ã·ãªãŒãºã®æåã®éšå
ã·ãªãŒãºã®ç¬¬3éš
ã¯ããã«
çšèªé
ãã®ã·ãªãŒãºã§ã¯ã次ã®ç¥èªãšç¥èªã䜿çšãããŸãã
- PKI ïŒ å ¬ééµã€ã³ãã©ã¹ãã©ã¯ã㣠ïŒ-ç§å¯éµãšå ¬ééµã«åºã¥ãæå·åã¿ã¹ã¯ããµããŒãããããã«äžç·ã«äœ¿çšããããå ¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ãäžé£ã®ããŒã«ïŒæè¡ãææã人éãªã©ïŒãåæ£ãµãŒãã¹ããã³ã³ã³ããŒãã³ãã ç¥èªPKIã¯äžè¬çã§ã¯ãªãããã以äžã§ã¯ããã銎æã¿ã®ããè±èªã®ç¥èªPKIã䜿çšãããŸãã
- X.509ã¯ãå ¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ããã³ç¹æš©ç®¡çã€ã³ãã©ã¹ãã©ã¯ãã£ã®ITU-Tæšæºã§ãã
- CA ïŒ èªèšŒå± ïŒ-ããžã¿ã«èšŒææžãçºè¡ãããµãŒãã¹ã 蚌ææžã¯ãå ¬ééµãææè ã«å±ããŠããããšã確èªããé»åææžã§ãã
- CRL ïŒ èšŒææžå€±å¹ãªã¹ã ïŒ-蚌ææžå€±å¹ãªã¹ãã CAã«ãã£ãŠçºè¡ãããå€éšã®çç±ã«ããæå¹æ§ãçµäºãã倱å¹ãã蚌ææžã®ãªã¹ããå«ã眲åä»ãé»åææžã 倱å¹ãã蚌ææžããšã«ãã·ãªã¢ã«çªå·ã倱å¹ã®æ¥ä»ãšæå»ãããã³å€±å¹ã®çç±ïŒãªãã·ã§ã³ïŒã瀺ãããŸãã ã¢ããªã±ãŒã·ã§ã³ã¯ãCRLã䜿çšããŠãæ瀺ããã蚌ææžãæå¹ã§ãããçºè¡è ã«ãã£ãŠåãæ¶ãããŠããªãããšã確èªã§ããŸããã¢ããªã±ãŒã·ã§ã³ã¯ãCRLã䜿çšããŠãæ瀺ããã蚌ææžãæå¹ã§ãããçºè¡è ã«ãã£ãŠåãæ¶ãããŠããªãããšã確èªã§ããŸãã
- SSL ïŒ Secure Sockets Layer ïŒãŸãã¯TLS ïŒ Transport Layer Security ïŒã¯ããªãŒãã³ãããã¯ãŒã¯ãä»ããã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®ããŒã¿è»¢éã®ã»ãã¥ãªãã£ãä¿èšŒããæè¡ã§ãã
- HTTPS ïŒ HTTP / Secure ïŒ-ã»ãã¥ã¢HTTPã¯ãSSLã䜿çšããç¹æ®ãªã±ãŒã¹ã§ãã
- ã€ã³ã¿ãŒãããPKIã¯ããªãŒãã³ããŒã¿éä¿¡ãã£ãã«äžã®X.509æšæºã«åºã¥ããŠããŒã¿éä¿¡ãä¿è·ããããã®åäžã®ïŒçµ±äžãããïŒã¡ã«ããºã ãæäŸããäžé£ã®æšæºãåæãæé ãããã³å®è·µã§ãã
- CPS ïŒ Certificate Practice Statement ïŒã¯ãå ¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ãšããžã¿ã«èšŒææžã管çããããã®æé ã説æããææžã§ãã
äžè¬çãªèšç»ã®åé¡
æè¡çãªãœãªã¥ãŒã·ã§ã³ãå®è£ ããã«ã¯ãæ éãªèšç»ãå¿ èŠã§ãã PKIå®è£ ãäŸå€ã§ã¯ãããŸããã ããã«ãç¹å®ã®ã±ãŒã¹ã§åæèšç»ã®ãšã©ãŒãæ¯èŒçè¿ éãã€ç°¡åã«ä¿®æ£ã§ããå ŽåãPKIã§ã¯ééããªãããã§ã¯ãããŸããã ãã§ã«è¿°ã¹ãããã«ãPKIãµãŒãã¹ã¯ãäœæ¥äžã«æå°éã®ïŒãŸãã¯éèŠã§ã¯ãªãïŒå€æŽãè¡ãã ãã§é·å¹Žæ©èœããããã«èšèšãããŠããŸãã
ããšãã°ãCA蚌ææžã®æå¹æéã¯çŽ10ã20幎ã§ãã ãã®ãããªé·ã寿åœã®çç±ã®1ã€ã¯ããããã®èšŒææžã®åçºè¡ã«ã¯å€å°æéããããæäœã§ãããå€æ°ã®é¡§å®¢ã®å€æŽãå¿ èŠã«ãªãå¯èœæ§ãããããšã§ãã ããã¯ãã¢ã¯ã»ã¹ã§ããªãã¯ã©ã€ã¢ã³ãã§ãå€æŽãå¿ èŠã«ãªããšããäºå®ã«ãã£ãŠæªåããŸãã ãã1ã€ã®ãã€ã³ãã¯ãPKIã¢ãŒããã¯ãã£ã«å€æŽãå ããå Žåãçºè¡ããã蚌ææžã®æå¹æéäžã¯çŸåšã®æ§æãç¶æããå¿ èŠããããšããããšã§ãã ã€ãŸããæ°ããæ§æã¯æ°ãã蚌ææžã«å¯ŸããŠæ©èœããŸããããããšäžŠè¡ããŠãæ¢ã«çºè¡ããã蚌ææžãæ£ããæ©èœããããã«ä»¥åã®æ§æãç¶æããå¿ èŠããããŸãã ããã«ãããPKIãå¥å šãªç¶æ ã«ç¶æããããšãé£ãããªããŸãã
