ãã®èšäºã§ã¯ãæ¢åã®DNSæ§é ã®æ¬ ç¹ã.comããã³.orgãã¡ã€ã³ãäŸãšããŠäœ¿çšããŠDNSSECãå®è£ ããå®å šãªããã»ã¹ãDNSSECã§çœ²åãããæå¹ãªèªå·±çœ²å SSL蚌ææžãäœæããæé ã«ã€ããŠèª¬æããŸãã
äžè¯DNSãšã¯
çŸåšã®åœ¢åŒã®DNSã·ã¹ãã ã¯ãæ å ±ã»ãã¥ãªãã£ãç¹ã«èããããŠããªãã£ã20幎以äžåã«éçºãããŸããã ããã€ãã®åºæ¬çãªè匱æ§ããããŸãã
DNSãµãŒããŒã®å¿çã®ä¿¡é Œæ§ã¯ã決ããŠãã§ãã¯ãããŸããã ããã«ããããã¡ã€ã³åãã¢ãã¬ã¹æå®ãããŠãŒã¶ãŒãä»»æã®IPã¢ãã¬ã¹ã«éä¿¡ããŠããµãŒããŒã®å¿çã眮ãæããããšãã§ããŸãã å®éã«ã¯ã ãã®ãããªæ»æã¯æ¬¡ã®ããã«ãªããŸã ã
ã¯ã©ã€ã¢ã³ãã®ãªãŸã«ããŒãšããŠæ©èœãããããã€ããŒã®ãã£ãã·ã¥DNSãµãŒããŒãè匱ã§ãïŒ ã«ãã³ã¹ããŒæ»æ ã
çŸåšãDNSã¬ã³ãŒãã«å ¬éããŒãä¿åããããã®æè¡ããããŸããããšãã°ãé»åã¡ãŒã«ã®DKIM眲å ã SSHFPã¬ã³ãŒãã®SSHããŒãªã©ã§ãã ãããã®æè¡ã¯ãã¹ãŠãDNSåœé ã«å¯Ÿããä¿è·ãå¿ èŠãšããŸãã
DNSSECçè«
DNSSECã¯ãæå·å眲åã䜿çšããŠDNSæ å ±ã®ä¿¡é Œæ§ãäžæã«æ€èšŒã§ããæè¡ã§ãã
äžè¬çã«DNSSECã«ã€ããŠã¯ã dxdt.ru / 2009/03/04/2163ã§èªãããšãã§ããŸãã
詳现ã¯ãã¡ãïŒ habrahabr.ru/blogs/sysadm/120620
ãããŠã Verisign.comã§
ç¶è¡ããåã«ãäžèšã®ãªã³ã¯ã泚ææ·±ãèªãããšã匷ããå§ãããŸãããŸãŒã³ã«çœ²åããæé ãäžèŠæ··ä¹±ããŠããããã«èŠããããã§ãã
å¯èœãªéãã·ã³ãã«ã«ãããã¯æ¬¡ã®ããã«ãªããŸãããã¹ãŠã®ç¬¬1ã¬ãã«ãã¡ã€ã³ã«é¢ããæ å ±ãå«ãã«ãŒããŸãŒã³ãããããããŸãã æ¯èŒçèšãã°ãããã¯ããã€ãã®è¡ã®ã»ãããæã€ããã¹ããã¡ã€ã«ã§ãããã»ãšãã©å€æŽãããŸããã å ¬é/ç§å¯ããŒã®ãã¢ãäœæããããã®ãã¡ã€ã«ã®åè¡ã眲åãããŸãïŒPGP / GPGã®ãã¯ãªã¢ãµã€ã³ãã¿ã€ãã«ãããããã¹ãã§å ¬ç¶ãšçœ²åããããã«é»åã¡ãŒã«ã§äœ¿çšããããBGPIN PGP SIGNATUREãã§å§ãŸããŸãïŒã
ãã®ãã¢ã®å ¬éããŒãååŸããã®ã§ããã®ãªã¹ãã®åãšã³ããªã®ä¿¡é Œæ§ã確èªã§ããŸãã ããšãã°ãripn.netãµãŒããŒããruããŸãŒã³ãå®éã«æ åœããŠããããšã確èªããŸãã
dig -t any + dnssec @ k.root-servers.net enã
å¿çã§ã¯ãããã·ã¥çœ²åãå«ãRRSIGã¬ã³ãŒãã確èªã§ããŸãã
