¼«ÂÄÍî¤Êµ»½Ñ¼Ô¤ÎÆüµ­

´ðËܤ϶ô¤Ã¤Æ¤ë¤«°û¤ó¤Ç¤ë¤«¤Ç¤¹¤¬¡¢¤è¤¯¼ñÌ£¤Ç¥«¥é¥ª¥±¡¦PKI¡¦½ð̾¡¦Ç§¾Ú¡¦¥×¥í¥°¥é¥ß¥ó¥°¡¦¾ðÊ󥻥­¥å¥ê¥Æ¥£¤ò¤ä¤Ã¤Æ¤¤¤Þ¤¹¡£Î¹¹¥¤­¡£¥Æ¥ì¥Ó¹¥¤­¤Ç·ÝǽÄÌ

¾ÚÌÀ½ñ

ºÇ¶á¤Î¾ÚÌÀ½ñ¤ÎÏÃÂê(2): CloudFlare DNS 1.1.1.1¥µ¥¤¥È¤ÎIPv6¾ÚÌÀ½ñ

º£Æü¤â¡¢¾ÚÌÀ½ñ¥Ï¥ó¥¿¡¼¥Í¥¿¤ÎÂèÆóÃÆ¤È¤¤¤¦¤³¤È¤Ç¡¢¡¢¡¢

4·î1Æü¤Ë¸ø³«¤Ë¤Ê¤Ã¤¿APNIC¤ÈCloudFlare¤¬Ä󶡤¹¤ë¡¢¥ì¥¹¥Ý¥ó¥¹¤¬Â®¤¯¤Æ¡¢¥×¥é¥¤¥Ð¥·¡¼¤ËÇÛθ¤·¤¿±½¤Î1.1.1.1¤È¤¤¤¦¥Ñ¥Ö¥ê¥Ã¥¯DNS¥µ¡¼¥Ó¥¹¤¬ÍøÍѤǤ­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿¡£DNS¥µ¡¼¥Ð¡¼¤Ï¡¢ÄÌ¿®¤¬°Å¹æ²½¤µ¤ì¤Æ¤¤¤Æ¤â¡¢¤É¤ÎIP¤«¤é¤É¤ÎIP¤Ë¥¢¥¯¥»¥¹¤·¤¿¤«¤È¤¤¤¦µ­Ï¿¤¬»Ä¤ë¤Î¤Ç¡¢¤½¤ì¤ò¥¿¡¼¥²¥Æ¥£¥ó¥°¹­¹ð¤Ê¤É¤Ë»È¤Ã¤¿¤ê¤¹¤ë¤½¤¦¤Ç¤¹¡£¤³¤ÎDNS¥µ¡¼¥Ó¥¹¤Ï¡¢¥×¥é¥¤¥Ð¥·¡¼¤ËÇÛθ¤·¤Æ¥í¥°¤ÎÊݸ´ü´Ö¤ò1½µ´Ö¤È¤·¡¢¹­¹ð¤Ê¤É¤Ë»È¤ï¤ì¤Ê¤¤¤è¤¦¤Ë¤·¤Æ¤¤¤ë¤½¤¦¤Ç¤¹¡£

¤³¤ó¤Êµ­»ö¸«¤Á¤ã¤¦¤ÈÄÌ¿®Á´ÂΤÇÁ᤯¤Ê¤ë¤Î¤«¤É¤¦¤«¤Ï¤è¤¯¤ï¤«¤é¤Ê¤¤¤Ç¤¹¤Í¡£¤Ç¡¢¤³¤Î¥µ¡¼¥Ó¥¹¤Î¸ø¼°¾Ò²ð¥µ¥¤¥Èhttps://1.1.1.1/¤Ê¤ó¤Ç¤¹¤¬¡¢FQDN¤Ç¤Ê¤¯¡¢IP¥¢¥É¥ì¥¹¤Çȯ¹Ô¤·¤Æ¤¤¤ë¤ï¤±¤Ç¤¹¡£²¿¤ä¤é¤ª¤â¤·¤í¤½¤¦¤¸¤ã¤Ê¤¤¤Ç¤¹¤«¡£Áᮡ¢¾ÚÌÀ½ñ¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¤ß¤Æ¡¢ÆâÍÆ¤ò¸«¤Æ¤ß¤Þ¤·¤ç¤¦¡£

$ openssl x509 -in ip1.1.1.1.cer -noout -text Certificate: Data: Version: 3 (0x2) Serial Number: 05:6c:de:b4:14:65:ff:27:07:16:c0:6e:91:16:2e:19 Signature Algorithm: <font color=¡Èorange¡É>ecdsa-with-SHA256</font> Issuer: C=US, O=DigiCert Inc, CN=DigiCert ECC Secure Server CA Validity Not Before: Mar 30 00:00:00 2018 GMT Not After : Mar 25 12:00:00 2020 GMT Subject: C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=*.cloudflare-dns.com Subject Public Key Info: Public Key Algorithm: id-ecPublicKey Public-Key: (256 bit) pub: 04:b2:45:0b:31:ac:50:63:ce:21:e6:7c:34:23:1a: c5:c1:53:45:96:97:7a:31:87:bb:e0:ea:1d:95:f5: ff:25:04:ca:75:f0:f6:3f:b5:df:51:e9:5b:c9:3d: ad:b4:03:05:73:20:92:3e:74:be:8e:4b:1b:e2:68: 86:44:6e:62:bb ASN1 OID: prime256v1 NIST CURVE: P-256 X509v3 extensions: X509v3 Authority Key Identifier: keyid:A3:9D:E6:1F:F9:DA:39:4F:C0:6E:E8:91:CB:95:A5:DA:31:E2:0A:9F X509v3 Subject Key Identifier: DF:97:4D:E5:43:B3:B0:41:A7:42:F2:90:CF:89:7F:AE:12:57:84:E1 X509v3 Subject Alternative Name: DNS:*.cloudflare-dns.com, IP Address:1.1.1.1, IP Address:1.0.0.1, DNS:cloudflare-dns.com, IP Address:2606:4700:4700:0:0:0:0:1111, IP Address:2606:4700:4700:0:0:0:0:1001 X509v3 Key Usage: critical Digital Signature X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 CRL Distribution Points: Full Name: URI:http://crl3.digicert.com/ssca-ecc-g1.crl Full Name: URI:http://crl4.digicert.com/ssca-ecc-g1.crl X509v3 Certificate Policies: Policy: 2.16.840.1.114412.1.1 CPS: https://www.digicert.com/CPS Policy: 2.23.140.1.2.2 Authority Information Access: OCSP - URI:http://ocsp.digicert.com CA Issuers - URI:http://cacerts.digicert.com/ DigiCertECCSecureServerCA.crt X509v3 Basic Constraints: critical CA:FALSE Signature Algorithm: ecdsa-with-SHA256 30:65:02:31:00:8e:8c:b2:d8:e8:21:d6:2d:7f:2a:1f:7e:a6: c3:1c:d4:e0:a1:95:02:2f:40:5e:80:92:88:d9:4b:cc:a5:89: aa:fa:9b:ca:b9:9e:a0:b7:a9:ed:21:1d:1d:1f:13:1c:0b:02: 30:2e:79:64:67:1d:7e:10:27:d9:68:a8:c8:6c:3e:4d:cd:07: 40:ac:d2:64:ad:b0:d0:cd:1b:af:c3:a4:26:30:ed:79:a3:a0: 6d:f2:d4:b4:bb:66:46:59:9a:a3:67:d9:0f
¤³¤Î¾ÚÌÀ½ñ¤ÎÆÃħ¤Ï¤³¤ó¤Ê¤È¤³¡§
  • DigiCert¤¬È¯¹Ô¤·¤Æ¤¤¤ë
  • Âʱ߶ÊÀþ(ECC)¤Î¸ø³«¸°¾ÚÌÀ½ñ
  • ¼çÂμÔÊÌ̾(subjectAltName)¤ËIPv4¥¢¥É¥ì¥¹¤ÈIPv6¥¢¥É¥ì¥¹¤¬µ­ºÜ¤µ¤ì¤Æ¤¤¤ë
¤¤¤ä¡Á¡Á¡Á¡¢¤¹¤´¤¤¤Ç¤¹¤Í¡£¾ÚÌÀ½ñ¥Ï¥ó¥¿¡¼¤Ê¤Î¤Ç¤¤¤í¤¤¤í¾ÚÌÀ½ñ¤òõ¤·¤Æ¸«¤Æ¤Þ¤¹¤±¤É¡¢IPv6¥¢¥É¥ì¥¹¸þ¤±¤Î¥×¥é¥¤¥Ù¡¼¥È¤¸¤ã¤Ê¤¤¾ÚÌÀ½ñ¤ò½é¤á¤Æ¸«¤Þ¤·¤¿¤è¡£¤³¤ì¤Ï¡¢Áᮥ³¥ì¥¯¥·¥ç¥óÂоݤǤ¹¤è¤Ã¡ª¡ª¡ª

ÀèÆü¡¢¥Ç¡¼¥¿ÄÌ¿®¶¨²ñ¤Î¥»¥ß¥Ê¡¼¤ÇÁí̳¾Ê¤ÎÊý¤Î¹Ö±é¤òÇÒݤ·¤¿¤ó¤Ç¤¹¤¬¡¢ ¡ÖiPhone¤È¤«¥¹¥Þ¥Û¤Î¤ª¤«¤²¤ÇIPv6¤Ã¤ÆËÜÅö¤ËÉáµÚ¤·¤Á¤ã¤Ã¤¿¡£¡×¤È¶Ä¤Ã¤Æ¤¤¤Þ¤·¤¿¡£ ¥Û¥ó¥È¡¢¤½¤ÎÄ̤ê¤Ê¤ó¤Ç¤¹¤Í¤§¡£ÆüËܤ«¤éGoogle¤Ø¤Î¥¢¥¯¥»¥¹¤Ï17%¤¬IPv6¤Ê¤ó¤À¤½¤¦¤Ç¤¹¡£ Apple iOS¤Ç¤Ï¡¢IPv4¤À¤È(¤ï¤¶¤È¡©)Ãٱ䤵¤»¤ë»ÅÁȤߤ¬Æþ¤ë¤½¤¦¤Ç¡¢º£¸å¡¢IPv6¤Ø¤Î°Ü¹Ô¤¬²Ã®¤µ¤ì¤ë¤À¤í¤¦¤È¤Î»ö¤Ç¤·¤¿¡£

¼Â¤Ï¡¢¼ñÌ£¤Çºî¤Ã¤¿jsrsasign¤È¤¤¤¦JavaScript¼ÂÁõ¤Î°Å¹æ/PKI´ØÏ¢¥é¥¤¥Ö¥é¥ê¤ò¸ø³«¤·¤Æ¤¤¤ë¤ó¤Ç¤¹¤¬¡¢¤è¤¯¹Í¤¨¤Æ¤ß¤¿¤éIPv6Âбþ¤·¤Æ¤Ê¤«¤Ã¤¿¤ó¤Ç¤¹¤è¡£¤³¤ê¤ã¥Þ¥º¥¤¤Ê¤¡¡¢¡¢¡¢¤È¡£Áᮡ¢Âбþ¤µ¤»¤Æ¤ß¤Þ¤·¤¿¡£

