æ¬èšäºã¯ãèªåã®çè§£ãæ·±ããããAIã¡ã³ã¿ãŒã¡ããã«ãŸãšããŠããã£ãè³æãããšã«åæ§æããŠããŸãã
ð ç®æ¬¡
- ãžããªã§çè§£ãããæå·åãã®äžç芳
- å
±ééµæå· vs å
¬é鵿å·
- ããã·ã¥é¢æ°ã£ãŠäœïŒ
- PKI ãš èšŒææžã®ä»çµã¿
- SSL/TLS ã®ããã¿
- GPG / OpenPGP
- 宿©ã³ãã³ãé
- 詊éšå¯ŸçããŒãã·ãŒã
ð¬ ãžããªã§çè§£ãããæå·åãã®äžç芳
ð° 倩空ã®åã©ãã¥ã¿ ïŒ å
±é鵿å·
ããã«ã¹ïŒãâ ãããå
±ééµïŒ
ã·ãŒã¿ãšããºãŒã ããç¥ã£ãŠãããåªæïŒéµïŒã
åãéµã§ããããïŒæå·åïŒãããè§£ãïŒåŸ©å·ïŒããã§ããã
ã§ãâŠãã®éµãã©ããã£ãŠå®å
šã«æž¡ãïŒ
â ããããéµé
éåé¡ãïŒ
ââââââââââââââââââââââââââââââââââââââââââ
â å
±é鵿å·ïŒå¯Ÿç§°éµæå·ïŒ â
â â
â ã·ãŒã¿ ââ[ãã«ã¹!]âââ¶ æå·æ â
â â
â ããºãŒ ââ[ãã«ã¹!]âââ¶ å
ã®æç« â
â â
â åãéµ = éãïŒã§ãéµã®åãæž¡ããåé¡â
ââââââââââââââââââââââââââââââââââââââââââ
ð® ãã®ã®ãå§« ïŒ å
¬é鵿å·
ã¢ã·ã¿ã«ã®ãèŠãç®ïŒå
¬ééµïŒãã¯èª°ã§ãèŠããã
ã§ããåªãïŒç§å¯éµïŒããæã€ã®ã¯ã¢ã·ã¿ã«ã ã
誰ã§ãæçŽãã¢ã·ã¿ã«å®ãŠã«ãå
¬ééµã§å°å°ãã§ãã
å°ãéããããã®ã¯ã¢ã·ã¿ã«ïŒç§å¯éµïŒã ãïŒ
âââââââââââââââââââââââââââââââââââââââââââââââ
â å
¬é鵿å·ïŒéå¯Ÿç§°éµæå·ïŒ â
â â
â å
¬ééµïŒèª°ã§ãæãŠãïŒâââ¶ æå·å â
â ç§å¯éµïŒèªåã ãæã€ïŒâââ¶ åŸ©å· â
â â
â éµé
éåé¡ã解決ïŒã§ãåŠçã¯é
ã â
âââââââââââââââââââââââââââââââââââââââââââââââ
ð é女ã®å®
æ¥äŸ¿ ïŒ ããã·ã¥é¢æ°
ãããçŒãããã³ âââ¶ é
éïŒããã·ã¥å€ïŒ
ã©ããªã«å€§ããªè·ç©ã§ããé
éèšŒææžïŒããã·ã¥å€ïŒãã¯å°ããäžå®
è·ç©ã1gã§ãå€ãããšãèšŒææžã¯å
šç¶éãèŠãç®ã«ãªã
èšŒææžããè·ç©ã®äžèº«ã¯çµ¶å¯Ÿã«åŸ©å
ã§ããªãïŒ
ââââââââââââââââââââââââââââââââââââââââââ
â ããã·ã¥é¢æ° â
â â
â ã©ããªé·ãã®ããŒã¿ â
â â â
â [ããã·ã¥é¢æ°] â
â â â
â åºå®é·ã®ããã·ã¥å€ïŒæçŽã¿ãããªãã®ïŒâ
â â
â ã»åãå
¥å â åžžã«åãåºå â
â ã»å°ãã§ãå€ãããšå
šç¶éãå€ â
â ã»ããã·ã¥å€ããå
ããŒã¿ã埩å
äžå¯ â
ââââââââââââââââââââââââââââââââââââââââââ
ð åãšåå°ã®ç¥é ã ïŒ ããžã¿ã«çœ²å
åå°ã®ååã¯æ¹¯å©å©ã«å¥ªãããã
ã§ããå¥çŽæžïŒããžã¿ã«çœ²åïŒãããã°
ãæ¬åœã«åå°ãæžãããã©ãããããããïŒ
ç§å¯éµã§çœ²å âââ¶ å
¬ééµã§æ€èšŒ
ããã®ææžã¯ç¢ºãã«ç§ãæžããŸãããã蚌æ
ð å
±ééµ vs å
¬ééµ {#å
±ééµ-vs-å
¬ééµ}
å
±é鵿å·ïŒå¯Ÿç§°éµæå·ïŒ
| ç¹åŸŽ |