ããããããã¯ååã§ã¯ãããŸãããããŠã³ã¹ããªãŒã ãµãŒããŒã解決ã«åå ããããããã®çãã確èªããå¿ èŠããããŸãã 次ã«ããããã¬ãã«ãã¡ã€ã³ã®ææè ïŒããšãã°ããcomãïŒãåãããŒãã¢ãäœæãããŸãŒã³å ã®ãã¹ãŠã®ã¬ã³ãŒãã«çœ²åããŠãããå ¬éããŒã®ãã£ã¹ããã«ãŒããŸãŒã³ã«è¿œå ããŸãã ãã®çµæãã«ãŒããŸãŒã³ã®å ¬éããŒãä¿¡é ŒããŠããŸãŒã³ããŒãcomãã®ä¿¡é Œæ§ã確èªã§ããŸããããã«å¿ããŠããããä¿¡é ŒããŸãã
dig -t any + dnssec @ k.root-servers.net comã
å¿çã§ã¯ãDSã¬ã³ãŒãã«ã¯ããŸãŒã³ãcomãã眲åãããŠããããŒã®ãã£ã¹ããå«ãŸããŠããŸãã
ãŸãŒã³å ã®åå€æŽåŸã«çœ²åãæ°ãã«è¡ãããããšãç解ããããšãéèŠã§ãã ãã ããã«ãŒããŸãŒã³ã¯ãŸãŒã³ãcomãã®å ¬ééµã®ã¿ã«çœ²åããããããŸãŒã³ãcomããå€æŽããããã³ã«ã«ãŒããŸãŒã³ã®ãšã³ããªãåãã£ãã·ã¥ããå¿ èŠã¯ãããŸããã
ããã§ãcomããã¡ã€ã³ãæ åœãããµãŒããŒããã®å¿çãèªèšŒã§ããŸãã
dig + dnssec -t any @ a.gtld-servers.net verisign.comã
ãã¡ã€ã³ã¬ã³ãŒããverisign.comã§ããããšãããããŸãã 眲åãããŠããŸããããã®æ®µéã§ã¯ãverisign.comãã¡ã€ã³ãæ åœããNSãµãŒããŒã®ã¢ãã¬ã¹ã®ä¿¡é Œæ§ã確ç«ããããšããã§ããŸããã IPã¢ãã¬ã¹ã解決ããã«ã¯ããããããå¿çãååŸããå¿ èŠããããŸãããã®ããããããã®NSãµãŒããŒã®ææè ã¯ç¬èªã®ããŒãã¢ãæã¡ãããã䜿çšããŠãŸãŒã³ã«çœ²åããDSã¬ã³ãŒãã«å ¬éããŒã¹ãããã·ã§ãããå ¥ããŸãã
verisign.comã®Aã¬ã³ãŒãããªã¯ãšã¹ãããŸãã
dig + dnssec -ta verisign.com @ a2.nstld.com
ãã®çµæãAã¬ã³ãŒãverisign.comã«å€192.5.6.31ãå«ãŸããŠãããšããäºå®ãæ€èšŒããããã«ã次ã®ä¿¡é Œãã§ãŒã³ãæ§ç¯ãããŸãã
ã«ãŒããŸãŒã³ã®å ¬éã㌠"ã"ãäºåã«ç¥ã£ãŠããŸãã ãããŠåœŒãä¿¡é ŒããŠããŸãã ã«ãŒããŸãŒã³ã«ã¯ããcomãå ã®ãã¹ãŠã®ãšã³ããªãæå®ããDSã¬ã³ãŒãããããŸãããŸãŒã³ã¯ãæå®ãããããŒã§çœ²åãããã¬ã³ãŒãèªäœã¯ãããããã«ãŒããŸãŒã³ããŒã§çœ²åãããŸãã ãã®ãšã³ããªã®ä¿¡é Œæ§ã確èªããåŸããã®ããŒã§çœ²åããããcomããŸãŒã³ã®ãã¹ãŠã®ãšã³ããªãä¿¡é ŒããŸãã comãZoneãæ åœãããµãŒããŒã«ã¯ãcomãZoneã®ããŒã§çœ²åãããå ¬éããŒverisign.comãå«ãDSã¬ã³ãŒããå«ãŸããŠãããverisign.comãæ åœããNSãµãŒããŒã®å¿çã§çœ²åã®ä¿¡é Œæ§ãæ€èšŒã§ããŸãã
