10æäžæ¬ãè©å€ã®è¯ãTLSèªèšŒå±ïŒCAïŒ GlobalSign㯠ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæ§ç¯ãéå§ããŸããã ãšããããGlobalSignã¯ãã«ãŒãTLS蚌ææžã®å€ãã®çžäºçœ²åãåé€ããŸããã
æ®å¿µãªããããã®éçšã§ãSafariãChromeãããã³IE11ãã©ãŠã¶ãŒã¯ãã»ãã¥ãªãã£äžã®çç±ã§å€±å¹ãããšGlobalSign蚌ææžãèªèãå§ããŸããã GlobalSignã®ãšã³ãžãã¢ã¯é倧ãªãšã©ãŒãè¿ éã«æé€ããŸãããã誀ã£ãOCSPå¿çã¯CDNã«ãã£ãã·ã¥ãããäžçäžã«åºãŸã£ãããšãå€æããŸããã çŸåšãããã³ãã©ãŠã¶ãŒã®OCSPãã£ãã·ã¥å ã®ã¬ã³ãŒãã®æå¹æéãåãã4æ¥åã«ãGlobalSignã®èšŒææžã§ä¿è·ãããŠãããµã€ãã¯ããŠãŒã¶ãŒã®å€§éšåãã¢ã¯ã»ã¹ã§ããªãå ŽåããããŸãã
圱é¿ãåãããµã€ãã«ã¯ã Wikipedia ã Dropbox ã Financial Timesãªã©ã®äŒæ¥ããããŸãã
è¡ãŸã¿ãã®æè¡ç詳现
OCSPãšã¯äœã§ããïŒ
SSLããã³TLSã¯ãã€ã³ã¿ãŒãããäžã®HTTPãã©ãã£ãã¯ãæå·åããããã«äœ¿çšãããŸãã ãããã®ãããã³ã«ã¯ããèªèšŒå±ãïŒCAïŒãŸãã¯èªèšŒå±ã®æŠå¿µãå°å ¥ããŠããŸãã åãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšåãã©ãŠã¶ã«ã¯ãä¿¡é Œãã蚌ææ©é¢ã®ãã£ãã·ã¥ãçµã¿èŸŒãŸããŠããŸãã HTTPSãµã€ãã«ã¯ãä¿¡é Œã§ããèªèšŒå±ã«ãã£ãŠçºè¡ããã蚌ææžãå¿ èŠã§ããããã§ãªãå Žåãæ¥ç¶ã¯å€±æãããã©ãŠã¶ãŒã«ãšã©ãŒã衚瀺ãããŸãã
ãã®æŠå¿µã«ã¯æ»ããããç¬éããããŸãã å®éãããšãã°ãµãŒããŒã«è匱æ§ãèŠã€ãã£ãå Žåãæ»æè ã¯æ¢åã®èšŒææžãšæå·åç§å¯éµã«ã¢ã¯ã»ã¹ã§ããŸãã æ»æè ã¯ããŒãçãã åŸãããã䜿çšããŠå ã®ãµã€ããã·ãã¥ã¬ãŒããããã®ãµã€ãã§äžéè ã®ãããªæ»æãçµç¹ããããšãã§ããŸãã ãã®çµæãæ³¥æ£ã¯ãµã€ã蚪åè ã®ãã¹ã¯ãŒãããã©ã¹ããã¯ã«ãŒãããã®ä»ã®æ©å¯æ å ±ã«ã¢ã¯ã»ã¹ããå¯èœæ§ããããŸãã
ãã®åé¡ã¯ãTLS蚌ææžãæ°žä¹ ã«ã§ã¯ãªããååã«é·ãæéïŒéåžžã¯1幎以äžïŒçºè¡ãããå€ãã®èªèšŒæ©é¢ïŒã¡ãªã¿ã«GlobalSignãå«ãïŒãTLS蚌ææžãè³Œå ¥ãã人ã«å²åŒãäžãããšããäºå®ã«ãã£ãŠæªåããŸãé·æã ããã¯ã Let's Encryptã®ç¡æèªèšŒå±ã解決ããããšããŠããåé¡ã®1ã€ã§ãã Let's Encryptãçºè¡ãã蚌ææžã¯3ãæ以å æå¹ã§ãããèªèšŒå±ã¯ãã®æéã30æ¥éã«ççž®ããäºå®ã§ãã
