GPKIããå®ããã«ç ã(ã¿ã¤ãã«ã§ç ½ãã¹ã¿ã¤ã«)
ã¯ããã«
ã®è¨äºãæ¸ããyumetodoã§ãããã£ã±ãGPKIããããã£ã¦ã¾ãã(ãã
çµè«
èªåèªè¨¼å±ã«ããGPKIã¯å®ãããªç ãã«ã¤ãããã§ãã
ã»ã³ã ãã©ã¹ãã·ã¹ãã ãºããããã¨ã¯ä»»ããã
2æã®GPKIé¨åã¯çµå±ä½ã ã£ãã
ä¸ã®è¨äºãæ¸ããã®ã2æã®ãã¨ã§ãã
2018å¹´3æ1æ¥æ¨ææ¥ 1æ15å06ç§ UTC+9 Elic Mill
So, to be clear, you would only revoke misissued certificates if required to do so by Mozilla -- not because they represent control failures, or in order to demonstrate to other root programs your CA's responsiveness and the seriousness with which you take control failures.
2018å¹´3æ1æ¥æ¨ææ¥ 1æ26å58ç§ UTC+9 Wayne Thayer
My comment was intended to point out that you are violating BR section 4.9.1.1(9) by not revoking these certificates. My comments were not intended to imply that revoking these certificates would change Mozilla's decision to deny this inclusion request.
ãã¸ã¼ãMozillaã«è¨ãããããç´ããã ãCAã¨ãã¦ã®è²¬ä»»ãæãããããããªãã¦ããã¨ããBRéåãã¦ããããç´ãã¦ãããã¨ã¨ãæ¥ãããã¨ãã£ãã®ã§ãã£ã¦ãå½è©²è¨¼ææ¸ã失å¹ããããåãå ¥ããã¨ãã話ãããªãããªã©ã¨ãæ¥æ¬æ¿åºã®GPKI Root証ææ¸ãæ¨ã£ç«¯å¾®å¡µã«ç²ç ãããã®ã§ããã
ã¤ã¾ããGPKIã¯æ¥æ¬æ¿åºãããã¯ã«ä»ãã¦ãããã®ã®ãä¸çããè¦æ¾ãããã»ã©ã® éãªéç¨ã§ä¿¡ç¨ã«å¤ããªããã ã®ãªã¬ãªã¬è¨¼ææ¸ ã«æãä¸ãã£ãããã§ãã
ããã«GPKIã®å ¬ééµãå®å ¨ã«å ¥æããæ¹æ³ãå®å ±ãè¦ããããªãã¨ããããã¾ã¤ã(Webãã¼ã¸ã§ãé ã£ã¦ãããå®å ¨ã§ã¯ãªã)
ã仲éã§ããLGPKIã¯ã©ããªã£ãã
LGPKIã¨ãããã®ããã£ãããã§ãããããã¤ã¯ãèªåã®èªè¨¼æ©é¢ãæã¤ã®ã諦ãã¦ã»ã³ã ãã©ã¹ãã·ã¹ãã ãºã«å¤æ³¨ããããã«ãªãã¾ããã
[PDF注æ]ç·åè¡æ¿ãããã¯ã¼ã¯ No. 185 ï¼ ç¬¬å次LGPKI移è¡ã®èæ¯ã¨ ãã®æ¦è¦