æŠç¥çã«ã¯ã次ã®ããã«ãªããŸãã
äžèšã®èª¬æã¯éåžžã«åå§çã§ã°ãããŠããŸãã ãæã§ãäœæ¥ããåçã説æããããšãç®çãšããŠæžãããŠããŸãã ãããããããã¯ãŸã£ããç解ãåçŽåããããããããã«æ··ä¹±ãããã ãã§ãã
DNSSECå®è£ ãã©ã¯ãã£ã¹
泚æïŒ ãã®åœä»€ã¯æ代é ãã§ãã NSEC3ã䜿çšããã«ãŸãŒã³ã«çœ²åãããšããŸãŒã³ã®ãã¹ãŠã®DNSã¬ã³ãŒããæ€åºã§ããŸãã
å®éã®æ瀺www.digitalocean.com/community/tutorials/how-to-setup-dnssec-on-an-authoritative-bind-dns-server--2
çŸåšã眲åãããŠããã®ã¯ãç¹ã«.netã.comã.orgãªã©ã®äžéšã®ãããã¬ãã«ãã¡ã€ã³ãŸãŒã³ã®ã¿ã§ãã
.ruãŸãŒã³ã¯ãŸã 眲åãããŠããŸããã.uaãŸãŒã³ã¯ãã¹ãã¢ãŒãã§çœ²åãããŠããŸãã.suãŸãŒã³ã¯æ£åŒã«çœ²åãããŠããŸããããããŸã§ã®ãšãããDSã¬ã³ãŒãã®è¿œå ããµããŒãããã¬ãžã¹ãã©ã¯ãããŸããã
ICANN Webãµã€ãã®å®å šãªãªã¹ããåç §ããŠãã ããã
ãŸãŒã³ã«çœ²åããã«ã¯ããã®æ©èœããã¡ã€ã³ã¬ãžã¹ãã©ãŒã§ãµããŒããããŠããå¿ èŠããããŸãã çŸæç¹ã§ã¯ãDNSSECããµããŒãããŠããåœå ã®ã¬ãžã¹ãã©ã«ã€ããŠã¯ç¥ããŸããã DNSããµããŒããã.ruãã¡ã€ã³ã®å§ä»»ãä¿é²ããR01ã¬ãžã¹ãã©ãšdnssec.ru Webãµã€ãã¯ã.ruãŸãŒã³ã眲åãããŠããªãããã銬鹿ããŠããŸãããã®å ŽåãR01ãµãŒããŒã¯ä¿¡é Œãã§ãŒã³ãæ§ç¯ããããã®åºçºç¹ã«ãªããŸãã
ãµããŒããããã®ã®ãã¡ãæ倧ã®ãã®ãåºå¥ã§ããŸãã
- Godaddy.com
- Dyn.com
- 101domain.com
- Gkg.net
UPDïŒçŸåšãnic.ruã¯DNSSEC www.nic.ru/news/2012/dnssec.html ããµããŒãããŠããŸãã
éšåçãªãªã¹ãã¯ããã«ãããŸã ã
ã¬ãžã¹ãã©ã«å ããŠãNSSSEC察å¿ã®NSãµãŒããŒãå¿ èŠã§ãã äžéšã®ã¬ãžã¹ãã©ã¯ããã®ãããªãµãŒãã¹ãæäŸããŠããŸãã Godaddyã§æãå®ããªãã·ã§ã³ã¯ããã¬ãã¢ã DNS $ 35 /幎ãšåŒã°ããŸãã dyn.comã§æãé«äŸ¡ãªã®ã¯ãDynECT LiteãšåŒã°ããæé¡30ãã«ã§ãã ãã®èšäºã§ã¯ãBIND 9.7.3ã«åºã¥ããŠç¬èªã®ãã¹ã¿ãŒDNSãµãŒããŒãã»ããã¢ããããäŸã瀺ããŸãã
ããã«ãå®å šã«æ§æãããç¬èªã®DNSã«å§ä»»ããããã¡ã€ã³ãšãå®æãããŸãŒã³ãã¡ã€ã«ãããããšãåæãšããŠããŸãã
named.confã§DNSSECãµããŒããæå¹ã«ããã«ã¯ããªãã·ã§ã³ã»ã¯ã·ã§ã³ã«è¿œå ããŸãã
