/ Flickr / Sven Graeme / CC BY-SA
ããŒãã«
2014幎ã«POODLEæ»æãåããŠç¥ãããããã«ãªããŸããã SSL 3.0ãããã³ã«ã®è匱æ§ã¯ãã»ãã¥ãªãã£å°é家ã®BodoMöllerãšGoogleã®ååã«ãã£ãŠçºèŠãããŸããã
ãã®æ¬è³ªã¯æ¬¡ã®ãšããã§ããããã«ãŒã¯ã¯ã©ã€ã¢ã³ãã«åŒ·å¶çã«SSL 3.0æ¥ç¶ã確ç«ãããåæãããéä¿¡ããšãã¥ã¬ãŒãããŸãã 次ã«ã CBCæå·åãã©ãã£ãã¯ã¢ãŒãã§ç¹å¥ãªã¡ãã»ãŒãžã¿ã°ãæ€çŽ¢ããŸãã æ»æè ã¯ãäžé£ã®åœã®ã¯ãšãªã䜿çšããŠãCookieãªã©ã®é¢å¿ã®ããããŒã¿ã®ã³ã³ãã³ããåæ§ç¯ã§ããŸãã
SSL 3.0ã¯å»æ¢ããããããã³ã«ã§ãã ãããããã®ã»ãã¥ãªãã£ã®åé¡ã¯äŸç¶ãšããŠé¢é£ããŠããŸãã ã¯ã©ã€ã¢ã³ãã¯ããã䜿çšããŠããµãŒããŒã®äºææ§ã®åé¡ãåé¿ããŸãã äžéšã®ã¬ããŒãã«ãããšãæã人æ°ã®ãã10äžã®ãµã€ãã®ã»ãŒ7ïŒ ããŸã SSL 3.0ããµããŒãããŠããŸãã POODLEã®å€æŽããããŸã ããã®ç®çã¯ãããçŸä»£çãªTLS 1.0ããã³TLS 1.1ã§ãã ä»å¹Žã TLS 1.2ä¿è·ããã€ãã¹ããæ°ãããŸã³ãPOODLEããã³GOLDENDOODLEæ»æãç»å ŽããŸããïŒãããã¯ãŸã CBCæå·åã«é¢é£ä»ããããŠããŸãïŒã
èªåãå®ãæ¹æ³ã å ã®POODLEã®å ŽåãSSL 3.0ãµããŒããç¡å¹ã«ããå¿ èŠããããŸãã ãã ãããã®å Žåãäºææ§ã®åé¡ã®ãªã¹ã¯ããããŸãã 代æ¿ãœãªã¥ãŒã·ã§ã³ã¯TLS_FALLBACK_SCSVã¡ã«ããºã ã§ããããã«ãããSSL 3.0ãä»ããããŒã¿äº€æãå€ãã·ã¹ãã ã§ã®ã¿å®è¡ãããããšãä¿èšŒãããŸãã æ»æè ã¯ããããã³ã«ã®ããŠã³ã°ã¬ãŒããéå§ã§ããªããªããŸãã Zombie POODLEããã³GOLDENDOODLEããä¿è·ããæ¹æ³ã¯ãTLS 1.2ã«åºã¥ããã¢ããªã±ãŒã·ã§ã³ã§CBCãµããŒããç¡å¹ã«ããããšã§ãã åºæ¬çãªæ±ºå®ã¯TLS 1.3ãžã®ç§»è¡ã§ã-ãããã³ã«ã®æ°ããããŒãžã§ã³ã¯CBCæå·åã䜿çšããŸããã
ããŒã¹ã
2011幎ã«çºèŠããããSSLããã³TLS 1.0ã«å¯Ÿããæåã®æ»æã®1ã€ã POODLEãšåæ§ã«ãBEAST 㯠CBCæå·åæ©èœã䜿çšããŸãã æ»æè ã¯ãTLSãŸãã¯SSLãä»ããŠããŒã¿ãéä¿¡ãããšãã«ã¡ãã»ãŒãžã眮ãæããJavaScriptãšãŒãžã§ã³ããŸãã¯Javaã¢ãã¬ãããã¯ã©ã€ã¢ã³ããã·ã³ã«ãããã€ããŸãã æ»æè ã¯ãåœã®ããã±ããã®å 容ãç¥ã£ãŠããããããããã䜿çšããŠåæåãã¯ãã«ã解èªããèªèšŒçšã®Cookieãªã©ã®ãã®ä»ã®ã¡ãã»ãŒãžããµãŒããŒã«èªã¿åãããšãã§ããŸãã
