蚌ææžã«åé¡ããããŸããïŒ
HTTPSãžã®åãæ¿ãã«å¯Ÿããæåã®æãäžè¬çãªéå£ã¯ãæå¹ãªèšŒææžã®ååŸãæ§æãããã³ç¶æã®äŸ¡æ Œã§ãã 蚌ææžãããã€ããŒãèŠã€ãã身å ã確èªããæ¯æããè¡ã£ãŠãµãŒããŒãæ§æããã¿ã€ã ãªãŒã«æŽæ°ããå¿ èŠããããŸãã
ãŠããã¿ã¹æå·åã«åãæ¿ããããã®ææ¡ã®ã»ãšãã©ã¯æ¬¡ã®ãããªãã®ã§ãããNSAã¯ãã¹ãŠã®ãã©ãã£ãã¯ãèšé²ããŸãããªãæå·åããªãã®ã§ããïŒã ãã®ãããªææ¡ã®ç®çã¯ãæ»æè ã䜿çšããããè€éã§æšçãçµã£ãæ»æã§ã¯ãªãããã¹ãŠã®ãã©ãã£ãã¯ã®ããã·ããã©ããã³ã°ã®ã³ã¹ããå¢ããããšã§ãã
Let's Encryptã®æ åœè ã¯ã蚌ææžã«é¢ããåé¡ã¯ã»ãŒå®å šã«èªååãããŠãããæãäžè¬çãªãã©ãããã©ãŒã ã®ããã€ãã§ã®ãªãªãŒã¹ãã€ã³ã¹ããŒã«ãæ§æãããã³æŽæ°ã®å®è£ ãã€ã³ã¿ãŒãããã®å€§éšåãã«ããŒã§ããããšããã§ã«æšæž¬ããŠããŸãã ãã°ãããä»äºã§ãããããã¹ãããšã¯ãŸã ãããããããŸããã蚌ææžã®åé¡ã¯è§£æ±ºããããšèããããšãã§ããŸãã
ããã§èšŒææžãäœæãããŸãããHTTPSãæå¹ã«ã§ããŸããïŒ
ãŸãå€åã ããããããã§ã¯ãªããããããŸããã æäŸãããã¹ãŠã®HTMLãªãœãŒã¹ã«åããã¹ããžã®ãªã³ã¯ïŒç»åãã¹ã¯ãªãããªã©ïŒããããçžå¯ŸURLã®ã¿ã䜿çšããŠããå Žåããã¹ãŠåé¡ãããŸããã ããããªããšãã»ãšãã©ã®å ŽåHTTPSãæ£ããæ©èœããŸããã
ãªã«ïŒ HTTPSã¯è¯ãã®ã§ããããªãããããã¹ãŠå£ããã®ã§ããïŒ
ã»ãŒç¢ºå®ã«ããŒãžã«ã³ã³ãã³ããæ··åšããŠããããããã¹ãŠãå£ããŸããã
æ··åã³ã³ãã³ããšã¯äœã§ããïŒãªãè奮ãããå¿ èŠããããŸããïŒ
OriginAãªãã¬ãŒã¿ãŒã§ããå Žåã次ã®ã±ãŒã¹ãèæ ®ããŠãã ããã ç·è²ã®åã¯ãhttpãšhttpsã§å©çšå¯èœãªãªãœãŒã¹ã§ããïŒ èµ€-httpã®ã¿ã ç¹ç·ã¯ãhttpãä»ããã³ã³ãã³ãã®èªã¿èŸŒã¿ã§ãã éåžžã®è¡ã¯httpsã§ãã ãã¹ãŠã®ãªã³ã¯ã絶察ã§ãããšä»®å®ããŸãã èµ€ãååã¯ãããŠã³ããŒãã倱æããããšãæå³ããŸãã

ããã§ã蚌ææžãèšå®ããOriginAã§httpsãæå¹ã«ãããšããŸãããã ãã£ãŒãã¯ã©ã®ããã«ãªããŸããïŒ

HTMLã®çµ¶å¯Ÿãªã³ã¯ãæŽæ°ããªãå Žåã§ãããã©ãŠã¶ãŒã¯httpçµç±ã§ãªãœãŒã¹ãååŸããããšããŸãã ã»ãšãã©ã®å Žåããã®ãããªããŠã³ããŒãã¯çŠæ¢ãããŠããããã®ãããªå Žåã¯èŠåã衚瀺ãããŸãã
