ããµãã¥ãŒã»ããå·¥ç§å€§åŠã è¬çŸ©ã³ãŒã¹6.858ã ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã ãã³ã©ã€ã»ãŒã«ããŽã£ããããžã§ãŒã ãºã»ãã±ã³ãºã 2014幎
ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã»ãã¥ãªãã£ã¯ãå®å šãªã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®éçºãšå®è£ ã«é¢ããã³ãŒã¹ã§ãã è¬çŸ©ã§ã¯ãè åšã¢ãã«ãã»ãã¥ãªãã£ãå±éºã«ãããæ»æãããã³æè¿ã®ç§åŠçç 究ã«åºã¥ããã»ãã¥ãªãã£æè¡ãæ±ããŸãã ãããã¯ã«ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒOSïŒã»ãã¥ãªãã£ãæ©èœãæ å ±ãããŒç®¡çãèšèªã»ãã¥ãªãã£ããããã¯ãŒã¯ãããã³ã«ãããŒããŠã§ã¢ã»ãã¥ãªãã£ãããã³Webã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãå«ãŸããŸãã
è¬çŸ©1ïŒãã¯ããã«ïŒè åšã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©2ïŒãããã«ãŒæ»æã®å¶åŸ¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©3ïŒããããã¡ãªãŒããŒãããŒïŒãšã¯ã¹ããã€ããšä¿è·ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©4ïŒãç¹æš©ã®å ±æã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©5ïŒãã»ãã¥ãªãã£ã·ã¹ãã ã¯ã©ãããæ¥ãã®ãïŒã ããŒã1 / ããŒã2
è¬çŸ©6ïŒãæ©äŒã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©7ïŒããã€ãã£ãã¯ã©ã€ã¢ã³ããµã³ãããã¯ã¹ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©8ïŒããããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©9ïŒãWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©10ïŒãã·ã³ããªãã¯å®è¡ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©11ïŒãUr / Webããã°ã©ãã³ã°èšèªã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©12ïŒãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©13ïŒããããã¯ãŒã¯ãããã³ã«ã ããŒã1 / ããŒã2 / ããŒã3
è¬çŸ©14ïŒãSSLããã³HTTPSã ããŒã1 / ããŒã2 / ããŒã3
