- 1. ã¯ããã«
- 2. ãµã¼ã証ææ¸ã®å¤±å¹ã¨ã¯
- 3. 失å¹æ å ±ç¢ºèªã®éè¦æ§
- 4.ãµã¼ã証ææ¸ã®å¤±å¹æ å ±ã確èªããä»çµã¿
- 5. 失å¹æ å ±ã確èªããåä»çµã¿ã®ã¡ãªããã¨ãã¡ãªãã
- 6. 失å¹æ å ±ç¢ºèªã®æ¨å¥¨å®è£
- 7. 失å¹æ å ±ç¢ºèªçµæã«å¯¾ãããµã¼ãééä¿¡å¯å¦ã®å¤æ
- 8. ã¾ã¨ã
- åèæç®
1. ã¯ããã«
NTTãã³ã¢ 第ä¸ãããã¯ããã¶ã¤ã³é¨ã®æ©çªã§ãã ãã¦ã¼ã¶ä½é¨ä¾¡å¤åä¸ãã®ãããããµã¼ãã¹ã®å質åä¸ããé害ã®æ©æ復æ§ããé害äºä¾ãåªè¯äºä¾ã®ãã¦ãã¦åãã«åãçµãã§ãã¾ãã æ¬è¨äºã§ã¯ããã¦ã¼ã¶ä½é¨ä¾¡å¤åä¸ãã®ããã®ãµã¼ã証ææ¸ã®å¤±å¹æ å ±ç¢ºèªã®å®è£ ã«ã¤ãã¦ããä¼ãã§ããã°ã¨æãã¾ãã
å¼ç¤¾ã管çãã¦ãããµã¼ãããä»ç¤¾ã管çãã¦ãããµã¼ãã«å¯¾ãæå·åéä¿¡ã確ç«ããéãæå·åéä¿¡ãéå§ããåã«ãä»ç¤¾ãµã¼ãã®ãµã¼ã証ææ¸ã®å¤±å¹æ å ±ã確èªãã¦ãã¾ãã ããã·ã¹ãã ã§ã¯ãOCSPã®ã¿ã§å¤±å¹æ å ±ã確èªãã¦ãã¾ããã ããã¦ããã®å¤±å¹æ å ±ç¢ºèªã«ããã¦ãå¼ç¤¾ã¨å¥ç´é¢ä¿ã«ãªãä¸é証ææ¸ã®OCSPã¬ã¹ãã³ãããã¦ã³ãããã¨ã«ãããæ£å¸¸ã«å¤±å¹æ å ±ã確èªã§ãã¾ããã§ããã ãã®çµæãå¥ç´é¢ä¿ã«ããéä¿¡å ãµã¼ãã¨éä¿¡ã確ç«ã§ããé害ãçºçãã¾ããã ãã®æãå¥ç´é¢ä¿ã«ããéä¿¡å ãµã¼ãã¯æ£å¸¸ã«ç¨¼åãã¦ããã«ãããããããå¥ç´é¢ä¿ã«ãªãOCSPã¬ã¹ãã³ãã®ãã¦ã³ã«ããé害ãçºçãããã¨ãããã¨ãéç¨èª²é¡ã¨èªèãã¾ããã
失å¹æ å ±ç¢ºèªã®å®è£ ã«ãã£ã¦ã¯ããã®ãããªé害ãé²ããå¯è½æ§ãããã¾ãã ããã§ãéç¨èª²é¡ã®è§£æ±ºã¨åããããªé害ã®åçºãé²æ¢ããããã«ããµã¼ãéã«ããããµã¼ã証ææ¸ã®å¤±å¹æ å ±ç¢ºèªã®é©åãªå®è£ ã«ã¤ãã¦æ´çãã¾ããã
2. ãµã¼ã証ææ¸ã®å¤±å¹ã¨ã¯
ãµã¼ã証ææ¸ã®å¤±å¹ã¨ã¯ãèªè¨¼å±ããµã¼ã証ææ¸ãç¡å¹åãããã¨ãæå³ãã¾ãã èªè¨¼å±ã¯ã以ä¸ã®ãããªã±ã¼ã¹ã§ãµã¼ã証ææ¸ãç¡å¹åãã¾ãã - ãµã¼ã証ææ¸ã®ææè ã失å¹ãè¦æ±ãã - ãµã¼ã証ææ¸ã®ç§å¯éµãæ¼æ´©ãã - ãµã¼ã証ææ¸ã®è¨è¼ã¨äºå®ãç°ãªã£ã¦ãã
