This document refers to the 2.2 version of Apache httpd, which is no longer maintained. The active release is documented here. If you have not already upgraded, please follow this link for more information.
You may follow this link to go to the current version of this document.
SSL/TLS æå·å: ã¯ããã«ãã®æ¥æ¬èªè¨³ã¯ãã§ã«å¤ããªã£ã¦ãã å¯è½æ§ãããã¾ãã æè¿æ´æ°ãããå 容ãè¦ãã«ã¯è±èªçãã覧ä¸ããã
æ¨æºè¦æ ¼ã®è¯ãæã¯ãããããã®è¦æ ¼ããé¸ã¹ãã¨ãããã¨ã ã ããã¦ãããæ¬å½ã«ã©ã®è¦æ ¼ãæ°ã«å ¥ããªããã°ã ä¸å¹´å¾ ã¤ã ãã§æ¢ãã¦ããè¦æ ¼ãç¾ããã
-- A. Tanenbaum, "Introduction to Computer Networks"
å ¥éã¨ãããã¨ã§ããã®ç« 㯠WebãHTTPãApache ã«éãã¦ãã èªè åãã§ãããã»ãã¥ãªãã£å°éå®¶åãã§ã¯ããã¾ããã SSL ãããã³ã«ã®æ±ºå®çãªæå¼ãã§ããã¤ããã¯ããã¾ããã ã¾ããçµç¹å ã®èªè¨¼ç®¡çã®ããã®ç¹å®ã®ãã¯ããã¯ãã ç¹è¨±ã輸åºè¦å¶ãªã©ã®éè¦ãªæ³çãªåé¡ã«ã¤ãã¦ãæ±ãã¾ããã ããããæ´ãªãç ç©¶ã¸ã®åºçºç¹ã¨ãã¦è²ã ãªæ¦å¿µãå®ç¾©ãä¾ã並ã¹ããã¨ã§ mod_ssl ã®ã¦ã¼ã¶ã«åºç¤ç¥èãæä¾ããäºãç®çã¨ãã¦ãã¾ãã
ããã«ç¤ºãããå
容ã¯ä¸»ã«ãåèè
ã®è¨±å¯ã®ä¸ The Open Group Research Institute ã® Frederick J. Hirsch æ°ã®è¨äº Introducing SSL and Certificates using SSLeay ãåºã«ãã¦ãã¾ãã æ°ã®è¨äºã¯ Web Security: A Matter of Trust, World Wide Web Journal, Volume 2, Issue 3, Summer 1997 ã«æ²è¼ããã¾ããã è¯å®çãªæè¦ã¯ Frederick Hirsch æ° (å
è¨äºã®èè
) ã¸å
¨ã¦ã®è¦æ
㯠Ralf S. Engelschall ( mod_ssl
ã®ä½è
) ã¸ãé¡ããã¾ãã [訳注: 訳ã«ã¤ãã¦ã¯ Apache ããã¥ã¡ã³ã翻訳ããã¸ã§ã¯ã ã¸ãé¡ããã¾ãã]
SSL ãçè§£ããã«ã¯ãæå·ã¢ã«ã´ãªãºã ã ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ã颿°(å¥å: 䏿¹å颿°ãããã·ã¥é¢æ°)ã é»åç½²åãªã©ã¸ã®çè§£ãå¿ è¦ã§ãã ãããã®æè¡ã¯æ¬ã丸ãã¨å¿ è¦ãªé¡ç®ã§ (ä¾ãã° [AC96] ãåç §)ã ãã©ã¤ãã·ã¼ãä¿¡ç¨ãèªè¨¼ãªã©ã®æè¡ã®åºç¤ã¨ãªã£ã¦ãã¾ãã
æå·ã¢ã«ã´ãªãºãä¾ãã°ãã¢ãªã¹ãééã®ããã«éè¡ã«ã¡ãã»ã¼ã¸ãéãããã¨ãã¾ãã å£åº§çªå·ãééã®éé¡ãå«ã¾ããããã ã¢ãªã¹ã¯ãã®ã¡ãã»ã¼ã¸ãç§å¯ã«ãããã¨æãã¾ãã è§£æ±ºæ¹æ³ã®ä¸ã¤ã¯æå·ã¢ã«ã´ãªãºã ã使ã£ã¦ãã¡ãã»ã¼ã¸ã èªã¾ããã人以å¤ã¯èªããã¨ãã§ããªãæå·åããã å½¢æ ã«å¤ãã¦ãã¾ããã¨ã§ãã ãã®å½¢æ ã«ãªãã¨ã ã¡ãã»ã¼ã¸ã¯ç§å¯ã®éµã«ãã£ã¦ã®ã¿è§£éãããã¨ãã§ãã¾ãã éµãªãã§ã¯ãã¡ãã»ã¼ã¸ã¯å½¹ã«ç«ã¡ã¾ããã è¯ãæå·ã¢ã«ã´ãªãºã ã¯ãä¾µå ¥è ãå ã®ããã¹ããè§£èªãããã¨ã é常ã«é£ãããããããåªåãå²ã«åããªãããã¾ãã
