Web ãµã€ãéçºã®ã³ã³ããã¹ãã§ã¯ãSSL ãã³ãã·ã§ã€ã¯ã¯ããŠãŒã¶ãŒã®ãã©ãŠã¶ãŒãAppMasterã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãªã©ã®ã¯ã©ã€ã¢ã³ããšãAppMaster ã§çæãããããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ãªã©ã®ãµãŒããŒãšã®éã«æå·åãããéä¿¡ãã£ãã«ã確ç«ããéèŠãªã»ãã¥ãªã㣠ããã»ã¹ã§ãã Secure Socket Layer (SSL) ãšãã®åŸç¶ã§ãã Transport Layer Security (TLS) ãããã³ã«ã®åºç€ãšããŠããã³ãã·ã§ã€ã¯ã¯ãã€ã³ã¿ãŒãããäžã§äº€æãããæ©å¯æ å ±ãä¿è·ããã¯ã©ã€ã¢ã³ããéä¿¡ãããµãŒããŒã®ä¿¡é Œæ§ã確ä¿ããããã«äžå¯æ¬ ã§ãã
SSL ãã³ãã·ã§ã€ã¯ã§ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã®éã§äº€æãããè€éãªäžé£ã®ã¡ãã»ãŒãžã䜿çšããŠãå®å šãªéä¿¡ã®ãã©ã¡ãŒã¿ãããŽã·ãšãŒãããŸãããã³ãã·ã§ã€ã¯ ããã»ã¹ã¯ããããã³ã« ããŒãžã§ã³ã®ç¢ºç«ãæå·ã¹ã€ãŒãã®éžæãããŒäº€æããµãŒããŒèªèšŒã察称ããŒã®ç¢ºç«ãšãã 5 ã€ã®äž»èŠãªã¹ãããã§æ§æãããŸãã
-
ãããã³ã« ããŒãžã§ã³ ããŽã·ãšãŒã·ã§ã³: ã¯ã©ã€ã¢ã³ãã¯ããµããŒããããæé«ã® SSL/TLS ãããã³ã« ããŒãžã§ã³ãæå®ããŠãClientHello ã¡ãã»ãŒãžããµãŒããŒã«éä¿¡ããããšã«ãã£ãŠãã³ãã·ã§ã€ã¯ãéå§ããŸãããµãŒããŒã¯ ServerHello ã¡ãã»ãŒãžã§å¿çããéžæããããããã³ã«ã確èªããŸããå€ã SSL ããŒãžã§ã³ã¯å®å šãšã¿ãªãããªããªã£ããããææ°ã®ã¯ã©ã€ã¢ã³ããšãµãŒããŒã¯éåžžãTLS ããŒãžã§ã³ 1.2 ãŸã㯠1.3 ãéžæããŸãã
-
æå·ã¹ã€ãŒãã®éžæ: ClientHello ã¡ãã»ãŒãžã«ã¯ãã¯ã©ã€ã¢ã³ãããµããŒãããæå·ã¹ã€ãŒãã®åªå é ã«ã©ã³ã¯ä»ãããããªã¹ããå«ãŸããŠããŸããæå·ã¹ã€ãŒãã¯ãããŒäº€æãèªèšŒãæå·åãæŽåæ§æ€èšŒã®ããã®æå·ã¢ã«ãŽãªãºã ã®çµã¿åããã§ãã ServerHello ã¡ãã»ãŒãžå ã®ãµãŒããŒã®å¿çã«ã¯ãéžæãããæå·ã¹ã€ãŒããå«ãŸããŸããããã¯éåžžãåæ¹ããµããŒãããæãå®å šãªãªãã·ã§ã³ã§ãã
-
éµäº€æ: éµäº€æããã»ã¹ã¯ãéžæããæå·ã¹ã€ãŒãã«å¿ããŠç°ãªããDiffie-Hellman (DH) éµäº€æãæ¥åæ²ç· Diffie-Hellman (ECDH) éµäº€æãªã©ã®æ¹æ³ãå¿ èŠã«ãªããŸãã TLS 1.3 ã§ã¯ããã³ãã·ã§ã€ã¯ ããã»ã¹ã¯ããããã®ã¡ãœããã®äžæçãªããªã¢ã³ã (DHE ããã³ ECDHE) ã®ã¿ã䜿çšããŠããŒäº€æãç°¡çŽ åããå®å šãªåæ¹ç§å¯ä¿æãä¿é²ããŸããããã«ãããæ»æè ãç§å¯ããŒã䟵害ããå Žåã§ããéå»ã®éä¿¡ã»ãã·ã§ã³ã埩å·åã§ããªããªããŸãã
