
ãã®èšäºã§ã¯ãæ¢åã®DNSæ§é ã®æ¬ ç¹ã.comããã³.orgãã¡ã€ã³ãäŸãšããŠäœ¿çšããŠDNSSECãå®è£
ããå®å
šãªããã»ã¹ãDNSSECã§
眲åããã
æå¹ãªèªå·±çœ²å SSLèšŒææžãäœæããæé ã«ã€ããŠèª¬æããŸãã
äžè¯DNSãšã¯
çŸåšã®åœ¢åŒã®DNSã·ã¹ãã ã¯ãæ
å ±ã»ãã¥ãªãã£ãç¹ã«èããããŠããªãã£ã20幎以äžåã«éçºãããŸããã ããã€ãã®åºæ¬çãªè匱æ§ããããŸãã
DNSãµãŒããŒã®å¿çã®ä¿¡é Œæ§ã¯ã決ããŠãã§ãã¯ãããŸããã ããã«ããããã¡ã€ã³åãã¢ãã¬ã¹æå®ãããŠãŒã¶ãŒãä»»æã®IPã¢ãã¬ã¹ã«éä¿¡ããŠããµãŒããŒã®å¿çã眮ãæããããšãã§ããŸãã å®éã«ã¯ã
ãã®ãããªæ»æã¯æ¬¡ã®ããã«ãªã
ãŸã ã
ã¯ã©ã€ã¢ã³ãã®ãªãŸã«ããŒãšããŠæ©èœãããããã€ããŒã®ãã£ãã·ã¥DNSãµãŒããŒãè匱ã§ãïŒ
ã«ãã³ã¹ããŒæ»æ ã
çŸåšãDNSã¬ã³ãŒãã«å
¬éããŒãä¿åããããã®æè¡ããããŸããããšãã°ãé»åã¡ãŒã«ã®
DKIM眲å ã
SSHFPã¬ã³ãŒãã®SSHããŒãªã©ã§ãã ãããã®æè¡ã¯ãã¹ãŠãDNSåœé ã«å¯Ÿããä¿è·ãå¿
èŠãšããŸãã
DNSSECçè«
DNSSECã¯ãæå·å眲åã䜿çšããŠDNSæ
å ±ã®ä¿¡é Œæ§ãäžæã«æ€èšŒã§ããæè¡ã§ãã
äžè¬çã«DNSSECã«ã€ããŠã¯ã
dxdt.ru /
2009/03/04/2163ã§èªãããšãã§ããŸãã
詳现ã¯ãã¡ãïŒ
habrahabr.ru/blogs/sysadm/120620ãããŠã
Verisign.comã§ç¶è¡ããåã«ãäžèšã®ãªã³ã¯ãæ³šææ·±ãèªãããšã匷ããå§ãããŸãããŸãŒã³ã«çœ²åããæé ãäžèŠæ··ä¹±ããŠããããã«èŠããããã§ãã
å¯èœãªéãã·ã³ãã«ã«ãããã¯æ¬¡ã®ããã«ãªããŸãããã¹ãŠã®ç¬¬1ã¬ãã«ãã¡ã€ã³ã«é¢ããæ
å ±ãå«ãã«ãŒããŸãŒã³ãããããããŸãã æ¯èŒçèšãã°ãããã¯ããã€ãã®è¡ã®ã»ãããæã€ããã¹ããã¡ã€ã«ã§ãããã»ãšãã©å€æŽãããŸããã å
¬é/ç§å¯ããŒã®ãã¢ãäœæããããã®ãã¡ã€ã«ã®åè¡ã眲åãããŸãïŒPGP / GPGã®ãã¯ãªã¢ãµã€ã³ãã¿ã€ãã«ãããããã¹ãã§å
¬ç¶ãšçœ²åããããã«é»åã¡ãŒã«ã§äœ¿çšããããBGPIN PGP SIGNATUREãã§å§ãŸããŸãïŒã
ãã®ãã¢ã®å
¬éããŒãååŸããã®ã§ããã®ãªã¹ãã®åãšã³ããªã®ä¿¡é Œæ§ã確èªã§ããŸãã ããšãã°ãripn.netãµãŒããŒããruããŸãŒã³ãå®éã«æ
åœããŠããããšã確èªããŸãã
dig -t any + dnssec @ k.root-servers.net enãå¿çã§ã¯ãããã·ã¥çœ²åãå«ãRRSIGã¬ã³ãŒãã確èªã§ããŸãã
ããããããã¯ååã§ã¯ãããŸãããããŠã³ã¹ããªãŒã ãµãŒããŒã解決ã«åå ããããããã®çãã確èªããå¿