CRLããã³OCSPãšåŒã°ããã¡ã«ããºã ãšåŒã°ããçŸåšã®ç¶æ³ãä¿®æ£ããŸããã ãã©ãŠã¶ã«ããããµã€ããæ瀺ããTLS蚌ææžãæå¹ãã©ããã確èªã§ããŸãã ããæç¹ã§ã蚌ææžã®ææè ã蚌ææžã®ç§å¯ããŒãééã£ãæã«æž¡ã£ããšçã£ãå Žåã蚌ææžãçºè¡ããã»ã³ã¿ãŒã«é£çµ¡ããŠåãæ¶ãããšãã§ããŸãã åãæ¶ããã蚌ææžã¯ãã»ãšãã©ã®ææ°ã®ãã©ãŠã¶ãŒãç¹ã«Safariããã³Chromeãããã³å°æ¥çã«ã¯ãã¹ãŠã®ãã©ãŠã¶ãŒã§åãå ¥ããããŸããã ãããã£ãŠãæ©å¯æ å ±ãééã£ãæã«æž¡ãããšã¯ãããŸããã
10æäžæ¬ã®åºæ¥äº
GlobalSignã¯ãå€ãã®ã«ãŒãä¿¡é ŒèšŒææžã管çããŸãã ãããã®èšŒææžã®å€ãã¯ãLet's Encryptãè¡ãæ¹æ³ãšåæ§ã«ãçžäºã«çœ²åããŸãã
æ°ããã«ãŒã蚌ææžãçºè¡ãããšããªã©ã«ãã¯ãã¹çœ²åãå¿ èŠã§ãã å€ãã®äººããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãæŽæ°ããããšã¯ãã£ãã«ãªããããæ°ããäœæãã蚌ææžãå€ããã©ãŠã¶ã®ãã£ãã·ã¥ã«ããã«è¡šç€ºãããªãå ŽåããããŸãã ã«ãŒã蚌ææžãæå³ããç®çã«äœ¿çšã§ããããã«ãå€ãã«ãŒã蚌ææžã®ããããã§çœ²åãããŸãã
ãã¡ãããã¯ãã¹çœ²åã¯ã«ãŒã蚌ææžã®ã¡ã³ããã³ã¹ãè€éã«ããŸãã ããã«ãäžéšã®GlobalSign蚌ææžã®ãªãªãŒã¹ããååãªæéãçµéããŠãããããæ®ãã®æŽæ°ãããŠããªãã·ã¹ãã ãç¡èŠã§ããŸãã æçµçã«ããããã®ã·ã¹ãã ã¯ãšã«ããéåœã«ãããŸã-ããšãã°ãæªåé«ãInternet Explorer 6ã¯ãããã«äœ¿çšã§ããæå·åãããã³ã«ãè匱ãªSSL 3.0以äžã®ããŒãžã§ã³ã§ãµããŒãããŸãã
ãããèæ ®ããŠã2016幎10æãGlobalSignã¯èšŒææžéã®çžäºçœ²åã®äžéšãåé€ããããããåå¥ã«ç¬ç«ããŠç®¡çããããšã決å®ããŸããã
äœãæªãã£ã
10æ14æ¥ã®æãã¯ãã¹çœ²åãåãæ¶ãããã»ã¹ã«ãšã©ãŒãå ¥ã蟌ã¿ãŸããã ãã®çµæãå€æ°ã®äžéGlobalSign蚌ææžïŒç¹ã«å®äŸ¡ã§æ®åããŠããAlphaSSL ïŒãSafariããã³Chromeãã©ãŠã¶ãŒã«ãã£ãŠåãæ¶ããããšèªèãããããã«ãªããAlphaSSLãªã©ãã蚌ææžãè³Œå ¥ãããã¹ãŠã®ãµã€ããéããªããªããŸããã
GlobalSignã®ãšã³ãžãã¢ã¯ããã«åé¡ãä¿®æ£ããŸãããããã©ãã«ã¯ããã§çµãããŸããã§ãã ã å®éãOCSPãµãŒããŒã¯CAã€ã³ãã©ã¹ãã©ã¯ãã£ã®éåžžã«è² è·ã®é«ãèŠçŽ ã§ããããã¹ãŠã®CAã¯ã©ã€ã¢ã³ãïŒ OCSPã¹ããŒãã«ãæ§æããã¯ã©ã€ã¢ã³ããé€ãïŒã®ãã¹ãŠã®ãŠãŒã¶ãŒã®ãã¹ãŠã®ãã©ãŠã¶ãŒãããã«ã¢ã¯ã»ã¹ããŸã ã ãããã£ãŠãã»ãšãã©ã®èªèšŒå±ã¯CDNã䜿çšããŠOCSPå¿çãé åžããŸãã ç¹ã«ãGlobalSignã¯Cloudflareã®ãµãŒãã¹ã䜿çšããŸãã 詳现ã¯ãŸã ãããŸããããã©ãããCloudflareã¯äœããã®çç±ã§ãã£ãã·ã¥ãããã«ã¯ãªã¢ã§ããã誀ã£ãOCSPã¹ããŒã¿ã¹ãã€ã³ã¿ãŒãããäžã§åºããç¶ããŸããã