次ã«ãã€ã³ã¿ãŒãããäžã®ãããã¯ãŒã¯æ¥ç¶ãä¿è·ããããã«æå·åãããã³ã«ãã©ã®ããã«äœ¿çšãããããããäžè¬çã«ãããã¯ãŒã¯èŠçŽ ãšã©ã®ããã«çžäºäœçšããããèŠãŠãããŸãã 詳现ãæãäžããåã«ãæ°Žææ¥ã«ãã¹ãããããŸããããã®èŽè¡ã§ã¯ãªããéåžžã®è¬çŸ©æéäžã«3éã®ãŠã©ãŒã«ãŒã§ãã¹ããè¡ââãããããšãæãåºããŠãã ããã
ããã§ãä»æ¥ã¯ãã€ã³ã¿ãŒããããæå·åã䜿çšããŠãããã¯ãŒã¯æ¥ç¶ãä¿è·ããæ¹æ³ã«ã€ããŠèª¬æããå¯æ¥ã«é¢é£ãã2ã€ã®ãããã¯ãæ€èšããŸãã
1ã€ç®ã¯ãååã®è¬çŸ©ã§èª¬æããKerberosã·ã¹ãã ãä¿è·ããããã倧èŠæš¡ãªæå·åæ¥ç¶ãä¿è·ããæ¹æ³ã§ãã 2ã€ç®ã¯ããããã¯ãŒã¯ã¬ãã«ã§æäŸããããã®æå·åä¿è·ãã¢ããªã±ãŒã·ã§ã³å šäœã«çµ±åããæ¹æ³ãšãæå·åãããã³ã«ãæäŸããä¿è·ã®äœ¿çšãWebãã©ãŠã¶ãä¿èšŒããæ¹æ³ã§ãã ãããã®ãããã¯ã¯å¯æ¥ã«é¢é£ããŠãããããæå·åã¯åžžã«æ©èœããããããããã¯ãŒã¯éä¿¡ã®ä¿è·ã¯éåžžã«ç°¡åã«æäŸã§ããŸãã ããããããããã©ãŠã¶ã«çµ±åããããšã¯ãæå·åãäžå¿ãšããã·ã¹ãã ãæ§ç¯ããããšãããã¯ããã«é£ããã¿ã¹ã¯ã§ãã
ãã®è°è«ã«å ¥ãåã«ãç§ãã¡ã䜿çšããæå·ã®åºæ¬çãªèŠçŽ ãæãåºããããšæããŸãã
Kerberosã«é¢ããååã®è¬çŸ©ã§ã¯ã察称æå·ã䜿çšããŸããããŸãã¯ã
æå·åãšåŸ©å·åã ãã®æå³ã¯ãç§å¯éµKãš2ã€ã®é¢æ°ãæã£ãŠãããšããããšã§ãã ãããã£ãŠãããŒã¿ã®äžéšãååŸããããšãã§ããŸãããããPãšåŒã³ãŸããããã¯æå·åæ©èœãé©çšã§ãããã¬ãŒã³ããã¹ãã§ãããããã¯ããŒKã®æ©èœã§ãããã®ãã¬ãŒã³ããã¹ããæå·åãããšãæå·åããã¹ãCãåŸãããŸããåãããŒKã䜿çšãã解èªé¢æ°Dãããããã®çµæãæå·åãããããã¹ãCã¯ãã¬ãŒã³ããã¹ãPã«å€ãããŸããããã¯ãKerberosãæ§ç¯ãããããªããã£ãã§ãã
ããããä»æ¥ã®è°è«ã«åœ¹ç«ã€ãé察称æå·åããã³åŸ©å·åãšåŒã°ããä»ã®ããªããã£ããããããšãããããŸãã ããã§ã®èãæ¹ã¯ãæå·åãšåŸ©å·åã«ç°ãªãããŒã䜿çšããããšã§ãã ããããªããããªã«åœ¹ç«ã€ã®ãèŠãŠã¿ãŸãããã
ããã«ã¯é¢æ°Eããããããã¯ç¹å®ã®å ¬ééµpkã§ç¹å®ã®ã¡ãã»ãŒãžPã®ã»ãããæå·åããŠãçµæãšããŠæå·åãããããã¹ãCãåä¿¡ã§ããŸããé¢æ°Dã§æå·åã解é€ããã«ã¯ã察å¿ããç§å¯éµskãæå®ããŠãœãŒã¹ããã¹ãPãååŸããã ãã§ã
é察称æå·åã®äŸ¿å©ãã¯ãã€ã³ã¿ãŒãããäžã§å ¬ééµãå ¬éã§ãã人ã ãããªãã®ããã«ã¡ãã»ãŒãžãæå·åã§ããããšã§ãããã¡ãã»ãŒãžã解èªããã«ã¯ç§å¯éµãå¿ èŠã§ãã ä»æ¥ã¯ãããããããã³ã«ã§ã©ã®ããã«äœ¿çšãããããèŠãŠãããŸãã å®éã«ã¯ãå ¬ééµæå·åããããã«ç°ãªãæ¹æ³ã§äœ¿çšããããšããããããŸãã ããšãã°ãã¡ãã»ãŒãžãæå·åããã³åŸ©å·åãã代ããã«ãã¡ãã»ãŒãžã®çœ²åãŸãã¯æ€èšŒãå¿ èŠã«ãªãå ŽåããããŸãã
