ãã£ã¨ãã¤ãã«ã誰ããç¡æã§HTTPSã使ããããã«ãªãï¼â¦MozillaãEFFãå ±åããã¸ã§ã¯ããç«ã¡ä¸ã - TechCrunchã ãããã³ã¡æ¬ã§ããã£ãã·ã³ã°ãµã¤ããè¦åããããªããªããã¨åéããã¦ããåãããããããªã®ã§ãã¡ãã£ã¨æ¸ãã¦ããã
ãã®Let's Encryptã ããLetâs Encrypt: Delivering SSL/TLS Everywhereã«èª¬æãæ¸ããã¦ãããããããä¸ã®TechCrunchã®è¨äºã§ã¯Let's Encryptãã©ããããã®ãåãããªãããã®è¨äºã§ã¯ä½ãã§ãã¦ä½ãã§ããªãããæ¸ãã¦ããªããã
TechCrunchã®è¨äºã¯ãªã¬ãè¦ãæç¹(2014/11/20 5:00)ã§ããããã¯ãæ°(792ã¦ã¼ã¶)ãªãã ãã©ãæ¬ä½ã®èª¬æã®ãã¯ãæ°ã¯4ã¦ã¼ã¶ããªã¬ãããã¯ãã¼ã¯ããã®ã§5ã¦ã¼ã¶ã§ãããã¡ãã£ã¨èª¿ã¹ã¦ããã³ã¡ã³ãããã°ããã®ã«ã
ä¸è¨ã®ã»ããè¦ç´ã¨ãã¦åããããããÂ
Let's Encryptã¨ã¯ä½ããä½ã§ãªãã
ã¾ãçµè«ãå ã«æ¸ãã¦ããã
ãã®Let's Encryptããµã¼ã証ææ¸ã®ã°ã¬ã¼ãã§ããã¨DV(Domain Validation)証ææ¸ã®ã¬ãã«ããã£ãã·ã³ã°ãµã¤ãã§ã¯ãªããã¨ãä¿è¨¼ããEV(Extended Validation)証ææ¸ã§ã¯ãªãããä¸è¬çã«ä½¿ç¨ããã¦ããéå¶å ã®èº«å 審æ»ãããOV(Organization Validation)証ææ¸ã§ããªãã
 |
 DV |
 OV |
 EV |
 èªè¨¼ã®ã¬ãã« |
 ä½ã¬ãã« |
 é«ã¬ãã« |
 æé«ã¬ãã« |
 ä¼æ¥ã®å®å¨ç¢ºèª |
 à |
 â |
 â |
ãã®ãããLet's Encryptã¯ãåã«æå·åãããã ãããæåã§OV証ææ¸ãåå¾ããã»ã©ã§ã¯ãªããç¨éã«ä½¿ãç©ã§ããã
ããããããã§ããã£ãã·ã³ã°ãµã¤ããè¦åããããªããªããã¨ããã®ã¯è¨¼ææ¸ã®éã(èªè¨¼ã¬ãã«ãç¨é)ã®éããç¥ããªããç¡è¦ããçºè¨ã§ãããLet's Encryptã«ãã£ã¦ãã£ãã·ã³ã°ãµã¤ãã容æã«httpsãµã¤ãã«ã§ããããã«ãªãããã¢ã¯ã»ã¹ãã人éãå¼ã£æãããã©ããã¯ããã¾ã§ã¨å¤ãããªãããããããä»ã¾ã§Schemeãhttpã®ãµã¤ãã«å¼ã£æãã£ã¦ããããã ãã
Let's Encryptã¨ã¯
Let's Encryptã¯ç±³Electronic Frontier Foundation(EFF)ãMozillaãCisco SystemsãAkamai TechnologiesãIdenTrustããã·ã¬ã³å¤§å¦ã®ç 究è ãåå ããå ¬çæ³äººãInternet Security Research Group(ISRG)ããéå¶ããã
Letâs Encrypt: Delivering SSL/TLS Everywhereã«ã¯ä¸è¨ã®ããã«ã¾ã¨ãããã¦ããã
- Free: Anyone who owns a domain can get a certificate validated for that domain at zero cost.
- Automatic: The entire enrollment process for certificates occurs painlessly during the serverâs native installation or configuration process, while renewal occurs automatically in the background.
- Secure: Letâs Encrypt will serve as a platform for implementing modern security techniques and best practices.
- Transparent: All records of certificate issuance and revocation will be available to anyone who wishes to inspect them.
- Open: The automated issuance and renewal protocol will be an open standard and as much of the software as possible will be open source.
- Cooperative: Much like the underlying Internet protocols themselves, Letâs Encrypt is a joint effort to benefit the entire community, beyond the control of any one organization.