ãªãã·ã§ã³{ ... dnssec-enable yes; ... };
ããŒçæããã³ãŸãŒã³çœ²åããŒã«ã¯ãææ°ã®BINDããã±ãŒãžã«å«ãŸããŠããŸãã
ãã®æ®µéã§ã¯ãèªè ã¯ãã§ã«ZSKïŒZone Sign KeyïŒãšKSKïŒKey Sign KeyïŒãäœã§ããããç¥ã£ãŠãããšæ³å®ãããŸãã
以äžã®ãã¹ãŠã®æäœã¯ãåå¥ã«äœæããããã©ã«ããŒã§å®è¡ããå¿ èŠããããŸãã
ZSKããŒçæïŒ
dnssec-keygen -a RSASHA1 -b 1024 -n ZONE my-domain.com
KSKããŒçæïŒ
dnssec-keygen -a RSASHA1 -b 2048 -f KSK -n ZONE my-domain.com
my-domain.comã¯ãããŒãçæããããã¡ã€ã³ã§ãã ãããã®ã³ãã³ãã®çµæã2ã€ã®ããŒãã¢ãäœæãããŸãã
次ã«ããŸãŒã³ãã¡ã€ã«ãçŸåšã®ãã©ã«ããŒã«ã³ããŒããŠçœ²åããå¿ èŠããããŸãã
dnssec-signzone -S -N INCREMENT my-domain.com
my-domain.comã¯ãŸãŒã³ããã¹ããã¡ã€ã«ã§ãã ããŒãšãŸãŒã³ãã¡ã€ã«ãšåããã©ã«ããŒã«ã³ãã³ããå®è¡ããããšãéèŠã§ãã ãã¹ãªãã®ãã¡ã€ã«åã
ãã®çµæã2ã€ã®ãã¡ã€ã«ãäœæãããŸãã
my-domain.com.signed-ãŸãŒã³çœ²åãã¡ã€ã«
dsset - my - domain.com -2ã€ã®DSã¬ã³ãŒããå«ããã¡ã€ã«
ãœãŒã¹ãŸãŒã³ãã¡ã€ã«ã¯å€æŽãããŸããã 次ã«ãBINDæ§æã§ããã¡ã€ã«ã眲åæžã¿ãã¡ã€ã«ã«çœ®ãæããå¿ èŠããããŸãã
ãŸãŒã³ãmy-domain.comã{ ã¿ã€ããã¹ã¿ãŒ; ãã¡ã€ã«ãmy-domain.com.signedã; allow-query {any; }; allow-transfer {....; }; };
ãŸãŒã³ãã¡ã€ã«ã®è©³çŽ°ãªäŸã¯ã nox.suã§è¡šç€ºã§ããŸãã
DNSã®åŸ©å åãé«ããã«ã¯ãã»ã«ã³ããªãµãŒããŒããå§ãããŸãã DNSSEC察å¿ã®ã¹ã¬ãŒããæäŸããç¡æã®ãµãŒãã¹ãããã€ããããŸãã http://www.frankb.us/dns/ã®ãªã¹ãã®äžéšã次ã«ç€ºããŸã ã rollernet.usã䜿çšãããããã¢ãã¬ã¹208.79.240.3ããã³208.79.241.3ããã®è»¢éãèš±å¯ããŸãã ã»ã«ã³ããªãµãŒããŒã䜿çšããå Žåã眲åããåã«ããããã«é¢ããã¬ã³ãŒãããŸãŒã³ãã¡ã€ã«ã«ååšããå¿ èŠããããŸãã 眲åæžã¿ãŸãŒã³ããã¹ã¿ãŒãµãŒããŒã«é 眮ãããåŸã転éãã¢ã¯ãã£ãã«ããããšããå§ãããŸãã
ããã«ã眲åæžã¿ãŸãŒã³ã¯æš©åšäž»çŸ©NSãµãŒããŒã§æ¢ã«ãã¹ããããŠãããå€éšããã¢ã¯ã»ã¹å¯èœã§ãããšæ³å®ãããŠããŸãã
