çŸåšãHTTPSã¯ãã¹ãŠã®Webãµã€ãã«å¿ èŠã§ã ããŠãŒã¶ãŒã¯å人ããŒã¿ã転éãããšãã«ã¢ãã¬ã¹ããŒã§ããã¯ãæ¢ããŸãã Chromeããã³Firefoxã¯ãHTTPSã䜿çšããªãããŒãžäžã®ãã©ãŒã ã䜿çšããŠãå®å šã§ãªãWebãµã€ããšããŠæ瀺çã«ãã©ã°ãç«ãŠãŸãã ããã¯ãæ€çŽ¢çµæã®äœçœ®ã« 圱é¿ãããã©ã€ãã·ãŒå šè¬ã«æ·±å»ãªåœ±é¿ãåãŒããŸãã ããã«ãç¡æã®èšŒææžãååŸããããã®ããã€ãã®ãªãã·ã§ã³ãçšæãããŠãããããHTTPSãžã®åãæ¿ãã¯å¿ èŠãªããšã§ãã
HTTPSã®ã€ã³ã¹ããŒã«ã¯ãæºåãã§ããŠããªããŠãŒã¶ãŒã«ãšã£ãŠã¯å°ãæããããã®ã§ããããŸããŸãªé¢ä¿è ãé¢äžããå€ãã®æé ãããã³æå·åãšãµãŒããŒæ§æã®ç¹å®ã®ç¥èãå¿ èŠã§ãããäžè¬ã«è€éã«æããŸãã
ãã®ã¬ã€ãã§ã¯ãåã ã®ã³ã³ããŒãã³ããšæé ã説æããã€ã³ã¹ããŒã«ã®åæé ãæ確ã«è¿°ã¹ãŸãã ç¹ã«ããã¹ãã£ã³ã°äºæ¥è èªäœãHTTPS蚌ææžãæäŸããŠããå Žåã¯ããã¹ãŠãã¹ã ãŒãºã«è¡ãããŸããã³ã³ãããŒã«ããã«ãé¢ããããšãªãããã¹ãŠããã°ããç°¡åã«å®è¡ã§ããå¯èœæ§ãé«ããªããŸãã
ããã«ã¯ãcPanelå ±æãã¹ãã£ã³ã°ææè ãLinuxããã³Unixã®Apache HTTPããã³nginxãµãŒããŒç®¡çè ãããã³Windowsã®Internet Information Serverã®è©³çŽ°ãªæé ãå«ãŸããŸãã
åºæ¬ããå§ããŸãããã
HTTPãHTTPSãHTTP / 2ãSSLãTLSïŒã©ãã§ïŒ
å€ãã®é åèªã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®éä¿¡ããã»ã¹ã説æããããã«äœ¿çšãããŸãã æè¡çãªæ¬è³ªã«äžæ £ããªäººã¯ããã°ãã°ããããæ··åããŸãã
ãã€ããŒããã¹ã転éãããã³ã«ïŒHTTPïŒã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒãæ¥ç¶ã確ç«ããããã«ãµããŒãããå¿ èŠãããäž»èŠãªéä¿¡ãããã³ã«ã§ãã èŠæ±ãšå¿çãã»ãã·ã§ã³ããã£ãã·ã³ã°ãèªèšŒãªã©ã®æŠå¿µã«ã€ããŠèª¬æããŸãã1989幎ã«CERNã®Tim Berners-Lee byãšåœŒã®ã°ã«ãŒãã«ãã£ãŠå§ãããããããã³ã«ãšHypertext Markup LanguageïŒHTMLïŒã®äœæ¥ã ãããã³ã«ã®æåã®å ¬åŒããŒãžã§ã³ïŒHTTP 1.0ïŒã¯1996幎ã«ãªãªãŒã¹ãããããã«1997幎ã«HTTP 1.1ã®ããŒãžã§ã³ãç»å ŽããŸãããããã¯ä»æ¥åºã䜿çšãããŠããŸãã
ãã®ãããã³ã«ã¯ããã©ãŠã¶ãŒãšãµãŒããŒã®éã§ã¯ãªã¢ããã¹ãã§æ å ±ãéä¿¡ãããããééãããããã¯ãŒã¯äžã§ãã®æ å ±ãèŠãããšãã§ããŸãã ããã¯ã»ãã¥ãªãã£äžã®åé¡ã§ããããã HTTP SecureïŒHTTPSïŒãçºæãããŸãããããã«ãããã¯ã©ã€ã¢ã³ããšãµãŒããŒã¯æå·åãããéä¿¡ãã£ãã«ã確ç«ãããã®ãã£ãã«ã§ã¯ãªã¢ããã¹ãã§ã¡ãã»ãŒãžãéä¿¡ããŠããªã¹ãã³ã°ããå¹æçã«ä¿è·ããŸãã
SSLãšTLSãšããçšèªã¯ãTLS 1.0ãSSL 3.0ã®ä»£ããã«ãªãããããã°ãã°äº€æå¯èœã«äœ¿çšãããŸãã SSLèªäœã¯Netscapeã«ãã£ãŠéçºãããTLSã¯IETFæšæºã§ãã ãã®èšäºã®å·çæç¹ã§ã¯ããã¹ãŠã®SSLããŒãžã§ã³ïŒ1.0ã2.0ã3.0ïŒã¯ãããŸããŸãªã»ãã¥ãªãã£åé¡ã®ããã«äœ¿çšããããšã¯ãå§ãã§ããŸãããææ°ã®ãã©ãŠã¶ãŒã§ã¯ããã«ã€ããŠèŠåã衚瀺ãããŸãã TLSæšæºãããããŒãžã§ã³1.0ã1.1ãããã³1.2ã䜿çšãããããŒãžã§ã³1.3ã¯çŸåšãã©ãã段éã«ãããŸãã
1996幎ãã1997幎ã®éã«ãææ°ã®ã€ã³ã¿ãŒãããïŒSSLããã³TLSã䜿çšãŸãã¯äœ¿çšããªãHTTP 1.1ïŒã®çŸåšã®å®å®ããŒãžã§ã³ãå ¥æããŸããã 以åã¯ãHTTPã¯éèŠã§ã¯ãªããã©ãã£ãã¯ïŒãã¥ãŒã¹ã®èªã¿åããªã©ïŒã«äœ¿çšãããHTTPSã¯éèŠãªãã©ãã£ãã¯ïŒèªèšŒãeã³ããŒã¹ãªã©ïŒã«äœ¿çšãããŠããŸããããã ãããã©ã€ãã·ãŒã®äŸ¡å€ãé«ãŸããšãGoogle Chromeãªã©ã®ãã©ãŠã¶ãŒã¯HTTPæ©å¯ããšå°æ¥çã«ãããã®æ°ããèŠåã衚瀺ãããŸãã
å¢å ãããµã€ãã§ãµããŒããããHTTPãããã³ã«ã®æ¬¡ã®æŽæ°-HTTP / 2-é 延ãæžãããããã©ãŒãã³ã¹ãšã»ãã¥ãªãã£ãåäžãããããã«ãæ°ããæ©èœïŒå§çž®ãå€éåãããŸããŸãªãã©ãã£ãã¯ã®åªå 床ïŒãå®è£ ããŸãã
HTTPããŒãžã§ã³1.1ã§ã¯ãã»ãã¥ã¢æ¥ç¶ã¯ãªãã·ã§ã³ã§ãïŒHTTPããã³/ãŸãã¯HTTPSãäºãã«ç¬ç«ããŠäœ¿çšã§ããŸãïŒããHTTP / 2ã§ã¯å®éã«å¿ é ã§ã-æšæºã§ã¯TLSãªãã®HTTP / 2ãèš±å¯ãããŠããŸãããã»ãšãã©ã®éçºè ãã©ãŠã¶ã¯TLSãéããŠHTTP / 2ãµããŒãã®ã¿ãå®è£ ãããšè¿°ã¹ãŸããã
HTTPSãæäŸãããã®ã¯äœã§ããïŒ
ããããHTTPSã«ã€ããŠèããå¿ èŠãããã®ã¯ãªãã§ããïŒ ããã¯ã3ã€ã®äž»ãªçç±ã§å°å ¥ãããŸããã
- å®ç§çŸ©å
ã€ã³ã¿ãŒããããªã©ã®ãªãŒãã³ãªç°å¢ã§ã¯ã2è éã®éä¿¡ãä¿è·ããŸãã ããšãã°ãHTTPSããªãå Žåããã®ã¢ã¯ã»ã¹ãã€ã³ãã®ãŠãŒã¶ãŒããªã³ã©ã€ã³ã§è³Œå ¥ãããšãWiFiã¢ã¯ã»ã¹ãã€ã³ãã®ææè ã¯ã¯ã¬ãžããã«ãŒããªã©ã®å人ããŒã¿ãèŠãããšãã§ããŸãã - èª å®ã
ããã«ãããæ å ±ãå®å šãã€ãã®ãŸãŸã®åœ¢ã§å®å ã«å±ããŸãã ããšãã°ãWiFiã¢ã¯ã»ã¹ãã€ã³ããæã€å人ã¯ããµã€ãã«åºåãè¿œå ãããããã©ãã£ãã¯ãç¯çŽããããã«ç»è³ªãäœäžãããããèªãã èšäºã®å 容ãå€æŽãããã§ããŸãã HTTPSã䜿çšãããšãWebãµã€ããå€æŽã§ããªããªããŸãã - çæ£æ§
ããã«ãããå®éã®Webãµã€ããæ¬äººã§ããããšãä¿èšŒããŸãã ããšãã°ãWiFiã¢ã¯ã»ã¹ãã€ã³ãã®åãææè ããã©ãŠã¶ãåœã®ãµã€ãã«éä¿¡ããå ŽåããããŸãã HTTPSã¯ãexample.com
ãšããŠè¡šç€ºãããWebãµã€ããå®éã«example.com
ããããšãä¿èšŒãexample.com
ã 蚌ææžã«ãã£ãŠã¯ããŠã§ããµã€ãã®ææè ã®æ³ç身å ã確èªãããã®ããããããyourbank.com
ææè ã¯YourBankãInc.