æå¹æéå ã§ããµã¼ã証ææ¸ãç¡å¹ã«ãããã¨ããã1ããã失å¹æ å ±ãé©æ確èªããå¿ è¦ãããã¾ãã
3. 失å¹æ å ±ç¢ºèªã®éè¦æ§
ãµã¼ã証ææ¸ã失å¹ããã¨ã以ä¸ã®ãããªã»ãã¥ãªãã£ãªã¹ã¯ãçºçããå¯è½æ§ãããã¾ãã
- ã¦ã¼ã¶ã®ä¿¡é ¼æ§ä½ä¸
ãµã¼ã証ææ¸ã失å¹ãã¦ããã¨ããã©ã¦ã¶ãã»ãã¥ãªãã£ãã¼ã«ãè¦åã表示ãããããã¦ã¼ã¶ã®ä¿¡é ¼ã失ãã¾ãã - ãã¼ã¿ã®çè´ãæ¹ãã
éä¿¡å 容ãæå·åããéµãç ´ããã¦ããå ´åããã®èå¼±æ§ãæªç¨ããéä¿¡å 容ãçè´ãããããæ¹ããããããããå¯è½æ§ãããã¾ãã - 社ä¼çä¿¡ç¨ã®å¤±å¢
PCI DSSï¼ã¯ã¬ã¸ããã«ã¼ãæ¥çã®ã»ãã¥ãªãã£åºæºï¼ã¯ããµã¼ã証ææ¸ã®æå¹æ§ãç¶æãããã¨ãæ±ãã¦ãã¾ãã ãããå®ããªãã¨ã社ä¼çä¿¡ç¨ã®å¤±å¢ã決æ¸åå¼ã®æ¸å°ãªã©ã®æªå½±é¿ãçºçããå¯è½æ§ãããã¾ãã - æ³å¾ä¸ã®éå
åå¼å ã¨ã®å¥ç´ã«ããã¦ãã»ãã¥ãªãã£å¯¾çã®ä¸ç°ã¨ãã¦æå¹ãªãµã¼ã証ææ¸ã®ä½¿ç¨ã義åä»ãããã¨ãããã¾ãã 失å¹ãããµã¼ã証ææ¸ã使ç¨ããã¨ãå¥ç´éåã¨ãªããæ³çãªè²¬ä»»ãåãããå¯è½æ§ãããã¾ãã
ãããã®çç±ããããµã¼ã証ææ¸ã®å¤±å¹æ å ±ç¢ºèªã¯é常ã«éè¦ã§ãã
4.ãµã¼ã証ææ¸ã®å¤±å¹æ å ±ã確èªããä»çµã¿
ãµã¼ã証ææ¸ã®å¤±å¹æ å ±ç¢ºèªã«ç¨ãããã主ãªä»çµã¿ã¯ã以ä¸ã®3ã¤ã§ãã
4.1. CRLï¼Certificate Revocation Listï¼
CRLã¯ã失å¹ãããµã¼ã証ææ¸ã®ä¸è¦§ãè¨è¼ãããªã¹ãã§ãã 失å¹ãããã¹ã¦ã®ãµã¼ã証ææ¸ãè¨è¼ããã¦ãããå®æçã«èªè¨¼å±ãæ´æ°ãã¾ãã éä¿¡å ãµã¼ãã¯ãéä¿¡å ãµã¼ãããåãåã£ããµã¼ã証ææ¸ãCRLã¨ç §åãããã¨ã§ããã®ãµã¼ã証ææ¸ã失å¹ãã¦ãããã©ããã確èªãã¾ãã
CRLã«ãã失å¹æ å ±ç¢ºèª
- èªè¨¼å±ã«ããCRLã®æ´æ°
èªè¨¼å±ã¯ã失å¹ãããµã¼ã証ææ¸ã®ã·ãªã¢ã«çªå·ãªã©ãå«ãCRLãå®æçã«æ´æ°ãã¾ãã - éä¿¡å
ãµã¼ãã«ããCRLã®åå¾
