Javaã¢ããªã±ãŒã·ã§ã³ã®SSL / TLSã§ä¿è·ãããçµ±åã®ãããã°ã¯ãéåžžã«éèŠãªã¿ã¹ã¯ã«ãªãããšããããŸããæ¥ç¶ã確ç«ãããªã/åæãããã¢ããªã±ãŒã·ã§ã³ãã°ãäžè¶³ããŠããå ŽåããããŸããããšãããã§ãã£ãŠãïŒãã£ãã«ãPFSã§æå·ã䜿çšãããšå€±æããå ŽåããããŸãã FiddlerãBurpãªã©ã®ãããã·ãµãŒããŒã¯æ©èœããªãå¯èœæ§ããããŸããããã¯ãã¢ããªã±ãŒã·ã§ã³ããããã·ãééããæ¹æ³ãç¥ããªããã蚌ææžãäŸµå ¥ãããšä¿¡ããããšãæåŠããããã§ã...
æè¿ã ValdikSSã® åºçç©ãHabrã« æ²èŒãããŸããã ãã 㯠ãWiresharkã䜿çšããŠãFirefoxããã³Chromeãã©ãŠã¶ãŒããã®ãã©ãã£ãã¯ããç§å¯ãµãŒããŒããŒã蚌ææžã®ãªãããŸãããããã·ãªãã§åŸ©å·åããæ¹æ³ã«é¢ãããã®ã§ãã 圌女ã¯ãã®èšäºã®èè ã«èããããããã«ä¿ããŸãã-ã»ãã·ã§ã³ããŒãã¡ã€ã«ã®ä»£ããã«JVMãããã°ãšã³ããªã䜿çšããŠããã®ã¢ãããŒããJavaã¢ããªã±ãŒã·ã§ã³ã«é©çšããããšã¯å¯èœã§ããïŒ ããã¯å€æããŸãã-ããã¯å¯èœã§ããããããŠä»æ¥ã芪æãªãäžæ¹ãç§ã¯ãããè¡ãæ¹æ³ãæããŸãã
ã¬ã·ãã®ã¢ã€ãã¢
Firefoxããã³Chromeãã©ãŠã¶ãŒã¯ãæè¿ã®ããŒãžã§ã³ä»¥éãéä¿¡ãããã©ãã£ãã¯ïŒããã³å¯Ÿç§°æå·åãSSL / TLSå ã§äœ¿çšãããããåä¿¡ãããã©ãã£ãã¯ïŒãæå·åããã»ãã·ã§ã³ããŒã®æŽŸçïŒåä¿¡ïŒã«ååãªç¹å¥ã«å®çŸ©ããããã¡ã€ã«ã«ããŒã¿ãåºåããããšãåŠã³ãŸããã å³å¯ã«èšãã°ãããã¯ãã©ãŠã¶ãŒèªäœã§ã¯ãªããæ§æå ã®NSSã©ã€ãã©ãªã«ãã£ãŠè¡ãããŸãã èšé²ããããã¡ã€ã«ã®åœ¢åŒãèšå®ããã®ã¯åœŒå¥³ã§ãã Wiresharkã¯ãã®åœ¢åŒãèªã¿åã£ãŠäœ¿çšãã察å¿ããããŒã§æå·åãããSSLã¬ã³ãŒãã解èªã§ããŸãã ããã£ãã·ã¥ãã®èãæ¹ã¯ãåãç®çã§Javaã¢ããªã±ãŒã·ã§ã³çšã«ãã®ãããªãã¡ã€ã«ãåå¥ã«äœæãã javax.net.debug JVMãªãã·ã§ã³ã§æšæºåºåã«æžã蟌ãŸãããããã°ãã°ããœãŒã¹ãšããŠäœ¿çšããæ¹æ³ãåŠã¶ããšã§ãã
æå
å¿ èŠãªãã®ïŒ
- èµ·åãã©ã¡ãŒã¿ãŒïŒJVMãªãã·ã§ã³ïŒãèšå®ã§ããJavaã¢ããªã±ãŒã·ã§ã³ ã
æ確ã«ããããã«ãæ¥ç¶ã確ç«ãããšãã«ã¢ããªã±ãŒã·ã§ã³ãã¯ã©ã€ã¢ã³ããšããŠæ©èœãããšèããŠããŸãã
