ããããããªãã®äœäººãã¯ãæè¿çºè¡šãããäºä»¶ã«ã€ããŠèããããšãããã§ãããã ç±³åœã®åå°äœã¡ãŒã«ãŒã§ããAllegro MicroSystem LLCã¯ã以åã®ITå°é家ã劚害è¡çºã§èšŽããŸããã ãã¡ã·ã¥ã»ããã«ã¯ãäŒç€Ÿã§14幎éåããŠãããæ°äŒèšå¹ŽåºŠã®æåã®é±ã«éèŠãªè²¡åããŒã¿ãç Žå£ããŸããã
ããã¯ã©ã®ããã«èµ·ãããŸãããïŒ
解任ãã2é±éåŸãPatelã¯ãŠã¹ã¿ãŒïŒç±³åœããµãã¥ãŒã»ããå·ïŒã®æ¬ç€Ÿã«å ¥ç€ŸããäŒæ¥ã®Wi-Fiãããã¯ãŒã¯ããã£ããããŸããã å ååãšè·å Žã®ã©ãããããã®è³æ Œæ å ±ã䜿çšããŠãPatelã¯äŒæ¥ãããã¯ãŒã¯ã«ãã°ã€ã³ããŸããã ãã®åŸã圌ã¯ã³ãŒããOracleã¢ãžã¥ãŒã«ã«å°å ¥ãã2016幎4æ1æ¥ïŒæ°äŒèšå¹ŽåºŠã®æåã®é±ïŒã«ãã®å®è¡ãããã°ã©ã ããŸããã ãã®ã³ãŒãã¯ãç¹å®ã®ããããŒãŸãã¯ãã€ã³ã¿ãŒãå¥ã®ããŒã¿ããŒã¹ããŒãã«ã«ã³ããŒããã¢ãžã¥ãŒã«ããåé€ããããšãç®çãšããŠããŸããã ã¡ããã©4æ1æ¥ã«ãããŒã¿ãã·ã¹ãã ããåé€ãããŸããã æ»æè ã¯Allegroãããã¯ãŒã¯ã«åæ³çã«ãã°ã€ã³ããããã圌ã®è¡åã¯ããã«ã¯æ°ã¥ããŸããã§ããã
äžè¬ã®äººã ã¯è©³çŽ°ãç¥ããŸããããã»ãšãã©ã®å ŽåãäŒæ¥ããããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããã«ãã¹ã¯ãŒãèªèšŒã䜿çšãããšããäºå®ã«ãããäºä»¶ãå¯èœã«ãªã£ãå¯èœæ§ãé«ãã§ãã 確ãã«ä»ã®ã»ãã¥ãªãã£åé¡ããããŸãããããã¹ã¯ãŒãã¯ãŠãŒã¶ãŒã«æ°ä»ãããã«çãŸããããšããããçãŸããè³æ Œæ å ±ã䜿çšããç¬éãŸã§ããã¹ã¯ãŒãã®çé£ã®äºå®ã¯æ€åºãããŸããã
匷åãª2èŠçŽ èªèšŒã®äœ¿çšãšæèœãªã»ãã¥ãªãã£ããªã·ãŒãšçµã¿åããããã¹ã¯ãŒãã®äœ¿çšã®çŠæ¢ã¯ãèšèŒãããŠããéçºãåé¿ããªããšããŠãããã®ãããªèšç»ã®å®è£ ã倧ãã劚ããå¯èœæ§ããããŸãã
äŒç€Ÿã®ã»ãã¥ãªãã£ã¬ãã«ãå€§å¹ ã«åäžããããã®ãããªäºä»¶ãã身ãå®ãæ¹æ³ã«ã€ããŠèª¬æããŸãã ããŒã¯ã³ãšæå·åïŒå€åœããã³åœå ïŒã䜿çšããŠãéèŠãªããŒã¿ã®èªèšŒãšçœ²åãæ§æããæ¹æ³ãåŠç¿ããŸãã
æåã®èšäºã§ã¯ãWindowsãã¡ã€ã³ã¢ã«ãŠã³ãã«ãã°ã€ã³ãããšãã«PKIã䜿çšããŠåŒ·åãª2èŠçŽ èªèšŒãèšå®ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
次ã®èšäºã§ã¯ãBitlockerã®æ§ææ¹æ³ãé»åã¡ãŒã«ã®ä¿è·æ¹æ³ãæãåçŽãªã¯ãŒã¯ãããŒã«ã€ããŠèª¬æããŸãã ã客æ§ãšãšãã«ãäŒæ¥ãªãœãŒã¹ãžã®å®å šãªã¢ã¯ã»ã¹ãšãVPNãä»ããå®å šãªãªã¢ãŒãã¢ã¯ã»ã¹ãèšå®ããŸãã