éä¿¡å ãµã¼ãã¯ãéä¿¡å ãµã¼ãããåãåã£ããµã¼ã証ææ¸ã«è¨è¼ããã¦ããCRLé å¸ãã¤ã³ãï¼URLï¼ãåç §ããCRLããã¦ã³ãã¼ããã¾ãã - éä¿¡å ãµã¼ãã«ããæ¤è¨¼ éä¿¡å ãµã¼ãã¯ããã¦ã³ãã¼ãããCRLã®ä¸ã«ãæ¤è¨¼ãã¦ãããµã¼ã証ææ¸ã¨åãã·ãªã¢ã«çªå·ã®ãµã¼ã証ææ¸ãè¨è¼ããã¦ãããæ¤è¨¼ãã¾ãã è¨è¼ããã¦ããå ´åããã®ãµã¼ã証ææ¸ã失å¹ãã¦ããã¨å¤æãã¾ãã
ã¯ã©ã¤ã¢ã³ãããéä¿¡å ãµã¼ãã«å¦çãè¦æ±ãã¦ãã¯ã©ã¤ã¢ã³ãã«çµæãè¿å´ãããã¾ã§ã®ã¤ã¡ã¼ã¸ã¯å³ã®éãã§ãã
4.2. OCSPï¼Online Certificate Status Protocolï¼
OCSPã¯ãç¹å®ã®ãµã¼ã証ææ¸ãæå¹ãã©ããããªã¢ã«ã¿ã¤ã ã«éä¿¡å ãµã¼ããåãåããããããã³ã«ã§ãã CRLã®ããã«ã失å¹ãããµã¼ã証ææ¸ã®ä¸è¦§ããã¦ã³ãã¼ããã¦ç¢ºèªããã®ã§ã¯ãªããå¿ è¦ãªæã«å¿ è¦ãªãµã¼ã証ææ¸ã ããOCSPã¬ã¹ãã³ãã¨å¼ã°ããèªè¨¼å±ã®ãµã¼ãã«éä¿¡å ãµã¼ããåãåããã¦ããµã¼ã証ææ¸ã失å¹ãã¦ããã確èªãã¾ãã
OCSPã«ãã失å¹æ å ±ç¢ºèª
- éä¿¡å
ãµã¼ãããOCSPã¬ã¹ãã³ãã«åãåãã
éä¿¡å ãµã¼ãã¯ãéä¿¡å ãµã¼ãããåãåã£ããµã¼ã証ææ¸ã®ã·ãªã¢ã«çªå·ãOCSPã¬ã¹ãã³ãã«éä¿¡ãã¾ãã - OCSPã¬ã¹ãã³ãã«ããå¿ç
OCSPã¬ã¹ãã³ãã¯ãåãåãããåãããµã¼ã証ææ¸ã®å¤±å¹æ å ±ã確èªãããã®çµæãéä¿¡å ãµã¼ãã«è¿ãã¾ãã - éä¿¡å
ãµã¼ãã«ããæ¤è¨¼
éä¿¡å ãµã¼ãã¯ãOCSPã¬ã¹ãã³ãã®å¿çãæ¤è¨¼ãããµã¼ã証ææ¸ã®æå¹æ§ã確èªãã¾ãã
ã¯ã©ã¤ã¢ã³ãããéä¿¡å ãµã¼ãã«å¦çãè¦æ±ãã¦ãã¯ã©ã¤ã¢ã³ãã«çµæãè¿å´ãããã¾ã§ã®ã¤ã¡ã¼ã¸ã¯å³ã®éãã§ãã
4.3. OCSP Stapling
OCSP Staplingã¯ããµã¼ã証ææ¸ã®å¤±å¹æ å ±ãOCSPã¬ã¹ãã³ãã«éä¿¡å ãµã¼ããåãåããã¾ãã OCSPã¬ã¹ãã³ãã®å¿çãéä¿¡å ãµã¼ãããã£ãã·ã¥ã¨ãã¦ä¿æãããµã¼ã証ææ¸ã¨ã¨ãã«éä¿¡å ãµã¼ãã«éä»ãã¾ãã éä¿¡å ãµã¼ãã¯ãéä¿¡å ãµã¼ãã¨ã®TLS/SSLãã³ãã·ã§ã¤ã¯ã®éç¨ã§ãµã¼ã証ææ¸ã失å¹ãã¦ããã確èªãã¾ãã
OCSP Staplingã«ãã失å¹æ å ±ç¢ºèª
- éä¿¡å
ãµã¼ãããOCSPã¬ã¹ãã³ãã«åãåãã
éä¿¡å ãµã¼ãã¯ãéä¿¡å ãµã¼ãããæ¥ç¶è¦æ±ãåããã¨ãOCSPã¬ã¹ãã³ãã«åãåããã¾ãã - OCSPã¬ã¹ãã³ãã«ããå¿ç