JDKïŒJREïŒããŒãžã§ã³1.6ãŸãã¯1.7ãå¿ èŠã§ãããä»ã®ïŒãããŸã§ã®ãšããïŒãã¹ããããŠããŸããã - WiresharkããŒãžã§ã³1.6.0以éã
- ããã¹ããšãã£ã¿ãŒ ïŒã¡ã¢åž³++ãªã©ïŒã
- èŸæ±åŒ·ãããã€ã³ããã«ãã¹ãæéã
ç·Žã
èµ·åãªãã·ã§ã³
ãã°ã¯æ å ±ã®äž»èŠãªãœãŒã¹ã®1ã€ã§ãããããæåã«è¡ãããšã¯ãå信確èªãæ£ããæ§æããããšã§ãã å®å šã«æ©èœãããªãã·ã§ã³ã¯ãJVMãªãã·ã§ã³javax.net.debug = sslïŒhandshakeïŒdataã§ãã ãã®ãããªå€ãæã€å¿ èŠã¯ãªãã®ã§ãããã«äºçŽããŸããïŒããããïŒãŠãããŒãµã«javax.net.debug = allãªãã§è¡ãããšãã§ããŸããããã®ãããªéžæã®çµæãæäœããã®ã¯é£ããå ŽåããããŸãïŒãã°ã®éãèšå€§ã«ãªãå¯èœæ§ããããŸãïŒã ç§ãã¡ã®éžæã¯ä»¥äžã«ãã£ãŠèª¬æãããŸãïŒ
- ssl -SSLã®ã¿ã«é¢ããã¡ãã»ãŒãžããã°ã«æžã蟌ãŸããããã«ããŸãã
- ãã³ãã·ã§ã€ã¯ -ã¡ã€ã³ã¹ããŒãžå ã®åã¡ãã»ãŒãžã衚瀺ããã«ã¯- ãã³ãã·ã§ã€ã¯ ã
- ããŒã¿ -äžéšã®å€ã10é²æ°ã·ã¹ãã ãã16é²æ°ïŒ16é²æ°ïŒã«æåã§å€æããªãããã«ãæ laãªäººåãã
ãã®ãããªãªãã·ã§ã³ããããšããããã°æ å ±ã®ãã°ïŒãŸãã¯æšæºåºåïŒãžã®åºåãæäŸãããŸãããããã«ã€ããŠã¯åŸã§èª¬æããŸãã
ã¹ããã¡ãŒèšå®
äžèšã®ãªãã·ã§ã³ãèšå®ããåŸã¯ãWiresharkã«ããã¿ãŒã²ããã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã£ãã¯ã®ã¿ãã¹ãããã£ã³ã°ã§ããŸãããã以å€ã®å Žåãã»ãã·ã§ã³ããŒããªãããã§ãã ããã«ãããŒã¯ãäžæçãã§ããããšã«æ³šæããå¿ èŠããããŸãã1ã€ã®SSLã»ãã·ã§ã³ã«ã®ã¿é©ããŠããŸããã€ãŸãã1ã€ã®éä¿¡ã»ãã·ã§ã³ã®ãã°ã¯å¥ã®ã»ãã·ã§ã³ã®ãã©ãã£ãã¯ã®åŸ©å·ã«ã¯é©ããŸããã ããŠãéåžžã«ç°¡åã«åŒåžã§ããããã«ãã¹ããã¡ãŒã®éå§æã«ããŒã¿ã亀æããäºå®ã®ãã¹ããããã«æå®ããããšããå§ãããŸãã ããã«ããããªã¹ãã³ã°ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãééããäžèŠãªãã±ããããéžäžãã§ãç Žæ£ã§ããŸãã
é²é³ãšé²é³
