Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
HTTPSの基本から NetworkSecurityConfigまで
Search
Amane Nikaido
February 09, 2018
Technology
4.5k
5
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
HTTPSの基本から NetworkSecurityConfigまで
Amane Nikaido
February 09, 2018
More Decks by Amane Nikaido
See All by Amane Nikaido
React with Kotlin
a2kaido
2
1.3k
Use Kotlin for build.gradle.
a2kaido
0
520
JavaからみたKotlin
a2kaido
0
140
Other Decks in Technology
See All in Technology
AIは推し活である。
kurazuuuuuu
2
1k
「大丈夫そう?」をObservabilityで確かめる
mrmtsu
0
220
Datadog で始める トークンセーフティなAI 導⼊と定着
vkbaba
1
120
キャリアLT今日までそして明日から
kentapapa
1
100
10年欲しかった音楽管理アプリを、AIと一緒に作りはじめた
judau
1
170
ボードゲームの遊び相手をFoundation Modelsで作る / iOSDC Japan 2026
genda
0
220
【Findyテック文化祭ワークショップ】新卒エンジニア&採用担当と作る、 なりたい姿と今やるべき一歩
dip_tech
PRO
0
140
高負荷プロダクション環境におけるAWS Lambdaのリアル 〜スケールとコストを左右する実行ライフサイクルの技術仕様〜
maimyyym
2
790
AIエージェントの一手は 誰も見ていない - Falco拡張OSS「Prempti」とeBPFで サーバーレス実行基盤を二層防御する
keitah
1
640
「ピッケル本」日本語版は4.0(第6版)が出版されるべき / pickaxe4-nagoyark05
kakutani
2
310
3人で1000GPU超を統合運用する?マルチクラウド&オンプレを跨ぐ、構築と運用のリアル!
kazukun0716
2
710
AIエージェント時代のPlatform as a Product —— テックリードがPdMとして回す発見・導入・計測 / Platform as a Product in the AI Agent Era
toshi0607
1
490
Featured
See All Featured
Large-scale JavaScript Application Architecture
addyosmani
515
110k
Stop Working from a Prison Cell
hatefulcrawdad
274
21k
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.9k
How to audit for AI Accessibility on your Front & Back End
davetheseo
0
550
Building the Perfect Custom Keyboard
takai
2
890
Build your cross-platform service in a week with App Engine
jlugia
234
19k
Kristin Tynski - Automating Marketing Tasks With AI
techseoconnect
PRO
0
530
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
The Curse of the Amulet
leimatthew05
3
15k
First, design no harm
axbom
PRO
2
1.3k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
123
22k
How STYLIGHT went responsive
nonsquared
100
6.3k
Transcript
%SPJE,BJHJ )5514ͷجຊ͔Β /FUXPSL4FDVSJUZ$POpH·Ͱ ೋ֊ಊ ว (Amane Nikaido) @a2kaido
ࣗݾհ • ௨৴͕͖Ͱ͢ • conbu͞Μͷ͓ख͍Λ ͠·ͨ͠
ຊηογϣϯͷத • HTTPS௨৴ͷׂͱΈ • NetworkSecurityConfigʹ͍ͭͯ • NΑΓલͷPinning Certificates • Pinning