ãããã®ç¹ãèæ ®ãããšãPKIèšç»ã«ã¯æãæ·±å»ãªæ¹æ³ã§ã¢ãããŒãããå¿ èŠããããŸãã ãããŠãPKIãããžã¿ã«ã»ãã¥ãªãã£ãé·æéã«ããã£ãŠç¢ºå®ã«æ©èœãããããšã«æåããã®ã¯åããŠã§ãã
å€æ®µéèšç»ããã»ã¹ã¯ãéžæããã¢ãã«ã®è«çå³ã«åºã¥ããŠããŸãã å段éã§ããã€ã¢ã°ã©ã ã®èŠçŽ ãæ¡åŒµïŒè©³çŽ°ïŒããããã®ããã«æ¥ç¶ãã¿ã¹ã¯ãããã³èŠä»¶ã圢åŒåãããŸãã å¿ èŠã«å¿ããŠãå®å šã«åœ¢åŒåãããã·ã¹ãã ãåŸããããŸã§è©³çŽ°åãç¶ããããŸãã ãã®èšäºã§ã¯ããã®èšç»ã¢ãããŒãã®äŸã瀺ããŸãã
PKIãã£ãŒã
å ã»ã©èšã£ãããã«ããã¹ãŠã¯éžæããã¢ãã«ã®è«çå³ããå§ãŸããŸãã è«çå³ã«ã¯ãã¹ãŠã®PKIã³ã³ããŒãã³ãã衚瀺ããããããç©çããããžã«ã·ããããå¿ èŠããããŸãã 2ã¬ãã«ã®PKIã¢ãã«ãé©çšããå Žåããã®ãããªå³ã¯æ¬¡ã®åœ¢åŒããšããŸãã
ãã®å³ã¯ã次ã®ã³ã³ããŒãã³ããšãã®è«çæ¥ç¶ã瀺ããŠããŸãã
- ã«ãŒãCA âäžäœCAã«ã®ã¿èšŒææžãçºè¡ãããã®èšŒææžãšå€±å¹ãªã¹ãã倱å¹ãµãŒããŒã«å ¬éããŸãã
- äžäœïŒäžéïŒCA-ãšã³ããŠãŒã¶ãŒã«èšŒææžãçºè¡ãããã®èšŒææžãšå€±å¹ãªã¹ãã倱å¹ãµãŒããŒã«å ¬éããŸãã åæã«ã倱å¹ãµãŒããŒããã«ãŒãCA倱å¹ãªã¹ããããŠã³ããŒãããŸãã
- 倱å¹ãµãŒã㌠-CA蚌ææžãšãã®å€±å¹ãªã¹ãã®ãªããžããªã§ãããä»»æã®ã¯ã©ã€ã¢ã³ããããŠã³ããŒãã§ããŸãã
- ã¯ã©ã€ã¢ã³ãæ¥ç¶ -äžäœCAãã蚌ææžãåãåãã倱å¹ãµãŒããŒãã倱å¹ãªã¹ããããŠã³ããŒãããŸãã
ç©çããããžã¯ãããã«ç°ãªãã次ã®åœ¢åŒã«ãªããŸãã
ç©çããããžã¯ãã¯ã©ã€ã¢ã³ããã©ãã§ã蚌ææžãæ€èšŒã§ããããã«ããããã¯ãŒã¯ã®å å€ã®ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã倱å¹ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããšãæ瀺çã«åŒ·èª¿ããŠããŸãã
CAåã®èšç»
CAåã¯ãç¹å®ã®CAã®[
Subject
ãã£ãŒã«ãã«è¡šç€ºãããååã§ãã 蚌ææžãµãŒãã¹ã®ãã¹ãåãšæ··åããªãã§ãã ããã CAã®ãã«ããŒã ã¯ãååèªäœïŒCNå±æ§ãŸãã¯å ±éåïŒãšX.500圢åŒã®ãªãã·ã§ã³ã®ãµãã£ãã¯ã¹ã®2ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŸãã ããã©ã«ãã§ã¯ãADCSã¯æ¬¡ã®åœ¢åŒã§ååãå²ãåœãŠãŸãã
ã¹ã¿ã³ãã¢ãã³CAã®å ŽåïŒ<
ComputerName
>
CA
ãšã³ã¿ãŒãã©ã€ãºCAã®å ŽåïŒ<
DomainShortName
>-<
ComputerName
>
CA,
<
X500DomainSuffix
>
è¯ãã§ããããããšãæªãã§ããïŒ æè¡çã«ã¯ãä»»æã®ååãéžæã§ããŸãããæ©èœçã«ã¯äœã«ã圱é¿ããŸããã CAã®ååã¯äœããã®åœ¢ã§PKIã®ååºã§ãããæ©èœã«çŽæ¥é¢ä¿ããŠããªããååãªã¬ãã«ã®æ å ±ãšå ¬éæ§ãæäŸãã詳现ã«å¯Ÿããæ 床ãåæ ããŠãããšèããããŠããŸãã ãããã£ãŠã蚌ææžã®ãã«ããŒã ãéžæãããšãã¯ãããã€ãã®æšå¥šäºé ã«åŸãå¿ èŠããããŸãã
- ååã¯ãçµç¹ã®ååïŒçç¥ãããŠããå ŽåããããŸãïŒããã³éå±€å ã®ç¹å®ã®CAã®åœ¹å²ïŒå±æ§CNãå ±éåïŒãåæ ããå¿ èŠããããŸãã
- æ¥å°ŸèŸã¯ãOUïŒçµç¹åäœïŒå±æ§ã§ã®ç®¡çãæ åœããéšéãŸãã¯åäœã®ååãåæ ããå¿ èŠããããŸãã
- çµç¹ã®ãã«ããŒã ãè€è£œããŸãïŒå±æ§Oãçµç¹ïŒã
