SSLãå®éã«è³Œå ¥ã»èšå®ããŠã¿ã
ãã¹ã¯ãŒããé©åã«ç®¡çãããµã³ãã«ã·ã¹ãã (ãã®ïŒ)ã§ãã°ã€ã³ã®æ©èœãæã£ãWebã¢ããªã±ãŒã·ã§ã³ãäœæããŠã¿ãŸããããã¹ã¯ãŒãã®ããã·ã¥åããã¹ã¯ãŒããªã»ããã®å®è£ ã¯æåããŸãããããŸã ãŸã ãã°ã€ã³ã·ã¹ãã ãšããŠã¯åé¡ããããŸããããã§ä»åã¯åé¡ã®ïŒã€ã§ããSSLã§ãªãç¹ã解決ããŸãã
èŠãŠã®éããååèªåãäœæãããã°ã€ã³ç»é¢ã¯SSLã§ã¯ãããŸãããäœãåé¡ããšèšããšPOSTããããŒã¿ãæå·åãããã«ãããã¯ãŒã¯ã«æµããããšã§ããå®éã«WireSharkãåãããŠPOSTããããŒã¿ããã£ããã£ãããã®ã以äžã§ãã

äºããŠãŒã¶ID:tsukaby1234ããã¹ã¯ãŒã:password1234ãšããŠç»é²ããŠããããã°ã€ã³ç»é¢ã§ãã°ã€ã³ãã¿ã³ãæŒãããšãã®ãã£ããã£ç»åã§ãã
ãŠãŒã¶IDããã¹ã¯ãŒãããã¬ãã¬ã§ãã
äŸãã°ãéä¿¡çµè·¯ã«ã¯ã©ãã«ãŒãå± ãŠããã±ãããç£èŠããŠããããã¹ã¯ãŒããæŒããããŠããŸããŸãããŠãŒã¶ãã«ãã§ãªã©ã§Freeã®ç¡ç·LANã¹ãããã«æ¥ç¶ããŠãSSLã§ãªããµãŒãã¹ãå©çšãããšããŸãããã®ã¹ãããã¯å®ã¯ã¯ã©ãã«ãŒãçšæããåœã®ã¹ãããã§éä¿¡ãã±ãããè§£æãããããããšæŒããããŠããŸããŸããARPã¹ããŒãã£ã³ã°ã§ãå¯èœããšæããŸãã
ãããªèš³ã§å°ãã§ãã·ã¹ãã ãå ç¢ã«ããããã«**SSLãå°å ¥ããŸãã**SSLã¯æ£èŠã®è²©å£²åºããè³Œå ¥ãããªã¬ãªã¬èšŒææžã¯é¿ããŸãããªã¬ãªã¬èšŒææžã¯ãã©ãŠã¶ã«ã€ã³ã¹ããŒã«ãããŠããã«ãŒãèªèšŒå±ã®èšŒææžããèªèšŒããããã§ãŒã³ã«å«ãŸããªããããèŠå衚瀺ãåºãŠããŸããŸããããã§ã¯æå³ããªãã®ã§è³Œå ¥ããŸãã
è³Œå ¥å ã®éžå®
èšŒææžã¯çš®é¡ãè³Œå ¥å ãæ§ã ã§ããèšŒææžã«ã¯ã©ã³ã¯ããã£ãŠãéè¡ç³»ã ãšäŸãã°ä»¥äžã®ããã«ã¢ãã¬ã¹ããŒãç·è²ã«ãªãé«ã©ã³ã¯ã®ãã®ãå©çšããŠããŸãã

ããã¯VeriSignã®EV SSLãšãããã®ã§å¹Žé20äžè¿ãã®è²»çšãããããŸããEV SSLã¯ä»ã®äŒæ¥ã§ã売ã£ãŠããŠããå°ãå®äŸ¡ã§ãããããã§ãé«äŸ¡ã§ããå人ã¬ãã«ã§ã¯äžèŠã§ããã§ã¯æ®éã®SSLãè³Œå ¥ãããããšæã£ãŠã1äžïœ3äžãããã¯ããããŸããã§ããã ãç¯çŽãããã®ã§ãä»åã¯æ Œå®ã®SSLã§è¡ããŸãã
