SSL / TLSãããã³ã«ã®åäœåçã¯ãå ¬ééµæå·ã«åºã¥ããŠããŸãã çžäºäœçšã®çåŽãŸãã¯äž¡åŽã«ã¯ã蚌ææžãšé¢é£ããç§å¯éµããããŸãã ããã«ããããã©ãã£ãã¯ã®èªèšŒãšæå·åãå¯èœã«ãªããŸãã
èªèšŒã«é¢ããŠã¯ãçžäºèªèšŒãããäžè¬çã§ããã€ãŸãããµãŒããŒã¯ã¯ã©ã€ã¢ã³ã蚌ææžããã§ãã¯ããã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒèšŒææžããã§ãã¯ããŸããããµãŒããŒã®ã¿ãã¯ã©ã€ã¢ã³ããèªèšŒããŸãã å¿ èŠã«å¿ããŠããµãŒããŒã¯ãã¯ã³ã¿ã€ã ãã¹ã¯ãŒããªã©ã®äœ¿çšå¯èœãªæ¹æ³ã䜿çšããŠãåŸã§ã¯ã©ã€ã¢ã³ããèªèšŒã§ããŸãã 蚌ææžèªèšŒãå®è¡ãããåçã¯éåžžã«ç°¡åã§ããã¯ã©ã€ã¢ã³ãã¯èªåã®ç§å¯éµã§ããŒã¿ã»ããã«çœ²åãããµãŒããŒã¯ãã®çœ²åãæ€èšŒããŸãã
äžéšã®äººã ãèããããã«ãSSL / TLSã䜿çšããæå·åã¯å®éã«ã¯é察称ã§ã¯ãããŸããã é察称æå·åã¯ã察称æå·åããŒã®äº€æã«äœ¿çšãããŸãã 察称æå·ã䜿çšããŠãããã«ããŒã¿äº€æãè¡ãããŸãã
ããŒãã¢ã®ã¿ã§èªèšŒãšæå·åã®ããã®æå·åæäœãå®è¡ããããšãå¯èœã§ãã ããããå ¬ééµã®é åžãšããããžã®ä¿¡é Œã«ã¯å°é£ã䌎ããŸãã çžäºäœçšã®åãµã€ãã§ã¯ãç¹å®ã®å ¬éããŒãç¹å®ã®ãµããžã§ã¯ãã«å¯Ÿå¿ããŠããããšãäœããã®æ¹æ³ã§ç¢ºèªããå¿ èŠããããŸãã ã€ãŸããä¿¡é Œã§ãããã£ãã«ãä»ããŠããŒãååŸããå¿ èŠããããŸããããã§ãªãå Žåãæ»æè ã§ã¯ãªãããšã確èªããæ¹æ³ã¯ãããŸããïŒ ããã§ã蚌ææžã圹ç«ã¡ãŸãã ãããã¯ããµããžã§ã¯ããšåœŒã®å ¬ééµã«é¢ããæ å ±ãå«ããé»å眲åã«ãã£ãŠçœ²åãããããŒã¿ã®ã»ããã§ãã 蚌ææžãè¡ãæãéèŠãªããšã¯ããã®ææè ïŒãµããžã§ã¯ãïŒãå ¬ééµãã¢ïŒç§å¯éµïŒãæã£ãŠããããšã蚌æããããšã§ãã
Webäžã®ä¿¡é Œã¢ãã«ã¯ããã©ãŠã¶ãŒïŒãŸãã¯ä»ã®ãœãããŠã§ã¢ïŒãä¿¡é Œã§ãããã®ã®ãªã¹ãã«èšŒææ©é¢ã®èšŒææžãå«ãããããµããžã§ã¯ãã®æçµçãªèšŒææžãçŽæ¥ä¿¡é Œããããšãæå³ããŸãã ãµãŒãããŒãã£ã®èšŒææžãä¿¡é Œã§ãããã®ãšããŠã€ã³ã¹ããŒã«ããã«ã¯ãç¹ã«ãã®ããã»ã¹ã«è³¢æã«åãçµãå ŽåããŠãŒã¶ãŒã«ããè¿œå ã®ã¢ã¯ã·ã§ã³ãå¿ èŠã§ãã ãããã£ãŠããµããžã§ã¯ãã®ä¿¡é Œã¢ãã«ã¯ããã®èšŒææžãçºè¡ãã蚌ææ©é¢ã®ä¿¡é ŒãéããŠããé »ç¹ã«ééããŸãã ç°¡åã«èšãã°ãCAãä¿¡é Œããå ŽåãCAãçºè¡ãã蚌ææžãä¿¡é ŒããŸãã