å®è£ ã¬ãã«ã§ã¯ãããã¯é¢é£ããæäœã§ãããAPIã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ã¯å°ãç°ãªãããã«èŠããå ŽåããããŸãã ããšãã°ãç§å¯éµskã§ã¡ãã»ãŒãžMã«çœ²åãã眲åSãååŸã§ããŸãã次ã«ã察å¿ããå ¬ééµpkã§ãã®ã¡ãã»ãŒãžãæ€èšŒãããã®çµæã眲åMãã¡ãã»ãŒãžMã«å¯ŸããŠæ£ãããã©ããã瀺ãè«çãã©ã°ãååŸã§ããŸãã
ãããã®æ©èœãæäŸããæ¯èŒççŽæçãªä¿èšŒãããã€ããããŸãã ããšãã°ããã®çœ²åãåãåã£ãŠæ£ããæ€èšŒãããå Žåãæ£ããç§å¯éµãæã€èª°ããçæããå¿ èŠããã£ãããšãæå³ããŸãã ããã¯æããã§ããïŒ
次ã«ãKerberosããã倧èŠæš¡ã«ãããã¯ãŒã¯æ¥ç¶ãä¿è·ããæ¹æ³ãèããŠã¿ãŸãããã Kerberosã§ã¯ãããªãåçŽãªã¢ãã«ãããããã¹ãŠã®ãŠãŒã¶ãŒãšãµãŒããŒãããŠãŒã¶ãŒããµãŒãã¹ãããã³ããŒã®ãã®å·šå€§ãªããŒãã«ãæã€KDCãªããžã§ã¯ããšäœããã®æ¥ç¶ã䜿çšããŠããŸããã ãŠãŒã¶ãŒããµãŒããŒãšéä¿¡ããããšãã¯ãã€ã§ãããã®å·šå€§ãªããŒãã«ã«åºã¥ããŠå¿ èŠãªãã±ãããäœæããããã«KDCã«èŠæ±ããå¿ èŠããããŸãã
ãããã£ãŠãããã¯ããªãåçŽãªã¢ãã«ã®ããã«èŠããŸãã ã§ã¯ããªãä»ã®äœããå¿ èŠãªã®ã§ããããïŒ ãªããµã€ãã§ã®äœæ¥ã«ã¯Kerberosãååã§ã¯ãªãã®ã§ããïŒ ã€ã³ã¿ãŒãããããã¹ãŠã®æ¥ç¶ãä¿è·ããããã«Kerberosãæä»çã«äœ¿çšããªãã®ã¯ãªãã§ããïŒ
ããªãã¯æ£ããçããŸãã-å¯äžã®KDCãå šå¡ãä¿¡é Œããã¹ãã§ãããããã¯æªãããã§ãã ç¹å®ã®ãã·ã³ãå®å šã«å®å šã§ãããšèãããšãåé¡ãçºçããå¯èœæ§ããããŸãã
ããããMITã®äººã ã¯ãKDCã管çããããŒã«ã«ãããã¯ãŒã¯äžã®èª°ããä¿¡é Œããã€ããã¯ãããŸãããã€ã³ã¿ãŒãããäžã®å šå¡ã§ã¯ãããŸããã
2çªç®ã®çåŸã®çããæ£ããã§ãããã®ãããªèšå€§ãªæ°ã®ããŒã管çããããšã¯éåžžã«å°é£ã§ãã å®éãäžçäžã®ãã¹ãŠã®äººã®ããã«10ååãŸãã¯100ååã®ããŒã管çã§ããåäžã®KDCãæ§ç¯ããããšã¯éåžžã«å°é£ã§ãã ã€ã³ã¿ãŒãããå šäœã§Kerberosã䜿çšãããã1ã€ã®åé¡ã¯ããã¹ãŠã®ãŠãŒã¶ãŒãããŒãæã£ãŠããããKDCãç¥ã£ãŠããå¿ èŠãããããšã§ãã KerberosããŒã¿ããŒã¹ã«ã¢ã«ãŠã³ãããªãå Žåãç 究æã§Kerberosã䜿çšããŠäžéšã®ãµãŒããŒã«æ¥ç¶ããããšãã§ããŸããã ã€ã³ã¿ãŒãããå šäœã§ã¯ãã³ã³ãã¥ãŒã¿ãŒã«ã¢ã¯ã»ã¹ãããšãã«èªåã誰ã§ãããããŸã£ããç¥ããªãããšãæåŸ ããã®ã¯éåžžã«åççã§ãããæå·åã«ãã£ãŠä¿è·ãããŠããAmazon Webãµã€ãã«ã¢ã¯ã»ã¹ã§ããŸãã
ãïŒ