èŠããããŸãã æ¬¡ã«ããããã¬ãã«ãã¡ã€ã³ã®ææè
ïŒããšãã°ããcomãïŒãåãããŒãã¢ãäœæãããŸãŒã³å
ã®ãã¹ãŠã®ã¬ã³ãŒãã«çœ²åããŠãããå
¬éããŒã®ãã£ã¹ããã«ãŒããŸãŒã³ã«è¿œå ããŸãã ãã®çµæãã«ãŒããŸãŒã³ã®å
¬éããŒãä¿¡é ŒããŠããŸãŒã³ããŒãcomãã®ä¿¡é Œæ§ã確èªã§ããŸããããã«å¿ããŠããããä¿¡é ŒããŸãã
dig -t any + dnssec @ k.root-servers.net comãå¿çã§ã¯ãDSã¬ã³ãŒãã«ã¯ããŸãŒã³ãcomãã眲åãããŠããããŒã®ãã£ã¹ããå«ãŸããŠããŸãã
ãŸãŒã³å
ã®å倿ŽåŸã«çœ²åãæ°ãã«è¡ãããããšãçè§£ããããšãéèŠã§ãã ãã ããã«ãŒããŸãŒã³ã¯ãŸãŒã³ãcomãã®å
¬ééµã®ã¿ã«çœ²åããããããŸãŒã³ãcomãã倿Žããããã³ã«ã«ãŒããŸãŒã³ã®ãšã³ããªãåãã£ãã·ã¥ããå¿
èŠã¯ãããŸããã
ããã§ãcomããã¡ã€ã³ãæ
åœãããµãŒããŒããã®å¿çãèªèšŒã§ããŸãã
dig + dnssec -t any @ a.gtld-servers.net verisign.comããã¡ã€ã³ã¬ã³ãŒããverisign.comã§ããããšãããããŸãã 眲åãããŠããŸããããã®æ®µéã§ã¯ãverisign.comãã¡ã€ã³ãæ
åœããNSãµãŒããŒã®ã¢ãã¬ã¹ã®ä¿¡é Œæ§ã確ç«ããããšããã§ããŸããã IPã¢ãã¬ã¹ã解決ããã«ã¯ããããããå¿çãååŸããå¿
èŠããããŸãããã®ããããããã®NSãµãŒããŒã®ææè
ã¯ç¬èªã®ããŒãã¢ãæã¡ãããã䜿çšããŠãŸãŒã³ã«çœ²åããDSã¬ã³ãŒãã«å
¬éããŒã¹ãããã·ã§ãããå
¥ããŸãã
verisign.comã®Aã¬ã³ãŒãããªã¯ãšã¹ãããŸãã
dig + dnssec -ta verisign.com @ a2.nstld.comãã®çµæãAã¬ã³ãŒãverisign.comã«å€192.5.6.31ãå«ãŸããŠãããšããäºå®ãæ€èšŒããããã«ã次ã®ä¿¡é Œãã§ãŒã³ãæ§ç¯ãããŸãã
ã«ãŒããŸãŒã³ã®å
¬éã㌠"ã"ãäºåã«ç¥ã£ãŠããŸãã ãããŠåœŒãä¿¡é ŒããŠããŸãã ã«ãŒããŸãŒã³ã«ã¯ããcomãå
ã®ãã¹ãŠã®ãšã³ããªãæå®ããDSã¬ã³ãŒãããããŸãããŸãŒã³ã¯ãæå®ãããããŒã§çœ²åãããã¬ã³ãŒãèªäœã¯ãããããã«ãŒããŸãŒã³ããŒã§çœ²åãããŸãã ãã®ãšã³ããªã®ä¿¡é Œæ§ã確èªããåŸããã®ããŒã§çœ²åããããcomããŸãŒã³ã®ãã¹ãŠã®ãšã³ããªãä¿¡é ŒããŸãã comãZoneãæ
åœãããµãŒããŒã«ã¯ãcomãZoneã®ããŒã§çœ²åãããå
¬éããŒverisign.comãå«ãDSã¬ã³ãŒããå«ãŸããŠãããverisign.comãæ
åœããNSãµãŒããŒã®å¿çã§çœ²åã®ä¿¡é Œæ§ãæ€èšŒã§ããŸãã