æå·åããŒã¹
æ©å¯æ§ãæŽåæ§ãããã³èªèšŒã¯HTTPSã®åºæã®æ©èœã§ã¯ãããŸããããããã¯æå·åã®éèŠãªæŠå¿µã§ãã ãããããã詳ããèŠãŠã¿ãŸãããã
å®ç§çŸ©å
æ©å¯æ§ã¯ãã©ã€ãã·ãŒã§ããã€ãŸããæ å ±ãç¡èš±å¯ã®äººã«ããèªã¿åãããä¿è·ããŸãã éåžžããã®ããã»ã¹ã§ã¯ãæ å ±ããã¬ãŒã³ããã¹ããšåŒã°ããèªã¿åãå¯èœãªåœ¢åŒïŒãªãŒãã£ãªãšãããªãå«ãïŒããæå·ããã¹ããšåŒã°ããæå·åãããèªã¿åãäžå¯èœãªåœ¢åŒã«å€æããŸãã ãã®ããã»ã¹ã¯æå·åãšåŒã°ããŸã ã èªã¿åãäžå¯èœãªæå·æãèªã¿åãå¯èœãªå¹³æã«æ»ãéã®ããã»ã¹ã¯ã 埩å·åãšåŒã°ããŸãã æ å ±ã®æå·åãšåŸ©å·åã«ã¯å€ãã®æ¹æ³ããããŸã- æå·åé¢æ° ïŒãŸãã¯ã¢ã«ãŽãªãºã ïŒã
2ã€ã®åœäºè ãéä¿¡ããã«ã¯ã2ã€ã®åé¡ã«åæããå¿ èŠããããŸãã
- éä¿¡ã§äœ¿çšããã¢ã«ãŽãªãºã ïŒæå·åé¢æ°ïŒã
- éžæããã¡ãœããã§äœ¿çšããããã©ã¡ãŒã¿ãŒããã¹ã¯ãŒãããŸãã¯ã«ãŒã«ïŒ ã·ãŒã¯ã¬ãã ïŒã
äž»ã«2ã€ã®æå·åæ¹æ³ããããŸãã
- 察称ç
äž¡æ¹ã®ããŒãã£ãŒã¯å ±æç§å¯ããŒãä¿æããŸã ã - é察称
åœäºè ã®1人ã¯ãå ¬éããŒã€ã³ãã©ã¹ãã©ã¯ãã£ïŒPKIïŒã®åºç€ãè¡šãå ¬éããŒãšç§å¯ããŒã®ãã¢ãææããŠããŸã ã
察称æå·åæ¹åŒã¯ãéä¿¡è ãæå·åã«äœ¿çšãããã®ãšåä¿¡è ãåãæ¹æ³ããã³åãããŒã§åŸ©å·åããããã«äœ¿çšããåãç§å¯ãäž¡æ¹ã®åœäºè ãä¿æããŠãããšããäºå®ã«äŸåããŠããŸãïŒäžã®å³ãåç §ïŒã ãããã®æ¹æ³ã®åé¡ã¯ãç©ççã«äºãã«äŒããã«ç§å¯éµãåœäºè ãã©ã®ããã«åæïŒã€ãŸã亀æïŒãããã§ããäœããã®å®å šãªéä¿¡ãã£ãã«ã確ç«ããå¿ èŠããããŸãã
察称æå·åïŒ ã©ãŒãžããŒãžã§ã³ãåç § ïŒ
é察称æ³ã¯ãã®çš®ã®åé¡ã解決ããŸã-ãããã¯å ¬ééµãšç§å¯éµã®æŠå¿µã«åºã¥ããŠããŸãã ã¯ãªã¢ããã¹ãã¯åäžã®ããŒã§æå·åãããããŒã®ãã¢ã䜿çšããŠè§£èªã§ããŸãã
ããã§ã¯ãã©ã®ããã«æ©èœããŸããïŒ äºãã«å®å šã«éä¿¡ããã2ã€ã®åŽé¢ããããšããŸã-ã¢ãªã¹ãšããïŒåæç§æžã§ã¯ãæ¶ç©ºã®äººç©ã®ååã¯åžžã«äœ¿çšãããŸããã»ãã¥ãªãã£ã¬ã€ããªã©ã§ã¯ããã®äŒçµ±ãå°éããŸãïŒã ããããã«åºæã®ããŒãã¢ããããŸãã1ã€ã¯ã·ãŒã¯ã¬ããããã1ã€ã¯ãããªãã¯ã§ãã ç§å¯éµã¯ãããããã®ææè ã®ã¿ãç¥ã£ãŠããŸãã å ¬ééµã¯ãã¹ãŠã«å ¬éãããŠããŸãã
ã¢ãªã¹ãããã«ã¡ãã»ãŒãžãéä¿¡ãããå Žåã圌女ã¯åœŒã®å ¬ééµãååŸããå¹³æãæå·åãã圌ã«æå·æãéä¿¡ããªããã°ãªããŸããã ãã®åŸã圌ã¯ç§å¯éµã䜿çšããŠåŸ©å·åããŸãã
ãããã¢ãªã¹ã«ã¡ãã»ãŒãžãéä¿¡ãããå Žåã圌ã¯åœŒå¥³ã®å ¬ééµãååŸããå¹³æãæå·åãã圌女ã«æå·æãéä¿¡ããªããã°ãªããŸããã 次ã«ã圌女ã¯ç§å¯éµã䜿çšããŠåŸ©å·åããŸãã
é察称æå·åïŒ ã©ãŒãžããŒãžã§ã³ãåç § ïŒ
察称æå·åã¯ãã€äœ¿çšããé察称æå·åã¯ãã€äœ¿çšããŸããïŒ
é察称æå·å㯠ãã¯ã©ã€ã¢ã³ããšãµãŒããŒéã§ç§å¯ã亀æããããã«äœ¿çšãããŸãã çŸå®ã«ã¯ãéåžžãåæ¹åã®é察称éä¿¡ã¯å¿ èŠãããŸãããæå·åãããã¡ãã»ãŒãžãåä¿¡ã§ããããã«ãããŒãã£ã®1ã€ïŒç°¡åã«ããããã«ãµãŒããŒãšåŒã³ãŸã ïŒãããŒã®ã»ãããææããŠããã°ååã§ãã å®éã«ã¯ãããã¯ã¯ã©ã€ã¢ã³ããããµãŒããŒãžã®äžæ¹åã®æ å ±ã®ã¿ãä¿è·ããŸããããã¯ãå ¬éããŒã§æå·åãããæ å ±ã¯ããã¢ã«ãªã£ãŠããç§å¯ããŒã䜿çšããŠã®ã¿è§£èªã§ããããã§ããã€ãŸãããµãŒããŒã®ã¿ã解èªã§ããŸãã ããäžæ¹ã®æ¹åã¯ä¿è·ãããŠããŸãã-ãµãŒããŒã®ç§å¯éµã§æå·åãããæ å ±ã¯ãå ¬ééµã§è§£èªã§ããŸããå ¬ééµã¯èª°ã§ãå©çšã§ããŸãã å察åŽïŒç°¡åã«ããããã«ã¯ã©ã€ã¢ã³ããšãåŒã°ããŸã ïŒã¯ãã©ã³ãã ã«çæãããã»ãã·ã§ã³ã·ãŒã¯ã¬ããããµãŒããŒã®å ¬éããŒã§æå·åããŠéä¿¡ãéå§ããæå·æããµãŒããŒã«éãè¿ããŸãããµãŒããŒã¯ãç§å¯ããŒã䜿çšããŠæå·åã解é€ããç§å¯ãä¿æããŸãã
次ã«ã察称æå·åã¯éä¿¡äžã«å®ããŒã¿ãä¿è·ããããã«äœ¿çšãããŸããããã¯ãé察称æå·åãããã¯ããã«é«éã ããã§ãã ç§å¯ã亀æãããšãæ å ±ãæå·åããã³åŸ©å·åã§ããã®ã¯2è ïŒã¯ã©ã€ã¢ã³ããšãµãŒããŒïŒã ãã§ãã
ãããããã³ãã·ã§ã€ã¯ã®æåã®é察称éšåãããŒäº€æãšãåŒã°ããçç±ã§ãããå®éã®æå·åéä¿¡ãæå·åæ¹æ³ãšããŠç¥ãããã¢ã«ãŽãªãºã ã䜿çšããçç±ã§ãã
èª å®ã
HTTPSã解決ãããã1ã€ã®åé¡ã¯ã ããŒã¿ã®æŽåæ§ã§ãã1ïŒãã¹ãŠã®æ å ±ãå®å šã«é ä¿¡ããããšããä¿èšŒã 2ïŒéä¿¡äžã«èª°ãæ å ±ãå€æŽããªããšããä¿èšŒã æ å ±ãã·ãŒã ã¬ã¹ã«éä¿¡ããããã«ã ã¡ãã»ãŒãžãã€ãžã§ã¹ãã¢ã«ãŽãªãºã ã䜿çšãããŸãã 亀æãããåã¡ãã»ãŒãžã®ã¡ãã»ãŒãžèªèšŒã³ãŒãïŒMACïŒã®èšç®ã¯ã æå·åããã·ã¥ããã»ã¹ã§ãã ããšãã°ãMACïŒ ã¿ã°ãšåŒã°ããããšããããŸãïŒãååŸããã«ã¯ã以äžã®å®éçãªäžå¯èœæ§ïŒäžå¯èœæ§ãšããçšèªã䜿çšãããããšãããïŒãä¿èšŒããæ¹æ³ã䜿çšãããŸãã
- ã¿ã°ã«åœ±é¿ãäžããã«ã¡ãã»ãŒãžãå€æŽãã
- 2ã€ã®ç°ãªãã¡ãã»ãŒãžã«å¯ŸããŠåãã¿ã°ãçæãã
- ããã»ã¹ãéã«ããŠãã¿ã°ããå ã®ã¡ãã»ãŒãžãååŸããŸãã
èªèšŒ
ä¿¡é Œæ§ã¯ã©ãã§ããïŒ å ¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ã®å®éã®ã¢ããªã±ãŒã·ã§ã³ã®åé¡ã¯ãã©ã¡ãã®åŽãå®éã«ç¬¬2ã®åŽã誰ã§ããããèŠã€ããæ¹æ³ããªãããšã§ãããããã¯ç©ççã«äºãã«åé¢ãããŠããŸãã ãã®ä¿¡é Œæ§ã第2ã®åœäºè ã«èšŒæããããã«ã çžäºä¿¡é Œã®ãã第3ã®åœäºè ãã€ãŸãèªèšŒå±ïŒCAïŒãé¢äžããŸãã ãã®CAã¯ããã¡ã€ã³å
example.com
ïŒäžæã®èå¥å ïŒãå ¬éããŒ
XXX
é¢é£ä»ããããŠããããšã確èªãã蚌ææžãçºè¡ã
example.com
ã å Žåã«ãã£ãŠã¯ïŒEVããã³OV蚌ææžã䜿çš-以äžãåç §ïŒãCAã¯ç¹å®ã®äŒç€Ÿããã®ãã¡ã€ã³ãå¶åŸ¡ããŠããããšã確èªããŸãã ãã®æ å ±ã¯èªèšŒå±Xã«ãã£ãŠä¿èšŒïŒã€ãŸãèªèšŒïŒããããã®ä¿èšŒã¯æ¥ä»YïŒã€ãŸãã蚌ææžã¯ãã®æ¥ä»ããæå¹ã«ãªããŸãïŒãããæ©ãæå¹ã§ãããæ¥ä»Zãããé ãïŒã€ãŸãããã®æ¥ä»ã§èšŒææžãæéåãã«ãªããŸãïŒ ã ãã®æ å ±ã¯ãã¹ãŠãHTTPS蚌ææžãšåŒã°ãã1ã€ã®ããã¥ã¡ã³ãã«å«ãŸããŠããŸã ã ç°¡åã«ç解ã§ããé¡æšãäžããããã«-ããã¯åœã®æ¿åºïŒã€ãŸãã誰ããä¿¡é Œãã第äžè ïŒã«ãã£ãŠçºè¡ãããIDãŸãã¯ãã¹ããŒãã®ãããªãã®ã§ã-ãããŠãæ¿åºãä¿¡é Œãããã¹ãŠã®äººã¯ãææè ãšææè èªèº«ã®èšŒææžïŒãã¹ããŒãïŒãä¿¡é ŒããŸã ãã¡ããããã¹ããŒãã¯åœç©ã§ã¯ãªããšæ³å®ãããŠããŸããã蚌ææžã®æ¹ããã¯ãã®èšäºã®ç¯å²å€ã§ãã
