ãšã³ã¿ãŒãã©ã€ãºèšŒææ©é¢ã«é¢ããäžé£ã®èšäºãç¶ããŸãã 仿¥ã¯ãå
¬éããŒãã€ã¢ã°ã©ã ã®äœæãèšŒææ©é¢ã®ååã®èšç»ãèšŒææžå€±å¹ãªã¹ãã®èšç»ãããã³ãã®ä»ã®ãã€ã³ãã«ã€ããŠèª¬æããŸãã ä»ããåå ãããïŒ

ã·ãªãŒãºã®æåã®éšå
ã·ãªãŒãºã®ç¬¬3éš
ã¯ããã«
çšèªé
ãã®ã·ãªãŒãºã§ã¯ã次ã®ç¥èªãšç¥èªã䜿çšãããŸãã
- PKI ïŒ å
¬ééµã€ã³ãã©ã¹ãã©ã¯ã㣠ïŒ-ç§å¯éµãšå
¬ééµã«åºã¥ãæå·åã¿ã¹ã¯ããµããŒãããããã«äžç·ã«äœ¿çšããããå
¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ãäžé£ã®ããŒã«ïŒæè¡ãææã人éãªã©ïŒã忣ãµãŒãã¹ããã³ã³ã³ããŒãã³ãã ç¥èªPKIã¯äžè¬çã§ã¯ãªãããã以äžã§ã¯ããã銎æã¿ã®ããè±èªã®ç¥èªPKIã䜿çšãããŸãã
- X.509ã¯ãå
¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ããã³ç¹æš©ç®¡çã€ã³ãã©ã¹ãã©ã¯ãã£ã®ITU-Tæšæºã§ãã
- CA ïŒ èªèšŒå± ïŒ-ããžã¿ã«èšŒææžãçºè¡ãããµãŒãã¹ã èšŒææžã¯ãå
¬ééµãææè
ã«å±ããŠããããšã確èªããé»åææžã§ãã
- CRL ïŒ èšŒææžå€±å¹ãªã¹ã ïŒ-èšŒææžå€±å¹ãªã¹ãã CAã«ãã£ãŠçºè¡ãããå€éšã®çç±ã«ããæå¹æ§ãçµäºãã倱å¹ããèšŒææžã®ãªã¹ããå«ã眲åä»ãé»åææžã 倱å¹ããèšŒææžããšã«ãã·ãªã¢ã«çªå·ã倱å¹ã®æ¥ä»ãšæå»ãããã³å€±å¹ã®çç±ïŒãªãã·ã§ã³ïŒã瀺ãããŸãã ã¢ããªã±ãŒã·ã§ã³ã¯ãCRLã䜿çšããŠãæç€ºãããèšŒææžãæå¹ã§ãããçºè¡è
ã«ãã£ãŠåãæ¶ãããŠããªãããšã確èªã§ããŸããã¢ããªã±ãŒã·ã§ã³ã¯ãCRLã䜿çšããŠãæç€ºãããèšŒææžãæå¹ã§ãããçºè¡è
ã«ãã£ãŠåãæ¶ãããŠããªãããšã確èªã§ããŸãã
- SSL ïŒ Secure Sockets Layer ïŒãŸãã¯TLS ïŒ Transport Layer Security ïŒã¯ããªãŒãã³ãããã¯ãŒã¯ãä»ããã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®ããŒã¿è»¢éã®ã»ãã¥ãªãã£ãä¿èšŒããæè¡ã§ãã
- HTTPS ïŒ HTTP / Secure ïŒ-ã»ãã¥ã¢HTTPã¯ãSSLã䜿çšããç¹æ®ãªã±ãŒã¹ã§ãã
- ã€ã³ã¿ãŒãããPKIã¯ããªãŒãã³ããŒã¿éä¿¡ãã£ãã«äžã®X.509æšæºã«åºã¥ããŠããŒã¿éä¿¡ãä¿è·ããããã®åäžã®ïŒçµ±äžãããïŒã¡ã«ããºã ãæäŸããäžé£ã®æšæºãåæãæé ãããã³å®è·µã§ãã
- CPS ïŒ Certificate Practice Statement ïŒã¯ãå
¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ãšããžã¿ã«èšŒææžã管çããããã®æé ã説æããææžã§ãã
äžè¬çãªèšç»ã®åé¡
æè¡çãªãœãªã¥ãŒã·ã§ã³ãå®è£
ããã«ã¯ãæ
éãªèšç»ãå¿
èŠã§ãã PKIå®è£
ãäŸå€ã§ã¯ãããŸããã ããã«ãç¹å®ã®ã±ãŒã¹ã§åæèšç»ã®ãšã©ãŒãæ¯èŒçè¿
éãã€ç°¡åã«ä¿®æ£ã§ããå ŽåãPKIã§ã¯ééããªãããã§ã¯ãããŸããã ãã§ã«è¿°ã¹ãããã«ãPKIãµãŒãã¹ã¯ãäœæ¥äžã«æå°éã®ïŒãŸãã¯éèŠã§ã¯ãªãïŒå€æŽãè¡ãã ãã§é·å¹Žæ©èœããããã«èšèšãããŠããŸãã
ããšãã°ãCAèšŒææžã®æå¹æéã¯çŽ10ã20幎ã§ãã ãã®ãããªé·ã寿åœã®çç±ã®1ã€ã¯ããããã®èšŒææžã®åçºè¡ã«ã¯å€å°æéããããæäœã§ããã倿°ã®é¡§å®¢ã®å€æŽãå¿
èŠã«ãªãå¯èœæ§ãããããšã§ãã ããã¯ãã¢ã¯ã»ã¹ã§ããªãã¯ã©ã€ã¢ã³ãã§ã倿Žãå¿
èŠã«ãªããšããäºå®ã«ãã£ãŠæªåããŸãã ãã1ã€ã®ãã€ã³ãã¯ãPKIã¢ãŒããã¯ãã£ã«å€æŽãå ããå Žåãçºè¡ãããèšŒææžã®æå¹æéäžã¯çŸåšã®æ§æãç¶æããå¿
