ï¼2015/1/30 追è¨ï¼ææã¯ä¸æã§ãããç¾æç¹ã®github.comã¯Ed25519éµã«ã対å¿ãã¦ãã¾ãã
ï¼2016/5/31 追è¨ï¼ãGitHubにバグ報告して賞金$500を頂いた話ãã§ç´¹ä»ããéããæ¢ã«å¼±ãéµã¯GitHubããåé¤ãããæ°è¦ç»é²ãã§ããªããªã£ã¦ãã¾ãã
GitHub APIãå©ç¨ãã¦ãGitHubã®31661ã¢ã«ã¦ã³ãã«ç»é²ããã¦ããSSHå
¬ééµ64404åãåå¾ãã¦ã¿ã¾ãããæ½åºæ¹æ³*1ãé©å½ããã¦åãããããããªæ°ããã¾ãããé¢ç½ãçµæãå¾ãããã¨æãã®ã§ã¾ã¨ãã¦ã¿ã¾ãã
SSHéµã®ç¨®é¡
éµã®ç¨®é¡ | åæ° | å²å |
---|---|---|
RSAéµ | 61749 | (95.88%) |
DSAéµ | 2647 | (4.11%) |
ECDSAéµ | 8 | (0.01%) |
ç´6ä¸åã®éµã®ãã¡ã8åã ãECDSAï¼æ¥åDSAï¼éµãè¦ã¤ããã¾ããï¼å¸¸ç¨ãã¦ããã®ã試ãã«ç»é²ãã¦ã¿ãã ããªã®ãã¯ãããã¾ããããä½ã«ããæèé«ãæãã§ã¹ããã§ããã
SSHéµã®bité·
RSAéµ
éµé· | åæ° | å²å |
---|---|---|
800bit | 1 | (0.00%) |
1024bit | 2034 | (3.29%) |
1026-2046bit | 15 | (0.02%) |
2048bit | 58773 | (95.18%) |
2050-4094bit | 25 | (0.04%) |
4096bit | 827 | (1.34%) |
4098bit- | 74 | (0.12%) |
2048bitéµãå¤æ°æ´¾ã¨ããçµæã«ãªãã¾ãããããã¯å¤ãã®SSHå®è£ ãããã©ã«ãã§çæããéµé·ã ã¨æãã®ã§ãå½ç¶ã®çµæã§ã¯ããã¾ãã
1024bitéµã®äººãããããè¦ã¤ããã¾ããæçã®éµé·ã¯ãªãã¨800bitã§ããããã¨ã§è§¦ãã¾ãããããããªãã§ããã
DSAéµ
éµé· | åæ° | å²å |
---|---|---|
512bit | 1 | (0.04%) |
1024bit | 2484 | (93.84%) |
1280bit | 2 | (0.08%) |
2048bit | 151 | (5.70%) |
3072bit- | 9 | (0.34%) |
å®ã¯ãOpenSSHã®ssh-keygenã¯1024bitã®DSAéµããä½ãã¾ããããããã£ãäºæ ãããã2048bitæªæºã®éµã使ã£ã¦ãã人ãããªãå¤ãçµæã«ãªãã¾ãããRSAéµã¨åæ§ããããããªãçµæã¨è¨ããã§ããããç¹ã«512bitã®éµã¯ä»åã®èª¿æ»ä¸ã§æå¼±ã®å¯è½æ§ãããã¾ãã
ECDSAéµ
éµé· | åæ° | å²å |
---|---|---|
256bit | 3 | (37.5%) |
