ãµã€ãã®ååã¯
HTTPSã䜿çšããŠããããã®æ°ã¯çå®ã«å¢å ããŠããŸãã ãã®ãããã³ã«ã¯ããã©ãã£ãã¯ååã®ãªã¹ã¯ã軜æžããŸãããè©Šè¡ãããæ»æèªäœãæé€ãããã®ã§ã¯ãããŸããã ãããã®ããã€ã-POODLEãBEASTãDROWNãªã©-ããã³ä¿è·æ¹æ³ã«ã€ããŠã¯ãè³æã§èª¬æããŸãã
/ Flickr / Sven Graeme / CC BY-SAããŒãã«
2014幎ã«
POODLEæ»æãåããŠç¥ãããããã«ãªããŸããã SSL 3.0ãããã³ã«ã®è匱æ§ã¯ãã»ãã¥ãªãã£å°é家ã®BodoMöllerãšGoogleã®ååã«ãã£ãŠçºèŠãããŸããã
ãã®æ¬è³ªã¯æ¬¡ã®ãšããã§ããããã«ãŒã¯ã¯ã©ã€ã¢ã³ãã«åŒ·å¶çã«SSL 3.0æ¥ç¶ã確ç«ãããåæãããéä¿¡ããšãã¥ã¬ãŒãããŸãã 次ã«ã
CBCæå·åãã©ãã£ãã¯ã¢ãŒãã§ç¹å¥ãªã¡ãã»ãŒãžã¿ã°ãæ€çŽ¢ããŸãã æ»æè
ã¯ãäžé£ã®åœã®ã¯ãšãªã䜿çšããŠãCookieãªã©ã®é¢å¿ã®ããããŒã¿ã®ã³ã³ãã³ããåæ§ç¯ã§ããŸãã
SSL 3.0ã¯å»æ¢ããããããã³ã«ã§ãã ãããããã®ã»ãã¥ãªãã£ã®åé¡ã¯äŸç¶ãšããŠé¢é£ããŠããŸãã ã¯ã©ã€ã¢ã³ãã¯ããã䜿çšããŠããµãŒããŒã®äºææ§ã®åé¡ãåé¿ããŸãã äžéšã®ã¬ããŒãã«ãããšãæã人æ°ã®ãã10äžã®ãµã€ãã®ã»ãŒ7ïŒ
ããŸã SSL 3.0ããµããŒãããŠããŸãã POODLEã®å€æŽããã
ãŸã ããã®ç®çã¯ãããçŸä»£çãªTLS 1.0ããã³TLS 1.1ã§ãã ä»å¹Ž
ã TLS 1.2ä¿è·ããã€ãã¹ããæ°ãããŸã³ãPOODLEããã³GOLDENDOODLEæ»æ
ãç»å ŽããŸããïŒãããã¯ãŸã CBCæå·åã«é¢é£ä»ããããŠããŸãïŒã
èªåãå®ãæ¹æ³ã å
ã®POODLEã®å ŽåãSSL 3.0ãµããŒããç¡å¹ã«ããå¿
èŠããããŸãã ãã ãããã®å Žåãäºææ§ã®åé¡ã®ãªã¹ã¯ããããŸãã 代æ¿ãœãªã¥ãŒã·ã§ã³ã¯TLS_FALLBACK_SCSVã¡ã«ããºã ã§ããããã«ãããSSL 3.0ãä»ããããŒã¿äº€æãå€ãã·ã¹ãã ã§ã®ã¿å®è¡ãããããšãä¿èšŒãããŸãã æ»æè
ã¯ããããã³ã«ã®ããŠã³ã°ã¬ãŒããéå§ã§ããªããªããŸãã Zombie POODLEããã³GOLDENDOODLEããä¿è·ããæ¹æ³ã¯ãTLS 1.2ã«åºã¥ããã¢ããªã±ãŒã·ã§ã³ã§CBCãµããŒããç¡å¹ã«ããããšã§ãã åºæ¬çãªæ±ºå®ã¯TLS 1.3ãžã®ç§»è¡ã§ã-ãããã³ã«ã®æ°ããããŒãžã§ã³ã¯CBCæå·åã䜿çšããŸããã
ããŒã¹ã
2011幎ã«çºèŠããããSSLããã³TLS 1.0ã«å¯Ÿããæåã®æ»æã®1ã€ã POODLEãšåæ§ã«ãBEAST
㯠CBCæå·åæ©èœã
䜿çšããŸãã æ»æè
ã¯ãTLSãŸãã¯SSLãä»ããŠããŒã¿ãéä¿¡ãããšãã«ã¡ãã»ãŒãžã眮ãæããJavaScriptãšãŒãžã§ã³ããŸãã¯Javaã¢ãã¬ãããã¯ã©ã€ã¢ã³ããã·ã³ã«ãããã€ããŸãã æ»æè