èŠããããšããããšã§ãã ã€ãŸããæ°ããæ§æã¯æ°ããèšŒææžã«å¯ŸããŠæ©èœããŸããããããšäžŠè¡ããŠãæ¢ã«çºè¡ãããèšŒææžãæ£ããæ©èœããããã«ä»¥åã®æ§æãç¶æããå¿
èŠããããŸãã ããã«ãããPKIãå¥å
šãªç¶æ
ã«ç¶æããããšãé£ãããªããŸãã
ãããã®ç¹ãèæ
®ãããšãPKIèšç»ã«ã¯æãæ·±å»ãªæ¹æ³ã§ã¢ãããŒãããå¿
èŠããããŸãã ãããŠãPKIãããžã¿ã«ã»ãã¥ãªãã£ãé·æéã«ããã£ãŠç¢ºå®ã«æ©èœãããããšã«æåããã®ã¯åããŠã§ãã
倿®µéèšç»ããã»ã¹ã¯ãéžæããã¢ãã«ã®è«çå³ã«åºã¥ããŠããŸãã åæ®µéã§ããã€ã¢ã°ã©ã ã®èŠçŽ ãæ¡åŒµïŒè©³çްïŒããããã®ããã«æ¥ç¶ãã¿ã¹ã¯ãããã³èŠä»¶ã圢åŒåãããŸãã å¿
èŠã«å¿ããŠãå®å
šã«åœ¢åŒåãããã·ã¹ãã ãåŸããããŸã§è©³çްåãç¶ããããŸãã ãã®èšäºã§ã¯ããã®èšç»ã¢ãããŒãã®äŸã瀺ããŸãã
PKIãã£ãŒã
å
ã»ã©èšã£ãããã«ããã¹ãŠã¯éžæããã¢ãã«ã®è«çå³ããå§ãŸããŸãã è«çå³ã«ã¯ãã¹ãŠã®PKIã³ã³ããŒãã³ãã衚瀺ããããããç©çããããžã«ã·ããããå¿
èŠããããŸãã 2ã¬ãã«ã®PKIã¢ãã«ãé©çšããå Žåããã®ãããªå³ã¯æ¬¡ã®åœ¢åŒããšããŸãã

ãã®å³ã¯ã次ã®ã³ã³ããŒãã³ããšãã®è«çæ¥ç¶ã瀺ããŠããŸãã
- ã«ãŒãCA âäžäœCAã«ã®ã¿èšŒææžãçºè¡ãããã®èšŒææžãšå€±å¹ãªã¹ãã倱å¹ãµãŒããŒã«å
¬éããŸãã
- äžäœïŒäžéïŒCA-ãšã³ããŠãŒã¶ãŒã«èšŒææžãçºè¡ãããã®èšŒææžãšå€±å¹ãªã¹ãã倱å¹ãµãŒããŒã«å
¬éããŸãã åæã«ã倱å¹ãµãŒããŒããã«ãŒãCA倱å¹ãªã¹ããããŠã³ããŒãããŸãã
- 倱å¹ãµãŒã㌠-CAèšŒææžãšãã®å€±å¹ãªã¹ãã®ãªããžããªã§ãããä»»æã®ã¯ã©ã€ã¢ã³ããããŠã³ããŒãã§ããŸãã
- ã¯ã©ã€ã¢ã³ãæ¥ç¶ -äžäœCAããèšŒææžãåãåãã倱å¹ãµãŒããŒãã倱å¹ãªã¹ããããŠã³ããŒãããŸãã
ç©çããããžã¯ãããã«ç°ãªããæ¬¡ã®åœ¢åŒã«ãªããŸãã

ç©çããããžã¯ãã¯ã©ã€ã¢ã³ããã©ãã§ãèšŒææžãæ€èšŒã§ããããã«ããããã¯ãŒã¯ã®å
å€ã®ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã倱å¹ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããããšãæç€ºçã«åŒ·èª¿ããŠããŸãã
CAåã®èšç»
CAåã¯ãç¹å®ã®CAã®[
Subject
ãã£ãŒã«ãã«è¡šç€ºãããååã§ãã èšŒææžãµãŒãã¹ã®ãã¹ãåãšæ··åããªãã§ãã ããã CAã®ãã«ããŒã ã¯ãååèªäœïŒCN屿§ãŸãã¯å
±éåïŒãšX.500圢åŒã®ãªãã·ã§ã³ã®ãµãã£ãã¯ã¹ã®2ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŸãã ããã©ã«ãã§ã¯ãADCSã¯æ¬¡ã®åœ¢åŒã§ååãå²ãåœãŠãŸãã
ã¹ã¿ã³ãã¢ãã³CAã®å ŽåïŒ<
ComputerName
>
CA
ãšã³ã¿ãŒãã©ã€ãºCAã®å ŽåïŒ<
DomainShortName
>-<
ComputerName
>
CA,
<
X500DomainSuffix
>
è¯ãã§ããããããšãæªãã§ããïŒ æè¡çã«ã¯ãä»»æã®ååãéžæã§ããŸãããæ©èœçã«ã¯äœã«ã圱é¿ããŸããã CAã®ååã¯äœããã®åœ¢ã§PKIã®ååºã§ãããæ©èœã«çŽæ¥é¢ä¿ããŠããªããååãªã¬ãã«ã®æ
å ±ãšå
¬éæ§ãæäŸãã詳现ã«å¯Ÿããæ
床ãåæ ããŠãããšèããããŠããŸãã ãããã£ãŠãèšŒææžã®ãã«ããŒã ãéžæãããšãã¯ãããã€ãã®æšå¥šäºé
ã«åŸãå¿
èŠããããŸãã
- ååã¯ãçµç¹ã®ååïŒçç¥ãããŠããå ŽåããããŸãïŒããã³éå±€å
ã®ç¹å®ã®CAã®åœ¹å²ïŒå±æ§CNãå
±éåïŒãåæ ããå¿
èŠããããŸãã
- æ¥å°ŸèŸã¯ãOUïŒçµç¹åäœïŒå±æ§ã§ã®ç®¡çãæ