äºèŠçŽ èªèšŒ
çµéšè±å¯ãªã·ã¹ãã 管çè ãšã»ãã¥ãªãã£ãµãŒãã¹ã¯ããŠãŒã¶ãŒãã»ãã¥ãªãã£ããªã·ãŒãžã®ã³ã³ãã©ã€ã¢ã³ã¹ãéåžžã«æèããŠããªãããšãååã«èªèããŠãããã¹ããã«ãŒã«è³æ Œæ å ±ãæžãçããŠã³ã³ãã¥ãŒã¿ãŒã®æšªã«è²Œãä»ããããååã«ãã¹ã¯ãŒãã転éãããããããšãã§ããŸãã ããã¯ããã¹ã¯ãŒããè€éã§ïŒ6æåãè¶ ããç°ãªãã¬ãžã¹ã¿ãæ°åãç¹æ®æåã®æåã§æ§æãããŠããïŒèŠãã«ããå Žåã«ç¹ã«é »ç¹ã«çºçããŸãã ãã ãããã®ãããªããªã·ãŒã¯ãçç±ã«ãã管çè ã«ãã£ãŠèšå®ãããŸãã ããã¯ãèŸæžã®ãã¹ã¯ãŒãã®åçŽãªåæãããŠãŒã¶ãŒã¢ã«ãŠã³ããä¿è·ããããã«å¿ èŠã§ãã ãŸãã管çè ã¯ããã®æéäžã«è€éãªãã¹ã¯ãŒãã§ãã¯ãªã¢ããããšãçè«çã«å¯èœã§ãããšããçç±ã ãã§ãå°ãªããšã6ãæã«1åãã¹ã¯ãŒããå€æŽããããšããå§ãããŸãã
èªèšŒãšã¯äœããæãåºããŸãããã ç§ãã¡ã®å Žåãããã¯ãµããžã§ã¯ããŸãã¯ãªããžã§ã¯ãã®ä¿¡é Œæ§ã確èªããããã»ã¹ã§ãã ãŠãŒã¶ãŒèªèšŒã¯ããŠãŒã¶ãŒãèªèšŒããããã»ã¹ã§ãã
ãŸãã2èŠçŽ èªèšŒã¯ãå°ãªããšã2ã€ã®ç°ãªãæ¹æ³ã䜿çšããŠIDã確èªããå¿ èŠãããèªèšŒã§ãã
å®éã®2èŠçŽ èªèšŒã®æãåçŽãªäŸã¯ãããã¯ãšã³ãŒãã®çµã¿åããã«ããå®å šã§ãã ãã®ãããªé庫ãéãã«ã¯ãã³ãŒããç¥ããããŒãææããå¿ èŠããããŸãã
ããŒã¯ã³ãšã¹ããŒãã«ãŒã
ããããã2èŠçŽ èªèšŒãå®è£ ããæãä¿¡é Œæ§ãé«ãæãç°¡åãªæ¹æ³ã¯ãæå·åããŒã¯ã³ãŸãã¯ã¹ããŒãã«ãŒãã䜿çšããããšã§ãã ããŒã¯ã³ã¯ããªãŒããŒãšã¹ããŒãã«ãŒãã®äž¡æ¹ã§ããUSBããã€ã¹ã§ãã ãã®å Žåã®æåã®èŠå ã¯ããã€ã¹ã®æææš©ã®äºå®ã§ããã2çªç®ã¯ãã®PINã³ãŒãã®ç¥èã§ãã
ããŒã¯ã³ãŸãã¯ã¹ããŒãã«ãŒãã䜿çšããŠãããã ãã«äœ¿çšããã®ããã䟿å©ã§ãã ããããæŽå²çã«ããã·ã¢ã§ã¯ããŒã¯ã³ã䜿çšããããšãäžè¬çã«ãªããŸãããããŒã¯ã³ã¯çµã¿èŸŒã¿ãŸãã¯å€éšã®ã¹ããŒãã«ãŒããªãŒããŒã®äœ¿çšãå¿ èŠãšããªãããã§ãã ããŒã¯ã³ã«ãæ¬ ç¹ããããŸãã ããšãã°ãåçãå°å·ããŸããã
åçã¯å žåçãªã¹ããŒãã«ãŒããšãªãŒããŒã瀺ããŠããŸãã
ããããäŒæ¥ã®ã»ãã¥ãªãã£ã«æ»ããŸãã
ãã·ã¢ã®ã»ãšãã©ã®äŒæ¥ã§ã¯Windowsãã¡ã€ã³ãäžå¿ã«äŒæ¥ãããã¯ãŒã¯ãæ§ç¯ãããŠãããããWindowsãã¡ã€ã³ããå§ããŸãã