- CAã®æ³çãªå Žæã ãããè¡ãã«ã¯ãå±æ§LïŒå°åïŒããã³CïŒåœïŒã䜿çšããã ãã§ååã§ãã ååãšããŠãããã¯çµç¹ãæ³çã«ç»é²ãããŠããéœåžãšåœã®ååã§ãã å¿ èŠã«å¿ããŠãSïŒå·ïŒå±æ§ã䜿çšããŠå·/å°åãæå®ã§ããŸãã
ã©ããã¢ã®ãªã¬ã«ããContoso Pharmaceuticals Ltd.ãšããäŒç€Ÿã®ã«ãŒãCAã®ååãéžæãã管çãæ å ±æè¡éšéã«ãã£ãŠæäŸãããŠãããšããŸãã ãã®å ŽåãCAã®ååã¯æ¬¡ã®ããã«ãªããŸãã
CN=Contoso Pharm Root Certification Authority, OU=Division Of IT (DoIT), O=Contoso Pharmaceuticals Ltd., L=Riga, C=LV
Countryå±æ§ã¯2æåã®åœã€ã³ããã¯ã¹ã®ã¿ããµããŒãããããšã«æ³šæããŠãã ããã ããšãã°ãLVãGBãRUãUSãªã©ã è¿œå ã®äŸãšããŠãVeriSign / SymantecãDigiCertãªã©ã®åçšãããã€ããŒã®CA蚌ææžãåç §ã§ããŸãã äžäœCAã®å Žåããã®ååã¯äŒŒãŠããŸãããååã®RootãšããèªãSubordinateãŸãã¯Issuingã«çœ®ãæããããç¹ãç°ãªããŸãã ããªã·ãŒCAãæ確ã«å²ãåœãŠãããŠãã3ã¬ãã«ã®éå±€ã®å Žåãã«ãŒããšããèªã¯ããªã·ãŒã«çœ®ãæããããŸãã äžã§è¿°ã¹ãããã«ãä»ã®ã«ãŒã«ãäŒç€Ÿã«é©çšãããå ŽåããããããããCAã®ååã§å®è£ ã§ããŸãããããã¯æ©èœã«åœ±é¿ããŸããã ãã®éã以äžãé¿ããŠãã ããïŒ
- CNå±æ§ã®ååãé·ãããïŒæ倧50æåïŒã CNå±æ§ã51æåããé·ãå Žåãååã®æåŸã«ç Žæ£ãããååã®ãã©ã°ã¡ã³ãã®ããã·ã¥ããããã³ã°ããããšã«ããççž®ãããŸãã ããã¯ãè¡çãããã»ã¹ãšåŒã°ãããããã³ã«[ MS-WCCE ]ã®3.1.1.4.1.1ã§èª¬æãããŠããŸãã ã€ãŸã ååãé·ããããšãåèªãéäžã§éåããŠèŠãç®ãæªããªãããšããããŸãã
- ã©ãã³ã¢ã«ãã¡ãããã®äžéšã§ã¯ãªãæåãã€ãŸã ã¯ãªãªãã¡ãŸãã¯åŒèšŒæ³ã®æåïŒÄãÅŸãÃãáºãªã©ïŒã¯ãããŸããã ADCSã¯ãCNå±æ§ããã³å¶éãããæåã»ããã®ã·ã³ã°ã«ãã€ããšã³ã³ãŒãã£ã³ã°ã®ã¿ããµããŒãããŸãã ãµããŒããããŠããªãæåã¯å¥ã®ãšã³ã³ãŒãã«å€æãããèªã¿åãäžèœã«ãªããŸãã çŠæ¢æåã®å®å šãªãªã¹ãã¯ã[ MS-WCCE ]ãããã³ã«ã®Â§3.1.1.4.1.1.2ã§æäŸãããŠããŸãã ãæé«ã¯åã®æµã§ããããšããååãããã§æ©èœããã®ã§ãååã¯ç°¡æœã§ååãªæ å ±ãæäŸããå¿ èŠããããŸãã
èšç»ã¬ãã¥ãŒãªã¹ãïŒCRLïŒ
è«çå³ã«åŸã£ãŠãåCAã¯ãã®ã¬ãã¥ãŒãªã¹ããå ¬éããŸãã ã¬ãã¥ãŒãªã¹ãã¯ãäž»ã«2ã€ã®ã«ããŽãªã§ç¹åŸŽä»ããããŸãã
- ãªã³ãŒã«ãªã¹ãã®å ¬éããã³é åžã®ãã€ã³ãã
- ãªã³ãŒã«ãªã¹ãã®æ§æãšæå¹æ§ã
ãªã¹ãã®å ¬éããã³é åžãã€ã³ãã®ã¬ãã¥ãŒ
倱å¹ãªã¹ããå ¬éããã«ã¯ã2çš®é¡ã®CRLé åžãã€ã³ãã䜿çšãããŸããå ¬éãã€ã³ãïŒç©çãã¡ã€ã«ãæžã蟌ãŸããå ŽæïŒãšãã¡ã€ã«ã®é åžãã€ã³ãïŒåä¿¡ïŒã§ãã
æåã®ã¿ã€ãã®ãã€ã³ãã¯ããã¡ã€ã«ãæžã蟌ãŸããããŒã«ã«ãŸãã¯ãããã¯ãŒã¯ãã¹ïŒUNC圢åŒïŒã瀺ããŸãã 2çªç®ã®ã¿ã€ãã®ãã€ã³ãã¯ãçºè¡ããã蚌ææžã«ç»é²ããã顧客ãã¬ãã¥ãŒãªã¹ããããŠã³ããŒãã§ããæ¹æ³ã瀺ããŸãã ãããã®ãã¹ã¯ãCRLé åžãã€ã³ãã®èšŒææžæ¡åŒµæ©èœã§å ¬éãããŸãã éåžžããããã®ãã¹ã¯äžèŽããŸããïŒå ¬éãã¹ãšé åžãã¹ãåãLDAPãé€ãïŒã å ¬éãã€ã³ãã決å®ããéã«ã¯ã次ã®èŠåã«åŸã£ãŠãã ããã