åœããéšéãŸãã¯åäœã®ååãåæ ããå¿
èŠããããŸãã
- çµç¹ã®ãã«ããŒã ãè€è£œããŸãïŒå±æ§Oãçµç¹ïŒã
- CAã®æ³çãªå Žæã ãããè¡ãã«ã¯ã屿§LïŒå°åïŒããã³CïŒåœïŒã䜿çšããã ãã§ååã§ãã ååãšããŠãããã¯çµç¹ãæ³çã«ç»é²ãããŠããéœåžãšåœã®ååã§ãã å¿
èŠã«å¿ããŠãSïŒå·ïŒå±æ§ã䜿çšããŠå·/å°åãæå®ã§ããŸãã
ã©ããã¢ã®ãªã¬ã«ããContoso Pharmaceuticals Ltd.ãšããäŒç€Ÿã®ã«ãŒãCAã®ååãéžæãã管çãæ
å ±æè¡éšéã«ãã£ãŠæäŸãããŠãããšããŸãã ãã®å ŽåãCAã®ååã¯æ¬¡ã®ããã«ãªããŸãã
CN=Contoso Pharm Root Certification Authority, OU=Division Of IT (DoIT), O=Contoso Pharmaceuticals Ltd., L=Riga, C=LV
Country屿§ã¯2æåã®åœã€ã³ããã¯ã¹ã®ã¿ããµããŒãããããšã«æ³šæããŠãã ããã ããšãã°ãLVãGBãRUãUSãªã©ã 远å ã®äŸãšããŠãVeriSign / SymantecãDigiCertãªã©ã®åçšãããã€ããŒã®CAèšŒææžãåç
§ã§ããŸãã äžäœCAã®å Žåããã®ååã¯äŒŒãŠããŸãããååã®RootãšããèªãSubordinateãŸãã¯Issuingã«çœ®ãæããããç¹ãç°ãªããŸãã ããªã·ãŒCAãæç¢ºã«å²ãåœãŠãããŠãã3ã¬ãã«ã®éå±€ã®å Žåãã«ãŒããšããèªã¯ããªã·ãŒã«çœ®ãæããããŸãã äžã§è¿°ã¹ãããã«ãä»ã®ã«ãŒã«ãäŒç€Ÿã«é©çšãããå ŽåããããããããCAã®ååã§å®è£
ã§ããŸãããããã¯æ©èœã«åœ±é¿ããŸããã ãã®éã以äžãé¿ããŠãã ããïŒ
- CN屿§ã®ååãé·ãããïŒæå€§50æåïŒã CN屿§ã51æåããé·ãå Žåãååã®æåŸã«ç Žæ£ãããååã®ãã©ã°ã¡ã³ãã®ããã·ã¥ããããã³ã°ããããšã«ããççž®ãããŸãã ããã¯ãè¡çãããã»ã¹ãšåŒã°ãããããã³ã«[ MS-WCCE ]ã®3.1.1.4.1.1ã§èª¬æãããŠããŸãã ã€ãŸã ååãé·ããããšãåèªãéäžã§éåããŠèŠãç®ãæªããªãããšããããŸãã
- ã©ãã³ã¢ã«ãã¡ãããã®äžéšã§ã¯ãªãæåãã€ãŸã ã¯ãªãªãã¡ãŸãã¯åŒèšŒæ³ã®æåïŒÄãÅŸãÃãáºãªã©ïŒã¯ãããŸããã ADCSã¯ãCN屿§ããã³å¶éãããæåã»ããã®ã·ã³ã°ã«ãã€ããšã³ã³ãŒãã£ã³ã°ã®ã¿ããµããŒãããŸãã ãµããŒããããŠããªãæåã¯å¥ã®ãšã³ã³ãŒãã«å€æãããèªã¿åãäžèœã«ãªããŸãã çŠæ¢æåã®å®å
šãªãªã¹ãã¯ã[ MS-WCCE ]ãããã³ã«ã®Â§3.1.1.4.1.1.2ã§æäŸãããŠããŸãã ãæé«ã¯åã®æµã§ããããšããååãããã§æ©èœããã®ã§ãååã¯ç°¡æœã§ååãªæ
å ±ãæäŸããå¿
èŠããããŸãã
èšç»ã¬ãã¥ãŒãªã¹ãïŒCRLïŒ
è«çå³ã«åŸã£ãŠãåCAã¯ãã®ã¬ãã¥ãŒãªã¹ããå
¬éããŸãã ã¬ãã¥ãŒãªã¹ãã¯ãäž»ã«2ã€ã®ã«ããŽãªã§ç¹åŸŽä»ããããŸãã
- ãªã³ãŒã«ãªã¹ãã®å
¬éããã³é
åžã®ãã€ã³ãã
- ãªã³ãŒã«ãªã¹ãã®æ§æãšæå¹æ§ã
ãªã¹ãã®å
¬éããã³é
åžãã€ã³ãã®ã¬ãã¥ãŒ
倱å¹ãªã¹ããå
¬éããã«ã¯ã2çš®é¡ã®CRLé
åžãã€ã³ãã䜿çšãããŸããå
¬éãã€ã³ãïŒç©çãã¡ã€ã«ãæžã蟌ãŸããå ŽæïŒãšãã¡ã€ã«ã®é
åžãã€ã³ãïŒåä¿¡ïŒã§ãã
æåã®ã¿ã€ãã®ãã€ã³ãã¯ããã¡ã€ã«ãæžã蟌ãŸããããŒã«ã«ãŸãã¯ãããã¯ãŒã¯ãã¹ïŒUNC圢åŒïŒã瀺ããŸãã 2çªç®ã®ã¿ã€ãã®ãã€ã³ãã¯ãçºè¡ãããèšŒææžã«ç»é²ããã顧客ãã¬ãã¥ãŒãªã¹ããããŠã³ããŒãã§ããæ¹æ³ã瀺ããŸãã ãããã®ãã¹ã¯ãCRLé
åžãã€ã³ãã®èšŒææžæ¡åŒµæ©èœã§å
¬éãããŸãã éåžžããããã®ãã¹ã¯äžèŽããŸããïŒå
¬éãã¹ãšé
åžãã¹ãåãLDAPãé€ãïŒã å
¬éãã€ã³ããæ±ºå®ããéã«ã¯ã次ã®èŠåã«åŸã£ãŠãã ããã
