ã翻訳ãWoSign 㨠StartCom ã«ããä»å¾ã®è¨¼ææ¸ã¯æå¦ãã¾ã
ãã®è¨äºã¯ã2016 å¹´ 10 æ 24 æ¥ä»ã§ Mozilla Security Blog ã«æ稿ããã Distrusting New WoSign and StartCom Certificatesï¼çè : kwilsonï¼ã®ç¿»è¨³ã§ãããã®ç¿»è¨³ã¯å ¬å¼ãªãã®ã§ã¯ããã¾ããã詳ããã¯ãã¡ããã覧ãã ããã
WoSign ã¨ããèªè¨¼å±ï¼CAï¼ãæè¡é¢ã¨éç¨é¢ã«ããã¦å¤ãã®å¤±æ ãç¯ãã¦ãããã¨ãããæ·±å»ãªãã¨ã«ã¯ã2016 å¹´ 1 æ 1 æ¥ããã£ã¦ SHA-1 SSL 証ææ¸ãçºè¡ã§ããªããªãæéãåé¿ãããããçºè¡æ¥ãå¤ãæ¥æã«æ¹ãããã¦è¨¼ææ¸ã®çºè¡ãè¡ã£ã¦ãããã¨ã Mozilla ã¯ç¢ºèªãã¾ãããããã«ãå¥ã® CA ã§ãã StartCom ã®ææ権ã WoSign ãå®å ¨ã«ä¿æãã¦ããã«ãé¢ããããMozilla ã®è¦æ±ããããªã·ã¼ã«åãã¦ãã®äºå®ãå ¬éãã¦ããªãã£ããã¨ãå¤æãã¾ãããWoSign 㨠StartCom ã®æ å½è ã¯ããããã®ççµã証æããã«è¶³ãååãªãã¼ã¿ãéã¾ãã¾ã§ãä»åã®äºä»¶ã«ã¤ãã¦å¦èªãç¶ãã姿å¢ã§ãã両社ã®æ å½è ãè¡ã£ãè©æ¬ºè¡çºã®ç¨åº¦ãéã¿ãçµæãç¾å¨ç»é²ããã¦ãã WoSign 㨠StartCom ã®ã«ã¼ã証ææ¸ã«ãã§ã¤ã³ãç¹ãã証ææ¸ãä»å¾çºè¡ãããå ´åããã®è¨¼ææ¸ã«å¯¾ããä¿¡é ¼ãç ´æ£ãããã¨ã¨ãã¾ããã
Mozilla ãè¬ãã¦ããå ·ä½çãªæ½çã¯ä»¥ä¸ã®éãã§ãã
- notBefore ã®æ¥ä»ã 2016 å¹´ 10 æ 21 æ¥ããå¾ã§ããããã¤ä»¥ä¸ã«ç¤ºãå½è©²ã«ã¼ã証ææ¸ã«ãã§ã¤ã³ãç¹ãã証ææ¸ã¸ã®ä¿¡é ¼ãç ´æ£ãã¾ãããã®æªç½®ã®è¿åãç®çã¨ããæ¥ä»ã®æ¹ãããï¼ã©ã®ãããªå½¢ã§ããï¼å¤æããå ´åã¯ãå½è©²ã«ã¼ã証ææ¸ã Mozilla ã¯å³åº§ã«ããã¤æ°¸ä¹
çã«å¤±å¹ããããã¨ã¨ãã¾ãã
- ãã®å¤æ´ã¯ Firefox 51 ã®ãªãªã¼ã¹äºå® ã«åããã¦åæ ããã¾ãã
- ä»åã®æªç½®ãå½è©²ã«ã¼ãã®ã¯ãã¹è¨¼ææ¸ã«ãé©ç¨ããããããå½è©²ã«ã¼ã証ææ¸ãèå¥ãã Subject Distinguished Names ã«ã¯ä»¥ä¸ã®å¤ãç¨ãã¾ãã
- CN=CA æ²éæ ¹è¯ä¹¦, OU=null, O=WoSign CA Limited, C=CN
- CN=Certification Authority of WoSign, OU=null, O=WoSign CA Limited, C=CN
- CN=Certification Authority of WoSign G2, OU=null, O=WoSign CA Limited, C=CN