dig + dnssec -t any @ super.vip.my.dns.com my-domain.com
ããŒã ã¯çœ²åæžã¿ãŸãŒã³ãè¿åŽããå¿ èŠããããŸãã
ãã®æ®µéã§ãã»ã«ã³ããªãµãŒããŒãã¢ã¯ãã£ãã«ããAXFRãä»ããŠãŸãŒã³ãåæã§ããŸãã
次ã«ããã¡ã€ã³ã¬ãžã¹ãã©ãŒããã«ã§DSã¬ã³ãŒããè¿œå ããå¿ èŠããããŸãã ãããã¯dnssec-signzoneäžã«çæããã次ã®ããã«dsset-my-domainãã¡ã€ã«ã«ãããŸãã
my-domain.comã IN DS 40513 5 1 6198D29A9FB9797719CDFD2316986BDFF5C29323 my-domain.comã IN DS 40513 5 2 1AAB29EC7B67013F45865AEB06D93899B45C598D65A4E4D5522BC39E B5B9212F
ããã¯ãGoDaddyããã«ã«DSã¬ã³ãŒããè¿œå ããããã®ãã©ãŒã ã§ãã
ç·šéåŸãã詳现ã¢ãŒããã«åãæ¿ããŠãäž¡æ¹ã®è¡ãã³ããŒããå¿ èŠããããŸãã TTLå€ãè¿œå ããããŒã®ãã£ã³ã¬ãŒããªã³ãã®2è¡ç®ã®ã¹ããŒã¹ãåé€ããå¿ èŠããããŸããããããªããšããã©ãŒã ã¯ãšã©ãŒãè¿ããŸãã ãã®çµæãã³ããŒãããè¡ã¯æ¬¡ã®ããã«ãªããŸãã
my-domain.comã 86400 IN DS 40513 5 1 6198D29A9FB9797719CDFD2316986BDFF5C29323 my-domain.comã 86400 IN DS 40513 5 2 1AAB29EC7B67013F45865AEB06D93899B45C598D65A4E4D5522BC39EB5B9212F
ãšã³ããªãè¿œå ãããã®ã¯ããã¹ã¿ãŒãµãŒããŒäžã®ãŸãŒã³ã䜿çšå¯èœã§ãæ£ãã眲åãããŠããå Žåã®ã¿ã§ãã
DSã¬ã³ãŒãã®ãã£ãŒã«ãå€ïŒ
86400-ãã®ãšã³ããªã®TTL
40513-ããŒã¿ã°
5-ã¢ã«ãŽãªãºã
1/2-ãã€ãžã§ã¹ãã¿ã€ã
äžèšã®äŸã§ã¯ãããŒãçæããããã«RSA-SHA1ã¢ã«ãŽãªãºã ã䜿çšããããããã¬ã³ãŒãã¯5çªã§ãã
ã¢ã«ãŽãªãºã çªå·è¡šïŒ
æ° | ã¢ã«ãŽãªãºã |
---|---|
1 | RSAMD5 |
2 | DH |
3 | DSA / SHA1 |
4 | ECC |
5 | RSA / SHA-1 |
6 | DSA-NSEC3-SHA1 |
7 | RSASHA1-NSEC3-SHA1 |
8 | RSA / SHA-256 |
9 | - |
10 | RSA / SHA-512 |
11 | - |
12 | GOST R 34.10-2001 |
äžèšã®äŸã®ãã€ãžã§ã¹ãã¿ã€ããæåã®ã¬ã³ãŒãã¯1ã2çªç®ã®ã¬ã³ãŒãã¯2ã§ãã
ãã€ãžã§ã¹ãã¿ã€ãçªå·è¡šïŒ
æ° | ãã€ãžã§ã¹ãã¿ã€ã |
---|---|
1 | SHA-1 |
2 | SHA-256 |
3 | SHA-512 |