æå·ã¢ã«ã´ãªãºã ã«ã¯ 徿¥åã¨å ¬ééµã®äºã¤ã®ç¨®é¡ãããã¾ãã
誰ããæå·åãããã¡ãã»ã¼ã¸ãå ¬ééµã«ãã£ã¦æå·å ãããã¨ãã§ãã¾ãããç§å¯éµã®æã¡ä¸»ã ãããããèªããã¨ã ã§ãã¾ãã ãã®æ¹æ³ã§ãéè¡ã®å ¬ééµã使ã£ã¦æå·åãããã¨ã§ã ã¢ãªã¹ã¯ç§å¯ã®ã¡ãã»ã¼ã¸ãéããã¨ãã§ãã¾ãã éè¡ã®ã¿ã復å·ãããã¨ãã§ãã¾ãã
ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ãã¢ãªã¹ã¯ã¡ãã»ã¼ã¸ãç§å¯ã«ãããã¨ãã§ãã¾ããã 誰ããä¾ãã°èªåã«ééããããã«ã¡ãã»ã¼ã¸ã夿´ãããã å¥ã®ãã®ã«ç½®ãæãã¦ãã¾ããããããªãã¨ããåé¡ãããã¾ãã ã¢ãªã¹ã®ã¡ãã»ã¼ã¸ã®ä¿¡ç¨ãä¿è¨¼ããæ¹æ³ã®ä¸ã¤ã¯ã ã¡ãã»ã¼ã¸ã®ç°¡æ½ãªãã¤ã¸ã§ã¹ããä½ã£ã¦ããããéè¡ã«éãã¨ãããã®ã§ãã ã¡ãã»ã¼ã¸ãåãåãã¨éè¡ããã¤ã¸ã§ã¹ãã使ãã ã¢ãªã¹ãéã£ããã®ã¨æ¯ã¹ã¾ããããä¸è´ãããªãã åãåã£ãã¡ãã»ã¼ã¸ã¯ç¡å·ã ã¨ãããã¨ã«ãªãã¾ãã
ãã®ãããªè¦ç´ã¯ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ãã 䏿¹è¡é¢æ°ãã¾ãã¯ããã·ã¥é¢æ°ã¨å¼ã°ãã¾ãã ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ãã¯é·ãå¯å¤é·ã®ã¡ãã»ã¼ã¸ãã çãåºå®é·ã®è¡¨ç¾ãä½ãã®ã«ä½¿ããã¾ãã ãã¤ã¸ã§ã¹ãã¢ã«ã´ãªãºã ã¯ã¡ãã»ã¼ã¸ãã 䏿ãªãã¤ã¸ã§ã¹ããçæããããã«ä½ããã¦ãã¾ãã ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ãã¯ãã¤ã¸ã§ã¹ãããå ã®ã¡ãã»ã¼ã¸ã å¤å®ããã®ãã¨ã¦ãé£ããããã«ã§ãã¦ãã¾ãã ã¾ããåãè¦ç´ã使ããäºã¤ã®ã¡ãã»ã¼ã¸ãæ¢ãã®ã¯ä¸å¯è½ã§ãã ãã£ã¦ãåãè¦ç´ã使ã£ã¦ã¡ãã»ã¼ã¸ãç½®ãæããã¨ãã å¯è½æ§ãæé¤ãã¦ãã¾ãã
ã¢ãªã¹ã¸ã®ããä¸ã¤ã®åé¡ã¯ããã®ãã¤ã¸ã§ã¹ããå®å ¨ã«éãæ¹æ³ãæ¢ããã¨ã§ãã ãããã§ããã°ãã¡ãã»ã¼ã¸ã®ä¿¡ç¨ãä¿è¨¼ããã¾ãã ä¸ã¤ã®æ¹æ³ã¯ãã®ãã¤ã¸ã§ã¹ãã«é»åç½²åãå«ããã¨ã§ãã
é»åç½²åã¢ãªã¹ãéè¡ã«ã¡ãã»ã¼ã¸ãéã£ãã¨ããéè¡ã¯ã ä¾µå ¥è ã彼女ã«ãªããã¾ãã¦å½¼å¥³ã®å£åº§ã¸ã®åå¼ãç³è«ãã¦ããªããã ã¡ãã»ã¼ã¸ãæ¬å½ã«å½¼å¥³ããã®ãã®ã確å®ã«åãããªããã°ããã¾ããã ã¢ãªã¹ã«ãã£ã¦ä½æãããã¡ãã»ã¼ã¸ã«å«ã¾ãã é»åç½²åãããã§å½¹ã«ç«ã¡ã¾ãã
é»åç½²åã¯ã¡ãã»ã¼ã¸ã®ãã¤ã¸ã§ã¹ãããã®ä»ã®æ å ±(å¦ççªå·ãªã©)ã éä¿¡è ã®ç§å¯éµã§æå·åãããã¨ã§ä½ããã¾ãã 誰ããå ¬ééµã使ã£ã¦ç½²åã復å·ãããã¨ãã§ãã¾ããã ç½²åè ã®ã¿ãç§å¯éµãç¥ã£ã¦ãã¾ãã ããã¯ãå½¼ãã®ã¿ãç½²åããããã¨ãæå³ãã¾ãã ãã¤ã¸ã§ã¹ããé»åç½²åã«å«ããã¨ã¯ã ãã®ç½²åããã®ã¡ãã»ã¼ã¸ã®ã¿ã«æå¹ã§ãããã¨ãæå³ãã¾ãã ããã¯ã誰ããã¤ã¸ã§ã¹ããå¤ãã¦ç½²åããããã¨ãã§ããªãããã ã¡ãã»ã¼ã¸ã®ä¿¡ç¨ãä¿è¨¼ãã¾ãã