ã¯ãåœã®ããã±ããã®å
容ãç¥ã£ãŠããããããããã䜿çšããŠåæåãã¯ãã«ã解èªããèªèšŒçšã®Cookieãªã©ã®ãã®ä»ã®ã¡ãã»ãŒãžããµãŒããŒã«èªã¿åãããšãã§ããŸãã
çŸåšãŸã§ã
å€ãã®ãããã¯ãŒã¯ããŒã«ã¯ ãBEASTã®è匱æ§ïŒããŒã«ã«ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãä¿è·ãããããã·ãšã¢ããªã±ãŒã·ã§ã³ïŒã«å¯ŸããŠäŸç¶ãšããŠè匱ã§ãã
èªåãå®ãæ¹æ³ã æ»æè
ã¯ãããŒã¿ã埩å·åããããã«å®æçã«ãªã¯ãšã¹ããéä¿¡ããå¿
èŠããããŸãã SSLSessionCacheTimeoutã®æéã5åïŒããã©ã«ãã®æšå¥šå€ïŒãã30ç§ã«ççž®ããããšããå§ãããŸãã ãã®ã¢ãããŒãã¯ãçç£æ§ã«ããã€ãã®æªåœ±é¿ãåãŒããŸãããæ»æè
åãã®èšç»ã®å®è£
ãè€éã«ããŸãã ããã«ãããã«BEASTã®è匱æ§ãç¬èªã®ãã®ã«ãªãå¯èœæ§ãããããšãç解ããå¿
èŠããããŸã-2020幎以æ¥ãæ倧ã®ãã©ãŠã¶ãŒã¯TLS 1.0ããã³1.1ã®ãµããŒãã
åæ¢ããŠããŸãã ãããã«ããããããã®ãããã³ã«ã䜿çšãããã©ãŠã¶ãŠãŒã¶ãŒã¯å
šäœã®1.5ïŒ
æªæºã§ãã
ownãã
ããã¯ã40ãããRSAããŒã䜿çšããSSLv2ã®å®è£
ã§ãšã©ãŒã䜿çšããã¯ãã¹ãããã³ã«æ»æã§ãã æ»æè
ã¯ãã¿ãŒã²ããã®äœçŸãã®TLSæ¥ç¶ããªãã¹ã³ããåãç§å¯ããŒã䜿çšããŠSSLv2ã§ãµãŒããŒã«ç¹å¥ãªãã±ãããéä¿¡ããŸãã ããã«ãŒã¯
Bleichenbacheræ»æã䜿çšããŠ
ãçŽ1,000ã®TLSã¯ã©ã€ã¢ã³ãã»ãã·ã§ã³ã®1ã€ã解èªã§ããŸãã
DROWNã¯2016幎ã«åããŠç¥ãããããã«ãªããäžçã®
ãµãŒããŒã®3åã® 1ããã
ã«ãããããŸããã çŸåšãŸã§ãé¢é£æ§ã¯å€±ãããŠããŸããã æã人æ°ã®ãã150,000ã®ãµã€ãã®ãã¡ã2ïŒ
ããŸã SSLv2ãšè匱ãªæå·åã¡ã«ããºã ã
ãµããŒãããŠããŸãã
èªåãå®ãæ¹æ³ã SSLv2ãµããŒããç¡å¹ã«ããæå·åã©ã€ãã©ãªã®éçºè
ãææ¡ããããããã€ã³ã¹ããŒã«ããå¿
èŠããããŸãã ããšãã°ããã®ãããª2ã€ã®ããããOpenSSLã«å°å
¥ãããŸããïŒ2016幎ã«ã¯
ãããã¯ã¢ããããŒã 1.0.1sããã³1.0.2gã§ããïŒã ãŸããè匱ãªãããã³ã«ãç¡å¹ã«ããããã®æŽæ°ãšæé ã
Red Hat ã
Apache ã
Debianã§å
¬éãããŸããã
IaaSãããã€ããŒ1cloud.ruã®éçºéšéã®è²¬ä»»è
ã§ããSergey Belkinæ°ã¯ã 次ã®ããã«è¿°ã¹ãŠããŸãã -ãã®ç¶æ³ã¯ãè€æ°ã®ãµãŒããŒãå
±éã®SSL蚌ææžã䜿çšããŠããå Žåã«çºçããŸãã ãã®å Žåããã¹ãŠã®ãã·ã³ã§SSLv2ãµããŒããç¡å¹ã«ããŸããã