- ã«ãŒãCAã®å Žåããã®ãµãŒããŒã¯ãããã¯ãŒã¯ããéé¢ããããããå³å¯ã«ããŒã«ã«ãªãã¹ãæå®ãããŸãã ãã¡ã€ã«ã®é åžãµãŒããŒïŒIISïŒãžã®ã³ããŒã¯æåã§è¡ãããŸãã ã«ãŒãCAã®ã¬ãã¥ãŒãªã¹ãã®å ¬éé »åºŠã¯æåäœã§æž¬å®ããããããããã¯åé¡ã§ã¯ãããŸããïŒè©³çŽ°ã«ã€ããŠã¯ä»¥äžãåç §ããŠãã ããïŒã
- çºè¡CAã®å Žåããããã¯ãŒã¯ãã¹ã瀺ãããŸãã DFSã§å ±æãã©ã«ããŒãäœæããããšããå§ãããŸããããã¯ãIISã§ä»®æ³ãã£ã¬ã¯ããªãšããŠç°¡åã«å®çŸ©ã§ããŸãã ãã®å Žåãç©çãã¡ã€ã«ãé åžãã€ã³ãã«å ¬éããããã»ã¹ã¯å®å šã«èªååãããŸãã
- 倱å¹ãªã¹ãã®å ¬éããã³é åžã«LDAPã䜿çšããªãã§ãã ããã
CRLé åžãã€ã³ããšæ©é¢æ å ±ã¢ã¯ã»ã¹ã®æ¡åŒµãšãã©ã¯ãã£ã¹ã®èšç»ã®è©³çŽ°ã«ã€ããŠã¯ãããã°æçš¿ã CRLé åžãã€ã³ããšæ©é¢æ å ±ã¢ã¯ã»ã¹ã®å Žæã®èšèš ããåç §ããŠãã ããã
ãªã¹ãæ§æã®ã¬ãã¥ãŒ
ãªã³ãŒã«ãªã¹ãã®æ§æãšæå¹æ§ãèšç»ããåã«ããªã³ãŒã«ãªã¹ãã®ç®çãšãã®åäœæ¡ä»¶ã«å¿ããæé©ãªãã©ã¡ãŒã¿ãŒãç解ããå¿ èŠããããŸãã ãåç¥ã®ããã«ãåCAã¯å®æçã«ã¬ãã¥ãŒãªã¹ããçºè¡ããŸããããã«ã¯ãç¹å®ã®CAã«ãã£ãŠå€±å¹ãããã¹ãŠã®èšŒææžã®ãªã¹ããå«ãŸããŸãã ããã«ãåãªã¹ãã«ã¯ãCAã®å šæéã«ããããã¹ãŠã®å€±å¹ãã蚌ææžãå«ãŸããŸãã ããšãã°ãCAã®å¯¿åœã10幎ã®å Žåããã®ãªã¹ãã¯å°è±¡çãªãµã€ãºïŒæ°ã¡ã¬ãã€ãã®ãªãŒããŒïŒã«æé·ããå¯èœæ§ããããŸãã
é«éæ¥ç¶ã§ãã£ãŠãã倱å¹ãªã¹ãã®ãã©ãã£ãã¯ã¯ããªãã®ãµã€ãºã«ãªããŸãã ãã¹ãŠã®èšŒææžã®æ¶è²»è ã«ã¯ææ°ã®æ¹èšãªã¹ããå¿ èŠã§ãã
倱å¹ãªã¹ãã®ãã©ãã£ãã¯ãæžããããã«ã2ã€ã®ã¿ã€ãã®CRLãã€ãŸãåºæ¬ïŒããŒã¹CRLïŒãšå·®åïŒãã«ã¿CRLïŒãå ¬éãããŸãã ããŒã¹ãªã¹ãã«ã¯ãå®å šãªã¬ãã¥ãŒãªã¹ããå«ãŸããŠããŸãã å·®åãªã¹ãã«ã¯ãããŒã¹CRLã®æåŸã®çºè¡ä»¥éã«å€±å¹ãã倱å¹ãã蚌ææžã®ãªã¹ãã®ã¿ãå«ãŸããŸãã ããã«ãããåºæ¬ãªã¹ããããé »ç¹ã«ãããé·æéå ¬éããããšãã§ããééå ã®å€±å¹ãã蚌ææžã«å¯Ÿããã¯ã©ã€ã¢ã³ãã®å¿çæéãççž®ããŠãããã€ãã®çåœãªå·®åCRLãçºè¡ã§ããŸãã
ãã©ã¡ãŒã¿ã®éžæã¯ãããã€ãã®èŠå ã«äŸåããŸãã ããšãã°ãçºè¡ããã蚌ææžã®èšç»ããªã¥ãŒã ãšå€±å¹ã®èšç»ããªã¥ãŒã ã å žåçãªã·ããªãªãæ€èšããŠãã ããã
ã«ãŒãCA
ã«ãŒãCAã¯ãäžéCAã«ã®ã¿èšŒææžãçºè¡ããŸããäžéCAã®æ°ã¯éåžžã1ããŒã¹ä»¥å ã§ãã äžéCAã®æå¹æéã¯ãã«ãŒãCA蚌ææžã®æå¹æéãšåçã§ãã ãŸããäžäœCAã¯èšç·Žãããæ åœè ã«ãã£ãŠç®¡çãããé©åãªã»ãã¥ãªãã£å¯Ÿçãå®æœãããŠãããããäžäœCAããªã³ãŒã«ãããªã¹ã¯ã¯éåžžã«äœããšæ³å®ãããŠããŸãã ãããã£ãŠã倱å¹ãªã¹ãã®ããªã¥ãŒã ã«ã¯å°æ°ã®å€±å¹ãã蚌ææžã®ã¿ãå«ããããšãã§ãããããCRLãã¡ã€ã«ã®ãµã€ãºãå°ããããšãä¿èšŒããããšèšããŸãã
ãã«ãïŒã¬ãã¥ãŒã®ãµã€ãºã«åºã¥ããŠCRLãã¡ã€ã«ã®èšç»ãµã€ãºãèšç®ããæ¹æ³ã¯ïŒ äžè¬çãªç©ºã®CRLã«ã¯çŽ600ã800ãã€ããå¿ èŠã§ãã å蚌ææžå€±å¹ã¬ã³ãŒãã¯88ãã€ãã§ãã ãããã®å€ã«åºã¥ããŠã倱å¹ãã蚌ææžã®æ°ã«å¿ããŠCRLãµã€ãºãèšç®ã§ããŸãã
ãããã£ãŠãã«ãŒãCAãåç¶ããéããªã³ãŒã«ãªã¹ãã¯1kb以å ã«ãªããå·®åCRLã«ã¯æå³ããããŸããã
CAã®å ¬é