å
容 |
| é床 |
â¡ éã |
| éµç®¡ç |
éåä¿¡è
ã§åãéµãå
±æ |
| åé¡ç¹ |
éµãå®å
šã«æž¡ãææ®µãå¿
èŠ |
| çšé |
倧éããŒã¿ã®æå·å |
代衚çã¢ã«ãŽãªãºã
| ã¢ã«ãŽãªãºã |
éµé· |
詊éšã§ã®æ³šæç¹ |
| AES |
128/192/256bit |
çŸåšã®æšæºïŒèŠããã |
| 3DES |
168bit |
å€ãã»é
ãã»éæšå¥š |
| Blowfish |
32ã448bit |
å¯å€é·ãç¹åŸŽ |
| DES |
56bit |
è匱ïŒè©Šéšã«åºã |
| RC4 |
å¯å€é· |
WEPã§äœ¿ãããã»å»æ¢ |
ð¡ 詊éšãã€ã³ãïŒ
DES = 56bit = è匱 = 䜿ã£ãŠã¯ãããªãïŒ
AES = çŸä»£ã®æšæº = å®å
šïŒ
å
¬é鵿å·ïŒéå¯Ÿç§°éµæå·ïŒ
| ç¹åŸŽ |
å
容 |
| é床 |
ð¢ é
ãïŒå
±ééµã®çŽ1000åé
ãïŒ |
| éµç®¡ç |
å
¬ééµãšç§å¯éµã®ã㢠|
| 解決ããããš |
éµé
éåé¡ |
| çšé |
éµäº€æã»çœ²åã»èšŒææž |
代衚çã¢ã«ãŽãªãºã
| ã¢ã«ãŽãªãºã |
çšé |
ç¹åŸŽ |
| RSA |
æå·åã»çœ²å |
æãããã¥ã©ãŒ |
| DSA |
眲åã®ã¿ |
眲åç¹å |
| ECDSA |
眲å |
æ¥åæ²ç·ãçãéµã§åŒ·ã |
| DH / ECDH |
éµäº€æ |
æå·åã§ã¯ãªãéµãå®å
šã«å
±æ |
| ElGamal |
æå·åã»çœ²å |
GPGã§äœ¿ããã |
ð¡ 詊éšãã€ã³ãïŒ
RSA = æå·åã眲åãã§ãã
DSA = 眲åå°çšïŒæå·åã¯ã§ããªãïŒïŒ
DH = éµäº€æïŒæå·åã§ã¯ãªãïŒ
ãã€ããªããæå·ïŒå®éã®SSLã¯ããïŒïŒ
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â ãã€ããªããæå·ã®æµã â
â â
â â å
¬é鵿å·ã§ãå
±ééµããå®å
šã«äº€æ â
â Alice ââ[Bobã®å
¬ééµã§æå·å]âââ¶ Bob â
â Bob ââ[Bobã®ç§å¯éµã§åŸ©å·]âââ¶ å
±ééµã²ãã â
â â
â â¡ å
±é鵿å·ã§ããŒã¿ãé«éã«æå·å â
â 倧éã®ããŒã¿ ââ[å
±ééµ]âââ¶ é«éïŒå®å
šïŒ â
â â
â å
¬ééµã®å®å
šæ§ ïŒ å
±ééµã®éã = ãããšãåãïŒ â
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
#ïžâ£ ããã·ã¥é¢æ° {#ããã·ã¥é¢æ°}
åºæ¬çãªæ§è³ª
1. äžæ¹åæ§ïŒããã·ã¥å€ããå
ããŒã¿ã¯çµ¶å¯Ÿã«åŸ©å
ã§ããªã
2. è¡çªèæ§ïŒç°ãªãããŒã¿ãåãããã·ã¥å€ã«ãªããªãïŒãªãã«ããïŒ
3. æ±ºå®æ§ãïŒåãå
¥åã¯å¿
ãåãåºåã«ãªã
4. éªåީ广ïŒå
¥åã1ãããå€ãããšåºåã倧ããå€ãã
代衚çãªããã·ã¥ã¢ã«ãŽãªãºã
| ã¢ã«ãŽãªãºã |
ãããé· |
å®å
šæ§ |
詊éšã§ã®æ±ã |
| MD5 |
128bit |
â è匱 |
è¡çªãçºèŠæžã¿ïŒäœ¿çšçŠæ¢ |
| SHA-1 |
160bit |
â è匱 |
廿¢æšå¥š |
| SHA-256 |
256bit |
â
å®å
š |
SHA-2ãã¡ããªãŒãçŸåšã®æšæº |
| SHA-512 |
512bit |
â
å®å
š |
ããã»ãã¥ã¢ |
