
10æäžæ¬ãè©å€ã®è¯ãTLSèªèšŒå±ïŒCAïŒ
GlobalSign㯠ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæ§ç¯ãéå§ããŸããã ãšããããGlobalSignã¯ãã«ãŒãTLSèšŒææžã®å€ãã®çžäºçœ²åãåé€ããŸããã
æ®å¿µãªããããã®éçšã§ãSafariãChromeãããã³IE11ãã©ãŠã¶ãŒã¯ãã»ãã¥ãªãã£äžã®çç±ã§å€±å¹ãããšGlobalSignèšŒææžãèªèãå§ããŸããã GlobalSignã®ãšã³ãžãã¢ã¯é倧ãªãšã©ãŒãè¿
éã«æé€ããŸãããã誀ã£ãOCSPå¿çã¯CDNã«ãã£ãã·ã¥ãããäžçäžã«åºãŸã£ãããšã倿ããŸããã çŸåšãããã³ãã©ãŠã¶ãŒã®OCSPãã£ãã·ã¥å
ã®ã¬ã³ãŒãã®æå¹æéãåãã4æ¥åã«ãGlobalSignã®èšŒææžã§ä¿è·ãããŠãããµã€ãã¯ããŠãŒã¶ãŒã®å€§éšåãã¢ã¯ã»ã¹ã§ããªãå ŽåããããŸãã
圱é¿ãåãããµã€ãã«ã¯ã
Wikipedia ã
Dropbox ã
Financial Timesãªã©ã®äŒæ¥ããããŸãã

è¡ãŸã¿ãã®æè¡ç詳现
OCSPãšã¯äœã§ããïŒ
SSLããã³TLSã¯ãã€ã³ã¿ãŒãããäžã®HTTPãã©ãã£ãã¯ãæå·åããããã«äœ¿çšãããŸãã ãããã®ãããã³ã«ã¯ããèªèšŒå±ãïŒCAïŒãŸãã¯èªèšŒå±ã®æŠå¿µãå°å
¥ããŠããŸãã åãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšåãã©ãŠã¶ã«ã¯ãä¿¡é ŒããèšŒææ©é¢ã®ãã£ãã·ã¥ãçµã¿èŸŒãŸããŠããŸãã HTTPSãµã€ãã«ã¯ãä¿¡é Œã§ããèªèšŒå±ã«ãã£ãŠçºè¡ãããèšŒææžãå¿
èŠã§ããããã§ãªãå Žåãæ¥ç¶ã¯å€±æãããã©ãŠã¶ãŒã«ãšã©ãŒã衚瀺ãããŸãã

ãã®æŠå¿µã«ã¯æ»ããããç¬éããããŸãã å®éãããšãã°ãµãŒããŒã«è匱æ§ãèŠã€ãã£ãå Žåãæ»æè
ã¯æ¢åã®èšŒææžãšæå·åç§å¯éµã«ã¢ã¯ã»ã¹ã§ããŸãã æ»æè
ã¯ããŒãçãã åŸãããã䜿çšããŠå
ã®ãµã€ããã·ãã¥ã¬ãŒããããã®ãµã€ãã§äžéè
ã®ãããªæ»æãçµç¹ããããšãã§ããŸãã ãã®çµæãæ³¥æ£ã¯ãµã€ã蚪åè
ã®ãã¹ã¯ãŒãããã©ã¹ããã¯ã«ãŒãããã®ä»ã®æ©å¯æ
å ±ã«ã¢ã¯ã»ã¹ããå¯èœæ§ããããŸãã

ãã®åé¡ã¯ãTLSèšŒææžãæ°žä¹
ã«ã§ã¯ãªããååã«é·ãæéïŒéåžžã¯1幎以äžïŒçºè¡ãããå€ãã®èªèšŒæ©é¢ïŒã¡ãªã¿ã«GlobalSignãå«ãïŒãTLSèšŒææžã賌å
¥ãã人ã«å²åŒãäžãããšããäºå®ã«ãã£ãŠæªåããŸãé·æã ããã¯ã
Let's Encryptã®ç¡æèªèšŒå±ã解決ããããšããŠããåé¡ã®1ã€ã§ãã Let's Encryptãçºè¡ããèšŒææžã¯3ãæä»¥å
æå¹ã§ãããèªèšŒå±ã¯ãã®æéã30æ¥éã«ççž®ããäºå®ã§ãã
CRLããã³
OCSPãšåŒã°ããã¡ã«ããºã ãšåŒã°ããçŸåšã®ç¶æ³ãä¿®æ£ããŸããã ãã©ãŠã¶ã«ããããµã€ããæç€ºããTLSèšŒææžãæå¹ãã©ããã確èªã§ããŸãã ããæç¹ã§ãèšŒææžã®ææè