çºè¡å CAã®å Žåãç¶æ³ã¯å€åããŠããŸãã çºè¡ããã蚌ææžã®éã¯ãã§ã«å€ããæ°åããã³æ°çŸäžåã«ãªããŸãã æ¶è²»è ãšã¯ãæè³æ Œè ã«ãã£ãŠçµ¶ããç£èŠãããŠããããé©åãªæ段ãæäŸã§ããªãããããªã³ãŒã«ã®ãªã¹ã¯ãé«ããŠãŒã¶ãŒããã³ããã€ã¹ã§ãã ãã®çµæãã¬ãã¥ãŒãªã¹ãã¯æ·±å»ãªãµã€ãºã«éããå¯èœæ§ããããŸãã ããšãã°ã倱å¹ã®ãªã¹ã¯ã10ïŒ ã«ãããšãçºè¡ããã100äžã®èšŒææžã«å¯ŸããŠçŽ10äžã®å€±å¹ããããŸãã 88ãã€ãã®100kã¬ã³ãŒãã¯10mbæªæºã§ãã å€ãã®å Žåã10 mbããšã«ãã¡ã€ã«ãæŽæ°ããããšã¯ããŸãå®çšçã§ã¯ãªããçºè¡é »åºŠãå°ãªãããŠãã¡ã€ã³CRLã®çºè¡ééã§ããã€ãã®è»œéå·®åDelta CRLãé åžããæ¹ã䟿å©ã§ãã ã€ãŸã ã«ãŒãCAã«åºæ¬çãªå€±å¹ãªã¹ãã ãã§ååãªå Žåã¯ããšã³ããŠãŒã¶ãŒã«èšŒææžãçºè¡ããCAã«ãã«ã¿ã䜿çšããå¿ èŠããããŸãã
CRLæå¹æéèšç»
åCAã®ã¬ãã¥ãŒãªã¹ãã®æ§æããã¹ãŠã§ããã ããã§ãã¿ã€ãã³ã°ã決å®ããå¿ èŠããããŸãã
- ã¬ãã¥ãŒãªã¹ãã¯ã©ã®ãããã®æéå ¬éããå¿ èŠããããŸããïŒ
- ãã®äžã®æ å ±ã¯ã©ã®ãããã®æéä¿¡é Œæ§ããããååã«é¢é£æ§ããããšèŠãªãããŸãã
ããã§ã¯ãåäœæ¡ä»¶ã«å¿ããŠã¢ãããŒããé©çšããããšãã§ããŸãã äžéCAãåãæ¶ããªã¹ã¯ã¯éåžžã«äœãããã空ã®CRLãé »ç¹ã«å ¬éããããšã¯æå³ããããŸããã çŸä»£ã®ãã©ã¯ãã£ã¹ã§ã¯ãCAã®CRLæå¹æéã«æ¬¡ã®äžè¬çãªå€ã䜿çšãããŸããããã¯ãä»ã®CAã«ã®ã¿èšŒææžãçºè¡ããŸãïŒ3ã6ããŸãã¯12ãæã ãªã³ãŒã«ãªã¹ããç¶æããããã®ãªã¹ã¯ãšç®¡çã³ã¹ãã®çšåºŠã«åºã¥ããŠããå¿ èŠããããŸãã ç¹å¥ãªæ¡ä»¶ããªãå Žåã¯ãå¹³åçãªçŽ6ãæãéžæããããšããå§ãããŸãã
äžäœCAã®å Žåãã¹ããŒã ã¯åãã§ãã ã¯ã©ã€ã¢ã³ã蚌ææžãåãæ¶ããªã¹ã¯ãé«ããããåãæ¶ãã®é »åºŠãé«ããšæ³å®ã§ããŸãã ãããã£ãŠããã®ãããªCAã¯ã¬ãã¥ãŒãªã¹ããã¯ããã«é »ç¹ã«å ¬éãããã©ãã£ãã¯ãç¯çŽããããã«ãåºæ¬CRLãšå·®åCRLãçµã¿åãããŸãã ããã©ã«ãã§ã¯ãMicrosoft CAã¯æ¬¡ã®é »åºŠã§å€±å¹ãªã¹ããå ¬éããŸããåºæ¬CRLã¯é±ã«1åããã«ã¿ã¯æ¯æ¥ã ãã®ç¶æ³ã§ã¯ã24æé以å ã«ã倱å¹ããææ°ã®èšŒææžãã客æ§ã«éç¥ãããŸãã
ã客æ§ã倱å¹ãã蚌ææžãæå¹ã§ãããšèªèããªãããã«ããã®æéãïŒçæ³çã«ã¯å³åº§ã«ïŒççž®ãã管çè ã®èŠæãç解ã§ããŸãã ãã ãã1ã€ã®ãªã¹ã¯ãæžå°ãããšãå¥ã®ãªã¹ã¯ãå¢å ããŸãã äœããã®çç±ã§ã以åã®CRLã®æå¹æéãè¿ã¥ããæ°ããCRLãå ¬éã§ããªãã£ããšãã«CAãµãŒããŒã倱æãããšæ³åããŠãã ããã ãã®åŸã蚌ææžã®å€±å¹ã確èªããCAãµãŒããŒãæ©èœããããã«åŸ©å ããããŸã§ããããåæ¢ããããšããåé¡ãå§ãŸããŸãã ã¬ãã¥ãŒãªã¹ãã®æå¹æéãèšå®ãããšãã¯ããã®ç¹ãèæ ®ããå¿ èŠããããŸãã
æ¢å®ã§ã¯ãMicrosoft CAã¯ãäºæããªãå Žåããã¬ãã¥ãŒãªã¹ãããã¹ãŠã®å ¬éãã€ã³ãã«é åžããã®ã«æéããããå ŽåïŒããšãã°ãã¬ããªã±ãŒã·ã§ã³ã®é 延ãåå ïŒã«ãããçšåºŠã®æéçäœè£ãæ¢ã«èšããŠããŸãã è±èªã®çšèªã§ã®ãã®äºåã¯ãCRLãªãŒããŒã©ãããšåŒã°ããŸãã é²åŸ¡ã¡ã«ããºã ã®èåŸã«ããèãæ¹ã¯ãCAã以åã«çºè¡ããããªã¹ãã®æå¹æéãåããåã«ã¬ãã¥ãŒãªã¹ããçæããŠçºè¡ããããšã§ãã