- ã«ãŒãCAã®å Žåããã®ãµãŒããŒã¯ãããã¯ãŒã¯ããéé¢ããããããå³å¯ã«ããŒã«ã«ãªãã¹ãæå®ãããŸãã ãã¡ã€ã«ã®é
åžãµãŒããŒïŒIISïŒãžã®ã³ããŒã¯æåã§è¡ãããŸãã ã«ãŒãCAã®ã¬ãã¥ãŒãªã¹ãã®å
¬éé »åºŠã¯æåäœã§æž¬å®ããããããããã¯åé¡ã§ã¯ãããŸããïŒè©³çްã«ã€ããŠã¯ä»¥äžãåç
§ããŠãã ããïŒã
- çºè¡CAã®å Žåããããã¯ãŒã¯ãã¹ã瀺ãããŸãã DFSã§å
±æãã©ã«ããŒãäœæããããšããå§ãããŸããããã¯ãIISã§ä»®æ³ãã£ã¬ã¯ããªãšããŠç°¡åã«å®çŸ©ã§ããŸãã ãã®å Žåãç©çãã¡ã€ã«ãé
åžãã€ã³ãã«å
¬éããããã»ã¹ã¯å®å
šã«èªååãããŸãã
- 倱å¹ãªã¹ãã®å
¬éããã³é
åžã«LDAPã䜿çšããªãã§ãã ããã
CRLé
åžãã€ã³ããšæ©é¢æ
å ±ã¢ã¯ã»ã¹ã®æ¡åŒµãšãã©ã¯ãã£ã¹ã®èšç»ã®è©³çްã«ã€ããŠã¯ãããã°æçš¿ã
CRLé
åžãã€ã³ããšæ©é¢æ
å ±ã¢ã¯ã»ã¹ã®å Žæã®èšèš ããåç
§ããŠãã ããã
ãªã¹ãæ§æã®ã¬ãã¥ãŒ
ãªã³ãŒã«ãªã¹ãã®æ§æãšæå¹æ§ãèšç»ããåã«ããªã³ãŒã«ãªã¹ãã®ç®çãšãã®åäœæ¡ä»¶ã«å¿ããæé©ãªãã©ã¡ãŒã¿ãŒãçè§£ããå¿
èŠããããŸãã ãåç¥ã®ããã«ãåCAã¯å®æçã«ã¬ãã¥ãŒãªã¹ããçºè¡ããŸããããã«ã¯ãç¹å®ã®CAã«ãã£ãŠå€±å¹ãããã¹ãŠã®èšŒææžã®ãªã¹ããå«ãŸããŸãã ããã«ãåãªã¹ãã«ã¯ãCAã®å
šæéã«ããããã¹ãŠã®å€±å¹ããèšŒææžãå«ãŸããŸãã ããšãã°ãCAã®å¯¿åœã10幎ã®å Žåããã®ãªã¹ãã¯å°è±¡çãªãµã€ãºïŒæ°ã¡ã¬ãã€ãã®ãªãŒããŒïŒã«æé·ããå¯èœæ§ããããŸãã
é«éæ¥ç¶ã§ãã£ãŠãã倱å¹ãªã¹ãã®ãã©ãã£ãã¯ã¯ããªãã®ãµã€ãºã«ãªããŸãã ãã¹ãŠã®èšŒææžã®æ¶è²»è
ã«ã¯ææ°ã®æ¹èšãªã¹ããå¿
èŠã§ãã
倱å¹ãªã¹ãã®ãã©ãã£ãã¯ãæžããããã«ã2ã€ã®ã¿ã€ãã®CRLãã€ãŸãåºæ¬ïŒããŒã¹CRLïŒãšå·®åïŒãã«ã¿CRLïŒãå
¬éãããŸãã ããŒã¹ãªã¹ãã«ã¯ãå®å
šãªã¬ãã¥ãŒãªã¹ããå«ãŸããŠããŸãã å·®åãªã¹ãã«ã¯ãããŒã¹CRLã®æåŸã®çºè¡ä»¥éã«å€±å¹ãã倱å¹ããèšŒææžã®ãªã¹ãã®ã¿ãå«ãŸããŸãã ããã«ãããåºæ¬ãªã¹ããããé »ç¹ã«ãããé·æéå
¬éããããšãã§ããééå
ã®å€±å¹ããèšŒææžã«å¯Ÿããã¯ã©ã€ã¢ã³ãã®å¿çæéãççž®ããŠãããã€ãã®çåœãªå·®åCRLãçºè¡ã§ããŸãã
ãã©ã¡ãŒã¿ã®éžæã¯ãããã€ãã®èŠå ã«äŸåããŸãã ããšãã°ãçºè¡ãããèšŒææžã®èšç»ããªã¥ãŒã ãšå€±å¹ã®èšç»ããªã¥ãŒã ã å
žåçãªã·ããªãªãæ€èšããŠãã ããã
ã«ãŒãCAã«ãŒãCAã¯ãäžéCAã«ã®ã¿èšŒææžãçºè¡ããŸããäžéCAã®æ°ã¯éåžžã1ããŒã¹ä»¥å
ã§ãã äžéCAã®æå¹æéã¯ãã«ãŒãCAèšŒææžã®æå¹æéãšåçã§ãã ãŸããäžäœCAã¯èšç·Žãããæ
åœè
ã«ãã£ãŠç®¡çãããé©åãªã»ãã¥ãªãã£å¯Ÿçã宿œãããŠãããããäžäœCAããªã³ãŒã«ãããªã¹ã¯ã¯éåžžã«äœããšæ³å®ãããŠããŸãã ãããã£ãŠã倱å¹ãªã¹ãã®ããªã¥ãŒã ã«ã¯å°æ°ã®å€±å¹ããèšŒææžã®ã¿ãå«ããããšãã§ãããããCRLãã¡ã€ã«ã®ãµã€ãºãå°ããããšãä¿èšŒããããšèšããŸãã
ãã«ãïŒã¬ãã¥ãŒã®ãµã€ãºã«åºã¥ããŠCRLãã¡ã€ã«ã®èšç»ãµã€ãºãèšç®ããæ¹æ³ã¯ïŒ äžè¬çãªç©ºã®CRLã«ã¯çŽ600ã800ãã€ããå¿
èŠã§ãã åèšŒææžå€±å¹ã¬ã³ãŒãã¯88ãã€ãã§ãã ãããã®å€ã«åºã¥ããŠã倱å¹ããèšŒææžã®æ°ã«å¿ããŠCRLãµã€ãºãèšç®ã§ããŸãããããã£ãŠãã«ãŒãCAãåç¶ããéããªã³ãŒã«ãªã¹ãã¯1kb以å
ã«ãªããå·®åCRLã«ã¯æå³ããããŸããã