ä¾µå ¥è ãç½²åãååãã¦å¾æ¥ã«åå©ç¨ããã®ãé²ããã é»åç½²åã«ã¯ä¸æãªå¦ççªå·ãå«ã¾ãã¾ãã ããã¯ãã¢ãªã¹ããããªã¡ãã»ã¼ã¸ã¯éã£ã¦ããªãã¨è¨ãè©æ¬º ããéè¡ãå®ãã¾ãã 彼女ã ããç½²åãããããã§ãã(å¦èªé²æ¢)
è¨¼ææ¸ã¢ãªã¹ã¯ç§å¯ã®ã¡ãã»ã¼ã¸ãéè¡ã«éãã ç½²åããã¦ãã¡ãã»ã¼ã¸ã®ä¿¡ç¨ãä¿è¨¼ãããã¨ãã§ããããã«ãªãã¾ãããã éä¿¡ãã¦ããç¸æãæ¬å½ã«éè¡ãªã®ã確ãããªãã¦ã¯ããã¾ããã ããã¯ã彼女ã使ãå ¬ééµãéè¡ã®ç§å¯éµã¨å¯¾ã«ãªã£ã¦ãããã®ãã 彼女ã¯ç¢ºãããªãã¦ã¯ãããªãã¨ãããã¨ãæå³ãã¾ãã åæ§ã«ãéè¡ã¯ã¡ãã»ã¼ã¸ã®ç½²åãæ¬å½ã«ã¢ãªã¹ã®ç½²åã確èªããå¿ è¦ã ããã¾ãã
ãã両è ã«èº«å ã証æããå ¬ééµã確èªããã¾ãä¿¡é ¼ãããæ©é¢ãç½²å ããè¨¼ææ¸ãããã°ã両è ã¨ãéä¿¡ç¸æã«ã¤ãã¦æ£ããç¸æã 㨠確信ãããã¨ãã§ãã¾ãã ãã®ãããªä¿¡é ¼ãããæ©é¢ã¯èªè¨¼å± (Certificate Authority ã¾ã㯠CA) ã¨å¼ã°ãã è¨¼ææ¸ (certificate) ãèªè¨¼ (authentication) ã«ä½¿ããã¾ãã
è¨¼ææ¸ã®å å®¹è¨¼ææ¸ã¯å ¬ééµã¨å人ããµã¼ãããã®ä»ã®ä¸»ä½ã®å®å¨ã®èº«å ã é¢é£ä»ãã¾ãã 表1ã«ç¤ºãããããã«è¨¼æå¯¾è±¡ã®æ å ±ã¯ èº«å 証æã®æ å ±(èå¥å)ã¨å ¬ééµãå«ã¾ãã¾ãã è¨¼ææ¸ã¯ã¾ããèªè¨¼å±ã®èº«å 証æã¨ç½²åãããã¦è¨¼ææ¸ã®æå¹æéã å«ã¿ã¾ãã ã·ãªã¢ã«ãã³ãã¼ãªã©ã®èªè¨¼å±ã®ç®¡çä¸ã®æ å ±ã ãã®ä»ã®è¿½å ã®æ å ±ãå«ã¾ãã¦ããããããã¾ããã
表1: è¨¼ææ¸æ å ± 証æå¯¾è±¡ èå¥åãå ¬ééµ çºè¡è èå¥åãå ¬ééµ æå¹æé éå§æ¥ã失广¥ ç®¡çæ å ± ãã¼ã¸ã§ã³ãã·ãªã¢ã«ãã³ãã¼ æ¡å¼µæ å ± åºæ¬çãªå¶ç´ããããã¹ã±ã¼ããã©ãã°ããã®ä»èå¥å(ãã£ã¹ãã£ã³ã°ã¤ãã·ã¥ã»ãã¼ã )ã¯ç¹å®ã®ç¶æ³ã«ããã 身å証æãæä¾ããã®ã«ä½¿ããã¦ãã¾ããä¾ãã°ããã人㯠ç§ç¨ã¨ä¼ç¤¾ã¨ã§å¥ã ã®èº«å証æãæã¤ããããã¾ããã èå¥å㯠X.509 æ¨æºè¦æ ¼ [X509] ã§å®ç¾©ããã¦ãã¾ãã X.509 æ¨æºè¦æ ¼ã¯ãé ç®ãé ç®åãããã¦é ç®ã®ç¥ç§°ãå®ç¾©ãã¦ãã¾ãã(表 2 åç §)
表 2: èå¥åæ å ± èå¥åé ç® ç¥ç§° 説æ ä¾ Common Name (ã³ã¢ã³ãã¼ã ) CN èªè¨¼ãããååèªè¨¼å±ã¯ã©ã®é
ç®ãçç¥å¯è½ã§ã©ããå¿
é ãã®æ¹éãå®ç¾©ãã ããããã¾ãããé
ç®ã®å
容ã«ã¤ãã¦ãèªè¨¼å±ãè¨¼ææ¸ã®ã¦ã¼ã¶ããã® è¦ä»¶ãããããããã¾ããã ä¾ãã°ããããã¹ã±ã¼ãã®ãã©ã¦ã¶ã¯ãµã¼ãã®è¨¼ææ¸ã® Common Name (ã³ã¢ã³ãã¼ã )ããµã¼ãã®ãã¡ã¤ã³åã® *.example.com
ã¨ãããããªã¯ã¤ã«ãã«ã¼ãã®ãã¿ã¼ã³ã«ãããããã㨠ãè¦æ±ãã¾ãã