ããã¯ãã¬ãã¥ãŒãªã¹ãã®2ã€ã®ãã£ãŒã«ããNext CRL Publishããã³Next Updateã䜿çšããŠå®çŸãããŸãã Next CRL Publishãã£ãŒã«ãã¯ãCAãæŽæ°ããã倱å¹ãªã¹ããïŒèªåçã«ïŒå ¬éããæå»ã瀺ããŸãã 次ã®æŽæ°ã¯ãçŸåšã®ãªã¹ããæéåãã«ãªãæéã瀺ããŸãã Next Updateãã£ãŒã«ãã¯ãåžžã«Next CRL Publishãããå°ãé ããŠèšå®ãããŸãã ã€ãŸããCAã¯ä»¥åã®ãªã¹ããæéåãã«ãªãåã«ãæŽæ°ããã倱å¹ãªã¹ããå ¬éããŸãã ãããã®ãã£ãŒã«ãã®èªåå€ãèšç®ããã¢ã«ãŽãªãºã ã¯èªæã§ã¯ãªãã次ã®èšäºã§èª¬æãããŠããŸãïŒ ThisUpdateãNextUpdateãNextCRLPublishã®èšç®æ¹æ³ïŒv2ïŒ äœããã®çç±ã§ããã©ã«ãå€ãé©åã§ãªãå Žåã¯ãç·šéã§ããŸãã æéããŒãžã³ã«ã¯äžéãšäžéãããããšã«çæããŠãã ããã ããšãã°ãäžéã¯CRLèªäœã®æå¹æéãè¶ ããããšã¯ã§ããŸããã ãããã£ãŠãCRLã®æå¹æéã1æ¥éã®å Žåãåšåº«ã¯æ倧1æ¥éã«ãªããCAã¯æ¯æ¥ã¬ãã¥ãŒãªã¹ããå ¬éããŸãããæå¹æéã¯2æ¥éã«ãªããŸãã ãããã£ãŠãäºæããªãç¶æ³ã®å Žåã«CAã埩å ããããã®æéã®ããŒãžã³ãéæãããŸãã
å®éã«ã¯ã管çè ãCRLã®æå¹æéèšå®ã次ã®çç±ã§æå°é床ã«èª¿æŽããããšããèŠæãããç®ã«ããŸãããããŠãŒã¶ãŒã¯çµäºãã倱å¹ãã蚌ææžã§èªèšŒã§ããªãã¯ãã§ããã åæ©ã¯ç解ã§ããŸãããã¬ãã¥ãŒãªã¹ããéããŠåé¡ã解決ããããšã¯å®å šã«æ£ãããšã¯éããŸããã ãŠãŒã¶ãŒãäŒæ¥ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãåæ¢ããå¿ èŠãããå Žåã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããŸãã¯ã³ã³ãã¥ãŒã¿ãŒãç¡å¹ã«ããå¿ èŠããããŸãã
CRLã®æå¹æéãšé »åºŠãèšç»ãããšãã¯ã次ã®æšå¥šäºé ã«åŸã£ãŠãã ããã
- ãšã³ããŠãŒã¶ãŒã§ã¯ãªããä»ã®CAã®ã¿ã«èšŒææžãçºè¡ãããã¹ãŠã®CAã¯ã3ãæãã12ãæã®éã1ãæã®ããŒãžã³ã§CRLãå ¬éããå¿ èŠããããŸãã
- ãšã³ããŠãŒã¶ãŒïŒãŠãŒã¶ãŒããã³ããã€ã¹ïŒã«èšŒææžãçºè¡ãããã¹ãŠã®CAã¯ãå°ãªããšã1é±éã«1ååºæ¬CRLãçºè¡ããå°ãªããšã3æ¥éïŒã§ããã°æ¯æ¥ïŒå·®åãªã¹ããçºè¡ããå¿ èŠããããŸãã æéããŒãžã³ã¯èª¿æŽããªãã§ãã ããïŒCAã®å éšããžãã¯ã«ãã£ãŠèªåçã«èšç®ããããã®ã䜿çšããŠãã ããïŒã
ãªã³ã©ã€ã³èšŒææžã¹ããŒã¿ã¹ãããã³ã«
ãã®èšäºã·ãªãŒãºã®äžç°ãšããŠã倱å¹ãã蚌ææžã«é¢ããæ å ±ãé åžããè¿œå ã®æ¹æ³ã«OCSPãµãŒããŒã䜿çšããŸããã å¿ èŠã«å¿ããŠãå æ¬çãªTechNetèšäºã ãªã³ã©ã€ã³ã¬ã¹ãã³ããŒã®ã€ã³ã¹ããŒã«ãæ§æãããã³ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã¬ã€ãããåç §ã§ããŸãã å®è·µã瀺ãããã«ãã»ãšãã©ã®å ŽåãOCSPã®ã€ã³ã¹ããŒã«ãšãµããŒãã¯ããã€ãã®çç±ã§æ£åœåãããŠããŸããã
OCSPã®äž»ãªç®æšã¯ãCRLããŠã³ããŒããã©ãã£ãã¯ããªãããŒãããããšã§ãã ãåç¥ã®ããã«ãCRLã«ã¯ãCAã®å šæéã«ããããã¹ãŠã®å€±å¹ãã蚌ææžã®ãªã¹ããå«ãŸããŠããã蚌ææžã®éäžçãªå€±å¹ã«ããããã®ãµã€ãºã¯å°è±¡çãªãµã€ãºïŒæ°ã¡ã¬ãã€ãïŒã«éããå¯èœæ§ããããŸãã äžèšã®ããã«ã倱å¹ãã10äžä»¶ã®èšŒææžã¯CRLãã¡ã€ã«ã§çŽ9MBã«ãªãããšã«æ³šæããŠãã ããã OCSPã䜿çšããŠèšŒææžã®å€±å¹ã確èªããéãåºå®ãµã€ãºã¯çŽ2.5KBã«ãªããŸãã ç®ã«èŠããéãããããŸãã å®éã«ã¯ãå€ãã®å Žåããªã³ãŒã«çã¯ã¯ããã«äœããªããŸãã ã«ãŒãCAãŸãã¯ããªã·ãŒã®CAã«ã€ããŠè©±ãå Žåããããã¯éšåçã«ã¬ãã¥ãŒãããã¬ãã¥ãŒãªã¹ãã®ãµã€ãºã¯1KBãã»ãšãã©è¶ ããŸããã