å¿ èŠãªã¢ããªã±ãŒã·ã§ã³èµ·åãã©ã¡ãŒã¿ãšã¹ããã¡ãŒèšå®ãèšå®ããããã¢ããªã±ãŒã·ã§ã³èªäœãèµ·åããŠãWiresharkã§ãã±ãããã£ããã£ãæå¹ã«ã§ããŸãã 次ã«ãã¢ããªã±ãŒã·ã§ã³ããµãŒããŒãšã®ïŒå®å šãªïŒæ¥ç¶ã«å°éããããšãããšããããããããã£ã±ãã«ãªãå§ããŸãã Wiresharkã®èŠ³ç¹ããã¯ã次ã®ããã«ãªããŸãã
ã芧ã®ããã«ãWiresharkã¯äžéšã®SSLã¬ã³ãŒããæå·åæžã¿ãšããŠæ瀺çã«å®çŸ©ããŠããŸãã ã¢ããªã±ãŒã·ã§ã³ããŒã¿ã¿ã€ãã®ãšã³ããªã¯åãã§ãã
ãããŠãã¢ããªã±ãŒã·ã§ã³ã®æšæºåºåïŒãã°ïŒã®èŠ³ç¹ãã-ãã®ãããªãã®ïŒ
... *** ClientHello, TLSv1 RandomCookie: GMT: 1427238714 bytes = { 246, 5, 6, 214, 168, 159, ... , 140, 141, 50, 196 } Session ID: {} Cipher Suites: [SSL_RSA_WITH_RC4_128_MD5, SSL_RSA_WITH_RC4_128_SHA, ..., SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA] Compression Methods: { 0 } ...
å®éãã¯ããã«å€ãã®ãã°ãèšé²ãããŸãïŒãããã°åºåã®åœ¢åŒã¯ã©ãã«ãæå®ãããŠããããJavaããŒãžã§ã³ããããŒãžã§ã³ã«å€æŽãããŸãïŒããçŸæç¹ã§ã¯å°ãªããšãããã ããèŠãå¿ èŠããããŸãã
ãæ ¡æ£ã
SSL / TLSéä¿¡ã»ãã·ã§ã³ããã®ãããã°ã¬ã³ãŒãããããããNSS圢åŒã®ã»ãã·ã§ã³ããŒãã¡ã€ã«ãäœæã§ããŸãã ãããè¡ãã«ã¯ããŸãéä¿¡ã»ãã·ã§ã³ã§äœ¿çšãããã»ãã·ã§ã³ããŒã®é åžæ¹æ³ã決å®ããå¿ èŠããããŸãã 亀ææ¹æ³ ïŒå¥åRSAïŒãŸãã¯çææ¹æ³ ïŒå¥åDHãŸãã¯PFSããããã¯ç°ãªããã®ã§ãïŒã 圌ãã®æ¬è³ªãšéãã¯ããµãªãŒã»ãŽã¡ã³ããŽã§ã³ã®çŽ æŽãããäœåã«ãããŸãã ç§ãã¡ã«ãšã£ãŠã¯ãã¡ãœããèªäœãç¥ãã ãã§ååã§ãããå°ãªããšã2ã€ã®æ¹æ³ã§æ±ºå®ã§ããŸãã
- ãã°ã«è¡šç€ºãããããã¹ããã¡ãŒã«ãã£ãŠå®çŸ©ãããæå·ã®ååã ããšãã°ããã®çµè«ã«ãããš
*** ServerHello, TLSv1 RandomCookie: GMT: 1037995915 bytes = { 168, 183, ... 204, 178 } Session ID: {141, 155, ... 214, 36} Cipher Suite: SSL_RSA_WITH_RC4_128_SHA ...