æŠç¥çã«ã¯ã次ã®ããã«ãªããŸãã

äžèšã®èª¬æã¯éåžžã«åå§çã§ã°ãããŠããŸãã ãæã§ãäœæ¥ããåçã説æããããšãç®çãšããŠæžãããŠããŸãã ãããããããã¯ãŸã£ããçè§£ãåçŽåããããããããã«æ··ä¹±ãããã ãã§ãã
DNSSECå®è£
ãã©ã¯ãã£ã¹
泚æïŒ ãã®åœä»€ã¯æä»£é
ãã§ãã NSEC3ã䜿çšããã«ãŸãŒã³ã«çœ²åãããšããŸãŒã³ã®ãã¹ãŠã®DNSã¬ã³ãŒããæ€åºã§ããŸãã
å®éã®æç€ºwww.digitalocean.com/community/tutorials/how-to-setup-dnssec-on-an-authoritative-bind-dns-server--2
çŸåšã眲åãããŠããã®ã¯ãç¹ã«.netã.comã.orgãªã©ã®äžéšã®ãããã¬ãã«ãã¡ã€ã³ãŸãŒã³ã®ã¿ã§ãã
.ruãŸãŒã³ã¯ãŸã 眲åãããŠããŸããã.uaãŸãŒã³ã¯ãã¹ãã¢ãŒãã§çœ²åãããŠããŸãã.suãŸãŒã³ã¯æ£åŒã«çœ²åãããŠããŸããããããŸã§ã®ãšãããDSã¬ã³ãŒãã®è¿œå ããµããŒãããã¬ãžã¹ãã©ã¯ãããŸããã
ICANN Webãµã€ãã®å®å
šãªãªã¹ããåç
§ããŠãã ããã
ãŸãŒã³ã«çœ²åããã«ã¯ããã®æ©èœããã¡ã€ã³ã¬ãžã¹ãã©ãŒã§ãµããŒããããŠããå¿
èŠããããŸãã çŸæç¹ã§ã¯ãDNSSECããµããŒãããŠããåœå
ã®ã¬ãžã¹ãã©ã«ã€ããŠã¯ç¥ããŸããã DNSããµããŒããã.ruãã¡ã€ã³ã®å§ä»»ãä¿é²ããR01ã¬ãžã¹ãã©ãšdnssec.ru Webãµã€ãã¯ã.ruãŸãŒã³ã眲åãããŠããªãããã銬鹿ããŠããŸãããã®å ŽåãR01ãµãŒããŒã¯ä¿¡é Œãã§ãŒã³ãæ§ç¯ããããã®åºçºç¹ã«ãªããŸãã
ãµããŒããããã®ã®ãã¡ãæå€§ã®ãã®ãåºå¥ã§ããŸãã
- Godaddy.com
- Dyn.com
- 101domain.com
- Gkg.net
UPDïŒçŸåšãnic.ruã¯DNSSEC www.nic.ru/news/2012/dnssec.html ããµããŒãããŠããŸããéšåçãªãªã¹ãã¯
ããã«ãããŸã ã
ã¬ãžã¹ãã©ã«å ããŠãNSSSEC察å¿ã®NSãµãŒããŒãå¿
èŠã§ãã äžéšã®ã¬ãžã¹ãã©ã¯ããã®ãããªãµãŒãã¹ãæäŸããŠããŸãã Godaddyã§æãå®ããªãã·ã§ã³ã¯ããã¬ãã¢ã DNS $ 35 /幎ãšåŒã°ããŸãã dyn.comã§æãé«äŸ¡ãªã®ã¯ãDynECT LiteãšåŒã°ããæé¡30ãã«ã§ãã ãã®èšäºã§ã¯ãBIND 9.7.3ã«åºã¥ããŠç¬èªã®ãã¹ã¿ãŒDNSãµãŒããŒãã»ããã¢ããããäŸã瀺ããŸãã
ããã«ãå®å
šã«æ§æãããç¬èªã®DNSã«å§ä»»ããããã¡ã€ã³ãšã宿ãããŸãŒã³ãã¡ã€ã«ãããããšãåæãšããŠããŸãã
named.confã§DNSSECãµããŒããæå¹ã«ããã«ã¯ããªãã·ã§ã³ã»ã¯ã·ã§ã³ã«è¿œå ããŸãã
ãªãã·ã§ã³{
...