ãã¤ããªå½¢å¼ã®è¨¼ææ¸ã¯ ASN.1 è¡¨è¨æ³ [X208] [PKCS] ã§ å®ç¾©ããã¦ãã¾ãã ãã®è¡¨è¨æ³ã¯å 容ãã©ã®ããã«è¨è¿°ããããå®ç¾©ãã 符å·åã®è¦å®ããã®æ å ±ãã©ã®ããã«ãã¤ããªå½¢å¼ã«å¤æããããã å®ç¾©ãã¾ãã è¨¼ææ¸ã®ãã¤ããªç¬¦å·å㯠Distinguished Encoding Rules (DER) ã§å®ç¾©ãããããã¯ããä¸è¬ç㪠Basic Encoding Rules (BER) ã«åºã¥ãã¦ãã¾ãã ãã¤ããªå½¢å¼ãæ±ããã¨ã®ã§ããªãéä¿¡ã§ã¯ã ãã¤ããªå½¢å¼ã¯ Base64 符å·å [MIME] ã§ ASCII å½¢å¼ã«å¤æããããã¨ãããã¾ãã ãã®ããã«ç¬¦å·åããã以ä¸ã®ä¾ã«ç¤ºãããããã«åºåãè¡ã« æã¾ãããã®ã¯ PEM 符å·åãããã¨è¨ãã¾ãã (PEM ã®åå㯠"Privacy Enhanced Mail" ã«ç±æ¥ãã¾ã)
PEM 符å·åãããè¨¼ææ¸ã®ä¾ (example.crt)-----BEGIN CERTIFICATE----- MIIC7jCCAlegAwIBAgIBATANBgkqhkiG9w0BAQQFADCBqTELMAkGA1UEBhMCWFkx FTATBgNVBAgTDFNuYWtlIERlc2VydDETMBEGA1UEBxMKU25ha2UgVG93bjEXMBUG A1UEChMOU25ha2UgT2lsLCBMdGQxHjAcBgNVBAsTFUNlcnRpZmljYXRlIEF1dGhv cml0eTEVMBMGA1UEAxMMU25ha2UgT2lsIENBMR4wHAYJKoZIhvcNAQkBFg9jYUBz bmFrZW9pbC5kb20wHhcNOTgxMDIxMDg1ODM2WhcNOTkxMDIxMDg1ODM2WjCBpzEL MAkGA1UEBhMCWFkxFTATBgNVBAgTDFNuYWtlIERlc2VydDETMBEGA1UEBxMKU25h a2UgVG93bjEXMBUGA1UEChMOU25ha2UgT2lsLCBMdGQxFzAVBgNVBAsTDldlYnNl cnZlciBUZWFtMRkwFwYDVQQDExB3d3cuc25ha2VvaWwuZG9tMR8wHQYJKoZIhvcN AQkBFhB3d3dAc25ha2VvaWwuZG9tMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKB gQDH9Ge/s2zcH+da+rPTx/DPRp3xGjHZ4GG6pCmvADIEtBtKBFAcZ64n+Dy7Np8b vKR+yy5DGQiijsH1D/j8HlGE+q4TZ8OFk7BNBFazHxFbYI4OKMiCxdKzdif1yfaa lWoANFlAzlSdbxeGVHoT0K+gT5w3UxwZKv2DLbCTzLZyPwIDAQABoyYwJDAPBgNV HRMECDAGAQH/AgEAMBEGCWCGSAGG+EIBAQQEAwIAQDANBgkqhkiG9w0BAQQFAAOB gQAZUIHAL4D09oE6Lv2k56Gp38OBDuILvwLg1v1KL8mQR+KFjghCrtpqaztZqcDt 2q2QoyulCgSzHbEGmi0EsdkPfg6mp0penssIFePYNI+/8u9HT4LuKMJX15hxBam7 dUHzICxBVC1lnHyYGjDuAMhe396lYAn8bCld1/L4NMGBCQ== -----END CERTIFICATE-----
ã¾ãè¨¼ææ¸ã®ç³è«ã®æ å ±ã確èªãããã¨ã§ã èªè¨¼å±ã¯ç§å¯éµã®æã¡ä¸»ã®èº«å ãä¿è¨¼ãã¾ãã ä¾ãã°ãã¢ãªã¹ãåäººè¨¼ææ¸ãç³è«ããã¨ããã¨ã èªè¨¼å±ã¯ã¢ãªã¹ãè¨¼ææ¸ã®ç³è«ã主張ããéã㮠人ç©ã ã¨ãããã¨ã確èªããªãã¦ã¯ããã¾ããã
è¨¼ææ¸é層æ§éèªè¨¼å±ã¯ä»ã®èªè¨¼å±ã¸ã®è¨¼ææ¸ãçºè¡ãããã¨ãã§ãã¾ãã æªç¥ã®è¨¼ææ¸ã調ã¹ãæã«ãã¢ãªã¹ã¯ãã®è¨¼ææ¸ã®çºè¡è ã«èªä¿¡ãæã¦ãã¾ã§ãçºè¡è ã®è¨¼ææ¸ã ãã®ä¸ä½é層ã®èªè¨¼å±ããã©ã£ã¦èª¿ã¹ãå¿ è¦ãããã¾ãã ãæªè³ªãªãè¨¼ææ¸ã®å±éºæ§ãæ¸ããããã 彼女ã¯éãããé£éã®çºè¡è ã®ã¿ä¿¡é ¼ãããã㫠決ãããã¨ãã§ãã¾ãã