çŸåšãŸã§ã å€ãã®ãããã¯ãŒã¯ããŒã«ã¯ ãBEASTã®è匱æ§ïŒããŒã«ã«ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãä¿è·ãããããã·ãšã¢ããªã±ãŒã·ã§ã³ïŒã«å¯ŸããŠäŸç¶ãšããŠè匱ã§ãã
èªåãå®ãæ¹æ³ã æ»æè ã¯ãããŒã¿ã埩å·åããããã«å®æçã«ãªã¯ãšã¹ããéä¿¡ããå¿ èŠããããŸãã SSLSessionCacheTimeoutã®æéã5åïŒããã©ã«ãã®æšå¥šå€ïŒãã30ç§ã«ççž®ããããšããå§ãããŸãã ãã®ã¢ãããŒãã¯ãçç£æ§ã«ããã€ãã®æªåœ±é¿ãåãŒããŸãããæ»æè åãã®èšç»ã®å®è£ ãè€éã«ããŸãã ããã«ãããã«BEASTã®è匱æ§ãç¬èªã®ãã®ã«ãªãå¯èœæ§ãããããšãç解ããå¿ èŠããããŸã-2020幎以æ¥ãæ倧ã®ãã©ãŠã¶ãŒã¯TLS 1.0ããã³1.1ã®ãµããŒããåæ¢ããŠããŸãã ãããã«ããããããã®ãããã³ã«ã䜿çšãããã©ãŠã¶ãŠãŒã¶ãŒã¯å šäœã®1.5ïŒ æªæºã§ãã
ownãã
ããã¯ã40ãããRSAããŒã䜿çšããSSLv2ã®å®è£ ã§ãšã©ãŒã䜿çšããã¯ãã¹ãããã³ã«æ»æã§ãã æ»æè ã¯ãã¿ãŒã²ããã®äœçŸãã®TLSæ¥ç¶ããªãã¹ã³ããåãç§å¯ããŒã䜿çšããŠSSLv2ã§ãµãŒããŒã«ç¹å¥ãªãã±ãããéä¿¡ããŸãã ããã«ãŒã¯Bleichenbacheræ»æã䜿çšããŠãçŽ1,000ã®TLSã¯ã©ã€ã¢ã³ãã»ãã·ã§ã³ã®1ã€ã解èªã§ããŸãã
DROWNã¯2016幎ã«åããŠç¥ãããããã«ãªããäžçã®ãµãŒããŒã®3åã® 1ãããã«ãããããŸããã çŸåšãŸã§ãé¢é£æ§ã¯å€±ãããŠããŸããã æã人æ°ã®ãã150,000ã®ãµã€ãã®ãã¡ã2ïŒ ããŸã SSLv2ãšè匱ãªæå·åã¡ã«ããºã ããµããŒãããŠããŸãã
èªåãå®ãæ¹æ³ã SSLv2ãµããŒããç¡å¹ã«ããæå·åã©ã€ãã©ãªã®éçºè ãææ¡ããããããã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã ããšãã°ããã®ãããª2ã€ã®ããããOpenSSLã«å°å ¥ãããŸããïŒ2016幎ã«ã¯ãããã¯ã¢ããããŒã 1.0.1sããã³1.0.2gã§ããïŒã ãŸããè匱ãªãããã³ã«ãç¡å¹ã«ããããã®æŽæ°ãšæé ãRed Hat ã Apache ã Debianã§å ¬éãããŸããã
IaaSãããã€ããŒ1cloud.ruã®éçºéšéã®è²¬ä»»è ã§ããSergey Belkinæ°ã¯ã 次ã®ããã«è¿°ã¹ãŠããŸãã -ãã®ç¶æ³ã¯ãè€æ°ã®ãµãŒããŒãå ±éã®SSL蚌ææžã䜿çšããŠããå Žåã«çºçããŸãã ãã®å Žåããã¹ãŠã®ãã·ã³ã§SSLv2ãµããŒããç¡å¹ã«ããŸããã