ç°¡åã«æ訳ãã¦ã¿ãã
- ç¡æï¼ãã¡ã¤ã³ãæã¤äººã¯èª°ã§ãã¼ãã³ã¹ãã§ãã®ãã¡ã¤ã³ã®ããã®è¨¼ææ¸ãæå¹ã«ã§ãã¾ãã
- èªåï¼ããã¾ã§ã¯è¨¼ææ¸ã®ç»é²ããã»ã¹å ¨ä½ãé£ããã£ããã©ããããç°¡åã«ã»èªåçã«è¡ããããã«ãã¾ãã
- ã»ãã¥ã¢ï¼ç¾å¨ã®ã»ãã¥ãªãã£æè¡ã¨ãã¹ããã©ã¯ãã£ã¹ã使ã£ã¦ããã®ã§ãã¤ã³ããªã¡ã³ãããããã®ãã©ãããã©ã¼ã ã¨ãã¦ä½¿ãã¾ãã
- ééæ§ï¼è¨¼ææ¸ã®çºè¡ã¨åãæ¶ãã®ã¬ã³ã¼ãã¯ã使ããã人ã¯èª°ã§ãå©ç¨å¯è½ã«ãªãã¾ãã
- ãªã¼ãã³ï¼èªåé å¸ãèªåæ´æ°ãªã©ã¯ãªã¼ãã³ã¹ã¿ã³ãã¼ãã«ãªããå¯è½ãªéããªã¼ãã³ã½ã¼ã¹ã«ãã¾ãã
- å ±åããã¸ã§ã¯ãï¼ããã¯æ ¹æ¬çãªã¤ã³ã¿ã¼ãããã»ãããã³ã«èªä½ã§ãããããã¯ãªã«ã1ã¤ã®ã³ãã¥ããã£ã ãã§ãªããå ¨ã³ãã¥ããã£ã¼ã«å½¹ç«ã¤å ±åããã¸ã§ã¯ãã§ãã
è¨ãæããã¨ãLet's Encryptã¯ãã¡ã¤ã³ã®ææè ã§ããã°èª°ããã¼ãã³ã¹ãã§è¨¼ææ¸ãåå¾ã§ãã証ææ¸ã®çºè¡ãã¤ã³ã¹ãã¼ã«ãæ´æ°ãªã©ã®ããã»ã¹ãèªååãããèªåçºè¡ãæ´æ°ã®ãããã³ã«ã¯ãªã¼ãã³ã¹ã¿ã³ãã¼ãã¨ããã½ããã¦ã§ã¢ãå¯è½ãªéããªã¼ãã³ã½ã¼ã¹ã«ããã¨ãããã¨ã§ããã
ããã£ãã·ã³ã°ãµã¤ããè¦åããããªããªããã¨ããã®ã¯åéã
ããã£ãã·ã³ã°ãµã¤ããè¦åããããªããªããã¨ããã®ã¯ã証ææ¸ã®éã(èªè¨¼ã¬ãã«ãç¨é)ã®éããç¥ããªããç¡è¦ããçºè¨ã§ããã
DV証ææ¸ã®ç½®ãæãç¨é
ããããã«ã¦ã§ã¢ãOSæ©è½ãå©ç¨ãããå ´åã®åæãSSL(https)ã¨ãããã¨ããããSSL(https)ã¨ãããã¨ã¯ãµã¼ã証ææ¸ãå¿ è¦ã§ãããå®ã¯ãããããã¾ã§åé¡ã ã£ãã
ä¾ãã°ãã®ããã°ã§ã¨ã³ããªãå¤ã話ã§ããã¨RD GW(ãªã¢ã¼ããã¹ã¯ããã ã²ã¼ãã¦ã§ã¤æ©è½)ã§ãããÂ
åºæ¬çã«ã¯ãªã¢ã¼ããã¹ã¯ãããã®æ¥ç¶ã社å¤ããè¡ãããã²ã¼ãã¦ã§ã¤æ©è½ã§ãããç¹å®ã®äººéã使ããã®ãWebãµã¼ãã®SSLå/ãããã³ã«ã®httpsåããããå ´åãSSLæå·åã¨ãµã¼ãèªè¨¼ãã»ããã«ãªã£ã¦ããã®ã§ãµã¼ã証ææ¸ãå¿ è¦ã«ãªã£ã¦ããããç¨éã«ãã£ã¦ã¯SSLæå·åããã§ããã°ããã¨ã¯å¥ã®ä»çµã¿ã§ã»ãã¥ãªãã£ãæ ä¿ã§ãã¦ããå ´åãããããã®ä¸ä¾ãRD GWã§ããã
Â
å¥ã®ç¨éã®è©±ãï¼ã¤ããã