Certificatesͷӡ༻
എܠ • ެऺແઢLANʹଓ͢Δػձͷ૿Ճ • ௨৴༰ͷ౪ௌվ᜵ͷՄೳੑ͕͋Δ
2014 SSLূ໌ॻݕূͷҙשى
2016 HTTPSͷεεϝ • Protecting against unintentional regressions to cleartext traffic
in your Android apps https://android-developers.googleblog.com/2016/04/protecting-against-unintentional.html • Mythbusting HTTPS: Squashing security’s urban legends - Google I/O 2016 https://www.youtube.com/watch?v=YMfW1bfyGSY
2017 Android Developers Blog • 2018/11·ͰʹTarget API levelΛ26Ҏ্ʹ ͠·͠ΐ͏ •
Android N͔ΒϢʔβʔ͕Πϯετʔϧ ͨ͠ϧʔτূ໌ॻΛ৴པ͠ͳ͍Α͏ʹ https://android-developers.googleblog.com/2017/12/improving-app-security-and- performance.html
https://goo.gl/n4Aahh
Androidͷ Ξοϓσʔτ
Android M • usesCleartextTraffic • ฏจͰͷ௨৴Λېࢭ͢Δઃఆ <application … android:usesCleartextTraffic=“false”>
… </application>
Android N • Ϣʔβ͕Πϯετʔϧͨ͠ϧʔτূ໌ॻ Λ৴པ͠ͳ͍ • NetworkSecurityConfig • ฏจͰͷ௨৴ͷࢭ •
CAͷΞϯΧʔ • Pinning Certificates(ϐϯཹΊ)
ͦͦHTTPSͱ
҉߸Խ௨৴ͷࡾཁૉ • ػີੑ • ϝοηʔδશੑ • ΤϯυϙΠϯτਅਖ਼ੑ
҉߸Խ௨৴ͷࡾཁૉ • ػີੑ • ϝοηʔδશੑ • ΤϯυϙΠϯτਅਖ਼ੑ ҉߸Խ͞Ε͍ͯͯ ౪ௌ͞Εͳ͍͜ͱ
҉߸Խ௨৴ͷࡾཁૉ • ػີੑ • ϝοηʔδશੑ • ΤϯυϙΠϯτਅਖ਼ੑ վ͟Μ͕ͳ͘ શͰ͋Δ͜ͱ
҉߸Խ௨৴ͷࡾཁૉ • ػີੑ • ϝοηʔδશੑ • ΤϯυϙΠϯτਅਖ਼ੑ ਖ਼͍͠௨৴ઌͱ ௨৴͍ͯ͠Δ͜ͱ
҉߸Խ௨৴ͷࡾཁૉ • ػີੑ • ϝοηʔδશੑ • ΤϯυϙΠϯτਅਖ਼ੑ HTTPSͰ҆શੑ͕୲อ͞Ε͍ͯΔͣͰʁ
HTTPS௨৴Λ͢ΔͨΊͷ ূ໌ॻͷ
Client Server
Client Server ΄Μͱʹਖ਼͍͠௨৴૬खͳͷ͔ͳʁ
Client Server ΄Μͱʹਖ਼͍͠௨৴૬खͳͷ͔ͳʁ Certification Authority(ೝূہ)
Client Server Certification Authority(ೝূہ) ϧʔτূ໌ॻ
Client Server Certification Authority(ೝূہ) ϧʔτূ໌ॻ ॺ໊͖ SSLূ໌ॻൃߦ
Client Server Certification Authority(ೝূہ) ϧʔτূ໌ॻ ॺ໊͖ SSLূ໌ॻൃߦ SSLূ໌ॻ
Client Server Certification Authority(ೝূہ) ϧʔτূ໌ॻ ॺ໊͖ SSLূ໌ॻൃߦ SSLূ໌ॻ CAͷॺ໊͕͋Δ͔Β ؒҧ͍ͳ͍
HTTPS௨৴ͷ ϋϯυγΣΠΫ
HTTPS௨৴ͷྲྀΕ 1/4 ClientHello Client Server
HTTPS௨৴ͷྲྀΕ 2/4 ClientHello Client Server ServerHello Certificate
HTTPS௨৴ͷྲྀΕ 2/4 ClientHello Client Server ServerHello Certificate ূ໌ॻΛνΣοΫ ৴པ͢ΔCAͷॺ໊͕͋Δ͔
HTTPS௨৴ͷྲྀΕ 3/4 ClientHello Client Server ServerHello Certificate Finish Finish
HTTPS௨৴ͷྲྀΕ 4/4 ClientHello Client Server ServerHello Certificate Finish Finish HTTPS
தؒऀ߈ܸ Client Server
தؒऀ߈ܸ ClientHello Client Server ClientHello ਖ਼͍͠ূ໌ॻ
தؒऀ߈ܸ ClientHello Client Server ClientHello ਖ਼͍͠ূ໌ॻ ূ໌ॻΛࠩ͠ସ͑
தؒऀ߈ܸ ClientHello Client Server ClientHello ਖ਼͍͠ূ໌ॻ ِͷূ໌ॻ
