SHA1with¤Ê¤ó¤È¤«¤Ç½ð̾¤µ¤ì¤¿SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤ËÂФ¹¤ëGoogle Chrome¤Î ¾Íè¤Î¼è°·¤¤¥Ý¥ê¥·¤Ë¤Ä¤¤¤Æ¡¢Google¤Î¥Ö¥í¥°¤Ç9·î5Æü¤Ë¾ðÊó¸ø³«¤µ¤ì¡¢¤Á¤ç¤Ã¤È¥Ó¥Ã¥¯¥ê¤·¤¿¿Í¤â¿¤¤¤ó¤¸¤ã¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£»ä¤Ï¡¢¡Ö¤³¤ê¤ã¤Á¤ç¤Ã¤ÈÌäÂê¤À¤Ê¤¡¡£¡×¤È»×¤Ã¤¿¤Î¤Çº£Æü¤Ï¥Ö¥í¥°¤Ç½ñ¤¤¤Æ¤ß¤è¤¦¤È»×¤¤¤Þ¤¹¡£
SHA1¤¬½¼Ê¬¤Ê°Å¹æ¶¯ÅÙ¤¬¤Ê¤¯¤Ê¤ê¤Ä¤Ä¤¢¤ëÏÃ
°Å¹æ¤ÎÀìÌç²È¤Ç¤Ï¤Ê¤¤¤Î¤Ç¡¢¤è¤¯¤ï¤«¤é¤Ê¤¤¤Î¤Ç¤¹¤¬¡¢ Î㤨¤Ð¥³¥ì¤Ê¤ó¤«¤ò¤ß¤Æ¤ß¤ë¤ÈSHA1¥Ï¥Ã¥·¥å¥¢¥ë¥´¥ê¥º¥à¤Î°Å¹æ¶¯ÅÙ¤¬½¼Ê¬¤Ç¤Ê¤¯¤Ê¤Ã¤Æ¤¤Æ¤¤¤ë¤È¸À¤ï¤ì¤Æ¤ª¤ê¡¢°Å¹æ¤Ë´Ø¤¹¤ëÆüËܤǼçÍפʥ¬¥¤¥É¥é¥¤¥ó¤Ç¤¢¤ëCRYPTREC°Å¹æ¥ê¥¹¥È¤Ç¤ÏSHA1¤Ï¡Ö±¿ÍÑ´Æ»ë°Å¹æ¥ê¥¹¥È¡×¡¢´íËز½¥ê¥¹¥¯¤¬¹â¤Þ¤Ã¤Æ¤¤¤ë¤¬¸ß´¹À°Ý»ý¤Î¤¿¤á»ÅÊý¤Ê¤¯»È¤Ã¤ÆÎɤ¤¥ê¥¹¥È¤ËÆþ¤Ã¤Æ¤¤¤Þ¤¹¡£
¤³¤Î¤è¤¦¤Ê¾õ¶·¤ò¼õ¤±¤Æ¡¢À½ÉÊ¥Ù¥ó¥À¡¼¡¢¾ÚÌÀ½ñȯ¹Ô¥µ¡¼¥Ó¥¹¤Ê¤É¤Î¥µ¡¼¥Ó¥µ¡¼¤Ê¤É¤ÏSHA1¤«¤éSHA2¤Ø¤Î°Ü¹Ô¤ò¤è¤¦¤ä¤¯»Ï¤á¤¿¤È¤³¤í¤Ê¤Î¤«¤Ê¤È»×¤¤¤Þ¤¹¡£
Êƹñ¤Îɸ½à²½µ¡´Ø¤Ç¤¢¤ëNIST¤Ï2011ǯ1·î¤Ë¡ÖNIST SP 800-131A Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lenghs(°Å¹æ¥¢¥ë¥´¥ê¥º¥à¤È¸°Ä¹¤Î»ÈÍѤ˴ؤ¹¤ë´«¹ð)¡×¤òȯ¹Ô¤·¤Æ¤ª¤ê¡¢¤½¤ÎÃæ¤Ç¡ÖSHA1¤ò»È¤Ã¤¿½ð̾¤ÎÀ¸À®¤È¸¡¾Ú¤Ï2013ǯ12·î31Æü°Ê¹ß¡¢Ç§¤á¤é¤ì¤Ê¤¤¡£¡×¤È¤·¤Æ¤¤¤Þ¤¹¤¬¡¢NISTÆâ¤Ç¤âSHA1¾ÚÌÀ½ñ¤ò»È¤Ã¤¿¥µ¥¤¥È¤¬¤Þ¤À»Ä¤Ã¤Æ¤¤¤ë¤½¤¦¤Ç¡¢¡Ö¼«Ê¬¤â¼é¤ì¤Æ¤Ê¤¤¤¸¤ã¡Á¡Á¤ó¡×¤ß¤¿¤¤¤Ê¾õÂ֤ˤʤäƤ¤¤ë¤½¤¦¤Ç¤¹¡£
2013ǯ11ȯɽ¤ÎMicrosoftÀ½ÉʤÎSHA1°Ü¹Ô¥Ý¥ê¥·¡¼