ãã©ãŠã¶ãæ··åã³ã³ãã³ãããããã¯ããã®ã¯ãªãã§ããïŒ ãµã€ãææè ãšããŠããã«åœ±é¿ãäžããããªãã®ã¯ãªãã§ããïŒ
ã»ãšãã©ã®Webã»ãã¥ãªãã£ã¢ãã«ã§ã¯ããœãŒã¹ã¯èªèº«ã®æ å ±ã«è²¬ä»»ãè² ããŸãã HTTPSçµç±ã§ããŠã³ããŒãããã³ã³ãã³ãã¯ããŠãŒã¶ãŒãå®å šã§ãªããµã€ãã«ãªãã€ã¬ã¯ãããPOSTãªã¯ãšã¹ããŸãã¯postMessageïŒïŒãå®å šã§ãªããœãŒã¹ã«éä¿¡ã§ããŸãããŸããhttpsãµã€ãã¯ãhttpçµç±ã§ããŠã³ããŒãããããã¥ã¡ã³ãããGETãPOSTãŸãã¯onMessageïŒïŒãåä¿¡ã§ããŸã ããã ãã§ããªãPOSTã¯èš±å¯ãããŸãããXHRã¯çŠæ¢ãããŸããïŒ
ãã©ãŠã¶ããµã€ãã«é©çšããããšããæ£åŒãªã»ãã¥ãªãã£ã«ãŒã«ããããŸãã ãã®ã«ãŒã«ã¯åããŠãéããããšããŠå®åŒåãããŸããã ç°¡åãªèšèã§èšãã°ãããã¯å®å šãªããã¥ã¡ã³ãã察話äžã«å®å šã§ãªããªãããšãæå³ããŸãã
Webã»ãã¥ãªãã£ã®ãã¹ãŠã®è€éããšèœãšãç©Žã®ãã¡ããã©ãŠã¶ã¯ãä¿¡é Œæ§ãé«ãæçšãªã»ãã¥ãªãã£ã€ã³ãžã±ãŒã¿ã1ã€ãããªããšããçµè«ã«éããŸãããã¢ãã¬ã¹ããŒãšããã¯ãã€ãŸãHTTPSã䜿çšããããšã§ãã ã¢ãã¬ã¹ããŒã«ãhttpsïŒ//ããšå ¥åããããæäœããããã¥ã¡ã³ãã®ããã¯ã¢ã€ã³ã³ã衚瀺ãããå Žåããã©ãŠã¶ã¯ã³ã³ãã³ããå€éšã®è åšããä¿è·ãããŠãããšçŽæããŸãã
httpsãµã€ããhttpãä»ããŠã¹ã¯ãªãããŸãã¯ç»åãã¢ããããŒãããå Žåããã®çŽæã¯ç ŽãããŸãã ãã®ãããªã¢ã¯ã·ã§ã³ã®ç¹å®ã®çµæã¯å€§ããç°ãªãå¯èœæ§ããããŸããããã©ãŠã¶ãŒã«ã¯ãããåŠçããæš©å©ããªãããããã®åäœãåçŽã«æå¶ããŸãã ããã¯ãã³ãŒããŒã·ã§ããã§httpãä»ããŠã¹ã¯ãªãããèŠæ±ãããã©ãŠã¶ã§ã¡ãŒã«ã¯ã©ã€ã¢ã³ããéããªã©ãèªåã§ç解ã§ããªããŠãŒã¶ãŒãä¿è·ããããã ãã§ãªããäœããèŠéããŠããå¯èœæ§ãããã³ã³ãã³ãäœæè ã®ææšãšããŠãè¡ãããŸããã
ããã¯ãŠãŒã¶ãŒã«ãšã£ãŠã¯è¯ã解決çã§ããããµã€ããhttpsã«å€æããéã«Webãµã€ããªãã¬ãŒã¿ãŒã«ããã€ãã®å°é£ãäžããŸãã å®å šã§ãªãã³ã³ãã³ãã«ãªã³ã¯ãããã¹ãŠã®HTMLãªãœãŒã¹ã¯ãèŠåãçºããŠãŠãŒã¶ãŒãå£ãããæãããããããŸãã ãã®äŸåé¢ä¿ã®åé¡ã¯ããªãœãŒã¹ã®100ïŒ ãHTTPSã«è»¢éããããã«å æããå¿ èŠãããæ¬åœã®é害ã ãšæããŸãã