CAã®å
¬éçºè¡å
CAã®å Žåãç¶æ³ã¯å€åããŠããŸãã çºè¡ãããèšŒææžã®éã¯ãã§ã«å€ããæ°åããã³æ°çŸäžåã«ãªããŸãã æ¶è²»è
ãšã¯ãæè³æ Œè
ã«ãã£ãŠçµ¶ããç£èŠãããŠããããé©åãªææ®µãæäŸã§ããªãããããªã³ãŒã«ã®ãªã¹ã¯ãé«ããŠãŒã¶ãŒããã³ããã€ã¹ã§ãã ãã®çµæãã¬ãã¥ãŒãªã¹ãã¯æ·±å»ãªãµã€ãºã«éããå¯èœæ§ããããŸãã ããšãã°ã倱å¹ã®ãªã¹ã¯ã10ïŒ
ã«ãããšãçºè¡ããã100äžã®èšŒææžã«å¯ŸããŠçŽ10äžã®å€±å¹ããããŸãã 88ãã€ãã®100kã¬ã³ãŒãã¯10mbæªæºã§ãã å€ãã®å Žåã10 mbããšã«ãã¡ã€ã«ãæŽæ°ããããšã¯ããŸãå®çšçã§ã¯ãªããçºè¡é »åºŠãå°ãªãããŠãã¡ã€ã³CRLã®çºè¡ééã§ããã€ãã®è»œéå·®åDelta CRLãé
åžããæ¹ã䟿å©ã§ãã ã€ãŸã ã«ãŒãCAã«åºæ¬çãªå€±å¹ãªã¹ãã ãã§ååãªå Žåã¯ããšã³ããŠãŒã¶ãŒã«èšŒææžãçºè¡ããCAã«ãã«ã¿ã䜿çšããå¿
èŠããããŸãã
CRLæå¹æéèšç»
åCAã®ã¬ãã¥ãŒãªã¹ãã®æ§æããã¹ãŠã§ããã ããã§ãã¿ã€ãã³ã°ã決å®ããå¿
èŠããããŸãã
- ã¬ãã¥ãŒãªã¹ãã¯ã©ã®ãããã®æéå
¬éããå¿
èŠããããŸããïŒ
- ãã®äžã®æ
å ±ã¯ã©ã®ãããã®æéä¿¡é Œæ§ããããååã«é¢é£æ§ããããšèŠãªãããŸãã
ããã§ã¯ãåäœæ¡ä»¶ã«å¿ããŠã¢ãããŒããé©çšããããšãã§ããŸãã äžéCAãåãæ¶ããªã¹ã¯ã¯éåžžã«äœãããã空ã®CRLãé »ç¹ã«å
¬éããããšã¯æå³ããããŸããã çŸä»£ã®ãã©ã¯ãã£ã¹ã§ã¯ãCAã®CRLæå¹æéã«æ¬¡ã®äžè¬çãªå€ã䜿çšãããŸããããã¯ãä»ã®CAã«ã®ã¿èšŒææžãçºè¡ããŸãïŒ3ã6ããŸãã¯12ãæã ãªã³ãŒã«ãªã¹ããç¶æããããã®ãªã¹ã¯ãšç®¡çã³ã¹ãã®çšåºŠã«åºã¥ããŠããå¿
èŠããããŸãã ç¹å¥ãªæ¡ä»¶ããªãå Žåã¯ãå¹³åçãªçŽ6ãæãéžæããããšããå§ãããŸãã
äžäœCAã®å Žåãã¹ããŒã ã¯åãã§ãã ã¯ã©ã€ã¢ã³ãèšŒææžãåãæ¶ããªã¹ã¯ãé«ããããåãæ¶ãã®é »åºŠãé«ããšæ³å®ã§ããŸãã ãããã£ãŠããã®ãããªCAã¯ã¬ãã¥ãŒãªã¹ããã¯ããã«é »ç¹ã«å
¬éãããã©ãã£ãã¯ãç¯çŽããããã«ãåºæ¬CRLãšå·®åCRLãçµã¿åãããŸãã ããã©ã«ãã§ã¯ãMicrosoft CAã¯æ¬¡ã®é »åºŠã§å€±å¹ãªã¹ããå
¬éããŸããåºæ¬CRLã¯é±ã«1åããã«ã¿ã¯æ¯æ¥ã ãã®ç¶æ³ã§ã¯ã24æé以å
ã«ã倱å¹ããææ°ã®èšŒææžãã客æ§ã«éç¥ãããŸãã
ã客æ§ã倱å¹ããèšŒææžãæå¹ã§ãããšèªèããªãããã«ããã®æéãïŒçæ³çã«ã¯å³åº§ã«ïŒççž®ãã管çè
ã®èŠæãçè§£ã§ããŸãã ãã ãã1ã€ã®ãªã¹ã¯ãæžå°ãããšãå¥ã®ãªã¹ã¯ãå¢å ããŸãã äœããã®çç±ã§ã以åã®CRLã®æå¹æéãè¿ã¥ããæ°ããCRLãå
¬éã§ããªãã£ããšãã«CAãµãŒããŒã倱æãããšæ³åããŠãã ããã ãã®åŸãèšŒææžã®å€±å¹ã確èªããCAãµãŒããŒãæ©èœããããã«åŸ©å
ããããŸã§ãããã忢ããããšããåé¡ãå§ãŸããŸãã ã¬ãã¥ãŒãªã¹ãã®æå¹æéãèšå®ãããšãã¯ããã®ç¹ãèæ
®ããå¿
èŠããããŸãã
æ¢å®ã§ã¯ãMicrosoft CAã¯ãäºæããªãå Žåããã¬ãã¥ãŒãªã¹ãããã¹ãŠã®å
¬éãã€ã³ãã«é
åžããã®ã«æéããããå ŽåïŒããšãã°ãã¬ããªã±ãŒã·ã§ã³ã®é
å»¶ãåå ïŒã«ãããçšåºŠã®æéçäœè£ãæ¢ã«èšããŠããŸãã è±èªã®çšèªã§ã®ãã®äºåã¯ãCRLãªãŒããŒã©ãããšåŒã°ããŸãã é²åŸ¡ã¡ã«ããºã ã®èåŸã«ããèãæ¹ã¯ãCAã以åã«çºè¡ããããªã¹ãã®æå¹æéãåããåã«ã¬ãã¥ãŒãªã¹ããçæããŠçºè¡ããããšã§ãã
ããã¯ãã¬ãã¥ãŒãªã¹ãã®2ã€ã®ãã£ãŒã«ããNext CRL Publishããã³Next Updateã䜿çšããŠå®çŸãããŸãã Next CRL Publishãã£ãŒã«ãã¯ãCAãæŽæ°ããã倱å¹ãªã¹ããïŒèªåçã«ïŒå
