ä»å¹Žã®åãã«ã¯ã蚌ææžã®çºè¡ãæ åœããçµç¹ãç¹å¥ãªDNSã¬ã³ãŒããèæ ®ããå¿ èŠãããããšãå€æããŸããã ãããã®ã¬ã³ãŒãã«ããããã¡ã€ã³ææè ã¯ããã¡ã€ã³ã®SSL / TLS蚌ææžãçºè¡ã§ããããµãŒã¯ã«ãªãããŒãœã³ããå®çŸ©ã§ããŸãã
ããããã¹ãŠã®æ±ºå®ã¯ãããã«ãŒæ»æãšãã£ãã·ã³ã°ãµã€ãã®æ°ã®å¢å ã«ããçšåºŠé¢é£ããŠããŸãã HTTPSãä»ããWebãµã€ããžã®æå·åãããæ¥ç¶ã¯ãã€ã³ã¿ãŒãããäžã§ããã«æ®åããŠããŸãã 蚌ææžã䜿çšãããšããã©ãŠã¶ãšWebãµãŒããŒéã§éä¿¡ãããããŒã¿ãæå·åã§ããã ãã§ãªãããµã€ããå±ããçµç¹ãæ€èšŒããããšãã§ããŸãã æ¬æ¥ã®èšäºã§ã¯ã蚌ææžã®çš®é¡ã確èªãã蚌ææžã®ååŸã®åé¡ã«è§ŠããŸãã
/ Flickr / montillon.a / cc
ãã¹ãŠã®SSL蚌ææžã¯åãããŒã¿ä¿è·æ¹æ³ã䜿çšããŸãã èªèšŒã«ã¯é察称æå·åã¢ã«ãŽãªãºã ïŒå ¬ééµãšç§å¯éµã®ãã¢ïŒã䜿çšãããæ©å¯æ§ã«ã¯å¯Ÿç§°ïŒç§å¯éµïŒã䜿çšãããŸãã ãã ãããããã¯æ€èšŒæ¹æ³ã«ãã£ãŠç°ãªããŸãã蚌ææžã¯ãæ£ããæ¿èªããããµã€ãã«å±ããŠããããšã確èªããããã«ã蚌ææ©é¢ã«ãã£ãŠæ€èšŒãããå¿ èŠããããŸãã 蚌ææžã«ã¯ããã€ãã®çš®é¡ããããŸãã
æåã®ã¿ã€ãã®èšŒææžã¯ããã¡ã€ã³æ€èšŒæžã¿ã§ãã éå¶å©ãµã€ãã«é©ããŠããŸãã移è¡å ã®ãµã€ãã«ãµãŒãã¹ãæäŸããWebãµãŒããŒã®ã¿ã確èªããããã§ãã DV蚌ææžã« 㯠ãçµç¹åãã£ãŒã«ãã«èå¥æ å ±ãå«ãŸããŠããŸãã ã éåžžãå€ã¯ãPersona Not ValidatedããŸãã¯ãUnknownãã§ãã
蚌ææžãèŠæ±ãã人ã確èªããããã«ãèªèšŒã»ã³ã¿ãŒã¯ãã¡ã€ã³åã«é¢é£ä»ããããé»åã¡ãŒã«ã¢ãã¬ã¹ïŒããšãã°ãadmin @ yourdomainname.comïŒã«é»åã¡ãŒã«ãéä¿¡ããŸãã ããã¯ã蚌ææžãèŠæ±ãã人ãå®éã«ãã¡ã€ã³åã®ææè ã§ããããšã確èªããããã§ãã Googleã¯www.google.comãå±ããŠããããšãäžè¬ã«èšŒæããå¿ èŠããªãããããã¡ã€ã³æ€èšŒã§ç°¡åãªèšŒææžã䜿çšã§ããŸãïŒãã ããITã®å·šäººã¯ãŸã OV蚌ææžã䜿çšããŠããŸããããã«ã€ããŠã¯åŸè¿°ããŸãïŒã