æå·åãããã³ã«ã«æåŸ ãããã®ãä»ã«ãããã€ããããŸããããããSSLã§ã©ã®ããã«è¡šç€ºãããããèŠãŠãããŸãã ããããéèŠãªèãæ¹ã¯ããã®ãœãªã¥ãŒã·ã§ã³ã¯KerberosãšSSLãŸãã¯TLSã§åãã§ãããšããããšã§ãã è¬çŸ©è³æã§èªãã å ã®Kerberosãããã³ã«ã¯ããªãåã«éçºããããšèšã£ãã®ã¯æ£ããããšã§ãã ãããŠãããããçŸä»£ã®ã€ã³ã¿ãŒãããã«äœ¿çšãããå Žåã圌ãã¯äœããå€æŽããå¿ èŠããããŸãã ä»ã«ã©ããªèãããããŸããããªãKerberosã䜿çšããªãã®ã§ããïŒ
ããã§ããã¢ã¯ã»ã¹ã埩å ãããšããããã³ããããæ°ãããŠãŒã¶ãŒãç»é²ãããšãã«ã¹ã±ãŒãªã³ã°ã®åé¡ããããŸãããªããªããå人çã«ããã€ãã®ã¢ã«ãŠã³ããªãã£ã¹ã«è¡ã£ãŠããã«ã¢ã«ãŠã³ããååŸããå¿ èŠãããããã§ãã ä»ã«äœïŒ
åŠçïŒ KerberosãµãŒããŒã¯åžžã«ãªã³ã©ã€ã³ã§ããå¿ èŠããããŸãã
ææïŒã¯ããããã¯å¥ã®åé¡ã§ãã äœããã®ç®¡çäžã®åé¡ããªã¹ãããŸãããããããã³ã«ã¬ãã«ã§ã¯ãKDCã¯åžžã«ãªã³ã©ã€ã³ã§ããå¿ èŠããããŸããå®éã«ã¯ããµãŒãã¹ãšã®ããåãã®ä»²ä»åœ¹ãšããŠæ©èœããããã§ãã ã€ãŸããæ°ããWebãµã€ãã«ã¢ã¯ã»ã¹ãããã³ã«ãKDCãšè©±ãå¿ èŠããããŸãã ãŸããããã©ãŒãã³ã¹ã®ç¹ã§ããã«ããã¯ã«ãªããŸãã å¥ã®ã¿ã€ãã®ã¹ã±ãŒã©ããªãã£ãšåæ§ã«ããã®ååã¯ããã©ãŒãã³ã¹ã®ã¹ã±ãŒã©ããªãã£ã«ã€ãªãããŸãããäžèšã®ååã¯ç®¡çã®ã¹ã±ãŒã©ããªãã£ã«ã€ãªãããŸãã
ã§ã¯ããããã®ååã䜿çšããŠãã®åé¡ãã©ã®ããã«è§£æ±ºã§ããŸããïŒ ã¢ã€ãã¢ã¯ãããŒæå·åã䜿çšããŠKDCã®äœ¿çšãåæ¢ããããšã§ãã
çžæåŽã®å ¬ééµã®äžéšãç¥ã£ãŠããã ãã§ãå®å šãªæ¥ç¶ã確ç«ã§ãããã©ããããŸã確èªããŸãããã ãããŠãKDCå ¬éããŒããŒãžã§ã³ããã®ãããã³ã«ã®é¢ä¿è ã®èªèšŒã«æ¥ç¶ããæ¹æ³ã確èªããŸãã KDCã䜿çšããªãå Žåã¯ãå ¬éããŒæå·åã䜿çšããŠæ¬¡ã®æäœãå®è¡ã§ããŸããæ¥ç¶ã®å察åŽã§ããŒãããŒã®å ¬éããŒãäœããã®æ¹æ³ã§ç¢ºèªããŸãã ãããã£ãŠãKerberosã§ã¯ããã¡ã€ã«ãµãŒããŒã«æ¥ç¶ããå Žåãã©ãããã§ããã¡ã€ã«ãµãŒããŒã®å ¬éããŒãç¥ã£ãŠããã ãã§ãã æ°å ¥çãšããŠããã¡ã€ã«ãµãŒããŒã®å ¬éããŒããã®ãããªãã®ã§ãããšããå°å·ç©ãåãåããããã䜿çšããŠæ¥ç¶ã§ããŸãã
æ¥ç¶ãããã¡ã€ã«ãµãŒããŒã®å ¬éããŒã®ã¡ãã»ãŒãžãåçŽã«æå·åã§ããŸãã ããããå®éã«ã¯ããããã®å ¬éããŒã䜿çšãããããã®æäœã¯éåžžã«é ãããšãããããŸããã 察称æå·åããŒãããæ°æ¡é ãã§ãã ãã®ãããå®éã«ã¯ãéåžžããããªãã¯æå·åã®äœ¿çšãåžžã«æŸæ£ããå¿ èŠããããŸãã