´ö¤Ä¤«¤Î¶È³¦¤äÀ½ÉʤǤÏÀè¹Ô¤·¤ÆSHA1¤«¤é¤Î°Ü¹Ô¥Ý¥ê¥·¡¼¤òºöÄê¡¢¸øɽ¤·¤Æ¤¤¤ë¤â¤Î¤â¤¢¤ê¤Þ¤¹¤¬¡¢SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Ë´Ø¤·¤Æ¤ÏÉý¹¤¤À½Éʤ䥵¡¼¥Ó¥¹¤Ç»È¤ï¤ì¡¢SHA1¤ò»È¤Ã¤Æ¤¤¤ëÈæΨ¤â¹â¤¯°Ü¹Ô¤ÏÆñ¤·¤¤¤Î¤À¤í¤¦¤È»×¤¤¤Þ¤¹¡£ËÜÍè¤Ê¤éCA Browser Forum¤ÎBaseline Profile¤Çµ¬Äꤵ¤ì¤Æ¤â¤è¤«¤Ã¤¿¤Î¤À¤í¤¦¤È»×¤¤¤Þ¤¹¤¬¡¢SHA1¤«¤é¤Î°Ü¹Ô¤Ë¤Ä¤¤¤Æ¤Ï¸ÀµÚ¤µ¤ì¤Æ¤¤¤Þ¤»¤ó¡£ ¤½¤ó¤ÊÃæ¡¢2013ǯ11·î12Æü¤Ëȯɽ¤µ¤ì¤¿MicrosoftÀ½Éʤ˴ؤ·¤Æ¸ø³«¤µ¤ì¤¿2¤Ä¤ÎSHA1°Ü¹Ô¥Ý¥ê¥·¡¼¤Ï¤Á¤ç¤Ã¤È¾×·âŪ¤Ç¤·¤¿¡£
- Windows Root Certificate Program - Technical Requirements version 2.0
- ¤³¤Î¥×¥í¥°¥é¥à¤ÏWindowsÀ½ÉʤΡ֥롼¥È¾ÚÌÀ½ñ¥×¥í¥°¥é¥à¡×¤È¤¤¤¦¡¢Windows¤Î¿®Íꤹ¤ë¥ë¡¼¥È¾ÚÌÀ½ñ¤Ë²Ã¤¨¤Æ¤â¤é¤¦¤¿¤á¤Ë¤Ï¡¢¤É¤Î¤è¤¦¤Ê´ð½à¤òËþ¤¿¤µ¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¤«¤òÄê¤á¤¿¤â¤Î¤Ç¤¹¤¬¡¢¡ÖÂоݤÎǧ¾Ú¶É¤Ï2016ǯ1·î1Æü°Ê¹ß¡¢SHA1¾ÚÌÀ½ñ¤òȯ¹Ô¤ò¤·¤Æ¤Ï¤Ê¤é¤Ê¤¤¡£¡×¤È¤·¤Æ¤¤¤Þ¤¹¡£
- Windows PKI Blog: SHA1 Deprecation Policy
- ¡ÖWindowsÀ½ÉʤǤÏ2017ǯ1·î1Æü°Ê¹ß¡¢SHA1¤ÎSSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤ò¼õÍý¤·¤Ê¤¤¤¿¤á¥¨¥é¡¼¤È¤Ê¤ë¡£¡×¤È¤·¤Æ¤¤¤Þ¤¹¡£¤¹¤Ê¤ï¤Á¡¢WindowsÀ½ÉʤÇSSL¤ò»È¤¨¤ë¤è¤¦¤Ë¤¹¤ë¤Ë¤Ï¡¢SHA1 SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤ò2016ǯ12·î31Æü¤Þ¤Ç¤ËSHA2¤Ë¥ê¥×¥ì¡¼¥¹¤·¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¤È¤¤¤¦»ö¤À¤½¤¦¤Ç¤¹¡£
¤³¤ì¤Ë´Ø¤·¤ÆÃíÌܤ¹¤Ù¤¥Ý¥¤¥ó¥È¤Ï°Ê²¼¤Î2¤Ä¤«¤È»×¤¤¤Þ¤¹¡£
- Ãæ´ÖCA¾ÚÌÀ½ñ¤ä¥ë¡¼¥È¾ÚÌÀ½ñ¤ÎSHA1¤Ë¤Ä¤¤¤Æ¤Ï¸ÀµÚ¤·¤Æ¤¤¤Ê¤¤¡£
- 2016ǯ1·î1Æü¤È¡¢2017ǯ1·î1Æü¤È¤¤¤¦2¤Ä¤Î¥Þ¥¤¥ë¥¹¥È¡¼¥ó¤ò¼é¤ê¤µ¤¨¤¹¤ì¤Ð¤è¤¤¡£