Dyn.comãªã©ã®äžéšã®ã¬ãžã¹ãã©ã§ã¯ãDSã¬ã³ãŒããè¿œå ããããã®ãã©ãŒã ã§ã¯è¡ãã³ããŒã§ããŸãããããã¹ãŠã®ãã£ãŒã«ãã«åå¥ã«å ¥åããå¿ èŠããããŸãã
Dyn.comã«ã¯ãé åºãæ£ãããªããçªå·ã®ã©ãã«ãä»ããŠããªãã¢ã«ãŽãªãºã ã®ãªã¹ãããããããæ··ä¹±ãçããŸãã ãã®ãã©ãŒã ããè¿œå ããå Žåã2çªç®ã®ããŒã®æçŽã®ã¹ããŒã¹ãåé€ããå¿ èŠããããŸãã
DSã¬ã³ãŒããè¿œå ããåŸããããã¬ãã«ãã¡ã€ã³ãæ åœãããµãŒããŒäžã§ãããã®å€èŠ³ã確èªã§ããŸãã ãã¡ã€ã³ãcomãã®å Žåã次ã®ããã«ãªããŸãã
dig + dnssec -t DS @ a.gtld-servers.net my-domain.com
ãã®å Žåã Verisignã®DNSSECãããã¬ãŒãšçœ²åãã§ãŒã³ããžã¥ã¢ã©ã€ã¶ãŒã䜿çšããŠããŸãŒã³ãæ£ãã眲åãããŠããããšã確èªã§ããŸãã
ãŸãŒã³ãšã³ããªãå€æŽãããã³ã«ãå眲åããå¿ èŠãããããšãæãåºãããŠãã ããã DSã¬ã³ãŒããæŽæ°ããå¿ èŠã¯ãããŸããã
ãã¹ãŠãæ£ãããã°ãã¯ã©ã€ã¢ã³ãåŽã®æ§æã«é²ãããšãã§ããŸãã
ã¯ã©ã€ã¢ã³ããªãŸã«ããŒã®æ§æ
ã¯ã©ã€ã¢ã³ãåŽã§çœ²åãæ€èšŒããã«ã¯ããã®æ©èœãã¢ãã¬ã¹è§£æ±ºãçºçããã·ã¹ãã DNSã§ãµããŒããããŠããå¿ èŠããããŸãã Googleã®ãããªãã¯DNS 8.8.8.8ã¯DNSSECã¬ã³ãŒãããµããŒãããŸãããæ€èšŒããŸããã 詳现ã¯FAQãã芧ãã ãã ã
UPDïŒ 2013幎3æ19æ¥ä»¥éãGoogle Public DNSã¯DNSSEC眲åãæ€èšŒããŠãããç¡å¹ãªçœ²åã®å Žåã googleonlinesecurity.blogspot.com / 2013/03 / google-public-dns-now-supports-dnssec.htmlã 解決ããŸããã
æãç°¡åãªãªãã·ã§ã³ã¯ã FirefoxãšChromeã®ãã©ã°ã€ã³ã§ãã
ãã®ãã©ã°ã€ã³ã¯ããã€ãã¹ã·ã¹ãã DNSã®è§£æ±ºãå¯èœã«ããDNSSECæ€èšŒããµããŒãããç¬èªã®ãµãŒããŒãäºåã«ã€ã³ã¹ããŒã«ãããŠããŸãã ããã©ã«ãã§ã¯ããã©ã°ã€ã³ã¯ã·ã¹ãã DNSã䜿çšããŸãããã©ã°ã€ã³èšå®ã§ãããå€æŽã§ããŸããCZ.NICãŸãã¯217.31.57.6ãéžæããŸã
digãŠãŒãã£ãªãã£ã«çœ²åã®æ€èšŒãæããã«ã¯ãã«ãŒããŸãŒã³ããŒã䜿çšããŠãã¡ã€ã«ãäœæããããšã«ãããä¿¡é Œãã§ãŒã³ã®éå§ç¹ãäœæããå¿ èŠããããŸãã
dig +nocomments +nostats +nocmd +noquestion -t dnskey . > /etc/trusted-key.key
ãã®åŸã / etc / trusted-key.keyãã¡ã€ã«ã®è¡ãåé€ããå¿ èŠããããŸãã
;; Truncated, retrying in TCP mode.
