、è¨¼ææ¸ã®æ´æ°é »åº¦ãä¸ããã ãã§ãªã、ã¾ãã¾ã夿§ãªã¤ã³ãã©ã¹ãã©ã¯ãã£ã¸ã®ãããã¤ãæ±ãããããã¨ã«ãªãã¾ã。ã¦ã§ãã®ãã©ãã£ãã¯ã¯è¤æ°ã®ãã¼ã¿ã»ã³ã¿ã¼ããæä¾ãã、å¤ãã®å ´åã¯ãããã¤ããç°ãªãã¾ã。ãã®ãã、æ´æ°ããå¿
è¦ãããè¨¼ææ¸ã管çããã、æ°ããè¨¼ææ¸ãæ£ãããããã¤ããããã使¥ãæåã§è¡ãã®ã¯é£ãããªãã¾ã。ã§ã¯、ã©ãããã°ããã®ã§ãããã。
åè¿°ã®æ®åç¶æ³ãèããã°、ç§ãã¡ãã客æ§ãæ§ç¯、ãããã¤ãããã¹ã¦ã®ãããã¯ãã«ã¨ã£ã¦、TLS ã Web PKI、è¨¼ææ¸ã©ã¤ããµã¤ã¯ã«ç®¡çãéè¦ã§ãããã¨ã¯æç½ã§ã。ãã®ãã、ç§ãã¡ã¯ãããã¯ãããµã¼ãã¹ã«ããã¦ããã©ã«ãã§ TLS ãæå¹åããã¨ããéè¦ãªåãçµã¿ãæ¡å¤§ãã¤ã¤、è¨¼ææ¸ã®æ´æ°ãèªååãã¦è¨¼ææ¸ã©ã¤ããµã¤ã¯ã«ç®¡çã®ä¿¡é ¼æ§ãåä¸ãã、ã°ãã¼ãã«ã§ã®æ¡å¤§ãå®ç¾ã、ã客æ§ããã®ç¢ºããªä¿¡é ¼ãå¾ãããããã«ãã¦ãã¾ãã。ç§ãã¡ã®ç®çã¯ã·ã³ãã«ã§、ã©ã® Google ã®ãµã¼ãã¹ã使ãå ´åã§ãããã« TLS ãå©ç¨ã§ããããã«ãããã¨ã§ã。
ãã®ç®çã®å®ç¾ã«åãã¦、å
é¨å°ç¨ã® ACME ãµã¼ãã¹ã§ãã
Google Trust Services ã使ã、Google ã®ãµã¼ãã¹ã対象㫠TLS è¨¼ææ¸ã®èªå管çãå®ç¾ãã¾ãã。ããã¯、Google ã®ãããã¯ãããµã¼ãã¹ã ãã§ãªã、Alphabet ã Google Cloud ã®ã客æ§ã®ããã«ã使ããã¦ãã¾ã。ãã®çµæ、ã客æ§ã®è¨¼ææ¸ãèªåçã«æ´æ°ãããããã«ãªã、ã¦ã¼ã¶ã¼ã¯è¨¼ææ¸ã®æå¹æéåããªã©ã«ã¤ãã¦å¿é
ããå¿
è¦ã¯ãªããªãã¾ãã。ãã®å®è£
ã®ãã¤ã³ããç´¹ä»ãã¾ã。
- Blogger ããã°、Google ãµã¤ã、Google ãã¤ãã¸ãã¹ ãµã¤ãã¯、ãã¹ã¦ã®ã«ã¹ã¿ã ãã¡ã¤ã³ãããã©ã«ãã§ HTTPS åããã¦ãã¾ã。
- Google Cloud ã¦ã¼ã¶ã¼ã¯、èªåã®ãã¡ã¤ã³ã§ Managed TLS ãå©ç¨ã§ãã¾ã。ãã®ãã、以ä¸ã®ããã«ãªãã¾ã。
- Firebase、Cloud Run、AppEngine ã§éçºãã¦ãããããããã¼ã¯、ä½ãããªãã¦ãã¢ããªã±ã¼ã·ã§ã³ã§ HTTPS ãå©ç¨ã§ãã¾ã。