èªèšŒå±ã¯ã蚌ææžã®çœ²åãä¿¡é Œããçµç¹ã§ãã Firefoxãã©ãŠã¶ã ãã§ãªããWindowsãmacOSãiOSãAndroidãªã©ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ã¯ãä¿¡é Œã§ãã蚌ææžã®ãªã¹ãããããŸãã
ãã©ãŠã¶ãä¿¡é ŒããŠãã蚌ææ©é¢ã確èªã§ããŸãã
- Firefox
ããªãã·ã§ã³ãâã詳现èšå®ãâã蚌ææžãâã蚌ææžã®è¡šç€ºãâãæš©éã - çª
ãã³ã³ãããŒã«ããã«ãâãã€ã³ã¿ãŒããããªãã·ã§ã³ãâãã³ã³ãã³ãã-ã蚌ææžãâãä¿¡é Œãããã«ãŒãèªèšŒå±/äžéèªèšŒå±ã - Mac
ãã¢ããªã±ãŒã·ã§ã³ãâããŠãŒãã£ãªãã£ãâãããŒãã§ãŒã³ã¢ã¯ã»ã¹ãããã«ããŽãªãã§ã蚌ææžããéžæããŸãã
ãã®åŸããã¹ãŠã®èšŒææžãæ€èšŒãããä¿¡é ŒãããŸãã æ€èšŒã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãŸãã¯ãã©ãŠã¶ã®ããããã«ãã£ãŠå®è¡ãããŸããä¿¡é Œã¯çŽæ¥ç¢ºç«ãããããä¿¡é Œã§ããä¿¡é Œãããé¢ä¿è ãéããŠç¢ºç«ãããŸãã ä¿¡é Œè»¢éã¡ã«ããºã ã¯ä¿¡é Œãã§ãŒã³ãšããŠç¥ãããŠããŸã ïŒ
ä¿¡é Œã®ãã§ãŒã³ïŒ ã©ãŒãžããŒãžã§ã³ãåç § ïŒ
è¿œå ã®èªèšŒå±ãè¿œå ã§ããŸããããã¯ãèªå·±çœ²å蚌ææžã䜿çšãããšãã«åœ¹ç«ã¡ãŸãïŒããã«ã€ããŠã¯åŸã§èª¬æããŸãïŒã
ã»ãšãã©ã®äžè¬çãªç¶æ³ã§ã¯ãã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã®IDïŒããšãã°ã顧客åãã®eã³ããŒã¹ãµã€ãïŒã確èªããå¿ èŠãããããããã®Webãµã€ãã®ã¿ã«èšŒææžãå¿ èŠã§ãã é»åæ¿åºã·ã¹ãã ãªã©ã®ãã®ä»ã®ç¶æ³ã§ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã®äž¡æ¹ã身å ã蚌æããå¿ èŠããããŸãã ããã¯ãäž¡æ¹ã®åœäºè ãèªèšŒã®ããã«èšŒææžãæ瀺ããå¿ èŠãããããšãæå³ããŸãã ãã®ãããªã·ã¹ãã ããã®èšäºã®ç¯å²ãè¶ ããŠããŸãã
HTTPS蚌ææžã®çš®é¡
HTTPS蚌ææžã«ã¯ããã€ãã®çš®é¡ããããŸãã ãããã¯ã次ã®åºæºã«åŸã£ãŠåé¡ã§ããŸãã
1.èªèšŒ
- æ€èšŒæžã¿ãã¡ã€ã³ïŒDVïŒ
æãäžè¬çãªã¿ã€ãã®DV蚌ææžã¯ããã¡ã€ã³ãç¹å®ã®å ¬éããŒãšäžèŽããããšã確èªããŸãã ãã©ãŠã¶ã¯ãµãŒããŒãžã®å®å šãªæ¥ç¶ã確ç«ããéããå京é ã¢ã€ã³ã³ã衚瀺ããŸãã ã¢ã€ã³ã³ãã¯ãªãã¯ãããšãããã®Webãµã€ãã¯ææè ã«é¢ããæ å ±ãæäŸããŸããã§ããããšããã¡ãã»ãŒãžã衚瀺ãããŸãã ãã¡ã€ã³ã®ææ暩以å€ã«ããã®èšŒææžãååŸããããã®è¿œå èŠä»¶ã¯ãããŸãããDV蚌ææžã¯ããã®ãã¡ã€ã³ã«æ£ããå ¬éããŒãæäŸãããããšãä¿èšŒããã ãã§ãã ãã©ãŠã¶ã«ã¯æ³äººã®ååã¯è¡šç€ºãããŸããã DV蚌ææžã¯ãå€ãã®å Žåãå®äŸ¡ïŒå¹Žé10ãã«ïŒãŸãã¯ç¡æã§ã-以äžã®Let's Encryptããã³Cloudflareã»ã¯ã·ã§ã³ãåç §ããŠãã ããã - æ¡åŒµç¢ºèªïŒEVïŒ
EV蚌ææžã¯ãWebãµã€ããææããæ³äººã確èªããŸãã ããã¯æãä¿¡é Œã§ããã¿ã€ãã®èšŒææžã§ãã èªèšŒå±ããã¡ã€ã³ãå¶åŸ¡ããæ³äººã確èªããåŸã«çºè¡ãããŸãã æ³äººã¯ããã€ãã®æ¡ä»¶ã®äžã§æ€èšŒãããŸãïŒ
- ãã¡ã€ã³ç®¡çïŒDV蚌ææžïŒ;
- äŒç€Ÿãç»é²ãããæå¹ã§ããããšã確èªããããã®å·ã®ã¬ãžã¹ããª;
- DunnãBradstreetãSalesforceã®connect.data.comãYellow Pagesãªã©ã®ç¬ç«ããããžãã¹ãã£ã¬ã¯ããªã
- ãã¹ãé話;
- 蚌ææžå ã®ãã¹ãŠã®ãã¡ã€ã³åã®æ€èšŒïŒEV蚌ææžã§ã¯ã¯ã€ã«ãã«ãŒãã¯æ瀺çã«çŠæ¢ãããŠããŸãïŒã
ããã¯ã¢ã€ã³ã³ã®ããã«ãEV HTTPS蚌ææžã«ã¯ãURLã®åã«ãæ€èšŒæžã¿ã®æ³äººã®ååïŒéåžžã¯ç»é²äŒç€ŸïŒã衚瀺ãããŸãã iOS Safariãªã©ã®äžéšã®ããã€ã¹ã¯ãURLãå®å šã«ç¡èŠããŠãæ€èšŒæžã¿ã®ãšã³ãã£ãã£ã®ã¿ã衚瀺ããŸãã ã¢ã€ã³ã³ãã¯ãªãã¯ãããšãæ°åãæ³å®äœæãªã©ãçµç¹ã«é¢ãã詳现ã衚瀺ãããŸãã ãããã®èšŒææžã®è²»çšã¯ã幎é150ãã«ãã300ãã«ã§ãã - æ€èšŒæžã¿çµç¹ïŒOVïŒ
EVãšåæ§ã«ãOV蚌ææžã¯ãWebãµã€ããææããæ³äººã確èªããŸãã ãã ããEVãšã¯ç°ãªããHTTPS OV蚌ææžã¯ããŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ã«æ€èšŒæžã¿ã®æ³äººã®ååã衚瀺ããŸããã ãã®çµæãOV蚌ææžã¯æ€èšŒã®èŠä»¶ãé«ãããããŸãäžè¬çã§ã¯ãããŸãããããŠãŒã¶ãŒã«èŠããå©ç¹ã¯æäŸããŸããã è²»çšã¯å¹Žé40ãã«ãã100ãã«ã§ãã
2.察象ãã¡ã€ã³ã®æ°
æãHTTPS蚌ææžã®CNãã£ãŒã«ãã«ã¯éåžžãåäžã®ãã¡ã€ã³ãå«ãŸããŠããŸããã åŸã«ããµããžã§ã¯ãã®å¥åïŒSANïŒãè¿œå ããã1ã€ã®èšŒææžãè¿œå ã®ãã¡ã€ã³ãã«ããŒããããã«ãªããŸããã çŸåšããã¹ãŠã®HTTPS蚌ææžã¯åãæ¹æ³ã§äœæãããŸããåäžãã¡ã€ã³ã®èšŒææžã§ãã£ãŠãããã®åäžãã¡ã€ã³ã®SANãã£ãŒã«ãïŒããã³ãã®ãã¡ã€ã³ã®
www
ããŒãžã§ã³ã®2çªç®ã®SANãã£ãŒã«ãïŒãååšããŸãã ãã ããå€ãã®å£²ãæã¯ãæŽå²çãªçç±ã«ããã1ã€ä»¥äžã®ãã¡ã€ã³ã®HTTPS蚌ææžã販売ããŠããŸãã
- åäžãã¡ã€ã³
ããã¯ãexample.com
ããã³www.example.com
ãã¡ã€ã³åã«æå¹ãªèšŒææžã®æãäžè¬çãªã¿ã€ãã§ãã - è€æ°ã®ãã¡ã€ã³ïŒUCC / SANïŒ
ãã®çš®é¡ã®èšŒææžã¯ããŠããã¡ã€ãã³ãã¥ãã±ãŒã·ã§ã³èšŒææžïŒUCCïŒãŸãã¯ãµããžã§ã¯ãã®å¥åïŒSANïŒãšãåŒã°ãããã¡ã€ã³ã®ãªã¹ããã«ããŒã§ããŸãïŒç¹å®ã®å¶éãŸã§ïŒã åäžã®ãã¡ã€ã³ã«éå®ãããŸãã-ããŸããŸãªãã¡ã€ã³ãšãµããã¡ã€ã³ãæå®ã§ããŸãã ã³ã¹ãã«ã¯éåžžãç¹å®ã®æ°ïŒ3ã5ïŒã®ãã¡ã€ã³ãå«ãŸããè¿œå æéã§ïŒç¹å®ã®å¶éãŸã§ïŒè¿œå ã§ããŸãã å§åŠ¹ãµã€ãã§ã®ã¿äœ¿çšããããšããå§ãããŸããã¯ã©ã€ã¢ã³ãã¯ãä»»æã®Webãµã€ãã§èšŒææžã確èªãããšãã«ãã¡ã€ã³ãã¡ã€ã³ãšãã¹ãŠã®è¿œå ãã¡ã€ã³ã確èªããããã§ãã - ãµããã¡ã€ã³ïŒã¯ã€ã«ãã«ãŒãïŒ
ãã®ã¿ã€ãã®èšŒææžã¯ãã¡ã€ã³ãã¡ã€ã³ãšãç¡å¶éã®æ°ã®ãµããã¡ã€ã³ïŒ*.example.com
ïŒãã«ããŒããŸã-ããšãã°ãexample.com
ãwww.example.com
ãmail.example.com
ãftp.example.com
ãªã©ãã¡ã€ã³ãã¡ã€ã³ã®ãµããã¡ã€ã³ã®ã¿ã察象ãšããŠããããšã
è¡šã«ã¯ãããŸããŸãªèšŒææžã瀺ãããŠããŸãã
蚌ææžã®çš®é¡ | æ€èšŒæžã¿ãã¡ã€ã³ïŒDVïŒ | æ€èšŒæžã¿çµç¹ïŒOVïŒ | æ¡åŒµç¢ºèªïŒEVïŒ |
---|---|---|---|
Https | Https