- Wiresharkã®ãã©ãã£ãã¯ã®ã€ã³ã¿ãŒã»ããã«ServerKeyExchange SSLã¡ãã»ãŒãžãååšããããšã«ããïŒãµãã»ã¯ã·ã§ã³ãåé€ãšèšé²ãã®ã¹ã¯ãªãŒã³ã·ã§ãããåç §ïŒ-RSAã§ã¯ãªãDHã¡ãœããã«ååšããŸãïŒãã®èšäºã®ç¯å²å€ã§ããçç±ã®èª¬æïŒã ãã¡ããããã®ã¡ãã»ãŒãžã®ååšã¯åããã°ã§å€æã§ããŸãã
ã»ãã·ã§ã³ããŒã®é åžæ¹æ³ãå®çŸ©ãããã NSSãã¡ã€ã«åœ¢åŒã®èª¬æã«ç§»ããŸããããããã¯ãããã2ã€ã®æ¹æ³ã ãã§åãã¡ã€ã«ã®è¡ãåºå¥ããããã«æ瀺ããŸãã ããããã«ã€ããŠè©³ããèŠãŠãããŸãããã
ãŸããã³ãã¥ãã±ãŒã·ã§ã³ã»ãã·ã§ã³ã§ãããçš®ã®RSAããŒã¹ã®æå·ã䜿çšããããšããŸãããã 圢åŒã®èª¬æã«ãããšããã¡ã€ã«ã®å¯Ÿå¿ããè¡ã¯RSAããã¹ãã§å§ãŸãã16ãã€ãã®HEXãšã³ã³ãŒãæå·åPreMasterSecretããŒãã¹ããŒã¹ã96ãã€ãã®HEXãšã³ã³ãŒãéæå·åPreMasterSecretããŒïŒã€ãŸããç¬èªã®ïŒãç¶ãå¿ èŠããããŸãã ãã®ããŒã¯ããã¹ã¿ãŒããŒMasterSecretãçæããããã®åºç€ã§ããã ClientKeyExchangeã¡ãã»ãŒãžã§ã¯ã©ã€ã¢ã³ããããµãŒããŒã«éä¿¡ããããµãŒããŒã®æå·åãããå ¬éããŒã§ãã ããã¯ãè¡ã®æåã®éšåïŒãã®ããŒã®æå·åãããè¡šçŸïŒãWiresharkã«è¡šç€ºãããããšãæå³ããŸãã ç®çã®ã¡ãã»ãŒãžãèŠã€ããŠç¢ºèªããŸã-ã¯ããããã§ãïŒ
ããŒãããã¯ã¯ãŒã ã¬ã€ã
çµéšè±å¯ãªçŸœé¡åŠè
ã«ã¯ã質åã§ã¹ããŒãªãŒãäžæããæš©å©ããããŸããæå·åãããããŒã®é·ãã256ãã€ãã§ããã®ã«ããªãNSSãã¡ã€ã«åœ¢åŒã§ã¯16ãã€ãããå¿
èŠãªãã®ã§ããïŒ
ããã¯ãæå·åãããå€ãã€ã³ããã¯ã¹ãšããŠWiresharkã«ãã£ãŠäœ¿çšããããšããäºå®ã«ãã£ãŠèª¬æãããŸã-NSSãã¡ã€ã«å ã®æœåšçãªè¡ã»ããããé©åãªMasterSecretãå«ãæ£ç¢ºãªã¬ã³ãŒããèŠã€ããããã«ã®ã¿å¿ èŠã§ãã ããã¯ããã®ããŒã®æå·åãããããŒãžã§ã³ïŒã€ã³ã¿ãŒã»ããããããã©ãã£ãã¯ããååŸïŒããã¡ã€ã«ã®åè¡ã®æåã®ïŒãRSAãã®åŸã®ïŒèŠçŽ ãšé çªã«ç §åããããšã§å®è¡ã§ããŸãã å®éãããã¯Wiresharkã®æ©èœã§ãããã®å ŽåãããŒãå šé·ã«æ²¿ã£ãŠæ¯èŒããå¿ èŠã¯ãããŸããã16ãã€ãã§ååã§ãã