ºÇ¸å¤Î¥µ¥ó¥×¥ë¤Ï¤¤¤í¤ó¤Ê¾ÚÌÀ½ñ¤ò´Êñ¤Ëºî¤ì¤ë¤Î¤Ç¡¢Í·¤ó¤Ç¤ä¤Ã¤Æ¤¯¤À¤µ¤¤¡£ ¤½¤¦¤¤¤¦°ÕÌ£¤Ç¤ÏOpenSSL¤Î¾ÚÌÀ½ñ¤Îɽ¼¨¤Ï
IP Address:2606:4700:4700:0:0:0:0:1001
¤Î¤è¤¦¤Ê´¶¤¸¤ÇRFC 5952¤ÇÀµµ¬²½¤µ¤ì¤Æ¤¤¤ë¤ï¤±¤Ç¤Ï¤Ê¤¤¡¢°ì°Õ¤¸¤ã¤Ê¤¤É½µ­¤Î¤ä¤Ä¤Ê¤ó¤Ç¤¹¤Í¤§¡£Àµµ¬²½¤·¤¿¤é¤³¤¦¤Ê¤ê¤Þ¤¹¤è¤Í¡£
IP Address:2606:4700:4700::1001
RFC 5952¤Ê¤ó¤ÆÃΤé¤Ê¤«¤Ã¤¿¤ó¤Ç¤¹¤¬¡¢JPNIC¤µ¤ó¤Î¡ÖRFC5952-IPv6¥¢¥É¥ì¥¹¤Î¿ä¾©É½µ­ IPv6¥¢¥É¥ì¥¹É½µ­¤Î½ÀÆðÀ­¤¬µ¯¤³¤¹ÌäÂê¤ÈRFC5952¤Î²òÀâ¡×¤ò¸«¤ÆÊÙ¶¯¤µ¤»¤Æ¤â¤é¤¤¤Þ¤·¤¿¡£¤¢¤ê¤¬¤¿¤ä¡£¤¢¤ê¤¬¤¿¤ä¡£

¤Æ¤Ê¤ï¤±¤Ç¡¢º£Æü¤â¥Ê¥¤¥¹¤Ê¾ÚÌÀ½ñ¤ò¥²¥Ã¥È¤À¤¼¡£º£Æü¤Ï¤³¤ÎÊդǡ¢¡¢¡¢

(¾®¥Í¥¿) Chrome 60¤Ç¾ÚÌÀ½ñ¤òɽ¼¨¤µ¤»¤ë¥Õ¥é¥°ÀßÄê

Chrome 56¤«¤éGoogle¤Î¡ÖÁǿͤϤ¹¤Ã¤³¤ó¤Ç¤í¡×UI/UX¥Ý¥ê¥·¡¼¤Ë¤è¤êHTTPS¤ÇÀܳ¤·¤¿ºÝ¤Ë»ÈÍѤ·¤Æ¤¤¤ëSSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Îɽ¼¨¤¬¸°¥¢¥¤¥³¥ó¤«¤é´Êñ¤Ë¤Ç¤­¤Ê¤¯¤Ê¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡£¾ÚÌÀ½ñÂç¹¥¤­¤Ã»Ò¤Ë¤Ï¤Ê¤ó¤È¤â¿É¤¤»ÅÂǤÁ¤Ç¤·¤¿¡£³«È¯¥Ä¡¼¥ë¤«¤é¤Ï¾ÚÌÀ½ñ¤¬É½¼¨¤Ç¤­¤ë¤Î¤Ç¡¢¥á¥Ë¥å¡¼¤òé¤Ã¤ÆÁàºî¤¹¤ë¤«¡¢¥·¥ç¡¼¥È¥«¥Ã¥È¥­¡¼¤òÁÇ¿¶¤ê100²ó¤·¤Æ¤¤¤¿Êý¤â¿¤¤¤Î¤Ç¤Ï¤È»×¤¤¤Þ¤¹¡£

Windows: Ctrl + Shift + I or F12
Mac: ⌘ + Opt + I

º£Æü¤Ï¡¢¤ä¤Ã¤ÈChrome 60¤«¤é¥Õ¥é¥°ÀßÄê¤Ç¾ÚÌÀ½ñ¤¬´Êñ¤Ëɽ¼¨¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤Ã¤¿¤Î¤Ç¡¢º£Æü¤Ï¤½¤ÎÀßÄê¤Ë¤Ä¤¤¤Æ¾Ò²ð¤·¤Þ¤¹¡£

²¿¤âÀßÄꤷ¤Æ¤¤¤Ê¤¤¤È¡¢HTTPS¥µ¥¤¥È¤ò¸«¤Æ¤¤¤ëºÝ¤Î¡¢¸°¥¢¥¤¥³¥ó¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¸«¤é¤ì¤ë¥á¥Ë¥å¡¼¤Ï¤³¤ó¤Ê´¶¤¸¡£
before
¤½¤³¤Ç¡¢¥¢¥É¥ì¥¹¥Ð¡¼¤Ç°Ê²¼¤Î¤è¤¦¤ËÆþÎϤ·¤Þ¤¹¡£

chrome://flags/#show-cert-link
¤¹¤ë¤È¡¢¤³¤Î¤è¤¦¤Ê¥Õ¥é¥°ÀßÄ꤬ɽ¼¨¤µ¤ì¤Þ¤¹¡£
flag
¡ÖÍ­¸ú¤Ë¤¹¤ë¡×¤ò¥¯¥ê¥Ã¥¯¤·¡¢»Ø¼¨¤Ë½¾¤Ã¤Æ¥Ö¥é¥¦¥¶¤òºÆµ¯Æ°¤·¤Þ¤¹¡£¤¹¤ë¤È¡¢HTTPS¥µ¥¤¥È¤òɽ¼¨¤·¤¿¾ì¹ç¤³¤Î¤è¤¦¤Ë
after
¡Ö¾ÚÌÀ½ñ¡¢Í­¸ú¡×¤È¤¤¤¦¥ê¥ó¥¯¤¬É½¼¨¤µ¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¡¢¥¯¥ê¥Ã¥¯¤¹¤ë¤È¾ÚÌÀ½ñ¤¬É½¼¨¤µ¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£¤¤¤ä¡Á¡Á¡¢¤è¤«¤Ã¤¿¡¢¤è¤«¤Ã¤¿¡£
52

Gmail¥¢¥«¥¦¥ó¥È¤ÇS/MIME ½ð̾/°Å¹æ¥á¡¼¥ë¤ò»È¤¦(¤½¤Î1 iOSɸ½à¥á¡¼¥é¡¼ÊÔ)

¤È¤¢¤ëƿ̾¤Î¿Â»Î¤¬¤´¸ü°Õ¤Ç¡¢JCAN¤ÎS/MIME¾ÚÌÀ½ñ¤ò¤ï¤¿¤·¤ÎGmail¤Î¥¢¥É¥ì¥¹¤Ëȯ¹Ô¤·¤Æ¤¯¤À¤µ¤ê¡¢iOS¤Îɸ½à¥á¡¼¥é¡¼¤ÎGmail¥¢¥«¥¦¥ó¥È¤«¤éS/MIME½ð̾/°Å¹æ¥á¡¼¥ë¤¬Á÷¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿¡£ docomo¥¢¥«¥¦¥ó¥È¤Î¥á¡¼¥ë¤ÏS/MIME»È¤¨¤Ê¤¤¤Î¤ÇÅϤê¤ËÁ¥¤Ç¤·¤¿¡£(ƿ̾¤Î½Ê½÷¤«¤é¤¤¤¿¤À¤¤¤Æ¤¤¤¿S/MIME¾ÚÌÀ½ñ¤Ï¤È¤Ã¤¯¤Ë´ü¸ÂÀÚ¤ì¤Ë¤Ê¤êº¤¤Ã¤Æ¤¤¤Þ¤·¤¿¡£)

¡Ö¥Ö¥í¥°¤Ë½ñ¤¤¤Æ²¼¤µ¤¤¤è¡Á¡Á¡Á¡×¤È¤½¤Î¿Â»Î¤Ë¸À¤ï¤ì¤Æ¤¤¤¿¤Î¤Ç¡¢¤Á¤ç¤Ã¤È½ñ¤¤¤Æ¤ß¤¿¤¤¤È»×¤¤¤Þ¤¹¡£

¤³¤³¤Ë½ñ¤¤¤Æ¤¢¤ë¤Î¤Ï¡¢JCAN¾ÚÌÀ½ñ¤Ë¸Â¤Ã¤¿ÏäǤϤʤ¤¤Î¤Ç¡¢iOSɸ½à¥á¡¼¥é¡¼¤ÎǤ°Õ¤Î¥¢¥«¥¦¥ó¥È¸þ¤±¤Î¾ÚÌÀ½ñ¤Ç»È¤¨¤ëÏäǤ¹¡£¸½»þÅÀ¤ÇºÇ¿·¤ÎiOS 10.3.2¤Ç»î¤·¤Þ¤·¤¿¡£

­¡¤Þ¤º¤Ï¼«Ê¬¤ÎS/MIME¾ÚÌÀ½ñ¤Î¥¤¥ó¥¹¥È¡¼¥ë

ȯ¹Ô¤µ¤ì¤¿¾ÚÌÀ½ñ¤ÈÈëÌ©¸°¤Î¥Õ¥¡¥¤¥ë¤Ç¤¢¤ë¡Ö*.p12¡×¤ä¡Ö*.pfx¡×¤òźÉÕ¥Õ¥¡¥¤¥ë¤Ë¤·¤ÆiOSɸ½à¥á¡¼¥é¡¼¤Î¥¢¥«¥¦¥ó¥È¤ËÁ÷¤ê¡¢ÅºÉÕ¥Õ¥¡¥¤¥ë¤ò³«¤­¤Þ¤¹¡£
IMG_2600m
ɽ¼¨¤µ¤ì¤Æ¤¤¤ë¡Ö¥¤¥ó¥¹¥È¡¼¥ë¡×¤Î¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤·¡¢iOS¤Î¥í¥Ã¥¯²ò½ü¥Ñ¥¹¥³¡¼¥É¤òÆþÎϤ·¡¢Â³¤¤¤Æ *.p12 ¤Þ¤¿¤Ï *.pfx ¥Õ¥¡¥¤¥ë¤Î¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ¹¤ì¤Ð¾ÚÌÀ½ñ¤¬¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤Þ¤¹¡£
IMG_2601m