OCSPã¯ãæ€èšŒæžã¿ã®èšŒææžã1ã€ããããããæ€èšŒãããå€ãã®ã¯ã©ã€ã¢ã³ããããå Žåã«å¹æçã§ããããšã«æ³šæããŠãã ããã ããã¯ãå žåçãªSSL / TLS蚌ææžã®ã·ããªãªã§ãã ãã®å Žåãåã¯ã©ã€ã¢ã³ãã¯æ¡ä»¶ä»ã9MB倱å¹ãªã¹ããããŠã³ããŒããã代ããã«ã2.5KBã®OCSPãã©ãã£ãã¯ãæ¶è²»ããŸãã ãã ããå察ã®ç¶æ³ïŒ1ã€ã®ãµãŒããŒãå€ãã®ã¯ã©ã€ã¢ã³ã蚌ææžãæ€èšŒããïŒã§ã¯ãOCSPããããã¯ãŒã¯ã«å€§ããªè² è·ããããå¯èœæ§ããããŸãã ããã«ã¯ãäžè¬çãªäŒæ¥ãããã¯ãŒã¯ã®ã·ããªãªãå«ãŸããŸãã蚌ææžã䜿çšããã¯ã©ã€ã¢ã³ãèªèšŒïŒã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ããã³VPNã§ã®EAP-TLSèªèšŒããã¡ã€ã³ã³ã³ãããŒã©ãŒã§ã®KerberosèªèšŒãªã©ïŒã åŸæ¥å¡ãè·å Žã«æ¥ãŠããããã¯ãŒã¯ïŒã¹ããŒãã«ãŒããã¢ãã€ã«ããã€ã¹ã®èšŒææžïŒããã³ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®èªèšŒã«èšŒææžã䜿çšãããšãRADIUSãµãŒããŒã¯åã¯ã©ã€ã¢ã³ã蚌ææžã®æ€èšŒã匷å¶ãããŸãã 1Kã®èšŒææžã®ã¿ããã§ãã¯ããã«ã¯ã2.5 MBã®ãã©ãã£ãã¯ãæ¶è²»ãããŸãã ãã®ç¶æ³ã§ã¯ãOCSPã®å©ç¹ã¯ãŸã£ãããããŸãããããŸã£ããéã§ãã
ãã®åŽé¢ã¯ãMicrosoft補åã®ããžãã¯ã§èæ ®ãããŸãã ç¹å®ã®æéãCrypto APIã¯ã©ã€ã¢ã³ããOCSPã䜿çšããŠ1ã€ã®ãããªãã·ã£ãŒãã50ïŒãã®å€ãæ§æå¯èœïŒèšŒææžããã§ãã¯ãããšãOCSPã®åŠçãçµäºããã¯ã©ã€ã¢ã³ãã¯ãã®ãããªãã·ã£ãŒã®CRLãããŠã³ããŒãããŠãã£ãã·ã¥ããŸãã ãã®åäœã®è©³çŽ°ã«ã€ããŠã¯ãWindows Vistaããã³Windows Server 2008ã®èšŒææžå€±å¹ç¢ºèªã® 倱å¹ãšã¯ã¹ããªãšã³ã¹ã®æé©åã»ã¯ã·ã§ã³ãã芧ãã ããã
蚌ææžçºè¡ããªã·ãŒãèšç»ãã
蚌ææžçºè¡ããªã·ãŒã¯ã蚌ææžã®æãç解ãã«ããåŽé¢ã®1ã€ã§ãããäŒæ¥ã§PKIãèšç»ããã³å±éãããšãã«ç®¡çè ã«ãã£ãŠå®å šã«ç¡èŠãããããšããããããŸãã ãã ããçºè¡ããªã·ãŒãç解ãã管çããèœåã«ãããããæè»ãªã·ã¹ãã ãè¿œå ã®å¶åŸ¡ã¬ãã«ããããŠæçµçã«ã¯PKIãèšè¿°ããã³ææžåããæ¹æ³ãšããŠæäŸãããŸãã
ããªã·ãŒå®çŸ©
ãŸãã蚌ææžçºè¡ããªã·ãŒã®å®çŸ©ãå ¥åããå¿ èŠããããŸãã 蚌ææžãçºè¡/ååŸããããã»ã¹ã¯ãåºæ¬çã«ã蚌ææžã®åä¿¡è ãšçºè¡CAãšã®éã®å¥çŽã§ãã ãã®å¥çŽã¯ãçºè¡ã®æé ã䜿çšã責任ç¯å²ãªã©ãå€ãã®åŽé¢ãå®çŸ©ããŠããŸãã
åäŒæ¥ã¯ãã¢ããªã±ãŒã·ã§ã³ã®æ€èšŒãšèšŒææžã®çºè¡ã«ç°ãªãæ¹æ³ã䜿çšããŠããå ŽåããããŸãã ããã€ãã®å žåçãªã±ãŒã¹ãèæ ®ããŠãã ããïŒ
- é»åã¡ãŒã«ã«çœ²åããããã®èšŒææžã¯ãç³è«è ã®æå°éã®æ€èšŒã§èªåçã«çºè¡ã§ããŸãïŒActive Directoryã§ã®ãŠãŒã¶ãŒã®èªèšŒãæåããå Žåã®ã¿ïŒã ãããã®èšŒææžãçºè¡ããããã«ããã以äžã®ã¢ã¯ã·ã§ã³ã¯è¡ãããŸããã
- ææžã®ããžã¿ã«çœ²åã®èšŒææžã¯ãçŽå±ã®äžåžãšã®åæããã³å¿ èŠãªãã¹ãŠã®çœ²åãå«ãæžé¢ã«ããç³è«æžã®æäŸåŸã«ã®ã¿çºè¡ã§ããŸãã
- ã¹ããŒãã«ãŒãã®èšŒææžã¯ãåŸæ¥å¡ã®å人çãªåºåžãããã³ã«ãŒãã®äœ¿çšãé¢é£èŠå¶ææžãžã®çœ²åã«é¢ããèŠåã«é¢ããæ瀺ãããå Žåã«ã®ã¿çºè¡ã§ããŸãã
- , , -.