ä»ã®æ€èšŒãªãã·ã§ã³ã«ã¯ãDNSã«TXTã¬ã³ãŒããè¿œå ããããCAãèªã¿åãããµãŒããŒã«ç¹å¥ãªãã¡ã€ã«ãé 眮ããããšãå«ãŸããŸãã ãã®ã¿ã€ãã®èšŒææžã¯æãå®äŸ¡ã§äººæ°ããããŸãããç»é²ããããã¡ã€ã³åã«é¢ããæ å ±ã®ã¿ãå«ãŸããŠãããããå®å šã«å®å šãšã¯èŠãªãããŸããã ãã®ãããå éšãããã¯ãŒã¯ãŸãã¯å°èŠæš¡ãªWebãµã€ãã§ã®ä¿è·ã«ãã䜿çšãããŸãã
2çªç®ã®ã¿ã€ãã®èšŒææžã¯ãçµç¹æ€èšŒæžã¿ããŸãã¯çµç¹æ€èšŒæžã¿èšŒææžãšåŒã°ããŸãã ãªã³ã©ã€ã³ãªãœãŒã¹ã®äŒç€Ÿææè ã®ç»é²ããŒã¿ãè¿œå ã§ç¢ºèªãããããDVãããä¿¡é Œæ§ãé«ããªããŸãã äŒç€Ÿã¯èšŒææžãè³Œå ¥ãããšãã«å¿ èŠãªãã¹ãŠã®æ å ±ãæäŸãã次ã«CAã¯çµç¹ã®ä»£è¡šè ã«çŽæ¥é£çµ¡ããŠç¢ºèªããŸãã
3çªç®ã®ã¿ã€ãã¯ã Extended Validation ããŸãã¯é«åºŠãªæ€èšŒã䌎ã蚌ææžã§ãããæãä¿¡é Œæ§ãé«ããšèããããŠããŸãã 2007幎ã«åããŠç»å Žããé«ã¬ãã«ã®æ©å¯æ§ãåããéèååŒãè¡ãWebãµã€ãã§å¿ èŠã«ãªããŸããã ãã®å Žåããã©ãŠã¶ã®ã¢ãã¬ã¹ããŒå šäœãç·è²ã§åŒ·èª¿è¡šç€ºãããŸãïŒããããç·è²ã®ããŒä»ãããšåŒã°ããçç±ã§ãïŒã ããã«ãç·ã®é åã«äŒç€Ÿåã衚瀺ãããŸãã
ããã§ãããŸããŸãªãã©ãŠã¶ã蚌ææžã®å¯çšæ§ã«ã€ããŠãŠãŒã¶ãŒã«éç¥ããæ¹æ³ã«ã€ããŠèªãããšãã§ããŸã ã
æ¯æããè¡ãããã©ã³ã¶ã¯ã·ã§ã³ãåŠçããããã®é«åºŠãªæ€èšŒãåãã蚌ææžã«ãã£ãŠç¢ºèªããããµãŒãããŒãã£ã®ãµã€ãã«ãŠãŒã¶ãŒããªãã€ã¬ã¯ããããå Žåããã®å Žåãéåžžã®OV蚌ææžã§ååã§ãã
EV蚌ææžã¯ããã¡ã€ã³ãç©ççµç¹ã«ãå³å¯ã«ã é¢é£ä»ããå¿ èŠãããå Žåã«åœ¹ç«ã¡ãŸãã ããšãã°ãBank of Americaããã³ãã¡ã€ã³bankofamerica.comã ãã®å Žåãçµç¹æ€èšŒä»ãã®èšŒææžã¯ããªãœãŒã¹ãéè¡ã«å®éã«å±ããŠããããšãä¿èšŒããŸããéè¡ã¯ãŠãŒã¶ãŒãç©ççã«ãéãé ããããšãã§ããŸã-ããã¯å°ãªããšããŠãŒã¶ãŒã«ãšã£ãŠäŸ¿å©ã§ãã