ããã¯ãæå·åãããå€ãã€ã³ããã¯ã¹ãšããŠWiresharkã«ãã£ãŠäœ¿çšããããšããäºå®ã«ãã£ãŠèª¬æãããŸã-NSSãã¡ã€ã«å ã®æœåšçãªè¡ã»ããããé©åãªMasterSecretãå«ãæ£ç¢ºãªã¬ã³ãŒããèŠã€ããããã«ã®ã¿å¿ èŠã§ãã ããã¯ããã®ããŒã®æå·åãããããŒãžã§ã³ïŒã€ã³ã¿ãŒã»ããããããã©ãã£ãã¯ããååŸïŒããã¡ã€ã«ã®åè¡ã®æåã®ïŒãRSAãã®åŸã®ïŒèŠçŽ ãšé çªã«ç §åããããšã§å®è¡ã§ããŸãã å®éãããã¯Wiresharkã®æ©èœã§ãããã®å ŽåãããŒãå šé·ã«æ²¿ã£ãŠæ¯èŒããå¿ èŠã¯ãããŸããã16ãã€ãã§ååã§ãã
ãšããã§ãã¢ããªã±ãŒã·ã§ã³ãã°ããåãå€ãååŸããããšãã§ããŸããããã§ã¯ãJVMãªãã·ã§ã³ã ïŒdata ãã䟿å©ã§ãã
èŠã€ãã£ãå€ïŒ16ãã€ãïŒã¯ãçæãããNSSãã¡ã€ã«ã«æ¿å ¥ã§ããŸãã 次ã«ãè¡ã®2çªç®ã®èŠçŽ ïŒ PreMasterSecretããŒã®åºæå€ïŒã«å¯ŸããŠåæ§ã®æäœãè¡ããŸãã æããã«ããªãŒãã³ãªåœ¢ã§ãããã¯ãŒã¯ãä»ããŠéä¿¡ãããããšã¯ãªãããïŒå®éãããã... SecretãšåŒã°ããçç±ã§ã ïŒããã°ãããã£ãã·ã³ã°ã¢ãŠãããã ãã§æžã¿ãŸãã 幞ããªããšã«ãJVMããã®æçœãªæãããã«ããããããè¡ãããšã¯ç¹ã«é£ãããããŸããã
ããã§ããã®å€ãäœæããNSSãã¡ã€ã«ã®è¡ã«è¿œå ãããã®ãããªçµæã«ãªãããã«è¡ããæ«ã§ããããå¿ èŠããããŸãïŒæšæºè¡šèšã®ã³ã¡ã³ãã¯ãŸã£ããåãå ¥ããããŸãïŒ ã
# SSL/TLS secrets log file, generated by Toparvion RSA 75ff866e23beca1c 03012aede74befa88233253e3207bb1320935ab206696512674df5c6dee7dfaa2156932bc559631c8f3bb46ae38a71ff
RSAãããŸãã«ãã®ã±ãŒã¹ãã§ãã人ïŒååãšããŠããããã¯Java 7ããåã®ã¢ããªã±ãŒã·ã§ã³ã§ãïŒã¯ãã詊飲ãã»ã¯ã·ã§ã³ã«é²ãã§ãã ããã PFSïŒå€ãã®å ŽåJava 7以éïŒã«ééãã人ã¯ããã£ãšèªãå¿ èŠããããŸã...
RSAæ¹åŒãšåæ§ã«ãPSFããŒã¹ã®ã¬ã³ãŒãã埩å·åããããã®è¡ã¯ãã¹ããŒã¹ã§åºåããã3ã€ã®èŠçŽ ã§æ§æãããå¿ èŠããããŸãã
- ã¬ã³ãŒãã®ã¿ã€ãã ãã®å Žåã CLIENT_RANDOMãšçãããªããã°ãªããŸããã
- 64ãã€ãã®HEXãšã³ã³ãŒããããã¯ã©ã€ã¢ã³ãä¹±æ°Random ;
- HEXãšã³ã³ãŒããããMasterSecretãã¹ã¿ãŒããŒã®96ãã€ãã
2çªç®ãš3çªç®ã®èŠçŽ ã®ããŒã¿ãœãŒã¹ãåã®æ¹æ³ãšäŒŒãŠããŸãããããã€ãã®åŸ®åŠãªç¹ããããŸãã ã¯ã©ã€ã¢ã³ãã®ä¹±æ°ã¯ãGMTããªç§åäœã®çŸåšæå»ãšå®éã®ä¹±æ°å€ãé£çµãããã®ã§ãã Wiresharkã®å Žåãããã¯ã¯ã£ãããšèŠããŸãã
ãã ãããã°ã«ã¢ã¯ã»ã¹ããå Žåãééããç¯ããããã§ããã次ã®ãã³ãã䜿çšã§ããŸãã