æ··åã³ã³ãã³ããä¿®æ£ãã
æ··åã³ã³ãã³ãã®åé¡ãä¿®æ£ããå¿ èŠãããå Žåã¯ãhttpsã«åãæ¿ããã³ã¹ãããããã«å¢å ããŸãã ããã¯ããµãŒããŒã®æ§æã蚌ææžã®ååŸãããå°ãè€éã§ã;æ··åã³ã³ãã³ãã®åé€ã¯é«äŸ¡ã§ãããåžžã«èªååã«å¯Ÿå¿ã§ãããšã¯éããŸããã
è€éãªãµã€ãã®å Žåããã¹ãŠã®ããŒãžã§s / http / https / gãå®è¡ããããmod_rewriteã§ã«ãŒã«ãèšè¿°ãããããããšã¯ã§ããŸããã httpãªãœãŒã¹ã¯ãéçã³ã³ãã³ããåçãããŒã¿ããŒã¹ã«ä¿åãããã¯ã©ã€ã¢ã³ãããµãŒãããŒãã£ã®ãªãœãŒã¹ããããŒã¿ãåä¿¡ãããªã©ãå€ãã®å Žæã§çºçããŸãã
éçºäžã®æ°ããä»æ§ã¯ ããã®ããã»ã¹ãä¿é²ããããšãç®çãšããŠããŸãã HTTPãªãœãŒã¹ãèªåçã«httpsã«çœ®ãæããã®ã«åœ¹ç«ã¡ãŸãã
å®å ïŒ

åŸïŒ

ãã®äŸã§ã¯ãUpgrade-Insecure-ResourcesãOriginAã¢ã¯ã»ã¹ã«åœ¹ç«ã¡ãŸããã ãããã³ã«ãèŠããªãããã«ã¹ããŒãã£ã³ã°ããããªã¢ãŒãäŸåé¢ä¿ãhttpsçµç±ã§å©çšå¯èœã«ãªã£ããããHTMLãªãœãŒã¹ã®1ã€ã«æ··åã³ã³ãã³ããå«ãŸããªããªããŸããã ãã®äŸã¯ãæããããšã©ãŒã¡ãã»ãŒãžãæ©èœã®æ¬ é¥ãé¿ããããã«ãå€ãã®ãµã€ããhttpsãä»ããŠç¬èªã®ã³ã³ãã³ããæäŸããããšãæžãçç±ã瀺ããŠããŸãã
ããã¯ãäŸåé¢ä¿ãã§ãŒã³ã®æåŸã«ããæã責任ã®äœãåå è ãé²è¡ã劚ããããšãã§ãããšããæ²ããç¶æ³ã«ã€ãªãããŸãã åšæçãªäŸåé¢ä¿ïŒWebã®åºå€§ãªæ§é ã«ç¢ºå®ã«ååšããããïŒã¯ã調æŽãªãã§ã¯è§£æ±ºã§ããªããããããã¯ãäœæããå¯èœæ§ããããŸãã
ãããã®ãµã€ãã¯ããããhttpsãæå¹ã«ã§ããŸãã

埪ç°äŸåé¢ä¿ã®è§£æ±º
httpãšhttpsã®éã«ååãªäžéç¶æ ããããŸããã ãã®æ¡ä»¶ã«æ¬¡ã®ããããã£ãããã°çæ³çã§ãã
1.éããã®ååã«éåããããšãªãããªãœãŒã¹ã«äŸåããå®å šãªãœãŒã¹ãããããåä¿¡ã§ããããã«ããŸãã
2.ä»ã®ãªãœãŒã¹ã«ãã»ãã¥ãªãã£ãŸãã¯æ··åã³ã³ãã³ãã®æ¬ åŠã«ã€ããŠæ¥ãã§çµè«ãäžãããšã匷å¶ããŸããã