- ¥·¥Þ¥ó¥Æ¥Ã¥¯¼Ò¡§ ¥Ï¥Ã¥·¥å¥¢¥ë¥´¥ê¥º¥à¤ÎSHA-1¤«¤éSHA-2¤Ø¤Î°Ü¹Ô¤Ë´Ø¤·¤Æ
- ¥°¥í¡¼¥Ð¥ë¥µ¥¤¥ó¼Ò¡§SHA-2ÅŻҾÚÌÀ½ñ¤Ø¤Î°Ü¹Ô¤Ë¤Ä¤¤¤Æ
2014ǯ9·î5Æü¤Ë¸ø³«¤µ¤ì¤¿Google Chrome¤ÎSHA1 ¾ÚÌÀ½ñÂбþ¥Ý¥ê¥·¡¼
2014ǯ9·î5Æü¤Ë¡ÖGoogle Online Security Blog: Gradually sunsetting SHA-1¡× ¤Ë¤Æ¡¢Google Chrome¤ÎSHA-1¾ÚÌÀ½ñ¤Ë¤¹¤ë¥Ý¥ê¥·¡¼¤ÎÊѹ¹¤¬È¯É½¤µ¤ì¡¢°ìÉô¤Î¿Í¤Ï¶Ã¤¤ò»ý¤Ã¤ÆÆɤó¤À¤Î¤Ç¤Ï¤Ê¤¤¤«¤È»×¤¤¤Þ¤¹¡£ ITmedia¥¨¥ó¥¿¡¼¥×¥é¥¤¥º¤Ç¤â ¡ÖGoogle¡¢¡ÖSHA-1¡×¥µ¥Ý¡¼¥ÈÃæ»ß¤Î¥¹¥±¥¸¥å¡¼¥ë¤òȯɽ(2014.09.08)¡× ¤È¤·¤Æ¾Ò²ð¤µ¤ì¤Þ¤·¤¿¡£(²¿ÅÀ¤«´Ö°ã¤¤¤¬¤¢¤ë¤Î¤Ç¡¢¸¶Ê¸¤ò»²¾È¤¹¤ë¤Î¤¬¤¤¤¤¤Ç¤·¤ç¤¦¡£)
¤³¤ì¤Ï´Êñ¤Ë¸À¤Ã¤Æ¤·¤Þ¤¦¤È¡¢¡ÖSHA-1¤ÎSSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Ë¤è¤Ã¤ÆHTTPS¤ÎÀܳɽ¼¨¤ò¶á¡¹(Â礤¯)ÊѤ¨¤Þ¤¹¤è¡×¤È¤¤¤¦¥¢¥Ê¥¦¥ó¥¹¤Ç¤¹¡£
Google Chrome¤ÎHTTPS¥¹¥Æ¡¼¥¿¥¹É½¼¨
Google Chrome¤Î¥¢¥É¥ì¥¹¥Ð¡¼¤Ë¤ª¤±¤ëHTTPS¤Î¥¹¥Æ¡¼¥¿¥¹É½¼¨¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤è¤¦¤Ç¤¹¡£
ɽ¼¨ | ÆâÍÆ |
---|---|
EV¾ÚÌÀ½ñ¤Ç¤Ê¤¤Àµ¾ï¤ÊHTTPSÀܳ¤Î¾ì¹ç | |
secure, but with minor errors Î㤨¤ÐHTTPS¤ÈHTTP¤Î¥³¥ó¥Æ¥ó¥Ä¤Îº®ºß¤Î¾ì¹ç¤Ê¤É¤Ë½Ð¤ë¡£ | |
neutral, lacking security ʿʸ¤ÎHTTP¤Ê¤É¡¢¥»¥¥å¥ê¥Æ¥£¤¬Ìµ¤¤ÃæΩ¤Î¾õÂÖ¡£ | |
affirmatively insecure ´í¸±¤À¤ÈÃǸÀ¤Ç¤¤ë¾ì¹ç¡£ | |
(»²¹Í) EV SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤ÇÀµ¾ï¤ËHTTPSÀܳ¤Ç¤¤Æ¤¤¤ë¾ì¹ç
|
Google Chrome¤Ï¾ÚÌÀ½ñ¥Á¥§¡¼¥ó¤¬SHA1¤«¤É¤¦¤«¥Á¥§¥Ã¥¯