確èªæžã¿ã®èäœæš©è | Https
確èªæžã¿ã®èäœæš©è ææè æ å ±ã¯ãã©ãŠã¶ã«è¡šç€ºãããŸã | |
åäžãã¡ã€ã³ | example.com, www.example.com
| ||
è€æ°ã®ãã¡ã€ã³ | example.com
ã www.example.com
ã mail.example.com
ã example.net
ã example.org
ãªã© ç¹å®ã®å¶éïŒéåžžã¯100ïŒãŸã§ã®å®çŸ©æžã¿ãªã¹ã | ||
ãµããã¡ã€ã³ | *.example.com
ä»»æã®ãµããã¡ã€ã³ã«é©ããŠããŸãã | 䜿çšäžå¯-ãã¹ãŠã®ååã蚌ææžã«æ瀺çã«å«ãã蚌ææ©é¢ã«ãã£ãŠæ€èšŒããå¿ èŠããããŸã |
æ§æ
èŠçŽãããšã4ã€ã®HTTPSã³ã³ããŒãã³ãã«ã¯æå·åãå¿ èŠã§ãã
- åæããŒäº€æ
é察称ã¢ã«ãŽãªãºã ã䜿çšãããŸãïŒç§å¯éµãšå ¬ééµïŒã - ID蚌ææž ïŒèšŒææ©é¢ã«ãã£ãŠçºè¡ãããHTTPS蚌ææžïŒ
é察称ã¢ã«ãŽãªãºã ã䜿çšãããŸãïŒç§å¯éµãšå ¬ééµïŒã - å®éã®ã¡ãã»ãŒãžæå·å
察称ã¢ã«ãŽãªãºã ã䜿çšãããŸãïŒäºåå ±æå ±æã·ãŒã¯ã¬ããïŒã - ã¡ãã»ãŒãžãã€ãžã§ã¹ã
æå·åããã·ã¥ã¢ã«ãŽãªãºã ã䜿çšãããŸãã
ãããã®åã³ã³ããŒãã³ãã¯ãç°ãªãããŒãµã€ãºã®äžé£ã®ã¢ã«ãŽãªãºã ïŒäžéšã¯äœ¿çšãæšå¥šãããªããªããŸããïŒã䜿çšããŸãã ãã³ãã·ã§ã€ã¯äžã«ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã¯ã䜿çšããæ¹æ³ã®çµã¿åããã«ã€ããŠåæããŸã-çŽ12çš®é¡ã®å ¬éããŒã¢ã«ãŽãªãºã ïŒããŒäº€æïŒãçŽ12çš®é¡ã®å¯Ÿç§°ããŒã¢ã«ãŽãªãºã ïŒæå·ïŒã3çš®é¡ïŒ2çš®é¡ã¯äœ¿çšããªãããšïŒã®ãããããéžæããŸããã€ãžã§ã¹ãã¡ãã»ãŒãžã®ã¢ã«ãŽãªãºã ãããã«ãããæ°çŸã®çµã¿åãããåŸãããŸãã
ããšãã°ã
ECDHE-RSA-AES256-GCM-SHA384
ãããšã æ¥åæ²ç·Diffie-Hellman EphemeralïŒECDHEïŒã¢ã«ãŽãªãºã ã䜿çšããŠããŒäº€æãå®è¡ãããŸã ã 蚌ææ©é¢ã¯ã Rivest-Shamir-AdlemanïŒRSAïŒã¢ã«ãŽãªãºã ã䜿çšããŠèšŒææžã«çœ²åããŸããã 察称ã¡ãã»ãŒãžæå·åã¯ã 256ãããããŒã§Advanced Encryption StandardïŒAESïŒæå·ã䜿çšãã GCMã¢ãŒãã§åäœããŸãã ã¡ãã»ãŒãžã®æŽåæ§ã¯ã 384ãããã®ãã€ãžã§ã¹ãã䜿çšããSHAã»ãã¥ã¢ããã·ã¥ã¢ã«ãŽãªãºã ã«ãã£ãŠä¿èšŒãããŸãã ïŒ ã¢ã«ãŽãªãºã ã®çµã¿åããã®å®å šãªãªã¹ããå©çšå¯èœã§ã ïŒã
ãã®ãããããã€ãã®æ§æãéžæããå¿ èŠããããŸãã
æå·ã¹ã€ãŒã
䜿çšããæå·ã¹ã€ãŒãã®éžæã¯ãäºææ§ãšã»ãã¥ãªãã£ã®ãã¬ãŒããªãã§ãã
- å€ããã©ãŠã¶ãšã®äºææ§ã®ããã«ããµãŒããŒã¯å€ãæå·ã¹ã€ãŒãããµããŒãããå¿ èŠããããŸãã
- ãã ããå€ãæå·ã¹ã€ãŒãã®å€ãã¯ããã¯ãå®å šãšã¯èŠãªãããŠããŸããã
OpenSSLã¯ããµããŒããããŠããçµã¿åããïŒäžèšãåç §ïŒãæå·åŒ·åºŠã®éé ã§ãªã¹ãããŸãã ããã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®æåã®ãã³ãã·ã§ã€ã¯äžã«ãäž¡æ¹ã®åœäºè ã«ãã£ãŠãµããŒããããçµã¿åãããèŠã€ãããŸã§ãæã匷ãçµã¿åããããé çªã«äžŠã¹æ¿ããããããã«è¡ãããŸãã ä»ã«éžæè¢ããªãå Žåã¯ãæåã«æãå®å šãªçµã¿åãããè©Šãã次ã«ã»ãã¥ãªãã£ãåŸã ã«åŒ±ããããšã¯çã«ããªã£ãŠããŸãã
ãŠã£ãããã£ã¢ã«ã¯ããã¹ãŠã®TLSã³ã³ããŒãã³ãã®ã¢ã«ãŽãªãºã ã®ç¶²çŸ çãªãªã¹ããå«ãŸããŠããã SSLããã³TLSã®ç°ãªãããŒãžã§ã³ã§ã®ãµããŒãã瀺ããŠããŸãã
Mozilla SSLæ§æãžã§ãã¬ãŒã¿ãŒã¯ããµãŒããŒã§äœ¿çšããæå·åæ¹æ³ãéåžžã«æçšã§åŒ·ãæšå¥šãããªãã¡ã¬ã³ã¹ã§ãã åŸã§å®éã®ãµãŒããŒæ§æã§äœ¿çšããŸãã
ããŒã¿ã€ã
Elliptic Curve CryptographyïŒ ECC ïŒèšŒææžã¯ãRSA蚌ææžãããåŠçãéãã䜿çšããCPUãå°ãªããããã¢ãã€ã«ã¯ã©ã€ã¢ã³ãã«ãšã£ãŠç¹ã«éèŠã§ãã ãã ããAmazonãCloudFrontãHerokuãªã©ã®äžéšã®ãµãŒãã¹ã¯ããã®èšäºã®å·çæç¹ã§ã¯ãŸã ECC蚌ææžããµããŒãããŠããŸããã
ECCã®256ãããã®ããŒé·ã§ååãšèŠãªãããŸãã
Rivest Shamir AdlemanïŒ RSA ïŒèšŒææžã¯äœéã§ãããå€çš®å€æ§ãªå€ããµãŒããŒãšäºææ§ããããŸãã RSAããŒã¯ãµã€ãºã倧ããããã2048ãããã®RSAããŒãæå°èš±å®¹ç¯å²ãšèŠãªãããŸãã 4096ããã以äžã®ããŒãæã€RSA蚌ææžã¯ãããã©ãŒãã³ã¹ãäœäžãããå¯èœæ§ããããŸã-ããã«ãã»ãšãã©ã®å Žåãè¿œå ã®ä¿è·ãæãªã2048ãããã®äžéããŒã«ãã£ãŠçœ²åãããŸãïŒ
äžèšã®èšè¿°ã®ææ§ããšæ°åã®æ¬ åŠã«æ°ã¥ãããããããŸããã 1ã€ã®ãµãŒããŒãããŒãã§ãããã®ã¯ãå¥ã®ãµãŒããŒãããŒãããŸããã ããã©ãŒãã³ã¹ãžã®åœ±é¿ãå€æããæåã®æ¹æ³ã¯ãå®éã®Webãµã€ããšå®éã®èšªåè ã䜿çšããŠãèªåã®ãµãŒããŒã§ããŠã³ããŒãã確èªããããšã§ãã ãããŠããããæéãšãšãã«å€åããŸãã
æç¶ã
HTTPS蚌ææžãååŸããã«ã¯ã次ã®æé ãå®è¡ããŸãã
- ç§å¯éµãšå ¬ééµã®ãã¢ãäœæããçµç¹ãšå ¬ééµã«é¢ããæ å ±ãå«ã蚌ææžçœ²åèŠæ±ïŒCSRïŒãæºåããŸãã
- 蚌ææ©é¢ã«é£çµ¡ããCSRã«åºã¥ããŠHTTPS蚌ææžãèŠæ±ããŸãã
- 眲åæžã¿HTTPS蚌ææžãååŸããŠããµãŒããŒã«ã€ã³ã¹ããŒã«ããŸãã
å ¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ïŒPKIïŒã®ããŸããŸãªã³ã³ããŒãã³ããå«ããã¡ã€ã«ã®ã»ããããããŸãïŒç§å¯éµãšå ¬ééµãCSRãããã³çœ²åæžã¿HTTPS蚌ææžãç©äºãããã«è€éã«ããããã«ãç°ãªãåœäºè ã¯ç°ãªãååïŒããã³æ¡åŒµåïŒã䜿çšããŠåããã®ã«ååãä»ããŸãã
æå§ãã«ãæ å ±ãä¿åããããã®2ã€ã®äžè¬çãªåœ¢åŒãDERãšPEMããããŸãã1ã€ç®ïŒDERïŒã¯ãã€ããªã§ã2ã€ç®ïŒPEMïŒã¯base64ã§ãšã³ã³ãŒããããDERãã¡ã€ã«ïŒããã¹ãïŒã§ããããã©ã«ãã§ã¯ãWindowsã¯DER圢åŒãçŽæ¥äœ¿çšããããªãŒã·ã¹ãã ã®äžçïŒLinuxããã³UNIXïŒã¯PEM圢åŒã䜿çšããŸãããã¡ã€ã«ããã圢åŒããå¥ã®åœ¢åŒã«å€æããããŒã«ïŒOpenSSLïŒããããŸãã
äŸãšããŠã次ã®ãã¡ã€ã«ã䜿çšããŸãã
-
example.com.key
ç§å¯éµä»ãã®PEMãã¡ã€ã«ãæ¡åŒµæ©èœã¯.key
æšæºã§ã¯ãªããããã ããã䜿çšã§ããå Žåãšã§ããªãå ŽåããããŸãããã¡ã€ã«ã¯ä¿è·ãããã¹ãŒããŒãŠãŒã¶ãŒã®ã¿ãã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãã -
example.com.pub
PEM . ( ), . . -
example.com.csr
. PEM , . , HTTPS. -
example.com.crt
HTTPS, . PEM, , , , ..crt
; ,.cert
.cer
.