தؒऀ߈ܸ ClientHello Client Server ClientHello ਖ਼͍͠ূ໌ॻ ِͷূ໌ॻ Finish Finish Finish
Finish HTTPS HTTPS
தؒऀ߈ܸ ClientHello Client Server ClientHello ਖ਼͍͠ূ໌ॻ ِͷূ໌ॻ Finish Finish Finish
Finish HTTPS HTTPS ͜͜Ͱূ໌ॻͷݕূΛ ͍ͯ͠ΔͷͰʁ
ِͷূ໌ॻΛ৴པʁ • ߈ܸऀΛCAͱͯ͠৴པ͍ͯ͠Δ (ϧʔτূ໌ॻΛΠϯετʔϧ͍ͯ͠Δ) Մೳੑ • ߈ܸऀ͕CA͔Βॺ໊͖ূ໌ॻΛ औಘͨ͠Մೳੑ
ِͷূ໌ॻΛ৴པʁ • ߈ܸऀΛCAͱͯ͠৴པ͍ͯ͠Δ (ϧʔτূ໌ॻΛΠϯετʔϧ͍ͯ͠Δ) Մೳੑ • ߈ܸऀ͕CA͔Βॺ໊͖ূ໌ॻΛ औಘͨ͠Մೳੑ ৴པ͢ΔCAΛ੍ݶ͢Ε͛Δ
ِͷূ໌ॻΛ৴པʁ • ߈ܸऀΛCAͱͯ͠৴པ͍ͯ͠Δ (ϧʔτূ໌ॻΛΠϯετʔϧ͍ͯ͠Δ) Մೳੑ • ߈ܸऀ͕CA͔Βॺ໊͖ূ໌ॻΛ औಘͨ͠Մೳੑ αʔό͕ฦ٫͢Δਖ਼͍͠ূ໌ॻΛ ͋Β͔͡Ί͍ͬͯΕ͛Δ
Android N • Ϣʔβ͕Πϯετʔϧͨ͠ϧʔτূ໌ॻ Λ৴པ͠ͳ͍ • NetworkSecurityConfig • ฏจͰͷ௨৴ͷࢭ •
CAͷΞϯΧʔ • Pinning Certificates(ϐϯཹΊ)
NetworkSecurityConfig (Android NҎ߱)
NetworkSecurityConfig • ฏจͰͷ௨৴ͷࢭ • CAͷΞϯΧʔ • Pinning Certificates(ϐϯཹΊ)
ઃఆํ๏ • res/xml/network_security_config.xml • ઃఆ༰Λهड़ • AndroidManifest.xml <application …
android:networkSecurityConfig="@xml/network_security_config"> … </application>
ฏจͰͷ௨৴ͷࢭ <network-security-config> <domain-config cleartextTrafficPermitted="false"> <domain includeSubdomains="true">secure.example.com</domain> </domain-config> </network-security-config>
CAͷΞϯΧʔ <network-security-config> <domain-config> <domain includeSubdomains="true">secure.example.com</domain> <domain includeSubdomains="true">cdn.example.com</domain> <trust-anchors> <certificates src="@raw/trusted_roots"/>
</trust-anchors> </domain-config> </network-security-config>
Pinning Certificates (ϐϯཹΊ) <network-security-config> <domain-config> <domain includeSubdomains="true">example.com</domain> <pin-set expiration="2018-01-01"> <pin
digest=“SHA-256”>{ hash value }</pin> <!-- backup pin --> <pin digest=“SHA-256”>{ hash value }</pin> </pin-set> </domain-config> </network-security-config>
Pinning Certificates <network-security-config> <domain-config> <domain includeSubdomains="true">example.com</domain> <pin-set expiration="2018-01-01"> <pin digest=“SHA-256”>{
hash value }</pin> <!-- backup pin --> <pin digest=“SHA-256”>{ hash value }</pin> </pin-set> </domain-config> </network-security-config> PinningͷظݶΛઃఆՄೳ ͷγεςϜ࣌ؒͱͷൺֱ
Pinning Certificates <network-security-config> <domain-config> <domain includeSubdomains="true">example.com</domain> <pin-set expiration="2018-01-01"> <pin digest=“SHA-256”>{