ãããã£ãŠãå žåçãªãããã³ã«ã¯æ¬¡ã®ããã«ãªããŸãã AãšBãããŠã圌ãã¯éä¿¡ãæãã§ãããAã¯å ¬ééµBãç¥ã£ãŠããŸããåæã«ãAã¯äœããã®ä¹±æ°ãéžæããŠã»ãã·ã§ã³ããŒSãçæããŸãã ãã®åŸãAã¯Sã»ãã·ã§ã³ããŒBãéä¿¡ããããšããŠãããããKerberosã®ããã«èŠããŸãã Bã®ã»ãã·ã§ã³ããŒSãæå·åããŸãã
Kerberosã§ãããè¡ãã«ã¯ãAãBã®ããŒãç¥ããªãã£ããããŸãã¯Bã ããç¥ãããšãã§ããç§å¯ã§ããããã圌ããããç¥ãããšãèš±å¯ãããªãã£ããããKDCãå¿ èŠã§ãããããã«ããã®Bspkå ¬éããŒã§ç§å¯ãæå·åããã¡ãã»ãŒãžBãéä¿¡ããŸããããã§ãBã¯ãã®ã¡ãã»ãŒãžã解èªãã次ã®ããã«èšãããšãã§ããŸãã ããã§ããã¹ãŠã®ã¡ãã»ãŒãžããã®ç§å¯éµSã§åçŽã«æå·åãããéä¿¡ãã£ãã«ãã§ããŸããã
ãããã£ãŠããã®ãããã³ã«ã«ã¯ããã€ãã®äŸ¿å©ãªæ©èœããããŸãã ãŸããKDCããªã³ã©ã€ã³ã«ããŠã»ãã·ã§ã³ããŒãçæããå¿ èŠæ§ãåãé€ããŸããã æ¥ç¶ã®åœäºè ã®1人ããããçæããKDCã䜿çšããã«çžæåŽã®ããã«æå·åããå Žåãéä¿¡ãããæ å ±ã®æ©å¯æ§ã確ä¿ããããšãã§ããŸãã
ãã1ã€ã®è¯ãç¹ã¯ãBã ãããã®ã¡ãã»ãŒãžã解èªã§ãããããBã ããAããBã«éä¿¡ãããã¡ãã»ãŒãžãèªãããšãã§ãããšããèªä¿¡ã§ãã ãããã£ãŠãBã«ã¯å¯Ÿå¿ããç§å¯ããŒSãå¿ èŠã§ãã
åŠçïŒãŠãŒã¶ãŒãŸãã¯ãµãŒããŒ-ãã®ããŒã誰ãäžãããã¯éèŠã§ããïŒ
ææïŒå€åã ãã®ãããã³ã«ã«å¿ èŠãªããããã£ã«äŸåãããšæããŸãã ãããã£ãŠãAããã¹ãããå ŽåããŸãã¯ééã£ãã©ã³ãã æ§ã䜿çšããå ŽåãããŒã¿ãéä¿¡ãããµãŒããŒã¯ããããããããAã«è¡šç€ºãããå¯äžã®ããŒã¿ã§ãããšèããŸãã ããã¯å®å šã«æ£ãããšã¯éããŸããã®ã§ãèããŠã¿ãŠãã ããã ãã®ãããã³ã«ã«ã¯ä»ã«ãããã€ãã®åé¡ããããŸãã
åŠçïŒæ»æè ã¯ããŒã䜿çšããŠç¹°ãè¿ãã¡ãã»ãŒãžãéä¿¡ã§ããŸããïŒ
ææïŒã¯ããåé¡ã¯ããããã®ã¡ãã»ãŒãžãããäžåºŠéä¿¡ã§ããã ãã§ãAãã¡ãã»ãŒãžBãå床éä¿¡ããããã«èŠããããšãªã©ã§ãã
ãããã£ãŠãéåžžããã®åé¡ã®è§£æ±ºçã¯ãæ¥ç¶ã®äž¡åŽãSã®çæã«é¢äžããããšã§ãããããã«ããã䜿çšããããŒããæ°é®®ãã«ãªããŸãã ããã§ãå³ã§ã¯ãå®éã«ã¯Bã¯äœãçæããªãããããããã®ãããã³ã«ã¡ãã»ãŒãžã¯æ¯ååãã«èŠããããã§ãã