- CN=CA WoSign ECC Root, OU=null, O=WoSign CA Limited, C=CN
- CN=StartCom Certification Authority, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL
- CN=StartCom Certification Authority G2, OU=null, O=StartCom Ltd., C=IL
- æ¥ä»ã®æ¹ããããã SHA-1 証ææ¸ã§ããããã¤å½è©²ã«ã¼ã証ææ¸ã«ãã§ã¤ã³ãç¹ããæ¢ç¥ã®è¨¼ææ¸ã OneCRLï¼åèï¼æ¥æ¬èªè¨³ï¼ã«è¿½å ãã¾ãã
- Ernst & Young Hong Kong ã«ããç£æ»è¨é²ãä»å¾åçãã¾ããã
- å°æ¥ã®ããæç¹ã«ããã¦ãå½è©²ã«ã¼ã証ææ¸ã Mozilla ã®ã«ã¼ã証ææ¸ä¸è¦§ ããåé¤ãã¾ããä»åã® CA ã«ããæ°ããã«ã¼ã証ææ¸ã®ç»é²ãèªããããå ´åã«ã¯ã証ææ¸ã®åå¾è ãæ°ããã«ã¼ã証ææ¸ã¸ç§»è¡ããã CA ã®è¡åè¨ç»ã確èªããä¸ãæ§ã«ã¼ã証ææ¸ã®åé¤æ¥æã調æ´ãã¾ãããã®æ¡ä»¶ãæºããããªãã£ãå ´åã«ã¯ã2017 å¹´ 3 æ以éã®ããæç¹ãåé¤æ¥æã¨ãã¾ãã
- 追å ã¾ãã¯ä»£æ¿ã¨ãªãæ½çãè¬ãã権å©ã Mozilla ã¯æãã¾ãã
ã©ã¡ããã® CA ãã 2016 å¹´ 10 æ 21 æ¥ä»¥éã«è¨¼ææ¸ãåå¾ãã¦ããå ´åãç°ãªã Subject Distinguished Names ã®æ°ããã«ã¼ã証ææ¸ãçºè¡å CA ããæä¾ãããªãéããã¾ãã¯ãã§ã¤ã³ãç¹ãã£ã¦ããå½è©²ã«ã¼ã証ææ¸ãæåã§ã¤ã³ãã¼ãããªãéããåå¾ãã証ææ¸ã¯ Firefox 51 ãªã©ã® Mozilla 製åã§å©ç¨ã§ããªããªãã¾ããweb ãµã¤ãã®å©ç¨è ã«ã¤ãã¦ããæ°ããã«ã¼ã証ææ¸ã Mozilla ã®ã«ã¼ã証ææ¸ä¸è¦§ã«ããã©ã«ãã¨ãã¦ç»é²ãããã¾ã§ãèªåã§æ°ããã«ã¼ã証ææ¸ãã¤ã³ãã¼ãããå¿ è¦ãããã¾ãã
WoSign ã«ã¤ãã¦ã¯ Bug #1311824 ã§ãStartCom ã«ã¤ãã¦ã¯ Bug #1311832 ã«ããã¦ï¼æ¢åã®ãã®ãç½®ãæããï¼æ°ããã«ã¼ã証ææ¸ã®åç»é²ç³è«ãè¡ããã¨ãã§ãã¾ãã
ä»åã®æªç½®ã¯ Mozilla ã®ããªã·ã¼ã¨ä¸è²«æ§ãæã¤ãã®ã§ãããã¾ã Mozilla's CA Certificate Policy ã CA/Browser Forum's BaselineãMozilla ã®æ å½è ã«ããç´æ¥ã®åãåããã«å¯¾ããä»ã® CA ãåããããªè©æ¬ºè¡çºãåããå ´åã«ãé©ç¨ããããã®ã¨èãã¦ãã¾ãã
Mozilla Security Team