­¢¼¡¤ËGmail¥¢¥«¥¦¥ó¥È¤Ø¤ÎS/MIME¾ÚÌÀ½ñ¤ÎÀßÄê

¼¡¤Ë¡¢iOS¤Îɸ½à¥á¡¼¥é¡¼¤«¤éGmail¤Î¥¢¥«¥¦¥ó¥È¤ÇS/MIME½ð̾¥á¡¼¥ë¤òÁ÷¤ì¤ë¤è¤¦¤Ë¡¢¾ÚÌÀ½ñ(¤È¸°)¤ÎÀßÄê¤ò¤·¤Þ¤¹¡£¡ÖÀßÄê¡ä¥á¡¼¥ë¡ä¥¢¥«¥¦¥ó¥È¡äGmail¡ä¥¢¥«¥¦¥ó¥È¡ä¾ÜºÙ¡×¤Î°ìÈÖ²¼¤ÎÊý¤ËS/MIME¤ÎÀßÄ꤬¤¢¤ê¤Þ¤¹¡£S/MIME¤ò¥ª¥ó¤Ë¤·¤Æ¡Ö½ð̾¡×¤ò³«¤­¡¢
IMG_2602m
¡Ö½ð̾¡×¤ò¥ª¥ó¤Ë¤·¤Æ¾ÚÌÀ½ñ¤òÁªÂò¤·¤Þ¤¹¡£JCAN¤«¤é¤Î¾ÚÌÀ½ñ¤Ï¡ÖBN-±Ñ¸ì»á̾¡×¤È¤Ê¤Ã¤Æ¤¤¤ë¤È»×¤¤¤Þ¤¹¡£
IMG_2603m
¤³¤Î»þÅÀ¤Ç¤Ï¡Ö¥Ç¥Õ¥©¥ë¥È¤Ç°Å¹æ²½¡×¤Ï¡Ö¤¤¤¤¤¨¡×¤Î¤Þ¤Þ¤¬¤¤¤¤¤Ç¤¹¡£

­£iOSɸ½à¥á¡¼¥é¡¼¤«¤éS/MIME½ð̾¥á¡¼¥ë¤òÁ÷¤Ã¤Æ¤ß¤ë

iOSɸ½à¥á¡¼¥é¡¼¤«¤éGmail¥¢¥«¥¦¥ó¥È¤òÁª¤ó¤Ç¿·µ¬¥á¡¼¥ë¤òÁ÷¤Ã¤Æ¤ß¤Þ¤·¤ç¤¦¡£
IMG_2604m
°¸À褬¶õÍó¤Î»þ¤Ë¤Ï¡¢¾ûÁ°¥¢¥¤¥³¥ó¤Ï¡Ö¥°¥ì¡¼¤Ç³«¤¤¤¿¡×¾õÂ֤Ǥ¹¡£¾ûÁ°¤¬³«¤¤¤Æ¤¤¤ë¾õÂ֤ϡÖÁê¼ê¤ËÂФ·¤Æ°Å¹æ²½¤·¤Þ¤»¤ó¤è¡×¤È¤¤¤¦°ÕÌ£¤Ç¤¹¡£¤Þ¤¿¡¢¥°¥ì¡¼¤Î¾ûÁ°¤¬¤¢¤ë¾õÂ֤ϡÖS/MIME¤¬ÍøÍѲÄǽ¡×¤Ê¾õÂ֤ˤ¢¤ë¤È¤¤¤¦¤³¤È¤Ç¤¹¡£¼¡¤Ë¡¢S/MIME½ð̾¥á¡¼¥ë¤òÁ÷¤ê¤¿¤¤Áê¼ê¤òÁª¤ó¤Ç¤ß¤Þ¤·¤ç¤¦¡£
IMG_2606m
ÀĤ¤¾ûÁ°¤¬³«¤¤¤Æ¤¤¤ë¾õÂ֤ϡ֥᡼¥ë¤ÎÁ÷¿®¤¬²Äǽ¤Ç¡¢Áê¼ê¤Ë¤ÏS/MIME°Å¹æ²½¤ò¤·¤Ê¤¤¡×¤È¤¤¤¦¤³¤È¤ò°ÕÌ£¤·¤Æ¤¤¤Þ¤¹¡£½é´ü¾õÂ֤ǤÏÁê¼ê¤Î¾ÚÌÀ½ñ¤ò¤â¤é¤Ã¤Æ¤¤¤Ê¤¤¤Î¤Ç¡¢°Å¹æ²½¤Ç¤­¤Ê¤¤¤Î¤ÏÅöÁ³¤Ç¤¹¡£¤³¤³¤Ç¡¢ÌµÍý¤ä¤ê¡Ö³«¤¤¤¿ÀĤ¤¾ûÁ°¡×¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¤ß¤Þ¤·¤ç¤¦¡£
IMG_2607m
Áê¼ê¤Î¾ÚÌÀ½ñ¤ò»ý¤Ã¤Æ¤¤¤Ê¤¤¤Î¤Ç¡¢°¸À褬ÀÖ¤¯¤Ê¤ê¡ÖÀÖ¤¤¾ûÁ°¡×¤Î¥¢¥¤¥³¥ó¤Ë¤Ê¤ê¡Ö°Å¹æ²½¤Ç¤­¤Þ¤»¤ó¡×¤Èɽ¼¨¤µ¤ì¤Þ¤¹¡£¤â¤¦°ìÅÙ¥¯¥ê¥Ã¥¯¤·¤ÆÀĤËÌᤷ¡¢Á÷¿®¤·¤Æ¤ß¤Æ¤¯¤À¤µ¤¤¡£

­¤Á÷¤é¤ì¤Æ¤­¤¿½ð̾¥á¡¼¥ë¤ò¼õ¤±¤Æ¤ß¤ë

iOS¤Î¥á¡¼¥é¡¼¤«¤éÁ÷¤é¤ì¤Æ¤­¤¿¥á¡¼¥ë¤òS/MIMEÂбþ¤Î¥á¡¼¥é¡¼¡¢Î㤨¤ÐOutlook¤Ç¸«¤Æ¤ß¤Þ¤·¤ç¤¦¡£
zzz01m

­¥¥Ñ¥½¥³¥ó¥æ¡¼¥¶¤ÎS/MIME½ð̾¥á¡¼¥ë¤«¤é¾ÚÌÀ½ñ¤òÅÐÏ¿¤¹¤ë

iPhone¤«¤é°Å¹æ¥á¡¼¥ë¤Þ¤¿¤Ï¡¢½ð̾°Å¹æ¥á¡¼¥ë¤òÁ÷¤ë¾ì¹ç¤Ë¤Ï¡¢iOS¤Îɸ½à¥á¡¼¥é¡¼¤ÎS/MIME´Ø·¸¤ÎÍøÍÑÊýË¡¤Ï¤¤¤í¤¤¤í¥¤¥Þ¥¤¥Á¤ÊÌ̤¬Â¿¤¤¤Ç¤¹¤¬¡¢½ð̾¥á¡¼¥ë¤Ëñ½ã¤ËÊÖ¿®¤¹¤ë·Á¤Ç¤ÏÁ÷¤ì¤º¡¢iPhone¤Ç¤ÎÁê¼ê¾ÚÌÀ½ñ¤Î»öÁ°ÅÐÏ¿¤¬É¬ÍפǤ¹¡£¤³¤³¤Ç¤Ï¡¢¤½¤Î¡ÖÁê¼ê¤Î¾ÚÌÀ½ñ¡×¤ÎÅÐÏ¿ÊýË¡¤ò¾Ò²ð¤·¤Þ¤¹¡£

¤Þ¤º¡¢Á÷¤é¤ì¤Æ¤­¤¿½ð̾¥á¡¼¥ë¤ò³«¤­¤Þ¤¹¡£
IMG_2606m
ÀĤ¤¾ûÁ°¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¤â¡¢¾ÚÌÀ½ñ¤¬Ìµ¤¤¤Î¤ÇÀÖ¤¯¤Ê¤ë¤À¤±¤Ê¤Î¤Ç¡¢¤â¤¦°ìÅÙ¥¿¥Ã¥Á¤·¤ÆÀĤˤʤë¤è¤¦¤ËÌᤷ¤Þ¤¹¡£
IMG_2607m
¤Á¤Ê¤ß¤Ë¡¢Á÷¤é¤ì¤Æ¤­¤¿¥á¡¼¥ë¤¬½ð̾°Å¹æ¥á¡¼¥ë¤À¤È¡¢°Ê²¼¤Î¤è¤¦¤Ë¥Ð¥Ã¥¸(½ð̾)¤È¾ûÁ°(°Å¹æ²½)¤Î2¤Ä¤Î¥¢¥¤¥³¥ó¤Ä¤­¤Þ¤¹¡£
IMG_2609m
¤Á¤Ê¤ß¤Ë¡¢¤³¤Î¥á¡¼¥ë¤òiPhone¤Îɸ½à¥á¡¼¥é¡¼¤Ç¤Ï¤Ê¤¯¡¢Gmail¤Î¥¦¥§¥Ö¥¢¥×¥ê¤Ç¸«¤Æ¤ß¤ë¤È°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£smime.p7m¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤¬ÅºÉÕ¤µ¤ì¤Æ¤¤¤ë¤À¤±¤Ç¡¢°Å¹æ²½¤µ¤ì¤Æ¤ª¤ê¡¢¥Ð¥¤¥Ê¥ê¥Õ¥¡¥¤¥ë¤ò¸«¤Æ¤âÆâÍÆ¤Ï¤ï¤«¤é¤Ê¤¤¤Ç¤·¤ç¤¦¡£(¤½¤Î¤¦¤Á¡¢¤³¤ÎÃæ¿È¤Î¥Ð¥¤¥Ê¥ê¥Õ¥¡¥¤¥ë¤Î·Á¼°¤Ë¤Ä¤¤¤Æ½Ò¤Ù¤ë¤³¤È¤â¤¢¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£) Google¤Ë¤â¥á¡¼¥ë¤ÎÆâÍÆ¤òÃΤé¤ì¤ë¤³¤È¤Ê¤¯¡¢°Â¿´¤Ç¤¹¤Í¡£
¥¹¥¯¥ê¡¼¥ó¥·¥ç¥Ã¥È 2017-06-09 22m
¤½¤³¤Ç¡¢Áê¼ê¤Î¥¢¥É¥ì¥¹¤ò¥¿¥Ã¥Á¤¹¤ë¤È¡¢Áê¼ê¤ÎÏ¢ÍíÀ褬ɽ¼¨¤µ¤ì¡¢¾ÚÌÀ½ñ¤Ë´Ø¤¹¤ëµ­½Ò¤â½ñ¤«¤ì¤Æ¤¤¤Þ¤¹¡£
IMG_2597m
¡Ö¾ÚÌÀ½ñ¤òɽ¼¨¡×¤Î¥ê¥ó¥¯¤ò¥¿¥Ã¥Á¤¹¤ë¤È¡¢Áê¼ê¤Î¾ÚÌÀ½ñ¤¬É½¼¨¤µ¤ì¤Þ¤¹¤Î¤Ç¡¢¡Ö¾ÜºÙ¡×¤òɽ¼¨¤Ê¤É¤·¤Æ¡¢ÆâÍÆ¤ò¤¶¤Ã¤È³Îǧ¤·¤Æ¡Ö¥¤¥ó¥¹¥È¡¼¥ë¡×¤ò¥¿¥Ã¥Á¤¹¤ë¤È¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤Þ¤¹¡£
IMG_2598m
IMG_2610m
°Ê¾å¤ÇÁ÷¿®Àè¤Î¾ÚÌÀ½ñ¤òÅÐÏ¿¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤·¤¿¡£