Windows¤ÎSHA1°Ü¹Ô¥Ý¥ê¥·¡¼¤Ï¥¨¥ó¥É¥¨¥ó¥Æ¥£¾ÚÌÀ½ñ¡¢¤¹¤Ê¤ï¤ÁSSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤¬SHA1¤«¤É¤¦¤«¤À¤±¤ò¥Á¥§¥Ã¥¯¤·¤Æ¤ª¤ê¡¢Ãæ´ÖCA¾ÚÌÀ½ñ¤¬SHA1¤«¤É¤¦¤«¤Ï´Ø·¸Ìµ¤«¤Ã¤¿¤Î¤Ç¤¹¤¬¡¢Google Chrome¤Î°Ü¹Ô¥Ý¥ê¥·¡¼¤Ï¡¢Á´¤Æ¤ÎÃæ´ÖCA¾ÚÌÀ½ñ¤â¥Á¥§¥Ã¥¯¤¹¤ë¤Î¤ÇÃí°Õ¤·¤Ê¤±¤ì¤Ð¤Ê¤ê¤Þ¤»¤ó¡£
¤Ç¡¢Chrome¤ÇSHA1¾ÚÌÀ½ñ¤ÇHTTPSÀܳ¤·¤¿¾ì¹ç¤É¤¦¤Ê¤ë¤Î¤«¡©
9·î5Æü¤Ëȯɽ¤µ¤ì¤¿¡¢Chrome¤ÇSHA1¾ÚÌÀ½ñ¤ËHTTPSÀܳ¤·¤¿¾ì¹ç¤ÎURL¥¢¥É¥ì¥¹¥Ð¡¼¤ÎHTTPS¥¹¥Æ¡¼¥¿¥¹É½¼¨¤¬¡¢¤³¤ÎȾǯ¤Ç3²ó½Ð¤Æ¤¯¤ëChrome¤Î¥Ð¡¼¥¸¥ç¥ó¤Ë¤è¤Ã¤Æ¡¢¤É¤¦ÊѤï¤Ã¤Æ¤¤¤¯¤Î¤«¤òÀ°Íý¤·¤¿¤Î¤¬²¼¤Îɽ¤Ç¤¹¡£
Chrome 39 ³«È¯ÈǤÎÅÓÃæ¤Þ¤Ç ¡Á2014.09.26 38°ÂÄêÈÇ¤Þ¤Ç (¡Á2014.11¾å½Ü) |
Chrome 39 ³«È¯ÈǤÎÅÓÃ椫¤é (2014.09.26¡Á 2014.11.09) 39°ÂÄêÈÇ ¥ê¥ê¡¼¥¹¤«¤é (2014.11¾å½Ü¡Á |
Chrome 40 ³«È¯ÈǤÎÅÓÃ椫¤é (2014.11.09¡Á 2015.Q1) 40°ÂÄêÈÇ ¥ê¥ê¡¼¥¹¤«¤é (2015.01?¡Á |
Chrome 41 ³«È¯ÈǤÎÅÓÃ椫¤é (2015.Q1¡Á 2016.12.31) 41°ÂÄêÈÇ ¥ê¥ê¡¼¥¹¤«¤é (2015.03?¡Á |
2017.01.01¡Á | |
---|---|---|---|---|---|
͸ú´ü¸Â¤¬2016ǯ5·î31Æü¤Þ¤Ç¤ÎSHA1¾ÚÌÀ½ñ | |||||
͸ú´ü¸Â¤¬2016ǯ6·î1Æü¤«¤é12·î31Æü¤Þ¤Ç¤ÎSHA1¾ÚÌÀ½ñ | |||||
͸ú´ü¸Â¤¬2017ǯ1·î1Æü°Ê¹ß¤ÎSHA1¾ÚÌÀ½ñ | |||||
Windows¤Î¾ì¹ç(ChromeƱÅù¤Îɽ¼¨¤È¤·¤Æ) |
º£²ó¤ÎChrome¤ÎSHA1Âбþ¥Ý¥ê¥·¤ÎÌäÂêÅÀ
º£²ó¤ÎGoogle Chrome¤ÎSHA1¾ÚÌÀ½ñ¤ËÂФ¹¤ëÂбþ·×²è¤ÏÍÍ¡¹¤ÊÌäÂ꤬¤¢¤ë¤È¹Í¤¨¤Æ¤¤¤Æ¡¢ÏÀÅÀ¤òÀ°Íý¤·¤¿¤¤¤È»×¤¤¤Þ¤¹¡£
- ºÇ¤â½ÅÍפÀ¤È»×¤¦¤Î¤¬¡¢¥Ö¥é¥¦¥¶Ëè¤ËHTTPS¤Î¥¨¥é¡¼¤äÌäÂê¤ËÂФ¹¤ëɽ¼¨¤Î°ÕÌ£¤¬°Û¤Ê¤Ã¤Æ¤·¤Þ¤¦¤È¤¤¤¦ÅÀ¤Ç¤¹¡£º£²ó¤ÎSHA1¾ÚÌÀ½ñ¤Îɽ¼¨¤Î·×²è¤¬¥Ö¥é¥¦¥¶¥Ù¥ó¥À¡¼Ëè¤Ë°Û¤Ê¤ë¤Î¤Ï¥æ¡¼¥¶¤¬º®Í𤹤뤳¤È¤Ë¤Ê¤ê¡¢Îɤ¯¤Ê¤«¤Ã¤¿¤È»×¤¤¤Þ¤¹¡£ËÜÍè¤Ê¤éCA Browser Forum¤ÎBaseline Profile¤Ê¤É¤Ç¡¢¶È³¦¤Ç°Õ»×Åý°ì¤µ¤ì¤¿SHA1¾ÚÌÀ½ñ¤Î°Ü¹Ô·×²è¤ò¼¨¤·¡¢EV¾ÚÌÀ½ñ¤Î¤è¤¦¤Ë½àµò¤¹¤ë¥Ö¥é¥¦¥¶¤ÏƱ¤¸¤è¤¦¤Ê¥¹¥Æ¡¼¥¿¥¹É½¼¨¤Ë¤¹¤ë¤Ù¤¤À¤Ã¤¿¤È»×¤¤¤Þ¤¹¡£