ãã¡ã€ã«åïŒããã³æ¡åŒµåïŒã¯æšæºåãããŠããŸãããã©ãã§ã䜿çšã§ããŸãããããã®ååãéžãã ã®ã¯ããããã話ããŠããããã«èŠããåã³ã³ããŒãã³ããå®è¡ããæ©èœãæ確ã«ããããã§ããæå³ã®ããä»»æã®åœåã¹ããŒã ã䜿çšã§ããŸããäž»ãªããšã¯ãæ§æããã»ã¹äžã«ã³ãã³ãããã³ãµãŒããŒæ§æã§å¯Ÿå¿ããããŒããã³èšŒææžãã¡ã€ã«ãæå®ããããšã§ãã
ç§å¯éµã¯ãã©ã³ãã ã«çæãããç¹å®ã®é·ãã®æååïŒ2048ãããã䜿çšïŒã§ã次ã®ãããªãã®ã§ããéµãç§å¯ã«ããŠãã ããïŒããã¯ãéåžžã«éãããæš©éïŒ600ïŒã§ä¿è·ãã誰ã«ãé瀺ããªãããšãæå³ããŸãã圌ã®ããŒãããŒ- å ¬ééµ -ã¯æ¬¡ã®ããã«ãªããŸãã
-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAm+036O2PlUQbKbSSs2ik6O6TYy6+Zsas5oAk3GioGLl1RW9N
i8kagqdnD69Et29m1vl5OIPsBoW3OWb1aBW5e3J0x9prXI1W/fpvuP9NmrHBUN4E
S17VliRpfVH3aHfPC8rKpv3GvHYOcfOmMN+HfBZlUeKJKs6c5WmSVdnZB0R4UAWu
Q30aHEBVqtrhgHqYDBokVe0/H4wmwZEIQTINWniCOFR5UphJf5nP8ljGbmPxNTnf
b/iHS/chjcjF7TGMG36e7EBoQijZEUQs5IBCeVefOnFLK5jLx+BC//X+FNzByDil
Tt+l28I/3ZN1ujhak73YFbWjjLR2tjtp+LQgNQIDAQABAoIBAEAO2KVM02wTKsWb
dZlXKEi5mrtofLhkbqvTgVE7fbOKnW8FJuqCl+2NMH31F1n03l765p4dNF4JmRhv
/+ne4vCgOPHR/cFsH4z/0d5CpHMlC7JZQ5JjR4QDOYNOpUG51smVamPoZjkOlyih
XGk/q72CxeU6F/gKIdLt6Dx03wBosIq9IAE8LwdMnioeuj18qaVg195OMeIOriIn
tpWP4eFya5rTpIFfIdHdIxyXsd6hF/LrRc9BMWTY1/uOLrpYjTf7chbdNaxhwH7k
buvKxBvCvmXmd6v/AeQQAXbUkdSnbTKDaB9B7IlUTcDJyPBJXvFS1IzzjN6vV+06
XBwHx5ECgYEAyRZLzwnA3bw8Ep9mDw8JHDQoGuQkFEMLqRdRRoZ+hxnBD9V9M0T6
HRiUFOizEVoXxf6zPtHm/T7cRD8AFqB+pA/Nv0ug6KpwUjA4Aihf5ADp0gem0DNw
YlVkCA6Bu7c9IUlE0hwF7RLB7YrryJVJit9AymmUTUUHCQTWW2yBhC8CgYEAxoHS
HGXthin5owOTNPwLwPfU2o7SybkDBKyW69uTi0KxAl3610DjyA/cV2mxIcFlPv1y
HualGd9eNoeCMBy/AUtjzI0K77yeRpjj321rj6k8c8bYWPHH539SiBXLWTY/WQ0w
pxfT3d/Z4QMh5d6p+p5f3UIrXESYQd+fAaG5tNsCgYEAksTdTB4YUT9EsWr6eN9G
jPlclFQUKV3OMvq77bfYvg8EJORz32nnDDmWS7SUjoOtemwutBlMeWbaKk25aMp3
5JNMXuV6apeMJ9Dd8GU7qBUqlIvVK31/96XPvzmnYzWZPqRVwO2HPcRFG3YcJmkg
JmZQyexJvCQ3wFNxiYUm+y0CgYBXQSMhFnCUg4jWbbDcHlnwRT+LnjHrN2arPE3O
eKLfGL6DotmqmjxFaStaRPv2MXMWgAMUsB8sQzG/WEsSaOBQaloAxJJlFIyhzXyE
bi1UZXhMD8BzQDu1dxLI/IN4wE6SDykumVuocEfuDxlsWDZxEgJjWD2E/iXK9seG
yRa+9wKBgEydVz+C1ECLI/dOWb20UC9nGQ+2dMa+3dsmvFwSJJatQv9NGaDUdxmU
hRVzWgogZ8dZ9oH8IY3U0owNRfO65VGe0sN00sQtMoweEQi0SN0J6FePiVCnl7pf
lvYBaemLrW2YI2B7zk5fTm6ng9BW/B1KfrH9Vm5wLQBchAN8Pjbu
-----END RSA PRIVATE KEY-----
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm+036O2PlUQbKbSSs2ik
6O6TYy6+Zsas5oAk3GioGLl1RW9Ni8kagqdnD69Et29m1vl5OIPsBoW3OWb1aBW5
e3J0x9prXI1W/fpvuP9NmrHBUN4ES17VliRpfVH3aHfPC8rKpv3GvHYOcfOmMN+H
fBZlUeKJKs6c5WmSVdnZB0R4UAWuQ30aHEBVqtrhgHqYDBokVe0/H4wmwZEIQTIN
WniCOFR5UphJf5nP8ljGbmPxNTnfb/iHS/chjcjF7TGMG36e7EBoQijZEUQs5IBC
eVefOnFLK5jLx+BC//X+FNzByDilTt+l28I/3ZN1ujhak73YFbWjjLR2tjtp+LQg
NQIDAQAB
-----END PUBLIC KEY-----
蚌ææžèŠæ±ã¯æ¬¡ã®ããã«ãªããŸãããã®ç¹å®ã®CSRã«ã¯ããµãŒããŒã®å ¬éããŒãšãã€ã®ãªã¹ã®ãã³ãã³ã«ããããã¡ã€ã³ãææããŠããACME Inc.ã«é¢ããæ å ±ãå«ãŸããŠããŸããæåŸã«ã眲åæžã¿ã®HTTPS蚌ææžã¯æ¬¡ã®ããã«ãªããŸãããã¹ãŠã®éšåãæ¥ç¶ãããŠãããäºãã«äžèŽããå¿ èŠããããŸããæåŸã®èšŒææžã¯ãåã«äŸã®ããã«çæããããã®ã§ããããã¯ãããããèªå·±çœ²å蚌ææžã§ããããã¯ãæ¿èªãããèªèšŒå±ã«ãã£ãŠçœ²åãããŠããªãããã§ãã
-----BEGIN CERTIFICATE REQUEST-----
MIICzjCCAbYCAQAwgYgxFDASBgNVBAMMC2V4YW1wbGUuY29tMQswCQYDVQQLDAJJ
VDEPMA0GA1UECAwGTG9uZG9uMRIwEAYDVQQKDAlBQ01FIEluYy4xIDAeBgkqhkiG
9w0BCQEWEWFkbWluQGV4YW1wbGUuY29tMQswCQYDVQQGEwJHQjEPMA0GA1UEBwwG
TG9uZG9uMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAm+036O2PlUQb
KbSSs2ik6O6TYy6+Zsas5oAk3GioGLl1RW9Ni8kagqdnD69Et29m1vl5OIPsBoW3
OWb1aBW5e3J0x9prXI1W/fpvuP9NmrHBUN4ES17VliRpfVH3aHfPC8rKpv3GvHYO
cfOmMN+HfBZlUeKJKs6c5WmSVdnZB0R4UAWuQ30aHEBVqtrhgHqYDBokVe0/H4wm
wZEIQTINWniCOFR5UphJf5nP8ljGbmPxNTnfb/iHS/chjcjF7TGMG36e7EBoQijZ
EUQs5IBCeVefOnFLK5jLx+BC//X+FNzByDilTt+l28I/3ZN1ujhak73YFbWjjLR2
tjtp+LQgNQIDAQABoAAwDQYJKoZIhvcNAQELBQADggEBAGIQVhXfuWdINNfceNPm
CkAGv4yzpx88L34bhO1Dw4PYWnoS2f7ItuQA5zNk9EJhjkwK8gYspK7mPkvHDbFa
Um7lPSWsm3gjd3pU7dIaHxQ+0AW9lOw5ukiBlO4t3qgt+jTVZ3EhMbR0jDSyjTrY
kTgfuqQrGOQSmLb5XviEtCcN0rseWib3fKIl8DM69JiA2AALxyk7DCkS1BqLNChT
pnbgvtlUhc4yFXNCtwPGskXIvLsCn2LRy+qdsPM776kDLgD36hK0Wu14Lpsoa/p+
ZRuwKqTjdaV23o2aUMULyCRuITlghEEkRdJsaXadHXtNd5I5vDJOAAt46PIXcyEZ
aQY=
-----END CERTIFICATE REQUEST-----
example.com
-----BEGIN CERTIFICATE-----
MIIDjjCCAnYCCQCJdR6v1+W5RzANBgkqhkiG9w0BAQUFADCBiDEUMBIGA1UEAwwL
ZXhhbXBsZS5jb20xCzAJBgNVBAsMAklUMQ8wDQYDVQQIDAZMb25kb24xEjAQBgNV
BAoMCUFDTUUgSW5jLjEgMB4GCSqGSIb3DQEJARYRYWRtaW5AZXhhbXBsZS5jb20x
CzAJBgNVBAYTAkdCMQ8wDQYDVQQHDAZMb25kb24wHhcNMTYwNDE5MTAzMjI1WhcN
MTcwNDE5MTAzMjI1WjCBiDEUMBIGA1UEAwwLZXhhbXBsZS5jb20xCzAJBgNVBAsM
AklUMQ8wDQYDVQQIDAZMb25kb24xEjAQBgNVBAoMCUFDTUUgSW5jLjEgMB4GCSqG
SIb3DQEJARYRYWRtaW5AZXhhbXBsZS5jb20xCzAJBgNVBAYTAkdCMQ8wDQYDVQQH
DAZMb25kb24wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCb7Tfo7Y+V
RBsptJKzaKTo7pNjLr5mxqzmgCTcaKgYuXVFb02LyRqCp2cPr0S3b2bW+Xk4g+wG
hbc5ZvVoFbl7cnTH2mtcjVb9+m+4/02ascFQ3gRLXtWWJGl9Ufdod88Lysqm/ca8
dg5x86Yw34d8FmVR4okqzpzlaZJV2dkHRHhQBa5DfRocQFWq2uGAepgMGiRV7T8f
jCbBkQhBMg1aeII4VHlSmEl/mc/yWMZuY/E1Od9v+IdL9yGNyMXtMYwbfp7sQGhC
KNkRRCzkgEJ5V586cUsrmMvH4EL/9f4U3MHIOKVO36Xbwj/dk3W6OFqTvdgVtaOM
tHa2O2n4tCA1AgMBAAEwDQYJKoZIhvcNAQEFBQADggEBABwwkE7wX5gmZMRYugSS
7peSx83Oac1ikLnUDMMOU8WmqxaLTTZQeuoq5W23xWQWgcTtfjP9vfV50jFzXwat
5Ch3OQUS53d06hX5EiVrmTyDgybPVlfbq5147MBEC0ePGxG6uV+Ed+oUYX4OM/bB
XiFa4z7eamG+Md2d/A1cB54R3LH6vECLuyJrF0+sCGJJAGumJGhjcOdpvUVt5gvD
FIgT9B04VJnaBatEgWbn9x50EP4j41PNFGx/A0CCLgbTs8kZCdhE4QFMxU9T+T9t
rXgaspIi7RA4xkSE7x7B8NbvSlgP79/qUe80Z7d8Oolva6dTZduByr0CejdfhLhi
mNU=
-----END CERTIFICATE-----
ãã®ããã»ã¹ããcPanelãLinuxãFreeBSDãããã³Windowsã§å®è¡ãããå®éã®æé ã§èª¬æããŸããããã¯ããã¹ãŠã®ã¿ã€ãã®èšŒææžã«é©ããæ®éçãªããã»ã¹ã§ããç¡æã®DV蚌ææžãååŸããå Žåã¯ãLet's Encrypt and Cloudflareã§èª¬æãããŠããä»ã®æé ã«åŸã£ãŠãã ããã
ã¹ããã1.ç§å¯éµãšèšŒææžèŠæ±ãäœæãã
次ã®äŸã§ã¯ãäºææ§ãé«ãããã2048ãããRSA蚌ææžã䜿çšããŸãããµãŒããŒãã€ã³ã¹ããŒã«ãããŠãããããã€ããŒãECCããµããŒãããŠããå ŽåïŒããšãã°ãHerokuãŸãã¯AWSãµãŒãã¹ã䜿çšããªãå ŽåïŒãECCã䜿çšããããšããå§ãããŸãã
cpanel
- ãã¹ãã®cPanelã«ãã°ã€ã³ããŸãã
- âSecurityâ âSSL/TLSâ.
âSecurityâ cPanel ( . )
- âSSL/TLS Managerâ. âPrivate Keys (KEY)â .
âSSL/TLS Managerâ cPanel ( . )
- âGenerate, Paste or Uploadâ âPrivate
Keyâ. 2048 âGenerateâ.
(âPrivate Keyâ) cPanel ( . )
- , :
cPanel ( . )
- âPrivate Keysâ, :
âPrivate Keysâ cPanel ( . )
- âSSL/TLS Managerâ. âCertificate Signing Requests (CSR)â .
âSSL/TLS Managerâ cPanel ( . )
- âGenerate Service Requestâ. . ( !), âDomainsâ, , HTTPS. (
example.com
);www
(www.example.com
). âGenerateâ.
âCreate New Certificate Signing Requestâ cPanel ( . )
- CSR, :
CSR cPanel ( . )
- ã蚌ææžçœ²åèŠæ±ãã»ã¯ã·ã§ã³ã«æ»ããšãããã«æ°ããCSRã衚瀺ãããŸã
ãcPanelã®ã蚌ææžçœ²åèŠæ±ãã»ã¯ã·ã§ã³ã«ã¯ãæ°ããçæãããCSRããããŸãïŒå€§ããªããŒãžã§ã³ãåç §ïŒ
LinuxãFreeBSD
OpenSSLãã€ã³ã¹ããŒã«ãããŠããããšã確èªããŠãã ãããããã確èªã§ããŸãïŒ
openssl version
ããã§ãªãå Žåã¯ãã³ã³ãœãŒã«ãéããŠãã©ãããã©ãŒã ã«ã€ã³ã¹ããŒã«ããŸãïŒ
- DebianãUbuntuãããã³ã¯ããŒã³
sudo apt-get install openssl
- Red HatãCentOSãããã³ã¯ããŒã³
sudo yum install openssl
- Freebsd
make -C /usr/ports/security/openssl install clean
ïŒãã®åŸãããŒã ãšããŠç§å¯éµãšCSRãçæãã
openssl req -newkey rsa:2048 -nodes -keyout example.com.key -out example.com.csr
ç§å¯éµãçæãããããªãã¯ãCSRã®ããã«ããã€ãã®è³ªåã«çããå¿ èŠããããŸããæ£ãããã¹ãŠã®è³ªåã«çããïŒåœŒãã¯ããªãã®çœ²åä»ã蚌ææžã«è¡šç€ºããããã«ãªãŒãã³ã«ãªããŸãïŒïŒãã«ç¹å¥ã®æ³šæã»ã¯ã·ã§ã³ãäžè¬åã ïŒããšãã°ãFQDNãµãŒããŒãŸãã¯YOURåïŒãããã¯ãHTTPS蚌ææžãèŠæ±ããŠãããã¡ã€ã³åãšæ£ç¢ºã«äžèŽããå¿ èŠããããŸããæäžäœãã¡ã€ã³ïŒïŒã®ã¿ãããã«å«ããŸãã蚌ææ©é¢ã¯éåžžããµããã¡ã€ã³èªäœãè¿œå ããŸãïŒã€ãŸããïŒïŒ
Generating a 2048 bit RSA private key
........................+++
................................................................+++
writing new private key to 'example.com.key'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
example.com
www
www.example.com
Country Name (2 letter code) [AU]:GB
State or Province Name (full name) [Some-State]:London
Locality Name (eg, city) []:London
Organization Name (eg, company) [Internet Widgits Pty Ltd]:ACME Inc.