­¦iPhone¤«¤éS/MIME½ð̾°Å¹æ¥á¡¼¥ë¤òÁ÷¤ë

Àè¤Û¤É¾ÚÌÀ½ñ¤òÅÐÏ¿¤·¤¿¿Í¤Ë¿·µ¬¤Ë¥á¡¼¥ë¤òÁ÷¤Ã¤Æ¤ß¤Þ¤¹¡£°¸Àè¤Ë¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ¹¤ë¤È¡¢ºÇ½é¤ÏÀĤ¤¾ûÁ°¤Ï³«¤¤¤Æ¤¤¤ë¾õÂ֤Ǥ¹¡£
IMG_2613m
ÀĤ¤¾ûÁ°¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¡¢Ìµ»ö¡Ö°Å¹æ²½ºÑ¤ß¡×¤Èɽ¼¨¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤¢¤È¤ÏÁ÷¿®¥Ü¥¿¥ó¤ò²¡¤¹¤À¤±¤Ç¤¹¡£
IMG_2614m
¥Ñ¥½¥³¥ó¤ÎOutlook¤Ç¼õ¤±¼è¤Ã¤Æ¤ß¤ë¤È̵»ö¡¢½ð̾°Å¹æ²½¥á¡¼¥ë¤ò¸«¤ë¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£
zzz07m

¤ª¤ï¤ê¤Ë

°Ê¾å¡¢JCAN¤ÎS/MIME¾ÚÌÀ½ñ¤ò¤¤¤¿¤À¤¤¤¿¤Î¤Ç¡¢iPhoneɸ½à¥á¡¼¥é¡¼¤ÎGmail¥¢¥«¥¦¥ó¥È¤ËÀßÄꤷ¡¢ ½ð̾°Å¹æ¥á¡¼¥ë¤òÁ÷¼õ¿®¤·¤Æ¤ß¤Þ¤·¤¿¡£ ¤¹¤³¤·¡¢ÅÐÏ¿¤Ê¤É¤Þ¤É¤í¤Ã¤³¤·¤¤½ê¤â¤¢¤ë¤ó¤Ç¤¹¤¬¡¢Android¤Ç¤Ï¤Þ¤È¤â¤ÊS/MIME¥á¡¼¥é¡¼¤Ï̵¤¤¤Î¤Ç¡¢ iPhone¤Îɸ½à¥á¡¼¥é¡¼¤ÏS/MIME¤ò¡Ö¤Á¤ã¤ó¤È¡×»È¤¨¤ÆÂ礷¤¿¤â¤ó¤À¤Ê¤¡¡¢¡¢¡¢¤È»×¤¤¤Þ¤¹¡£ º£²ó¤Î¾ÚÌÀ½ñ¤ÏJCAN¤µ¤ó¤Î¤Ç¤·¤¿¤¬¡¢±Ñ¸ì¤Î¿½ÀÁ¤¬µ¤¤Ë¤Ê¤é¤Ê¤±¤ì¤ÐCOMODO¤«¤é¤â ̵ÎÁ¤ÎS/MIME¾ÚÌÀ½ñ¤òȯ¹Ô¤·¤Æ¤â¤é¤¨¤Þ¤¹¡£¤è¤«¤Ã¤¿¤é¥È¥é¥¤¤·¤Æ¤ß¤Æ¤¯¤À¤µ¤¤¡£

¤³¤ì¤Ç¡¢Google¤Ï¥æ¡¼¥¶¡¼¤Î¥á¡¼¥ë¤ÎÆâÍÆ¤ò´Æ»ë¤·¤Æ¤¤¤¿¤ê¤¹¤ë¤ó¤Ç¤·¤ç¤¦¤¬¡¢°Â¿´¤·¤Æ¥à¥Õ¥Õ¤Ê¥á¡¼¥ë¤Î¤ä¤ê¼è¤ê¤ò¾¤Î¿Í¤Ë¤Ï·è¤·¤Æ¤ß¤é¤ì¤ë¤³¤È¤Ê¤¯Á÷¤ì¤ë¤ï¤±¤Ç¤¹¡£¤¤¤ä¡Á¡Á¡¢ÁÇÀ²¤é¤·¤¤¤Ç¤¹¤Í¡£

Gmail¥¢¥«¥¦¥ó¥ÈÍѤÎS/MIME¾ÚÌÀ½ñ¤òÍߤ·¤«¤Ã¤¿¤Î¤Ï¡¢¼Â¤Ï Google¤ÎG-Suite Enterprise¤Ç¤Ï¥µ¡¼¥Ð¡¼¤ËÈëÌ©¸°¤È¾ÚÌÀ½ñ¤òÀßÄꤷ¤Æ ¥¯¥é¥¦¥É·¿¤ÇS/MIME¤Î½ð̾°Å¹æ¥á¡¼¥ë¤¬»È¤¨¤ë¤½¤¦¤Ç¡¢¤½¤ì¤ò»È¤Ã¤Æ¤ß¤¿¤«¤Ã¤¿¤È¤¤¤¦¤Î¤¬ ¤¢¤ê¤Þ¤¹¡£ºÇ¶á¡¢¥¤¥ó¥·¥Ç¥ó¥ÈÂбþ¤ËÄɤï¤ì¤Æ¤Ê¤«¤Ê¤«»þ´Ö¤¬¼è¤ì¤Ê¤¤¤ó¤Ç¤¹¤¬¡¢ ¤Ê¤ó¤È¤«»þ´Öºî¤Ã¤Æ»î¤·¤¿¤¤¤Ê¤¡¤È»×¤Ã¤Æ¤¤¤Þ¤¹¡£ ¤Ç¤Ï¤Ç¤Ï¡£

´ØÏ¢µ­»ö

SSL Pulse¤ÎÅý·×¾ðÊó¤Ç¸«¤ëSSL/TLS (2015ǯ12·îÈÇ)

¤¤¤ä¤¡¡¢Ç¯¤ÎÀ¥¤Ç¤¹¤Í¤§¡£ºÇ¶á¡¢SSL/TLS´ØÏ¢¤ÎÄ´ºº¤ËÁ´¤¯»þ´Ö¤¬¼è¤ì¤Æ¤Ê¤¤¤Ã¤¹¡£ SSL Pulse¥µ¥¤¥È(https://www.trustworthyinternet.org/ssl-pulse/)¤Ï¡¢ ssllabs¤Ç¤âͭ̾¤ÊQualys¼Ò¤¬±¿±Ä¤·¤Æ¤¤¤ë¥µ¥¤¥È¤Ç¡¢ Web¥µ¥¤¥ÈÄ´ºº¤ÎAlexa¼Ò¤Ë¤è¤ë À¤³¦¤Î¥¢¥¯¥»¥¹¥È¥Ã¥×20Ëü¥µ¥¤¥È¤òÂоݤËSSL´Ø·¸¤ÎÅý·×¾ðÊó¤òËè·î¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£ 10·î¤Ë°ú¤­Â³¤­2015ǯ12·î¤ÎSSL Pulse¤Ç¤ÎSSL/TLS¤Î¾õ¶·¿ä°Ü¤ò¥°¥é¥Õ²½¤·¤Þ¤·¤ç¤¦¡£ º£·î¤Ï¡¢¤Ê¤«¤Ê¤«¥Ç¡¼¥¿¸ø³«¤¬Áᤫ¤Ã¤¿¤Ã¤Ý¤¤¤Ç¤¹¤¬¡¢µ¤¤Å¤¯¤Î¤ËÃÙ¤ì¤Þ¤·¤¿¡£

ÀȼåÀ­Âбþ¤Î¿ä°Ü


201512-a1vuln

SSL/TLS¥×¥í¥È¥³¥ë¤Î¿ä°Ü


201512-a2proto

SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Î¸°Ä¹¡¢½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î¿ä°Ü


201512-a3crt

¿·¤·¤¤µ»½Ñ¤Î¥µ¥Ý¡¼¥È¤Î¿ä°Ü


201512-a4adv
SPDY¤¬²¼¤¬¤Ã¤Æ¤¤¤Þ¤¹¡£HTTP/2¤Ø¤Î°Ü¹Ô¤¬»Ï¤Þ¤Ã¤Æ¤¤¤Þ¤¹¡£¼Â¤ÏSSL Pulse¤ÇHTTP/2¤ÎÂбþ¾õ¶·¤â4¥ö·îÁ°¤¢¤¿¤ê¤«¤é¼è¤ì¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢¤½¤í¤½¤í²Ä»ë²½¤·¤¿¤¤¤È»×¤Ã¤Æ¤¤¤Þ¤¹¡£

¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201512-a5kx

DH(E)¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201512-a6dh
DH¸°¸ò´¹¤Î¥µ¥Ý¡¼¥ÈΨ¤Ï¡¢¤Û¤Ü²£¤Ð¤¤¤Ç¤¢¤ë¤Î¤ËÂФ·¤Æ¡¢

ECDH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201512-a7ecdh
ECDH(E)¤Ø¤ÎÂбþ¤Ï¿Ê¤ó¤Ç¤¤¤ë¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£

¤ª¤ï¤ê¤Ë

ǯËö¿Ê¹Ô¤Ç¡¢¤½¤ó¤Ê¤ËÆÝ¤ß¤Ë¹Ô¤Ã¤Æ¤¤¤ëµ¤¤â¤·¤Þ¤»¤ó¤¬¡¢¤Ê¤ó¤«»Å»ö¤¬»³ÀѤߤǤ¹orz ¥³¥á¥ó¥È¾¯¤Ê¤á¤Ç¤¹¤ß¤Þ¤»¤ó¡£º£·î¤Ï¤³¤ÎÊդǡ£

´ØÏ¢µ­»ö

SSL Pulse¤ÎÅý·×¾ðÊó¤Ç¸«¤ëSSL/TLS (2015ǯ10·îÈÇ)

SSL Pulse¥µ¥¤¥È(https://www.trustworthyinternet.org/ssl-pulse/)¤Ï¡¢ ssllabs¤Ç¤âͭ̾¤ÊQualys¼Ò¤¬±¿±Ä¤·¤Æ¤¤¤ë¥µ¥¤¥È¤Ç¡¢ Web¥µ¥¤¥ÈÄ´ºº¤ÎAlexa¼Ò¤Ë¤è¤ë À¤³¦¤Î¥¢¥¯¥»¥¹¥È¥Ã¥×20Ëü¥µ¥¤¥È¤òÂоݤËSSL´Ø·¸¤ÎÅý·×¾ðÊó¤òËè·î¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£ 8·î¤Ë°ú¤­Â³¤­2015ǯ10·î¤ÎSSL Pulse¤Ç¤ÎSSL/TLS¤Î¾õ¶·¿ä°Ü¤ò¥°¥é¥Õ²½¤·¤Þ¤·¤ç¤¦¡£ º£·î¤Ï¡¢¤Ê¤«¤Ê¤«¥Ç¡¼¥¿¸ø³«¤·¤Æ¤¯¤ì¤Ê¤¯¤Æ¡¢³Î¤«10·î19Æüº¢¤è¤¦¤ä¤¯¥¢¥Ã¥×¥Ç¡¼¥È¤µ¤ì¤¿¤è¤¦¤Ç¤¹¡£¿·¤·¤¤¹àÌÜÁý¤¨¤Æ¤¤¤ë¤ï¤±¤Ç¤â¤Ê¤¤¤Î¤Ë¡¢¤Ê¤ó¤Ç¤Ç¤·¤ç¤¦¤Í¡£