- 2¤Ä¤Î͸ú´ü¸Â¤Î°Û¤Ê¤ë¾ÚÌÀ½ñ¤¬¤¢¤Ã¤Æ¡¢¤½¤Î͸ú´ü¸Â¤Ë¤è¤êɽ¼¨¾õÂÖ¤¬°Û¤Ê¤ë¤È¤¤¤¦¤³¤È¤ÏÌäÂê¤Ç¤¹¡£
º£²ó¤ÏSHA1½ð̾¥¢¥ë¥´¥ê¥º¥à¤Î°Å¹æ´íËز½¤òÌäÂê¤Ë¼è¤ê¾å¤²¤Æ¤¤¤ë¤Î¤Ç¤¹¤«¤é¡¢Í¸ú´ü¸Â¤ÎĹû¤Ë¤«¤«¤ï¤é¤º¡¢¤¢¤ë»þÅÀ¤Ç¤Î°Å¹æ´íËز½¤ÎÄøÅÙ¤ÏÁ´¤¯Æ±¤¸¤Ç¤¢¤ê¡¢Æ±¤¸¤â¤Î¤ËÂФ·¤Æ¤ÏƱ°ì¤ÎHTTPS¥¹¥Æ¡¼¥¿¥¹É½¼¨¤Ë¤¹¤Ù¤¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£
- 2017ǯ1·î1Æü¤«¤é¤ò¡¢SHA1¾ÚÌÀ½ñ¤ò»È¤Ã¤Æ¤Ï¤Ê¤é¤Ê¤¤Æü¤ÈÄê¤á¤¿¤È¤·¤Æ¡¢2ǯ3¥ö·î°Ê¾å¤âÁ°¤Ë¥æ¡¼¥¶¤Ëɽ¼¨¤òÊѤ¨¤ÆÅÁ¤¨¤ëɬÍפ¬¤¢¤ë¤Î¤Ç¤·¤ç¤¦¤«¡£2017ǯ1·î1Æü¤Þ¤Ç¤ÏSHA1¾ÚÌÀ½ñ¤ò»È¤Ã¤ÆÎɤ¤¤È¤¹¤ë¤Ê¤é¡¢¤¤¤«¤Ê¤ë·Ù¹ð¤â¤½¤Î¤³¤È¤Ç½Ð¤¹É¬Íפ¬¤Ê¤¯¡¢¤³¤ì¤Ï¥æ¡¼¥¶¤â¡¢¥¦¥§¥Ö¥µ¥¤¥È±¿±Ä¼Ô¤âº®Í𤵤»¤ë¤À¤±¤Ç¤¹¡£2ǯ°Ê¾å¤âÁ°¤Ëɽ¼¨¤¬°Û¤Ê¤Ã¤Æ¤·¤Þ¤¦¤³¤È¤Ç¡¢¥æ¡¼¥¶¤Ï¥µ¥¤¥È¤Ø¥¯¥ì¡¼¥à¤äÌ䤤¹ç¤ï¤»¤òÆþ¤ì¤ë¤è¤¦¤Ë¤Ê¤ê¡¢¥¦¥§¥Ö¥µ¥¤¥È´ÉÍý¼Ô¤Ï»ÅÊý¤Ê¤¯2ǯÁ°Åݤ·¤ÇSHA2¾ÚÌÀ½ñ¤Ø¤Î°Ü¹Ô¤òÇ÷¤é¤ì¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£
- ºÇ¶á¤Î¥â¥À¥ó¤Ê¥Ö¥é¥¦¥¶¤Ç¤ÏSHA2¾ÚÌÀ½ñ¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¤¬¡¢¸Å¤¤Java¤ä¡¢Áȹþ¤ßµ¡´ï¡¢IC¥«¡¼¥É¡¢¥¬¥é¥±¡¼(¥Õ¥£¡¼¥Á¥ã¡¼¥Õ¥©¥ó)¤Ê¤ÉSHA2¾ÚÌÀ½ñ¤ËÂбþ¤Ç¤¤Ê¤¤´Ä¶¤Ï¡¢Ì¤¤À¤Ë¿¿ô¤¢¤ê¤Þ¤¹¡£¤³¤ì¤é¤Î´Ä¶¤ÈÊâÄ´¤ò¤¢¤ï¤»¤Ê¤¬¤éSSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤ÎSHA2°Ü¹Ô¤ò¿Ê¤á¤ëɬÍפ¬¤¢¤Ã¤¿¤Î¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£