ãã¡ãããèªèšŒã»ã³ã¿ãŒã®çœ²åã®ç¢ºèªã«å ããŠãæå¹æéã倱å¹ãªã¹ãïŒCRLïŒã®ååšãç®çãªã©ãä»ã®å€ãã®èšŒææžæ€èšŒãè¡ãããŸãã
ãã¡ã€ã³ã®èšŒææž
ãã¡ã€ã³ææè ã¯ãHTTPSãä»ããŠãŠãŒã¶ãŒãWebãµã€ãã«ã¢ã¯ã»ã¹ã§ããããã«èšŒææžãåãåãããããŠãŒã¶ãŒã¯WebãµãŒããŒãžã®ãã©ãã£ãã¯ãä¿è·ãããWebãµãŒããŒãäžæ£ã§ã¯ãªãããšã確èªã§ããŸãã 蚌ææžãçºè¡ãã蚌ææ©é¢ãšããŠãã»ãšãã©ã®ãã©ãŠã¶ãŒã§ä¿¡é ŒãããŠãããã®ãéžæãããŸãã ããã«ããããµã€ã蚪åè ã«ã¯ã»ãã¥ãªãã£èŠåã衚瀺ãããªããªããŸãã 蚌ææžã«çœ²åããåã«ã蚌ææ©é¢ã¯ãã¡ã€ã³ææè ã蚌ææžã«ã¢ã¯ã»ã¹ããŠããããšã確èªããŸãã ãããè¡ãããã«ãCAã¯ãã®ãã¡ã€ã³ã®æè¡çãªé»åã¡ãŒã«ãžã®ãªã³ã¯ãéä¿¡ããããããšãã°ãWebãµãŒããŒã«ç¹å®ã®ãã¡ã€ã«ãé 眮ããããã«äŸé Œã§ããŸãã æ¡åŒµæ€èšŒ-æ¡åŒµæ€èšŒèšŒææžã䜿çšãã蚌ææžã«ã¯ããã¡ã€ã³ææè ã®ããå³å¯ãªæ€èšŒãå¿ èŠã§ãã
蚌ææžã®åé¡
èªèšŒå±ããããã®ãã¡ã€ã³ã®ææè ã®èš±å¯ãªãã«ãã¡ã€ã³ã®èšŒææžãçºè¡ããäŸããããŸãã
- ãã£ã³ã©ã³ãã®ITãããŒãžã£ãŒããhostmaster @ live.fiãsecurity @ live.fiãhostmaster @ hotmail.fiãšãããšã€ãªã¢ã¹ãã¡ãŒã«ããã¯ã¹ã«ç»é²ããŸããã 圌ã¯åŸã«live.fiãã¡ã€ã³ã®èšŒææžãååŸããŸããã
- CNNICèªèšŒå±ã¯äžéèªèšŒå±ã«èšŒææžãçºè¡ããäžéèªèšŒå±ã¯ããã䜿çšããŠããŒã«ã«ãããã¯ãŒã¯ã§äžéè ãç·šæããŸããã 蚪åããWebãµã€ãã®æå¹ãªèšŒææžã¯ããã®å Žã§çæãããŸããã
- å éšãã¹ãäžã«ãã·ãã³ããã¯ã¯ google.comãwww.google.comãå«ãããã€ãã®ãã¡ã€ã³ã®èšŒææžãçºè¡ããŸãã
æå¹ãªèšŒææžã®äžæ£ãªçºè¡ã®ãããã®ã±ãŒã¹ããã³ãã®ä»ã®ã±ãŒã¹ã¯ããŠãŒã¶ãŒããã³æè¡å°é家ã ããå¿é ãããã®ã§ã¯ãããŸããã 蚌ææ©é¢èªäœã¯ãæäŸãããµãŒãã¹ã«å¯Ÿããä¿¡é Œã倱ããããããŸããã ãŸããGoogleã®ãããªã€ã³ã¿ãŒãããã®å·šäººã¯ã圌ãã®ãµãŒãã¹ãç¥ããã«äŸµå®³ãããããšãæãã§ããŸããã