ããã«ãEV蚌ææžã¯ãMountain America Credit Unionã®å Žåãšåæ§ã«ããã£ãã·ã³ã°ãµã€ãã䜿çšããæ»æããä¿è·ããŸãã æ»æè ã¯ãä¿¡çšæ©é¢ã®ãµã€ãã®ã³ããŒã®æ³çSSL蚌ææžãååŸããããšãã§ããŸããã å®éã«ã¯ãéè¡ã¯ãã¡ã€ã³åmacu.comã䜿çšããæ»æè ã¯ååmountain-america.netã䜿çšããç³è«æã«ç¡éªæ°ãªãµã€ããæçš¿ããŸããã 蚌ææžãåãåã£ãåŸããµã€ãã¯ãã£ãã·ã³ã°ãªãœãŒã¹ã«çœ®ãæããããŸããã EV蚌ææžã¯ããã®ãããªããã©ãŒã«ã¹ãã®å®è£ ãæ·±å»ã«è€éã«ããŸã-å°ãªããšãç¯äººã®äœæã¯ããã«å€æããŸãã
OVãEVãªã©ã®èšŒææžãçºè¡ããå ŽåãèªèšŒã»ã³ã¿ãŒã¯ã蚌ææžãåãåãäŒç€Ÿãå®éã«ååšããæ£åŒã«ç»é²ããããªãã£ã¹ãæã¡ãæå®ãããé£çµ¡å ããã¹ãŠæ©èœããŠããããšã確èªããå¿ èŠããããŸãã çµç¹ã®è©äŸ¡ã¯ãå ¬åŒã®å·ç»é²ã確èªããããšããå§ãŸããŸãã ãã·ã¢ã§ã¯ãããã¯é£éŠçšåãµãŒãã¹ã®ãŠã§ããµã€ãã«è¡šç€ºãããæ³äººã®ç»é²ç°¿ã䜿çšããŠè¡ãããŸãã
蚌ææžã®ç³è«ãåãåã£ãåŸãCAã¯çµç¹ã«é¢ãã質åãèšèŒãããã¬ã¿ãŒããããéä¿¡ããŸãã質åã«ã¯èšå ¥ããŠçœ²åããå¿ èŠããããŸãã äŒç€Ÿã®é·ãšäŒèšäž»ä»»ã眲åãšå°ç« ãå ¥ããŸããã ãã®åŸãã¹ãã£ã³ãããããã¥ã¡ã³ãã¯èªèšŒã»ã³ã¿ãŒã«è¿éãããUSRLEããã³TINã®èå¥åã«ãã£ãŠãã§ãã¯ãããŸãã
æäŸãããããŒã¿ãèªèšŒã»ã³ã¿ãŒã®åŸæ¥å¡ãå®å šã«æºãããŠããå Žåã蚌ææžãçºè¡ãããŸãã ææžãåæ³åããå¿ èŠãããå Žåã¯ãèŠæ±ãããææžã®ã¹ãã£ã³ç»åãé»åã¡ãŒã«ã§èªèšŒã»ã³ã¿ãŒã«éä¿¡ããå¿ èŠããããŸãã
ãããã®ææžã®ç¿»èš³ãšç¿»èš³ã®å ¬èšŒãå¿ èŠãã©ããããªãã³ã«å ¬èšŒäººã®èšŒææžãã¢ãã¹ãã£ãŒãŠã«ãã£ãŠå¿ èŠãšããããã©ãããæ確ã«ããããšã¯äºåçãªããšã§ãã å ¬èšŒäººã®æš©éã確èªããããã«ã¢ãã¹ãã£ãŒãŠã®ä»£ããã«ã é£éŠå ¬èšŒäººäŒè°æã®ãŠã§ããµã€ãäžã®é©åãªãªã³ã¯ãèªèšŒã»ã³ã¿ãŒã«éç¥ã§ããŸãã 翻蚳ãå ¬èšŒãµãŒãã¹ãã¢ãã¹ãã£ãŒãŠã«ã¯è¿œå è²»çšãšçµç¹çåªåãå¿ èŠã«ãªãããããããã®ã¢ã¯ã·ã§ã³ã®å¿ èŠæ§ã確èªããåã«ãèªèšŒã»ã³ã¿ãŒã¯ãããã«é¢äžãã¹ãã§ã¯ãããŸããã