- Á°½Ò¤ÎOS¤Ê¤É¤Î¥ì¥Ù¥ë¤Ç¥¢¥ë¥´¥ê¥º¥à¤È¤·¤ÆSHA2½ð̾¤ò¥µ¥Ý¡¼¥È¤·¤Æ¤¤¤¿¤È¤·¤Æ¤â¡¢¸¡¾Ú¤Ê¤É¤Ç»È¤ª¤¦¤È¤¹¤ëSHA2¾ÚÌÀ½ñ¤Î¥È¥é¥¹¥È¥¢¥ó¥«¤È¤Ê¤ë¥ë¡¼¥È¾ÚÌÀ½ñ¤¬¡Ö¿®Íꤹ¤ë¥ë¡¼¥È¾ÚÌÀ½ñ¡×¥¹¥È¥¢¤ËÆþ¤Ã¤Æ¤¤¤ë¤«¤É¤¦¤«¤ÏÊ̤ÎÌäÂê¡£Î㤨¤ÐÁ´¤Æ¤Î¤ªµÒÍͤ䡢Á´¼Ò°÷¤ÎWindows XP SP3¤ËÂФ·¤Æ¥ë¡¼¥È¾ÚÌÀ½ñ¤òÄɲ䵤»¤ë¤È¤¤¤¦»ö¤Ï¤«¤Ê¤êº¤Æñ¡£
- Netcraft¤Î2014ǯ5·î¤ÎÄ´ºº¤Ë¤è¤ì¤Ð¡¢ ¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Î¥¦¥§¥Ö¥µ¥¤¥È¤Î¤¦¤Á92%¤¬SHA1¾ÚÌÀ½ñ¤Î¤Þ¤Þ¤Ç¤¢¤ê¡¢SHA2¾ÚÌÀ½ñ¤Ø°Ü¹ÔºÑ¤Ê¤Î¤Ï¤ï¤º¤«7%¤Ë¤¹¤®¤Þ¤»¤ó¡£HeartBleedÀȼåÀ¤Î±Æ¶Á¤Ç¾ÚÌÀ½ñ¤Î¥ê¥×¥ì¡¼¥¹¤¬Â¿¤¯¤¢¤Ã¤¿¤¿¤á¡¢SHA2¤Ø¤Î°Ü¹Ô¤Ï¿Ê¤ó¤À¤è¤¦¤Ç¤¹¤¬¡¢¤½¤ì¤Ç¤â¤¿¤Ã¤¿7%¤Ç¤¹¡£¤³¤Î¤è¤¦¤Ê¾õ¶·¤Ç2014ǯ9·î¤Ë¤ÏHTTPS¥¹¥Æ¡¼¥¿¥¹É½¼¨¤òÊѤ¨¤ë¤È¤¤¤¦¤Î¤ÏµÞ¤¹¤®¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£(Äɵ SSLPulse¤Ë¤è¤ë¤È2014ǯ9·î»þÅÀ¤ÇSHA2¤Ï15%¤À¤½¤¦)
- SHA1¾ÚÌÀ½ñ¤ËÂФ¹¤ëɽ¼¨Êѹ¹¤Î¥Ý¥ê¥·¡¼¤ò2014ǯ9·î5Æü¤Ë¥¢¥Ê¥¦¥ó¥¹¤·¤Æ¤«¤é¡¢¤ï¤º¤«21Æü¸å¤Î2014ǯ9·î26Æü¤Î³«È¯ÈÇ¥¢¥Ã¥×¥Ç¡¼¥È¡¢°ÂÄêÈǤǤÏ2014ǯ11·îº¢¤Î39¥ê¥ê¡¼¥¹¤Ç¡¢±Æ¶Á¤ò¼õ¤±¤ë¥µ¥¤¥È¤¬½Ð»Ï¤á¤Þ¤¹¡£½¼Ê¬¤Êͱͽ´ü´Ö¡¢½àÈ÷´ü´Ö¤ò»ý¤Æ¤ë¤è¤¦¤ËÎ㤨¤ÐȾǯ¤ä1ǯ¤È¤¤¤Ã¤¿¥¹¥Ñ¥ó¤Ç»öÁ°¥¢¥Ê¥¦¥ó¥¹¤ò¤¹¤ëɬÍפ¬¤¢¤Ã¤¿¤Î¤Ç¤Ï¤Ê¤¤¤Ç¤·¤ç¤¦¤«¡£
- SSL¥µ¡¼¥Ð¡¼¾ÚÌÀ½ñ¤Ï°ìÈ̤Ë2ǯ¤ä1ǯ¤È¤¤¤Ã¤¿Í¸ú´ü´Ö¤Î¤â¤Î¤ò¹ØÆþ¤µ¤ì¤ëÁÈ¿¥¤¬Â¿¤¤¤È»×¤¤¤Þ¤¹¤¬¡¢Î㤨¤Ð2014ǯ6·î1Æü¤«¤é¡¢¥¢¥Ê¥¦¥ó¥¹¤Î¤¢¤Ã¤¿2014ǯ9·î5Æü¤Ë2ǯʪ¤ÎSHA1¾ÚÌÀ½ñ¤ò¹ØÆþ¤·ÀßÄꤷ¤¿¥¦¥§¥Ö¥µ¥¤¥È¤Ï¡¢Áá®2015ǯ¤Î1Q¤Ë¤Ï¡¢ÌäÂ꤬¤¢¤ë¤«¤Î¤è¤¦¤Ê²«¿§É½¼¨ ¤Ë¤Ê¤ê¤Þ¤¹¡£»öÁ°¤ËÃΤ餵¤ì¤Æ¤¤¤ì¤Ð¡¢1ǯʪ¤òÇ㤦¤È¤«SHA2¾ÚÌÀ½ñ¤òÇ㤦¤È¤«Âкö¤¬¤Ç¤¤¿¤«¤â¤·¤ì¤Þ¤»¤ó¡£ ¤³¤ì¤Ï¡¢¤¢¤Þ¤ê¤ËÉÔ¿ÆÀڤǥ桼¥¶¤ä¥µ¥¤¥È´ÉÍý¼Ô¤Î»ö¤ò¹Í¤¨¤Æ¤¤¤Ê¤¤¹Ô°Ù¤À¤È»×¤¤¤Þ¤¹¡£