æä¸ä½èªè¨¼å±ã®ä½æåã«è¿°ã¹ãããã«ãå ¨ã¦ã®è¨¼ææ¸ã«ã¤ãã¦ã æä¸ä½ã®èªè¨¼å±(CA)ã¾ã§ããããã®çºè¡è ã 対象ã®èº«å 証æã®æå¹æ§ãæããã«ããå¿ è¦ãããã¾ãã åé¡ã¯ã誰ããã®æä¸ä½ã®èªè¨¼æ©é¢ã®è¨¼ææ¸ãä¿è¨¼ããã®ãã ã¨ãããã¨ã§ãã ãã®ãããªå ´åã«éããè¨¼ææ¸ã¯ãèªå·±ç½²åãããã¾ãã ã¤ã¾ããè¨¼ææ¸ã®çºè¡è ã¨è¨¼æå¯¾è±¡ãåãã¨ãããã¨ã«ãªãã¾ãã ãã®çµæãèªå·±ç½²åãããè¨¼ææ¸ãä¿¡ç¨ããã«ã¯ ç´°å¿ã®æ³¨æãå¿ è¦ã§ãã æä¸ä½èªè¨¼å±ãå ¬ééµãåºãå ¬è¡¨ãããã¨ã§ã ãã®éµãä¿¡é ¼ãããªã¹ã¯ãä½ããããã¨ãã§ãã¾ãã ãããä»äººããã®èªè¨¼å±ã«ãªããã¾ããæã«ããããé²è¦ãã ããããã§ãã å¤ãã®ãã©ã¦ã¶ã¯æåãªèªè¨¼å±ãä¿¡é ¼ããããã« è¨å®ããã¦ãã¾ãã
Thawte ã VeriSign ã®ãããªå¤ãã®ä¼ç¤¾ãèªè¨¼å±ã¨ãã¦éè¨ãã¾ããã ãã®ãããªä¼ç¤¾ã¯ä»¥ä¸ã®ãµã¼ãã¹ãæä¾ãã¾ã:
èªåã§èªè¨¼å±ãä½ããã¨ãå¯è½ã§ãã ã¤ã³ã¿ã¼ãããç°å¢ã§ã¯å±éºã§ããã å人ããµã¼ãã®èº«å 証æãç°¡åã«è¡ããçµç¹ã® ã¤ã³ãã©ãããå ã§ã¯å½¹ã«ç«ã¤ããããã¾ããã
è¨¼ææ¸ç®¡çèªè¨¼å±ã®éè¨ã¯å¾¹åºãã管çãæè¡ãéç¨ã®ä½å¶ãå¿ è¦ã¨ãã 責任ã®ããä»äºã§ãã èªè¨¼å±ã¯è¨¼ææ¸ãçºè¡ããã ãã§ãªãã 管çãããªããã°ãªãã¾ããã å ·ä½çã«ã¯ãè¨¼ææ¸ããã¤ã¾ã§æå¹ããæ±ºå®ããæ´æ°ãã ã¾ãæ¢ã«çºè¡ãããã失å¹ããè¨¼ææ¸ã®ãªã¹ã (Certificate Revocation Lists ã¾ã㯠CRL) ã管çããªããã°ããã¾ããã ä¾ãã°ãã¢ãªã¹ãä¼ç¤¾ãã社å¡ã¨ãã¦è¨¼ææ¸ãä¸ããããã¨ãã¾ãã ããã¦ãã¢ãªã¹ãä¼ç¤¾ãè¾ããã¨ãã«ã¯è¨¼ææ¸ãåãæ¶ããªããã° ãããªãã¨ãã¾ãã è¨¼ææ¸ã¯æ¬¡ã ã¨äººã«æ¸¡ããã¦ãããã®ãªã®ã§ã è¨¼ææ¸ãã®ãã®ããããããåãæ¶ãããã夿ãããã¨ã¯ ä¸å¯è½ã§ãã ãã£ã¦ãè¨¼ææ¸ã®æå¹æ§ã調ã¹ãã¨ãã«ã¯ã èªè¨¼å±ã«é£çµ¡ã㦠CRL ãç §åããå¿ è¦ãããã¾ãã æ®éãã®éç¨ã¯èªååããã¦ãããã®ã§ã¯ããã¾ããã
注æããã©ã«ãã§ãã©ã¦ã¶ã«è¨å®ããã¦ããªãèªè¨¼å±ã使ã£ãå ´åã èªè¨¼å±ã®è¨¼ææ¸ããã©ã¦ã¶ã«èªã¿è¾¼ãã§ã ãã©ã¦ã¶ããã®èªè¨¼å±ã«ãã£ã¦ç½²åããããµã¼ãã®è¨¼ææ¸ã æå¹åããå¿ è¦ãããã¾ãã ä¸åº¦èªã¿è¾¼ã¾ããã¨ããã®èªè¨¼å±ã«ãã£ã¦ç½²åãããå ¨ã¦ã® è¨¼ææ¸ãåãå ¥ãããããå±éºãä¼´ãã¾ãã
Secure Sockets Layer (SSL)Secure Sockets Layer ãããã³ã«ã¯ä¿¡é ¼æ§ã®ããã³ãã¯ã·ã§ã³åã® ãããã¯ã¼ã¯å±¤ã®ãããã³ã«(ä¾ãã°ãTCP/IP)㨠ã¢ããªã±ã¼ã·ã§ã³å±¤ã®ãããã³ã«(ä¾ãã°ãHTTP) ã®éã«ç½®ããã¨ãã§ãã¾ãã SSL ã¯ãç¸äºèªè¨¼ã«ãã£ã¦ãµã¼ãã¨ã¯ã©ã¤ã¢ã³ãéã®å®å ¨ãªéä¿¡ãã é»åç½²åã«ãã£ã¦ãã¼ã¿ã®å®å ¨æ§ãã ããã¦æå·åã«ãã£ã¦ãã©ã¤ãã·ãæä¾ãã¾ãã