- Google Kubernetes Engine ã«、ã¾ã㯠Google Cloud Load Balancing(GCLB)ã®èå¾ã«ã¢ããªã±ã¼ã·ã§ã³ããããã¤ããå ´åã¯、ã客æ§ã Google ã管çããè¨¼ææ¸ã使ããã¨ã鏿ããã¨、èªåçã«è¨¼ææ¸ç®¡çãè¡ããã¾ã。ããã«ã¯、ããããã®ãããã¯ãã§ç°¡åãã¤ç¢ºå®ã« TLS ãå©ç¨ã§ããããã«ãªãã¨ãã广ãããã¾ã。
Google ã®ãµã¼ãã¹ã«ã¨ã£ã¦、ããã©ã¼ãã³ã¹、æ¡å¼µæ§、ä¿¡é ¼æ§ã¯å¿
é è¦ä»¶ã§ã。ç§ãã¡ã¯、ãããã¯ãããµã¼ãã¹ã§ãããã®åºæºãæºãããããã«、å
¬çã«ä¿¡é ¼ããã CA ã§ãã Google Trust Services ãè¨ç«ãã¾ãã。åæã«、ç§ãã¡ã¯ã¦ã¼ã¶ã¼ã®é¸æãéè¦ãã¾ã。ãã®ãã、Google Trust Services ãç°¡åã«ä½¿ããããã«ãã¤ã¤ã、Google ã®ãããã¯ãããµã¼ãã¹å
¨ä½ã§ Let’s Encrypt ã使ããããã«ãã¦ãã¾ã。ããã¯、ããªãã¡ã¬ã³ã¹ãæå®ãã
CAA ã¬ã³ã¼ãã使ãããã¨ã§、ç°¡åã«é¸æã§ãã¾ã。
ããã«ä½¿ãã TLS ã¯ãã¹ã¦ã®äººã«æ©æµãããããã¾ãã、ãã¯ã¼ã¦ã¼ã¶ã¼ã«ã¯ç¹å¥ãªãã¼ãºããããã¨ãæ¿ç¥ãã¦ãã¾ã。ããã§、
Google Cloud Load Balancing ã§ã¯、TLS ã¿ã¼ããã¼ã·ã§ã³é¢ä¿ã®ããªã·ã¼ãå¶å¾¡ã§ããé«åº¦ãªæ©è½ãæä¾ãã¦ãã¾ã。
ããã«、
Certificate Transparency ã®ä½æ¥ã§ã¯、ä»ã®çµç¹ã¨ã飿ºã、WebPKI ã¨ã³ã·ã¹ãã ã§èªåã®ãã¡ã¤ã³ãããã«ä¼¼ããã¡ã¤ã³ã«å¯¾ãã¦çºè¡ãããè¨¼ææ¸ãã¢ãã¿ãªã³ã°ãããã¨ã§、ã客æ§ãç°¡åã«èªèº«ãã¦ã¼ã¶ã¼ã®ãã©ã³ããä¿è·ã§ããããã«ãã¦ãã¾ã。ãã®äºå対çã«ãã、åé¡ãèµ·ããåã«æªç¨ã鲿¢ã§ãã¾ã。ãã¨ãã°、Facebook 㯠Certificate Transparency ãã°ã使ç¨ãã¦、Facebook ã®ãµã¼ãã¹ã«ãªããã¾ããã¨ããå¤ãã®ãã£ãã·ã³ã° ãµã¤ãã
ç¹å®ãã¾ãã。
ç§ãã¡ã¯、çããã«ã¨ã£ã¦ã»ãã¥ãªãã£、ãã©ã¤ãã·ã¼、ä¿¡é ¼æ§ãã©ãã»ã©éè¦ãªãã®ã§ããããæ¿ç¥ãã¦ãã、çããããã¾ãã¾ãªãããã¯ãã«å®å¿ã㦠TLS ãå°å
¥ããããã«å¿
è¦ãªãã¼ã«ãæä¾ãã使¥ãé²ãã¦ãã¾ã。ä»å¾ã、ã¤ã³ã¿ã¼ããããå®å
¨ãªå ´æã«ããããã®åãçµã¿ãååãã¦é²ãã¦ããããã¨æãã¾ã。
Reviewed by
Eiji Kitamura - Developer Relations Team