3.ããã¯éåžžã«å®äŸ¡ã§ãããå®è£ ã®ãªã¹ã¯ãåŒãèµ·ãããŸããã çæ³çã«ã¯ãhttpããããŒãè¿œå ããŸãã
4.éããã®ååã«éåããäŸåé¢ä¿ã決å®ããããæ··åã³ã³ãã³ãã®ãšã©ãŒãäœæãããã§ããŸãã

OriginBã¯https-transitionalã¢ãŒãã«å ¥ããŸãã ã€ãŸããhttpsïŒ//ãä»ããŠãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšã¯ã§ããŸããããæå¹ãªèšŒææžãå«ãå®å šãªä¿èšŒä»ãã§TLSãä»ããŠå°æ¥å©çšã§ããããã«ãªããŸãã ãã©ãŠã¶ãšãŠãŒã¶ãŒã¯ãã®ãªãœãŒã¹ã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ã«ã€ããŠäœãç¥ããªããããOriginBã®ã³ã¹ãã¯ããããŸããã
OriginBãªãœãŒã¹ãhttps-transitionalãä»ããŠå©çšå¯èœã«ãªããŸããã OriginAã«ã¯HTTPSãå«ãŸããŠããŸãã ãã©ãŠã¶ã¯ãOriginBãžã®TLSæ¥ç¶ãéå§ããåŸæ¥ã®httpãããã³ã«ãä»ããŠãªãœãŒã¹ãèŠæ±ã§ããããšãç¥ã£ãŠããŸãã ãã®ãããã³ã«ã®å€æŽã倱æãããšããªãœãŒã¹ã¯å®å šã§ãªããšããŒã¯ãããæ··åã³ã³ãã³ãã«é¢ããèŠåã衚瀺ãããŸãã ãã¹ãŠãæ£åžžã«çµäºãããšããã©ãŠã¶ã䞻匵ãããã¹ãŠã®OriginAã»ãã¥ãªãã£ä¿èšŒãçã«ãªãããã¡ã€ã«ãhttpçµç±ã§è»¢éããããšããäºå®ã«ãããããããæ··åã³ã³ãã³ãã«é¢ããèŠåã¯ãããŸããã
ã¢ããã°ã¬ãŒãåŸãOriginA OriginCãã¢ããã°ã¬ãŒããããå ŽåããããŸãã OriginBã¯äŸç¶ãšããŠOriginDã«äŸåããŠããããããŸã httpsã«åãæ¿ããããšã¯ã§ããŸããããããã©ã³ãžãããã¢ãŒããæå¹ã«ãããšããªãœãŒã¹AãšBãhttpsçµç±ã§ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã®ç¶æ ãã©ã®ããã«äœæã§ããŸããïŒ
æ··åã³ã³ãã³ããå«ãããã¥ã¡ã³ããäœæããã«åŸªç°äŸåé¢ä¿ã解決ããã«ã¯ãContent-Typeããã¹ã/ htmlãè¿ãããšãã§ãããã®ãé€ããã¹ãŠã®èŠæ±ã«å¯ŸããŠ404ãè¿ããã£ã«ã¿ãŒãæ§æããå¿ èŠããããŸãã CORSã«é¢é£ããããã€ãã®ã±ãŒã¹ãé€ããããªãè¯ããœãªã¥ãŒã·ã§ã³ã å¿ èŠãª4ã€ã®ããããã£ã®ãã¡ããã®ã¢ãããŒãã§ã¯3ã€å®è£ ããŠããŸãã