ãèšŒææžã®ç§å¯ããŒãééã£ãæã«æž¡ã£ããšçã£ãå ŽåãèšŒææžãçºè¡ããã»ã³ã¿ãŒã«é£çµ¡ããŠåãæ¶ãããšãã§ããŸãã åãæ¶ãããèšŒææžã¯ãã»ãšãã©ã®ææ°ã®ãã©ãŠã¶ãŒãç¹ã«Safariããã³Chromeãããã³å°æ¥çã«ã¯ãã¹ãŠã®ãã©ãŠã¶ãŒã§åãå
¥ããããŸããã ãããã£ãŠãæ©å¯æ
å ±ãééã£ãæã«æž¡ãããšã¯ãããŸããã
10æäžæ¬ã®åºæ¥äº
GlobalSignã¯ãå€ãã®ã«ãŒãä¿¡é ŒèšŒææžã管çããŸãã ãããã®èšŒææžã®å€ãã¯ãLet's Encryptãè¡ãæ¹æ³ãšåæ§ã«ãçžäºã«çœ²åããŸãã

æ°ããã«ãŒãèšŒææžãçºè¡ãããšããªã©ã«ãã¯ãã¹çœ²åãå¿
èŠã§ãã å€ãã®äººããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãæŽæ°ããããšã¯ãã£ãã«ãªããããæ°ããäœæããèšŒææžãå€ããã©ãŠã¶ã®ãã£ãã·ã¥ã«ããã«è¡šç€ºãããªãå ŽåããããŸãã ã«ãŒãèšŒææžãæå³ããç®çã«äœ¿çšã§ããããã«ãå€ãã«ãŒãèšŒææžã®ããããã§çœ²åãããŸãã
ãã¡ãããã¯ãã¹çœ²åã¯ã«ãŒãèšŒææžã®ã¡ã³ããã³ã¹ãè€éã«ããŸãã ããã«ãäžéšã®GlobalSignèšŒææžã®ãªãªãŒã¹ããååãªæéãçµéããŠãããããæ®ãã®æŽæ°ãããŠããªãã·ã¹ãã ãç¡èŠã§ããŸãã æçµçã«ããããã®ã·ã¹ãã ã¯ãšã«ããéåœã«ãããŸã-ããšãã°ãæªåé«ãInternet Explorer 6ã¯ãããã«äœ¿çšã§ããæå·åãããã³ã«ã
è匱ãªSSL 3.0以äžã®ããŒãžã§ã³ã§
ãµããŒãããŸãã
ãããèæ
®ããŠã2016幎10æãGlobalSignã¯èšŒææžéã®çžäºçœ²åã®äžéšãåé€ããããããåå¥ã«ç¬ç«ããŠç®¡çããããšã決å®ããŸããã
äœãæªãã£ã
10æ14æ¥ã®æãã¯ãã¹çœ²åãåãæ¶ãããã»ã¹ã«ãšã©ãŒãå
¥ã蟌ã¿ãŸããã ãã®çµæã倿°ã®äžéGlobalSignèšŒææžïŒç¹ã«å®äŸ¡ã§æ®åããŠãã
AlphaSSL ïŒãSafariããã³Chromeãã©ãŠã¶ãŒã«ãã£ãŠåãæ¶ããããšèªèãããããã«ãªããAlphaSSLãªã©ããèšŒææžã賌å
¥ãããã¹ãŠã®ãµã€ããéããªããªããŸããã
GlobalSignã®ãšã³ãžãã¢ã¯ããã«åé¡ãä¿®æ£ããŸãã
ãããã©ãã«ã¯ããã§çµãããŸããã§ãã ã å®éãOCSPãµãŒããŒã¯CAã€ã³ãã©ã¹ãã©ã¯ãã£ã®éåžžã«è² è·ã®é«ãèŠçŽ ã§ããããã¹ãŠã®CAã¯ã©ã€ã¢ã³ãïŒ
OCSPã¹ããŒãã«ãæ§æããã¯ã©ã€ã¢ã³ããé€ãïŒã®ãã¹ãŠã®ãŠãŒã¶ãŒã®ãã¹ãŠã®ãã©ãŠã¶ãŒã
ããã«ã¢ã¯ã»ã¹ããŸã ã ãããã£ãŠãã»ãšãã©ã®èªèšŒå±ã¯CDNã䜿çšããŠOCSPå¿çãé
åžããŸãã ç¹ã«ãGlobalSignã¯Cloudflareã®ãµãŒãã¹ã䜿çšããŸãã 詳现ã¯ãŸã ãããŸããããã©ãããCloudflareã¯äœããã®çç±ã§ãã£ãã·ã¥ãããã«ã¯ãªã¢ã§ããã誀ã£ãOCSPã¹ããŒã¿ã¹ãã€ã³ã¿ãŒãããäžã§åºããç¶ããŸããã