ã¾ãä¸ã¤ç®ãå®å ¨ã«ã¤ã³ãã©ãããã«éãã¦ä½¿ç¨ãããµã¼ãã®å ´åãå ¨é¨ã¤ã³ãã©ãããå ã§å®çµããã®ã§ãOV(Organization Validation)証ææ¸ãåå¾ããã¾ã§ããªãã
ãã¨ããä¸ã¤ããã¹ãç¨ã«ã¤ã³ã¿ã¼ãããã«ææ(ãã¹ãæéã®ã¿)å ¬éãããµã¼ãã®å ´åããã¹ãã®å 容ã使ç¨ããä¼æ¥ã»çµç¹ããå ãã¨ãã¯OV証ææ¸ã使ç¨ãããããããã¹ãæ¥ç¨ã®åè¿«ã追å ãã¹ãã®é½åã§æ¥é½ãµã¼ãã追å ããå ´åãªã©ãä»ããã«ãã¹ããµã¼ããåããããã®ã«ããµã¼ã証ææ¸(OV証ææ¸)å ¥æå¾ ã¡ã¨ãããã¨ã¯æ³å®ã§ãããã¨ãããããããçµé¨ãããã
Â
ä¸è¨ï¼ãã¿ã¼ã³ããããã®å ´åãæåã®OV証ææ¸ãåå¾ããã¾ã§ããªãã¨å¤æãããå ´åãDV(Domain Validation)証ææ¸ãå¿ è¦ãªã®ã ãããã«ãªã¬ãªã¬è¨¼ææ¸(èªå·±è¨¼ææ¸)ã使ããã¨ã«ãªãããªã¬ãªã¬è¨¼ææ¸ãä½ããè¨å®ããã®ã¯ãããªãã«é¢åã§ãããããªã¬ãªã¬è¨¼ææ¸ãªã®ã§æéãåæã«é·ãè¨å®ããããã ããããã§ãææã§ããããã¤ãã¯æ´æ°ããªããã°ãªããªããã¯ã©ã¤ã¢ã³ãå´ãã¯ã¼ãã³ã°ãåºã¦ç ©ããããã証ææ¸ã®ã¤ã³ã¹ãã¼ã«ãå¿ è¦ã§é¢åã§ãããLet's Encryptã¯ã¾ããã®ãããªç¨éã§ä½¿ç¨ããããã®ã§ããã
OV証ææ¸ã®ç½®ãæãç¨éÂ
ãå§ãããªããä»æ§ã®è©³ç´°ãåãããªãã®ã§ãªãã¨ãè¨ããªãããç°¡åã«åå¾ã§ããã¨ããäºã¯ãéå¶å ã®èº«å 審æ»ãããOV(Organization Validation)証ææ¸ã§ã¯ãªãããããããããªã®ã§ãå§ãããªãã®ã ããå¤å使ãããéå¶å ã®èº«å 審æ»ã£ã¦ããã¨é¢åãªãã§ãããOV証ææ¸åå¾ããæã«çµé¨ãããã©ãã¢ã¬ãããã ãã§ãç°¡åã«åå¾ãã«ãªããªãã
ä¼æ¥ã®ãµã¤ããªã©ã¯é常httpã§ããããç°¡åãªå ¥åãã©ã¼ã ãªã©ã¯OV証ææ¸ã§æå·åããã¦ãã(ããã¦ããã¹ã)ãOV証ææ¸ã¯æåã ãæéãæ大5å¹´ãããï¼ã§çããhttpã¨httpsãæ··å¨ãããã¼ã¸ãä½ãã¨ãã©ã¦ã¶ãã¯ã¼ãã³ã°ãåºãå ´åããããèªç¤¾(èªçµç¹)ãµã¤ãå ¨é¨ãhttpsã«ããã®ã§ããã°ããã®Let's Encryptã使ãä¼æ¥ã»çµç¹ããããããããªããLet's Encryptã¯OV証ææ¸ã®ã¬ãã«ã§ã¯ãªãã¯ããªã®ã§å ¨é¨ç½®ãæãã¡ããã®ã¯ãããªããå ¥åãã©ã¼ã ãç½®ããµã¼ãã«ã¯ãã¡ãã¨OV証ææ¸ã使ã£ã¦ã»ããã
ä¸ã«ã(ããã¦ããã¹ã)ãã¨æ¸ããããæãã«ã¹ã¿ãã¯ã¨ã³ã¸ãã¢è¬åº§ã¯ç³è¾¼ãã©ã¼ã ç»é¢ãhttpã ã£ããã§ããããããªããã«ã¹ã¿ãã¯ã¨ã³ã¸ãã¢ããµã¤ãã¼ãã¼ã¬ã¼ãæ¦æ³ï½ï½ãã¨æã£ãè¨æ¶ããÂ