Organizational Unit Name (eg, section) []:IT
Common Name (eg server FQDN or YOUR name) []:example.com
Email Address []:admin@example.com
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
- âStartâ â âAdministrative Toolsâ â âInternet Information Services (IIS) Managerâ. . âServer Certificatesâ :
âInternet Information Services (IIS) Managerâ. âServer Certificatesâ. ( . )
- âCreate Certificate Requestâ .
âCreate Certificate Requestâ . ( . )
- , âCommon Nameâ, . âNextâ.
. ( . )
- âCryptographic Service Provider.â âBit lengthâ
2048
. âNextâ.
âBit lengthâ2048
. ( . )
- CSR âFinishâ.
CSR âFinishâ. ( . )
2. HTTPS
Webãµã€ãã®èšŒææžãååŸããã«ã¯ããŸãã蚌ææžã®è²©å£²è ããéžæããã¿ã€ãïŒDVãOVãEVã1ã€ã®ãµã€ããè€æ°ã®ãµã€ãããµããã¡ã€ã³-äžèšåç §ïŒã®HTTPS蚌ææžã®ããŒã³ãè³Œå ¥ããŸããããã»ã¹ã®æåŸã«ãéžæãããã¡ã€ã³ã®è³Œå ¥ããããŒã³ã䜿çšãã蚌ææžã®ãªã¯ãšã¹ããéä¿¡ããå¿ èŠããããŸããè¡
-----BEGIN CERTIFICATE REQUEST-----
ãšãå«ããã¹ãŠã®CSRããã¹ããæäŸããããã«æ±ããããŸãïŒã€ãŸããããŠã³ããŒããã£ãŒã«ãã«æ¿å ¥ããŸãïŒ
-----END CERTIFICATE REQUEST-----
ãEVãŸãã¯OV蚌ææžãå¿ èŠãªå Žåã¯ã蚌ææžãèŠæ±ããŠããæ³äººãæå®ããå¿ èŠããããŸãããŸãããã®äŒç€Ÿã代衚ããŠãããšããäºå®ã確èªããè¿œå ã®æžé¡ãæ±ããããå ŽåããããŸãã次ã«ã蚌ææžã¬ãžã¹ãã©ããªã¯ãšã¹ãïŒããã³ãã¹ãŠã®é¢é£ããã¥ã¡ã³ãïŒããã§ãã¯ãã眲åæžã¿HTTPS蚌ææžãçºè¡ããŸãã
HTTPS蚌ææžã®ååŸ
ãã¹ãã£ã³ã°ãããã€ããŒãŸãã¯HTTPSã¬ãžã¹ãã©ãŒã¯ç°ãªãç»é²æé ãæã£ãŠããå ŽåããããŸãããäžè¬çãªããžãã¯ã¯åãã§ãã
- HTTPS蚌ææžã®è²©å£²è ãèŠã€ããŸãã
- 蚌ææžã®çš®é¡ïŒDVãOVãEVã1ã€ã®ãµã€ããè€æ°ã®ãµã€ãããµããã¡ã€ã³ïŒãéžæããŠããã¹ã±ããã«è¿œå ããŸãããåžæã®æ¯æãæ¹æ³ãéžæããŠãæ¯æããè¡ã£ãŠãã ããã
- ãã¡ã€ã³ã®æ°ããHTTPS蚌ææžãã¢ã¯ãã£ãã«ããŸãããã©ãŒã ã«è²Œãä»ãããã蚌ææžã«çœ²åãããªã¯ãšã¹ããå«ããã¡ã€ã«ãã¢ããããŒãã§ããŸããã·ã¹ãã ã¯ãCSRãã蚌ææžæ å ±ãæœåºããŸãã
- « » (âDomain Control Validationâ, DCV) â , HTML ( HTML ),
TXT
( DNS ). DCV . - , HTTPS. .
蚌ææžã«èªåã§çœ²åãããã®æš©éãèªèšŒæ©é¢ã«äžããªãããšãå¯èœã§ããæå·åã®èŠ³ç¹ãããèªå·±çœ²å蚌ææžã¯ä»ã®èšŒææžãšéãã¯ãããŸãããããã©ãŠã¶ãŒã¯ãããä¿¡é ŒããŸããããã»ãã¥ãªãã£èŠåã衚瀺ããå§ãããããããã¯ãã¹ãç®çã«é©ããŠããŸã-誰ã§ãåœè£ ã§ããŸãããããã¯ä¿¡é Œã§ãã第äžè ã«ãã£ãŠæ€èšŒãããŸãããŠãŒã¶ãŒãWebãµã€ããä¿¡é Œããå ŽåããŠãŒã¶ãŒã¯ãã©ãŠã¶ãŒã«äŸå€ãè¿œå ã§ããŸããããã«ããã蚌ææžãä¿åãããä»åŸã®ã¢ã¯ã»ã¹ã§ãµã€ããä¿¡é ŒãããŸãã
ããšãã°ãèªå·±çœ²å蚌ææžã¯äžèšã§å ¬éãããŠããŸã-ãã¡ã€ã³
example.com
ã§äœ¿çšã§ãããã®æéã¯æ©èœããŸãã
OpenSSLãåããä»»æã®ãã©ãããã©ãŒã ã§èªå·±çœ²å蚌ææžãäœæã§ããŸãã
openssl x509 -signkey example.com.key -in example.com.csr -req -days 365 -out example.com.crt
蚌ææžãçæããããããµãŒããŒã«ã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã1ã€ã®ãããã€ããŒãããã¹ãã£ã³ã°ãšHTTPSç»é²ãµãŒãã¹ãææããŠããå ŽåïŒå€ãã®ãã¹ãã£ã³ã°ãããã€ããŒãHTTPS蚌ææžã販売ããŠããŸãïŒãWebãµã€ãã®æ°ããHTTPS蚌ææžãã€ã³ã¹ããŒã«ããŠã¢ã¯ãã£ãã«ããããã®èªåæé ãæå¹ã«ãªãå ŽåããããŸããå¥ã®å Žæã§ãã¹ãããŠããå Žåã¯ã蚌ææžãããŠã³ããŒãããããã䜿çšããããã«ãµãŒããŒãæ§æããå¿ èŠããããŸãã
ã¹ããã3. Webãµã€ãã®HTTPS蚌ææžãã€ã³ã¹ããŒã«ãã
cpanel
- ãSSL / TLSãããŒãžã£ãŒãã«æ»ããŸããã蚌ææžïŒCRTïŒããã¯ãªãã¯ããŠãæ°ãã蚌ææžãã€ã³ããŒãããŸãã
cPanelã®ãSSL / TLSãããŒãžã£ãŒãã»ã¯ã·ã§ã³ïŒã©ãŒãžããŒãžã§ã³ãåç §ïŒ
- âPaste, Upload or Generateâ âCertificateâ. , HTTPS, âBrowseâ.
HTTPS cPanel ( . )
- HTTPS, , . âSave Certificateâ.
HTTPS cPanel ( . )
- , .
HTTPS cPanel ( . )
- âCertificates (CRT)â, HTTPS.
âCertificatesâ cPanel HTTPS. ( . )
- âSSL/TLS Managerâ. âInstall and Manage SSL for your website (HTTPS)â, - .
âSSL/TLS Managerâ cPanel. ( . )
- âInstall an SSL Websiteâ. âBrowse Certificatesâ HTTPS. - ( ) âCertificateâ âPrivate Keyâ.
