èªèšŒ
ãŸããŸãå€ãã®ãµã€ããHTTPSãæ¡çšããŠããããã蚌ææžããããçã®ãŽãŒã«ãã©ãã·ã¥ãçºçããŠããŸãã ã»ãã¥ãªãã£ãšãã©ã€ãã·ãŒã®æãããªå©ç¹ã«å ããŠãå®å šãªæ¥ç¶ãå®è£ ããããšã«ã¯ä»ã®å©ç¹ããããŸããããã«ã€ããŠã¯ãã HTTPSã¯å¿ èŠãªããšæããŸããïŒ ãã äžè¬ã«ãSSL蚌ææžããŸãã¯ãHTTPS蚌ææžããšåŒã°ããããšã¯ãã€ã³ã¿ãŒãããã®æŽå²ã§èŠãããšã®ãªãé床ã§é£æ£ããŸãã æ¯æ¥ããã©ãã£ãã¯ã®æåã®100äžãããµã€ãã調æ»ãããããã®ã»ãã¥ãªãã£ã®ããŸããŸãªåŽé¢ãåæãã6ãæããšã«ã¬ããŒããçºè¡ããŠããŸãã ãããã®ã¬ããŒãã¯ããã§èª¿ã¹ãããšãã§ããŸãããä»ã®ãšããã¯HTTPSå®è£ ã®ããŒã¹ãèŠãŠã¿ãŸãããã
Alexaã®çµ±èšã«ãããšãHTTPSããŒãžã§ã³ãžã®ãªãã€ã¬ã¯ããããæåã®100äžã®æã人æ°ã®ãããµã€ãããã®ãµã€ãã®å²å
HTTPSã®å®è£ ãç¶ç¶ããŠããã ãã§ãªããå®è£ ã®é床ãåäžããŠããŸãã æ¬åœã«é²æ©ããŠããããã§ãã åªããLet's Encryptã®ãããã§ãæéã®çµéãšãšãã«èšŒææžãååŸããããã»ã¹ãããç°¡åã«ãªããŸããããã«ã蚌ææžãç¡æã«ãªããŸããã ã€ãŸãã蚌ææžçœ²åèŠæ±ïŒCSRïŒã蚌ææ©é¢ïŒCAïŒã«éä¿¡ããã ãã§ã圌ã¯ãã¡ã€ã³ã®æææš©ã®èšŒæãç³ãåºãŸãã ããã¯éåžžãDNS TXTã¬ã³ãŒããå€æŽãããããã¡ã€ã³ã®ã©ã³ãã ãªURLã®ã©ããã«ã«ã¹ã¿ã ã³ãŒããé 眮ããããšã«ãã£ãŠè¡ãããŸãã ã¿ã¹ã¯ãå®äºãããšãCAã¯èšŒææžãçºè¡ãããã©ãŠã¶ãŒã«æ瀺ããŠãã¢ãã¬ã¹ããŒã«ç·è²ã®ããã¯ãšHTTPSã衚瀺ã§ããŸãã
éå§å Žæ ã æ£ããã¢ããã°ã¬ãŒãããæ¹æ³ã äºé蚌ææžã®äœ¿çšæ¹æ³ãªã©ããã®ããã»ã¹ã«é¢ããããã€ãã®æ瀺ãæžããŸããã ããã¯ãã¹ãŠçŽ æŽãããã§ããã ããããåé¡ã¯äœã§ããïŒ ãããŠããã¹ãŠãèšç»éãã«é²ã¿ãããªããæªãæ¥ãéããããšãã«åé¡ãçºçããŸãã
ãããã³ã°ããã
誰ããããã®èšèãèããããããŸããããçŸå®ã¯ãç§ãã¡ãæããããé »ç¹ã«ããããèããªããã°ãªããªããšããããšã§ãã ããã«ãŒã¯ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããã°äœã§ãå ¥æã§ããå€ãã®å Žåãç§å¯éµãå¿ èŠã§ãã HTTPS蚌ææžã¯ããµã€ãã®ãã¹ãŠã®èšªåè ã«éä¿¡ããå ¬éããã¥ã¡ã³ãã§ãããä»ã®äººãåã蚌ææžã䜿çšã§ããªãããã«ããå¯äžã®ããšã¯ãç§å¯ããŒã®æ¬ åŠã§ãã ãã©ãŠã¶ããµã€ããžã®å®å šãªæ¥ç¶ã確ç«ãããšã䜿çšãããŠãã蚌ææžã®ç§å¯éµããµãŒããŒã«ããããšã確èªããŸãã ã ãã誰ãç§ãã¡ã®èšŒææžã䜿çšã§ããŸããã ããã«ãŒãç§å¯éµãåãåããšãç¶æ³ã¯å€ãããŸãã