SSL ãããã³ã«ã¯æå·åããã¤ã¸ã§ã¹ããé»åç½²åã«ã¤ãã¦ã æ§ã ãªã¢ã«ã´ãªãºã ããµãã¼ãããããã«ã§ãã¦ãã¾ãã ãããããã¨ã§ãæ³ã輸åºã®è¦å¶ãèæ ®ã«å ¥ãã¦ããµã¼ãã«åããã ã¢ã«ã´ãªãºã ãé¸ã¶ãã¨ãã§ããã¾ããæ°ããã¢ã«ã´ãªãºã ã å©ç¨ãã¦ãããã¨ãå¯è½ã«ãã¦ãã¾ãã ã¢ã«ã´ãªãºã ã®é¸æã¯ãããã³ã«ã»ãã·ã§ã³éå§æã« ãµã¼ãã¨ã¯ã©ã¤ã¢ã³ãéã§åãæ±ºãããã¾ãã
表4: SSL ãããã³ã«ã®ãã¼ã¸ã§ã³ ãã¼ã¸ã§ã³ åºå ¸ 説æ ãã©ã¦ã¶ã®ãµãã¼ã SSL v2.0 Vendor Standard (Netscape Corp. ãã) [SSL2] å®è£ ãç¾åããåãã¦ã® SSL ãããã³ã« - NS Navigator 1.x/2.x表4ã«ç¤ºãããã¨ãããSSL ãããã³ã«ã«ã¯ ããã¤ãã®ãã¼ã¸ã§ã³ãããã¾ãã 表ã«ãæ¸ããã¦ããããã«ãSSL 3.0 ã®å©ç¹ã®ä¸ã¤ã¯ è¨¼ææ¸é層æ§é ããµãã¼ããããã¨ã§ãã ãã®æ©è½ã«ãã£ã¦ããµã¼ãã¯èªåã®è¨¼ææ¸ã«å ãã¦ã çºè¡è ã®è¨¼ææ¸ããã©ã¦ã¶ã«æ¸¡ããã¨ãã§ãã¾ãã è¨¼ææ¸é層æ§é ã«ãã£ã¦ã ãã©ã¦ã¶ã«çºè¡è ã®è¨¼ææ¸ãç´æ¥ç»é²ããã¦ããªãã¦ãã é層ã®ä¸ã«å«ã¾ãã¦ããã°ã ãã©ã¦ã¶ã¯ãµã¼ãã®è¨¼ææ¸ãæå¹åãããã¨ãã§ãã¾ãã SSL 3.0 ã¯ç¾å¨ Internet Engineering Task Force (IETF) ã«ãã£ã¦éçºããã¦ãã Transport Layer Security [TLS] ãããã³ã«æ¨æºè¦æ ¼ã®åºç¤ã¨ãªã£ã¦ãã¾ãã
ã»ãã·ã§ã³ã®ç¢ºç«å³1ã§ç¤ºãããããã«ã ã»ãã·ã§ã³ã®ç¢ºç«ã¯ã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãéã® ãã³ãã·ã§ã¼ã¯ã·ã¼ã¯ã¨ã³ã¹ã«ãã£ã¦è¡ãªããã¾ãã ãµã¼ããè¨¼ææ¸ãæä¾ããããã¯ã©ã¤ã¢ã³ãã®è¨¼ææ¸ããªã¯ã¨ã¹ãããã ã¨ãããµã¼ãã®è¨å®ã«ããããã®ã·ã¼ã¯ã¨ã³ã¹ã¯ç°ãªããã®ã¨ãªãã¾ãã æå·æ å ±ã®ç®¡çã®ããã«ã追å ã®ãã³ãã·ã§ã¼ã¯éç¨ãå¿ è¦ã«ãªã å ´åãããã¾ããããã®è¨äºã§ã¯ ããããã·ããªãªãæçã«èª¬æãã¾ãã å ¨ã¦ã®å¯è½æ§ã«ã¤ãã¯ãSSL 仿§æ¸ãåç §ãã¦ãã ããã
注æä¸åº¦ SSL ã»ãã·ã§ã³ã確ç«ããã¨ãã»ãã·ã§ã³ãåå©ç¨ãããã¨ã§ã ã»ãã·ã§ã³ãéå§ããããã®å¤ãã®éç¨ãç¹°ãè¿ãã¨ãã ããã©ã¼ãã³ã¹ã®æå¤±ãé²ãã¾ãã ãã®ããããµã¼ãã¯å ¨ã¦ã®ã»ãã·ã§ã³ã«ä¸æãªã»ãã·ã§ã³èå¥åã å²ãå½ã¦ããµã¼ãã«ãã£ãã·ã¥ããã¯ã©ã¤ã¢ã³ãã¯æ¬¡åãã (èå¥åããµã¼ãã®ãã£ãã·ã¥ã§æéåãã«ãªãã¾ã§ã¯) ãã³ãã·ã§ã¼ã¯ãªãã§æ¥ç¶ãããã¨ãã§ãã¾ãã
å³1: SSL ãã³ãã·ã§ã¼ã¯ã·ã¼ã¯ã¨ã³ã¹æ¦ç¥
ãµã¼ãã¨ã¯ã©ã¤ã¢ã³ãã§ä½¿ããã ãã³ãã·ã§ã¼ã¯ã·ã¼ã¯ã¨ã³ã¹ã®è¦ç´ ã以ä¸ã«ç¤ºãã¾ã:
第ä¸ã¹ãããã®æå·ã¹ã¤ã¼ãåãæ±ºãã«ãã£ã¦ã ãµã¼ãã¨ã¯ã©ã¤ã¢ã³ãã¯ããããã«ãã£ã æå·ã¹ã¤ã¼ããé¸ã¶ãã¨ãã§ãã¾ãã SSL3.0 ãããã³ã«ã®ä»æ§æ¸ã¯ 31 ã®æå·ã¹ã¤ã¼ããå®ç¾©ãã¦ãã¾ãã æå·ã¹ã¤ã¼ãã¯ä»¥ä¸ã®ã³ã³ãã¼ãã³ãã«ããå®ç¾©ããã¦ãã¾ã:
ãããã®ä¸ã¤ã®è¦ç´ ã¯ä»¥ä¸ã®ã»ã¯ã·ã§ã³ã§èª¬æããã¦ãã¾ãã
éµã®äº¤æææ®µéµã®äº¤æææ®µã¯ã¢ããªã±ã¼ã·ã§ã³ã®ãã¼ã¿éä¿¡ã«ä½¿ããã å ±æããã対称æå·éµãã©ã®ããã«ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã§ åãæ±ºããããå®ç¾©ãã¾ãã SSL 2.0 㯠RSA éµäº¤æãã使ãã¾ãããã SSL 3.0 ã¯è¨¼ææ¸ã使ãããã¨ã㯠RSA éµäº¤æã使ãã è¨¼ææ¸ãç¡ããã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã®äºåã®éä¿¡ãç¡ãå ´å㯠Diffie-Hellman éµäº¤æã使ã ãªã©æ§ã ãªéµäº¤æã¢ã«ã´ãªãºã ããµãã¼ããã¾ãã
éµã®äº¤ææ¹æ³ã«ãããä¸ã¤ã®é¸æè¢ã¯é»åç½²åã§ãã é»åç½²åã使ããã©ãããã¾ãã ã©ã®ç¨®é¡ã®ç½²åã使ããã¨ãã鏿ãããã¾ãã ç§å¯éµã§ç½²åãããã¨ã§å ±æéµãçæãããæ å ±äº¤æããæã® ãã³ã»ã¤ã³ã»ã¶ã»ããã«æ»æãé²ããã¨ãã§ãã¾ãã [AC96, p516]
ãã¼ã¿éä¿¡ã®æå·è¡SSL ã¯ã»ãã·ã§ã³ã®ã¡ãã»ã¼ã¸ã®æå·åã«åè¿°ãã 徿¥åæå·(対称æå·)ãç¨ãã¾ãã æå·åããªãã¨ãã鏿è¢ãå«ãä¹ã¤ã®é¸æè¢ãããã¾ã:
ããã§ã® CBC ã¨ã¯æå·ãããã¯é£é (Cipher Block Chaining) ã®ç¥ã§ãä¸ã¤åã®æå·åãããæå·æã®ä¸é¨ã ãããã¯ã®æå·åã«ä½¿ããããã¨ãæå³ãã¾ãã DES ã¯ãã¼ã¿æå·åæ¨æºè¦æ ¼ (Data Encryption Standard) [AC96, ch12] ã®ç¥ã§ã DES40 ã 3DES_EDE ãå«ãããã¤ãã®ç¨®é¡ãããã¾ãã Idea ã¯æé«ãªãã®ã®ä¸ã¤ã§ãæå·è¡çã«ã¯ç¾å¨ããä¸ã§ æãå¼·åãªãã®ã§ãã RC2 㯠RSA DSI ã«ããç¬å çãªã¢ã«ã´ãªãºã ã§ãã [AC96, ch13]
ãã¤ã¸ã§ã¹ã颿°ãã¤ã¸ã§ã¹ã颿°ã®é¸æã¯ã¬ã³ã¼ãã¦ãããããã©ã®ããã«ãã¤ã¸ã§ã¹ããçæãããããæ±ºå®ãã¾ãã SSL ã¯ä»¥ä¸ããµãã¼ããã¾ã:
ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ã㯠Message Authentication Code (MAC) ã®çæã«ä½¿ãããã¡ãã»ã¼ã¸ã¨å ±ã«æå·åãããã¡ãã»ã¼ã¸ã®ä¿¡ç¨ã æä¾ãããªãã¬ã¤æ»æãé²ãã¾ãã
ãã³ãã·ã§ã¼ã¯ã·ã¼ã¯ã¨ã³ã¹ãããã³ã«ãã³ãã·ã§ã¼ã¯ã·ã¼ã¯ã¨ã³ã¹ã¯ä¸ã¤ã®ãããã³ã«ã使ãã¾ã:
ä¸ã¤ã®ãããã³ã«ã¯ãã¢ããªã±ã¼ã·ã§ã³ãããã³ã«ãã¼ã¿ã¨ã¨ãã«ã å³2ã«ç¤ºãã¨ãã SSL ã¬ã³ã¼ããããã³ã« ã§ã«ãã»ã«åããã¾ãã ã«ãã»ã«åããããããã³ã«ã¯ãã¼ã¿ãæ¤æ»ããªã ä¸å±¤ã®ãããã³ã«ã«ãã£ã¦ãã¼ã¿ã¨ãã¦ä¼éããã¾ãã ã«ãã»ã«åããããããã³ã«ã¯ä¸å±¤ã®ãããã³ã«ã«é¢ãã¦ä¸åé¢ç¥ãã¾ããã
å³2: SSL ãããã³ã«ã¹ã¿ãã¯