ÀȼåÀ­Âбþ¤Î¿ä°Ü


201510vuln
RC4¤ÎÍøÍѲÄǽΨ¤¬½çÄ´¤Ë·Ñ³¤·¤Æ²¼¤¬¤Ã¤Æ¤ª¤ê¡¢º£·î¤Ç¤Ï53%¤Î¥µ¥¤¥È¤·¤«»È¤¨¤Ê¤¯¤Ê¤ê¤Þ¤·¤¿¡£ ¤Þ¤¿¡¢ECDHE¤äDHE¤Î¸°¸ò´¹¤ò¥µ¥Ý¡¼¥È¤¹¤ëPFS¤ËÂбþ¤·¤¿¥µ¥¤¥È¤Ï71.5%¤Ë¤Þ¤Ç¾å¤¬¤Ã¤Æ¤ª¤ê¡¢¤«¤Ê¤ê¤Î¥µ¡¼¥Ð¡¼¤Ç»È¤¨¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤­¤Þ¤·¤¿¡£

SSL/TLS¥×¥í¥È¥³¥ë¤Î¿ä°Ü


201510proto
POODLE¤Î±Æ¶Á¤ÇSSLv3¤¬»È¤¨¤ë¥µ¥¤¥È¤¬32.5%¤Ë¤Þ¤Ç²¼¤¬¤Ã¤Æ¤¤¤Þ¤¹¡£

SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Î¸°Ä¹¡¢½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î¿ä°Ü


201510crt
Google Chrome¤äWindowsÀ½ÉʤÎSHA1¾ÚÌÀ½ñ¤Î¥¢¥é¡¼¥ÈÂбþ¤ò¼õ¤±¤Æ¡¢º£·î¤â½çÄ´¤ËSHA2°Ü¹Ô¤¬¿Ê¤ó¤Ç¤ª¤êSHA1withRSA¤¬24.1%¡¢SHA256withRSA¤¬74.9%¤Þ¤Ç¿Ê¤ó¤Ç¤¤¤Þ¤¹¡£¤¢¤È»Ä¤ê1/4¤Ë¤Ê¤ê¤Þ¤·¤¿¤Í¡Á¡Á¡Á¡£

¿·¤·¤¤µ»½Ñ¤Î¥µ¥Ý¡¼¥È¤Î¿ä°Ü


201510adv
HSTS¤â¡¢OCSP Stapling¤â¡¢EV¤â½ù¡¹¤Ë¾å¤¬¤Ã¤Æ¤¤¤Þ¤¹¤¬¡¢Á´¤¯Â礷¤¿¤³¤È¤Ê¤¤¡£

¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201510kx
¸°¸ò´¹¤Î¸°Ä¹¤Ï½çÄ´¤Ë¡¢512bit¡¢1024bit¤ÎÍøÍѤò¤ä¤á¡¢2048bitÁêÅö¤Ë°Ü¹Ô¤¬¿Ê¤ó¤Ç¤¤¤ë¤è¤¦¤Ç¤¹¤¬¡¢¡¢¡¢

DH(E)¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201510dh
DH¸°¸ò´¹¤ò¥µ¥Ý¡¼¥È¤·¤Ê¤¤¥µ¥¤¥È¤¬48.2%¤â¤¢¤ê¡¢°Å¹æ¶¯ÅÙ¤¬½½Ê¬¤Ç¤Ê¤¤DH1024bit¤â¸º¤Ã¤Æ¤Ï¤¤¤ë¤â¤Î¤Î¡¢28.9%¤â¤¢¤ê¡¢¤¤¤í¤ó¤Ê°Õ¸«¤Ï¤¢¤ë¤Ç¤·¤ç¤¦¤¬¡¢DH(E)¤Ï»È¤ï¤º¤ËECDH(E)¤ò»È¤¦¤Î¤¬Îɤ¤¤Î¤Ç¤Ï¤È»×¤¤¤Þ¤¹¡£

ECDH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201510ecdh
ECDH/ECDHE¤¬»È¤¨¤Æ¤¤¤Ê¤¤¥µ¥¤¥È¤¬34.2%¤Ë¤Þ¤Ç¸º¤ê¡¢ECC 256bit¤ò»È¤¨¤ë¥µ¥¤¥È¤¬61.9%¤Ë¤Þ¤ÇÁý¤¨¤Æ¤¤¤Þ¤¹¡£¤«¤Ê¤êÉáµÚ¤·¤Æ¤­¤¿¤È¤¤¤¦´¶¤¬¤¢¤ê¡¢¡Ö²¿¤â¹Í¤¨¤º¤Ë¤È¤ê¤¢¤¨¤ºECDHE»È¤¨¤ë¤è¤¦¤Ë¤·¤È¤±¡ª¡×¤È»×¤¤¤Þ¤¹¡£

¤ª¤ï¤ê¤Ë

¹Ö±é»ñÎÁ2Ëܺî¤é¤Ê¤¤¤È¥Þ¥¸¤Ç¤ä¤Ð¤¹¡£º£Æü¤Ï¤³¤ÎÊդǡ£

´ØÏ¢µ­»ö

Deep Inside Certificate Transparency (¤½¤Î1)

Certificate Transparency(°Ê²¼CT)¤Ë¤Ï¿§¡¹ÌäÂ꤬¤¢¤Ã¤Æ²¿¤À¤«¤Ê¡Á¡Á¡Á¤È»×¤Ã¤Æ¤¤¤ë¤ï¤±¤Ç¤¹¤¬¡¢»³¤¬¤½¤³¤Ë¤¢¤Ã¤¿¤é¡¢ÅФꤿ¤¯¤Ê¤ë¤Î¤â¤Þ¤¿¿Í¾ð¡Ê¡°¡°¡¨ CT¥í¥°¥µ¡¼¥Ð¡¼¤ä³ÊǼ¤µ¤ì¤Æ¤¤¤ë¥Ç¡¼¥¿¤Ë¤Ä¤¤¤Æ¡¢¤¤¤í¤ó¤Ê¥Ä¡¼¥ë¤òºî¤ê¤Ê¤¬¤éÄ´ºº¤ò¤·¤Æ¤¤¤Þ¤¹¡£²¿²ó¤«¤Ëʬ¤±¤Æ¡¢CT¤Ë¤Ä¤¤¤Æ¤ï¤«¤Ã¤¿¤³¤È¤ò½ñ¤¤¤Æ¤¤¤³¤¦¤È»×¤Ã¤Æ¤Þ¤¹¡£

¥×¥ì¾ÚÌÀ½ñ¤Ë¤Ä¤¤¤Æ

CT¤ËÂбþ¤·¤Æ¤¤¤ë¤³¤È¤ò¼¨¤¹¤¿¤á¤Ë¡¢´ö¤Ä¤«ÊýË¡¤Ï¤¢¤ë¤Î¤Ç¤¹¤¬¡¢¼ÂºÝ¤ËÍ­¸ú¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ïȯ¹Ô¤¹¤ë¾ÚÌÀ½ñ¤ËSigning Time Stamp(SCT)³ÈÄ¥¤òËä¤á¹þ¤à¤³¤È¤Ç¤¹¡£TLS¤Î³ÈÄ¥¤äOCSP¤È¤Ä¤¤¤Ç¤ËÅϤ¹¤È¤¤¤¦ÊýË¡¤Î¼ÂÁõ¤ò¸«¤¿¤³¤È¤¬¤¢¤ê¤Þ¤»¤ó¡£

SCT³ÈÄ¥¤ò´Þ¤á¤ë¤¿¤á¤Ë¤Ï¥×¥ì¾ÚÌÀ½ñ¤Ê¤ë¾ÚÌÀ½ñ¤¬É¬Íפˤʤë¤ó¤Ç¤¹¤¬¡¢¥×¥ì¾ÚÌÀ½ñ¤¬¤É¤ó¤Ê¤â¤Î¤«¡¢¤É¤ó¤Ê¥Õ¥í¡¼¤Çȯ¹Ô¤µ¤ì¤ë¤Î¤«¤Ï¤³¤Î¥¹¥é¥¤¥É¤ÇÀâÌÀ¤·¤Æ¤¤¤Þ¤¹¡£DigiCert¤µ¤ó¤Î´ö¤Ä¤«¤Î¥Ú¡¼¥¸¤Ç¤â¥×¥ì¾ÚÌÀ½ñ¤Ë¤Ä¤¤¤Æ²òÀ⤵¤ì¤Æ¤¤¤ë¤Î¤Ç¤è¤«¤Ã¤¿¤é¤´Í÷¤¯¤À¤µ¤¤¡£ [1] [2] [3]

¤³¤ì¤Þ¤Ç¤ËCT¤Î»ÅÁȤߤ¬Æ³Æþ¤µ¤ì¤ëÁ°¤Î¾ÚÌÀ½ñ¡¢CT¤ËÂбþ¤¹¤ëͽÄê¤Î¤Ê¤«¤Ã¤¿¾ÚÌÀ½ñ¤Ë´Ø¤·¤Æ¤ÏCT¤Î¥í¥°¥µ¡¼¥Ð¡¼¤ËÉáÄ̤ËX.509¾ÚÌÀ½ñ¤Î¥Á¥§¡¼¥ó¤¬³ÊǼ¤µ¤ì¤ë¤ó¤Ç¤¹¤¬¡¢CT¤Ë¤Þ¤È¤â¤ËÂбþ¤·¤è¤¦¤È¤·¤Æ¤¤¤ë¥Ù¥ó¥À¡¼¤Î¾ÚÌÀ½ñ¤Ï¡¢¥×¥ì¾ÚÌÀ½ñ¤Î¥Á¥§¡¼¥ó¤¬³ÊǼ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£Chrome¤Ç¡Ö¸ø³«´Æºº¾ðÊ󤬤¢¤ê¤Þ¤¹¡×¤Èɽ¼¨¤µ¤ì¤ë¤â¤Î¤Ë¤Ä¤¤¤Æ¤â¡¢¥×¥ì¾ÚÌÀ½ñ¥Ù¡¼¥¹¤ÎSCT³ÈÄ¥¤¬X.509¾ÚÌÀ½ñ¤Ë´Þ¤Þ¤ì¤Æ¤¤¤ë¤â¤Î¤·¤«¡¢¤³¤Î¤è¤¦¤Ëɽ¼¨¤µ¤ì¤Ê¤¤¤È»×¤¤¤Þ¤¹¡£

º£Æü¤Î»þÅÀ¤Ç¡¢Google pilot¤ÎCT¥í¥°¥µ¡¼¥Ð¡¼¤Ë¤ÏÌó670Ëü¤Î¾ÚÌÀ½ñ¥Á¥§¡¼¥ó¤¬ÅÐÏ¿¤µ¤ì¤Æ¤¤¤Þ¤¹¤¬¡¢¤½¤Î¤¦¤Á¥×¥ì¾ÚÌÀ½ñ¤È¤·¤ÆÅÐÏ¿¤µ¤ì¤Æ¤¤¤ë¤â¤Î(=Chrome¤Ç¸ø³«´Æºº¤¢¤ê¤Èɽ¼¨¤µ¤ì¤ë¤â¤Î)¤Ï16ËüËçʬ¤·¤«¤¢¤ê¤Þ¤»¤ó¡£