éåžžãäžæ¹ãSãªã©ã®ä¹±æ°ãéžæãã次ã«ä»æ¹ã®Bãéåžžãã³ã¹ãšåŒã°ããä¹±æ°ãéžæããããšããããŸãã 2ã€ã®æ°åãšãå®éã«ã¯çåŽã ãã§éžæãããã®ã§ã¯ãªãããŒããããŸããããã¯ãäž¡åŽãå ±åã®çžäºäœçšã®ããã«éžæããããã·ã¥ã§ãã ããã·ã¥ã«å ããŠãDiffie-Hellmanãããã³ã«ã䜿çšã§ããŸããDiffie-Hellmanãããã³ã«ã¯ãååã®è¬çŸ©ã§æ€èšããŸãããããã®ãããã§ãã©ã€ãã·ãŒãæåã«åŸãããŸãã ããã¯ãããã2ã€ã®åŽé¢ãéžæãã2ã€ã®ä¹±æ°ãåã«ããã·ã¥ãããããè€éãªæ°åŠã§ãã ãã ããå ã®å ±æç§å¯ããŒãªã©ã®åªããããããã£ãååŸããããããæå·åãããããŒã¿ãéä¿¡ãããšãã«åŸ©å·åããŒã転éããå¿ èŠããªããªããŸãã
ãããã£ãŠã次ã®ããã«ç¹°ãè¿ãæ»æãåé¿ã§ããŸãã Bã¯ãã³ã¹ãçæããŠãããå®éã®ç§å¯éµS 'ãèšå®ããŸããããã¯ããã®ãã³ã¹ã§ç§å¯éµSãããã·ã¥ããããã«äœ¿çšãããŸãã ãããŠãã¡ãããBãAã«ãã³ã¹ãè¿éããŠãäž¡è ãããŒã«åæãããšãã«äœãèµ·ãããã調ã¹ãå¿ èŠããããŸãã
ãã1ã€ã®åé¡ã¯ãå®éã®èªèšŒAããªãããšã§ããAã¯Bã誰ã§ããããç¥ã£ãŠããããå°ãªããšã誰ãããŒã¿ã解èªã§ããããç¥ã£ãŠããŸãã ããããBãä»ã®èª°ãã«ãªãããŸããŠããæµã§ããããä»ã®èª°ãã«èŠããããŠããã®ããBã«ã¯çžæã誰ãªã®ãããããŸããã ãããå ¬ééµã®äžçã§ã©ã®ããã«ä¿®æ£ã§ããŸããïŒ
ãããè¡ãã«ã¯ããã€ãã®æ¹æ³ããããŸãã 1ã€ã®å¯èœæ§ã¯ããã®è¯ã眲åã®ååããããããæåã«ãã®ã¡ãã»ãŒãžã«çœ²åããããšã§ãã ãããã£ãŠãããããç§å¯éµã§ããã«çœ²åã§ããŸãã ãã®çœ²åã¯åã«çœ²åãæäŸããŸãããããããããªãã¯ãããå²ãåœãŠããã®ã¡ãã»ãŒãžãæäŸããŸãã
次ã«ãBã¯ã眲åãæ€èšŒããããã«Aãå ¬ééµã§ããããšãç¥ã£ãŠããå¿ èŠããããŸãã ããããBãAãå ¬ééµã§ããããšãç¥ã£ãŠããå ŽåãBã¯Aããã®ã¡ãã»ãŒãžãéä¿¡ãã人ã§ããããšãããªã確信ããŸãã
ãã1ã€ã§ããããšã¯ãæå·åã«å¯Ÿããä¿¡é Œã§ãã ãããã£ãŠãããããBã¯Aã«æäŸãããå ¬ééµã§æå·åããŠãã³ã¹ãAã«éãè¿ãããšãã§ããŸãããããŠãAã®ã¿ããã³ã¹ã解èªããæçµã»ãã·ã§ã³ããŒS 'ãçæã§ããŸãã ã ããããªããã§ããããã€ãã®ããªãã¯ããããŸãã ããããä»æ¥ã®ã€ã³ã¿ãŒããããã©ãŠã¶ã§ã®ã¯ã©ã€ã¢ã³ã蚌ææžã®æ©èœã§ãã
ãããã£ãŠãAã¯ç§å¯éµãæã£ãŠãããããå人ã®MIT蚌ææžãåãåããšããã©ãŠã¶ãŒã¯é·åœã®ç§å¯éµãäœæãããã®èšŒææžãåãåããŸãã WebãµãŒããŒã«èŠæ±ãéä¿¡ãããã³ã«ããŠãŒã¶ãŒèšŒææžã®ç§å¯ããŒãç¥ã£ãŠããããšã蚌æããæ¥ç¶ã®æ®ãã®éšåã«ç§å¯ããŒSãèšå®ããŸãã
ãããã¯ããããã³ã«ã¬ãã«ã§ç°¡åã«ä¿®æ£ã§ããåé¡ã§ãã ãã ããäžèšã®ãã¹ãŠã®æ ¹æ ã¯ããã¹ãŠã®é¢ä¿è ãäºãã®å ¬ééµãç¥ã£ãŠããããšã§ãã 誰ãã®å ¬ééµãèŠã€ããã«ã¯ã©ãããã°ããã§ããïŒ Webãµã€ãã«æ¥ç¶ããããæ¥ç¶ãããURLããŸãã¯ãã¹ãåããããã©ã®å ¬éããŒãããã«äžèŽãããã調ã¹ãã«ã¯ã©ãããã°ããã§ããïŒ