-
ãµãŒããŒèªèšŒ: ãµãŒããŒã¯ããã®èº«å ã蚌æããããã«ãä¿¡é Œã§ããèªèšŒå± (CA) ã«ãã£ãŠçœ²åãããããžã¿ã«èšŒææžãšã察å¿ããå ¬éããŒãéä¿¡ããŸããã¯ã©ã€ã¢ã³ãã¯ãèšŒææžã®çœ²åãæå¹æéãçºè¡è ã確èªããŠãèšŒææžã®ä¿¡é Œæ§ãæ€èšŒããŸãããã®æé ã§ã¯ãã¯ã©ã€ã¢ã³ãããªãããŸããµãŒããŒã§ã¯ãªãç®çã®ãµãŒããŒãšéä¿¡ããŠããããšã確èªããããšã§ãäžéè æ»æãé²ããŸãã
-
察称ããŒã®ç¢ºç«: æåŸã«ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã¯ã亀æãããå ¬éããŒãšããŒäº€æããã»ã¹äžã«çæãããå ±æç§å¯ã䜿çšããŠãåäžã®å¯Ÿç§°ããŒãçæããŸãããããã®å¯Ÿç§°ããŒã¯ãåŸç¶ã®ãã¹ãŠã®éä¿¡ãæå·åããã³åŸ©å·åããæ©å¯æ§ãšæŽåæ§ã確ä¿ããŸãã
çµè«ãšããŠãSSL ãã³ãã·ã§ã€ã¯ã¯ã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®å®å šãªæå·åãããæ¥ç¶ã容æã«ãããããWeb ãµã€ãéçºã«ãããŠéèŠãªã»ãã¥ãªã㣠ã³ã³ããŒãã³ãã§ãã AppMaster ã§çæãããã¢ããªã±ãŒã·ã§ã³ã« SSL/TLS ãããã³ã«ãå®è£ ããããšã§ãéçºè ã¯é«ãã»ãã¥ãªãã£åºæºãç¶æããæœåšçãªæ»æè ããæ©å¯ããŒã¿ã®äº€æãä¿è·ã§ããŸããããã«ããã¹ã ãã©ã¯ãã£ã¹ã«åŸããææ°ã®ãããã³ã« ããŒãžã§ã³ãšæå·ã¹ã€ãŒããæ¡çšããããšã§ãéçºè ã¯ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãæå€§éã«é«ããé²åããè åšã«åžžã«å¯Ÿå¿ã§ããŸãã
AppMasterno-codeãã©ãããã©ãŒã ã§ã¯ããšã³ã¿ãŒãã©ã€ãº ã°ã¬ãŒãã®ã»ãã¥ãªãã£æ©èœãšããã©ãŒãã³ã¹ãåããããã¯ãšã³ããWebãããã³ã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ã®çæãå¯èœã«ãªããããææ°ã® SSL/TLS ãããã³ã«ãå©çšããããšã§ããã©ãããã©ãŒã ã®ã¹ã±ãŒã©ãã«ã§å®å šãªã¢ããªã±ãŒã·ã§ã³ãäœæããæ©èœãããã«åŒ·åãããŸãã仿¥ã®ããžã¿ã«ç°å¢ã«ãããŠå®å šãªéä¿¡ãã£ãã«ãäžå¯æ¬ ã§ããããšãèæ ®ãããšã AppMasterãã©ãããã©ãŒã ãš Web ãµã€ãéçºã³ãã¥ããã£å šäœãå©çšããéçºè ã«ãšã£ãŠãSSL ãã³ãã·ã§ã€ã¯ ããã»ã¹ããã£ãããšçè§£ããããšãéèŠã§ãã