ãåç¥ã®ããã«ãWindowsãã¡ã€ã³ããªã·ãŒããŠãŒã¶ãŒèšå®ãActive Directoryã®ã°ã«ãŒãèšå®ã¯ãèšå€§ãªæ°ã®ã¢ããªã±ãŒã·ã§ã³ãšãããã¯ãŒã¯ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãæäŸããã³å¶éããŸãã
ãã¡ã€ã³ã®ã¢ã«ãŠã³ããä¿è·ããããšã«ãããã»ãšãã©ã®ãå Žåã«ãã£ãŠã¯ãã¹ãŠã®å éšæ å ±ãªãœãŒã¹ãä¿è·ã§ããŸãã
PINã³ãŒãã䜿çšããããŒã¯ã³ãã¡ã€ã³ã§ã®2èŠçŽ èªèšŒã¯ãéåžžã®ãã¹ã¯ãŒãã¹ããŒã ããå®å šãªã®ã¯ãªãã§ããïŒ
PINã³ãŒãã¯ç¹å®ã®ããã€ã¹ïŒãã®å Žåã¯ããŒã¯ã³ïŒã«é¢é£ä»ããããŠããŸãã PINã³ãŒãã ããç¥ã£ãŠãããšããŸããããŸããã
ããšãã°ãããŒã¯ã³ããã®PINã³ãŒãã¯é»è©±ã§ä»ã®äººã«å£è¿°ããããšãã§ããããã¯ããŒã¯ã³ã«åå泚æããç¡äººã®ãŸãŸã«ããªããšæ»æè ã«äœãäžããŸããã
ãã¹ã¯ãŒãã䜿çšãããšãç¶æ³ã¯ãŸã£ããç°ãªããŸããæ»æè ããã¡ã€ã³ã®ã¢ã«ãŠã³ããããã¹ã¯ãŒããååŸãæšæž¬ãã¹ãã€ããŸãã¯äœããã®åœ¢ã§æŒåããå Žåãæ»æè ã¯ãã¡ã€ã³èªäœãšããã䜿çšããä»ã®äŒæ¥ãµãŒãã¹ã®äž¡æ¹ãèªç±ã«å ¥åã§ããŸãåãã¢ã«ãŠã³ãã
ããŒã¯ã³ã¯ãã³ããŒã§ããªãäžæã®ç©çãªããžã§ã¯ãã§ãã æ£åœãªãŠãŒã¶ãŒãããŸãã ããŒã¯ã³ã«ãã2èŠçŽ èªèšŒã¯ã管çè ãæå³çã«ãŸãã¯ç£èŠã«ãã£ãŠã·ã¹ãã ã®ãæãç©Žããæ®ããå Žåã«ã®ã¿åé¿ã§ããŸãã
ããŒã¯ã³ã§ãã¡ã€ã³ãå ¥åããå©ç¹
ããŒã¯ã³ããã®PINã³ãŒãã¯ããã¹ã¯ãŒããããã¯ããã«åçŽã§ãããããèŠããããã§ãã ãçµéšã®ããããŠãŒã¶ãŒãããå®å šãªããã¹ã¯ãŒããèŠããŠå ¥åããããšã§ãæ°åã®è©Šè¡ã§ã·ã¹ãã ãèªèšŒããããšãã§ããªãããšãã人çã§å°ãªããšãäžåºŠã¯èŠãããšãããã¯ãã§ãã
ããŒã¯ã³ã¯PINã³ãŒãã®æ€çŽ¢ã«å¯ŸããŠããèæ§ããããããPINã³ãŒããåžžã«å€æŽããå¿ èŠã¯ãããŸããã äœåºŠãå ¥åã«å€±æãããšãããŒã¯ã³ã¯ãããã¯ãããŸãã
ãŠãŒã¶ãŒã«ããŒã¯ã³ã䜿çšããå Žåãã·ã¹ãã ãžã®ãã°ã€ã³ã¯æ¬¡ã®ããã«ãªããŸããã³ã³ãã¥ãŒã¿ãŒãããŒãããåŸãããŒã¯ã³ãã³ã³ãã¥ãŒã¿ãŒã®USBããŒãã«æ¥ç¶ãã4ã6æ¡ãå ¥åããŠEnterãã¿ã³ãæŒããŸãã äžè¬ã®äººã ã®æ°åã®å ¥åé床ã¯ãæåã®å ¥åé床ãããéãã ãããã£ãŠãPINã³ãŒãã®å ¥åãéããªããŸãã
ããŒã¯ã³ã䜿çšãããšããæŸæ£ãããè·å Žãã®åé¡ã解決ã§ããŸãããŠãŒã¶ãŒãè·å Žãé¢ããã¢ã«ãŠã³ããããã°ã¢ãŠãããã®ãå¿ããå Žåã§ãã