¬éããæå»ã瀺ããŸãã æ¬¡ã®æŽæ°ã¯ãçŸåšã®ãªã¹ããæéåãã«ãªãæéã瀺ããŸãã Next Updateãã£ãŒã«ãã¯ãåžžã«Next CRL Publishãããå°ãé
ããŠèšå®ãããŸãã ã€ãŸããCAã¯ä»¥åã®ãªã¹ããæéåãã«ãªãåã«ãæŽæ°ããã倱å¹ãªã¹ããå
¬éããŸãã ãããã®ãã£ãŒã«ãã®èªåå€ãèšç®ããã¢ã«ãŽãªãºã ã¯èªæã§ã¯ãªããæ¬¡ã®èšäºã§èª¬æãããŠããŸãïŒ
ThisUpdateãNextUpdateãNextCRLPublishã®èšç®æ¹æ³ïŒv2ïŒ äœããã®çç±ã§ããã©ã«ãå€ãé©åã§ãªãå Žåã¯ãç·šéã§ããŸãã æéããŒãžã³ã«ã¯äžéãšäžéãããããšã«çæããŠãã ããã ããšãã°ãäžéã¯CRLèªäœã®æå¹æéãè¶
ããããšã¯ã§ããŸããã ãããã£ãŠãCRLã®æå¹æéã1æ¥éã®å Žåãåšåº«ã¯æå€§1æ¥éã«ãªããCAã¯æ¯æ¥ã¬ãã¥ãŒãªã¹ããå
¬éããŸãããæå¹æéã¯2æ¥éã«ãªããŸãã ãããã£ãŠãäºæããªãç¶æ³ã®å Žåã«CAã埩å
ããããã®æéã®ããŒãžã³ãéæãããŸãã
å®éã«ã¯ã管çè
ãCRLã®æå¹æéèšå®ã次ã®çç±ã§æå°é床ã«èª¿æŽããããšããèŠæãããç®ã«ããŸãããããŠãŒã¶ãŒã¯çµäºãã倱å¹ããèšŒææžã§èªèšŒã§ããªãã¯ãã§ããã åæ©ã¯çè§£ã§ããŸãããã¬ãã¥ãŒãªã¹ããéããŠåé¡ã解決ããããšã¯å®å
šã«æ£ãããšã¯éããŸããã ãŠãŒã¶ãŒãäŒæ¥ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ã忢ããå¿
èŠãããå Žåã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããŸãã¯ã³ã³ãã¥ãŒã¿ãŒãç¡å¹ã«ããå¿
èŠããããŸããCRLã®æå¹æéãšé »åºŠãèšç»ãããšãã¯ãæ¬¡ã®æšå¥šäºé
ã«åŸã£ãŠãã ããã
- ãšã³ããŠãŒã¶ãŒã§ã¯ãªããä»ã®CAã®ã¿ã«èšŒææžãçºè¡ãããã¹ãŠã®CAã¯ã3ãæãã12ãæã®éã1ãæã®ããŒãžã³ã§CRLãå
¬éããå¿
èŠããããŸãã
- ãšã³ããŠãŒã¶ãŒïŒãŠãŒã¶ãŒããã³ããã€ã¹ïŒã«èšŒææžãçºè¡ãããã¹ãŠã®CAã¯ãå°ãªããšã1é±éã«1ååºæ¬CRLãçºè¡ããå°ãªããšã3æ¥éïŒã§ããã°æ¯æ¥ïŒå·®åãªã¹ããçºè¡ããå¿
èŠããããŸãã æéããŒãžã³ã¯èª¿æŽããªãã§ãã ããïŒCAã®å
éšããžãã¯ã«ãã£ãŠèªåçã«èšç®ããããã®ã䜿çšããŠãã ããïŒã
ãªã³ã©ã€ã³èšŒææžã¹ããŒã¿ã¹ãããã³ã«
ãã®èšäºã·ãªãŒãºã®äžç°ãšããŠã倱å¹ããèšŒææžã«é¢ããæ
å ±ãé
åžãã远å ã®æ¹æ³ã«OCSPãµãŒããŒã䜿çšããŸããã å¿
èŠã«å¿ããŠãå
æ¬çãªTechNetèšäºã
ãªã³ã©ã€ã³ã¬ã¹ãã³ããŒã®ã€ã³ã¹ããŒã«ãæ§æãããã³ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã¬ã€ãããåç
§ã§ããŸãã å®è·µã瀺ãããã«ãã»ãšãã©ã®å ŽåãOCSPã®ã€ã³ã¹ããŒã«ãšãµããŒãã¯ããã€ãã®çç±ã§æ£åœåãããŠããŸããã
OCSPã®äž»ãªç®æšã¯ãCRLããŠã³ããŒããã©ãã£ãã¯ããªãããŒãããããšã§ãã ãåç¥ã®ããã«ãCRLã«ã¯ãCAã®å
šæéã«ããããã¹ãŠã®å€±å¹ããèšŒææžã®ãªã¹ããå«ãŸããŠãããèšŒææžã®éäžçãªå€±å¹ã«ããããã®ãµã€ãºã¯å°è±¡çãªãµã€ãºïŒæ°ã¡ã¬ãã€ãïŒã«éããå¯èœæ§ããããŸãã äžèšã®ããã«ã倱å¹ãã10äžä»¶ã®èšŒææžã¯CRLãã¡ã€ã«ã§çŽ9MBã«ãªãããšã«æ³šæããŠãã ããã OCSPã䜿çšããŠèšŒææžã®å€±å¹ã確èªããéãåºå®ãµã€ãºã¯çŽ2.5KBã«ãªããŸãã ç®ã«èŠããéãããããŸãã å®éã«ã¯ãå€ãã®å Žåããªã³ãŒã«çã¯ã¯ããã«äœããªããŸãã ã«ãŒãCAãŸãã¯ããªã·ãŒã®CAã«ã€ããŠè©±ãå Žåããããã¯éšåçã«ã¬ãã¥ãŒãããã¬ãã¥ãŒãªã¹ãã®ãµã€ãºã¯1KBãã»ãšãã©è¶