. , . , â .. , , (, ).
, . . Network Policy Server (NPS) Active Directory Dynamic Access Control . , . , -.
NPS , , , -. , NPS ( ) . , , . Active Directory Dynamic Access Control, .
, . , , . , ? .
, - . , . , . . , ( PKI ) , , , .
: PKI â Certificate Practice Statement CPS ( , , ). ( ) , RFC 3647 . , PKI. . , , - .
CPS :
- PKI, , .
- . PKI, , CPS, , .
CPS ( ). CPS ( ).
ITU-T ISO. : OID' ? , IANA (Internet Assigned Numbers Authority) . , , : 1.3.6.1.4.1.x.1, x â , IANA. :
- 1.3.6.1.4.1.x.1.1
- 1.3.6.1.4.1.x.1.2
- 1.3.6.1.4.1.x.1.3
- 1.3.6.1.4.1.x.1.4
- ...
, . , , . Certificate Policies , .
, DigiCert, 2.16.840.1.114412.2.1 ( Extended Validation ) 2.23.140.1.1 (, CAB/Forum) CPS. CPS .
, , , . . , - , , ( ). : Certificate Policies extension â all you should know (part 1) Certificate Policies extension â all you should know (part 2) . , , Windows.
: (10 ) , . (, ), . RFC 5280 §4.2.1.4 (global wildcard) anyPolicy = 2.5.29.32.0, .
, , . , .. , , , , anyPolicy , . , . anyPolicy .
AD CS ( ). (, ). , (AD CS JET Database Engine). ããã¯çè«äžã§ãã
, . Windows Server 2003 Evaluating CA Capacity, Performance, and Scalability ( , .. TechNet), , . (, ), .
2010 , Windows PKI Team ( 2007 ) Windows Server 2008. : Windows CA Performance Numbers . , , AD CS 2007 150 . . . , . Windows Server 2016 ( Windows Server 2016 System Requirements ):
- CPU â dual-core 1.4 GHz;
- â 1GB RAM;
- â 48 GB 48 GB . RAID1.
- â SVGA (800*600);
- â .
, ( ) ( ) .
( ), . , , . .
.
Standalone CA | |
Root CA | |
15 | |
AD () | Certification Authorities
AIA |
CRT | 1) -
2) C:\CertData\contoso-rca<CertificateName>.crt 3) IIS:\InetPub\PKIdata\contoso-rca<CertificateName>.crt* |
CRT | 1) URL=http://cdp.contoso.com/pki/contoso-rca<CertificateName>.crt |
CRL | 1) -
2) C:\CertData\contoso-rca<CRLNameSuffix>.crt 3) IIS:\InetPub\PKIdata\contoso-rca<CRLNameSuffix>.crt* |
CRL | 1) URL=http://cdp.contoso.com/pki/contoso-rca<CRLNameSuffix>.crt |
Contoso Lab Root Certification authority | |
OU=Division Of IT, O=Contoso Pharmaceuticals, C=US | |
RSA#Microsoft Software Key Storage Provider | |
4096 | |
SHA256 | |
15 | |
CRL | Base CRL |
Base CRL | |
Base CRL | |
6ã¶æ | |
1ã¶æ | |
SHA256 | |
AD |
.
Enterprise CA | |
Subordinate CA | |
: 5 ( ) | |
AD () | AIA
NTAuthCertificates |
CRL | Base CRL
Delta CRL |
CRT | 1) -
2) \\IIS\PKI\contoso-pica<CertificateName>.crt |
CRT | 1) URL=http://cdp.contoso.com/pki/contoso-pica<CertificateName>.crt |
CRL | 1) -
2) \\IIS\PKI\contoso-pica<CRLNameSuffix><DeltaCRLAllowed>.crl |
CRL | 1) URL=http://cdp.contoso.com/pki/contoso-pica<CRLNameSuffix><DeltaCRLAllowed>.crl |
Contoso Lab Issuing Certification authority | |
OU=Division Of IT, O=Contoso Pharmaceuticals, C=US | |
RSA#Microsoft Software Key Storage Provider | |
4096 | |
SHA256 | |
15 ( ) | |
1) : All Issuance Policies
OID=2.5.29.32.0 URL=http://cdp.contoso.com/pki/contoso-cps.html | |
Basic Constraints | isCA=True ( â )
PathLength=0 ( ). |
Base CRL | |
Base CRL | |
1é±é | |
SHA256 | |
AD | |
Delta CRL | |
Delta CRL | |
1 | |
- | |
SHA256 | |
AD |
IIS
- | cdp |
cdp.contoso.com | |
PKI=C:\InetPub\wwwroot\PKIdata | |
Double Escaping |
, . , .
èè ã«ã€ããŠ
â PowerShell Public Key Infrastructure, Microsoft MVP: Cloud and Datacenter Management 2009 PowerShell PKI. 9 PKI . PKI PowerShell .