åæ§ã«ãæ瞟ã確èªããããã«MITãµãŒããŒã«æ¥ç¶ããå ŽåããµãŒããŒã¯ä»ã®MITåŠçã®å ¬ééµãšåºå¥ããããã«å ¬ééµãã©ãããã¹ãããã©ã®ããã«ç¥ãã®ã§ããïŒ
ããã¯ãKDCã察åŠããäž»ãªåé¡ã§ãã å®éãKDCã¯2ã€ã®åé¡ã解決ããŸããã ãŸããã¡ãã»ãŒãžïŒEbspkïŒSïŒïŒãçæããã»ãã·ã§ã³ããŒãäœæããŠããµãŒããŒçšã«æå·åããŸããã çŸåšãå ¬ééµæå·ãäœæããããšã§ãããä¿®æ£ããŠããŸãã ãã ããã¡ã€ã³ã®æåååãã以åã«æäŸãããKerberosæå·åããŒã«ãããããå¿ èŠããããŸããã
HTTPSã®äžçã«ã¯ããã®ãããªãã®ã®ããã®TLCãããã³ã«ããããŸãã ãã®æå³ã¯ãããã»ã¹åå è ã®ååãæå·åããŒã«ãããã³ã°ãããããã®å·šå€§ãªããŒãã«ããµããŒãããããã»ã¹ã®ç¹å®ã®åŽé¢ã«äŸåãç¶ããããšã§ãã èšç»ã§ã¯ãèªèšŒå±ãšåŒã°ãããã®ãçšæããŸããããã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ã«é¢ããããããçš®é¡ã®æç®ã§CAãšããæåã§ç€ºãããŠããŸãã ãŸãããã®CAã¯è«ççã«ããŒãã«ããµããŒãããŸããããŒãã«ã®äžéšã«ã¯ãã¹ãŠã®åå è ã®ååã衚瀺ãããããäžæ¹ã«ã¯å¯Ÿå¿ããå ¬éããŒã衚瀺ãããŸãã ãã®ã»ã³ã¿ãŒãšKerberosã®äž»ãªéãã¯ããã®CAããã¹ãŠã®ãã©ã³ã¶ã¯ã·ã§ã³ã§ãªã³ã©ã€ã³ã§ããå¿ èŠããªãããšã§ãã
Kerberosã§ã¯ã誰ããšæ¥ç¶ãããã誰ãã®ããŒãèŠã€ãããããããã«ãKDCãšè©±ãå¿ èŠããããŸãã 代ããã«ãCAã®äžçããããè¡ããŸãã
ããã«äœããã®ååã®ååããããããŒãã«ã®å¥ã®éšåã«å¯Ÿå¿ããããŒããŒãããå ŽåãèªèšŒå±ã¯ãã®ããŒãã«ã«ç¹å®ã®è¡ãååšãããšããã¡ãã»ãŒãžã«åçŽã«çœ²åããŸãã ãããã£ãŠãèªèšŒå±ã¯ç¬èªã®ç§å¯éµãšå ¬ééµãããã§ä¿æããå¿ èŠããããŸãã 圌ã¯ç§å¯éµã䜿çšããŠãä¿¡é Œã§ããã·ã¹ãã äžã®ä»ã®ãŠãŒã¶ãŒãžã®ã¡ãã»ãŒãžãèŠã€ããŸãã
ãããã£ãŠãCAããŒã¿ããŒã¹ã«ãåå+ããŒãã¬ã³ãŒããããå ŽåãCAã¯ããã®ååããã®å ¬ééµãšäžèŽãããšããã¡ãã»ãŒãžãäœæããCAç§å¯éµã§ãã®ã¡ãã»ãŒãžã«çœ²åããŸãã
ããã«ãããKerberosã®æ©èœãšéåžžã«ãã䌌ãããšãå¯èœã«ãªããŸãããåæã«ãã¹ãŠã®ãã©ã³ã¶ã¯ã·ã§ã³ã«ã€ããŠCAããªã³ã©ã€ã³ã§æ€çŽ¢ããå¿ èŠããªããªããŸãã ãããŠãå®éã«ã¯ã¯ããã«ã¹ã±ãŒã©ãã«ã«ãªããŸãã ããã¯ãŸãã«èšŒææžãšåŒã°ãããã®ã§ãã ã¯ã©ã€ã¢ã³ããŸãã¯ãã®ã·ã¹ãã ã䜿çšããä»ã®äººã«ãšã£ãŠããããœãŒã¹ããæäŸããã蚌ææžãä»ã®ãœãŒã¹ããã®èšŒææžããå£ã£ãŠããªããšããäºå®ã«ãããã¹ã±ãŒã©ããªãã£ã確ä¿ãããŸãã 蚌ææ©é¢ã®ç§å¯ããŒã«ãã£ãŠçœ²åãããŸãã ãããã£ãŠãå®éã«èªèšŒå±ãããã«ãªã¹ããããŠããä»ã®é¢ä¿è ã«é£çµ¡ããããšãªãããã®çæ£æ§ãæ€èšŒã§ããŸãã