521bit | 5 | (62.5%) |
NISTã®ã¬ã¤ãã©ã¤ã³ãRecommendation for Key Management: Part 1: General (Revision 3)ã(PDF) ã«ããã°ã256bit ECDSAéµã¯3072bit RSAéµã«ã521bit ECDSAéµã¯15360bit RSAéµã«ç¸å½ããããã§ããå®å¿æãããã¾ããã
ã¡ãªã¿ã«521bitã¨ããã®ã¯typoã§ã¯ããã¾ããã念ã®ããï¼åèï¼ã楕円曲線暗号に 512 bit は存在しないãï¼ã
強度ã®ä½ãSSHéµãç¾å½¹ã§ä½¿ããã¦ããæ¸å¿µ
ä»å調ã¹ã¦ã¿ã¦æ°ã¥ããã®ã¯ã強度ã®ä½ãSSHéµãã¾ã ã¾ã 使ããã¦ããã®ã§ã¯ãªãããã¨ãããã¨ã§ãã1024bit以ä¸ã®DSAéµã¨RSAéµã¯ããããæ¨ã¦ãã¹ãææãæ¥ã¦ããã¨ããã®ãåã®èªèã§ãã
å°ãåã«ãæå·ã¢ã«ã´ãªãºã ã®2010å¹´åé¡ãã¨ããè¨èãå«ã°ãããã¨ãããã¾ãããç±³æ¿åºãæ¥æ¬æ¿åºã®ã·ã¹ãã ã§ã®æå·å¼·åº¦ã«é¢ããã¬ã¤ãã©ã¤ã³ãåºããã2010å¹´ã¾ã§ã«ä¸å®ä»¥ä¸ã®å®å ¨æ§ã®æå·ã«ç½®ãæããããã¨ããåãããã£ããã¨ãæãã¾ãããã®ã¬ã¤ãã©ã¤ã³ã§ã¯ã2048bitæªæºã®RSAã2048bitæªæºã®DSAã223bit以ä¸ã®ECDSAãåãæ¿ããã¹ãã¨ããã¾ãããä¸ã®èª¿æ»çµæã§ããã¨å ¨ä½ã®ç´7%ã®éµã該å½ãã¾ãã
ã暗号技術調査WG(計算機能力評価)活動報告ã(PDF)ã®8ãã¼ã¸ç®ã®ã°ã©ããè¦ãéãããã¨æ°å¹´ãããã®éã¯ã1024bit RSAéµã®è§£èªã«ä¸çãããã¬ãã«ã®ã¹ãã³ã³ã1å¹´å æãããããã®è¨ç®éãå¿ è¦ããã§ããå人ã®SSHéµã1024bité·ã ããã¨ãã£ã¦ç¾å®å³ã®ããè å¨ã¨ã¯è¨ãã«ããã§ãããçå±ä¸ã¯æ¢ã«å±éºæ°´åã¨èªèãã¹ãã§ãããã
SSHå ¬ééµãå ¨ä¸çã«å ¬éããããã¨ã«å¯¾ããæ¸å¿µ
ä»åãã®ãããªèª¿æ»ãã§ããã®ã¯ãGitHubãユーザーの公開鍵をAPIで公開しているããã§ããèªåã®å ¬ééµãGitHubã®ç¹å®URLããèªã¿åãããã¨ã§ä»äººã«å ¬ééµãä¼ããã®ã楽ã«ãªãã¾ããããåå人ã¨ãã¦ã¯é常ã«ä¾¿å©ãªæ©è½ã ã¨æãã¦ãã¾ãããã ããµã¼ãã¹å ¨ä½ã®è¨è¨ã¨ãã¦ã¯åé¡ãããããã«ãèãã¦ãã¾ãã
確ãã«ãå ¬ééµæå·ã¯ãç§å¯éµããç¥ãããªããã°å ¬ééµã¯ãã¬ã¦ãå®å ¨ãã¨ããæ§è³ªãããã¾ããããå ¬ééµãå ¬éãã¦ãåé¡ãç¡ãããã«æãã¾ãããã ããã®åæã¨ãã¦ãååãªå¼·åº¦ã®éµãã¢ã使ã£ã¦ããããã¨ãå¿ è¦ã§ãã7%ã®ã¦ã¼ã¶ã¼ã強度ã«çåã®ããéµãç»é²ãã¦ããç¶æ³ã§å ¨ã¦ã¼ã¶ã¼ã®å ¬ééµãå ¬éãã¦æ¬å½ã«å¤§ä¸å¤«ãªã®ã§ããããã