OCSPã¬ã¹ãã³ãã¯ãåãåãããåãããµã¼ã証ææ¸ã®å¤±å¹æ å ±ã確èªãããã®çµæãéä¿¡å ãµã¼ãã«è¿ãã¾ãã - OCSPã¬ã¹ãã³ãã®å¿çãã£ãã·ã¥
éä¿¡å ãµã¼ãã¯ãOCSPã¬ã¹ãã³ãã®å¿çããã£ãã·ã¥ãã¾ãã - éä¿¡å
ãµã¼ãã«ããå¿ç
éä¿¡å ãµã¼ãã¯ããµã¼ã証ææ¸ã¨ãã£ãã·ã¥ããOCSPã¬ã¹ãã³ãã®å¿çãä¸ç·ã«éä¿¡å ãµã¼ãã«éä¿¡ãã¾ãã - éä¿¡å
ãµã¼ãã«ããæ¤è¨¼
éä¿¡å ãµã¼ãã¯ãéä¿¡å ãµã¼ãããåãåã£ãOCSPå¿çãæ¤è¨¼ãããµã¼ã証ææ¸ã®æå¹æ§ã確èªãã¾ãã
ã¯ã©ã¤ã¢ã³ãããéä¿¡å ãµã¼ãã«å¦çãè¦æ±ãã¦ãã¯ã©ã¤ã¢ã³ãã«çµæãè¿å´ãããã¾ã§ã®ã¤ã¡ã¼ã¸ã¯å³ã®éãã§ãã
5. 失å¹æ å ±ã確èªããåä»çµã¿ã®ã¡ãªããã¨ãã¡ãªãã
CRLãOCSPãOCSP Staplingã®ä»çµã¿ãéä¿¡å ãµã¼ããå®è£ ããå ´åããããã以ä¸ã®ãããªã¡ãªããã¨ãã¡ãªãããããã¾ãã
5.1. CRLã®ã¡ãªãã
- å®å®æ§
CRLããã¦ã³ãã¼ãæ¸ã¿ã§ããã°ãCRLé å¸ãã¤ã³ãã¨æ¥ç¶ã§ããªãã¦ã失å¹æ å ±ã確èªã§ãã¾ãã
5.2. CRLã®ãã¡ãªãã
- è² è·
CRLããã¦ã³ãã¼ãããæããããã¯ã¼ã¯ãã©ãã£ãã¯ãå¢å ãã¾ãã å¤ãã®ãµã¼ã証ææ¸ãçºè¡ããã¦ããå ´åãCRLã®ãµã¤ãºã大ãããªããããã«æ¯ä¾ãã¦ãããã¯ã¼ã¯ã®è² è·ãå¢å ãã¾ãã ã¾ããCRLã®ãã¦ã³ãã¼ãã解æããã£ãã·ã¥ã«ãããéä¿¡å ãµã¼ãã®å¦çè² è·ãå¢å ãã¾ãã ç¹ã«ãä½ã¹ããã¯ã®ãµã¼ãã§ã¯ãåä½ãé ããªãå¯è½æ§ãããã¾ãã - ãªã¢ã«ã¿ã¤ã æ§
失å¹ãããµã¼ã証ææ¸ã®æ å ±ãåæ ãããã¾ã§ã«æéããããã¾ãã ãã®éã«ã失å¹ãããµã¼ã証ææ¸ãå©ç¨ãããå¯è½æ§ãããã¾ãã
5.3. OCSPã®ã¡ãªãã
- å¹çæ§
å¿ è¦ãªãµã¼ã証ææ¸ã®æ å ±ã®ã¿ãåãåããããããå¹çãã失å¹æ å ±ã確èªã§ãã¾ãã - ãªã¢ã«ã¿ã¤ã æ§
é½åº¦ããµã¼ã証ææ¸ã®å¤±å¹æ å ±ã確èªãããããææ°ã®å¤±å¹æ å ±ã確èªã§ãã¾ãã
5.4. OCSPã®ãã¡ãªãã
- OCSPã¬ã¹ãã³ãè² è·
éä¿¡å ãµã¼ãããåãåãããéä¸ããã¨ãOCSPã¬ã¹ãã³ãã«è² è·ããããå¿çãé ããå¯è½æ§ãããã¾ãã - åä¸é害ç¹