DROWNãçºèŠããæ
å ±ã»ãã¥ãªãã£ã®å°é家ã«ãã£ãŠéçºãããç¹å¥ãª
ãŠãŒãã£ãªãã£ã䜿çšããŠãã·ã¹ãã ãæŽæ°ããå¿
èŠããããã©ããã確èªã§ããŸãã ãã®ã¿ã€ãã®æ»æã«å¯Ÿããä¿è·ã«é¢é£ããæšå¥šäºé
ã«ã€ããŠ
ã¯ãOpenSSL Webãµã€ãã®æçš¿ãã芧ãã ãã ã
ããŒãããªãŒã
ãœãããŠã§ã¢ã®æ倧ã®è匱æ§ã®1ã€ã¯
Heartbleedã§ãã 2014幎ã«OpenSSLã©ã€ãã©ãªã§çºèŠãããŸããã ãšã©ãŒãçºè¡šãããæç¹ã§ãè匱ãªWebãµã€ãã®æ°ã¯
50äžãšæšå®ãããŸãããããã¯ããããã¯ãŒã¯äžã®ä¿è·ããããªãœãŒã¹ã®çŽ17ïŒ
ã§ãã
ãã®æ»æã¯ãå°ããªããŒãããŒãTLSæ¡åŒµã¢ãžã¥ãŒã«ãéããŠå®è£
ãããŸãã TLSãããã³ã«ã§ã¯ãããŒã¿ãç¶ç¶çã«éä¿¡ããå¿
èŠããããŸãã é·æéã®ããŠã³ã¿ã€ã ã®å Žåãäžæãçºçããæ¥ç¶ãå確ç«ããå¿
èŠããããŸãã ãã®åé¡ã«å¯ŸåŠããããã«ããµãŒããŒãšã¯ã©ã€ã¢ã³ãã¯äººçºçã«ãã£ãã«ãããã€ãºãïŒ
RFC 6520ãpã5 ïŒããã©ã³ãã ãªé·ãã®ãã±ãããéä¿¡ããŸãã æãå€ãã®ããã±ãŒãžã§ããããšãå€æããå ŽåãOpenSSLã®è匱ãªããŒãžã§ã³ã¯ãå²ãåœãŠããããããã¡å€ã®ã¡ã¢ãªãèªã¿åããŸãã ãã©ã€ããŒãæå·åããŒãä»ã®æ¥ç¶ã«é¢ããæ
å ±ãªã©ãããããããŒã¿ããã®é åã«ååšããå¯èœæ§ããããŸãã
ãã®è匱æ§ã¯ã1.0.1ãã1.0.1fãŸã§ã®ã©ã€ãã©ãªã®ãã¹ãŠã®ããŒãžã§ã³ãããã³å€ãã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒ12.04.4ãŸã§ã®Ubuntuã6.5ããå€ãCentOSãOpenBSD 5.3ãªã©ïŒã«ååšããŠããŸããã å®å
šãªãªã¹ãã¯
ãHeartbleed Webãµã€ãã«ãããŸãã ãã®è匱æ§ã«å¯Ÿãããããã¯ãçºèŠåŸããã«ãªãªãŒã¹ãããŸããããåé¡ã¯ãããŸã§ãšåæ§ã«é¢é£ããŠããŸãã 2017幎ã«ã¯ã
çŽ20äžã®ãµã€ããHeartbleedã®åœ±é¿ãåããŠããŸããã
èªåãå®ãæ¹æ³ã OpenSSLãããŒãžã§ã³1.0.1g以éã«
ã¢ããã°ã¬ãŒãããå¿
èŠããã
ãŸã ã DOPENSSL_NO_HEARTBEATSãªãã·ã§ã³ã䜿çšããŠãããŒãããŒãèŠæ±ãæåã§ç¡å¹ã«ããããšãã§ããŸãã ã¢ããã°ã¬ãŒãåŸãæ
å ±ã»ãã¥ãªãã£ã®å°é家
㯠ãSSL蚌ææžã®åçºè¡ã
æšå¥šããŠããŸãã æå·åããŒã®ããŒã¿ããŸã ããã«ãŒã«å±ããŠããå Žåã亀æãå¿
èŠã§ãã
蚌ææžã®ãªãããŸã
管ç察象ããŒãã¯ããã©ãã£ãã¯ãç©æ¥µçã«ååããæ£åœãªSSL蚌ææžã䜿çšããŠããŠãŒã¶ãŒãšãµãŒããŒã®éã«ã€ã³ã¹ããŒã«ãããŸãã ãã®ããŒãã¯æ£åœãªãµãŒããŒã®ãµããããŠãæå¹ãªèšŒææžãæ瀺ããMITMæ»æãè¡ãããšãå¯èœã«ãªããŸãã