dnssec-enable yes;
...
};
ããŒçæããã³ãŸãŒã³çœ²åããŒã«ã¯ãææ°ã®BINDããã±ãŒãžã«å«ãŸããŠããŸãã
ãã®æ®µéã§ã¯ãèªè
ã¯ãã§ã«ZSKïŒZone Sign KeyïŒãšKSKïŒKey Sign KeyïŒãäœã§ããããç¥ã£ãŠãããšæ³å®ãããŸãã
以äžã®ãã¹ãŠã®æäœã¯ãåå¥ã«äœæããããã©ã«ããŒã§å®è¡ããå¿
èŠããããŸãã
ZSKããŒçæïŒ
dnssec-keygen -a RSASHA1 -b 1024 -n ZONE my-domain.com
KSKããŒçæïŒ
dnssec-keygen -a RSASHA1 -b 2048 -f KSK -n ZONE my-domain.com
my-domain.comã¯ãããŒãçæããããã¡ã€ã³ã§ãã ãããã®ã³ãã³ãã®çµæã2ã€ã®ããŒãã¢ãäœæãããŸãã
次ã«ããŸãŒã³ãã¡ã€ã«ãçŸåšã®ãã©ã«ããŒã«ã³ããŒããŠçœ²åããå¿
èŠããããŸãã
dnssec-signzone -S -N INCREMENT my-domain.com
my-domain.comã¯ãŸãŒã³ããã¹ããã¡ã€ã«ã§ãã ããŒãšãŸãŒã³ãã¡ã€ã«ãšåããã©ã«ããŒã«ã³ãã³ããå®è¡ããããšãéèŠã§ãã ãã¹ãªãã®ãã¡ã€ã«åã
ãã®çµæã2ã€ã®ãã¡ã€ã«ãäœæãããŸãã
my-domain.com.signed-ãŸãŒã³çœ²åãã¡ã€ã«
dsset -
my -
domain.com -2ã€ã®DSã¬ã³ãŒããå«ããã¡ã€ã«
ãœãŒã¹ãŸãŒã³ãã¡ã€ã«ã¯å€æŽãããŸããã æ¬¡ã«ãBINDæ§æã§ããã¡ã€ã«ãçœ²åæžã¿ãã¡ã€ã«ã«çœ®ãæããå¿
èŠããããŸãã
ãŸãŒã³ãmy-domain.comã{
ã¿ã€ããã¹ã¿ãŒ;
ãã¡ã€ã«ãmy-domain.com.signedã;
allow-query {any; };
allow-transfer {....; };
};
ãŸãŒã³ãã¡ã€ã«ã®è©³çްãªäŸã¯ã
nox.suã§è¡šç€ºã§ããŸãã
DNSã®åŸ©å
åãé«ããã«ã¯ãã»ã«ã³ããªãµãŒããŒããå§ãããŸãã DNSSEC察å¿ã®ã¹ã¬ãŒããæäŸããç¡æã®ãµãŒãã¹ãããã€ããããŸãã
http://www.frankb.us/dns/ã®ãªã¹ãã®äžéšã次ã«ç€ºã
ãŸã ã rollernet.usã䜿çšãããããã¢ãã¬ã¹208.79.240.3ããã³208.79.241.3ããã®è»¢éãèš±å¯ããŸãã ã»ã«ã³ããªãµãŒããŒã䜿çšããå Žåã眲åããåã«ããããã«é¢ããã¬ã³ãŒãããŸãŒã³ãã¡ã€ã«ã«ååšããå¿
èŠããããŸãã çœ²åæžã¿ãŸãŒã³ããã¹ã¿ãŒãµãŒããŒã«é
眮ãããåŸã転éãã¢ã¯ãã£ãã«ããããšããå§ãããŸãã
ããã«ãçœ²åæžã¿ãŸãŒã³ã¯æš©åšäž»çŸ©NSãµãŒããŒã§æ¢ã«ãã¹ããããŠãããå€éšããã¢ã¯ã»ã¹å¯èœã§ãããšæ³å®ãããŠããŸãã