OCSPã¬ã¹ãã³ãã¨æ¥ç¶ã§ããªãå ´åããµã¼ã証ææ¸ã®æå¹æ§ã確èªã§ããªããªãã¾ãã - ã»ãã¥ãªãã£åé¡
OCSPã¬ã¹ãã³ãã®åãåããå 容ãããéä¿¡å ãµã¼ãã®IPã¢ãã¬ã¹ãªã©ãæ¼æ´©ããå¯è½æ§ãããã¾ãã - ãã©ã¤ãã·ã¼åé¡
OCSPã¬ã¹ãã³ãã¯ãéä¿¡å ãµã¼ãããã®åãåããããã°ã¨ãã¦ä¿åãããã¨ãããã¾ãã ãã®ãã°ã«éä¿¡å ãµã¼ãã®æ å ±ã¨ãµã¼ã証ææ¸ã®èå¥æ å ±ãçµã¿åããã¦ä¿åãã¦ããå ´åãèªè¨¼å±ã«ã¢ã¯ã»ã¹å±¥æ´ãç¥ãããå¯è½æ§ãããã¾ãã
5.5. OCSP Staplingã®ã¡ãªãã
- ããã©ã¼ãã³ã¹
- éä¿¡å
ãµã¼ãå´ã®å¦çé度åä¸
OCSP Staplingã§ã¯ãéä¿¡å ãµã¼ããOCSPã¬ã¹ãã³ãã«åãåããã¦åå¾ããæ å ±ãããµã¼ã証ææ¸ã¨ä¸ç·ã«éä¿¡å ãµã¼ãã«æä¾ãã¾ãã ããã«ãããéä¿¡å ãµã¼ãã¯OCSPã¬ã¹ãã³ãã«åãåãããå¿ è¦ããªããªããå¦çé度ãåä¸ãã¾ãã - ãããã¯ã¼ã¯ãã©ãã£ãã¯ã®åæ¸
éä¿¡å ãµã¼ããOCSPã¬ã¹ãã³ãã«ç´æ¥åãåãããåæ°ãæ¸ãããããããã¯ã¼ã¯ãã©ãã£ãã¯ãåæ¸ããã¾ãã
- éä¿¡å
ãµã¼ãå´ã®å¦çé度åä¸
- ã»ãã¥ãªãã£
éä¿¡å ãµã¼ããOCSPã¬ã¹ãã³ãã«åãåããããããéä¿¡å ãµã¼ãã®æ å ±æ¼æ´©ã®å¯è½æ§ãä½æ¸ãã»ãã¥ãªãã£ãå¼·åã§ãã¾ãã
5.6. OCSP Staplingã®ãã¡ãªãã
- ãã£ãã·ã¥ãããæ
å ±ã®ä¿¡é ¼æ§
失å¹æ å ±ç¢ºèªçµæã®ãã£ãã·ã¥ãé©åã«éä¿¡å ãµã¼ãã管çãã¦ããªããã°ãå¤ã失å¹æ å ±ç¢ºèªçµæã使ç¨ãããå¯è½æ§ãããã¾ãã
6. 失å¹æ å ±ç¢ºèªã®æ¨å¥¨å®è£
ä¸è¨ãããããã©ã¼ãã³ã¹ã¨ã»ãã¥ãªãã£ã¨ããç¹ã§ã失å¹æ å ±ç¢ºèªã¯OCSP Staplingãå©ç¨ããå®è£ ãæ¨å¥¨ãã¾ãã ç¹ã«ã1ç§å½ããã®ãã©ã³ã¶ã¯ã·ã§ã³æ°ãæ°ç¾ã«ä¸ããããªå¤§è¦æ¨¡ãªã·ã¹ãã ããé«è² è·ãäºæ³ãããã·ã¹ãã ã«ããã¦ã¯ãã¡ãªãããããå¤ã享åã§ããã¨èãããã¾ãã ããã¦ãã·ã¹ãã ãåãæ±ãéç¨å¡ã¨ä¿å®å¡ã ãã§ãªããOCSPã¬ã¹ãã³ãã管çãã¦ãããã³ããã¦ã¼ã¶ãªã©ããã¹ã¦ã®ã·ã¹ãã é¢ä¿è ãããã®æ©æµãåãããã¨ãã§ããã§ãããã