JVMãªãã·ã§ã³javax.net.debugã®å€ã«ã¯ãïŒdataããšãããšã³ããªããããŸããããã«ãããæ°å€ã·ã¹ãã ã®æåå€æãäžèŠã«ãªããŸãã åèšã§ã64ãã€ãã®ä¹±æ°ãå¿ èŠã§ãããã®å Žåããã¹ãŠãå®å šã«ãªããŸãïŒRSAã®å Žåã®ããã«ãå é ã ãã§ã¯ãããŸããïŒã WiresharkãNSSãã¡ã€ã«å ã®é©åãªãšã³ããªãæ€çŽ¢ãããšãã«ãã€ã³ããã¯ã¹ã®åœ¹å²ãæãããŸãã
è¡ã®3çªç®ã®èŠçŽ ã§ããMasterSecretãã¹ã¿ãŒã·ãŒã¯ã¬ããããŒããã¢ããªã±ãŒã·ã§ã³ãã°ããæœåºã§ããŸãã
ãã°ããã¡ã€ã³ããŒãæœåºããåŸãçæãããè¡ã«ãcombããè¿œå ããŠã次ã®ãããªãã®ãååŸããŸãã
# SSL/TLS secrets log file, generated by Toparvion CLIENT_RANDOM 551435582740bdc1386b20b7fcb51428fe3042e06c8e6e94c910786f577a2ada 976dc1d54dd74d3c2e715109c8a4fb8e743efc084614abc0e12fdb78e472c30e3590ac5eb383424b2d8fa3de84c8b0f5
WiresharkãNSSãã¡ã€ã«ã®åœ¢åŒã«éåžžã«ææã§ããããšã«æ°ä»ããªãããšã¯äžå¯èœã§ãããããã£ãŠãæååã®åèŠçŽ ã®ãã€ãæ°ãåæãããã©ããããŸãã©ããã«äœåãªã¹ããŒã¹ããããã©ãããæ éã«ç¢ºèªããããšããå§ãããŸãã å°æ¥çã«æéãç¯çŽã§ãããããããŸããã
詊飲
ãã¹ãŠã®ãæåãã¹ããããå®äºããã®ã§ã次ã¯Wiresharkã«ããã¢ãæäŸããŸããåé ã§è¿°ã¹ãèšäºã§èª¬æãããšããã«ãäœæãããã¡ã€ã«ãæ瀺ããŸãã
- SSL / TLSãã±ããã§Wiresharkã®ã³ã³ããã¹ãã¡ãã¥ãŒãéããŸãã
- [ãããã³ã«èšå®]-> [Secure Socket Layerèšå®]ãéžæããŸã ã
- éãããŠã£ã³ããŠã®ïŒäºåïŒãã¹ã¿ãŒã·ãŒã¯ã¬ãããã°filnenameåã§ãäœæããNSSãã¡ã€ã«ãžã®ãã¹ãæå®ããŸãã
[OK]ãã¯ãªãã¯ããŠãååãããã©ãã£ãã¯ã®å€åã確èªããŸãã
埩å·åãæåããå Žåã以åã«ååã«Encryptedãšããåèªãå«ãŸããŠãããã±ããã¯ãç¹å®ã®ååãååŸããŸãã ããã¯ãäžã®å³ã«ç€ºãããŠããFinishedã³ãã³ãã§èµ·ãã£ãããšãšãŸã£ããåãã§ãã
ããã«ïŒãããããããæã楜ããç¬éã§ãïŒãSSLãŸãã¯TLSãããã³ã«ã䜿çšããŠä»»æã®ãã±ãããéžæããã³ã³ããã¹ãã¡ãã¥ãŒã§[ SSLã¹ããªãŒã ã«åŸã ]ãã¯ãªãã¯ããããšãã§ããŸããçµæã«ã¯ã³ã¡ã³ãã¯äžèŠã§ãã
ã芧ã®ãšãããHTTP SåŒã³åºãã«ãããããããéä¿¡ããããã©ãã£ãã¯ã確èªããããã«åæããããã«ãšã¯ã¹ããŒãã§ããŸãã
ããã§ãããŸããããªãå Žåã¯...