æ»æè ãç§å¯éµãææããŠããå Žåãæ»æè ã¯ç§ãã¡ã«ãªãããŸãããšãã§ããŸãã ãããç¹°ãè¿ããŸããããã€ã³ã¿ãŒãããäžã®èª°ããèªåãããªãã§ããããšã蚌æã§ããŸãããå®éã«ã¯ããã§ã¯ãããŸããã ããã¯æ¬åœã®åé¡ã§ãããããªããèããåã«ããããã¯ç§ã«ã¯æ±ºããŠèµ·ãããŸããããšHeartbleedãæãåºããŠãã ããã OpenSSLã©ã€ãã©ãªã®ãã®å°ããªãã°ã«ããããã¹ãŠã®ã»ãã¥ãªãã£å¯Ÿçãè¬ããå Žåã§ããæ»æè ã¯ç§å¯éµãçãããšãã§ããŸããã ãŸããå¶ç¶ãŸãã¯é倱ã«ããç§å¯éµãæŒæŽ©ããã±ãŒã¹ã¯ç¡æ°ã«ãããŸãã çŸå®ã«ã¯ãç§å¯ããŒãçŽå€±ããå¯èœæ§ãããããããçºçããå Žåãæ»æè ã蚌ææžã䜿çšã§ããªãããã«ããæ¹æ³ãå¿ èŠã§ãã 圌ãæãåºãå¿ èŠããããŸãã
ãã£ãŒãããã¯
䟵害ãããå Žåãæªçšã®å¯èœæ§ãæé€ããããã«èšŒææžã倱å¹ãããå¿ èŠããããŸãã 蚌ææžã倱å¹ãšããŠããŒã¯ããããšããã©ãŠã¶ã¯ãæéãåããŠããªããŠãä¿¡é Œã§ããªãããšãèªèããŸãã ææè ãã¬ãã¥ãŒãèŠæ±ãããããã¯ã©ã€ã¢ã³ãã¯ãã®èšŒææžãåãå ¥ããŠã¯ãªããŸããã
ãããã³ã°ã®äºå®ãç¥ããšããã«ãCAã«é£çµ¡ãã蚌ææžã®åãæ¶ããäŸé ŒããŸãã 蚌ææžãææããŠããããšã蚌æããå¿ èŠããããŸãããããè¡ããšããã«ãCAã¯èšŒææžã倱å¹ãšããŠããŒã¯ããŸãã 次ã«ããã®æ å ±ãå¿ èŠãšãããã¹ãŠã®ã¯ã©ã€ã¢ã³ãã«ãã®äºå®ãäŒããæ¹æ³ãå¿ èŠã§ãã çŸæç¹ã§ã¯ããã©ãŠã¶ã¯ãã¡ããäœãç¥ããŸãããããã¯åé¡ã§ãã æ å ±ã®é åžã«äœ¿çšããã2ã€ã®ã¡ã«ããºã ããããŸãã蚌ææžå€±å¹ãªã¹ãïŒCRLïŒãšãªã³ã©ã€ã³èšŒææžã¹ããŒã¿ã¹ãããã³ã«ïŒOCSPïŒã§ãã
蚌ææžå€±å¹ãªã¹ã
CRLã¯å®éã«ã¯éåžžã«åçŽãªæŠå¿µã§ãããCAã倱å¹ãšããŒã¯ãããã¹ãŠã®èšŒææžã®ãªã¹ãã«ãããŸããã ã¯ã©ã€ã¢ã³ãã¯ãCRLãµãŒããŒã«èŠæ±ãéä¿¡ãããªã¹ãã®ã³ããŒãããŠã³ããŒãã§ããŸãã ãã®ãªã¹ãã®ã³ããŒããããšããã©ãŠã¶ã¯æ瀺ããã蚌ææžããã§ãã¯ããŸãã ååšããå Žåããã©ãŠã¶ã¯èšŒææžãç¡å¹ã§ãããä¿¡é Œã§ããªãããšãèªèãããšã©ãŒãã¹ããŒããŠåæããŸãã 蚌ææžããªã¹ãã«ãªãå Žåããã¹ãŠãæ£åžžã§ããããã©ãŠã¶ã¯åŒãç¶ãåäœããŸãã
CRLã®åé¡ã¯ããªã¹ãã«ç¹å®ã®èšŒææ©é¢ããã®å€ãã®èšŒææžãå«ãŸããŠããããšã§ãã ããŸã詳现ã«èª¬æããªããŠãããããã¯äžéCA蚌ææžã«åå²ããã蚌ææ©é¢ã¯å°ããªéšåã§ãªã¹ããçºè¡ã§ããŸãããåé¡ã¯åããŸãŸã§ãã CRLã«ã¯ããªãã®ãµã€ãºããããŸãã å¥ã®åé¡ã¯ãã¯ã©ã€ã¢ã³ããCRLã®æ°ããã³ããŒãæã£ãŠããªãããããµã€ããžã®æåã®æ¥ç¶ã§ãããèŠæ±ããå¿ èŠããããããæé å šäœãèããé ããªãå¯èœæ§ãããããšã§ãã ãã¹ãŠãèŠæ ãããããªãã®ã§ãOCSPãèŠãŠã¿ãŸãããã