ãããè¡ãããªãå Žåãdigã¯ä»¥äžãè¿ããŸãã
No trusted keys present
ããã§ãdigã䜿çšããŠçœ²åã®ä¿¡é Œæ§ãæ€èšŒã§ããŸãã
dig +sigchase @217.31.57.6 whitehouse.gov
眲åæ€èšŒæ©èœã䜿çšããŠååž°ãªãŸã«ããŒãæ§æããæ¹æ³ã«ã€ããŠã¯ã ãã¡ããã芧ãã ããã
å®çšçãªã¡ãªãã
DNSSECæšæºã¯ãŸã éçºäžã§ãããšããäºå®ã«ããããããããã§ã«ãã®æ©æµãåããããšãå¯èœã§ãã
SSHå ¬ééµ
SSHãµãŒããŒã«åããŠæ¥ç¶ãããšããã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã®å ¬éããŒã®ãã£ã³ã¬ãŒããªã³ããåå¥ã«æ€èšŒããyesãå ¥åããããã«èŠæ±ããŸãããã®åŸããµãŒããŒã®å ¬éããŒã¯known_hostsãã¡ã€ã«ã«ä¿åãããŸãã
DNSSECã®åºçŸã«ãããå ¬ééµã¯SSHFPã¿ã€ãã®DNSã¬ã³ãŒãã«é 眮ã§ãããµãŒããŒã«åããŠæ¥ç¶ãããšãã«ãèŠæ±ãªãã§èªåçã«ãã§ãã¯ãããŸãã ãã®æ©èœãæå¹ã«ããã«ã¯ãSSHã¯ã©ã€ã¢ã³ãèšå®ã«VerifyHostKeyDNS = yesãªãã·ã§ã³ãè¿œå ããå¿ èŠããããŸãããŸããã·ã¹ãã ãªãŸã«ããŒãDNSSECæ€èšŒããµããŒãããŠããå¿ èŠããããŸãã
èªå·±çœ²åSSL蚌ææžïŒHTTPSïŒ
UPDïŒ sslããŒãDNSã«ä¿åããããã®æšæºãå ¬éãããDANE ru.wikipedia.org/wiki/DANEãšããååã«ãªã£ãåŸã以äžã¯ãã¯ãé¢ä¿ãããŸãããGoogleã¯ChromeããDANEãµããŒããåé€ããŸããã Chromeéçºè github.com/agl/dnssec-tls-tools/issues/4ãšã®ãã£ã¹ã«ãã·ã§ã³
DNSSECã䜿çšãããšããã©ãŠã¶ã§ãæå¹ãã«ãªãSSL蚌ææžã«åå¥ã«çœ²åã§ããŸãã
ãã®å®éšçãªæ©èœã¯çŸåšæŽ»çºã«éçºãããŠãããçŸåšGoogle Chrome / Chromiumãã©ãŠã¶ã§ã®ã¿ãµããŒããããŠããŸãã
ãã©ããæšæºïŒ tools.ietf.org/html/draft-agl-dane-serializechain-01
ãã®æè¡ã¯ãAdam Langleyãšããååã®GoogleåŸæ¥å¡ã«ãã£ãŠéçºãããŠããã圌ã«ã¯éåžžã«èå³æ·±ãããã°http://www.imperialviolet.org/ããããŸã ã
ãã®æè¡ã«é¢ããæçš¿ ã
ããã«ã蚌ææžãçæããããã¡ã€ã³ã¯DNSSECã«ãã£ãŠçœ²åãããŠãããšæ³å®ãããŠããŸãã
dnssec-tls-toolsãããŠã³ããŒãããŸãã
git clone gitïŒ//github.com/agl/dnssec-tls-tools.git
ãããŠã³ã³ãã€ã«ïŒ
gcc -o gencert gencert.c -Wall -lcrypto
RSAããŒçæïŒ
openssl genrsa 1024> privkey.pem openssl rsa -pubout -in privkey.pem> pubkey.pem
ããŒãã£ã³ã¬ãŒããªã³ãã®äœæïŒ
python ./gencaa.py pubkey.pem
dnssec-tls-toolsããã±ãŒãžã®gencaa.pyãã¡ã€ã«ã¯ã©ãã«ãããŸãã
ã³ãã³ãã¯æ¬¡ã®åœ¢åŒã®è¡ãè¿ããŸãã
EXAMPLE.COMã 60ã¿ã€ã257 \ïŒ70 020461757468303e3039060a2b06010401d6790203010 ...