ããŸããã
OCSPã¯ãæ€èšŒæžã¿ã®èšŒææžã1ã€ããããããæ€èšŒãããå€ãã®ã¯ã©ã€ã¢ã³ããããå Žåã«å¹æçã§ããããšã«æ³šæããŠãã ããã ããã¯ãå
žåçãªSSL / TLSèšŒææžã®ã·ããªãªã§ãã ãã®å Žåãåã¯ã©ã€ã¢ã³ãã¯æ¡ä»¶ä»ã9MB倱å¹ãªã¹ããããŠã³ããŒããã代ããã«ã2.5KBã®OCSPãã©ãã£ãã¯ãæ¶è²»ããŸãã ãã ããå察ã®ç¶æ³ïŒ1ã€ã®ãµãŒããŒãå€ãã®ã¯ã©ã€ã¢ã³ãèšŒææžãæ€èšŒããïŒã§ã¯ãOCSPããããã¯ãŒã¯ã«å€§ããªè² è·ããããå¯èœæ§ããããŸãã ããã«ã¯ãäžè¬çãªäŒæ¥ãããã¯ãŒã¯ã®ã·ããªãªãå«ãŸããŸããèšŒææžã䜿çšããã¯ã©ã€ã¢ã³ãèªèšŒïŒã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ããã³VPNã§ã®EAP-TLSèªèšŒããã¡ã€ã³ã³ã³ãããŒã©ãŒã§ã®KerberosèªèšŒãªã©ïŒã åŸæ¥å¡ãè·å Žã«æ¥ãŠããããã¯ãŒã¯ïŒã¹ããŒãã«ãŒããã¢ãã€ã«ããã€ã¹ã®èšŒææžïŒããã³ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®èªèšŒã«èšŒææžã䜿çšãããšãRADIUSãµãŒããŒã¯åã¯ã©ã€ã¢ã³ãèšŒææžã®æ€èšŒã匷å¶ãããŸãã 1Kã®èšŒææžã®ã¿ããã§ãã¯ããã«ã¯ã2.5 MBã®ãã©ãã£ãã¯ãæ¶è²»ãããŸãã ãã®ç¶æ³ã§ã¯ãOCSPã®å©ç¹ã¯ãŸã£ãããããŸãããããŸã£ããéã§ãã
ãã®åŽé¢ã¯ãMicrosoft補åã®ããžãã¯ã§èæ
®ãããŸãã ç¹å®ã®æéãCrypto APIã¯ã©ã€ã¢ã³ããOCSPã䜿çšããŠ1ã€ã®ãããªãã·ã£ãŒãã50ïŒãã®å€ãæ§æå¯èœïŒèšŒææžããã§ãã¯ãããšãOCSPã®åŠçãçµäºããã¯ã©ã€ã¢ã³ãã¯ãã®ãããªãã·ã£ãŒã®CRLãããŠã³ããŒãããŠãã£ãã·ã¥ããŸãã ãã®åäœã®è©³çްã«ã€ããŠ
ã¯ãWindows Vistaããã³Windows Server 2008ã®
èšŒææžå€±å¹ç¢ºèªã® 倱å¹ãšã¯ã¹ããªãšã³ã¹ã®
æé©åã»ã¯ã·ã§ã³ãã芧ãã ããã
èšŒææžçºè¡ããªã·ãŒãèšç»ãã
èšŒææžçºè¡ããªã·ãŒã¯ãèšŒææžã®æãçè§£ãã«ããåŽé¢ã®1ã€ã§ãããäŒæ¥ã§PKIãèšç»ããã³å±éãããšãã«ç®¡çè
ã«ãã£ãŠå®å
šã«ç¡èŠãããããšããããããŸãã ãã ããçºè¡ããªã·ãŒãçè§£ãã管çããèœåã«ãããããæè»ãªã·ã¹ãã ã远å ã®å¶åŸ¡ã¬ãã«ããããŠæçµçã«ã¯PKIãèšè¿°ããã³ææžåããæ¹æ³ãšããŠæäŸãããŸãã
ããªã·ãŒå®çŸ©
ãŸããèšŒææžçºè¡ããªã·ãŒã®å®çŸ©ãå
¥åããå¿
èŠããããŸãã èšŒææžãçºè¡/ååŸããããã»ã¹ã¯ãåºæ¬çã«ãèšŒææžã®åä¿¡è
ãšçºè¡CAãšã®éã®å¥çŽã§ãã ãã®å¥çŽã¯ãçºè¡ã®æé ã䜿çšã責任ç¯å²ãªã©ãå€ãã®åŽé¢ãå®çŸ©ããŠããŸãã
åäŒæ¥ã¯ãã¢ããªã±ãŒã·ã§ã³ã®æ€èšŒãšèšŒææžã®çºè¡ã«ç°ãªãæ¹æ³ã䜿çšããŠããå ŽåããããŸãã ããã€ãã®å
žåçãªã±ãŒã¹ãèæ
®ããŠãã ããïŒ
- é»åã¡ãŒã«ã«çœ²åããããã®èšŒææžã¯ãç³è«è
ã®æå°éã®æ€èšŒã§èªåçã«çºè¡ã§ããŸãïŒActive Directoryã§ã®ãŠãŒã¶ãŒã®èªèšŒãæåããå Žåã®ã¿ïŒã ãããã®èšŒææžãçºè¡ããããã«ããã以äžã®ã¢ã¯ã·ã§ã³ã¯è¡ãããŸããã
- ææžã®ããžã¿ã«çœ²åã®èšŒææžã¯ãçŽå±ã®äžåžãšã®åæããã³å¿
èŠãªãã¹ãŠã®çœ²åãå«ãæžé¢ã«ããç³è«æžã®æäŸåŸã«ã®ã¿çºè¡ã§ããŸãã
- ã¹ããŒãã«ãŒãã®èšŒææžã¯ãåŸæ¥å¡ã®å人çãªåºåžãããã³ã«ãŒãã®äœ¿çšãé¢é£èŠå¶ææžãžã®çœ²åã«é¢ããèŠåã«é¢ããæç€ºãããå Žåã«ã®ã¿çºè¡ã§ããŸãã
- , , -.