4çªç®ã®ããããã£ã¯ãå®å šãªHTTPSãæå¹ã«ã§ããç¬éãç¥ãããã«ãäŸåé¢ä¿ã®ç¶æ ãå€æããæ©èœã§ãã ãã©ãŠã¶ãhttpããã¥ã¡ã³ãã«å¯ŸããŠãupgrade-insecure-requestsãã§Content-Security-Policy-Report-Onlyã䜿çšã§ããå Žåã¯ã©ããªããŸããïŒ
- ãããã³ã«ã眮ãæããããšããŠããŸã
- 倱æããå ŽåïŒhttpãžã®ããŒã«ããã¯ã管çè ãžã®ã¡ãã»ãŒãž
äžèšã®æé 以å€ã®æäœã¯å¿ èŠãªãå ŽåããããŸãã ãupgrade-insecure-requestsãã䜿çšãããã®æ§æã¯ãAãBãããã³Cã«å®è£ ãããŠããŸãã

iframe
æ®å¿µãªãããhttpsãä»ããHTMLã®ãªãœãŒã¹éä¿¡ã«åãæ¿ããã ãã§ã¯äžååã§ãããiframeãä»ããHTMLããHTMLãžã®äŸåé¢ä¿ã§ã¯æ©èœããŸããã ããã¯ãã䜿çšãããŸãã

ãããã³ã«ãTLSã«çœ®ãæããŠHTMLãªãœãŒã¹ãããŒãããæ©èœãå®çŸããå¿ èŠããããŸãããããã¯å®å šãªããŒãžã§ã®ã¿ã§ãã ãããã³ã«ã¹ããŒãã£ã³ã°ããªããã°ã³ã³ãã³ãã¯ãã§ã«å®å šã§ã¯ãªããããããã¯ã»ãã¥ãªãã£ã«éåããŸããããã®ãããOriginBãŠãŒã¶ãŒåãã®æ··åã³ã³ãã³ãã¯äœæããŸããã
ALPNããã³HTTP Alt-Svcã䜿çšããhttps-transitional
ALPNã§ã¯ãã¯ã©ã€ã¢ã³ãã䜿çšããå¥ã®ãããã³ã«ãæå®ããããšã«ãããã¯ã©ã€ã¢ã³ãã¯TLSãä»ããŠãµãŒããŒãšéä¿¡ã§ããŸãã
æ°ããã¿ã€ãã®ALPNãããã³ã«ãhttps-transitionalãã玹ä»ããŸãããã ãã®æ¹æ³ã§ã¯ã©ã€ã¢ã³ããããŒã¿ãèŠæ±ãããµãŒããŒã¯ãããããhttpã§ãµãŒããŒã«æ¥ç¶ããŸãããhttpsã§ã¯ãªãTLSã§æ¥ç¶ããŸãããšèªèããŸãã Alt-Svc HTTPãã©ããã§èª¬æãããŠããããã«ãTLSæ¥ç¶ãçºçãããµãŒããŒã¯ãã¡ã€ã³ã«äžèŽãã蚌ææžãæ瀺ããå¿ èŠããããŸãã
ãhttps-transitionalããä»ããŠéããããªãœãŒã¹ã«ã¯ã次ã®ããããã£ããããŸãã
- ãªãœãŒã¹ãæ··åã³ã³ãã³ããšããŠãããã¯ããªãã§ãã ããã
- ãhttps-transitionalããä»ããŠéä¿¡ãããããã¥ã¡ã³ãã®èšå®ã¯ãæ··åã³ã³ãã³ããçŠæ¢ãã¹ãã§ã¯ãããŸããã
- åã®ããããã£ã¯ãããã¥ã¡ã³ãã®èŠªãã¬ãŒã ãçŠæ¢ãããŸã§å®è¡ãããŸãã ãã®å Žåãupgrade-insecure-requestsã¯èªåçã«çºçããã¯ãã§ã
Upgrade-Insecure-Requestsã¯æ¬¡ã®ããã«å€æŽãããŸãã