蚌ææžã¹ããŒã¿ã¹æ€èšŒãããã³ã«
OCSPã¯ããã®åé¡ã«å¯Ÿããã¯ããã«çŸãããœãªã¥ãŒã·ã§ã³ãæäŸããCRLã«æ¯ã¹ãŠå€§ããªå©ç¹ããããŸãã ããã§ã¯ãCAã«åäžã®ç¹å®ã®èšŒææžã®ã¹ããŒã¿ã¹ãèŠæ±ããŸãã ããã¯ãCAãåçŽãªåçã®ã¿ãè¿ãå¿ èŠãããããšãæå³ããŸãã蚌ææžã¯æå¹ãŸãã¯ç¡å¹ã§ããããã®ãããªå¿çã¯CRLãªã¹ããããã¯ããã«å°ãããªããŸãã ãããïŒ
確ãã«ãOCSPã¯å¿çã®åä¿¡é床ã«ãããŠCRLãããåªããŠããŸããããã®å©ç¹ãæ¯æãå¿ èŠããããŸãïŒãããçºçããå Žåãå«ãã§ããïŒïŒã äŸ¡æ Œã¯éåžžã«é«ã-ããã¯ããªãã®ãã©ã€ãã·ãŒã§ã... OCSPãªã¯ãšã¹ãã®æ¬è³ªãèãããšãããã¯åäžã®HTTPS蚌ææžã«å¯Ÿããéåžžã«å ·äœçãªãªã¯ãšã¹ãã§ãã å®éãæ å ±ã®æŒæŽ©ããããŸãã OCSPãªã¯ãšã¹ããéä¿¡ãããšããæåéã蚌ææ©é¢ã«å°ããŸãïŒ
pornhub.comã®èšŒææžã¯æå¹ã§ããïŒ
ãããã£ãŠãããã¯çæ³çãªã·ããªãªã§ã¯ãããŸããã ããã§ã蚪åãããµã€ãã®å±¥æŽããããªããäœãç¥ããªããµãŒãããŒãã£ã«ããããŠãã¹ãŠHTTPSã®ããã«æäŸããŸããããã«ããããã©ã€ãã·ãŒãšã»ãã¥ãªãã£ãåäžããŸãã ããããã¡ãã£ãšãäœãä»ã®ãã®ããããŸãã
å®å šãªå€±æ
äžèšã§ã¯ã2ã€ã®ãã©ãŠã¶ãŒèšŒææžæ€èšŒã¡ã«ããºã ã§ããCRLãšOCSPã«ã€ããŠèª¬æããŸãããããããã¯æ¬¡ã®ããã«ãªããŸãã
蚌ææžãåãåã£ãåŸããã©ãŠã¶ã¯ãããã®ãµãŒãã¹ã®1ã€ã«é£çµ¡ãã蚌ææžã®ã¹ããŒã¿ã¹ãæçµçã«å€æããèŠæ±ãéä¿¡ããŸãã ããããCAã®èª¿åãæªããã€ã³ãã©ã¹ãã©ã¯ãã£ããªãã©ã€ã³ã®å Žåã¯ã©ãã§ããããã ç¶æ³ããã®ããã«ãªã£ããã©ããªããŸããïŒ
ããã§ã¯ããã©ãŠã¶ã«ã¯2ã€ã®ãªãã·ã§ã³ãããããŸããã 蚌ææžã®ã¹ããŒã¿ã¹ã確èªã§ããªãããã蚌ææžã®åãå ¥ããæåŠããå ŽåããããŸãã ãŸãã¯ããªã¹ã¯ãåãã蚌ææžãåãæ¶ãããŠãããã©ããã«é¢ä¿ãªãããã®ã¹ããŒã¿ã¹ãç¥ããã«èšŒææžãåãå ¥ããŸãã ã©ã¡ãã®ãªãã·ã§ã³ã«ãé·æãšçæããããŸãã ãã©ãŠã¶ã蚌ææžã®åãå ¥ããæåŠãããšãCAã€ã³ãã©ã¹ãã©ã¯ãã£ããªãã©ã€ã³ã«ãªããã³ã«ããµã€ããããã«ç§»åããŸãã ãã©ãŠã¶ãåŒãç¶ã蚌ææžãåãå ¥ããå ŽåãçãŸãã蚌ææžãåãå ¥ããå±éºãããããŠãŒã¶ãŒãå±éºã«ããããŸãã ããã¯é£ããéžæã§ãããä»ãä»æ¥ãå®éã«ã¯äœãèµ·ãããŸãã...