å®ãSSLèšŒææžã¯RapidSSLäžæã ãšæããŸããã³ã¢ããå®ããã€ããããŸãããããã¯äžåºŠã¯ã©ãã¯ã§äºä»¶ã«ãªã£ãŠãã®ã§é¿ããŸãããã®æ¥çã¯ä¿¡é Œãåœã§ãã®ã§ã»ã»ã»ãRapidSSLã¯å ¬åŒãµã€ãã§è²·ã£ãŠãçŽ3000åãæ¥æ¬ã®æ£èŠä»£çåºã ãšçŽ2500åã販売代çåºã ãšããã«å®ããŠãçŽ1400åã§è³Œå ¥ã§ããŸãã
ãšããããã§ãRapidSSLãéžæã販売代çåºã¯ãã£ãã¡ã€ã³ååäŒç€ŸãéžæããŸããã
è³Œå ¥
ãŸãã¯http://define.co.jp/ssl/geotrust/rapidssl/ããè³Œå ¥ãµã€ããžãžã£ã³ãã
äŒå¡ç»é²ããŸãããã®äŒç€Ÿã®äŒå¡ããŒãžã¯åœç¶SSLã§ãããå ã®EV SSLã§ãããã¡ãããšèããŠãã®ããªã
RapidSSLãã«ãŒãã«å ¥ããŠè³Œå ¥æç¶ããžãPayPalãéžã¹ãŸãããèªåã¯äœ¿ããªãã®ã§éè¡æ¯ã蟌ã¿ãéžæããŸãããã¯ã¬ã«æ±ºæžãç¡ãã®ãæ®å¿µã§ããïŒé£äŒã®æ¥æã«è³Œå ¥ãæ¯èŸŒãããã®ã§ã次ã®éè¡ã®å¶æ¥æ¥ãã€ãŸãç«æ(ææã¯ç¥æ¥ã§ãã)ã«æ¯ã蟌ãŸããŸããAM11:30é ã«ãã£ãã¡ã€ã³ããå ¥éå®äºã¡ãŒã«ãæ¥ãŸããã
å ¥éå®äºã¡ãŒã«ã®æ¬¡ã¯èšŒææžçºè¡URIã®æ¡å ã¡ãŒã«ãå±ããŸãããŸã èšŒææžã«é¢ããæ å ±ã¯äœãæç€ºããŠããªãèš³ã§ããããåœç¶çºè¡ãããŸããããã¡ãã§ãããããèšŒææžãäœã£ãŠãã ããããšããäŸé ŒãããŸãã
èšŒææžã®äœæ(äŸé Œ)ãšèšçœ®
以äžã®ãµã€ããåèã«ãªããŸãã
ãããã®VPSïŒCentOS 5.5ïŒã« RapidSSL ãã€ã³ã¹ããŒã«ãããŸã§ã®ã¡ã¢
å 人ã®çµéšãé Œãã«ãããŠããã£ãŠãèªåãæç¶ããé²ããŸãã
ãŸãserver.csrãäœæããŠãããã«çœ²åãããèšŒææžãäœæããããäŸé ŒããŸããäŸé Œã¯ã¡ãŒã«ã«èšèŒãããURLå ã§è¡ããŸãããã£ãã¡ã€ã³ã®RapidSSLã ãšãããªæãã®ããŒãžãåºãŠããŸãã

see exampleã®ãªã³ã¯ã§äŸãèŠãã°ããããŸãããçæããserver.csrã®äžèº«ã貌ãä»ããŸãã
-----BEGIN CERTIFICATE REQUEST-----
(é©åœãªæåå)
-----END CERTIFICATE REQUEST-----
åŸã¯ä»ã®éžæéšåã§ã以äžãéžãã§æ¬¡ãžé²ã¿ãŸãã
- Email Authentication
- Apache + MOD SSL
- SHA2 with a 256-bit Digest