DROWNãçºèŠããæ å ±ã»ãã¥ãªãã£ã®å°é家ã«ãã£ãŠéçºãããç¹å¥ãªãŠãŒãã£ãªãã£ã䜿çšããŠãã·ã¹ãã ãæŽæ°ããå¿ èŠããããã©ããã確èªã§ããŸãã ãã®ã¿ã€ãã®æ»æã«å¯Ÿããä¿è·ã«é¢é£ããæšå¥šäºé ã«ã€ããŠã¯ãOpenSSL Webãµã€ãã®æçš¿ãã芧ãã ãã ã
ããŒãããªãŒã
ãœãããŠã§ã¢ã®æ倧ã®è匱æ§ã®1ã€ã¯Heartbleedã§ãã 2014幎ã«OpenSSLã©ã€ãã©ãªã§çºèŠãããŸããã ãšã©ãŒãçºè¡šãããæç¹ã§ãè匱ãªWebãµã€ãã®æ°ã¯50äžãšæšå®ãããŸãããããã¯ããããã¯ãŒã¯äžã®ä¿è·ããããªãœãŒã¹ã®çŽ17ïŒ ã§ãã
ãã®æ»æã¯ãå°ããªããŒãããŒãTLSæ¡åŒµã¢ãžã¥ãŒã«ãéããŠå®è£ ãããŸãã TLSãããã³ã«ã§ã¯ãããŒã¿ãç¶ç¶çã«éä¿¡ããå¿ èŠããããŸãã é·æéã®ããŠã³ã¿ã€ã ã®å Žåãäžæãçºçããæ¥ç¶ãå確ç«ããå¿ èŠããããŸãã ãã®åé¡ã«å¯ŸåŠããããã«ããµãŒããŒãšã¯ã©ã€ã¢ã³ãã¯äººçºçã«ãã£ãã«ãããã€ãºãïŒ RFC 6520ãpã5 ïŒããã©ã³ãã ãªé·ãã®ãã±ãããéä¿¡ããŸãã æãå€ãã®ããã±ãŒãžã§ããããšãå€æããå ŽåãOpenSSLã®è匱ãªããŒãžã§ã³ã¯ãå²ãåœãŠããããããã¡å€ã®ã¡ã¢ãªãèªã¿åããŸãã ãã©ã€ããŒãæå·åããŒãä»ã®æ¥ç¶ã«é¢ããæ å ±ãªã©ãããããããŒã¿ããã®é åã«ååšããå¯èœæ§ããããŸãã
ãã®è匱æ§ã¯ã1.0.1ãã1.0.1fãŸã§ã®ã©ã€ãã©ãªã®ãã¹ãŠã®ããŒãžã§ã³ãããã³å€ãã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒ12.04.4ãŸã§ã®Ubuntuã6.5ããå€ãCentOSãOpenBSD 5.3ãªã©ïŒã«ååšããŠããŸããã å®å šãªãªã¹ãã¯ãHeartbleed Webãµã€ãã«ãããŸãã ãã®è匱æ§ã«å¯Ÿãããããã¯ãçºèŠåŸããã«ãªãªãŒã¹ãããŸããããåé¡ã¯ãããŸã§ãšåæ§ã«é¢é£ããŠããŸãã 2017幎ã«ã¯ã çŽ20äžã®ãµã€ããHeartbleedã®åœ±é¿ãåããŠããŸããã
èªåãå®ãæ¹æ³ã OpenSSLãããŒãžã§ã³1.0.1g以éã«ã¢ããã°ã¬ãŒãããå¿ èŠããããŸã ã DOPENSSL_NO_HEARTBEATSãªãã·ã§ã³ã䜿çšããŠãããŒãããŒãèŠæ±ãæåã§ç¡å¹ã«ããããšãã§ããŸãã ã¢ããã°ã¬ãŒãåŸãæ å ±ã»ãã¥ãªãã£ã®å°é家㯠ãSSL蚌ææžã®åçºè¡ãæšå¥šããŠããŸãã æå·åããŒã®ããŒã¿ããŸã ããã«ãŒã«å±ããŠããå Žåã亀æãå¿ èŠã§ãã
蚌ææžã®ãªãããŸã
管ç察象ããŒãã¯ããã©ãã£ãã¯ãç©æ¥µçã«ååããæ£åœãªSSL蚌ææžã䜿çšããŠããŠãŒã¶ãŒãšãµãŒããŒã®éã«ã€ã³ã¹ããŒã«ãããŸãã ãã®ããŒãã¯æ£åœãªãµãŒããŒã®ãµããããŠãæå¹ãªèšŒææžãæ瀺ããMITMæ»æãè¡ãããšãå¯èœã«ãªããŸãã