hash value }</pin> <!-- backup pin --> <pin digest=“SHA-256”>{ hash value }</pin> </pin-set> </domain-config> </network-security-config> αʔόʔͷSSLূ໌ॻͷϋογϡΛઃఆ
Pinning Certificates <network-security-config> <domain-config> <domain includeSubdomains="true">example.com</domain> <pin-set expiration="2018-01-01"> <pin digest=“SHA-256”>{
hash value }</pin> <!-- backup pin --> <pin digest=“SHA-256”>{ hash value }</pin> </pin-set> </domain-config> </network-security-config> base64 encoded digest of X.509 SubjectPublicKeyInfo (SPKI)
digestͷ࡞Γํ (खݩͷূ໌ॻͰ) ιʔε: https://github.com/datatheorem/TrustKit/blob/master/ get_pin_from_certificate.py $ python get_pin_from_certificate.py ca.pem
digestͷ࡞Γํ (αʔόʔ͔Β) $ openssl s_client \ -connect <hostname>:<port> \ |
openssl x509 -pubkey -noout \ | openssl rsa -pubin -outform der \ | openssl dgst -sha256 -binary \ | openssl enc -base64
NetworkSecurityConfig ͷιʔείʔυͷ༠͍
ؾ࣋ͪ • ͳʹ͔͋ͬͨ࣌ʹௐ͍ࠪ͢͠ • ؾʹͳΔڍಈΛ֬ೝͰ͖ΔΑ͏ʹͳΔ
ؔ࿈Ϋϥε • ManifestConfigSourceΫϥε • ઃఆͷಡΈࠐΈ • XmlConfigSourceΫϥε • network_security_config.xmlΛύʔε
ؔ࿈Ϋϥε • NetworkSecurityConfigΫϥε • XmlConfigSourceͰΠϯελϯεԽ͞ΕΔ • NetworkSecurityTrustManagerΫϥε • ূ໌ॻνΣοΫͱPinningνΣοΫΛ࣮ࢪ •
ূ໌ॻνΣοΫ࣮ॲཧdelegateͷ TrustManagerImplʹͤΔ
ؔ࿈Ϋϥε • TrustManagerImplΫϥε • ূ໌ॻνΣοΫͷ࣮ • https://github.com/google/conscrypt/blob/master/platform/ src/main/java/org/conscrypt/TrustManagerImpl.java • ߹ΘͤͯಡΉͱྑ͍
https://developer.android.com/training/ articles/security-ssl.html
Pinning Certificates <network-security-config> <domain-config> <domain includeSubdomains="true">example.com</domain> <pin-set expiration="2018-01-01"> <pin digest=“SHA-256”>{
hash value }</pin> <!-- backup pin --> <pin digest=“SHA-256”>{ hash value }</pin> </pin-set> </domain-config> </network-security-config> PinningͷظݶΛઃఆՄೳ ͷγεςϜ࣌ؒͱͷൺֱ ࠶ ׃
NetworkSecurityTrustManager private void checkPins(List<X509Certificate> chain) throws CertificateException { PinSet pinSet
= mNetworkSecurityConfig.getPins(); if (pinSet.pins.isEmpty() || System.currentTimeMillis() > pinSet.expirationTime || !isPinningEnforced(chain)) { return; } … } PinningͷظݶΛઃఆՄೳ ͷγεςϜ࣌ؒͱͷൺֱ