. , . , â .. , , (, ).
, . .
Network Policy Server (NPS) Active Directory Dynamic Access Control . , . , -.
NPS , , , -. , NPS ( ) . , , . Active Directory Dynamic Access Control, .
, . , , . , ? .
, - . , . , . . , ( PKI ) , , , .
: PKI â
Certificate Practice Statement CPS ( , , ). ( ) ,
RFC 3647 . , PKI. . , , - .
CPS :
- PKI, , .
- . PKI, , CPS, , .
CPS ( ). CPS ( ).
ITU-T ISO. :
OID' ? , IANA (Internet Assigned Numbers Authority) . , , : 1.3.6.1.4.1.x.1, x â , IANA. :
- 1.3.6.1.4.1.x.1.1
- 1.3.6.1.4.1.x.1.2
- 1.3.6.1.4.1.x.1.3
- 1.3.6.1.4.1.x.1.4
- ...
, . , , . Certificate Policies , .

, DigiCert, 2.16.840.1.114412.2.1 (
Extended Validation ) 2.23.140.1.1 (, CAB/Forum) CPS. CPS .
, , , . . , - , , ( ). :
Certificate Policies extension â all you should know (part 1) Certificate Policies extension â all you should know (part 2) . , , Windows.
: (10 ) , . (, ), .
RFC 5280 §4.2.1.4 (global wildcard) anyPolicy = 2.5.29.32.0, .
, , . , .. , , , , anyPolicy , . , . anyPolicy .
AD CS ( ). (, ). , (AD CS JET Database Engine). ããã¯çè«äžã§ãã
, . Windows Server 2003
Evaluating CA Capacity, Performance, and Scalability ( , .. TechNet), , . (, ), .
2010 , Windows PKI Team ( 2007 ) Windows Server 2008. :
Windows CA Performance Numbers . , , AD CS 2007 150 . . . , . Windows Server 2016 (
Windows Server 2016 System Requirements ):
- CPU â dual-core 1.4 GHz;
- â 1GB RAM;
- â 48 GB 48 GB . RAID1.
- â SVGA (800*600);
- â .
, ( ) ( ) .
( ), . , , . .
.
| |
---|
|
| Standalone CA |
| Root CA |
| 15 |
AD () | Certification Authorities AIA |
CRT | 1) - 2) C:\CertData\contoso-rca<CertificateName>.crt 3) IIS:\InetPub\PKIdata\contoso-rca<CertificateName>.crt* |
CRT | 1) URL=http://cdp.contoso.com/pki/contoso-rca<CertificateName>.crt |
CRL | 1) - 2) C:\CertData\contoso-rca<CRLNameSuffix>.crt 3) IIS:\InetPub\PKIdata\contoso-rca<CRLNameSuffix>.crt* |
CRL | 1) URL=http://cdp.contoso.com/pki/contoso-rca<CRLNameSuffix>.crt |
|
| Contoso Lab Root Certification authority |
| OU=Division Of IT, O=Contoso Pharmaceuticals, C=US |
| RSA#Microsoft Software Key Storage Provider |
| 4096 |
| SHA256 |
| 15 |
CRL | Base CRL |
Base CRL |
| Base CRL |
| 6ã¶æ |
| 1ã¶æ |
| SHA256 |
AD | |
* â IIS .
.
| |
---|
|
| Enterprise CA |
| Subordinate CA |
| : 5 ( ) |
| |
AD () | AIA NTAuthCertificates |
CRL | Base CRL Delta CRL |
CRT | 1) - 2) \\IIS\PKI\contoso-pica<CertificateName>.crt |
CRT | 1) URL=http://cdp.contoso.com/pki/contoso-pica<CertificateName>.crt |
CRL | 1) - 2) \\IIS\PKI\contoso-pica<CRLNameSuffix><DeltaCRLAllowed>.crl |
CRL | 1) URL=http://cdp.contoso.com/pki/contoso-pica<CRLNameSuffix><DeltaCRLAllowed>.crl |
|
| Contoso Lab Issuing Certification authority |
| OU=Division Of IT, O=Contoso Pharmaceuticals, C=US |
| RSA#Microsoft Software Key Storage Provider |
| 4096 |
| SHA256 |
| 15 ( ) |
| 1) : All Issuance Policies OID=2.5.29.32.0 URL=http://cdp.contoso.com/pki/contoso-cps.html |
Basic Constraints | isCA=True ( â ) PathLength=0 ( ). |
Base CRL |
| Base CRL |
| 1é±é |
| |
| SHA256 |
AD | |
Delta CRL |
| Delta CRL |
| 1 |
| - |
| SHA256 |
AD | |
IIS
| |
---|
|
- | cdp |
| cdp.contoso.com |
| PKI=C:\InetPub\wwwroot\PKIdata |
Double Escaping | |
, . , .
èè
ã«ã€ããŠ
â PowerShell Public Key Infrastructure, Microsoft MVP: Cloud and Datacenter Management 2009 PowerShell PKI. 9 PKI . PKI PowerShell
.