dig + dnssec -t any @ super.vip.my.dns.com my-domain.com
ããŒã ã¯çœ²åæžã¿ãŸãŒã³ãè¿åŽããå¿
èŠããããŸãã
ãã®æ®µéã§ãã»ã«ã³ããªãµãŒããŒãã¢ã¯ãã£ãã«ããAXFRãä»ããŠãŸãŒã³ãåæã§ããŸãã
次ã«ããã¡ã€ã³ã¬ãžã¹ãã©ãŒããã«ã§DSã¬ã³ãŒãã远å ããå¿
èŠããããŸãã ãããã¯dnssec-signzoneäžã«çæãããæ¬¡ã®ããã«dsset-my-domainãã¡ã€ã«ã«ãããŸãã
my-domain.comã IN DS 40513 5 1 6198D29A9FB9797719CDFD2316986BDFF5C29323
my-domain.comã IN DS 40513 5 2 1AAB29EC7B67013F45865AEB06D93899B45C598D65A4E4D5522BC39E B5B9212F
ããã¯ãGoDaddyããã«ã«DSã¬ã³ãŒãã远å ããããã®ãã©ãŒã ã§ãã

ç·šéåŸãã詳现ã¢ãŒããã«åãæ¿ããŠãäž¡æ¹ã®è¡ãã³ããŒããå¿
èŠããããŸãã TTLå€ã远å ããããŒã®ãã£ã³ã¬ãŒããªã³ãã®2è¡ç®ã®ã¹ããŒã¹ãåé€ããå¿
èŠããããŸããããããªããšããã©ãŒã ã¯ãšã©ãŒãè¿ããŸãã ãã®çµæãã³ããŒãããè¡ã¯æ¬¡ã®ããã«ãªããŸãã
my-domain.comã 86400 IN DS 40513 5 1 6198D29A9FB9797719CDFD2316986BDFF5C29323
my-domain.comã 86400 IN DS 40513 5 2 1AAB29EC7B67013F45865AEB06D93899B45C598D65A4E4D5522BC39EB5B9212F
ãšã³ããªã远å ãããã®ã¯ããã¹ã¿ãŒãµãŒããŒäžã®ãŸãŒã³ã䜿çšå¯èœã§ãæ£ãã眲åãããŠããå Žåã®ã¿ã§ãã
DSã¬ã³ãŒãã®ãã£ãŒã«ãå€ïŒ
86400-ãã®ãšã³ããªã®TTL
40513-ããŒã¿ã°
5-ã¢ã«ãŽãªãºã
1/2-ãã€ãžã§ã¹ãã¿ã€ã
äžèšã®äŸã§ã¯ãããŒãçæããããã«RSA-SHA1ã¢ã«ãŽãªãºã ã䜿çšããããããã¬ã³ãŒãã¯5çªã§ãã
ã¢ã«ãŽãªãºã çªå·è¡šïŒ
æ° | ã¢ã«ãŽãªãºã |
---|
1 | RSAMD5 |
2 | DH |
3 | DSA / SHA1 |
4 | ECC |
5 | RSA / SHA-1 |
6 | DSA-NSEC3-SHA1 |
7 | RSASHA1-NSEC3-SHA1 |
8 | RSA / SHA-256 |
9 | - |
10 | RSA / SHA-512 |
11 | - |
12 | GOST R 34.10-2001 |
äžèšã®äŸã®ãã€ãžã§ã¹ãã¿ã€ããæåã®ã¬ã³ãŒãã¯1ã2çªç®ã®ã¬ã³ãŒãã¯2ã§ãã
ãã€ãžã§ã¹ãã¿ã€ãçªå·è¡šïŒ
æ° | ãã€ãžã§ã¹ãã¿ã€ã |
---|
1 | SHA-1 |
2 | SHA-256 |
3 | SHA-512 |
Dyn.comãªã©ã®äžéšã®ã¬ãžã¹ãã©ã§ã¯ãDSã¬ã³ãŒãã远å ããããã®ãã©ãŒã ã§ã¯è¡ãã³ããŒã§ããŸãããããã¹ãŠã®ãã£ãŒã«ãã«åå¥ã«å