ããã¾ã§ãã©ãæ¸ãã¦ãèªããªã人ãããã¨æã(ä¸è¨åç §)ã®ã§ããä¸åº¦æ¸ãã¦ãããä»æ§ã®è©³ç´°å¾ ã¡ã ãã©ãå¤åOV証ææ¸ã®ä»£ããã¨ãã¦ã¯ãå§ãã§ããªãã
EV証ææ¸ã®ç½®ãæãç¨é
ããããªããEV(Extended Validation)証ææ¸ã¯ãã£ãã·ã³ã°ãé²ãããã®(é«ä¾¡ãª)証ææ¸ã§ããã¡ãã¨åèããã°ãããªãã«å¹æãããããããªãã«ã¨ããã®ã¯äººã®ç®ã§é²ãããã£ãã·ã³ã°ãªãã¨ãããã¨ã§ãã£ã¦ãCSRFãçªããã¦ã®MITM,MITBãªã©ã¯EV証ææ¸ãå®ãç¯å²ã§ã¯ãªãã
Let's EncryptãEV証ææ¸ãå¿ è¦ãªã¬ãã«ã®ãµã¤ãã«ä½¿ããã¤ã¯ããªãã¯ã
EV(Extended Validation)証ææ¸ã«ã¤ãã¦ã¯ä»¥åä¸è¨ã¨ã³ããªã§ãã£ãã(ãã©ããããã«)æ¸ããããã©ããããã«ãç·è²ã確èªã§ãããä¸èº«ãè¦ãå¿ è¦ã¯ç¡ãâ¦â¦ãããã©è¦ã¦ã¿ããã¨æ¯åæ¸ããã®ã«ãã³ã¡ã«ãä¸èº«ãè¦ãå¿ è¦ã¯ç¡ãã¯ããã£ã¦æ¸ããã¦ãèªã¾ãã«ã³ã¡ã³ããããªãã¨æã£ãããã²ã§ã EV証ææ¸ã説æããããã«éãã¦è¦ããã ãã§ãEV証ææ¸ã«æããã¾ããã»EV証ææ¸ã®åå¨ãæããã«ãªããªãéããä¸èº«ãè¦ãå¿ è¦ãç¡ãã®ã¯ã»ãã¥ãªãã£ãå°éãããªããªã¬ã ã£ã¦ããã£ã¦ãã¤ã¼ã®ãã·ãããã
ã¤ã¾ãã¤ã³ã¿ã¼ããããã³ãã³ã°ãªã©ããã£ãã·ã³ã°ãããã¨é大ãªè¢«å®³ãæ³å®ããããµã¤ãã®å ´åãæä¾è å´ã¯EV証ææ¸ã使ãã¹ãã§ãããå©ç¨è å´ãEV証ææ¸ã¨OV証ææ¸ãä¸ç®ã§è¦åããããæ©è½ãæã¤ãã©ã¦ã¶ã®å©ç¨ãå¿ é ã§ããã
ã¨ããããã§ãEV証ææ¸ãå¿ è¦ãªã¬ãã«ã®ãµã¤ãã«Let's Encryptã®å©ç¨ã¯ããå¾ãªããLet's Encryptã«ãã£ã¦ãã£ãã·ã³ã°ãå¢ããã¨ããã®ã¯èª¤èªã§ãããå¼ã£æãã奴ã¯Let's Encryptã®åå¨ã«é¢ä¿ç¡ãå¼ã£æããã
ã¾ããTwitterã§ããEV証ææ¸ä½¿ã£ã¦ãããå ¥åãã¦ãããå 容ã«ãã£ã¦ã¯ããéã絡ã¾ãªãã¦ãEV証ææ¸ã«ç§»è¡ãã¹ãã¨æã£ã¦ããã
æ°è£ çã人éã®è¨¼æ (è§å·æ庫)
- ä½è : 森æèª ä¸
- åºç社/ã¡ã¼ã«ã¼: è§å·æ¸åº
- çºå£²æ¥: 2004/05/15
- ã¡ãã£ã¢: æ庫
- è³¼å ¥: 1人 ã¯ãªãã¯: 47å
- ãã®ååãå«ãããã° (66件) ãè¦ã
- åºç社/ã¡ã¼ã«ã¼: ãã¤ãªãã¢LDC
- çºå£²æ¥: 2000/09/22
- ã¡ãã£ã¢: DVD
- ã¯ãªãã¯: 18å
- ãã®ååãå«ãããã° (37件) ãè¦ã
Â