å次LGPKIã¯ãå¹³æ28年度ã«çå®ãã第å次ç·åè¡æ¿ãããã¯ã¼ã¯æ´åè¨ç»æ¸ã«ããã¦ãå¤é¨èªè¨¼å±ãæ´»ç¨ãããã¨ã¨ãã¦ããããå°æ¹å ¬å ±å£ä½çµç¹èªè¨¼åºç¤ã®æ§ç¯åã³éç¨æ¥åãã«ä¿ã調éã®çµæãèªè¨¼å±éå¶äºæ¥è ãã»ã³ã ãã©ã¹ãã·ã¹ãã ãºï¼æ ªï¼ã¨ãããã¨ã«æ±ºå®ãã¾ããã
ããã¾ã§ãèªåã§éç¨ãã¦ããç¾è¡LGPKIã¨ã¯ç°ãªããå¤é¨èªè¨¼å±ã®ã½ãªã¥ã¼ã·ã§ã³ãæ´»ç¨ãã¦éç¨çµè²»ãä½æ¸ãã¤ã¤ããã¤ãã»ãã¥ãªãã£ã¯ç¾ç¶ã®æ°´æºãç¶æãããã¨ãå®ç¾ããã¨ã¨ãã«ãå©ä¾¿æ§ã®åä¸ã両ç«ããããã第å次 LGPKIã®æ§ç¯ãéå§ãã¾ããã
GPKIã¯å¤§å¤ãªãã¨ã«ãªã£ã¦ããã©ãä¸æ¹LGPKIã¯ã»ã³ã ãããã¨ã«ãªã£ã¦ãèªæ²»ä½ã«ã¯ã¤ã³ã¿ã¼ãããå´ã§ã使ãããããªã£ã¦æå ±ã / âç·åè¡æ¿ãããã¯ã¼ã¯ No. 185 ï¼ ç¬¬å次LGPKI移è¡ã®èæ¯ã¨ ãã®æ¦è¦ ã第å次Lâ¦â https://t.co/36TNZprspT
— ä¸å å²å¤ªé/Tetsu. Uehara (@tetsutalow) March 20, 2018
ãã£ã¡ã¯çã£å½ãªè·¯ç·ã«ãªã£ããªã
GPKIãªè¨¼ææ¸ãå©ç¨ãã¦ããWebãµã¤ãã¯ã©ããªã£ã
ä¾ãã°CRYPTRECã¯
https://t.co/MuohWCRnAH ã«httpsã§ç¹ããã¨ããã¨å¤±æããã®å«ãããâ¦â¦ããªããSSL/TLSæå·è¨å®ã¬ã¤ãã©ã¤ã³ãã®ç¬¬äºçãèªã¿ã«ãã£ã¦æ°ä»ãã¾ãã orz
— Kazuo Moriwaka (@moriwaka) 2018å¹´6æ1æ¥
æè¿æ´æ°ããGPKIã®è¨¼ææ¸ãè¦ã㨠https://t.co/J8DYsMrdi6 LGPKIã¨åæ§ã®æ£å¸¸åï¼ããã®ã§ã¯ãªããã¨æ·¡ãæå¾ ãæã£ã¦è¦ã¦ãã¾ã(ããããªãã島岡ããï¼ã https://t.co/jlwCng5hKf ãåæ¥é±expireãªã®ã§åæ§ã«æ£å¸¸åãã¦ããã ããããã®ã§ãã
— Shigeki Ohtsu (@jovi0608) 2018å¹´6æ5æ¥
CRYPTREC https://t.co/jlwCngmT8P ããã£ã¨GPKIããã»ã³ã ããã«å¤ããã¾ããã https://t.co/MfMyimQLJO ã§ãSSLLabsã®ã¹ã³ã¢ã¯BãSSL/TLSæå·è¨å®ã¬ã¤ãã©ã¤ã³ãå®ãã¾ããããã pic.twitter.com/WTN11kvoGk
— Shigeki Ohtsu (@jovi0608) 2018å¹´6æ14æ¥
GPKIã¯ã©ããªãã¹ãã
WebTrust for BRã«æºæ ãã¦ãªãéç¨ãã¦ãGPKIãããLet's Encryptã®æ¹ãCAã¨ãã¦ãã·ãªæ°ãããããããããLet's Encrypt使ããªãå ´åã§ãEVãªè¨¼ææ¸ä½¿ããªãæ°ããããã ããããããããµã¤ãã
— Makoto Kato ï¸ï¸ (@makoto_kato) 2018å¹´6æ5æ¥