- äŸåãªãœãŒã¹ã®ãããã³ã«ã¹ããŒãã£ã³ã°ã®å Žåãhttpsã«æ¥ç¶ããhttp / spdy / h2ã«å ããŠãæ°ãããhttps-transitionalãALPNãããã³ã«ãåªå ãããã³ã«ãšããŠè¿œå ããŸãã
- ãµãŒããŒããhttps-transitionalããç解ããŠããå Žåã¯ããã®ãããã³ã«ã䜿çšããŠå¿çããTLSãä»ããŠhttpãªãœãŒã¹ãé ä¿¡ããŸãã
- ãµãŒããŒããhttps-transitionalããç解ããŠããªãå Žåã¯ãhttpsã§è¿ä¿¡ããŸãã
æ··åã³ã³ãã³ãã®ãããã¯ãå€æŽããå¿ èŠããããŸãã äž¡æ¹ã®ã¹ããŒã ãåãã³ã³ãã³ããæäŸãããšããä¿èšŒããªãããããã©ãŠã¶ã¯çŸåšãhttpãhttpsã«èªåçã«çœ®ãæããããšã¯ããŠããŸããã ãhttps-transitionalãã®ã¹ããŒã ã¯ããã®ãããªä¿èšŒãæäŸããŸãã Servetã¯ãHTTP Alt-SvcããããŒã䜿çšããŠããã©ã³ãžããã¢ãŒãã®å¯çšæ§ãå ±åããããšãã§ããŸãã
転éäžã®ããã¥ã¡ã³ããããŠã³ããŒãããåŸããã©ãŠã¶ã¯ãæ··åã³ã³ãã³ããšããŠãããã¯ããããã¹ãŠã®æ¥ç¶ããupgrade-insecure-requestsãæå¹ã§ãããã®ããã«çœ®ãæããããšããŸãããååã®è©Šè¡ã倱æããå Žåã¯httpsã§éãã«ã³ã³ãã³ããããŠã³ããŒãããå¿ èŠããããŸã ãŸããã³ã³ãœãŒã«ã«ãšã©ãŒãåºåããå¿ èŠããããŸãã

äžèšã®å³ã¯ãäžèšã®ã«ãŒã«ã®å®è£ ã瀺ããŠããŸãã OriginBããã©ã³ãžããã¢ãŒãããµããŒãããŠãããããOriginAããããŠã³ããŒãããããªãœãŒã¹ã¯ãOriginBãæãiframeã«ã¯æ··åã³ã³ãã³ããå«ãŸããŸããã ãã ããOriginBãªãœãŒã¹ãæ··åã³ã³ãã³ãããããã¯ããããã¥ã¡ã³ãããããŒãããããããã³ã«ã眮ãæããããšãã§ããªããªãœãŒã¹ïŒOriginDã®JSãã¡ã€ã«ãªã©ïŒã«äŸåããŠããå Žåããã®ãããªèŠæ±ã¯éãã«ãããã¯ãããŸãã æ éãå®äºããããã«ã¯ãéšåçãªæå·ãæãŸããã§ãã OriginBããçŽæ¥ããŠã³ããŒããããOriginDã«äŸåãããªãœãŒã¹ã¯ãéããã®ååãå¿ èŠãªããããããã¯ãããŸããã
ããã©ãŒãã³ã¹ãžã®åœ±é¿
httpsãªãœãŒã¹ã®å Žåããã®ææ¡ã§ã¯ãUpgrade-Insecure-Requestsã䜿çšããå Žåãšæ¯èŒããŠãæ°ããé 延ã¯çºçããŸããã ãã©ãŠã¶ã¯TLSãåªå ãããããhttps移è¡ãµããŒãã決å®ããããã«æ°ãããªã¯ãšã¹ãã¯å¿ èŠãããŸããã