| SHA-3 |
å¯å€ |
â
å®å
š |
æ°ããèšèš |
ð¡ èŠãæ¹ïŒ
MD5ã»SHA-1 â å€ãã»å±éºã»äœ¿ããªïŒ
SHA-256ä»¥äž â å®å
šïŒäœ¿ããïŒ
ãã䜿ãããå Žé¢
ã»ãã¹ã¯ãŒãã®ä¿åïŒããã·ã¥åããŠä¿åïŒ
ã»ãã¡ã€ã«ã®æ¹ããæ€ç¥ïŒããŠã³ããŒããããã¡ã€ã«ã®ç¢ºèªãªã©ïŒ
ã»ããžã¿ã«çœ²åïŒçœ²åã¯ããã·ã¥å€ã«å¯ŸããŠè¡ãïŒ
ã»HMACïŒéµä»ãããã·ã¥ = ã¡ãã»ãŒãžèªèšŒã³ãŒãïŒ
ð PKI ãšèšŒææž {#pki-ãšèšŒææž}
PKIïŒå
¬ééµåºç€ïŒã®å
šäœå
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â PKIïŒPublic Key InfrastructureïŒ â
â â
â âââââââââââââââââââââââââââââââ â
â â CAïŒèªèšŒå±ïŒ â â
â â Certificate Authority â â
â â ã»èšŒææžãçºè¡ããä¿¡é Œã®æ ¹æ â â
â ââââââââââââ¬âââââââââââââââââââ â
â â 眲åããŠèšŒææžãçºè¡ â
â ââââââââââââŒâââââââââââââââââââ â
â â ãµãŒããŒèšŒææž â â
â â ã»å
¬ééµãå«ãŸãã â â
â â ã»æå¹æéãã â â
â â ã»CAã®çœ²åã§æ£åœæ§ã蚌æ â â
â ââââââââââââ¬âââââââââââââââââââ â
â â ãã©ãŠã¶ãæ€èšŒ â
â ââââââââââââŒâââââââââââââââââââ â
â â ã¯ã©ã€ã¢ã³ãïŒãã©ãŠã¶çïŒ â â
â â ãæ¬ç©ã®ãµã€ããã©ããã確èªâ â
â âââââââââââââââââââââââââââââââ â
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
èšŒææžã®çš®é¡
| çš®é¡ |
説æ |
| ã«ãŒãCAèšŒææž |
ä¿¡é Œã®æ ¹ã£ããOSããã©ãŠã¶ã«çµã¿èŸŒã¿ |
| äžéCAèšŒææž |
ã«ãŒãCAãšæ«ç«¯ã®éãéå±€æ§é ãäœã |
| ãµãŒããŒèšŒææž |
Webãµã€ããªã©ã«äœ¿ã |
| ã¯ã©ã€ã¢ã³ãèšŒææž |
ãŠãŒã¶ãŒèªèšŒã«äœ¿ã |
X.509èšŒææžã®äžèº«
ââââââââââââââââââââââââââââââââââââââ
â X.509 èšŒææžã®æ§æèŠçŽ â
â â
â ã»ããŒãžã§ã³ïŒv1/v2/v3ïŒ â
â ã»ã·ãªã¢ã«çªå· â
â ã»çºè¡è
ïŒCAïŒã®åå â
â ã»æå¹æéïŒéå§ãçµäºïŒ â
â ã»ãµããžã§ã¯ãïŒèª°ã®èšŒææžãïŒ â
â ã»å
¬é鵿
å ± â
â ã»æ¡åŒµé åïŒv3ã®ã¿ïŒ â
â ã»CAã®ããžã¿ã«çœ²å â
ââââââââââââââââââââââââââââââââââââââ
èšŒææžã®å€±å¹
| ä»çµã¿ |
説æ |
|
CRLïŒèšŒææžå€±å¹ãªã¹ãïŒ |
倱å¹ããèšŒææžçªå·ã®äžèЧãå®ææŽæ° |
| OCSP |
ãªã¢ã«ã¿ã€ã ã§å€±å¹ç¢ºèªãCRLããæ°ãã |
ð¡ 詊éšãã€ã³ãïŒ
CRL = ãªã¹ã圢åŒã»å®ææŽæ°ã»å€ãæ¹åŒ
OCSP = ãªã¢ã«ã¿ã€ã 確èªã»æ°ããæ¹åŒ
ð SSL/TLS {#ssltls}
SSL vs TLS
SSL 2.0 â è匱ã»å»æ¢