ãã®ããã«åäœããŸãã éä¿¡ãããµãŒããŒã«ã¯ãæåã«èšŒææ©é¢ããåãåã£ã蚌ææžãæ ŒçŽãããŸãã ãããŠãããªããããã«æ¥ç¶ãããã³ã«ããµãŒããŒã¯ããªãã«èšãïŒãOKãããã«ç§ã®èšŒææžããããŸãã ãã®CAã«ãã£ãŠçœ²åãããŸããã 眲åãæ€èšŒãããããç§ã®å ¬ééµã§ããããããç§ã®ååã§ããããšã確èªããã ãã§ãã
äžæ¹ãã¯ã©ã€ã¢ã³ã蚌ææžã§ãåãããšãèµ·ãããŸãã ãŠãŒã¶ãŒãWebãµãŒããŒã«æ¥ç¶ãããšãã¯ã©ã€ã¢ã³ã蚌ææžã¯ãå ¬éããŒããã©ãŠã¶ãŒã§æåã«çæãããç§å¯ããŒãšäžèŽããããšã瀺ããŸãã , , , MIT, , . , , , , Athena.
: , ?
: , , â , ? - , , , , . - , . . , VeriSign. US Postal Service CA, , . , CA , KDC.
, , Kerberos. , , KDC. , KDC, , . , , . CA , KDS.
: ?
: , . , , KDC, . , . , , . , , , . Kerberos, . Kerberos , . , , . , , . , .
, . , , CA - , . , amazon.com, amazon.com. CA, . , , , .
. , CA , , , , - , . , , . - , amazon.com, , - .
, -, , , , . , . «» , , .
, . -, CRL, ertificate Revocation List. . , - , . , , , : «, , , - . , ».
, , , CRL, , web-, CRL. , - , , . , , , , , .
, . , . , . , . , CRL, - .
, ? , . , CRL .
, , , Kerberos, KDC. CA , . , « SSL », OCSP. CA KDC. , , , , , , - . , OCSP, : «, . , »? , CRL . , , . , , .
26:30
MITã³ãŒã¹ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã®ã»ãã¥ãªãã£ãã 14: «SSL HTTPS», 2
ã³ãŒã¹ã®å®å šçã¯ãã¡ãããå ¥æã§ããŸã ã
ãæ»åšããã ãããããšãããããŸãã ? ããèå³æ·±ãè³æãèŠããã§ããïŒ , 30% entry-level , : VPS (KVM) E5-2650 v4 (6 Cores) 10GB DDR4 240GB SSD 1Gbps $20 ? ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§ 6ãæã®æéãæ¯æãå Žåã¯12æãŸã§ç¡æ㧠ã ããã§æ³šæã§ããŸã ã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšç±³åœã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ§ç¯æ¹æ³ã«ã€ããŠèªã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