MozillaãGoogleãããã³è€æ°ã®å€§åŠã®ããŒã
ã«ãã調æ»ã«ãããšããããã¯ãŒã¯äžã®å®å
šãªæ¥ç¶ã®çŽ11ïŒ
ããçèŽããããŠããŸãã ããã¯ãçãããã«ãŒã蚌ææžããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ããçµæã§ãã
èªåãå®ãæ¹æ³ã ä¿¡é Œã§ãã
SSLãããã€ããŒã®ãµãŒãã¹ã䜿çšããŸãã
Certificate Transparency ïŒCTïŒãµãŒãã¹ã䜿çšããŠã
蚌ææžã®ãå質ãã確èªã§ããŸãã ã¯ã©ãŠããããã€ããŒã¯çèŽã®æ€åºã«ã圹ç«ã¡ãŸããä»æ¥ãäžéšã®å€§äŒæ¥ã¯TLSæ¥ç¶ãç£èŠããããã®å°çšããŒã«ãæäŸããŠããŸãã
ãã1ã€ã®ä¿è·æ¹æ³ã¯ãSSL蚌ææžã®åä¿¡ãèªååããæ°ããACME
æšæºã§ãã åæã«ã圌ã¯ãµã€ãææè
ããã§ãã¯ããããã®è¿œå ã®ã¡ã«ããºã ãè¿œå ããŸãã
以åã®è³æã§åœŒã«ã€ããŠãã£ãš
æžãã ã
/ Flickr / ãŠãŒãªãµã¢ã€ãã / CC BYHTTPSã®èŠéã
å€ãã®è匱æ§ã«ãããããããITã®å·šäººãšæ
å ±ã»ãã¥ãªãã£ã®å°é家ã¯ãããã³ã«ã®å°æ¥ã«èªä¿¡ãæã£ãŠããŸãã HTTPSã®ç©æ¥µçãªå®è£
ã«ã€ããŠã¯ãWWWã®äœæè
ã§ããTim Berners-Leeã
æ¯æããŠããŸãã 圌ã«ãããšãæéã®çµéãšãšãã«TLSã¯ããå®å
šã«ãªããæ¥ç¶ã®ã»ãã¥ãªãã£ã倧å¹
ã«åäžããŸãã Berners-Leeã¯ã
å°æ¥ ãèªèšŒçšã®ã¯ã©ã€ã¢ã³ã蚌ææž
ãããããšãææ¡ããŸããã ãããã¯ã䟵å
¥è
ããã®ãµãŒããŒä¿è·ã®æ¹åã«åœ¹ç«ã¡ãŸãã
ãŸããæ©æ¢°åŠç¿ã®å©ããåããŠSSL / TLSãã¯ãããžãŒãéçºããäºå®ã§ããã¹ããŒãã¢ã«ãŽãªãºã ãæªæã®ãããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ãæ
åœããŸãã HTTPSæ¥ç¶ã§ã¯ã管çè
ã¯ãã«ãŠã§ã¢ããã®ãªã¯ãšã¹ãã®æ€åºãå«ããæå·åãããã¡ãã»ãŒãžã®å
容ãèŠã€ããæ¹æ³ããããŸããã ãã§ã«ããã¥ãŒã©ã«ãããã¯ãŒã¯ã¯æœåšçã«å±éºãªãã±ããã90ïŒ
ã®ç²ŸåºŠã§ãã£ã«ã¿ãªã³ã°ã§ããŸãã ïŒ
ã¹ã©ã€ã23ã®ãã¬ãŒã³ããŒã·ã§ã³ ïŒã
çµè«
HTTPSãžã®æ»æã®å€§éšåã¯ããããã³ã«èªäœã®åé¡ã§ã¯ãªããå€ãæå·åã¡ã«ããºã ããµããŒãããããã®ãã®ã§ãã ITæ¥çã¯ãåäžä»£ã®ãããã³ã«ã段éçã«å»æ¢ããè匱æ§ãçºèŠããããã®æ°ããããŒã«ãæäŸããŠããŸãã å°æ¥ããããã®ããŒã«ã¯ããã€ã³ããªãžã§ã³ãã«ãªããŸãã
è¿œå ã®é¢é£ãªã³ã¯ïŒ