SSL 3.0 â POODLEæ»æã§å»æ¢
TLS 1.0 â éæšå¥š
TLS 1.1 â éæšå¥š
TLS 1.2 â çŸåšãåºã䜿çš
TLS 1.3 â ææ°ã»æšå¥šïŒãã³ãã·ã§ã€ã¯ãéã
TLSãã³ãã·ã§ã€ã¯ã®æµã
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â TLS ãã³ãã·ã§ã€ã¯ïŒTLS 1.2ã®å ŽåïŒ â
â â
â Client Server â
â â â â
â âââ ClientHello âââââââââââââââââââ¶ â â
â â ïŒå¯Ÿå¿ããæå·ã¹ã€ãŒããæç€ºïŒ â â
â â â â
â â âââââââââââââââ ServerHello âââââ â â
â â ïŒäœ¿ãæå·ã¹ã€ãŒããæ±ºå®ïŒ â â
â â â â
â â âââââââââââââââ Certificate âââââ â â
â â ïŒãµãŒããŒèšŒææžãéãïŒ â â
â â â â
â â èšŒææžãæ€èšŒïŒæ¬ç©ã®ãµãŒããŒïŒ â â
â â â â
â âââ ClientKeyExchange âââââââââââââ¶ â â
â â ïŒå
±ééµã®å
ã«ãªãæ
å ±ãéãïŒ â â
â â â â
â âââ ChangeCipherSpec ââââââââââââââ¶ â â
â âââ Finished ââââââââââââââââââââââ¶ â â
â â âââââââââââââââ Finished âââââââ â â
â â â â
â â ð æå·åéä¿¡ã¹ã¿ãŒãïŒ â â
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
æå·ã¹ã€ãŒãã®èªã¿æ¹
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
â â â â â â
| | | | | ââ HMACã®ããã·ã¥
| | | | âââââ æå·ã¢ãŒã
| | | âââââââââââââ å
±é鵿å·ãšãããé·
| | ââââââââââââââââââââââ èªèšŒæ¹åŒ
| ââââââââââââââââââââââââââââââ éµäº€ææ¹åŒ
âââââââââââââââââââââââââââââââââââ ãããã³ã«
ECDHE = åæ¹ç§å¿æ§ããïŒè©Šéšã«åºãéèŠããŒã¯ãŒã
ð¡ åæ¹ç§å¿æ§ïŒPerfect Forward Secrecy / PFSïŒãšã¯ïŒ
ã»ãã·ã§ã³ããšã«äžæçãªéµãçæããä»çµã¿ã
ä»®ã«ç§å¯éµãæŒããŠããéå»ã®éä¿¡ã¯åŸ©å·ã§ããªãïŒ
DHEãECDHEãåæ¹ç§å¿æ§ãæã€ã
âïž GPG / OpenPGP {#gpg--openpgp}
GPGãšã¯ïŒ
GnuPGïŒGNU Privacy GuardïŒ= OpenPGPæšæºã®å®è£
ãã¡ã€ã«ã®æå·åã»çœ²åã»éµç®¡çãã§ããã³ãã³ãã©ã€ã³ããŒã«
åºæ¬çãªäœ¿ãæ¹
# éµãã¢çæ
gpg --gen-key
# å
¬ééµã®äžèŠ§è¡šç€º
gpg --list-keys
# ç§å¯éµã®äžèŠ§è¡šç€º
gpg --list-secret-keys
# å
¬ééµããšã¯ã¹ããŒãïŒããã¹ã圢åŒïŒ
gpg --armor --export user@example.com > pubkey.asc
# å
¬ééµãã€ã³ããŒã
gpg --import pubkey.asc
# ãã¡ã€ã«ãæå·åïŒçžæã®å
¬ééµã§ïŒ
gpg --encrypt --recipient user@example.com file.txt