MozillaãGoogleãããã³è€æ°ã®å€§åŠã®ããŒã ã«ãã調æ»ã«ãããšããããã¯ãŒã¯äžã®å®å šãªæ¥ç¶ã®çŽ11ïŒ ããçèŽããããŠããŸãã ããã¯ãçãããã«ãŒã蚌ææžããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ããçµæã§ãã
èªåãå®ãæ¹æ³ã ä¿¡é Œã§ããSSLãããã€ããŒã®ãµãŒãã¹ã䜿çšããŸãã Certificate Transparency ïŒCTïŒãµãŒãã¹ã䜿çšããŠã 蚌ææžã®ãå質ãã確èªã§ããŸãã ã¯ã©ãŠããããã€ããŒã¯çèŽã®æ€åºã«ã圹ç«ã¡ãŸããä»æ¥ãäžéšã®å€§äŒæ¥ã¯TLSæ¥ç¶ãç£èŠããããã®å°çšããŒã«ãæäŸããŠããŸãã
ãã1ã€ã®ä¿è·æ¹æ³ã¯ãSSL蚌ææžã®åä¿¡ãèªååããæ°ããACME æšæºã§ãã åæã«ã圌ã¯ãµã€ãææè ããã§ãã¯ããããã®è¿œå ã®ã¡ã«ããºã ãè¿œå ããŸãã 以åã®è³æã§åœŒã«ã€ããŠãã£ãšæžãã ã
/ Flickr / ãŠãŒãªãµã¢ã€ãã / CC BY
HTTPSã®èŠéã
å€ãã®è匱æ§ã«ãããããããITã®å·šäººãšæ å ±ã»ãã¥ãªãã£ã®å°é家ã¯ãããã³ã«ã®å°æ¥ã«èªä¿¡ãæã£ãŠããŸãã HTTPSã®ç©æ¥µçãªå®è£ ã«ã€ããŠã¯ãWWWã®äœæè ã§ããTim Berners-Leeãæ¯æããŠããŸãã 圌ã«ãããšãæéã®çµéãšãšãã«TLSã¯ããå®å šã«ãªããæ¥ç¶ã®ã»ãã¥ãªãã£ãå€§å¹ ã«åäžããŸãã Berners-Leeã¯ã å°æ¥ ãèªèšŒçšã®ã¯ã©ã€ã¢ã³ã蚌ææžãããããšãææ¡ããŸããã ãããã¯ãäŸµå ¥è ããã®ãµãŒããŒä¿è·ã®æ¹åã«åœ¹ç«ã¡ãŸãã
ãŸããæ©æ¢°åŠç¿ã®å©ããåããŠSSL / TLSãã¯ãããžãŒãéçºããäºå®ã§ããã¹ããŒãã¢ã«ãŽãªãºã ãæªæã®ãããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ãæ åœããŸãã HTTPSæ¥ç¶ã§ã¯ã管çè ã¯ãã«ãŠã§ã¢ããã®ãªã¯ãšã¹ãã®æ€åºãå«ããæå·åãããã¡ãã»ãŒãžã®å 容ãèŠã€ããæ¹æ³ããããŸããã ãã§ã«ããã¥ãŒã©ã«ãããã¯ãŒã¯ã¯æœåšçã«å±éºãªãã±ããã90ïŒ ã®ç²ŸåºŠã§ãã£ã«ã¿ãªã³ã°ã§ããŸãã ïŒ ã¹ã©ã€ã23ã®ãã¬ãŒã³ããŒã·ã§ã³ ïŒã
çµè«
HTTPSãžã®æ»æã®å€§éšåã¯ããããã³ã«èªäœã®åé¡ã§ã¯ãªããå€ãæå·åã¡ã«ããºã ããµããŒãããããã®ãã®ã§ãã ITæ¥çã¯ãåäžä»£ã®ãããã³ã«ã段éçã«å»æ¢ããè匱æ§ãçºèŠããããã®æ°ããããŒã«ãæäŸããŠããŸãã å°æ¥ããããã®ããŒã«ã¯ããã€ã³ããªãžã§ã³ãã«ãªããŸãã