¥×¥ì¾ÚÌÀ½ñ¤Îȯ¹ÔËç¿ô¿ä°Ü

Google pilot¥í¥°¥µ¡¼¥Ð¡¼¤Ø¤Î¥¨¥ó¥È¥ê¤ÎÅÐÏ¿¼«ÂΤÏ2013ǯ3·î26Æü¤«¤é¡¢´û¸¤Î¾ÚÌÀ½ñ(¥Ñ¥¹)¤Ë¤Ä¤¤¤ÆÅÐÏ¿¤¬³«»Ï¤µ¤ì¤Æ¤¤¤Þ¤¹¤¬¡¢CTƳÆþ°Ê¹ß¤Î¥×¥ì¾ÚÌÀ½ñȯ¹ÔËç¿ô¿ä°Ü¤ò¥°¥é¥Õ¤Ç¸«¤Æ¤ß¤Þ¤·¤ç¤¦¡£
blog-pre
ºÇ½é¤Î¥×¥ì¾ÚÌÀ½ñ¤¬Google pilot¤ÎCT¥í¥°¥µ¡¼¥Ð¡¼¤ËÅÐÏ¿¤µ¤ì¤¿¤Î¤¬¡¢2013ǯ11·î¤Ç¡¢¥×¥ì¾ÚÌÀ½ñ¤È¤¤¤¦¤«SCTÂбþ¤Î¾ÚÌÀ½ñȯ¹Ô¤ò¥µ¡¼¥Ó¥¹¤È¤·¤ÆÀµ¼°¤Ë¥µ¥Ý¡¼¥È¤·»Ï¤á¤¿¤Î¤Ï2014ǯ12·îº¢¤Ç¤¢¤ë¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£

CT¤ÎÂбþ¤¬Áᤫ¤Ã¤¿¤Î¤Ï¤É¤³¤Îǧ¾Ú¶É(¥Ö¥é¥ó¥É)¤«

2015ǯ9·î»þÅÀ¤Ç¡¢96¤ÎÃæ´Öǧ¾Ú¶É(¥µ¥ÖCA)¡¢30¤Î¥Ö¥é¥ó¥É¤¬¥×¥ì¾ÚÌÀ½ñ¤òȯ¹Ô¤·¤Æ¤¤¤Þ¤¹¡£ ¥×¥ì¾ÚÌÀ½ñ¤Îȯ¹Ô¤¬Áᤫ¤Ã¤¿30¤Î¥Ö¥é¥ó¥É¤Î½ç½ø¡¢È¯¹ÔÆü¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤·¤¿¡£

ǧ¾Ú¶É¥Ö¥é¥ó¥É½é¥×¥ì¾ÚÌÀ½ñȯ¹ÔÆü
DigiCert2013ǯ11·î01Æü
COMODO2014ǯ01·î23Æü
TAIWAN-CA2014ǯ05·î09Æü
Entrust2014ǯ07·î21Æü
AffirmTrust2014ǯ10·î27Æü
Symantec2014ǯ11·î11Æü
GlobalSign2014ǯ11·î28Æü
GeoTrust2014ǯ12·î08Æü
Thawte2014ǯ12·î08Æü
Buypass2014ǯ12·î10Æü
Network Solutions2014ǯ12·î15Æü
USERTRUST2014ǯ12·î16Æü
Trend Micro2014ǯ12·î22Æü
Starfield2014ǯ12·î23Æü
Go Daddy2014ǯ12·î23Æü
TERENA2014ǯ12·î29Æü
Trustwave2015ǯ01·î05Æü
Cybertrust2015ǯ01·î07Æü
VeriSign2015ǯ01·î12Æü
QuoVadis2015ǯ01·î14Æü
HydrantID2015ǯ01·î22Æü
Google UK2015ǯ01·î27Æü
Aetna2015ǯ01·î29Æü
IZENPE2015ǯ02·î04Æü
Certum2015ǯ02·î05Æü
Camerfirma2015ǯ02·î20Æü
NCC2015ǯ03·î30Æü
SECOM Trust2015ǯ04·î30Æü
Actalis2015ǯ05·î18Æü
WoSign2015ǯ08·î20Æü
CT¤Î»ÅÍͺöÄê¤ä¼ÂÁõ¤Ê¤É¤ÇGoogle¤È¶¨ÎÏ´Ø·¸¤Ë¤¢¤Ã¤¿DigiCert¤¬Âбþ¤¬Áᤤ¤Î¤Ï¤¤¤¤¤È¤·¤Æ¡¢ÂæÏѤÎTAIWAN-CA(TWCA)¤¬ÂбþÁᤫ¤Ã¤¿¤ó¤Ç¤¹¤Í¤§¡£ÆüËܤΥ٥ó¥À¡¼¤µ¤ó¤â´èÄ¥¤Ã¤Æ¤¤¤Þ¤¹¡£

¥×¥ì¾ÚÌÀ½ñ¤Îȯ¹ÔËç¿ô½ç°Ì

¼¡¤Ë¥×¥ì¾ÚÌÀ½ñ¤Îȯ¹ÔËç¿ô¤Ç¸«¤Æ¤ß¤Þ¤·¤ç¤¦¡£Âç¼ê¤¬Â¿¤¤¤Î¤ÏÅö¤¿¤êÁ°¤È¤·¤Æ¡¢ Cybertrust¤µ¤ó´èÄ¥¤Ã¤Æ¤¤¤ë´¶¤¬¤¢¤ê¤Þ¤¹¤Í¡£ ¤½¤¦¤¤¤¨¤Ð¡¢StartSSL¤Ï¤É¤¦¤Ê¤Ã¤Æ¤ë¤ó¤Ç¤·¤ç¤¦¤«¡£ 10ËçÄøÅٰʲ¼¤Î¤È¤³¤í¤Ï¡¢¤Þ¤À¥Æ¥¹¥ÈÃæ¤Ã¤Æ´¶¤¸¤Ç¤¹¤«¤Í¡£

ǧ¾Ú¶É¥Ö¥é¥ó¥É¥×¥ì¾ÚÌÀ½ñȯ¹ÔËç¿ô
Symantec50760
DigiCert20856
GeoTrust17447
COMODO14573
Cybertrust13020
Go Daddy12635
Thawte9891
Entrust6616
GlobalSign6063
TERENA2363
QuoVadis1873
Google UK1861
Starfield1262
Network Solutions939
Trend Micro615
Certum367
VeriSign196
WoSign187
Trustwave177
SECOM Trust161
Buypass154
IZENPE116
TAIWAN-CA76
HydrantID37
Aetna34
NCC25
AffirmTrust10
Actalis7
USERTRUST7
Camerfirma4

¤É¤ó¤Ê¥Ä¡¼¥ë¤ò¤Ä¤¯¤Ã¤¿¤«

Ä´¤Ù¤ë¤Ë¤¢¤¿¤Ã¤Æ¤Ï¡¢Perl¤äNode(+jsrsasign)¤Ê¤É¤Ç´ö¤Ä¤«¥Ä¡¼¥ë¤òºî¤Ã¤¿¤ê¤Ü¤Á¤Ü¤Á´Ä¶­¤òÀ°È÷¤·¤Æ¤¤¤Þ¤¹¡£¸ø³«¤·¤Æ¤â¤¤¤¤¤ó¤Ç¤¹¤±¤É¡¢¥É¥­¥å¥á¥ó¥ÈÀ°È÷¤·¤¿¤ê¡¢¥³¥Þ¥ó¥É¥é¥¤¥ó¥ª¥×¥·¥ç¥ó¤Ê¤É¤Á¤ã¤ó¤Èºî¤ê¹þ¤Þ¤Ê¤¤¤È¡¢¡Ö¥É¥­¥å¥á¥ó¥È¤¬¤Ê¤¤¤«¤é»È¤¤¤â¤ó¤Ë¤Ê¤ó¤Í¡Á¡Á¡ª¡ª¡×¤È¤«Åܤé¤ì¤ÆÈó¾ï¤Ë¥Ø¥³¤à¤ó¤¹¤è¤Í¡£¥ª¡¼¥×¥ó¥½¡¼¥¹¤Ê¤ó¤À¤«¤é¡¢¤Á¤ç¤Ã¤È¥³¡¼¥É¤ß¤Æ¤¯¤ì¤ê¤ã¤¤¤¤¤·¡¢¥Æ¥¹¥È¥³¡¼¥É¸«¤ê¤ã¤½¤Î¤Þ¤Þ»È¤¤Êý¥º¥Ð¥ê¤Ê¤Î¤Ç¡¢¡¢¡¢¤È»×¤¦¤ó¤¹¤±¤É¤Í¡Á¡Á¡Á¡£(jsrsasign¤Î¶òÃԤäݤ¯¤Æ¤¹¤ß¤Þ¤»¤ó¡£)

¤¶¤Ã¤¯¤ê¤³¤ó¤Ê¥Ä¡¼¥ë¤òºî¤Ã¤Æ¤ß¤Æ¤¤¤Þ¤¹¡£(¾¤Ë¤â¤¤¤í¤¤¤í¤¢¤ê¤Þ¤¹¤¬¡¢º£²ó¤Ë´Ø·¸¤¹¤ëʬ¤À¤±¡£)

  • ¥×¥ì¾ÚÌÀ½ñ¤È¤½¤Î²òÀϾðÊó¤À¤±¤ò½¸¤á¤¿SQLite¥Ç¡¼¥¿¥Ù¡¼¥¹
  • ¥í¥°¥¨¥ó¥È¥ê¤Îleaf_inputÊݸ¥Ä¡¼¥ë
  • ¥í¥°¥¨¥ó¥È¥ê¤Îextra_dataÊݸ¥Ä¡¼¥ë
  • ¥í¥°¥¨¥ó¥È¥ê¤«¤é¥×¥ì¾ÚÌÀ½ñ¤Î¥Á¥§¡¼¥ó¤ò¼è¤ê½Ð¤·¤Æ¾ÚÌÀ½ñ¤È¤·¤ÆÊݴɤ¹¤ë¥Ä¡¼¥ë
  • leaf_input¤Î¥Ç¡¼¥¿¥Õ¥¡¥¤¥ë¤Î²òÀϥġ¼¥ë
  • ¥×¥ì¾ÚÌÀ½ñ¤ÎTBSCertificate¤«¤é¥Ë¥»½ð̾¤ò¤Ä¤±¤ÆÅ¬Åö¤Ê¾ÚÌÀ½ñ¤Ë»ÅΩ¤Æ¤ë¥Ä¡¼¥ë (TBSCertificate¥Ó¥å¡¼¥¢¡¼¤Ã¤Æ°ìÈÌŪ¤Ë̵¤¤¤Î¤Ç¤³¤ì¤¬¤Ç¤­¤ë¤È ÉáÄ̤ξÚÌÀ½ñ¥Ó¥å¡¼¥¢¡¼(openssl x509¥³¥Þ¥ó¥É¤Ê¤É)¤¬»È¤¨¤ë¤Î¤Ç¤È¤Æ¤âÊØÍø¡£)
  • ¥í¥°¥¨¥ó¥È¥ê¤ÎÅÐÏ¿Æü¤òɽ¼¨¤¹¤ë¥Ä¡¼¥ë