ã¾ããSSHã®å ´åã¯ä¸ç¹å®å¤æ°ã¨éä¿¡ããHTTPSãªã©ã¨ã¯å©ç¨ã·ã¼ã³ãç°ãªã£ã¦ããã誰ã«ã§ãå ¬ééµãå ¬éããå¿ è¦æ§ã¯ããã¾ãããä¸ä¸å ¬ééµãå ã«ç´ å æ°å解ãé¢æ£å¯¾æ°åé¡ã解ããã¦ãã¾ãã¨SSHãã°ã¤ã³ã許ããã¨ã«ãªãã¾ããããå ¬éããªãæ¹ãå®å ¨ãªã®ã¯ééããªãã¯ãã§ããã¦ã¼ã¶ã¼ããªã¹ã¯ãæ¿ç¥ã§å ¬éãããªãå人ã®åæã§ããããµã¼ãã¹ã¨ãã¦å ¨å¡ã®å ¬ééµãå ¬éããã®ã¯çåã§ãã
èªè¡çã¨ãã¦ãGitHubã«ç»é²ããéµãã¢ãæ®æ®µä½¿ãã®éµã¨ã¯å¥ã«ãããã¨ããã®ãæããããã¾ããããã ããã·ã³ãã¨ã«éµãã¢ã2çµä½ãã®ãé¢åãªã®ã§ãåå人ã¯ãã¾ãããæ°ããã¾ãããâ¦ã
ãã®ç¹ã«ã¤ãã¦ã¯èè ã®æè¦ã伺ãããã¨ããã§ããã»ãã¥ãªãã£çéã®æ¹ã ãããããé¡ããããã¾ãã
SSHéµã®éµé·ã確èªããæ¹æ³
æ¬ç¨¿ãèªãã§ãèªåã®SSHéµã¯å¤§ä¸å¤«ãªãã ã£ãï¼ãã¨ä¸å®ã«ãªã£ãæ¹ã®ããã«ãSSHå ¬ééµããéµé·ãç°¡åã«èª¿ã¹ãæ¹æ³ãç´¹ä»ãã¾ããããã¯ãOpenSSHä»å±ã®ssh-keygenã§æ¬¡ã®ããã«ãã¦èª¿ã¹ããã¨ãã§ãã¾ãã
$ ssh-keygen -l -f $HOME/.ssh/id_rsa.pub 2048 1a:a3:de:59:da:d5:9f:b9:a2:09:2b:eb:4c:8d:7b:83 [email protected] (RSA)
1ã«ã©ã ç®ãbité·ãæå¾ã®ã«ã©ã ãéµã®ç¨®é¡ã§ãããªãã·ã§ã³ã®æå®ãééãã¦éµãã¢ãä¸æ¸ãããªããããæ°ãã¤ãã¦ãã ãããã
ã¾ã¨ã
- GitHubã¦ã¼ã¶ã¼ã®SSHéµãåå¾ãã¦å¾åã調ã¹ã¾ãã
- 強度ã«çåã®ããéµãç´7%åå¨ãã¾ãã
- GitHubã«ç»é²ãã¦ããSSHå ¬ééµãå ¨ä¸çã«å ¬éããã¦ãããã¨ã«ã¤ãã¦çåãåãã¾ãã
- èªåã®SSHéµã®éµé·ã調ã¹ãæ¹æ³ãç´¹ä»ãã¾ãã
åå人ã®å¤æã¨ãã¦ã¯ã2048bit RSAéµã§2030å¹´ã¾ã§æ¦ãããããã®ã§å½åããã§ããã¨æã£ã¦ãã¾ããéé²ã«SSHã®éµé·ãé·ãããã¨DHéµäº¤æããã®ä»ã®æå·åããã»ã¹ãè¨ç®éãå¢ãã¦ãçµæã¨ãã¦å¦çãéããªã£ã¦ãã¾ãããããªãã§ãããããä½äºããã¬ã¼ããªããããããã£ã¦ãã¨ã§ã