çŸæç¹ã§ã¯ãCDNãã£ãã·ã¥ã®åé¡ã解決ãããŠããŸãããå€ãã®ãŠãŒã¶ãŒã«ãšã£ãŠã誀ã£ãOCSPã¹ããŒã¿ã¹ããã©ãŠã¶ãŒã«ãã£ãã·ã¥ãããããã«ãªããŸããã ãã©ãŠã¶ãŒããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®OCSPãã£ãã·ã¥ã«èšé²ããããšã¯ãä»åŸ4æ¥éæå¹ã§ãããç¶æ³ã¯ä¿®æ£ãããŸãã
Safariããã³Chromeãã©ãŠã¶ãŒã§OCSPã¬ã³ãŒããåŠçããéã®ãã°ãåé¡ã®åå ã§ãããšä¿¡ãã鿥çãªçç±ããããŸãã ãã ããããã«ã€ããŠã®å®éã®èšŒæ ã¯ãŸã ãããŸãã ã
æŽæ°ïŒ Twitter
ã®ç»é² ã¬ããŒã ïŒGlobalSignã®åŸæ¥å¡ã¯ãBBC Radioãšã®ã€ã³ã¿ãã¥ãŒã§ãåé¡ã¯å®å
šã«èªåã®åŽã«ããããšã確èªããŸããã
ã€ã³ã·ãã³ãã®éå§ãã11æéåŸãGlobalSignã¯åé¡ãä¿®æ£ããããã®
æšå¥šäºé
ãçºè¡ããŸãããããã®éã«ãã§ã«å€ãã®ã¯ã©ã€ã¢ã³ããä»ã®CAã«ç§»è¡ããŠããŸãã
ãã®ç¶æ³ã§æãäžå¿«ãªã®ã¯ãGlobalSignãšã©ãŒãäž»ã«ãã©ãã£ãã¯ã®å€ãã€ã³ã¿ãŒããããµãŒãã¹ã«åœ±é¿ããããšã§ãã å®éãCloudflareã¯äžæ£ç¢ºãªOCSPã¬ã¹ãã³ã¹ãè¿ããŸãããã圱é¿ãåãããµã€ãã¯ãããã®æ°æéã®éã«ãããã蚪åãããŠãŒã¶ãŒã®ã¿ãå©çšã§ããªããªããŸãã ãµã€ãã®äººæ°ãé«ãã»ã©ããã®ãããªãŠãŒã¶ãŒã®ã·ã§ã¢ã¯å€§ãããªããŸãã 亀ééã®å°ãªããµã€ããšå®æçãªèšªåè
ã®ããªããµã€ãã¯ããã®äºä»¶ã®åœ±é¿ãã»ãšãã©åããŸããã§ããã
èªåã§HTTPSãµã€ããžã®ã¢ã¯ã»ã¹ã«åé¡ãããããµã€ãèšŒææžãåãæ¶ããããšãã©ãŠã¶ãå ±åããå Žåã¯ãããŒã«ã«CRLããã³OCSPãã£ãã·ã¥ãã¯ãªã¢ããŠã¿ãŠãã ããã é¢é£ããæé ã¯
ãGlobalSign Webãµã€ãã§èŠã€ããããšãã§ããŸãã
æãéèŠãªããš
ãã®äºä»¶ã¯ãã®çš®ã®æåã®ãã®ã§ãã ã€ã³ã¿ãŒãããã®æŽå²äžåããŠããã®ã¬ãã«ã®åé¡ãçºçããŸãããCAæ¥çã®ãã¹ãŠã®é¢ä¿è
ãããããåã³èµ·ãããªãããã«ããããã«å¯èœãªãã¹ãŠã®ããšãè¡ãããšã¯ééããããŸããã
TLSãšCAã®ã°ããŒãã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯è€éã§èšå€§ã§ãããã©ã®ã·ã¹ãã ããšã©ãŒã§ã¯ãªãããšã©ãŒãžã®å¿çã«ãã£ãŠç¹åŸŽä»ããããŸãã ããã¯ãå®å
šãªãããã³ã«ãšæå·ã®æ®åãæ¢ããçç±ãšèŠãªãããã¹ãã§ã¯ãããŸããã ãµã€ãã«HTTPSãHSTSãHPKPãå«ããããšã§ããŠãŒã¶ãŒãä¿è·ããã€ã³ã¿ãŒãããã®å®å
šæ§ãé«ããŸãããã€ã³ã¿ãŒãããã®ä¿¡é Œæ§ãé«ããŸãã ãããŠãããã¯ã€ã³ã¿ãŒããããåãã¹ãæ¹åã§ãã
GlobalSignã¯é¡§å®¢ã«å¯ŸããŠéåžžã«æçœªã§ãããããã®äŒç€Ÿã¯
ééããèªèããããããçµè«ãåŒãåºãããšã
ã§ããããšã§ç¥ãããŠã
ãŸã ã è¿ãå°æ¥ããã¹ãŠã®ç¶æ³ã®è©³çްãªåæãšãšã©ãŒã«é¢ããæªè§£æ±ºã®äœæ¥ãäŒç€Ÿã«æåŸ
ããŸãã