ãã¡ã€ã³ã®èšŒææžïŒããã³ç§å¯ããŒïŒãæå ã«çœ®ããŠãäžéè æ»æãçµç¹ãããšã©ãŒã¡ãã»ãŒãžã§æ³šæãåŒãããšã¯ã§ããŸããããã¡ã€ã³ã®èšŒææžã¯éæ³ã§ã¯ãããŸããããã©ãŠã¶ãŒã®èŠ³ç¹ããã¯ç¡å¹ã§ããçãã
蚌ææžã®éææ§
ãã®ããããã¡ã€ã³ææè ã¯èªåã®ãã¡ã€ã³ã«å¯ŸããŠçºè¡ããã蚌ææžãåžžã«ææ¡ããŠããããã§ã¯ãªããšããäºå®ã«æ°ä»ããŸããã 蚌ææžã®éææ§ ïŒCTïŒãããžã§ã¯ãã¯ããã®èª€è§£ãåãé€ãããšãç®çãšããŠããŸãã
蚌ææžã®éææ§ã¯ãå®éšçãªãªãŒãã³IETFæšæºã§ãããGoogleã«ãã£ãŠéå§ããããªãŒãã³ãœãŒã¹ãããžã§ã¯ãã§ãã
蚌ææžã®éææ§ã¯ããã¡ã€ã³æææš©ã®è¿œå ã®æ€èšŒãè¿œå ããã蚌ææžã®çºè¡ã劚ããŸãããã誰ã§ãèªèšŒã»ã³ã¿ãŒã«ãã£ãŠçºè¡ããããã¹ãŠã®èšŒææžã«ã€ããŠç¥ãããšãã§ããŸãã ãã¹ãŠã®èšŒææ©é¢ããã®æšæºããµããŒããããšããã¡ã€ã³ææè ããããç¥ãããšãã§ããªãããã«èšŒææžãçºè¡ããããšãã§ããªããªããŸãã
蚌ææžã®éææ§ã䜿çšããå Žåãçºè¡ãããå蚌ææžã«é¢ããæ å ±ã¯ãã°ïŒ Certificate log ïŒã«èšé²ãããŸã ãããã¯æžã蟌ã¿å°çšã§ãå ¬éç£æ»çšã«éãããŠããŸãã ãã®ãã°ã§ã¯ããšã³ããªã®å€æŽãŸãã¯åé€ã¯èš±å¯ãããŸããããè¿œå ã®ã¿ãèš±å¯ãããŸãã 誰ã§ããã°ã«ã¢ã¯ã»ã¹ããŠãçºè¡ããã蚌ææžã«é¢ããæ å ±ãååŸã§ããŸãã çŸæç¹ã§ã¯ããã§ã«ããã€ãã®ãã®ãããªãã°ããããŸãã ãããã®ãã°ãåžžã«ç£èŠããããšã§ããã¡ã€ã³ã®ãã¹ãŠã®èšŒææžã®çºè¡ã远跡ã§ããééã£ã蚌ææžãèŠéãããšã¯ãããŸããã ãšã³ããªãè¿œå ããããšã«ãã£ãŠã®ã¿ãã°ã«ã¢ã¯ã»ã¹ã§ããããã«ããã«ã¯ã Merkle treeãšåŒã°ããããªãŒããã·ã¥ã䜿çšããŸã ã ããã«ããããã°ã®æ°ããããŒãžã§ã³ã«ä»¥åã®ããŒãžã§ã³ãå«ãŸããŠããããšã確èªã§ããŸãã ãã°èªäœã¯é»åçã«çœ²åããå¿ èŠããããŸããããæ£ç¢ºã«ã¯ããã°ã®ããŒã¯ã«ããªãŒã«ãŒãã®ããã·ã¥ã«çœ²åããå¿ èŠããããŸãã