ãã¡ã€ã³ããªã·ãŒã¯ãããŒã¯ã³ãååŸããããšãã«ã³ã³ãã¥ãŒã¿ãŒãèªåçã«ããã¯ãããããã«æ§æã§ããŸãã ãŸããããŒã¯ã³ã«ã¯äŒç€Ÿã®æ·å°å ãééããããã®RFIDã¿ã°ãè£ åããããšãã§ãããããè·å ŽããããŒã¯ã³ãæŸãããšãªããåŸæ¥å¡ã¯é åå ã移åããããšã¯ã§ããŸããã
æ¬ ç¹ããããããªãå Žå
ããŒã¯ã³ãŸãã¯ã¹ããŒãã«ãŒãã¯ç¡æã§ã¯ãããŸããïŒäºç®ïŒã
ããããèæ ®ãã管çããç¶æããå¿ èŠããããŸãïŒããŒã¯ã³ç®¡çã·ã¹ãã ãšã¹ããŒãã«ãŒãã«ãã£ãŠè§£æ±ºãããŸãïŒã
äžéšã®æ å ±ã·ã¹ãã ã¯ãããã®ãŸãŸãããŒã¯ã³ã«ããèªèšŒããµããŒãããŠããªãå ŽåããããŸãïŒã·ã³ã°ã«ã¢ã«ãŠã³ãã䜿çšããŠå°åã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããå¯èœæ§ãæŽçããããã«èšèšãããã·ã³ã°ã«ãµã€ã³ãªã³ã·ã¹ãã ã«ãã£ãŠè§£æ±ºãããŸãïŒã
Windowsãã¡ã€ã³ã§2èŠçŽ èªèšŒãæ§æãã
çè«çãªéšåïŒ
Active Directoryãã£ã¬ã¯ããªãµãŒãã¹ã¯ãWindows 2000以éãã¹ããŒãã«ãŒããšããŒã¯ã³ã«ããèªèšŒããµããŒãããŠããŸããKerberosRFC 4556ãããã³ã«ã®PKINITæ¡åŒµæ©èœïŒå ¬éããŒã®åæå-å ¬éããŒã®åæåïŒã«çµã¿èŸŒãŸããŠããŸãã
Kerberosã¯ã匷åãªãŠãŒã¶ãŒèªèšŒãæäŸããããã«ç¹å¥ã«èšèšãããŠããŸãã èªèšŒããŒã¿ã®éäžã¹ãã¬ãŒãžã䜿çšã§ããSingle Sing-Onã¡ã«ããºã ãæ§ç¯ããåºç€ãšãªããŸãã ãããã³ã«ã¯ãããŒãšã³ãã£ãã£ãã±ããïŒãã±ããïŒã«åºã¥ããŠããŸãã
ãã±ããïŒãã±ããïŒã¯ãKerberosãããã³ã«ïŒããŒé åžã»ã³ã¿ãŒïŒKDCãããŒé åžã»ã³ã¿ãŒïŒïŒã®èŠ³ç¹ãããä¿¡é Œã§ããèªèšŒã»ã³ã¿ãŒã«ãã£ãŠçºè¡ãããæå·åãããããŒã¿ãã±ããã§ãã
ãŠãŒã¶ãŒãèªèšŒã«æåããåŸã«ãã©ã€ããªèªèšŒãå®è¡ãããšãKDCã¯ãããã¯ãŒã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®ãã©ã€ããªãŠãŒã¶ãŒID-ãã±ããèš±å¯ãã±ããïŒTGTïŒãçºè¡ããŸãã
ãã®åŸããŠãŒã¶ãŒã¯åã ã®ãããã¯ãŒã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããšãã«ãTGTãéä¿¡ããç¹å®ã®ãããã¯ãŒã¯ãªãœãŒã¹-ãã±ããèš±å¯ãµãŒãã¹ïŒTGSïŒã«ã¢ã¯ã»ã¹ããããã®èšŒææžãKDCããåãåããŸãã
é«ã¬ãã«ã®ã»ãã¥ãªãã£ãæäŸããKerberosãããã³ã«ã®å©ç¹ã®1ã€ã¯ã察話äžã«ãã¹ã¯ãŒãããã¹ã¯ãŒãã®ã¯ãªã¢ããã·ã¥å€ãéä¿¡ãããªãããšã§ãã