âInstall an SSL Websiteâ cPanel. ( . )
ã§Webãµã€ãã«ã¢ã¯ã»ã¹ã§ããããšã確èªããŸã
https://www.example.com
ããã¹ãŠãæ£åžžã«æ©èœããå Žåã¯ãããããHTTPãã©ãã£ãã¯ãHTTPSã«æ°žç¶çã«ãªãã€ã¬ã¯ãããå¿ èŠããããŸãããããè¡ãã«
.htaccess
ã¯ããµãŒããŒã®ã«ãŒããã£ã¬ã¯ããªã«ãããã¡ã€ã«ïŒApache WebãµãŒããŒãããå ŽåïŒã«æ°è¡ãè¿œå ããŸãããã¡ã€ã«ãå Žåã¯æ¢ã«ååšããŠãããããªãã ãã®è¡ãæ¿å ¥ããåã«æ¢åã®ãã£ã¬ã¯ãã£ãã®åŸã
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
.htaccess
RewriteCond
RewriteRule
RewriteEngine On
LinuxãFreeBSD
çæãããç§å¯éµïŒ
example.com.key
ïŒã蚌ææžçœ²åèŠæ±ïŒ
example.com.csr
ïŒããã³æå¹ãªHTTPS 蚌ææžïŒïŒãé©åãªãã£ã¬ã¯ããªã«é 眮ã
example.com.crt
ãŸãã
- DebianãUbuntuããã³ã¯ããŒã³ãFreeBSD
cp example.com.crt /etc/ssl/certs/
cp example.com.key /etc/ssl/private/
cp example.com.csr /etc/ssl/private/
- Red HatãCentOSãããã³ã¯ããŒã³
cp example.com.crt /etc/pki/tls/certs/
cp example.com.key /etc/pki/tls/private/
cp example.com.csr /etc/pki/tls/private/
restorecon -RvF /etc/pki
ãã¡ã€ã«ã¯ã«ãŒãã«å±ããæš©éèšå®ã«ãã£ãŠä¿è·ãããŠããå¿ èŠããããŸã
600
ã
- DebianãUbuntuãããã³ã¯ããŒã³
chown -R root. /etc/ssl/certs /etc/ssl/private
chmod -R 0600 /etc/ssl/certs /etc/ssl/private
- Red HatãCentOSãããã³ã¯ããŒã³
chown -R root. /etc/pki/tls/certs /etc/pki/tls/private
chmod -R 0600 /etc/pki/tls/certs /etc/pki/tls/private
- Freebsd
chown -R root:wheel /etc/ssl/certs /etc/ssl/private
chmod -R 0600 /etc/ssl/certs /etc/ssl/private
ã¢ããã
ãµã€ãã§HTTPSãæå¹ã«ããã«ã¯ã次ãå®è¡ããå¿ èŠããããŸãã
- mod_sslããµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠããããšã確èªããŠãã ããã
- åä¿¡ããHTTPS蚌ææžïŒ
.crt
ïŒã®ãã¡ã€ã«ããµãŒããŒã«ã¢ããããŒããã - ApacheãµãŒããŒæ§æãã¡ã€ã«ãç·šéããŸãã
ããã§ãã¯ããããšããå§ã
mod_ssl
ãŸãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«å¿ããŠããªãã·ã§ã³ã®ãããããæ©èœããŸãã
apache2 -M | grep ssl
ãŸãã¯
httpd -M | grep ssl
mod_ssl
ã€ã³ã¹ããŒã«ãããŠããå Žåãããªãã¯ãã®ãããªçããåŸãã§ããã... ...ãŸãã¯é¡äŒŒããäœããã€ã³ã¹ããŒã«ãããŠããªããæ©èœããªãå Žåã¯ããããè©ŠããŠãã ããïŒ
ssl_module (shared)
Syntax OK
- DebianãUbuntuãããã³ã¯ããŒã³
sudo a2enmod ssl
sudo service apache2 restart
- Red HatãCentOSãããã³ã¯ããŒã³
sudo yum install mod_ssl
sudo service httpd restart
- Freebsd
make -C /usr/ports/www/apache24 config install clean
apachectl restart
Apacheæ§æãã¡ã€ã«ïŒhttpd.confïŒãç·šéããŸãã
- DebianãUbuntu
/etc/apache2/apache2.conf
- Red HatãCentOS
/etc/httpd/conf/httpd.conf
- Freebsd
/usr/local/etc/apache2x/httpd.conf
Listen 80 Listen 443 <VirtualHost *:80> ServerName example.com ServerAlias www.example.com Redirect 301 / https://www.example.com/ </VirtualHost> <VirtualHost *:443> ServerName example.com Redirect 301 / https://www.example.com/ </VirtualHost> <VirtualHost *:443> ServerName www.example.com ... SSLEngine on SSLCertificateFile/path/to/signed_certificate_followed_by_intermediate_certs SSLCertificateKeyFile /path/to/private/key # Uncomment the following directive when using client certificate authentication #SSLCACertificateFile /path/to/ca_certs_for_client_authentication # HSTS (mod_headers is required) (15768000 seconds = 6 months) Header always set Strict-Transport-Security "max-age=15768000" ... </VirtualHost> # intermediate configuration, tweak to your needs SSLProtocol all -SSLv3 SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS SSLHonorCipherOrder on SSLCompression off SSLSessionTickets off # OCSP Stapling, only in httpd 2.3.3 and later SSLUseStapling on SSLStaplingResponderTimeout 5 SSLStaplingReturnResponderErrors off SSLStaplingCache shmcb:/var/run/ocsp(128000)
ãã®æ§æã¯ãåè¿°ã®Mozilla SSL Configuration Generatorã䜿çšããŠçæãããŸãããããã䜿çšããŠãæ§æã®é¢é£æ§ã確èªããŸãã蚌ææžãšç§å¯ããŒã®æ£ãããã¹ãç·šéããŸããããã«ç€ºãããŠããæ§æã¯äžéèšå®ã§çæãããŠããŸã-æé©ãªèšå®ãéžæããåã«ãåèšå®ã®å¶éãšãã©ãŠã¶ãŒã®æ§æã«ã€ããŠèªãã§ãã ããã
HTTPããHTTPSãžã®ãªãã€ã¬ã¯ããããã³é
www
ãã¡ã€ã³c
www
ïŒSEOã¿ã¹ã¯ã«æçšïŒããã®ãªãã€ã¬ã¯ããåŠçããããã«ãã³ãŒãã«ããã€ãã®å€æŽãå ããããŸããã
Nginx
nginxïŒ
nginx.conf
ïŒæ§æãã¡ã€ã«ãç·šéããŸãã
- DebianãUbuntuãRed HatãCentOS
/etc/nginx/nginx.conf
- Freebsd
/usr/local/etc/nginx/nginx.conf
server { listen 80 default_server; listen [::]:80 default_server; # Redirect all HTTP requests to HTTPS with a 301 Moved Permanently response. return 301 https://$host$request_uri; } server { listen 443 ssl http2; listen [::]:443 ssl http2; # certs sent to the client in SERVER HELLO are concatenated in ssl_certificate ssl_certificate /path/to/signed_cert_plus_intermediates; ssl_certificate_key /path/to/private_key; ssl_session_timeout 1d; ssl_session_cache shared:SSL:50m; ssl_session_tickets off; # Diffie-Hellman parameter for DHE ciphersuites, recommended 2048 bits ssl_dhparam /path/to/dhparam.pem; # intermediate configuration. tweak to your needs. ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS'; ssl_prefer_server_ciphers on; # HSTS (ngx_http_headers_module is required) (15768000 seconds = 6 months) add_header Strict-Transport-Security max-age=15768000; # OCSP Stapling --- # fetch OCSP records from URL in ssl_certificate and cache them ssl_stapling on; ssl_stapling_verify on; ## verify chain of trust of OCSP response using Root CA and Intermediate certs ssl_trusted_certificate /path/to/root_CA_cert_plus_intermediates; resolver <IP DNS resolver>; .... }
ãã®æ§æã¯ãåè¿°ã®Mozilla SSL Configuration Generatorã䜿çšããŠçæãããŸãããããã䜿çšããŠãæ§æã®é¢é£æ§ã確èªããŸãã蚌ææžãšç§å¯ããŒã®æ£ãããã¹ãç·šéããŸããããã«ç€ºãããŠããæ§æã¯äžéèšå®ã§çæãããŠããŸã-æé©ãªèšå®ãéžæããåã«ãåèšå®ã®å¶éãšãã©ãŠã¶ãŒã®æ§æã«ã€ããŠèªãã§ãã ããã
ãžã§ãã¬ãŒã¿ãŒã¯ãHTTPããHTTPSãžã®ãªãã€ã¬ã¯ããåŠçããã³ãŒããèªåçã«çæããæåã«HTTP / 2ãµããŒããã¢ã¯ãã£ãã«ããŸãïŒ
- âStartâ â âAdministrative Toolsâ â âInternet Information Services (IIS) Managerâ. . âServer Certificatesâ .
âInternet Information Services (IIS) Managerâ. âServer Certificatesâ. ( . )
- âComplete Certificate Requestâ .
âComplete Certificate Requestâ . ( . )
- (
example.com.crt
), . - âFriendly nameâ, . âPersonalâ (IIS 8+). âOKâ.
. ( . )
- , âServer Certificatesâ.
âServer Certificatesâ. ( . )
- . âSitesâ -, HTTPS. âBindingsâ .
- âBindingsâ. ( . )
- âSite Bindingsâ âAddâ.
âAddâ. ( . )
- :
- âTypeâ: âhttpsâ
- âIP addressâ: âAll Unassignedâ
- âPortâ: â443â
âSSL Certificateâ HTTPS . âOKâ.
âHTTPSâ HTTPS. ( . )
- - HTTP HTTPS.
- HTTP HTTPS. ( . )
ã¢ãã¬ã¹ããŒã®è¿ãã«ãèŠåãµã€ã³ãšãæ¥ç¶ã¯å®å šã§ã¯ãããŸããïŒããŒãžã®äžéšã¯ä¿è·ãããŠããŸããïŒç»åãªã©ïŒããããã¯ã蚌ææžã誀ã£ãŠã€ã³ã¹ããŒã«ããããšãæå³ãããã®ã§ã¯ãããŸãããããŒã«ã«ãµãŒããŒãšãªã¢ãŒããµãŒããŒã®äž¡æ¹ã®ãã¹ãŠã®ãªãœãŒã¹ïŒã€ã¡ãŒãžãã¹ã¿ã€ã«ã·ãŒããã¹ã¯ãªãããªã©ïŒãžã®ãªã³ã¯ãã§å§ãŸããªãããšã確èªããŠãã ãã
http://
ããã¹ãŠã®ãªãœãŒã¹ã¯ãã«ãŒãïŒã«é¢é£ããã¢ãã¬ã¹ãæããŠããå¿ èŠããã
/images/image.png
ã
/styles/style.css
ãªã©ãD.ïŒãŸãã¯ïŒçŸåšã®ããã¥ã¡ã³ãã«å¯Ÿããçžå¯Ÿ
../images/image.png
ïŒããŸãã¯ããã§å§ãŸãå®å šãªURLã§ãªããã°ãªããŸãã
https://
ãã
<script src="https://code.jquery.com/jquery-3.1.0.min.js"></script>
ã
ãããã®ãã³ãã¯ãæ··åã³ã³ãã³ãã®èŠåã解決ããã®ã«åœ¹ç«ã¡ããã©ãŠã¶ã«ã¯æå笊ã®ãªãããã¯ãããå京é ã衚瀺ãããŸãã
ãµãŒããŒãã¹ã
HTTPSã䜿çšããŠãµãŒããŒãæ§æããŠèµ·åããããQualys SSL Server Testã䜿çšããŠæ§æã®ã»ãã¥ãªãã£ã確èªããããšã匷ããå§ãããŸããæ§æã®å æ¬çãªè©äŸ¡ãå«ãWebãµã€ããã¹ãã£ã³ããæœåšçãªåŒ±ç¹ãç¹å®ããæšå¥šäºé ãäœæããŸãã圌ã®ãã³ãã«åŸã£ãŠããµãŒããŒã®ã»ãã¥ãªãã£æ§æãããã«æ¹åããŠãã ããã
æŽæ°
蚌ææžã¯äžå®ã®æé-éåžžã¯1幎éæå¹ã§ãããããæŽæ°ããæåŸã®ç¬éãåŸ ããªãã§ãã ãã-æŽæ°ã®æéãè¿ã¥ããŠãããšãã«ã¬ãžã¹ãã©ã¯ããªãã«é»åã¡ãŒã«ãéä¿¡ãå§ããŸããæåã®éç¥ãåãåã£ããããã«æ°ãã蚌ææžãçºè¡ããŸããæé ã¯ã»ãŒåãã§ãã蚌ææžçœ²åèŠæ±ãäœæããæ°ããHTTPS蚌ææžãååŸããŠããµãŒããŒã«ã€ã³ã¹ããŒã«ããŸãã蚌ææžã¯çœ²åããç¬éãã倱å¹ããŸãããæå¹æéã¯åã®èšŒææžã®å€±å¹ãã1幎åŸã«èšå®ãããŸãããããã£ãŠãäž¡æ¹ã®èšŒææžãæå¹ã«ãªãæéããããå€ã蚌ææžã®æå¹æéãåããŠãã1幎ãçµéããŸãããã®éè€ã®éãããªãã¯ç¢ºèªããæ©äŒããããŸãå€ã蚌ææžã®æå¹æéãåããåã«æ°ãã蚌ææžãæ£åžžã«æ©èœããããšã«ããããŠã§ããµã€ãã®åæ»ãªéçšãä¿èšŒãããŸãã
ãã£ãŒãããã¯
ãµãŒããŒãå±éºã«ãããããŠããå ŽåããŸãã¯èª°ãããã©ã€ããŒãããŒã«ã¢ã¯ã»ã¹ã§ããå¯èœæ§ããããšæãããå Žåã¯ãçŸåšã®HTTPS蚌ææžãããã«åãæ¶ãå¿ èŠããããŸããã¬ãžã¹ãã©ã«ãã£ãŠæé ã¯ç°ãªããŸãããäžè¬çã«ã¯ãã¬ãžã¹ãã©ã®ç¹å¥ãªããŒã¿ããŒã¹ã§äŸµå®³ããã蚌ææžãéã¢ã¯ãã£ããšããŠããŒã¯ããæ°ããHTTPS蚌ææžãçºè¡ããããšã«ãªããŸãããã¡ããã誰ãããªãã«ãªãããŸãããšãã§ããªãããã«ãã§ããã ãæ©ãçŸåšã®èšŒææžã倱å¹ãããã»ãã¥ãªãã£éåã®åå ãèŠã€ããŠä¿®æ£ããåŸã«ã®ã¿æ°ãã蚌ææžãã€ã³ã¹ããŒã«ããŠãã ãããã¬ãžã¹ãã©ã«å©ããæ±ããããšãã§ããŸãã
æå·åããŸããã
ãŠã§ããµã€ãLet's EncryptãåŒçšããŸãããïŒ
Let's Encrypt â , (CA), . Let's Encrypt Internet Security Research Group (ISRG) .
