Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
コピペでQualys SSL Server Test A+ ゲットだぜ!
Search
atpons
September 25, 2016
Programming
180
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
コピペでQualys SSL Server Test A+ ゲットだぜ!
設定の見直し
atpons
September 25, 2016
More Decks by atpons
See All by atpons
食べログのサーキットブレーカー導入を振り返って
atpons
1
180
TLSから見るSREの未来
atpons
3
780
Securing Credentials for Package Manager and Bundler
atpons
0
240
AWS Organizations で実現する、 マルチ AWS アカウントのルートユーザー管理からの脱却
atpons
1
720
Other Decks in Programming
See All in Programming
RTSPクライアントを自作してみた話
simotin13
0
610
脅威をエンジニアリングの糧にして――現場編 / Turning Threats into Engineering Fuel — Field Edition
nrslib
0
280
AIだと陥りがちなJakarta EE最新技術への移行時の落とし穴と解決策
tnagao7
0
110
CSC307 Lecture 17
javiergs
PRO
0
320
コンテキストの使い捨てをやめる — ビジネスルール駆動開発と miko —
ioki
0
210
その問い、本当に正しいですか?AI時代のエンジニアに必要な哲学と認知科学 / ai-philosophy-cognitive-science
minodriven
11
5.8k
ADKを使って簡単にAIエージェントを作ってみよう
k1mu21
0
270
ECSアプリログをFireLensでコスト削減しようとしたけど諦めた話 in Fargate×Node.js
akihisaikeda
2
4.2k
[2026年度第1回ORセミナー] 計画最適化ベンチャーと競技プログラミング人材
terryu16
0
270
Performance Engineering for Everyone
elenatanasoiu
0
160
Oxcを導入して開発体験が向上した話
yug1224
4
320
New "Type" system on PicoRuby
pocke
1
960
Featured
See All Featured
Documentation Writing (for coders)
carmenintech
77
5.4k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.8k
Bash Introduction
62gerente
615
220k
Claude Code どこまでも/ Claude Code Everywhere
nwiizo
65
56k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
240
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
254
22k
Designing for humans not robots
tammielis
254
26k
A designer walks into a library…
pauljervisheath
211
24k
Producing Creativity
orderedlist
PRO
348
40k
Jess Joyce - The Pitfalls of Following Frameworks
techseoconnect
PRO
1
170
Building the Perfect Custom Keyboard
takai
2
800
What the history of the web can teach us about the future of AI
inesmontani
PRO
1
610
Transcript
ίϐϖͰQualys SSL Server Test A+ ήοτͩͥʂ atpons @ IGGG Meetup
2016 Summer
ࣗݾհ
atpons / ϙϯਣ
https://atpons.com/ ϗεςΟϯά࣌ͷݟ
Έͳ͞Μ SSL ͯ͠·͔͢ʁ
Έͳ͞Μ TLS ͯ͠·͔͢ʁ
None
҆શͳଓ
ੲͷৗࣝ
ূ໌ॻߴ͍
ࠓͷৗࣝ
None
ແྉͷূ໌ॻ
ςετڥ
- Ubuntu 16.04.1 LTS - Apache/2.4.18 (Ubuntu) - $ sudo
letsencrypt —-apache ࡁ ˎˎˎˎˎˎˎˎˎˎ on DigitalOcean
ͳɺͳΜͩͬͯʁ
ʮnginxʯͩͱʁ
;ɺ;͚͟Δͳ ✊
ʮApacheʯͰ ѹత
SSL/TLSͷ੬ऑੑ
Heartbleed POODLE etc…
HTTPSαʔό ઃఆͷॏཁੑ
SSL/TLS ༗ޮ͚ͩͰ ҙຯ͕ͳ͍
ݹ͍ Cipher SuiteͰ ҙຯ͕ͳ͍
Cipher Suite ʹԿΛબͿ 5-4పఈԋश4QFBLFS%FDLIUUQTTQFBLFSEFDLDPNTIJHFLJUMTDIFEJZBOYJΑΓҾ༻ ࠓ5-4ʹԿΛ͏ʁ 伴ަ 34" 'PSXBSE4FDSFDZ %)& &$%)&
σδλϧॺ໊ 34" %44 %4" &$%4" ର҉߸ %&4 3$ "&4 $IB$IB ͦͷଞ ҉߸Ϟʔυ $#$ "&"% $$. ($. 1PMZ ϝοηʔδೝূ ʢϋογϡʣ .% 4)" 4)" 4)" ɿΘͳ͍ɺԫɿҙɺɿࠓͷͱ͜Ζͬͯେৎ ҙɺ҉߸ֶతҙͱকདྷతʹීٴ͕ݟࠐ·Εͳ͍ҙؚ·Ε·͢ ͪͳΈʹɺ ྔࢠίϯϐϡʔλͰ伴ަɺσδλ ϧॺ໊શ෦Ξτʂ Cipher Suite
HTTPSαʔόςετͷ ॏཁੑ
Qualys SSL Server Test
Qualys SSL Server Test
ͱΓ͋͑ͣ͜͜Ͱ A+ औͬͯQiitaʹࡌͤ Ε͍͍ΜͰ͠ΐ
None
HTTPSαʔό ઃఆͩΔ͍ʁ
ྑ͍ײ͡ͷ configΛు͘
Mozilla SSL Configuration Generator
https://mozilla.github.io/ server-side-tls /ssl-config-generator/
σϞ
Demo • Mozilla SSL Configuration Generator • Apache / Intermediate
/ HSTS Enabled • Cipher Suite • ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE- ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA- AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM- SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE- RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256- SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA- AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128- SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3- SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM- SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128- SHA:AES256-SHA:DES-CBC3-SHA:!DSS
Qualys SSL Server Test
A+ήοτͩͥʂ
Conclusion • A+ ධՁΛಘΔͨΊʹϓϩτίϧCipher Suiteͷ ݟ͕͠ඞཁ • ࠓޙHTTP/2ߦ͘ͳΒTLS 1.2͕ཁ݅ʹͳ͍ͬͯΔ •
͋͘·ͰHTTPSαʔόͷSSL/TLSͷݕূ • Webαʔόࣗମͷ੬ऑੑɼXSSͱ͔ɼҰൠతͳη ΩϡϦςΟରࡦඞཁͰ͢ʢࠓճলུ͍ͯ͠·͢ʣ
Conclusion • Let’s Encrypt • DVূ໌ॻͳͷͰݸਓϢʔε͚ͩΑͶ • 90Ͱͷߋ৽͕ඞཁͳͷͰͦͷ࡞ۀͷࣗಈ ԽΛΕΔͱࠔΔ •
ͪΖΜcronͰࣗಈԽʙ
ࢀߟจݙ • TLSపఈԋश • https://speakerdeck.com/shigeki/tlsche-di- yan-xi