# ãã¡ã€ã«ã埩å·ïŒèªåã®ç§å¯éµã§ïŒ
gpg --decrypt file.txt.gpg
# ãã¡ã€ã«ã«çœ²å
gpg --sign file.txt
gpg --detach-sign file.txt # 眲åãå¥ãã¡ã€ã«ã«
# 眲åãæ€èšŒ
gpg --verify file.txt.sig file.txt
ä¿¡é Œã®èŒªïŒWeb of TrustïŒ
ââââââââââââââââââââââââââââââââââââââââââ
â PGP ã®ä¿¡é Œã¢ãã« = ä¿¡é Œã®èŒª â
â â
â Alice â ä¿¡é Œ ââ¶ Bob â ä¿¡é Œ ââ¶ Carol â
â â
â Aliceã¯CarolãšçŽæ¥äŒã£ãããšããªããŠã â
â Bobãçµç±ããŠä¿¡é Œã§ããïŒ â
â â
â â»PKIã®CAæ¹åŒãšã¯éã忣åã¢ãã« â
ââââââââââââââââââââââââââââââââââââââââââ
ð» 宿©ã³ãã³ãé {#宿©ã³ãã³ãé}
OpenSSL åºæ¬æäœ
# RSAç§å¯éµãçæïŒ2048bitïŒ
openssl genrsa -out private.key 2048
# ç§å¯éµããå
¬ééµãåãåºã
openssl rsa -in private.key -pubout -out public.key
# CSRïŒèšŒææžçœ²åèŠæ±ïŒãäœæ
openssl req -new -key private.key -out server.csr
# èªå·±çœ²åèšŒææžãäœæïŒãã¹ãçšïŒ
openssl req -x509 -new -key private.key -days 365 -out cert.pem
# èšŒææžã®å
容ã確èª
openssl x509 -in cert.pem -text -noout
# ãµãŒããŒã®TLSèšŒææžã確èª
openssl s_client -connect example.com:443
# ããã·ã¥å€ãèšç®
openssl dgst -sha256 file.txt
sha256sum file.txt # ãã¡ãã§ãå¯
ãã¡ã€ã«ã®æå·åã»åŸ©å·
# AES-256-CBCã§ãã¡ã€ã«ãæå·å
openssl enc -aes-256-cbc -in plaintext.txt -out encrypted.bin
# 埩å·
openssl enc -aes-256-cbc -d -in encrypted.bin -out decrypted.txt
ãã¹ã¯ãŒãã®ããã·ã¥å
# SHA-512ã§ãã¹ã¯ãŒããããã·ã¥ïŒsaltããïŒ
openssl passwd -6 "mypassword"
# MD5ïŒå€ãã»éæšå¥šïŒ
openssl passwd -1 "mypassword"
/etc/ssh/ é¢é£ïŒSSHæå·åïŒ
# SSHãã¹ãéµã®ç¢ºèª
ls -la /etc/ssh/ssh_host_*
# SSHéµãã¢çæïŒãŠãŒã¶ãŒçšïŒ
ssh-keygen -t ed25519 -C "user@example.com"
ssh-keygen -t rsa -b 4096
# å
¬ééµã®æçŽã確èª
ssh-keygen -lf ~/.ssh/id_ed25519.pub
èšŒææžã®æå¹æéãã§ãã¯ïŒå®åã§ãã䜿ãïŒ
# èšŒææžã®æå¹æéã ã衚瀺
openssl x509 -in cert.pem -noout -dates
# ãªã¢ãŒããµãŒããŒã®èšŒææžç¢ºèª
echo | openssl s_client -connect example.com:443 2>/dev/null \
| openssl x509 -noout -dates