PKINITæ¡åŒµã«ãããKerberosäºåèªèšŒæ®µéã§ããŒã¯ã³ãŸãã¯ã¹ããŒãã«ãŒãã«ãã2èŠçŽ èªèšŒã䜿çšã§ããŸãã
ãã°ã€ã³ã¯ããã¡ã€ã³ãã£ã¬ã¯ããªãµãŒãã¹ãšããŒã«ã«ãã£ã¬ã¯ããªãµãŒãã¹ã®äž¡æ¹ã䜿çšããŠæäŸã§ããŸãã TGTã¯ãã¹ããŒãã«ãŒããŸãã¯ããŒã¯ã³ã§èšç®ãããé»å眲åã«åºã¥ããŠäœæãããŸãã
ã¯ã©ã€ã¢ã³ããšãµãŒããŒã®çžäºèªèšŒã®ããã»ã¹ãå®è£ ãããŠããããããã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã«èšŒææžãã¡ã€ã³ã³ã³ãããŒã©ãŒèªèšŒãŸãã¯KerberosèªèšŒãã€ã³ã¹ããŒã«ãããŠããå¿ èŠããããŸãã
ç·Žç¿ïŒ
èšå®ããŸãããã
ããŒã¯ã³ãæ瀺ããPINã³ãŒããç¥ã£ãŠããå Žåã«ã®ã¿ãã¢ã«ãŠã³ãã®ãã¡ã€ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ã«ã¯ãAktivãäœæããPKI Rutoken EDSã䜿çšããŸãã
ã¹ããŒãž1-ãã¡ã€ã³ã®ã»ããã¢ããæåã«ãèªèšŒãµãŒãã¹ãã€ã³ã¹ããŒã«ããŸãã
å 責äºé
ãã®èšäºã¯ããšã³ã¿ãŒãã©ã€ãºPKIã®å®è£ ã«é¢ãããã¥ãŒããªã¢ã«ã§ã¯ãããŸããã PKIã®èšèšãå±éãããã³æèœãªäœ¿çšã®åé¡ã¯ããã®ãããã¯ãåºå€§ã§ãããããããã§ã¯èæ ®ããŸããã
ãã®ãããªãœãªã¥ãŒã·ã§ã³ãå®è£ ãããŠãããã©ã¬ã¹ãå ã®ãã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒãšãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒã¯ãã«ãŒã蚌ææ©é¢ïŒèªèšŒæ©é¢ïŒã確å®ã«ä¿¡é Œããå¿ èŠããããŸãã
蚌ææ©é¢ã®ç®çã¯ãé»å眲å蚌ææžã䜿çšããŠæå·åããŒã®ä¿¡é Œæ§ãæ€èšŒããããšã§ãã
æè¡çã«ã¯ã蚌ææ©é¢ã¯ããŠãŒã¶ãŒã®æå·åããŒã管çããã°ããŒãã«ãã£ã¬ã¯ããªãµãŒãã¹ã®ã³ã³ããŒãã³ããšããŠå®è£ ãããŸãã å ¬éããŒããã³ãã®ä»ã®ãŠãŒã¶ãŒæ å ±ã¯ã蚌ææ©é¢ã«ãã£ãŠããžã¿ã«èšŒææžã®åœ¢åŒã§ä¿åãããŸãã
ã¹ããŒãã«ãŒããŸãã¯ããŒã¯ã³ã䜿çšããããã®èšŒææžãçºè¡ãã蚌ææ©é¢ã¯ãNT Authorityãªããžããªã«é 眮ããå¿ èŠããããŸãã
ãµãŒããŒãããŒãžã£ãŒã«ç§»åãã[圹å²ãšæ©èœã®è¿œå ]ãéžæããŸãã
ãµãŒããŒã®åœ¹å²ãè¿œå ãããšãã¯ããActive Directory蚌ææžãµãŒãã¹ããéžæããŸãïŒããã©ãŒãã³ã¹ã®åé¡ãçºçããªãããã«ããã¡ã€ã³ã³ã³ãããŒã©ãŒã§ã¯ãããè¡ããªãããšã匷ããå§ãããŸãïŒã éãããŠã£ã³ããŠã§ããã³ã³ããŒãã³ãã®è¿œå ããéžæãããèªèšŒå±ããéžæããŸãã