ãã®æ»ããããæé¢ã§ã¯ãå€ãã®ééããç¯ãå¯èœæ§ããããŸãã æãéèŠãªæ å ±ãœãŒã¹ã®1ã€ã¯wiresharkã®ãã°ã§ãããã°ãã¡ã€ã«ãžã®ãã¹ããã¹ãŠåãSSLèšå®ãŠã£ã³ããŠã®ãããã°ãã¡ã€ã«ã®SSLåã§æå®ãããŠããå Žåãç¶æãããŸãã
ãã°ã«ãã£ã«ã¿ãªã³ã°ãæäŸãããŠããããWiresharkãéåžžã«è©³çŽ°ã§ããããšã«æ³šæããããšãéèŠã§ãããããã£ãŠããã°ã絶ãããªã³ã«ä¿ã€ãšããŸããéåžžã«æ¥éã«æé·ãã次ã«ãWiresharkèªäœã®æå¶ã«ã€ãªããå¯èœæ§ããããŸãæããã«åæçã«æžã蟌ãŸããŸãïŒã ãã®ç¹ã§ãNSSãã¡ã€ã«ã䜿çšããçŽåã«ãã°ãã¡ã€ã«ãæå®ããåæã®æåŸã«ãããåé€ããããšããå§ãããŸãïŒãã ããåé€ã¯ããªãã§ãã ããïŒã
ãããã«
ãã®èšäºã§ã¯ãJavaã¢ããªã±ãŒã·ã§ã³ã®SSL / TLSãã©ãã£ãã¯ã解èªããŠãããã°ããããã®å¥ã®ã¢ãããŒããæ€èšããŸããã
ãã®åœ¢åŒã§ã¯ãæéã®ããªãã®æè³ãšããã©ãŒããŒã®ç¹å®ã®ç¥èãšã¹ãã«ã®ååšãå¿ èŠãšããããããã®ã¢ãããŒãã¯å®éã«ã¯ã»ãšãã©é©çšã§ããŸããã ãã ããæ瀺ããã説æã«ããããã®ã¢ãããŒãã圢åŒåããããšãã§ãããããã£ãŠããã®ã¢ãããŒããèªååïŒããã°ã©ã ïŒããŠã人ã ã®ãµãŒãã¹ã«çœ®ãããšãã§ããŸãã ãã®ãããªäœæ¥ã¯ãèè ã«ãã£ãŠãã§ã«éå§ãããŠããŸãã ãã®ã¢ã€ãã¢ãããªãã«ãšã£ãŠãé¢çœããªããç§ãã¡ã¯ããªãã«æ æ²ãæ±ããŸãïŒ Habréã§ããã«ã€ããŠè©±ãããšãå¿ããªãã§ãã ããã
èªãã§ãããŠããããšãïŒ
æŽæ°ãã
芪æãªãå åŒãèšäºã§èª¬æãããŠããã¢ãããŒãã«èå³ãããããæåã§äœ¿çšããã«ã¯æ¬åœã«
å®è¡ã®æ§æã¯ç°¡åã§ãããœãŒã¹JVMãã°ãã¡ã€ã«ãæå®ããã ãã§ãã
java -jar nssjavamaker.jar some/directory/java-ssl-debug.log
çŸåšã®ãã£ã¬ã¯ããªã®åºåã«ãããNSSãã¡ã€ã«session-keys.nssãäœæãããWiresharkãžã®ã€ã³ããŒãã®æºåãæŽããŸãã ãã®ãã¹ããã³ãã®ä»ã®ãã©ã¡ãŒã¿ãŒãå€æŽããã«ã¯ã Readmeãã¡ã€ã«ãåç §ãããããã©ã¡ãŒã¿ãŒããŸã£ããæå®ããã«ãŠãŒãã£ãªãã£ãå®è¡ããŸãã
JARãå®è¡ããæºåã¯ãææ°ããŒãžã§ã³ã®ããŒãžã§ããŠã³ããŒãã§ããŸãã
ãŠãŒãã£ãªãã£ã«é¢ããææ¡/ææ¡/ã³ã¡ã³ã/ã³ã¡ã³ãã¯ããããžã§ã¯ãããŒãžã®ã¢ããªã±ãŒã·ã§ã³ã»ã¯ã·ã§ã³ããã³toparvion@gmx.comã§æè¿ãããŠããŸã ã é 匵ã£ãŠãã ããïŒ