6.1. OCSP Staplingå®è£ æã®ãã¤ã³ã
OCSP Staplingã¯ãããã©ã¼ãã³ã¹ã¨ã»ãã¥ãªãã£ãåä¸ãããæå¹ãªæ段ã§ãããå®è£ ã«éãã¦ã¯æ³¨æç¹ãããã¾ãã
- éä¿¡å
ãµã¼ãã®OCSP Stapling対å¿
ãã¹ã¦ã®ãµã¼ããOCSP Staplingã«å¯¾å¿ãã¦ããããã§ã¯ããã¾ããã OCSP Staplingãå©ç¨ããå ´åãéä¿¡å ãµã¼ããOCSP Staplingã«å¯¾å¿ãã¦ããããã確èªãã ããã OCSP Staplingãæªå¯¾å¿ã ã£ãå ´åãOCSPã¨CRLãçµã¿åããã失å¹æ å ±ç¢ºèªãè¡ã£ã¦ãã ããã - åä½è©¦é¨
éä¿¡å ãµã¼ãããæ³å®éã失å¹æ å ±ç¢ºèªçµæãè¿ã£ã¦ãããåä½ã確èªãã¦ãã ããã ã¾ããçµæãè¿ã£ã¦ããªãã£ãæã®ãã¨ãæ³å®ããå®è£ ãã¦ãã ããã ãã¨ãã°ã確èªçµæãéä¿¡å ãµã¼ããä¸å®æéãã£ãã·ã¥ãããã®æ å ±ããã¨ã«å¦çãç¶ç¶ãããã¨ã¯æå¹ãªå¯¾çæ段ã¨ãªãã¾ãã ãã£ãã·ã¥ããå ´åã«ã¯ãæ å ±ãå¤ããªããªãããã«é©åãªæéãè¨å®ãããã注æãã¦ãã ããã
7. 失å¹æ å ±ç¢ºèªçµæã«å¯¾ãããµã¼ãééä¿¡å¯å¦ã®å¤æ
OCSPã¨OCSP Staplingã«ãã失å¹æ å ±ç¢ºèªçµæã«å¿ããéä¿¡å¯å¦å¤æã«ã¤ãã¦ãæ´çãã¾ãã ãµã¼ã証ææ¸ã®å¤±å¹æ å ±ç¢ºèªçµæã¨ãã¦ã以ä¸ã®ãããããéä¿¡å ãµã¼ããåãåãã¾ãã
- æå¹(good)
ãµã¼ã証ææ¸ã失å¹ãã¦ããªãç¶æ - 失å¹(revoke)
ãµã¼ã証ææ¸ã失å¹ãã¦ããç¶æ - ä¸æ(unknown)
ãµã¼ã証ææ¸ã失å¹ãã¦ãããã失å¹ãã¦ããªããå¤æã§ããªãç¶æ
失å¹æ å ±ç¢ºèªçµæããæå¹ãã®å ´åã«ã¯ããµã¼ãéã®éä¿¡ã許å¯ãã¾ãã ã失å¹ãã®å ´åã«ã¯ããµã¼ãéã®éä¿¡ãæå¦ãã¾ãã 失å¹æ å ±ç¢ºèªçµæããä¸æãã ã£ãå ´åã«ã¯ã以ä¸ã®å¯¾å¿ãæ¤è¨ãã¾ãã
- CRLã§å¤±å¹æ å ±ã確èªãã
- éä¿¡å ãµã¼ãã¨ã®é¢ä¿ã¨éä¿¡è¦ä»¶ã«ãã£ã¦éä¿¡å¯å¦ãå¤æãã
CRLã®å¤±å¹æ å ±ç¢ºèªããã¼ã«ã¤ãã¦ã¯ãä¸è¿°ã®éãã§ãã éä¿¡å ãµã¼ãã¨ã®é¢ä¿æ§ã¨éä¿¡è¦ä»¶ã«ããéä¿¡å¯å¦å¤æã«ã¤ãã¦ã¯ã以ä¸ã®ããã«èãã¾ãã
- éä¿¡å
ãµã¼ãã¯ã次ã®æ¡ä»¶ã®ããããã«å½ã¦ã¯ã¾ãç¹å®ã®ãµã¼ãã