Let's Encrypt:
Let's Encrypt .- èªåå
- Let's Encrypt , .- å®å šæ§
Let's Encrypt TLS, , - .- éææ§
çºè¡ãŸãã¯åãæ¶ããã蚌ææžã¯ãã¹ãŠãå ¬çã«èšé²ããã誰ã§ãé²èŠ§ã§ããããã«ãªããŸãã- éæŸæ§
èªåçºè¡ããã³æŽæ°ãããã³ã«ã¯ãä»ã®äººã䜿çšã§ãããªãŒãã³ã¹ã¿ã³ããŒããšããŠå ¬éãããŸãã- ã³ã©ãã¬ãŒã·ã§ã³
ã€ã³ã¿ãŒãããã®æ ¹åºã«ãããããã³ã«ãšåæ§ã«ãLet's Encryptã¯ãã©ã®çµç¹ã«ã管çãããŠããªãã³ãã¥ããã£ã®å©çã®ããã®å ±åãããžã§ã¯ãã§ãã
Let's Encryptãå©çšããã«ã¯ããã¹ãã£ã³ã°ãŸãã¯ãµãŒããŒã§ã¢ã«ãŠã³ããé©åã«æ§æããå¿ èŠããããŸããæå·åãè¡ã£ãŠãçæçãªèšŒææžãçºè¡ããŸããããã¯ãå®æçã«æŽæ°ããŠHTTPS Webãµã€ããéçšãç¶ããå¿ èŠããããŸãã
ä»çµã¿
Let's Encryptãšä»ã®èªèšŒæ©é¢ã®ããã©ãŒãã³ã¹ã«ã¯ããã€ãã®éèŠãªéãããããŸããäžèšã®æåã®3ã€ã®ãã€ã³ãã«åŸã£ãŠããããã®éãã¯æ¬¡ã®ãšããã§ãã
-
Let's Encryptã®ç¡æ HTTPS蚌ææžã¯ããµã€ãã®å šæéãéããŠå®å šã«ç¡æã§ãã - èªåå
1幎éæå¹ãªéåžžã®HTTPS蚌ææžãšã¯ç°ãªããHTTPS蚌ææžã®æå·åã¯90æ¥éæå¹ã§ãã人ã ã¯ã蚌ææžã®æŽæ°ãèªååããããæ±ããããŠããŸããããšãã°ããµãŒããŒç®¡çè ã¯ç¹æ®ãªãœãããŠã§ã¢ãµãŒãã¹ãéå§ïŒãŸãã¯å®æçã«cronããããã°ã©ã ãåŒã³åºãïŒããŠããã¡ã€ã³ã®åææ€èšŒãšãã®ãã¡ã€ã³ãã¹ãŠã®åŸç¶ã®æŽæ°ããã€ã³ã¹ããŒã«ããŠå¿ãããã¹ã¿ã€ã«ã§ç®¡çã§ããŸãã - å®å
šæ§
HTTPS Let's Encrypt , . , .
å¶éäºé
æå·åã¯DV蚌ææžã®ã¿ãçºè¡ããŸãã OVããã³EV蚌ææžã¯ãµããŒããããŠããŸãããçŸåšããããããµããŒãããäºå®ã¯ãããŸããã蚌ææžã¯1ã€ãŸãã¯è€æ°ã®ãã¡ã€ã³ã«å¯ŸããŠçºè¡ãããŸãããçŸæç¹ã§ã¯ãµããã¡ã€ã³ïŒã¯ã€ã«ãã«ãŒãïŒãæã€èšŒææžã¯ãããŸããã詳现ã«ã€ããŠã¯ãLet's Encrypt FAQãåç §ããŠãã ããã
Let's Encryptã®èªåã¢ãŒãã§ã¯ãæå³çã§æå³ããªãæªçšããã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããã«ã䜿çšã«ããã€ãã®å¶éã課ãããŸãã䜿çšåŒ·åºŠã®å¶éã¯ååã«é«ããããæ°çŸã®ãã¡ã€ã³ãèªç±ã«äœ¿çšã§ããäžè¬ãŠãŒã¶ãŒã§ã䜿çšã§ããŸããããã ããHTTPS蚌ææžãéåžžã«å€§èŠæš¡ã«ç®¡çããå Žåã¯ããããã®å¶éã«æ £ããå¿ èŠããããŸãã
å€ãã¯ã©ã€ã¢ã³ããšãšããŸããã¯ãªã¯ã©ã€ã¢ã³ãïŒWindows XP SP3ããåïŒã¯ãµããŒããããŠããŸããã詳现ã«ã€ããŠã¯ãäºææ§ããŒãžãåç §ããŠãã ããã
HTTPS蚌ææžãå®éã«æå·åããŠã¿ãŸããã
cpanel
- ãã¹ãã®cPanelã«ãã°ã€ã³ããŸãã
- ãã»ãã¥ãªãã£ãã»ã¯ã·ã§ã³ãŸã§ã¹ã¯ããŒã«ããŠã³ãããcPanelã§æå·åããŸãããããã¯ãªãã¯ããŸãã
cPanelã®ã»ãã¥ãªãã£ã»ã¯ã·ã§ã³ãïŒã©ãŒãžããŒãžã§ã³ãåç §ïŒ
- ãcPanelã§æå·åããŸããããã»ã¯ã·ã§ã³ã«ããŸãããã¡ã€ã³åïŒã®äž¡æ¹ããã§ãã¯
example.com
ããŠwww.example.com
ïŒãããåŸããçºè¡è€æ°ããã¯ãªãã¯ããŠãã ããã
äž¡æ¹ã®ãã¡ã€ã³åã確èªãããè€æ°çºè¡ããã¯ãªãã¯ããŸããïŒã©ãŒãžããŒãžã§ã³ãåç §ïŒ
- . ( -
www
,www
, âSubject Alt Nameâ (SAN) HTTPS. âIssueâ. , , â .
âIssueâ . ( . )
- , . «», .
, . ( . )
- ããã«ããLet's Encrypt certificatesã䜿çšãããã¡ã€ã³ããåç
§ããŠãã ãããã-
https://
ã
Let's EncryptãïŒãïŒ
Let's Encryptâ Certbotã-âã
Certbot for Let's EncryptïŒãïŒ
çŸåšãWindowsã«ã¯IISã®å ¬åŒã¯ã©ã€ã¢ã³ãã¯ãããŸããããããã€ãã®åé¿çããããŸãã
Let's Encryptã®ãã€ãã£ãWindowsã¯ã©ã€ã¢ã³ããäœæããããšãç®çãšããããã€ãã®ãããžã§ã¯ãïŒ
- ACMESharpïŒPowerShellïŒã¯ãWindowsã¯ã©ã€ã¢ã³ããèšè¿°ããæåã®è©Šã¿ã§ãã
- letsencrypt-win-simpleïŒã³ãã³ãã©ã€ã³çšïŒãæã䜿ããããããã§ãã
- Certifyã¯ACMESharpã®äžã«GUIãæäŸããŸããããŸã ã¢ã«ãã¡çã§ãã
ã¯ã©ãŠããã¬ã¢
Cloudflareã¯ãã³ã³ãã³ãé ä¿¡ãããã¯ãŒã¯ïŒCDNïŒãWebãµã€ãã®ã»ãã¥ãªãã£ãµãŒãã¹ãããã³DDoSæ»æã«å¯Ÿããä¿è·ãæäŸãããµãŒãã¹ã§ããç¡æã®æéãå«ããã¹ãŠã®æéãã©ã³ã§ç¡æã®HTTPS蚌ææžãæäŸããŸããããã¯DV Cloudflare Universal SSLã®éå蚌ææžã§ããäžæã®HTTPS蚌ææžãååŸããã«ã¯ãããžãã¹æéã«åãæ¿ããå¿ èŠããããŸãã
蚌ææžãååŸããã«ã¯ãã¢ã«ãŠã³ããäœæããWebãµã€ããäœæããŠãæå·åãã»ã¯ã·ã§ã³ã«é²ã¿ãŸãã
CertSimple
CertSimpleã¯EV蚌ææžã®ã¿ãæäŸããŸããDV HTTPS蚌ææžåžå Žã§Let's Encryptãè¡ã£ãããã«ãEV HTTPS蚌ææžåžå Žã«é©åœããããããéåžžã¯é ããŠè² æ ã倧ããçµç¹ãæ€èšŒããããã®ããè¿ éã§ç°¡åãªããã»ã¹ãæäŸããŸããããã®å©ç¹ã¯æ¬¡ã®ãšããã§ãã
-
. , . -
, , 7-10 . -
.
- HTTPS IP-
ãã³ãã·ã§ã€ã¯ããã»ã¹ã®æ§è³ªã®ãããåãIPã¢ãã¬ã¹äžã®ä»®æ³ãã¹ãã¯TLSã®åé¡ã§ããã¯ã©ã€ã¢ã³ãã¯HTTPãªã¯ãšã¹ãã®ããããŒã«ãã¡ã€ã³åãå«ãããããä»®æ³ãã¹ãã¯æ©èœããŸãããHTTPSã䜿çšããå Žåãæåã®HTTPãªã¯ãšã¹ããéä¿¡ãããåã«TLSãã³ãã·ã§ã€ã¯ãçºçããŸããããããŒãå«ãããã®ãããã¯ã©ã€ã¢ã³ãã«æ¥ç¶ããåã«ããµãŒããŒã¯ã©ã®èšŒææžãæ瀺ããããç¥ããªããããæ§æãã¡ã€ã«ã®æåã®èšŒææžã衚瀺ãããŸãããããŠãã¡ããããã®èšŒææžã¯ãªã¹ãã®æåã®TLSãµã€ãã§ã®ã¿æå¹ã§ãã
ãã®åé¡ãåé¿ããæ¹æ³ã¯ããã€ããããŸããTLSã䜿çšããŠåãã¡ã€ã³ã®äžæã®IPã¢ãã¬ã¹ãååŸãããã1ã€ã®èšŒææžã§ãã¹ãŠã®ãã¡ã€ã³ãç»é²ããŸããäž¡æ¹ã®æ¹æ³ã¯å®éã«ã¯ããŸããããããŸãã-IPv4ã¢ãã¬ã¹ã¹ããŒã¹ã¯æ¢ã«äœ¿ãæããããŠããŸã.1ã€ã®å€§ããªHTTPS蚌ææžã«ãã¹ãŠã®ãµã€ããç»é²ãããšãæ°ãããµã€ãããµãŒããŒã«è¿œå ãããšãã«ã蚌ææžå šäœãè€æ°ã®ãã¡ã€ã³ã«åçºè¡ããå¿ èŠããããŸãã
ãã®å¶éã«å¯ŸåŠããããã«ãTLSãããã³ã«ã®æ¡åŒµãServer Name IndicationïŒSNIïŒãšããååã§éçºãããŸããããµãŒããŒãšã¯ã©ã€ã¢ã³ãã®äž¡æ¹ã§ãµããŒããããŠããå¿ èŠããããŸãã SNIãµããŒãã¯ä»æ¥åºãæ®åããŠããŸãããå¯èœæ§ã®ãããã¹ãŠã®é¡§å®¢ãšã®äºææ§ã®ä¿èšŒãããªãã«ãšã£ãŠéèŠã§ããå ŽåããŸã 100ïŒ ä¿èšŒãããŠããŸããã
SNIã®éå§ã«é¢ãã詳现Apacheãnginxãããã³IISïŒ8+ïŒã«ã€ããŠã¯ãé¢é£ããã¥ã¡ã³ããåç §ããŠãã ããã
æçšãªãªãœãŒã¹
- Mozilla SSLæ§æãžã§ãã¬ãŒã¿ãŒ
- SSLãµãŒããŒãã¹ããQualys
- Mozilla Wiki ã«ãããµãŒããŒåŽTLSã»ãã¥ãªãã£
- SSLããã³TLSãå®è£ ããããã®ãã¹ããã©ã¯ãã£ã¹ãSSL Labs
- ããã¥ã¡ã³ããQualys SSL Labs
- ããŒã¿ããŒã¹ã®çžäºæ¥ç¶IT ã§æ€çŽ¢ããã³çœ®æããããã®PHPã¹ã¯ãªãããWordPressããŒã¿ããŒã¹å ã®ãã¹ãŠã®HTTPèšåãHTTPSïŒãªã³ã¯ãç»åãªã©ïŒã«çœ®ãæããããã