CAã¯EV蚌ææžãæ¿åºæ©é¢ã«çºè¡ããããšãã§ããŸãããæ¿åºæ©é¢ã¯å€ãã®èŠä»¶ãæºããå¿ èŠããããŸãã 第1ã«ãçµç¹ã®ååšã¯ãçµç¹ãéå¶ãããŠããè¡æ¿åºåã®ãšã³ãã£ãã£ã«ãã£ãŠç¢ºèªãããªããã°ãªããŸããã 第äºã«ãçµç¹ã¯ã蚌ææžãçºè¡ããCAã®æŽ»åãçŠæ¢ãããŠããåœã«ãã£ãŠã¯ãªããŸããã ãŸããçŠæ¢ãããŠããçµç¹ã®ãªã¹ãã«å·ã®æ§é èªäœãè¡šãã¹ãã§ã¯ãããŸããã
åæã«ãäŒç€Ÿã®å ¬åŒææžããã§ãã¯ããæ³çååšã®èªèšŒè ãšããŠè¡åã§ããåœéæ©é¢ãããããšã«æ³šæããŠãã ããã ãããã®æ©é¢ã®äžã§æãæåãªã®ã¯ãã³ïŒãã©ããã¹ããªãŒãã§ãã çµç¹ã確èªããåŸãDïŒBã¯ããžã¿ã«èå¥å-DUNSïŒDigital Universal Numbering SystemïŒãçºè¡ããŸããããã¯ãçµç¹ã®åæ³æ§ã確èªããããã«åç §ã§ããŸãã
OVãEVãªã©ã®SSL蚌ææžã®çºè¡ã«ã¯ãååŸãåžæããçµç¹ããã®è²»çšãå¿ èŠã«ãªããŸãã ãã ãããã¹ãŠã®åªåã®çµæãã€ã³ã¿ãŒãããäžã®çµç¹ã«å¯Ÿããè©å€ãšé¡§å®¢ã®ä¿¡é Œã¬ãã«ãåäžããŸãã
蚌ææžãã§ãŒã³
äžè¬ã«ãWebãµãŒããŒãšãŠãŒã¶ãŒã®ãã©ãŠã¶ãŒéã§éä¿¡ãããããŒã¿ãæå·åããã«ã¯ãåäžã®èšŒææžã§ååã§ãã ãã ããgoogle.ruãªãœãŒã¹èªèšŒãã¹ãèŠããšã3ã€ããããšãããããŸãã
éè¡ãééã®å笊売ãå Žãªã©ãå€ãã®ãµã€ãã蚪åããå ŽåããŠãŒã¶ãŒã¯æ¥ç¶ãå®å šã§ããããšã ãã§ãªããéããµã€ããæ£ãããµã€ãã§ããããšã確èªããããšèããŠããŸãã ãã®äºå®ã蚌æããã«ã¯ã1ã€ã®èšŒææžã§ã¯äžååã§ãã æ¥ç¶ãä¿è·ããããã«ããã®ãµã€ãå°çšã«çºè¡ããã蚌ææžã䜿çšãããŠããããšããµãŒãããŒãã£ïŒèªèšŒæ©é¢ïŒã確èªããå¿ èŠããããŸãã
誰ããBãããAããæ€èšŒãããBããä¿¡é Œããå Žåãåé¡ã¯è§£æ±ºããŸãã
ãBããããããªãå Žåã¯ããCãã圌ãç¥ã£ãŠãããšå ±åã§ããŸãã
IDãã§ãŒã³ã®é·ãã¯ç¡å¶éã§ãã äž»ãªããšã¯ãããããŠãŒã¶ãŒãä¿¡é Œãããã®ã§ããããšã§ãã ããã«ãæŽå²çããã³æè¡çã«ãå€ãã®èªèšŒã»ã³ã¿ãŒãITåéã§æãé«ãè©äŸ¡ãåããŠããŸãã ãããã£ãŠãæå·èšŒææžãã«ãŒããšåŒã³ãåžžã«ãã®ãããªçœ²åãä¿¡é Œãããšããåæããã決å®ãäžãããŸããã