¥åããå¿
èŠããããŸãã

Dyn.comã«ã¯ãé åºãæ£ãããªããçªå·ã®ã©ãã«ãä»ããŠããªãã¢ã«ãŽãªãºã ã®ãªã¹ãããããããæ··ä¹±ãçããŸãã ãã®ãã©ãŒã ãã远å ããå Žåã2çªç®ã®ããŒã®æçŽã®ã¹ããŒã¹ãåé€ããå¿
èŠããããŸãã
DSã¬ã³ãŒãã远å ããåŸããããã¬ãã«ãã¡ã€ã³ãæ
åœãããµãŒããŒäžã§ãããã®å€èгã確èªã§ããŸãã ãã¡ã€ã³ãcomãã®å Žåãæ¬¡ã®ããã«ãªããŸãã
dig + dnssec -t DS @ a.gtld-servers.net my-domain.com
ãã®å Žåã
Verisignã®
DNSSECãããã¬ãŒãš
眲åãã§ãŒã³ããžã¥ã¢ã©ã€ã¶ãŒã䜿çšããŠããŸãŒã³ãæ£ãã眲åãããŠããããšã確èªã§ããŸãã
ãŸãŒã³ãšã³ããªã倿Žãããã³ã«ãå眲åããå¿
èŠãããããšãæãåºãããŠãã ããã DSã¬ã³ãŒããæŽæ°ããå¿
èŠã¯ãããŸããã
ãã¹ãŠãæ£ãããã°ãã¯ã©ã€ã¢ã³ãåŽã®æ§æã«é²ãããšãã§ããŸãã
ã¯ã©ã€ã¢ã³ããªãŸã«ããŒã®æ§æ
ã¯ã©ã€ã¢ã³ãåŽã§çœ²åãæ€èšŒããã«ã¯ããã®æ©èœãã¢ãã¬ã¹è§£æ±ºãçºçããã·ã¹ãã DNSã§ãµããŒããããŠããå¿
èŠããããŸãã Googleã®ãããªãã¯DNS 8.8.8.8ã¯DNSSECã¬ã³ãŒãããµããŒãããŸãããæ€èšŒããŸããã 詳现ã¯
FAQãã芧
ãã ãã ã
UPDïŒ 2013幎3æ19æ¥ä»¥éãGoogle Public DNSã¯DNSSEC眲åãæ€èšŒããŠãããç¡å¹ãªçœ²åã®å Žåã googleonlinesecurity.blogspot.com / 2013/03 / google-public-dns-now-supports-dnssec.htmlã 解決ããŸãããæãç°¡åãªãªãã·ã§ã³ã¯ã
Firefoxãš
Chromeã®ãã©ã°ã€ã³ã§ãã

ãã®ãã©ã°ã€ã³ã¯ããã€ãã¹ã·ã¹ãã DNSã®è§£æ±ºãå¯èœã«ããDNSSECæ€èšŒããµããŒãããç¬èªã®ãµãŒããŒãäºåã«ã€ã³ã¹ããŒã«ãããŠããŸãã ããã©ã«ãã§ã¯ããã©ã°ã€ã³ã¯ã·ã¹ãã DNSã䜿çšããŸãããã©ã°ã€ã³èšå®ã§ããã倿Žã§ããŸããCZ.NICãŸãã¯217.31.57.6ãéžæããŸã
digãŠãŒãã£ãªãã£ã«çœ²åã®æ€èšŒãæããã«ã¯ãã«ãŒããŸãŒã³ããŒã䜿çšããŠãã¡ã€ã«ãäœæããããšã«ãããä¿¡é Œãã§ãŒã³ã®éå§ç¹ãäœæããå¿
èŠããããŸãã
dig +nocomments +nostats +nocmd +noquestion -t dnskey . > /etc/trusted-key.key
ãã®åŸã
/ etc / trusted-key.keyãã¡ã€ã«ã®è¡ãåé€ããå¿
èŠããããŸãã
;; Truncated, retrying in TCP mode.