éšåçãªæ é
å®éãä»æ¥ã®ãã©ãŠã¶ã¯ãéšåçãªå€±æã§ããããã蚌ææžå€±å¹ãã§ãã¯ãå®è¡ããŸãã ã€ãŸãããã©ãŠã¶ã¯èšŒææžã®ã¹ããŒã¿ã¹ããã§ãã¯ããããšããŸãããçãããŸã£ãããªãã£ãå ŽåããŸãã¯çæéã§è¿ãããªãã£ãå Žåããã©ãŠã¶ã¯ãã®ããšãå¿ããŸãã ããã«æªãããšã«ãChromeã¯èšŒææžãæ€èšŒããããšããããŸããã ã¯ããããªãã¯ãããæ£ããèªã¿ãŸãããChromeã¯åãåã£ã蚌ææžã®ã¹ããŒã¿ã¹ããã§ãã¯ããããšããããŸãã ã ããã¯å¥åŠã«æãããããããŸããããç§ã¯åœŒãã®ã¢ãããŒãã«å®å šã«åæããFirefoxãéããªãåäœãéå§ããå¯èœæ§ãé«ãããšãå ±åã§ããããšãå¬ããæããŸãã 説æãããŠãã ããã å®å šãªé害ã®åé¡ã¯æããã§ããCAã«æªãæ¥ãããã°ãæã ããããæ±ããããšã«ãªããŸããããããéšåçãªé害ã®è«çã«å°éããæ¹æ³ã§ãã ãã©ãŠã¶ã¯ã蚌ææžã®å€±å¹ã確èªããããšããŸãããæéãããããããå ŽåããŸãã¯CAããªãã©ã€ã³ã«ãªã£ããšæãããå Žåã¯ãå®å šã«æåŠããŸãã åŸ ã£ãŠãæåŸã®èšèã¯äœã§ãããïŒ ãCAããªãã©ã€ã³ã«ãªã£ããšæãããå Žåãã倱å¹ã®èšŒææžãã§ãã¯ã¯ãã£ã³ã»ã«ãããŸãã æ»æè ããã®ãããªç¶æ ãã·ãã¥ã¬ãŒãã§ããã®ã ãããïŒ
MiTMæ»æãå®è¡ããŠããå Žåã蚌ææžæ€èšŒèŠæ±ããããã¯ããCAãæ©èœããŠããªããšããå°è±¡ãäœæããã ãã§ãã ãã©ãŠã¶ã¯éšåçãªæ€èšŒãšã©ãŒã«ééãã倱å¹ãã蚌ææžãåŒãç¶ã䜿çšããŸãã 誰ãããªããæ»æããŠããªãå Žåããã®ç¹å®ã®èšŒææžã確èªãããã³ã«ã蚌ææžãåãæ¶ãããŠããªãããšã確èªããããã«æéãšãªãœãŒã¹ãè²»ãããŸãã ãããŠäžåºŠãããªããæ»æããããšã-ããªããæ¬åœã«ãã®ãããªãã§ãã¯ãæ¬åœã«å¿ èŠãªã®ã¯-ã ãã§ã-æ»æè ã¯åã«æ¥ç¶ããããã¯ãããã©ãŠã¶ã¯éšåçãªå€±æãçµéšããŸãã Googleã®ã¢ãã ã©ã³ã°ã¬ãŒã¯ã蚌ææžã®å€±å¹ãšã¯ã©ã®ãããªãã®ã§ããããæããã説æããŠããŸããããã¯ãäºæ æã«ç Žæããã·ãŒããã«ãã§ããã圌ã¯æ£ããã§ãã æ¯æ¥ããªãã¯è»ã«ä¹ã£ãŠã·ãŒããã«ããç· ããŸã-ãããŠããã¯ããªãã«å®å šã§å¿«é©ã§å¿«é©ãªæèŠãäžããŸãã ãããŠãããæ¥äœãããããããªããŸã-ããªãã¯äºæ ã«éããããã§ããã³ãã¬ã©ã¹ã«é£ã³åºããŸãã æ¬åœã«å¿ èŠãªãšãã ããã·ãŒããã«ããããªãã倱æãããŸãã
åé¡ãä¿®æ£ãã