- 2017ǯ1·î1Æü°Ê¹ß¤¬Í¸ú´ü¸Â¤Ç¤¢¤ëSHA1¾ÚÌÀ½ñ¤¬¡¢2017ǯ1·î1Æü°Ê¹ß¤Ï»È¤¨¤Ê¤¯¤Ê¤ë¤È¤¤¤¦»ö¤ÏÍý²ò¤Ç¤¤ë¤È¤·¤Æ¡¢2016ǯ6·î1Æü¤«¤é2016ǯ12·î31Æü¤Î´Ö¤Ë͸ú´ü¸Â¤¬¤¢¤ë¾ÚÌÀ½ñ¤òʬ¤±¤Æ¥¢¥é¡¼¥Èɽ¼¨¤ò¤¹¤ëɬÍפ¬¤¢¤ë¤È¤Ï»×¤¨¤Þ¤»¤ó¡£
»²¹Í¤Ë¤¹¤Ù¤¥Ú¡¼¥¸
º£²ó¤ÎChrome¤ÎSHA1°Ü¹Ô¤Ë¤Ä¤¤¤ÆÌäÂêÄ󵯤äÂкö¤Ê¤É¤ò¼¨¤·¤Æ¤¤¤ëÎɤ¤¥Ú¡¼¥¸¤¬¤¢¤ë¤Î¤Ç¡¢¾Ò²ð¤·¤Æ¤ª¤¤¿¤¤¤È»×¤¤¤Þ¤¹¡£
- CSO Online: Do you agree with Google's tactics to speed adoption of SHA-2 certificates?
- CA Security Council¤ÎÃæ¤Î¿Í¤ÎÌäÂêÄ󵯡£¥ª¥ó¥é¥¤¥ó¥·¥ç¥Ã¥×¥¯¥ê¥¹¥Þ¥¹¾¦Àï¤Î»þ¤Ë¤³¤Î¤è¤¦¤ÊÌäÂê¤òµ¯¤³¤¹¤Î¤äÎɤ¯¤Ê¤¤¤È¤â¸À¤Ã¤Æ¤¤¤ë¡£Windows Server 2003¤Ç¤Ïhotfix¤Ê¤·¤Ç¤ÏÈóÂбþ¤À¤È¡£Â¾¤Ë¤â»²¹Í¤Ë¤Ê¤ë¥¢¥É¥Ð¥¤¥¹¤¬¤¢¤ë¡£°Õ¸«¤âÊ罸¤·¤Æ¤¤¤ë¡£
- BLOG: IVAN RISTIC: SHA1 deprecation: what you need to know (2014.09.09)
- SSL¤Î¾õÂÖ¤òÄ´¤Ù¤é¤ì¤ëQualys¤ÎSSLLabs¤òºî¤Ã¤Æ¤¤¤¿¤ê¡¢SSL¤ÎÀßÄꥬ¥¤¥É¤Ê¤É¤ò½ñ¤¤¤Æ¤¤¤ëIvan¤µ¤ó¤Î¥Ú¡¼¥¸¤Ç¡¢º£²ó¤ÎGoogle Chrome SHA1°Ü¹Ô¤Ë¤Ä¤¤¤Æ¡¢¤É¤Î¤è¤¦¤ËÂн褹¤ë¤Î¤¬Îɤ¤¤«²òÀ⤷¤Æ¤¤¤Þ¤¹¡£¤¤¤Ä¤âÎäÀŤÊʬÀϤò¤µ¤ì¤ë¿Í¤Ç¤¹¤¬¡¢º£²ó¤Ë´Ø¤·Èãɾ¤¬Ìµ¤¤¤Î¤Ï¼ä¤·¤¤¡£
- CA Security Council: List of Operating Systems, Browsers, and Servers Which Support SHA-256 Hashes in SSL Certificates (last update Sep 8, 2014)
- ºÇ¿·¤ÎSHA-256¥µ¥Ý¡¼¥È¾õ¶·¤Î¥ê¥¹¥È¤Ç¤¹¡£»²¹Í¤Ë¤Ê¤ê¤Þ¤¹¡£¤Ç¤â¡¢OS¤ä´Ä¶¥ì¥Ù¥ë¤ÇSHA2¤ò¥µ¥Ý¡¼¥È¤·¤¿¤È¸À¤Ã¤Æ¤â¡¢¤³¤ì¤«¤é»È¤ª¤¦¤È¤·¤Æ¤¤¤ëSHA2¾ÚÌÀ½ñ¤Î¥È¥é¥¹¥È¥¢¥ó¥«¤È¤Ê¤ë¥ë¡¼¥È¾ÚÌÀ½ñ¤¬¿®Íꤹ¤ë¥ë¡¼¥È¾ÚÌÀ½ñ¥¹¥È¥¢¤ËÆþ¤Ã¤Æ¤¤¤ë¤«¤ÏÊ̤ÎÌäÂê¡£