¤ª¤ï¤ê¤Ë

º£²ó¤Ï¡¢¥í¥°¥Ç¡¼¥¿¥Ù¡¼¥¹¤òÄ´¤Ù¤Æ¤ï¤«¤Ã¤¿¡¢Åý·×Ū¤ÊÏäòÃæ¿´¤Ë¥ì¥Ý¡¼¥È¤·¤Þ¤·¤¿¡£¼¡²ó¤Ï¥Ç¡¼¥¿¹½Â¤¡¢¥×¥ì¾ÚÌÀ½ñ¤ÎÆâÍÆ¤Ê¤ó¤«¤òÃæ¿´¤Ë½ñ¤±¤ë¤È¤¤¤¤¤Ê¤È»×¤Ã¤Æ¤Þ¤¹¡£¤Ç¤Ï¤Ç¤Ï¡£

SSL Pulse¤ÎÅý·×¾ðÊó¤Ç¸«¤ëSSL/TLS (2015ǯ8·îÈÇ)

SSL Pulse¥µ¥¤¥È(https://www.trustworthyinternet.org/ssl-pulse/)¤Ï¡¢ ssllabs¤Ç¤âͭ̾¤ÊQualys¼Ò¤¬±¿±Ä¤·¤Æ¤¤¤ë¥µ¥¤¥È¤Ç¡¢ Web¥µ¥¤¥ÈÄ´ºº¤ÎAlexa¼Ò¤Ë¤è¤ë À¤³¦¤Î¥¢¥¯¥»¥¹¥È¥Ã¥×20Ëü¥µ¥¤¥È¤òÂоݤËSSL´Ø·¸¤ÎÅý·×¾ðÊó¤òËè·î¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£ 6·î¤Ë°ú¤­Â³¤­º£·î¤â8·î¤ÎSSL Pulse¤Ç¤ÎSSL/TLS¤Î¾õ¶·¿ä°Ü¤ò¥°¥é¥Õ²½¤·¤Þ¤·¤ç¤¦¡£

ÀȼåÀ­Âбþ¤Î¿ä°Ü


201508-vuln
RC4¤ÎÍøÍѲÄǽΨ¤¬½çÄ´¤Ë²¼¤¬¤Ã¤Æ¤¤¤ë¤Ê¤É¡¢¤ª¤ª¤à¤Í½çÄ´¤Ê´¶¤¸¤¬¤·¤Þ¤¹¤Í¡£¤Ä¤Þ¤é¤ó¡£

SSL/TLS¥×¥í¥È¥³¥ë¤Î¿ä°Ü


201508-ssl
POODLE¤Î±Æ¶Á¤ÇSSLv3¤Î̵¸ú²½¤¬35.0%¤Þ¤Ç½çÄ´¤Ë²¼¤¬¤Ã¤Æ¤¤¤Þ¤¹¡£¤³¤ì¤â¤Ä¤Þ¤é¤ó¡£

SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Î¸°Ä¹¡¢½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î¿ä°Ü


201508-crt
Google Chrome¤äWindowsÀ½ÉʤÎSHA1¾ÚÌÀ½ñ¤Î¥¢¥é¡¼¥ÈÂбþ¤ò¼õ¤±¤Æ¡¢º£·î¤â½çÄ´¤ËSHA2°Ü¹Ô¤¬¿Ê¤ó¤Ç¤ª¤êSHA1withRSA¤¬31.9%¡¢SHA256withRSA¤¬67.2%¤Þ¤Ç¿Ê¤ó¤Ç¤¤¤Þ¤¹¡£

¿·¤·¤¤µ»½Ñ¤Î¥µ¥Ý¡¼¥È¤Î¿ä°Ü


201508-new
¤¦¡Á¤à¡¢¤³¤ì¤â¤Ä¤Þ¤é¤ó¡£

¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201508-kx
¸°¸ò´¹¤Î¸°Ä¹¤Ï½çÄ´¤Ë¡¢512bit¡¢1024bit¤ÎÍøÍѤò¤ä¤á¡¢2048bitÁêÅö¤Ë°Ü¹Ô¤¬¿Ê¤ó¤Ç¤¤¤Þ¤¹¡£

DH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201508-dh
°Å¹æ¶¯Å٤ν½Ê¬¤Ç¤Ê¤¤DH1024bit¡¢512bit¤ÎÍøÍѤϽçÄ´¤Ë¸º¤ê¡¢2048bit¤ÏÁý¤¨¤Æ¤¤¤Þ¤¹¤¬¡¢¤½¤¦¤Ï¤¤¤Ã¤Æ¤âÂ礷¤¿Î¨¤Ç¤Ê¤¯¡¢¤ä¤Ï¤êDH/DHE¤Ï»È¤ï¤Ê¤¤¤Î¤¬Îɤ¤¤È»×¤¤¤Þ¤¹¡£

ECDH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201508-ecdh
ECDH/ECDHE¤¬»È¤¨¤Æ¤¤¤Ê¤¤¥µ¥¤¥È¤¬½çÄ´¤Ë¸º¤ê¡¢»È¤¨¤ë¥µ¥¤¥È¤¬Áý¤¨¤Æ¤ª¤ê¡¢ECC 256bit¤ÎECDH/ECDHE¤¬»È¤¨¤ë¥µ¥¤¥È¤¬58.5%¤Þ¤ÇÁý¤¨¤Æ¤¤¤Þ¤¹¡£

¤ª¤ï¤ê¤Ë

º£½µ¤Ï¡¢¥»¥­¥å¥ê¥Æ¥£¡¦¥­¥ã¥ó¥×Á´¹ñÂç²ñ¤ËÍè¤Æ¤¤¤ë¤Î¤Ç¡¢¤¢¤Ã¤µ¤êÉ÷Ì£¤Ç¡£

´ØÏ¢µ­»ö

SSL Pulse¤ÎÅý·×¾ðÊó¤Ç¸«¤ëSSL/TLS (2015ǯ6·îÈÇ)

SSL Pulse¥µ¥¤¥È(https://www.trustworthyinternet.org/ssl-pulse/)¤Ï¡¢ ssllabs¤Ç¤âͭ̾¤ÊQualys¼Ò¤¬±¿±Ä¤·¤Æ¤¤¤ë¥µ¥¤¥È¤Ç¡¢ Web¥µ¥¤¥ÈÄ´ºº¤ÎAlexa¼Ò¤Ë¤è¤ë À¤³¦¤Î¥¢¥¯¥»¥¹¥È¥Ã¥×20Ëü¥µ¥¤¥È¤òÂоݤËSSL´Ø·¸¤ÎÅý·×¾ðÊó¤òËè·î¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£ 5·î¤Ë°ú¤­Â³¤­6·î¤ÎSSL Pulse¤Ç¤ÎSSL/TLS¤Î¾õ¶·¿ä°Ü¤ò¥°¥é¥Õ²½¤·¤Æ¤ß¤Þ¤·¤ç¤¦¡£ ËÜÅö¤Ï³Ö·î¤Ë¤·¤è¤¦¤È»×¤Ã¤Æ¤¿¤ó¤Ç¤¹¤¬¡¢Logjam¤Î±Æ¶Á¤¬¸«¤¿¤«¤Ã¤¿¤Î¤Çº£·î¤Ï¤ä¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡£ (¥¦¥½¡¢º£·î¤Ï¤ä¤é¤Ê¤¯¤ÆÎɤ¤·î¤À¤Ã¤¿¤Î¤Ë˺¤ì¤Æ¤Æ¥°¥é¥Õ¤òºî¤Ã¤Æ¤·¤Þ¤Ã¤¿¤À¤±¤Ç¤¹orz )

ÀȼåÀ­Âбþ¤Î¿ä°Ü


201506vuln

SSL/TLS¥×¥í¥È¥³¥ë¤Î¿ä°Ü


201506proto
POODLE¤Î±Æ¶Á¤ÇSSLv3¤Î̵¸ú²½¤¬½çÄ´¤Ë²¼¤¬¤Ã¤Æ¤ª¤ê¡¢¥µ¥Ý¡¼¥È¤¹¤ë¥µ¥¤¥È¤Ï37.6%¤Þ¤Ç¤Ë¸º¤ê¤Þ¤·¤¿¡£

SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Î¸°Ä¹¡¢½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î¿ä°Ü


201506crt
Google Chrome¤äWindowsÀ½ÉʤÎSHA1¾ÚÌÀ½ñ¤Î¥¢¥é¡¼¥ÈÂбþ¤ò¼õ¤±¤Æ¡¢SHA1¤ÈSHA2¾ÚÌÀ½ñ¤ÎÈæÎ¨¤¬5·î¤ËµÕž¤·¤Þ¤·¤¿¤¬¡¢½çÄ´¤ËSHA2°Ü¹Ô¤¬¿Ê¤ß¡¢SHA2¤¬60%¡¢SHA1¤¬40%¤Þ¤Ç¤­¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£

¿·¤·¤¤µ»½Ñ¤Î¥µ¥Ý¡¼¥È¤Î¿ä°Ü


201506adv
OCSP staplingÂбþΨ¤Ï¿­¤Ó¤«¤«¤Ã¤¿¤Î¤Ë¤Þ¤¿Ìá¤Ã¤Æ¤·¤Þ¤¤¤Þ¤·¤¿¡£

¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201506kx
¸°¸ò´¹¤Î¾ðÊó¤¬3·î¤«¤é¼è¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¡¢¤è¤¦¤ä¤¯·¹¸þ¤¬¤Ä¤«¤á¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤­¤Æ¤¤¤Þ¤¹¡£

DH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201506dh
¼å¤¤Í¢½Ð¥°¥ì¡¼¥É¤ÎDH(E)¸°¤Î¥À¥¦¥ó¥°¥ì¡¼¥É¤Ë¤è¤ëLogjamÀȼåÀ­¤¬5·î¤Ë¸øÉ½¤µ¤ì¤¿¤³¤È¤Ç¡¢Á´ÂÎŪ¤ËDH¸°¸ò´¹¤Î¸°Ä¹¤¬Áý¤¨¤Æ¤¤¤Þ¤¹¤¬¡¢¤È¤Ï¸À¤Ã¤Æ¤â2¡¢3%¤ÎÊѲ½¤·¤«¤Ê¤¯¡¢ ¤ä¤Ï¤êDH¸°¸ò´¹¤Î¸°Ä¹¤òÁý¤ä¤¹¤è¤¦ÀßÄꤹ¤ë¤è¤ê¤â¡¢DH¸°¸ò´¹¤Ï»È¤ï¤º¡¢ECDH·Ï¤Î¸°¸ò´¹¤ò»È¤¦¤Î¤¬Îɤ¤¤è¤¦¤Ë»×¤¤¤Þ¤¹¡£