ä»ããã®ç¹å®ã®ç¬éã«ãçŸå®ã¯ç§ãã¡ãç¶æ³ãä¿®æ£ã§ããªããšããããšã§ãã ãã ããäœããè¡ãããšãã§ããå°æ¥ã蚌ææžå€±å¹ã¡ã«ããºã ã¯æ¬åœã«ä¿¡é Œã§ãããã®ã«ãªãã§ãããã
ç¬èªã®ã¡ã«ããºã
ãµã€ããå±éºã«ãããããæ»æè ãç§å¯éµãåãåã£ãå Žåããã®ãµã€ããåœé ããŠäœããã®æ害ãåŒãèµ·ããå¯èœæ§ããããŸãã ããã§ã¯äœãè¯ãããšã§ã¯ãããŸãããããã£ãšæªãããšããã£ãã§ãããã CAã䟵害ãããæ»æè ãäžé蚌ææžã®ç§å¯éµãååŸããå Žåã¯ã©ããªããŸããïŒ æ»æè ã¯èªåã®èšŒææžã«çœ²åããããšã§ãæåéãèªåãæããããããµã€ããåœé ã§ãããããããã¯çœå®³ãšãªããŸãã ãããã£ãŠãChromeãšFirefoxã«ã¯ã倱å¹ã®äžé蚌ææžããªã³ã©ã€ã³ã§ãã§ãã¯ãã代ããã«ãåãã¿ã¹ã¯ã®ããã®ç¬èªã®ã¡ã«ããºã ããããŸãã
Chromeã§ã¯ã CRLsetsãšåŒã°ããFirefoxã§ã¯OneCRLãšåŒã°ããŸã ã ãããã®ã¡ã«ããºã ã¯ãå©çšå¯èœãªCRLãçµã¿åãããŠãããã蚌ææžãéžæããããšã«ããã蚌ææžå€±å¹ãªã¹ãããã§ãã¯ããŸãã äžé蚌ææžã®ãããªç¹ã«äŸ¡å€ã®ãã蚌ææžããã§ãã¯ãããŸãããéåžžã®èšŒææžã¯ã©ãã§ããïŒ
OCSPãã¹ãã¹ããŒãã«
OCSP Must-Stapleãšã¯äœãã説æããã«ã¯ããŸãOCSP Staplingãšã¯äœããç°¡åã«ç解ããå¿ èŠããããŸãã ããã§ã¯ããŸã詳ããããŸãããã OCSP Staplingããã°ããå æ¬çãªæ å ±ãå ¥æã§ããŸãããããããã€ã³ãã§ãã OCSP Staplingã§ã¯ã蚌ææžèªäœãšãšãã«OCSPå¿çãçºè¡ããããšã«ããããã©ãŠã¶ãŒãOCSPèŠæ±ãéä¿¡ããå¿ èŠããªããªããŸãã ããã¯ããµãŒããŒãOCSPå¿çã蚌ææžã§ãã¹ããŒãã«ãããããããäžç·ã«çºè¡ããå¿ èŠããããããOCSP StaplingãšåŒã°ããŸãã
äžèŠãããã¯å°ãå¥åŠã«æããŸãããªããªãããµãŒããŒã¯èªèº«ã®èšŒææžãæªæ€èšŒãšããŠãèªèšŒãããŠããããã«èŠããŸããããã¹ãŠãæ£åžžã«æ©èœããŠããããã§ãã OCSPå¿çã¯çæéã®ã¿æå¹ã§ããã蚌ææžãšåãæ¹æ³ã§CAã«ãã£ãŠçœ²åãããŸãã ãããã£ãŠããã©ãŠã¶ã蚌ææžãCAã«ãã£ãŠçœ²åãããŠããããšã確èªã§ããå ŽåãOCSPå¿çãCAã«ãã£ãŠçœ²åãããŠããããšã確èªã§ããŸãã ããã«ããã倧ããªãã©ã€ãã·ãŒã®åé¡ã解æ¶ãããã¯ã©ã€ã¢ã³ãã¯å€éšãªã¯ãšã¹ããå®è¡ããè² æ ãã解æŸãããŸãã æè¯ã®ãªãã·ã§ã³ïŒ ããããæ¬åœã«æé«ã§ã¯ãããŸãããããããªããã OCSP Staplingã¯çŽ æŽãããããšã§ãããç§ãã¡å