æç§çå¤å±ã®ã¹ãã¼ãåºã®åºå ±ãã¼ã¸ https://t.co/qmRFNAsEYY ã§ã Let's Encrypt ã®DV証ææ¸ãå©ç¨ãã¦ãããã§ãã⦠ä»ã® https://t.co/lcSQE0omPH ãã¡ã¤ã³ã§ã¡ãã»ããhttpããæä¾ãã¦ãªããµã¤ããããã£ã½ã©ã¾ããã¨ãhttps://t.co/vFqWfZMJBT
— Shigeki Ohtsu (@jovi0608) 2018å¹´6æ5æ¥
ããããããGPKIã¯é¨ç½²ãã¨ãªãã£ããã¨ã«ã»ã»ã»ã»ãããã»ã»ã»ã§ãããããã
— himorin@9/8-9ãã£ã¤ããã§ã¹2018 (@himorin) 2018å¹´6æ5æ¥
GPKIã使ãçç±ããªããçµæã¯åããhttps://t.co/HyXLtRigZs
— Hiromitsu Takagi (@HiromitsuTakagi) 2018å¹´6æ6æ¥
ç§ã¯ç´ 人ã ãã©ãGPKIã¯å½ããã©ããã¦æ°éã«è¨¼æãã¦ããããªãããªããªããã ï¼ãã¨ããã¡ã³ãã®ã¿ã§ç«ã¡ä¸ãããã®ãªã®ã§ï¼ãããã©ãããã©ã¦ã¶ã¡ã¼ã«ã¼ã«é ä¸ããªãã¨ãããªãï¼ãSECOMã§ããªãã§ããæ°éãã証ææ¸è²·ã£ãã»ããè¯ãããã§ãããã
— å¼è·å£« å峯èå¹³ï¼ã«ã³ããã«æ²æ» å§å¡ä¼ï¼ (@kyoshimine) 2018å¹´6æ6æ¥
ãããã«ããããªãããããªãã§ãããâ¦â¦ã https://t.co/v4cvfXBUNI
ãããèªåèªè¨¼å±ã«ããGPKIã¯ã©ãèãã¦ãéç¨ä¸å¯è½ã§ãå®ããã«ç ãä¸æã
ã«ããã°ã5æ20æ¥ã«LGPIKåæ§ãã»ã³ã ãã©ã¹ãã·ã¹ãã ãºã«ç½²åãã¦ããã£ãGPKIã®éµãåºã¦ããã®ã§ãããããæ¹åã«èµãåããã ãããã»ã»ã»ã¦è§£éã§ãããã§ãããï¼
IIJ TechnicalNIGHT vol.5
IIJ TechnicalNIGHT vol.5
— picoGaloisï¼ é»åã¯ã©ã (@DenshiClub) 2018å¹´6æ28æ¥
ã§ã¯ããããªãGPKIãLGPKIã®è©±ããã¦ããã
ãã¤ãã¿ã¼ã«ã¯æ¸ããªãã§ã¨ããã³ã¡ã³ããã¤ãã¦ããã
ããIIJ TechnicalNIGHT vol.5ï¼ãªã«ããã
âã»ãã·ã§ã³1ãæè¿æ¹è¨ãããSSL/TLSæå·è¨å®ã¬ã¤ãã©ã¤ã³ãç´è§£ã
ï¼è¬æ¼è ï¼IIJ ã»ãã¥ãªãã£æ¬é¨ ã»ãã¥ãªãã£æ å ±çµ±æ¬å®¤ é è³ ç¥æ²»
ï¼ç´¹ä»æï¼
å æãCRYPTRECã«ããSSL/TLSæå·è¨å®ã¬ã¤ãã©ã¤ã³ã®æ¹å®ã3å¹´ã¶ãã«è¡ãªããã¾ããã
æ¬ã»ãã·ã§ã³ã§ã¯ããã®ã¬ã¤ãã©ã¤ã³ãèªã¿è§£ãããã«å¿ è¦ã¨ãªãç¥èãæè¡èæ¯ãæãã解説ãã¾ãã
ãããã
SSL/TLSæå·è¨å®ã¬ã¤ãã©ã¤ã³ã¨ããã®ã¯
CRYPTREC ï½ CRYPTRECå ±åæ¸
ããé£ã¹ã
[PDF注æ]SSL/TLSæå·è¨å®ã¬ã¤ãã©ã¤ã³ - cryptrec-gl-3001-2.0.pdf
ã®ãã¨ã ããã
èãã«è¡ãããã£ããªã»ã»ã»ã