蚌ææžããã°ã«è¿œå ãããšã眲åããã蚌ææžã®ã¿ã€ã ã¹ã¿ã³ããå¿çãšããŠè¿ãããŸãã ããã¯ãŸãã§ãã°ãçŽæãäžå®æéãã°ã«å«ããããšã®çŽæã§ãã TLSæ¥ç¶ã確ç«ããå ŽåãWebãµãŒããŒã¯ã蚌ææžãšãšãã«1ã€ä»¥äžã®ãã°ããã¿ã€ã ã¹ã¿ã³ããã¯ã©ã€ã¢ã³ãã«æäŸããå¿ èŠããããŸãã ã¯ã©ã€ã¢ã³ããã©ãŠã¶ã¯ãæå¹ãªã¿ã€ã ã¹ã¿ã³ãããªãå Žåã蚌ææžãåãå ¥ããŸããã
眲åãããã¿ã€ã ã¹ã¿ã³ãã«ã€ããŠã¯ã©ã€ã¢ã³ãã«äŒããã«ã¯ã3ã€ã®ç°ãªãæ¹æ³ããããŸãã
- X.509v3蚌ææžæ¡åŒµæ©èœã«ã¿ã€ã ã¹ã¿ã³ããè¿œå ããŸãã ãã®å ŽåãWebãµãŒããŒã¯å€æŽãå¿ èŠãšããŸããã 蚌ææ©é¢ã¯ãããããäºå蚌ææžããã°ãµãŒããŒã«éä¿¡ããããã«å¿ããŠçœ²åä»ãã¿ã€ã ã¹ã¿ã³ããåä¿¡ããŸãããã®åŸã蚌ææžãçºè¡ãããŸãã äºå蚌ææžèªäœã¯ãç¹å¥ãªæ¡åŒµã®ããã«ã¯ã©ã€ã¢ã³ãã§æ€èšŒã«åæ Œããããšã¯ã§ããŸããããèªèšŒã»ã³ã¿ãŒã«ãããã®çºè¡ã¯ãå®éã®èšŒææžãçºè¡ããçŽæãæå³ããŸãã ãããã£ãŠãäºå蚌ææžã®èª€ã£ãçºè¡ã¯ã蚌ææžã®èª€ã£ãçºè¡ãšåçã§ãã
- TLSæ¡åŒµ signed_certificate_timestampã§ã¿ã€ã ã¹ã¿ã³ããæž¡ããŸãã 次ã«ãWebãµãŒããŒããã®ãããªæ¡åŒµæ©èœã®ãµããŒããéå§ããããã«ãå€æŽãå¿ èŠã§ãã
- OCSPã®ãããã¹æ¢ãã¡ã«ããºã ã ãã®ãããèªèšŒã»ã³ã¿ãŒã¯èšŒææžãçºè¡ãããšåæã«ããã°ãµãŒããŒã«è»¢éããŸãã 次ã«ãWebãµãŒããŒã¯OCSPèŠæ±ãäœæãã眲åãããã¿ã€ã ã¹ã¿ã³ãä»ãã®å¿çã蚌ææ©é¢ããåãåããŸãã
ãã°ã®ç£èŠã¯ããªãã¶ãŒããŒïŒ 蚌ææžã¢ãã¿ãŒ ïŒã«ãã£ãŠè¡ãããŸãã ãããã¯ããã°å ã®æ°ããåãšã³ããªã远跡ããMerkleããªãŒã«ãŒãã®æ°ããããã·ã¥ãç¬èªã®èšç®ãšæ¯èŒãããµãŒããŒã§ãã ãããã¯ãéæ³ã«çºè¡ããã蚌ææžãŸãã¯ç°åžžãªèšŒææžãããšãã°èªèšŒã»ã³ã¿ãŒã®èšŒææžãèŠã€ããããã«èšèšãããŠããŸãã
蚌ææžã®éææ§ã«ããããã1ã€ã®åœ¹å²ã¯ã 蚌ææžç£æ»å¡ã§ãã ãã°ã«é¢ããéšåçãªæ å ±ãååŸãããã®æ å ±ãä»ã®å©çšå¯èœãªéšåçãªæ å ±ãšäžèŽããããšã確èªããŸããã€ãŸãããã°ãšãã®æå·ã·ãŒã±ã³ã¹ã®æ£ããåäœã確信ããŠããŸãã ç£æ»äººã®2çªç®ã®ã¿ã¹ã¯ã¯ãç¹å®ã®èšŒææžããã°ã«è¡šç€ºãããããã«ããããšã§ãã ç£æ»äººã¯ãã¯ã©ã€ã¢ã³ãã®ãã©ãŠã¶ãšãµãŒãããŒãã£ãµãŒãã¹ã®äž¡æ¹ã«ããããšãã§ããŸãã ç£æ»æ©èœã¯ããªãã¶ãŒããŒãå®è¡ããããšãã§ããŸãã