¤ª¤ï¤ê¤Ë
Google Chrome¤ÏÎɤ¤¥Ö¥é¥¦¥¶¤À¤È»×¤¦¤·¡¢ÊØÍø¤À¤·¡¢Âç¹¥¤¤Ê¤ó¤Ç¤¹¤¬¡¢CRLSet¤ÎÌäÂê¤È¡¢º£²ó¤ÎSHA1Âбþ¤Î·ï¤Ï¤Á¤ç¤Ã¤È¥Ò¥É¥¤¤Ê¤¡¤È»×¤¤¤Þ¤¹¡£¥µ¥¤¥È¤Î±¿±Ä¼Ô¤ÎÊý¤Ï¡¢ºÇ½é¤Î¥Þ¥¤¥ë¥¹¥È¡¼¥ó¤Î9·î26Æü¤Þ¤Ç¡¢¤¢¤Þ¤ê;͵¤¬¤Ê¤¤¤Î¤Ç¡¢»êµÞ¼«Ê¬¤Î´Ä¶¤òÄ´ºº¤·¤ÆÂкö¤ò¼è¤Ã¤¿Êý¤¬¤¤¤¤¤È»×¤¤¤Þ¤¹¡£º£Æü¤Ï¤³¤ó¤Ê¤È¤³¤í¤Ç¡£
ËÜ¥Ö¥í¥°¤Î´ØÏ¢µ»ö
- ¾ÍèGoogle Chrome¤¬SSL¾ÚÌÀ½ñ¤Î¥ª¥ó¥é¥¤¥ó¼º¸ú¸¡¾Ú¤ò¤ä¤á¤ÆÆȼ«¤Î¼º¸ú¾ðÊó¥×¥Ã¥·¥å¤ò¹Ô¤¦¤È¤¤¤¦º¤¤Ã¤¿ÏÃ(2012.02.13)
- Windows Server 2003¤ÈSHA2¾ÚÌÀ½ñ(2008.08.24) - ¥³¥á¥ó¥È¤Ëhotfix
´ØÏ¢¥ê¥ó¥¯
- Mozilla Security Blog: Phasing Out Certificates with SHA-1 based Signature Algorithms (2014.09.23)
- Mozilla Firefox¤«¤é¤âƱÍͤÎSHA1°Ü¹Ô¥Ý¥ê¥·¡¼¤¬¸ø³«¤µ¤ì¤Þ¤·¤¿¡£
(ÄûÀµ)¥Ð¡¼¥¸¥ç¥óÈÖ¹æ¤Î½¤Àµ(2014.09.17)
¥Ð¡¼¥¸¥ç¥ó38¤¬´û¤Ë¥ê¥ê¡¼¥¹¤µ¤ì¤Æ¤¤¤ë¤È´ª°ã¤¤¤·¤Æ¡¢ º£²ó¤ÎSHA1¥¢¥é¡¼¥Èɽ¼¨¤Î½¤Àµ¤¬¡¢¥Þ¥¤¥Ê¡¼¤ÇÆþ¤ë¤Î¤«¤È´ª°ã¤¤¤·¤¿¤¿¤áɽ¤Î ¥Ð¡¼¥¸¥ç¥ó¤Îɽµ¤¬¤ª¤«¤·¤¯¤Ê¤Ã¤Æ¤¤¤Þ¤·¤¿¤Î¤Ç½¤Àµ¤·¤Þ¤·¤¿¡£ ¥Ð¡¼¥¸¥ç¥ó¤Î³Îǧ¤Ï¤³¤Á¤é¤Ç¤Ç¤¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤ª¤ê¡¢Ä¾¶á¤Î¥á¥¸¥ã¡¼¤Ç¤¹¤È°Ê²¼¤Î¤è¤¦¤Ê¥ê¥ê¡¼¥¹ÍúÎò¤Ç¤¢¤ë¤È¤ï¤«¤ê¤Þ¤·¤¿¡£¤¹¤ß¤Þ¤»¤ó¤Ç¤·¤¿¡£(±Æ¶ÁÆü¤ä¥Ð¡¼¥¸¥ç¥ó¤Ë¤Ä¤¤¤ÆºÆ½¤Àµ¤·¤Þ¤·¤¿9/17 12:50)
- °ÂÄêÈǥ᥸¥ã¡¼ 37.0.2062.94 2014.08.26 for Win,Mac,Linux
- °ÂÄêÈǥ᥸¥ã¡¼ 36.0.1985.125 2014.07.16 for Win,Mac,Linux
- °ÂÄêÈǥ᥸¥ã¡¼ 35.0.1916.114 2014.05.20 for Win,Mac,Linux
- °ÂÄêÈǥ᥸¥ã¡¼ 34.0.1847.116 2014.04.08 for Win,Mac,Linux