šå¡ããã®æè¡ããµã€ãã§ãµããŒãããå¿ èŠããããŸãããæ»æè ãããããµããŒããããšæ¬åœã«èããŠããŸããïŒ ããããç§ã¯ããã¯æããŸããããã¡ãã圌ã¯ãããããªãã§ãããã æ¬åœã«å¿ èŠãªã®ã¯ããµãŒããŒãOCSPã¹ããŒãã«ããµããŒãããããã«ããããšã§ããããããOCSP Must-Stapleã®ç®çã§ãã CAã«èšŒææžãèŠæ±ãããšããOCSP Must-Stapleãã©ã°ãèšå®ããããã«åœŒã«äŸé ŒããŸãã ãã®ãã©ã°ã¯ã蚌ææžã OCSPå¿çãšãšãã«é ä¿¡ãããããæåŠãããããšããã©ãŠã¶ã«éç¥ããŸãã ãã©ã°ã®èšå®ã¯ç°¡åã§ãã
ãã®ãã©ã°ãèšå®ããåŸãOCSP Stapleã䜿çšãããŠããããšã確èªããå¿ èŠããããŸãã䜿çšãããŠããªãå Žåããã©ãŠã¶ãŒã¯èšŒææžãæåŠããŸãã 䟵害ãçºçããå Žåãæ»æè ãããŒãåãåã£ãå ŽåãOCSP Stapleã蚌ææžãšäžç·ã«äœ¿çšããå¿ èŠããããOCSP Stapleãæå¹ã«ããªãå ŽåãOCSPå¿çã¯èšŒææžãåãæ¶ããããšãã©ãŠã¶ãåãå ¥ããªãããšãéç¥ããŸãã å€ç°ïŒ
OCSP Expect-Staple
Must-Stapleã¯ã蚌ææžã®å€±å¹ãæ€èšŒããããã®åªãããœãªã¥ãŒã·ã§ã³ã®ããã«èŠããŸãããããã¯å®å šã«çå®ã§ã¯ãããŸããã ç§ã®æèŠã§ã¯ãæ倧ã®åé¡ã®1ã€ã¯ããµã€ãéå¶è ãšããŠãOCSP Stapleã¿ã°ã®ä¿¡é Œæ§ãšã¯ã©ã€ã¢ã³ããããããåãå ¥ããæ¹æ³ãæ£ç¢ºã«ç¥ãããšãã§ããªããšããããšã§ãã OCSP Must-Stapleãæå¹ã«ãªã£ãŠããªãå Žåãããã¯åé¡ã§ã¯ãããŸããããOCSP Must-Stapleãæå¹ã«ããOCSP Stapleãä¿¡é Œã§ãããæ£ãããã©ããäžæãªå Žåãããã¯ãµã€ãã®åé¡ã§ãã OCSP Stapleã©ãã«ã®å質ã«é¢ãããã£ãŒãããã¯ãååŸããã«ã¯ãOCSP Expect-Stapleãšããé¢æ°ãã¢ã¯ãã£ãã«ããŸãã 以åã«ããã«ã€ããŠæžããŸãããã OCSP Expect-Stapleããã°ã§è©³çŽ°ã確èªã§ããŸãããããã§ãç°¡åã«èª¬æããŸãã HSTSããªããŒããªã¹ãã«å ããŠãOCSP Stapleã©ãã«ã«æºè¶³ããŠããå Žåã¯ããã©ãŠã¶ãŒã«ã¬ããŒããéä¿¡ããããã«æ±ããŠããŸãã èªåã§ã¬ããŒããåéãããã report-uri.ioãµãŒãã¹ã䜿çšã§ããŸããã©ã¡ãã®å Žåãããµã€ãã§OCSP Must-Stapleã§åé¡ãçºçããæ£ç¢ºãªã¿ã€ãã³ã°ãç¥ãããšãã§ããŸãã HSTSããªããŒããªã¹ãã䜿çšããããšã¯ç§ãæãã»ã©æçœã§ã¯ãªãããã Expect-StapleãšåŒã°ããæ°ããã»ãã¥ãªãã£ããããŒãå®çŸ©ããããã®ä»æ§ãäœæããŸããã ããã¯ãMust-Stapleãã¢ã¯ãã£ãã«ãªãåã§ãã£ãŠãããã®ããããŒãèšå®ããŠãéåžžã«å¿ èŠãªã¬ããŒããéä¿¡ããæ©èœãæå¹ã«ã§ããããã«ãªã£ããšããèãã§ãã ä»ã®ãã¹ãŠã®ã»ãã¥ãªãã£ããããŒãšåæ§ã«ãããããŒã®èšå®ã¯ç°¡åã§ãã