çŸæç¹ã§ã¯ãCDNãã£ãã·ã¥ã®åé¡ã解決ãããŠããŸãããå€ãã®ãŠãŒã¶ãŒã«ãšã£ãŠã誀ã£ãOCSPã¹ããŒã¿ã¹ããã©ãŠã¶ãŒã«ãã£ãã·ã¥ãããããã«ãªããŸããã ãã©ãŠã¶ãŒããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®OCSPãã£ãã·ã¥ã«èšé²ããããšã¯ãä»åŸ4æ¥éæå¹ã§ãããç¶æ³ã¯ä¿®æ£ãããŸãã
ã€ã³ã·ãã³ãã®éå§ãã11æéåŸãGlobalSignã¯åé¡ãä¿®æ£ããããã®æšå¥šäºé ãçºè¡ããŸãããããã®éã«ãã§ã«å€ãã®ã¯ã©ã€ã¢ã³ããä»ã®CAã«ç§»è¡ããŠããŸãã
ãã®ç¶æ³ã§æãäžå¿«ãªã®ã¯ãGlobalSignãšã©ãŒãäž»ã«ãã©ãã£ãã¯ã®å€ãã€ã³ã¿ãŒããããµãŒãã¹ã«åœ±é¿ããããšã§ãã å®éãCloudflareã¯äžæ£ç¢ºãªOCSPã¬ã¹ãã³ã¹ãè¿ããŸãããã圱é¿ãåãããµã€ãã¯ãããã®æ°æéã®éã«ãããã蚪åãããŠãŒã¶ãŒã®ã¿ãå©çšã§ããªããªããŸãã ãµã€ãã®äººæ°ãé«ãã»ã©ããã®ãããªãŠãŒã¶ãŒã®ã·ã§ã¢ã¯å€§ãããªããŸãã 亀ééã®å°ãªããµã€ããšå®æçãªèšªåè ã®ããªããµã€ãã¯ããã®äºä»¶ã®åœ±é¿ãã»ãšãã©åããŸããã§ããã
èªåã§HTTPSãµã€ããžã®ã¢ã¯ã»ã¹ã«åé¡ãããããµã€ã蚌ææžãåãæ¶ããããšãã©ãŠã¶ãå ±åããå Žåã¯ãããŒã«ã«CRLããã³OCSPãã£ãã·ã¥ãã¯ãªã¢ããŠã¿ãŠãã ããã é¢é£ããæé ã¯ãGlobalSign Webãµã€ãã§èŠã€ããããšãã§ããŸãã
æãéèŠãªããš
ãã®äºä»¶ã¯ãã®çš®ã®æåã®ãã®ã§ãã ã€ã³ã¿ãŒãããã®æŽå²äžåããŠããã®ã¬ãã«ã®åé¡ãçºçããŸãããCAæ¥çã®ãã¹ãŠã®é¢ä¿è ãããããåã³èµ·ãããªãããã«ããããã«å¯èœãªãã¹ãŠã®ããšãè¡ãããšã¯ééããããŸããã
TLSãšCAã®ã°ããŒãã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯è€éã§èšå€§ã§ãããã©ã®ã·ã¹ãã ããšã©ãŒã§ã¯ãªãããšã©ãŒãžã®å¿çã«ãã£ãŠç¹åŸŽä»ããããŸãã ããã¯ãå®å šãªãããã³ã«ãšæå·ã®æ®åãæ¢ããçç±ãšèŠãªãããã¹ãã§ã¯ãããŸããã ãµã€ãã«HTTPSãHSTSãHPKPãå«ããããšã§ããŠãŒã¶ãŒãä¿è·ããã€ã³ã¿ãŒãããã®å®å šæ§ãé«ããŸãããã€ã³ã¿ãŒãããã®ä¿¡é Œæ§ãé«ããŸãã ãããŠãããã¯ã€ã³ã¿ãŒããããåãã¹ãæ¹åã§ãã
GlobalSignã¯é¡§å®¢ã«å¯ŸããŠéåžžã«æ眪ã§ãããããã®äŒç€Ÿã¯ééããèªèããããããçµè«ãåŒãåºãããšãã§ããããšã§ç¥ãããŠããŸã ã è¿ãå°æ¥ããã¹ãŠã®ç¶æ³ã®è©³çŽ°ãªåæãšãšã©ãŒã«é¢ããæªè§£æ±ºã®äœæ¥ãäŒç€Ÿã«æåŸ ããŸãã