ã«ãŒã蚌ææ©é¢ãšãã®å ¬éããŒã®ãªã¹ãã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«ä¿åãããŸãã é£ç¶ããŠçœ²åããã蚌ææžã®ãã§ãŒã³ãã«ãŒã蚌ææžãå®äºãããšããã®ãã§ãŒã³ã«å«ãŸãããã¹ãŠã®èšŒææžã確èªæžã¿ãšèŠãªãããŸãã
ä»ã®çš®é¡ã®èšŒææž
çµè«ãšããŠã蚌ææžã®ç€ºãããã°ã©ããŒã·ã§ã³ïŒDVãOVãEVïŒã«å ããŠãä»ã®çš®é¡ã®èšŒææžããããŸãã ããšãã°ã蚌ææžã¯ãçºè¡ããããã¡ã€ã³ã®æ°ãç°ãªãå ŽåããããŸãã åäžãã¡ã€ã³èšŒææžïŒåäžèšŒææžïŒã¯ãè³Œå ¥æã«æå®ãããåäžãã¡ã€ã³ã«é¢é£ä»ããããŠããŸãã ãã«ããã¡ã€ã³èšŒææžïŒãµããžã§ã¯ãã®å¥åããŠããã¡ã€ãã³ãã¥ãã±ãŒã·ã§ã³èšŒææžããã«ããã¡ã€ã³èšŒææžãªã©ïŒã¯ãããå€ãã®ãã¡ã€ã³åãšãµãŒããŒã«å¯ŸããŠæå¹ã§ãããæå®ãããæ°ãè¶ ãããªã¹ãã«å«ãŸããåååã«ã€ããŠã¯ãåå¥ã«æ¯æãå¿ èŠããããŸãã
ç»é²æã«æå®ããããã¡ã€ã³åã®ãã¹ãŠã®ãµããã¡ã€ã³ãã«ããŒãããµããã¡ã€ã³èšŒææžïŒWildCardãªã©ïŒããŸã ãããŸãã 蚌ææžãå¿ èŠã«ãªãå ŽåããããŸããããã«ã¯ããã¡ã€ã³ã«å ããŠããã€ãã®ãµããã¡ã€ã³ãåæã«å«ãŸããŸãã ãã®ãããªå Žåã Comodo PositiveSSL Multi-Domain WildcardãComodo Multi-Domain Wildcard SSLãªã©ã®èšŒææžãååŸãã䟡å€ããããŸãã ãã®å Žåãéåžžã®ãã«ããã¡ã€ã³èšŒææžãè³Œå ¥ããããšãã§ããŸãããã®å Žåãå¿ èŠãªãµããã¡ã€ã³ãæå®ããã ãã§ãã
SSL蚌ææžã¯èªåã§ååŸã§ããŸãããã®ããã®ããŒãã¢ã¯ãç¡æã®OpenSSLãªã©ã®ãžã§ãã¬ãŒã¿ãŒãä»ããŠååŸãããŸã ã ãã®ãããªå®å šãªéä¿¡ãã£ãã«ã¯ã瀟å ã®ããŒãºïŒãããã¯ãŒã¯ããã€ã¹ãŸãã¯ã¢ããªã±ãŒã·ã§ã³éã®äº€æïŒã«ç°¡åã«äœ¿çšã§ããŸãã ãã ããå€éšWebãµã€ãã§äœ¿çšããã«ã¯ãå ¬åŒã®èšŒææžãè³Œå ¥ããå¿ èŠããããŸãã ãã®å Žåããã©ãŠã¶ã¯å®å šã§ãªãæ¥ç¶ã«é¢ããã¡ãã»ãŒãžã衚瀺ããŸãããã転éãããããŒã¿ã«ã€ããŠã¯èœã¡çããŸãã
PSããã°ã®ãããã¯ã«é¢ããããã€ãã®è³æïŒ