ã³ã³ããŒãã³ãã®ã€ã³ã¹ããŒã«ã確èªããããŒãžã§ããã€ã³ã¹ããŒã«ããã¯ãªãã¯ããŸãã
ã¹ããŒãž2-ããŒã¯ã³ã䜿çšããŠãã¡ã€ã³ãšã³ããªãèšå®ãã
ã·ã¹ãã ã«å ¥ãã«ã¯ãã¹ããŒãã«ãŒããã°ãªã³ããã³ã¯ã©ã€ã¢ã³ãèªèšŒèå¥åãå«ã蚌ææžãå¿ èŠã§ãã
ã¹ããŒãã«ãŒããŸãã¯ããŒã¯ã³ã®èšŒææžã«ã¯ããŠãŒã¶ãŒã®UPNïŒãŠãŒã¶ãŒããªã³ã·ãã«åã®ãµãã£ãã¯ã¹ïŒãå«ããå¿ èŠããããŸãã æ¢å®ã§ã¯ãã¢ã«ãŠã³ãã®ãŠãŒã¶ãŒããªã³ã·ãã«åã®ãµãã£ãã¯ã¹ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããå«ãDNSãã¡ã€ã³åã§ãã
蚌ææžãšç§å¯ããŒã¯ã¹ããŒãã«ãŒããŸãã¯ããŒã¯ã³ã®é©åãªã»ã¯ã·ã§ã³ã«é 眮ããå¿ èŠããããŸãããç§å¯ããŒã¯ããã€ã¹ã®ã¡ã¢ãªã®ä¿è·é åã«é 眮ããå¿ èŠããããŸãã
蚌ææžã¯ã蚌ææžå€±å¹ãªã¹ãã®é åžãã€ã³ãïŒCRLé åžãã€ã³ãïŒãžã®ãã¹ãæå®ããå¿ èŠããããŸãã ãã®ãããªãã¡ã€ã«ã«ã¯ã蚌ææžã®ã·ãªã¢ã«çªå·ã倱å¹æ¥ã倱å¹çç±ã瀺ã蚌ææžã®ãªã¹ããå«ãŸããŠããŸãã 倱å¹ãã蚌ææžã«é¢ããæ å ±ãã蚌ææžã®ä¿¡é Œæ§ãæ€èšŒããããšãããŠãŒã¶ãŒãã³ã³ãã¥ãŒã¿ãŒãããã³ã¢ããªã±ãŒã·ã§ã³ã«è»¢éããããã«äœ¿çšãããŸãã
ã€ã³ã¹ããŒã«æžã¿ã®èªèšŒãµãŒãã¹ãæ§æããŸãã å³äžé ã«ããæå笊ã®ä»ããé»è²ã®äžè§åœ¢ãã¯ãªãã¯ããã蚌ææžãµãŒãã¹ã®æ§æ...ããã¯ãªãã¯ããŸãã
[è³æ Œæ å ±]ãŠã£ã³ããŠã§ã圹å²ãæ§æããããã«å¿ èŠãªãŠãŒã¶ãŒè³æ Œæ å ±ãéžæããŸãã èªèšŒå±ãéžæããŸãã
ãšã³ã¿ãŒãã©ã€ãºCAãéžæããŸã
ãšã³ã¿ãŒãã©ã€ãºCAã¯ADãšçµ±åãããŠããŸãã ADã§èšŒææžãšèšŒææžå€±å¹ãªã¹ããå ¬éããŸãã
ãã«ãŒãCAãã®ã¿ã€ããæå®ããŸãã
次ã®ã¹ãããã§ããæ°ããç§å¯éµãäœæããããéžæããŸãã
蚌ææžã®æå¹æéãéžæããŸãã
ã¹ããŒãž3-蚌ææžãã³ãã¬ãŒãã®è¿œå
蚌ææžãã³ãã¬ãŒããè¿œå ããã«ã¯ãã³ã³ãããŒã«ããã«ãéãã[管çããŒã«]ãéžæããŠãèªèšŒå±ãéããŸãã
ãã©ã«ããCertificate Templatesãã®ååãã¯ãªãã¯ãããManagementããéžæããŸãã
ãã³ãã¬ãŒãã®ååãã¹ããŒãã«ãŒããŠãŒã¶ãŒããã¯ãªãã¯ããããã³ãã¬ãŒãã®ã³ããŒããéžæããŸãã 以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ããæ°èŠãã³ãã¬ãŒãããããã£ããŠã£ã³ããŠã®ã©ã®ãã©ã¡ãŒã¿ãå€æŽããå¿ èŠããããã瀺ããŠããŸãã