ã¬ã³ã¼ããããã³ã«ã«ãã SSL ã³ã³ããã¼ã«ãããã³ã«ã®ã«ãã»ã«åã¯ã ã¢ã¯ãã£ããªã»ãã·ã§ã³ã®äºåç®ã®éä¿¡ããã£ãå ´åã ã³ã³ããã¼ã«ãããã³ã«ãå®å ¨ã§ãããã¨ãæå³ãã¾ãã æ¢ã«ã»ãã·ã§ã³ãç¡ãå ´åã¯ãNull æå·ã¹ã¤ã¼ãã使ããã æå·åã¯è¡ãªããããã»ãã·ã§ã³ã確ç«ããã¾ã§ã¯ ãã¤ã¸ã§ã¹ããç¡ãç¶æ ã¨ãªãã¾ãã
ãã¼ã¿éä¿¡å³3ã«ç¤ºããã SSL ã¬ã³ã¼ããããã³ã« ã¯ã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãéã®ã¢ããªã±ã¼ã·ã§ã³ã SSL ã³ã³ããã¼ã«ãã¼ã¿ã®éä¿¡ã«ä½¿ããã¾ãã ãã®ãã¼ã¿ã¯ããå°ããã¦ãããã«åãããããã ããã¤ãã®é«ç´ãããã³ã«ãã¾ã¨ãã¦ä¸ã¦ãããã¨ãã¦éä¿¡ã è¡ãªããããã¨ãããã¾ãã ãã¼ã¿ãå§ç¸®ãããã¤ã¸ã§ã¹ãç½²åãæ·»ä»ãã¦ã ãããã®ã¦ããããæå·åããã®ã¡ããã¼ã¹ã¨ãªã£ã¦ãã ä¿¡é ¼æ§ã®ãããã©ã³ã¹ãã¼ããããã³ã«ãç¨ããããããã¾ããã (注æ: ç¾å¨ã¡ã¸ã£ã¼ãª SLL å®è£ ã§å§ç¸®ããµãã¼ããã¦ãããã®ã¯ããã¾ãã)
å³ 3: SSL ã¬ã³ã¼ããããã³ã«
ãããã SSL ã®ä½¿ãæ¹ã¯ãã©ã¦ã¶ã¨ã¦ã§ããµã¼ãéã® HTTP éä¿¡ ã®å®å
¨åã§ãã ããã¯ã徿¥ã®å®å
¨ã§ã¯ãªã HTTP ã®ä½¿ç¨ãé¤å¤ãããã®ã§ã¯ããã¾ããã å®å
¨åããããã®ã¯ä¸»ã« SSH ä¸ã®æ®éã® HTTP ã§ãHTTPS ã¨å¼ã°ãã¾ãã 大ããªéãã¯ãURL ã¹ãã¼ã ã« http
ã®ä»£ããã« https
ãç¨ãããµã¼ããå¥ã®ãã¼ãã使ããã¨ã§ã (ããã©ã«ãã§ã¯443)ã ããã主㫠mod_ssl
ã Apache ã¦ã§ããµã¼ãã«æä¾ããæ©è½ã§ãã
Applied Cryptography, 2nd Edition, Wiley, 1996. See http://www.counterpane.com/ for various other materials by Bruce Schneier.
Specification of Abstract Syntax Notation One (ASN.1), 1988. See for instance http://www.itu.int/rec/recommendation.asp?type=items&lang=e&parent=T-REC-X.208-198811-I.
The Directory - Authentication Framework. See for instance http://www.itu.int/rec/recommendation.asp?type=folders&lang=e&parent=T-REC-X.509.
Public Key Cryptography Standards (PKCS), RSA Laboratories Technical Notes, See http://www.rsasecurity.com/rsalabs/pkcs/.
Multipurpose Internet Mail Extensions (MIME) Part One: Format of Internet Message Bodies, RFC2045. See for instance http://ietf.org/rfc/rfc2045.txt.
The SSL Protocol, 1995. See http://www.netscape.com/eng/security/SSL_2.html.
The SSL Protocol Version 3.0, 1996. See http://www.netscape.com/eng/ssl3/draft302.txt.
The TLS Protocol Version 1.0, 1999. See http://ietf.org/rfc/rfc2246.txt.
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4