çµæãšããŠããã©ãŠã¶ã蚌ææžãåãå ¥ããªãå Žåããã®æ å ±ããã°ã«ãªãå Žåãä»ã®èª°ãã®ãã¡ã€ã³ã«æ°ä»ãããã«èšŒææžãçºè¡ããããšã¯å°é£ã§ãã ãã ãã蚌ææžã®éææ§ã®èŠä»¶ãæºãã蚌ææžã®äžæ£ãªåé¡ãæ€åºããããã«ããã¡ã€ã³ææè ã¯ãã°ãç£èŠããå¿ èŠããããŸãã ã€ãŸãããªãã¶ãŒããµãŒããŒãç¬ç«ããŠç¶æãããããã®ãã¡ã€ã³ã«å¯ŸããŠçºè¡ããã蚌ææžããã¡ã€ã³ææè ã«éç¥ãããµãŒãããŒãã£ãµãŒãã¹ã«ãµãŒãã¹ã®æéãæ¯æããŸãã
2015幎ã®åããããChromeãã©ãŠã¶ãŒã§ã¯EV蚌ææžã®CTãµããŒããå¿ èŠã§ãã ãã®ãããããšãã°ãåããã¡ã€ã³ã®ã¢ãã¬ã¹ããŒãFirefoxãšChromeã§è¡šç€ºãããããã«ãªããŸããã
æ¥ç¶ã®è©³çŽ°ãèŠããšããã®èšŒææžã®CTæ å ±ããªãããšãããããŸãã
Firefoxãã©ãŠã¶ãŒã¯ã蚌ææžã®éææ§ãã¯ãããžãŒããµããŒãããäºå®ã§ãã ããããMicrosoftã¯ç¬èªã®æ¹æ³ã§å¥ã®ãã¯ãããžãŒãéçºããŠããŸãã IE11以éãçµã¿èŸŒã¿ã®SmartScreenãã£ã«ã¿ãŒã¯ãWebããŒãžãã¢ã¯ã»ã¹ãã蚌ææžã«é¢ããæ å ±ãåéããŸãã ãã®ããŒã¿ã¯ãããšãã°æ¬¡ã®ãããªç°åžžãªèšŒææžãæ€çŽ¢ããããã«äœ¿çšã§ããŸãã
- ãŠã§ããµã€ãã¯ãäžäœã®èªèšŒæ©é¢åãã®èšŒææžã䜿çšããŠããŸã
- ç¹å®ã®å°åãžã®èšªåè ã«å¯Ÿããå¥ã®èšŒææžã®äºæããªã䜿çš
- ç¹å®ã®èšŒææ©é¢ã«ãã£ãŠçºè¡ããã蚌ææžã®åéã«ãããéèŠãªå€æŽã ããšãã°ãOCSPãžã®åç §ã®å€æŽãŸãã¯æ¬ åŠã
äžè¬ã«ãMicrosoftã®ã¢ãããŒãã¯ããééçã§ãããäž»ã«ãŠãŒã¶ãŒã察象ãšããŠããŸãã ãããã¯ã¯ããã«ã€ããŠã§ã¯ãªãã®ã§ãç§ã¯ç¹ã«ã³ã¡ã³ãããŸããã
ãããã«
æšæºã¯ãŸã å®éšçã§ãããããã¯åŸã ã«é©çšãããããšã劚ããŸããã 蚌ææ©é¢ãšãã©ãŠã¶ã¡ãŒã«ãŒã®äž¡æ¹ã¯ããã§ã«éšåçã«èšŒææžã®éææ§ã®ãµããŒããéå§ããŠããããå°ãªããšãåå ãçºè¡šããŠããŸãã äŒæ¥ã¯èªèšŒæ©é¢ã管çããããŒã«ãåãåãããæªãã蚌ææžãè¿ éã«ç¹å®ã§ããããã«ãªããŸãã èªèšŒå±ã¯ã蚌ææžã®çºè¡ã«ãããŠããã«è²¬ä»»ãè² ããŸãã äžèœè¬ãšããŠèšŒææžã®éææ§ã«é Œãã¹ãã§ã¯ãããŸããããæ»æè ã®æŽ»åãè€éã«ããããšã¯ééããªãå¯èœã§ãã