- IPã¢ãã¬ã¹ãåºå®ã§ãã
- å°ç¨ç·ãVPNçµç±ã§éä¿¡ãã
- éä¿¡å ãµã¼ãã¾ã§ã®éä¿¡çµè·¯ãä¿¡ç¨ã§ãã
- éä¿¡è¦ä»¶ã¯ãæ©å¯æ§ä½ãããã¯å¯ç¨æ§éè¦ã
ãããã®çµã¿åããã«ãã£ã¦ã失å¹æ å ±ç¢ºèªçµæãåãåã£ãå¾ã®éä¿¡å¯å¦ã以ä¸ã®ããã«å¤æãã¾ãã
8. ã¾ã¨ã
è¿å¹´ããµã¼ã証ææ¸ã®æå¹æéãå¾ã ã«çããªã£ã¦ãã¦ãã¾ãã
- 2015å¹´ï¼æå¹æéã5å¹´ãã3å¹´ã«ç縮
- 2018å¹´ï¼æå¹æéã3å¹´ãã2å¹´ã«ç縮
- 2020å¹´ï¼æå¹æéã2å¹´ãã1å¹´1ã¶æã«ç縮
Google社ã¯ãWebãã©ã¦ã¶ãã³ãã¼ã¨èªè¨¼å±ãåå ããä¼è°ä½ãCA/Browser Forumãã§æå¹æéãæ大90æ¥ã«ç縮ããæ¹éã¨çºè¡¨ãã¦ãã¾ãã2 ã¾ããApple社ã¯ã2027å¹´4æã¾ã§ã«æå¹æéã45æ¥ã¾ã§ã«ç縮ãããã¨ãæå±ãã¦ãã¾ãã3
ããã¦ããµã¼ã証ææ¸ã®çºè¡æ°ãä¸çæå¤ã®èªè¨¼å±ã§ããLet's Encryptã¯ãOCSPã®ãµã¼ãã¹ãçµäºããæ¹éã§ããã¨çºè¡¨ãã¾ããã4 OCSPã®ãµã¼ãã¹ãæã¡åã£ãå ´åãOCSPã¨OCSP Staplingã使ããªããããLet's Encryptã®ãµã¼ã証ææ¸ã®å¤±å¹ç¢ºèªã¯ãCRLãå©ç¨ãããã¨ã«ãªãã¾ãã ããã¯ããµã¼ã証ææ¸ã®æå¹æéãçãå ´åãOCSPãããCRLã®æ¹ã失å¹æ å ±ç¢ºèªã«æå¹ã§ããã¨ãLet's Encryptãèãã¦ããããã§ãã
ä¸æ¹ã§ãã¨ã³ã¿ã¼ãã©ã¤ãºç¨éã¨ãã¦ãOCSP Staplingã¯ãã·ã¹ãã ã®ã»ãã¥ãªãã£ã¨ããã©ã¼ãã³ã¹ãåä¸ãããæå¹ãªæ段ã«ãªãã¾ãã å¸å ´ã®ååãã·ã¹ãã æ§æãèæ ®ããå®è£ ã®ãã¤ã³ããè¸ã¾ããªãããOCSP Staplingãå®è£ ãã¦ããã ããã°ã¨æãã¾ãã
æ¬è¨äºã§ã¯ããµã¼ã証ææ¸ã®å¤±å¹æ å ±ç¢ºèªã®éè¦æ§ã¨æ¨å¥¨å®è£ ã«ã¤ãã¦è§£èª¬ãã¾ããã æå¾ã¾ã§èªãã§ããã ãããããã¨ããããã¾ããã
åèæç®
- ãã¸ãµã¼ãã®ãµã¼ãã¼è¨¼ææ¸ã«ãOãããoãã¨ãã誤è¨ã5æ12æ¥ã«å¼·å¶å¤±å¹ã¸â©
- Googleã®SSLãµã¼ã証ææ¸ãæå¹æé90æ¥åã«ã¤ãã¦â©
- SSLãµã¼ã証ææ¸ã90æ¥ãã45æ¥ã¸ç縮ããèµ·æ¡ã¨ã証ææ¸èªååã®å½¹å²â©
- Intent to End OCSP Serviceâ©