ããã¯ãEXAMPLE.COMã®ä»£ããã«ãŸãŒã³ãã¡ã€ã«ã«è¿œå ããå¿ èŠãããDNSã¬ã³ãŒãã§ãã ãã®æå³ã ãŸãŒã³ããŸã 眲åãããŠããªãå Žåã¯ããããè¡ãå¿ èŠããããŸãã ã¬ã³ãŒããæ¢ã«çœ²åæžã¿ã®ãŸãŒã³ã«è¿œå ãããŠããå Žåããããã眲åãå床å®è¡ããå¿ èŠããããŸãã
DNSã®æ£ããããŒã確èªããŸãã
dig + dnssec + sigchase -t type27 example.com
ã³ãã³ãã¯ã DNSSECæ€èšŒãæ£åžžã§ããããšãè¿ãå¿ èŠããããŸãïŒSUCCESS
type27ã¬ã³ãŒãã䜿çšå¯èœã«ãªã眲åãããåŸãDNSSECä¿¡é Œãã§ãŒã³ãçæã§ããŸãã
python ./chain.py example.comãã§ãŒã³
ãããŠã蚌ææžèªäœïŒ
./gencert privkey.pem chain> cert.pem
Nginxã§èšŒææžãæ¥ç¶ãããšæ¬¡ã®ããã«ãªããŸãã
ãµãŒããŒ{ ... ssl on; ssl_certificate cert.pem; ssl_certificate_key privkey.pem; ... }
DNSSEC眲åãã§ãŒã³ã¯å€æŽãããå¯èœæ§ãããããããã§ãŒã³ã®äœæãšèšŒææžã®çæïŒæåŸã®2ã€ã®ã³ãã³ãïŒãã¯ã©ãŠã³ã«è¿œå ããŠãããšãã°1æ¥ã«1åå®è¡ããå¿ èŠããããŸãã
çµæã¯æ¬¡ã®ããã«ãªããŸãïŒ https : //dnssec.imperialviolet.org/
DNSSECãã§ãŒã³å šäœã蚌ææžã«é 眮ããããšããäºå®ã«ããããã©ãŠã¶ã¯å®å šãªãã§ãŒã³ãã§ãã¯ãå®è¡ããå¿ èŠããªããããã·ã¹ãã ãªãŸã«ããDNSSECæ€èšŒããµããŒãããŠããªããŠã蚌ææžã¯ãæå¹ãã«ãªããŸãã
PSãã®èšäºã§ã¯ãDNSSECããŒã®æå¹æ§ã«ã€ããŠã¯èª¬æããŠããŸããã代æ¿ã®DLVEC Look-aside Validation DLVä¿¡é Œãã§ãŒã³ã«ã€ããŠã¯èª¬æããŠããŸããã ãããã®åé¡ãç解ãã説æããŠããã人ã ã«æè¬ããŸãã
PPSç§ã¯ããã®ãããªã¿ãŒã³ããŒã¹ã®HOWTOããç解ããã«ããŒã ãç¡æèã«ã³ããŒããããšã«ã€ãªããæªåœ±é¿ãç¥ã£ãŠããŸãã ãããããã®åé¡ã«é¢ããæ å ±ãã»ãšãã©ãªããäžéšã®å Žæã§ã¯ççŸããŠãããšããäºå®ã«ããããã®èšäºãç§ãçŽé¢ããªããã°ãªããªãã£ãæ··ä¹±ã誰ããé¿ããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã åè°ãšåœŒã®èšäºããããAlexander Venedyukhinã«æè¬ããŸãã