ããã©ãŒãã³ã¹ã倱ãå¯èœæ§ãããå¯äžã®å Žæã¯ãAlt-SvcããããŒã«ããæ¥ç¶ã®äº€æã§ãã ãã©ãŠã¶ã¯äŸåãããã¹ãŠã®ãªãœãŒã¹ãååž°çã«æŽæ°ããããšããŸããããã®äžéšã¯httpsçµç±ã§ã¯å©çšã§ããªãå Žåãããã倧ããªé 延ãçºçããå¯èœæ§ããããŸãã ãŸããäžå®ã®æéãç¹å®ã®ãœãŒã¹ã§TLSã䜿çšã§ããªãã£ãããšããŸãã¯äžŠååããããªã¯ãšã¹ããæãåºããŠããããä¿®æ£ããããšãã§ããŸãã ãããããæè¯ã®æŠç¥ã決å®ããããã«ããã€ãã®å®éšãå¿ èŠã§ãã
ããæç¹ã§ããã¹ãŠã®ãµã€ããhttpããé¢ããããšæãã§ãããã httpsãä»ããããŠã³ããŒããhttpã«ããŒã«ããã¯ããããšã¯ãããŸããããäžèšã®ã·ããªãªã§ã¯ãæ»æã䜿çšããŠæå·åãåé€ããããã«ãŒããä¿è·ããã«ã¯äžååã§ãã ç¹ã«æåã®ååšããµã€ãäžã®åãªã³ã¯ã®ãªã¯ãšã¹ãã¹ããŒã ãå€æŽããå¿ èŠãåé¿ããããšãæå³ããå Žåãã©ãããã°ãã©ã³ãžãããŠã§ãããå®å šã«ã»ãã¥ã¢ãªãŠã§ãã«ç§»è¡ã§ããŸããïŒ
HTTPããã³Alt-SvcããããŒãå®å šã«æŸæ£ããããµã€ãã®åé¡ã解決ããããã«äœæãããHTTP Strict Transport Securityã«åºã¥ããã¿ãŒã³ã®éçºãéå§ã§ããŸãã
管çè ãæåã«ã§ããããšã¯ãAlt-Svcãç¡éã«èšå®ããããšã§ããããã¯ããã©ãŠã¶ãhttpçµç±ã§æ¥ç¶ããããšãããåžžã«https-transitionalãšhttpsã®ã¿ã䜿çšããããã«ä¿¡å·ãéããŸãã ãã®åŸããµã€ãã¯ã¬ã¬ã·ã¯ã©ã€ã¢ã³ãã®httpãµããŒããæ®ãããå®å šã«ç¡å¹ã«ããŸãã
次ã®ã¹ãããã¯ããã©ã³ãžããã³ã³ãã³ãã«éå¯æ§ã®ååãé©çšããããšã§ãã ãããããããè¡ãæè¯ã®æ¹æ³ã¯ãHTTPããããŒã䜿çšããããšã§ãã ãéããªãããããèšå®ãããšãæ··åã³ã³ãã³ããçŠæ¢ãããŸãã ãŸãããã®ãªãœãŒã¹ãããã¯ã¢ã€ã³ã³ãåä¿¡ããããã€ã³ã¿ãŒãã§ã€ã¹ã«åæ§ã®å€æŽãåŒãèµ·ããããããå¯èœæ§ããããŸãã
ããæ¥ããã©ã³ãžããã¢ãŒãã®äŒæãååã§ããã°ããã©ãŠã¶ã¯httpã®æŸæ£ãéå§ã§ããŸãã ããããæåã¯ãèšå®å ã®ã¢ã€ãã ã®å€èŠ³ããããŠå€§ããªèŠåã®è¡šç€ºã§ãããã å€ãã®ãµã€ãã¯ç¡å¶éã®æéãéä¿¡äžã®ãŸãŸã«ãªãå¯èœæ§ããããŸããããŠãŒã¶ãŒã¯TLSãµã€ãã䜿çšããããšã§å©çãåŸãããšãã§ããŸãã