Expect-Staple: max-age=31536000; report-uri="https://scotthelme.report-uri.io/r/d/staple"; includeSubDomains; preload
åœã®èšŒææž
蚌ææžã®å€±å¹ã«ã€ããŠè©±ããŠããå Žåãæ¹ããã®ãããã¯ãèæ ®ããå¿ èŠããããŸãã 誰ããCAã䟵害ããããšããŠããå ŽåããŸãã¯äœããã®æ¹æ³ã§è³æ Œã®ãªã蚌ææžãååŸããããšããŠããå Žåãã©ã®ããã«è¡åããŸããïŒ ä»ããCAããããã³ã°ããŠãµã€ãã®èšŒææžãååŸããå Žåããã¥ãŒã¹ã§å ±åãããŸã§ãã®ããšã¯ããããŸããã ããªãã®äŒç€Ÿã«ã¯ãå éšæç¶ããè¿åãã蚌ææžãåãåãã€ã³ãµã€ããŒãããããããããŸããã 絶察çãªéææ§ãå¿ èŠã§ããããã«å ¥æã§ããŸãã ããã蚌ææžã®éææ§ã§ãã
蚌ææžã®éææ§
CTã¯ãæ¥å¹Žã®åãã«å¿ é ãšãªãæ°ããèŠä»¶ã§ãã ãã©ãŠã¶ãããããä¿¡é Œã§ããããã«ããã¹ãŠã®èšŒææžãå ¬éãžã£ãŒãã«ã«èšé²ããå¿ èŠããããšèŠå®ãããŠããŸãã CTã®è©³çŽ°ãªèª¬æãèšèŒãããèšäºãèªãããšãã§ããŸãããèå¿ãªç¹ã¯ãCAãçºè¡ãããã¹ãŠã®èšŒææžãCTãã°ã«èšé²ããããšã§ãã
ãããã®éèªã¯å®å šã«å ¬éãããŠããã誰ã§ãèŠãããšãã§ããã®ã§ã誰ããããªãã®ãµã€ãã®èšŒææžãåãåã£ãå Žåãããªãã¯ããã«ã€ããŠç¥ãã§ãããã ããšãã°ã ããã§ã¯ãç§ã®ãã¡ã€ã³ã«çºè¡ããããã¹ãŠã®èšŒææžã確èªããèªåã®èšŒææžãæ€çŽ¢ã§ããŸãã åãç®çã§sslmateã®CertSpotterãµãŒãã¹ããããŸãããŸããç¹å®ã®ãã¡ã€ã³ã®èšŒææžãçºè¡ããããã³ã«ã¡ãŒã«ãéä¿¡ããFacebook蚌ææžéææ§ç£èŠããŒã«ã䜿çšããŠããŸãã CTèŠæ Œã¯çŽ æŽãããã¢ã€ãã¢ã§ããã矩ååããã®ãåŸ ã¡ãããŸãããã泚æç¹ã1ã€ãããŸãã å®éãCTã¯æåã®äžæ©ã«ãããŸããã ãããã®èšŒææžã«ã€ããŠç¥ã£ãŠããã®ã¯è¯ãããšã§ããã倱å¹ã«é¢ããŠèšåãããŠãããã¹ãŠã®åé¡ããŸã æ®ã£ãŠããŸãã ãã ããäžåºŠã«è§£æ±ºã§ããåé¡ã¯1ã€ã ãã§ããäžçã§æé«ã®å€±å¹ã¡ã«ããºã ã§ããã倱å¹ãããå¿ èŠããã蚌ææžãããããªããã°å¹æããããŸããã CTã¯å°ãªããšããã®æ å ±ãæäŸããŠãããŸãã