ãããè¡ãããªãå Žåãdigã¯ä»¥äžãè¿ããŸãã
No trusted keys present
ããã§ãdigã䜿çšããŠçœ²åã®ä¿¡é Œæ§ãæ€èšŒã§ããŸãã
dig +sigchase @217.31.57.6 whitehouse.gov
çœ²åæ€èšŒæ©èœã䜿çšããŠååž°ãªãŸã«ããŒãæ§æããæ¹æ³ã«ã€ããŠã¯ã
ãã¡ããã芧ãã ãããå®çšçãªã¡ãªãã
DNSSECæšæºã¯ãŸã éçºäžã§ãããšããäºå®ã«ããããããããã§ã«ãã®æ©æµãåããããšãå¯èœã§ãã
SSHå
¬ééµ
SSHãµãŒããŒã«åããŠæ¥ç¶ãããšããã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒã®å
¬éããŒã®ãã£ã³ã¬ãŒããªã³ããåå¥ã«æ€èšŒããyesãå
¥åããããã«èŠæ±ããŸãããã®åŸããµãŒããŒã®å
¬éããŒã¯known_hostsãã¡ã€ã«ã«ä¿åãããŸãã
DNSSECã®åºçŸã«ãããå
¬ééµã¯SSHFPã¿ã€ãã®DNSã¬ã³ãŒãã«é
眮ã§ãããµãŒããŒã«åããŠæ¥ç¶ãããšãã«ãèŠæ±ãªãã§èªåçã«ãã§ãã¯ãããŸãã ãã®æ©èœãæå¹ã«ããã«ã¯ãSSHã¯ã©ã€ã¢ã³ãèšå®ã«VerifyHostKeyDNS = yesãªãã·ã§ã³ã远å ããå¿
èŠããããŸãããŸããã·ã¹ãã ãªãŸã«ããŒãDNSSECæ€èšŒããµããŒãããŠããå¿
èŠããããŸãã
èªå·±çœ²åSSLèšŒææžïŒHTTPSïŒ
UPDïŒ sslããŒãDNSã«ä¿åããããã®æšæºãå
¬éãããDANE ru.wikipedia.org/wiki/DANEãšããååã«ãªã£ãåŸã以äžã¯ãã¯ãé¢ä¿ãããŸãããGoogleã¯ChromeããDANEãµããŒããåé€ããŸããã Chromeéçºè
github.com/agl/dnssec-tls-tools/issues/4ãšã®ãã£ã¹ã«ãã·ã§ã³DNSSECã䜿çšãããšããã©ãŠã¶ã§ãæå¹ãã«ãªãSSLèšŒææžã«åå¥ã«çœ²åã§ããŸãã
ãã®å®éšçãªæ©èœã¯çŸåšæŽ»çºã«éçºãããŠãããçŸåšGoogle Chrome / Chromiumãã©ãŠã¶ã§ã®ã¿ãµããŒããããŠããŸãã
ãã©ããæšæºïŒ
tools.ietf.org/html/draft-agl-dane-serializechain-01ãã®æè¡ã¯ãAdam Langleyãšããååã®GoogleåŸæ¥å¡ã«ãã£ãŠéçºãããŠããã圌ã«ã¯éåžžã«è峿·±ãããã°
http://www.imperialviolet.org/ããããŸã ã
ãã®æè¡ã«é¢ãã
æçš¿ ã
ããã«ãèšŒææžãçæããããã¡ã€ã³ã¯DNSSECã«ãã£ãŠçœ²åãããŠãããšæ³å®ãããŠããŸãã
dnssec-tls-toolsãããŠã³ããŒãããŸãã
git clone gitïŒ//github.com/agl/dnssec-tls-tools.git
ãããŠã³ã³ãã€ã«ïŒ
gcc -o gencert gencert.c -Wall -lcrypto
RSAããŒçæïŒ
openssl genrsa 1024> privkey.pem
openssl rsa -pubout -in privkey.pem> pubkey.pem
ããŒãã£ã³ã¬ãŒããªã³ãã®äœæïŒ
python ./gencaa.py pubkey.pem
dnssec-tls-toolsããã±ãŒãžã®gencaa.pyãã¡ã€ã«ã¯ã©ãã«ãããŸãã
ã³ãã³ãã¯æ¬¡ã®åœ¢åŒã®è¡ãè¿ããŸãã
EXAMPLE.COMã 60ã¿ã€ã257 \ïŒ70 020461757468303e3039060a2b06010401d6790203010 ...