ҙ • ʮશͯཧղͨ͠ʯͱ͍ͬͯࣗͰ ࣮͠ͳ͍͜ͱ
Android NΑΓલͰ Pinning Certificates͢Δ
Pinning Certificates (ϐϯཹΊ) ɹ TrustKit-AndroidΛར༻ ɹ OkHttpClientͷcertificatePinnerΛར༻
Pinning Certificates (ϐϯཹΊ) → TrustKit-AndroidΛར༻ ɹ OkHttpClientͷcertificatePinnerΛར༻
TrustKit-AndroidΛར༻ • API 15+ • MIT License • NetworkSecurityConfigͷઃఆΛ ಡΈࠐΜͰূ໌ॻͷݕূΛ͢Δ
TrustKit-AndroidΛར༻ TrustKit.initializeWithNetworkSecurityConfiguration(this); URL url = new URL("https://www.datatheorem.com"); String serverHostname =
url.getHost(); // HttpsUrlConnection HttpsURLConnection connection = (HttpsURLConnection) url.openConnection(); connection.setSSLSocketFactory( TrustKit.getInstance().getSSLSocketFactory(serverHostname) ); // OkHttp 3.3.x and higher OkHttpClient client = new OkHttpClient().newBuilder() .sslSocketFactory( TrustKit.getInstance().getSSLSocketFactory(serverHostname), TrustKit.getInstance().getTrustManager(serverHostname) ) .build(); }
TrustKit-AndroidΛར༻ TrustKit.initializeWithNetworkSecurityConfiguration(this); URL url = new URL("https://www.datatheorem.com"); String serverHostname =
url.getHost(); // HttpsUrlConnection HttpsURLConnection connection = (HttpsURLConnection) url.openConnection(); connection.setSSLSocketFactory( TrustKit.getInstance().getSSLSocketFactory(serverHostname) ); // OkHttp 3.3.x and higher OkHttpClient client = new OkHttpClient().newBuilder() .sslSocketFactory( TrustKit.getInstance().getSSLSocketFactory(serverHostname), TrustKit.getInstance().getTrustManager(serverHostname) ) .build(); }
TrustKit-AndroidΛར༻ TrustKit.initializeWithNetworkSecurityConfiguration(this); URL url = new URL("https://www.datatheorem.com"); String serverHostname =
url.getHost(); // HttpsUrlConnection HttpsURLConnection connection = (HttpsURLConnection) url.openConnection(); connection.setSSLSocketFactory( TrustKit.getInstance().getSSLSocketFactory(serverHostname) ); // OkHttp 3.3.x and higher OkHttpClient client = new OkHttpClient().newBuilder() .sslSocketFactory( TrustKit.getInstance().getSSLSocketFactory(serverHostname), TrustKit.getInstance().getTrustManager(serverHostname) ) .build(); }