LogjamÀȼåÀ­¤Îȯ¸«¼Ô¤Î°ì¿Í¤Ç¤¢¤ëMatthew GreenÀèÀ¸¤Î¥Ö¥í¥°¤Ë¤è¤ë¤È¡¢¤³¤Î¹¶·â¤òÀ®¸ù¤µ¤»¤ë¤Ë¤ÏÃæ´Ö¼Ô¤¬¥Ï¥ó¥É¥·¥§¥¤¥¯Ãæ¤Î½½Ê¬Ã»¤¤»þ´Ö¤ÇDH¸°¤Î²òÆÉ¤ò¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¤½¤¦¤Ç¤¹¤¬¡¢¤¢¤ë¸°¥Ñ¥é¥á¡¼¥¿¡¼¤Ë¤Ä¤¤¤Æ»öÁ°·×»»¤ò¤·¤Æ¤ª¤±¤Ð¤³¤ì¤Ï²Äǽ¤Ç¤¢¤ê¡¢512bit¤Ê¤é°ìÈÌŪ¤Ê´Ä¶­¤Ç¤â¿ô½½ÉäDzò¤¯¤³¤È¤Ï²Äǽ¤Ç¤¢¤ê¡¢1024bit¤Î¾ì¹ç¡¢°ìÈÌŪ¤Ê´Ä¶­¤Ç¤Ï̵Íý¤«¤â¤·¤ì¤Ê¤¤¤¬NSA¤Î¤è¤¦¤ÊĵÊ󵡴ؤǤ¢¤ì¤Ð¡¢¤½¤Îͽ»»¤ÈÈæ³Ó¤·¤ÆÁ´¤¯ÉÔ²Äǽ¤È¤¤¤¦ÃͤǤâ¤Ê¤¤¤È¤¤¤¦¤³¤È¤Ç¤¹¡£Éݤ¤¤Ç¤¹¤Í¡Á¡Á¡Á¡£

ECDH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201506ecdh
ECDH·Ï¤Î¸°¸ò´¹¤ò»È¤¨¤ë¥µ¥¤¥È¤È¡¢»È¤¨¤Ê¤¤¥µ¥¤¥È¤ÎÈæÎ¨¤¬5·î¤ËµÕž¤·¤Þ¤·¤¿¤¬¡¢ECC 256bit¤ÎÍøÍѤ¬½çÄ´¤Ë¿Ê¤ó¤Ç¤¤¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£

¤ª¤ï¤ê¤Ë

Íè½µ·îÍˤÏJNSA¤ÎÊÙ¶¯²ñ¤Ê¤Î¤Ç¡¢Á᤯»ñÎÁºî¤é¤ó¤È¤¤¤«¤ó¤Ê¤¡¡£¤·¤«¤·¡¢¤ª¤®¤ã¡Á¤µ¤ó¤Ï¡¢¤â¤Î¤¹¤´¤¤½¸µÒÎϤÀ¤Ê¤¡¡£

´ØÏ¢µ­»ö

SSL Pulse¤ÎÅý·×¾ðÊó¤Ç¸«¤ëSSL/TLS (2015ǯ5·îÈÇ)

SSL Pulse¥µ¥¤¥È(https://www.trustworthyinternet.org/ssl-pulse/)¤Ï¡¢ ssllabs¤Ç¤âͭ̾¤ÊQualys¼Ò¤¬±¿±Ä¤·¤Æ¤¤¤ë¥µ¥¤¥È¤Ç¡¢ Web¥µ¥¤¥ÈÄ´ºº¤ÎAlexa¼Ò¤Ë¤è¤ë À¤³¦¤Î¥¢¥¯¥»¥¹¥È¥Ã¥×20Ëü¥µ¥¤¥È¤òÂоݤËSSL´Ø·¸¤ÎÅý·×¾ðÊó¤òËè·î¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£ 3·î¤Ë°ú¤­Â³¤­5·î¤ÎSSL Pulse¤Ç¤ÎSSL/TLS¤Î¾õ¶·¿ä°Ü¤ò¥°¥é¥Õ²½¤·¤Æ¤ß¤Þ¤·¤ç¤¦¡£ ³Ö·î¤Ç¸«¤Æ¤¤¤±¤¿¤é¤È»×¤Ã¤Æ¤¤¤Þ¤¹¡Ê¡°¡°¡¨

ÀȼåÀ­Âбþ¤Î¿ä°Ü


201505vuln

SSL/TLS¥×¥í¥È¥³¥ë¤Î¿ä°Ü


201505proto
POODLE¤Î±Æ¶Á¤ÇSSLv3¤Î̵¸ú²½¤¬½çÄ´¤Ë²¼¤¬¤Ã¤Æ¤ª¤ê¡¢¥µ¥Ý¡¼¥È¤¹¤ë¥µ¥¤¥È¤Ï40%¤Þ¤Ç¤Ë¸º¤ê¤Þ¤·¤¿¡£

SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Î¸°Ä¹¡¢½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î¿ä°Ü


201505cert
Google Chrome¤äWindowsÀ½ÉʤÎSHA1¾ÚÌÀ½ñ¤Î¥¢¥é¡¼¥ÈÂбþ¤ò¼õ¤±¤Æ¡¢SHA1¤ÈSHA2¾ÚÌÀ½ñ¤ÎÈæÎ¨¤¬µÕž¤·¤Þ¤·¤¿¡£º£·î¤Î¥°¥é¥Õ¤ÇºÇ¤âÆÃħŪ¤Ê»ö¤«¤È»×¤¤¤Þ¤¹¡£

¿·¤·¤¤µ»½Ñ¤Î¥µ¥Ý¡¼¥È¤Î¿ä°Ü


201505adv
OCSP staplingÂбþΨ¤Ï½çÄ´¤Ë¿­¤Ó¤Æ¤¤¤Þ¤¹¤¬¡£Â礷¤¿¤³¤È¤Ï¤¢¤ê¤Þ¤»¤ó¡£

¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201505kx
¸°¸ò´¹¤Î¾ðÊó¤¬3·î¤«¤é¼è¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¡¢¤è¤¦¤ä¤¯·¹¸þ¤¬¤Ä¤«¤á¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤­¤Æ¤¤¤Þ¤¹¡£

DH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201505dh
DH¸°¸ò´¹¤ËÂбþ¤¹¤ë¥µ¥¤¥È¤Ï¤ï¤º¤«¤Ê¤¬¤éÁý¤¨¤Æ¤¤¤Þ¤¹¤¬¡¢2048bit¤À¤±¤Ç¤Ê¤¯¡¢°ÂÁ´¤Ç¤Ê¤¤¤È¤µ¤ì¤ë1024bit¤âÁý¤¨¤Æ¤¤¤ë¤³¤È¡¢¤Þ¤¿¤½¤ì°Ê¾å¤Ë°ÂÁ´¤Ç¤Ê¤¤512bit¤¬»È¤ï¤ì¤Æ¤¤¤ë¤³¤È¤ÏÈó¾ï¤ËÌäÂê¤Ç¤¹¡£¤³¤Î¤è¤¦¤Ê·¹¸þ¤«¤é¤â¡¢DH¸°¸ò´¹¤Î¸°Ä¹¤òÁý¤ä¤¹¤è¤¦ÀßÄꤹ¤ë¤è¤ê¤â¡¢DH¸°¸ò´¹¤Ï»È¤ï¤º¡¢ECDH·Ï¤Î¸°¸ò´¹¤ò»È¤¦¤Î¤¬Îɤ¤¤è¤¦¤Ë»×¤¤¤Þ¤¹¡£

ÀèÆü¥Ö¥í¥°¤Ë½ñ¤¤¤¿TLS¤Î¼ÂÁõ¤ÈƳÆþ¾å¤Î¿ä¾©¤ò¤Þ¤È¤á¤¿RFC 7525¤Î4.4Àá¤Ë¤âDH¸°¸ò´¹¤Î²ÝÂ꤬À°Íý¤µ¤ì¤Æ¤ª¤ê¡¢RFC 7525¤Ç¤Ï¡Ö»È¤¦¤Ê¡×¤È¤Ï¸À¤Ã¤Æ¤¤¤Þ¤»¤ó¤¬¡¢¤³¤ì¤òÆÉ¤à¤ÈDH·Ï¤Î¸°¸ò´¹¤Ï»È¤¦¤Ù¤­¤Ç¤Ï¤Ê¤¤¤è¤¦¤Ë»×¤¤¤Þ¤¹¡£

ECDH¸°¸ò´¹¤ÎºÇÄ㸰Ĺ


201505ecdh
ECDH·Ï¤Î¸°¸ò´¹¤ò»È¤¨¤ë¥µ¥¤¥È¤È¡¢»È¤¨¤Ê¤¤¥µ¥¤¥È¤ÎÈæÎ¨¤¬µÕž¤·¡¢ECDH·Ï¤Î¸°¸ò´¹¤Ø¤ÎÂбþ¤¬È¾¿ô¤òͤ¨¤Æ¤­¤Þ¤·¤¿¡£ECDH·Ï¸°¸ò´¹¤ò»È¤¨¤Ê¤¤ÈæÎ¨¤Î¸º¤êÊý¤¬DH¤ËÈæ¤Ù¤Æ¸²Ãø¤Ç¤¹¡£

¤ª¤ï¤ê¤Ë

¤Ê¤ó¤«º£½µËö¤Ï¥Ö¥í¥°¥é¥Ã¥·¥å¤Ã¤¹¤Í¡£¥á¥Ã¥»¡¼¥¸Æþ¤êSSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Î·ï¤¬½ñ¤±¤Ê¤«¤Ã¤¿¤Ê¤¡¡£º£Æü¤Ï¤³¤ÎÊդǡ£

´ØÏ¢µ­»ö

(¾®¥Í¥¿)Íè·î¤Ë¤ÏSHA2¾ÚÌÀ½ñ¤ÎËç¿ô¤¬SHA1¤òÄɤ¤±Û¤·¤½¤¦¤Ê·ï

SSL Pulse ¤Î 2015ǯ4·îÈǤ¬¸ø³«¤µ¤ì¤Þ¤·¤¿¤Í¡£¤¤¤Ä¤â¤Ï2¥ö·î¤Ë1²ó¾õ¶·Êó¹ð¤·¤è¤¦¤È¤·¤Æ¤¤¤¿¤ó¤Ç¤¹¤¬¡¢SHA1¾ÚÌÀ½ñ¤«¤éSHA2¾ÚÌÀ½ñ¤Ø¤Î°Ü¹Ô¤¬µ¤¤Ë¤Ê¤Ã¤Æ¤¿¤Î¤Ç¡¢¾ÚÌÀ½ñ¤Î¸°¤ä½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î°Ü¹Ô¾õ¶·¤À¤±¥°¥é¥Õ¤Ë¤·¤Æ¤ß¤Þ¤·¤¿¡£SHA1¾ÚÌÀ½ñ¤¬51%¡¢SHA2¾ÚÌÀ½ñ¤¬48%¤È¤«¤Ê¤ê¶á¤Å¤¤¤Æ¤¤¤Þ¤¹¡£
sslpulse201504-keysig
Ʊ¤¸¤è¤¦¤Ë¿ä°Ü¤·¤¿¤È¤¹¤ë¤È¡¢2015ǯ5·î¤Ë¤ÏSHA1¾ÚÌÀ½ñ¤Î¿ô¤¬SHA256¾ÚÌÀ½ñ¤Î¿ô¤òÄɤ¤±Û¤·¤½¤¦¤Ç¤¹¤Í¡£

´ØÏ¢µ­»ö

ºÇ¿·µ­»ö
Categories
Archives
Twitter
µ­»öGoogle¸¡º÷

ËÜ¥Ö¥í¥°Æâ¤òGoogle¸¡º÷
Yahoo!¥¢¥¯¥»¥¹²òÀÏ
Travel Advisor
µ­»ö¸¡º÷
QR¥³¡¼¥É
QR¥³¡¼¥É
  • ¥é¥¤¥Ö¥É¥¢¥Ö¥í¥°