ãµãã©ã€ã€ãŒã®ãªã¹ãã«ãAktiv ruToken CSP v1.0ããå«ãŸããŠããªãå ŽåããRootoken Drivers for Windowsãããããã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
Windows Server 2008 R2以éã補é å ã®ç¹å¥ãªãããã€ããŒã®ä»£ããã«ããMicrosoft Base Smart Card Crypto Providerãã䜿çšã§ããŸãã
Rootokenããã€ã¹ã®å ŽåããMicrosoft Base Smart Card Crypto ProviderãããµããŒããããminidriverãã©ã€ãã©ãªã¯ãWindows Updateãä»ããŠé åžãããŸãã
ããããã©ã€ããŒãããµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠãããã©ããã確èªããã«ã¯ãRutokenããµãŒããŒã«æ¥ç¶ããããã€ã¹ãããŒãžã£ãŒã確èªããŸãã
äœããã®çç±ã§ããããã©ã€ããããªãå Žåã¯ããRootoken Drivers for Windowsãããããã€ã³ã¹ããŒã«ãããMicrosoft Base Smart Card Crypto Providerãã䜿çšããŠåŒ·å¶çã«ã€ã³ã¹ããŒã«ã§ããŸãã
Rootoken Drivers for Windows Kitã¯ã Rutokenãµã€ãããç¡æã§é åžãããŠããŸãã
ãèªèšŒãšãŒãžã§ã³ãããšãã«ãŒãã±ã³ã®ãŠãŒã¶ãŒãã®2ã€ã®æ°ãããã³ãã¬ãŒããè¿œå ããŸãã
ãããè¡ãã«ã¯ãããã³ãã¬ãŒã管çããŠã£ã³ããŠãçµäºããŸãã ã蚌ææžãã³ãã¬ãŒãããå³ã¯ãªãã¯ããŠããäœæãã¡ãã¥ãŒé ç®ãšãçºè¡ããã蚌ææžãã³ãã¬ãŒãããµãé ç®ãéžæããŸãã
次ã«ããç»é²ãšãŒãžã§ã³ãããšãRutokenã®ãŠãŒã¶ãŒããéžæãããOKããã¯ãªãã¯ããŸãã
ãã®çµæããããã®ãã³ãã¬ãŒãã®ååã蚌ææ©é¢ã«è¡šç€ºãããŸãã
次ã«ããã¡ã€ã³ç®¡çè ã«èšŒææžãçºè¡ããå¿ èŠããããŸãã RunãµãŒãã¹ãéãã mmcã³ãã³ããæå®ããŸãã 蚌ææžã¹ãããã€ã³ãè¿œå ããŸãã
[蚌ææžãããŒãžã£ãŒã¹ãããã€ã³]ãŠã£ã³ããŠã§ã[ãŠãŒã¶ãŒã¢ã«ãŠã³ã]ãéžæããŸãã [ã¹ãããã€ã³ã®è¿œå ãšåé€]ãŠã£ã³ããŠã§ã蚌ææžã®è¿œå ã確èªããŸãã
[蚌ææž]ãã©ã«ããŒãéžæããŸãã
æ°ãã蚌ææžãèŠæ±ããŸãã 蚌ææžãç»é²ããããŒãžãéããŸãã 蚌ææžãèŠæ±ãã段éã§ãç»é²ããªã·ãŒã管çè ããéžæãããã¢ããªã±ãŒã·ã§ã³ããã¯ãªãã¯ããŸãã
åæ§ã«ãç»é²ãšãŒãžã§ã³ãã®èšŒææžãèŠæ±ããŸãã
ç¹å®ã®ãŠãŒã¶ãŒã®èšŒææžãèŠæ±ããã«ã¯ã[蚌ææž]ãã¯ãªãã¯ãã[代çã§ç»é²...]ãéžæããŸãã
蚌ææžãèŠæ±ããããã®ãŠã£ã³ããŠã§ããRootokenãæã€ãŠãŒã¶ãŒããã§ãã¯ããã¯ã¹ãéžæããŸãã
次ã«ããŠãŒã¶ãŒãéžæããå¿ èŠããããŸãã