Pinning Certificates ɹ TrustKit-AndroidΛར༻ → OkHttpClientͷcertificatePinnerΛར༻
OkHttpClientͷcertificatePinnerΛར༻ public void run() throws Exception { OkHttpClient client =
new OkHttpClient.Builder() .certificatePinner(new CertificatePinner.Builder() .add("publicobject.com", “sha256/{ hash value }”) .build()) .build(); Request request = new Request.Builder() .url("https://publicobject.com/robots.txt") .build(); Response response = client.newCall(request).execute(); }
OkHttpClientͷcertificatePinnerΛར༻ public void run() throws Exception { OkHttpClient client =
new OkHttpClient.Builder() .certificatePinner(new CertificatePinner.Builder() .add("publicobject.com", “sha256/{ hash value }”) .build()) .build(); Request request = new Request.Builder() .url("https://publicobject.com/robots.txt") .build(); Response response = client.newCall(request).execute(); } PinningͷظݶΛઃఆෆՄ
Pinning Certificatesͷ ӡ༻
ӡ༻࣌ͷϙΠϯτ • αʔόʔαΠυͱͷௐ • SSLূ໌ॻΛม͑ΒΕΔͱ௨৴Ͱ͖ͳ͘ͳΔ • SSLূ໌ॻߋ৽࣌ͷϧʔϧ੍ఆ • Pinning CerficatesͷexpireઃఆͳͲ
ཧతͳӡ༻ Server ূ໌ॻAظݶ ূ໌ॻAϐϯཹΊ + expireઃఆͳ͠ Client
ཧతͳӡ༻ Server ূ໌ॻAظݶ Client ূ໌ॻBൃߦ ূ໌ॻAϐϯཹΊ + expireઃఆͳ͠
ཧతͳӡ༻ Server ূ໌ॻAظݶ Client ূ໌ॻBൃߦ ূ໌ॻA + BϐϯཹΊͷΞϓϦϦϦʔε ڧ੍Ξοϓσʔτ ূ໌ॻAϐϯཹΊ
+ expireઃఆͳ͠
ཧతͳӡ༻ Server ূ໌ॻAظݶ Client ূ໌ॻBൃߦ ূ໌ॻBʹΓସ͑ ূ໌ॻA + BϐϯཹΊͷΞϓϦϦϦʔε ڧ੍Ξοϓσʔτ
ূ໌ॻAϐϯཹΊ + expireઃఆͳ͠
ཧతͳӡ༻ͷؾ࣋ͪ • ৗʹPinning Certificates͕༗ޮ • ূ໌ॻͷೖΕସ͑ͷλΠϛϯάͰ༗ޮ • expireͷઃఆΛ͍Ε͍ͯͳ͍ͷͰ γεςϜ͕࣌ؒͣΕ͍ͯͯ༗ޮ
ཧతͳӡ༻ͷؾ࣋ͪ • ৗʹPinning Certificates͕༗ޮ • ূ໌ॻͷೖΕସ͑ͷλΠϛϯάͰ༗ޮ • expireͷઃఆΛ͍Ε͍ͯͳ͍ͷͰ γεςϜ͕࣌ؒͣΕ͍ͯͯ༗ޮ ⚠
ΞϓϦͷߋ৽ΛΕΔͱ௨৴Ͱ͖ͳ͘ͳΔ ⚠ ڧ੍Ξοϓσʔτ͕ඞཁ
expireઃఆʹΑΔଥڠҊ Server ূ໌ॻAظݶ Client ূ໌ॻAϐϯཹΊظݶ
expireઃఆʹΑΔଥڠҊ Server ূ໌ॻAظݶ Client ূ໌ॻAϐϯཹΊظݶ ূ໌ॻBൃߦ
expireઃఆʹΑΔଥڠҊ Server ূ໌ॻAظݶ Client ূ໌ॻAϐϯཹΊظݶ ূ໌ॻBൃߦ ূ໌ॻBʹΓସ͑
expireઃఆʹΑΔଥڠҊ Server ূ໌ॻAظݶ Client ূ໌ॻAϐϯཹΊظݶ ূ໌ॻBൃߦ ূ໌ॻBʹΓସ͑ ূ໌ॻBϐϯཹΊ൛ϦϦʔε
ଥڠҊͷؾ࣋ͪ • ΞϓϦͷߋ৽ΛΕͯ௨৴Ͱ͖Δ • ڧ੍Ξοϓσʔτ͕ඞཁͳ͍ • ূ໌ॻΓସ͑࣌ʹPinning͕ޮ͔ͳ͍ ࣌ظ͕͋Δ
·ͱΊ
·ͱΊ • HTTPΊ·͠ΐ͏ • NetworkSecurityConfigʹΑͬͯɺѱҙ ͷ͋Δ߈ܸऀ͔ΒϢʔβʔΛकΔઃఆ͕ ؆୯ʹͰ͖ΔΑ͏ʹͳΓ·ͨ͠ • ӡ༻࣌ؾΛ͚ͭ·͠ΐ͏
͝੩ௌ͋Γ͕ͱ͏ ͍͟͝·ͨ͠
Appendix • GMailͷϝοηʔδݟΒΕͨ https://www.computerworld.com/article/2510951/cybercrime-hacking/ hackers-spied-on-300-000-iranians-using-fake-google-certificate.html • ෆਖ਼ͳূ໌ॻ͕ൃߦ͞Εͨ http://www.atmarkit.co.jp/news/201109/08/diginotar.html