ð 詊éšå¯ŸçããŒãã·ãŒã {#詊éšå¯ŸçããŒãã·ãŒã}
⡠絶察èŠããã¢ã«ãŽãªãºã æ©èŠè¡š
ãå
±é鵿å·ã
DES â 56bit â è匱ã»å»æ¢ïŒ
3DES â 168bit â å€ãã»äœé
AES â 128/192/256bit â â
çŸåšã®æšæº
Blowfish â å¯å€é·ïŒæå€§448bitïŒ
ãå
¬é鵿å·ã
RSA â æå·åã»çœ²åäž¡æ¹OK
DSA â 眲åå°çšïŒæå·åäžå¯ïŒ
ECDSA â æ¥åæ²ç·ã»çãéµã§åŒ·å
DH/ECDH â éµäº€æå°çš
ãããã·ã¥ã
MD5 â 128bit â è¡çªçºèŠæžã¿ã»å»æ¢
SHA-1 â 160bit â 廿¢æšå¥š
SHA-256 â 256bit â â
çŸåšã®æšæº
SHA-512 â 512bit â â
ããã»ãã¥ã¢
ãSSL/TLS ããŒãžã§ã³ã
SSL2/3 â 廿¢
TLS 1.0/1.1 â éæšå¥š
TLS 1.2 â çŸåšã䜿çš
TLS 1.3 â â
ææ°ã»æšå¥š
ð£ 詊éšã«ããåºãã廿¢ã»è匱ãããŒã¯ãŒã
| æè¡ |
ãªããã¡ïŒ |
| DES |
éµã56bitãšçããã |
| RC4 |
çµ±èšçåãããã |
| MD5 |
è¡çªæ»æãæåããŠãã |
| SHA-1 |
Google ãè¡çªãå®èšŒ(2017) |
| SSL 3.0 |
POODLEæ»æ |
| TLS 1.0 |
BEASTæ»æ |
ð 詊éšã«ããåºããçšèªããŸãšã
| çšèª |
æå³ |
| PFS / åæ¹ç§å¿æ§ |
éå»ã®éä¿¡ãåŸããè§£èªã§ããªãæ§è³ªãDHE/ECDHEãå®çŸ |
| HMAC |
éµä»ãããã·ã¥é¢æ°ãã¡ãã»ãŒãžã®å®å
šæ§ãšèªèšŒãç¢ºèª |
| PKCS |
å
¬é鵿å·ã®æšæºèŠæ ŒçŸ€ãPKCS#1(RSA)ãPKCS#12(èšŒææž+ç§å¯éµ)ãªã© |
| CRL |
倱å¹èšŒææžãªã¹ããCAãå
¬éãã |
| OCSP |
ãªã¢ã«ã¿ã€ã ã®å€±å¹ç¢ºèªãããã³ã« |
| CSR |
èšŒææžçœ²åèŠæ±ãCAã«éãããã®ç³è«æž |
| Web of Trust |
PGP/GPGã®ä¿¡é Œã¢ãã«ãPKIã®CAãšã¯éã |
| salt |
ãã¹ã¯ãŒãããã·ã¥ã«ä»å ããã©ã³ãã å€ãã¬ã€ã³ããŒããŒãã«å¯Ÿç |
ð¯ åºé¡ãã¿ãŒã³å¥ã»çããããããã€ã³ã
â ããªãDESã¯ãã¡ãïŒãâ éµé·56bitãçããã
â¡ ãåæ¹ç§å¿æ§ãæã€ã®ã¯ïŒãâ DHEãECDHE
⢠ã眲åå°çšã¢ã«ãŽãªãºã ã¯ïŒãâ DSA
⣠ãCRLãšOCSPã®éãã¯ïŒãâ CRL=ãªã¹ã/å®ææŽæ°ãOCSP=ãªã¢ã«ã¿ã€ã
†ãWeb of TrustãšCAã¢ãã«ã®éããâ 忣å vs äžå€®éæš©å
ðž ãŸãšãïŒ53%âåæ Œç¹ãžã®ããŒãããã
Week 1ïŒã¢ã«ãŽãªãºã ã®æèš
â å
±ééµã»å
¬ééµã»ããã·ã¥ã®è¡šãå®å
šæèš
â 廿¢ããããã®ïŒDES, MD5, SSL3.0ïŒã確å®ã«æŒããã
Week 2ïŒPKI ãš TLS ã®æµã
â ãã³ãã·ã§ã€ã¯ã®é çªãå³ã§æããããã«ãã
â èšŒææžã®ä»çµã¿ïŒCA â äžéCA â ãµãŒããŒèšŒææžïŒ
Week 3ïŒå®æ©ã§æãåãã
â opensslã³ãã³ããå®éã«æã£ãŠã¿ã
â gpgã§éµçæã»æå·åã»çœ²åãäœéš
Week 4ïŒéå»å & 匱ç¹è£åŒ·
â ééããåé¡ã®çšèªãæ¬èšäºã§ç¢ºèª