ããã¯ãEXAMPLE.COMã®ä»£ããã«ãŸãŒã³ãã¡ã€ã«ã«è¿œå ããå¿
èŠãããDNSã¬ã³ãŒãã§ãã ãã®æå³ã ãŸãŒã³ããŸã 眲åãããŠããªãå Žåã¯ããããè¡ãå¿
èŠããããŸãã ã¬ã³ãŒããæ¢ã«çœ²åæžã¿ã®ãŸãŒã³ã«è¿œå ãããŠããå Žåããããã眲åãå床å®è¡ããå¿
èŠããããŸãã
DNSã®æ£ããããŒã確èªããŸãã
dig + dnssec + sigchase -t type27 example.com
ã³ãã³ãã¯ã
DNSSECæ€èšŒãæ£åžžã§ããããšãè¿ãå¿
èŠããã
ãŸãïŒSUCCESStype27ã¬ã³ãŒãã䜿çšå¯èœã«ãªã眲åãããåŸãDNSSECä¿¡é Œãã§ãŒã³ãçæã§ããŸãã
python ./chain.py example.comãã§ãŒã³
ãããŠãèšŒææžèªäœïŒ
./gencert privkey.pem chain> cert.pem
Nginxã§èšŒææžãæ¥ç¶ãããšæ¬¡ã®ããã«ãªããŸãã
ãµãŒããŒ{
...
ssl on;
ssl_certificate cert.pem;
ssl_certificate_key privkey.pem;
...
}
DNSSEC眲åãã§ãŒã³ã¯å€æŽãããå¯èœæ§ãããããããã§ãŒã³ã®äœæãšèšŒææžã®çæïŒæåŸã®2ã€ã®ã³ãã³ãïŒãã¯ã©ãŠã³ã«è¿œå ããŠãããšãã°1æ¥ã«1åå®è¡ããå¿
èŠããããŸãã
çµæã¯æ¬¡ã®ããã«ãªããŸãïŒ
https :
//dnssec.imperialviolet.org/DNSSECãã§ãŒã³å
šäœãèšŒææžã«é
眮ããããšããäºå®ã«ããããã©ãŠã¶ã¯å®å
šãªãã§ãŒã³ãã§ãã¯ãå®è¡ããå¿
èŠããªããããã·ã¹ãã ãªãŸã«ããDNSSECæ€èšŒããµããŒãããŠããªããŠãèšŒææžã¯ãæå¹ãã«ãªããŸãã
PSãã®èšäºã§ã¯ãDNSSECããŒã®æå¹æ§ã«ã€ããŠã¯èª¬æããŠããŸããã代æ¿ã®DLVEC Look-aside Validation DLVä¿¡é Œãã§ãŒã³ã«ã€ããŠã¯èª¬æããŠããŸããã ãããã®åé¡ãçè§£ãã説æããŠããã人ã
ã«æè¬ããŸãã
PPSç§ã¯ããã®ãããªã¿ãŒã³ããŒã¹ã®HOWTOããçè§£ããã«ããŒã ãç¡æèã«ã³ããŒããããšã«ã€ãªããæªåœ±é¿ãç¥ã£ãŠããŸãã ãããããã®åé¡ã«é¢ããæ
å ±ãã»ãšãã©ãªããäžéšã®å Žæã§ã¯ççŸããŠãããšããäºå®ã«ããããã®èšäºãç§ãçŽé¢ããªããã°ãªããªãã£ãæ··ä¹±ã誰ããé¿ããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã åè°ãš
圌ã®èšäºãããã
Alexander Venedyukhinã«æè¬ããŸãã