[éžæãããªããžã§ã¯ãã®ååãå ¥å]ãã£ãŒã«ãã§ããã¡ã€ã³å ã®ãŠãŒã¶ãŒåãæå®ãã[ååã®ç¢ºèª]ãã¯ãªãã¯ããŸãã
ãŠãŒã¶ãŒãéžæããããã®ãŠã£ã³ããŠã§ããã¢ããªã±ãŒã·ã§ã³ããã¯ãªãã¯ããŸãã
ããããããŠã³ãªã¹ãã§ãããŒã¯ã³åãéžæããPINã³ãŒããæå®ããŸãã
åæ§ã«ããã¡ã€ã³å ã®ä»ã®ãŠãŒã¶ãŒã®èšŒææžãéžæããŸãã
ã¹ããŒãž4-ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®èšå®
ã¢ã«ãŠã³ããèšå®ããã«ã¯ãADãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ããéããŸãã
[ãŠãŒã¶ãŒ]ãã©ã«ããŒãš[ããããã£]é ç®ãéžæããŸãã
[ã¢ã«ãŠã³ã]ã¿ãã«ç§»åãã[ãããã¯ãŒã¯ãžã®å¯Ÿè©±åã¢ã¯ã»ã¹ã«ã¯ã¹ããŒãã«ãŒããå¿ èŠã§ã]ããã¯ã¹ããªã³ã«ããŸãã
ã»ãã¥ãªãã£ããªã·ãŒãæ§æããŸãã ãããè¡ãã«ã¯ãã³ã³ãããŒã«ããã«ãéãã[管ç]ãéžæããŸãã ã¡ãã¥ãŒãéããŠã°ã«ãŒãããªã·ãŒã管çããŸãã
[ã°ã«ãŒãããªã·ãŒç®¡ç]ãŠã£ã³ããŠã®å·ŠåŽã§ã[ããã©ã«ããã¡ã€ã³ããªã·ãŒ]ãã¯ãªãã¯ãã[å€æŽ]ãéžæããŸãã
[ã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒ]ãŠã£ã³ããŠã®å·ŠåŽã§ã[ã»ãã¥ãªãã£èšå®]é ç®ãéžæããŸãã
Interactive LoginïŒRequire Smart Cardããªã·ãŒãéããŸãã
[ã»ãã¥ãªãã£ããªã·ãŒã®èšå®]ã¿ãã§ã[次ã®ããªã·ãŒèšå®ãå®çŸ©ãã]ãã§ãã¯ããã¯ã¹ããªã³ã«ããŸãã
Interactive LoginïŒSmart Card Removal Behaviorããªã·ãŒãéããŸãã
[ã»ãã¥ãªãã£ããªã·ãŒèšå®]ã¿ãã§ã[次ã®ããªã·ãŒèšå®ãå®çŸ©ãã]ãã§ãã¯ããã¯ã¹ããªã³ã«ããããããããŠã³ãªã¹ããã[ã¯ãŒã¯ã¹ããŒã·ã§ã³ããã¯]ãéžæããŸãã
ã³ã³ãã¥ãŒã¿ãŒãåèµ·åããŸãã ãããŠã次åãã¡ã€ã³ã§èªèšŒãè©Šã¿ããšãã«ãããŒã¯ã³ãšãã®PINã³ãŒãããã§ã«äœ¿çšã§ããŸãã
ãã³ãŽïŒ
ãã¡ã€ã³ã«å ¥ãããã®2èŠçŽ èªèšŒãæ§æãããŠããŸããã€ãŸããè¿œå ã®ã»ãã¥ãªãã£æ©èœã«æ£æ°ãè²»ããããšãªããWindowsãã¡ã€ã³ã«å ¥ãããã®ã»ãã¥ãªãã£ã¬ãã«ãå€§å¹ ã«åäžããŸãã çŸåšãããŒã¯ã³ãªãã§ã¯ã·ã¹ãã ãžã®ãã°ã€ã³ã¯äžå¯èœã§ããããŠãŒã¶ãŒã¯èœã¡çããŠæ¯ãããããšãã§ããè€éãªãã¹ã¯ãŒãã«æ©ãŸãããããšã¯ãããŸããã
次ã®ã¹ãããã¯å®å šãªã¡ãŒã«ã§ãã次ã®èšäºã§ãããã«ã€ããŠãããã³ä»ã®ã·ã¹ãã ã§ã®å®å šãªèªèšŒã®èšå®ã«ã€ããŠèªãã§ãã ããã