蚌ææ©é¢ã®æ¿èª
蚌ææžã®çºè¡ãé²ãããšã¯ã蚌ææžãåãæ¶ããããã¯ããã«ç°¡åã§ãããã®ãããCAA æ¿èªãå¿ èŠã§ãã ç¹°ãè¿ãã«ãªããŸããã詳现ã¯åç §ã«ããèšäºã«èšèŒãããŠããŸãããèŠããã«ãæ¬è³ªã¯ãç¹å®ã®èšŒææ©é¢ã«ã®ã¿èšŒææžãçºè¡ããæš©éãäžããããšãã§ãããšããããšã§ãã æ¿èªã¯ãDNSã¬ã³ãŒããäœæããã®ãšåããããç°¡åã§ãã
scotthelme.co.uk. IN CAA 0 issue "letsencrypt.org"
CAæ¿èªã¯ç¹ã«åŒ·åãªã¡ã«ããºã ã§ã¯ãªãã蚌ææžã®èª€ã£ãçºè¡ã®ãã¹ãŠã®ç¶æ³ã§åœ¹ç«ã€ããã§ã¯ãããŸããããå Žåã«ãã£ãŠã¯åœ¹ç«ã€ã®ã§ãCAAã¬ã³ãŒããäœæããŠèšå®ã宣èšããå¿ èŠããããŸãã
ãããã«
誰ããç§å¯éµãåãåã£ãå Žåã蚌ææžãåãæ¶ãããšãã§ããªããšããçŸå®ã®åé¡ããããŸãã ããŒãããªãŒãã¹ã±ãŒã«ã®æ¬¡ã®ã°ããŒãã«ãªè匱æ§ãæããã«ãªãããšãæ³åããŠã¿ãŠãã ããïŒ ã§ããããšã®1ã€ã¯ã蚌ææžã®æå¹æéãççž®ããããšã«ãããæŒæŽ©ã«ããæ害ã®éãå¶éããããšã§ãã 3幎ã§ã¯ãªãã1幎以äžã瀺ããŸãã æå·åã¯ã90æ¥éã®ã¿æå¹ãªèšŒææžã®ã¿ãçºè¡ããŸãïŒ èšŒææžã®æå¹æéãççž®ããããšã«ãããæ»æè ã¯æªçšãããæéãå°ãªããªããŸãã ãŸããã»ãšãã©äœãã§ããŸããã
åé¡ãšå®éã®åé¡ã瀺ãããã«ããµã€ãã§éããæ°ãããµããã¡ã€ã³revoked.scotthelme.co.ukã«ã¢ã¯ã»ã¹ããŠã¿ãŠãã ããã ãããããæ³åã®ãšããã倱å¹ãã蚌ææžã¯ãã®ãµããã¡ã€ã³ã«æ·»ä»ãããŠãããéåžžã¯ãã©ãŠã¶ã«èªã¿èŸŒãŸããŸãã ããã§ãªãå Žåããã©ãŠã¶ã«æéåãã®èŠåã衚瀺ãããå Žåãããã¯ãã©ãŠã¶ãåŒãç¶ãOCSPãªã¯ãšã¹ããéä¿¡ããããªããèªåã®ãµã€ãã«ã¢ã¯ã»ã¹ããããšãCAã«éç¥ããããšãæå³ããŸãã ãã®ãããªãœãããã§ã€ã«ãã§ãã¯ã圹ã«ç«ããªãããšã
ocsp.int-x3.letsencrypt.org
ããã«ã¯ãIPã¢ãã¬ã¹
127.0.0.1
ocsp.int-x3.letsencrypt.org
ã
hosts
è¿œå ããããä»ã®æ¹æ³ã§ãããã¯ããŠãåæ¥ç¶ãè©Šã¿ãŸãã ä»åã¯ã倱å¹ãã蚌ææžã®ãã§ãã¯ãæ©èœããªããããããŒãžã¯æ£åžžã«ããŒãããããã©ãŠã¶ã¯ããŒãžã®ããŒããç¶è¡ããŸãã ãã®ãããªãã§ãã¯ã®æèŠ...
蚌ææžãåãæ¶ãæé ãä¿®æ£ããå¿ èŠããããšãã質åã§èšäºãçµäºããããšæããŸãã ãã ããããã¯å¥ã®èšäºã®ãããã¯ã§ãã