CSRã¯èŸæžãèŠãã°ããããŸãããèšŒææžçºè¡ã®ãªã¯ãšã¹ãã®ããšã§ããããããèšŒææžãšã¯å€§éæã«ãããšå ¬ééµãšãã®å ¬ééµã®çœ²åã§ãããªãå ¬ééµã«çœ²åãå¿ èŠãªã®ããšãããšãå ¬ééµãåœè£ ãããå Žåãããã«æ°ä»ããªãããã§ããSSLã§ãµã€ãã«ã¢ã¯ã»ã¹ãããšãéä¿¡å ã®ãµãŒãããå ¬ééµãåãåããŸããããã¯ã€ãŸããããã®å ¬ééµã䜿ã£ãŠããŒã¿ãæå·åããŠéã£ãŠããç§ããè§£èªã§ããªãããå¹³æ°ã ãïŒããšèšã£ãŠããäºãšåãã§ãããããããã®å ¬ééµã¯æ¬åœã«æ£èŠã®(èªåãéä¿¡ããã)ãµãŒãã®ãã®ãªã®ãåãããŸãããåœè£ ããããã®ã ãšãããããã®åœè£ ãã人ã¯åœè£ ããå ¬ééµãšå¯Ÿã«ãªãç§å¯éµãæã£ãŠããã®ã§ããããè§£èªã§ããŠããŸããŸããããã ãšããºã€ã®ã§ã眲åãšããæ¹ãããæ€ç¥ããä»çµã¿ã䜿ã£ãŠå ¬ééµãåœè£ ã§ããªãããã«ããŸããCSRã®è©±ã«æ»ããŸãããèªèšŒå±ã¯å ¬ééµã«çœ²åãããŠèšŒææžãäœã£ãŠããå¿ èŠãããã®ã§ãããããé¡ãããŸããšäŸé Œããã®ãCSRãšããããšã§ãã
次ã®ç»é¢ã§ã¯èªåã®CSRã®å 容確èªãšã¡ãŒã«èªèšŒã®ããã®ã¡ãŒã«ã¢ãã¬ã¹ãèªåã®æ å ±ãå ¥åããŸããã¡ãŒã«èªèšŒã§ã¯webmaster@[èªåã®ãã¡ã€ã³]ãéžã³ãŸãããAlias webmasterãäœæããŠããã®ã§ãå¥ã®ã¡ã¢ãã«å±ãããã«ãªã£ãŠããŸããå¿è«webmasterãšããLinuxãŠãŒã¶ãäœã£ãŠãæ§ããŸããããèªåã®æ å ±ãå ¥åããéšåã§ã¯ãTitleããšãªã£ãŠããéšåãè¯ãåãããŸããã§ãããããã¯ã©ãããã圹è·ããšããæå³ã®ããã§ããé©åœã«å ¥åããã°è¯ãã§ããããèªåã¯ãSSLããšãå ¥åããŠãããŸããã
確å®ãããšäžèšã®ã¡ãŒã«ã¢ãã¬ã¹ãèªåã®å Žåã¯webmaster@tsukaby.comã«ç¢ºèªã¡ãŒã«ãæ¥ãã®ã§ã¡ãŒã«å ã®URLãéããŸãã

äžèšã®ç»é¢ã§æ¿èªãããšãCSRã®å 容確èªç»é¢ã§å ¥åããèªåã®æ å ±ã®ã¡ãŒã«ã¢ãã¬ã¹ã«ã¡ãŒã«ãæ¥ãŸããèªåã®å Žåã¯gmailã§ããããã«ä»¥äžã®ãããªæååãèŒã£ãŠããããããèšŒææžã§ãããã®å 容ãserver.crtã«ã³ããããŸãã
-----BEGIN CERTIFICATE-----
(é©åœãªæåå)
-----END CERTIFICATE-----
èšŒææžã®åäœç¢ºèª
åºæ¬çã«äžèšã§ç€ºããURLã®éããèšå®ããŸãããã ããäžèšã®URLã¯SSL販売代çåºãRapid-SSL.jpã§ãããä»åèªåãéžãã ãã£ãã¡ã€ã³ååäŒç€Ÿã§ã¯ãããŸããããã®ãããããã€ãéãããããŸããã
ãããŸã§ã§ https ã«ã¢ã¯ã»ã¹ããŠã¿ããã©ã ãæ¥ç¶ã®å®å šæ§ã確èªã§ããŸãããïŒFirefoxïŒã£ãŠèšãããã
èªåã®å Žåã¯ãã®ç»é¢ã¯åºãŸããã§ãããçç±ã¯äžæã§ããèªèšŒãã§ãŒã³ã®éçšã§ãäžè¶³ããŠããäžéèªèšŒå±èšŒææžãã©ããããåã£ãŠããŠããã®ã§ããããã»ã»ã»ã
ãäžéèšŒææžããã¡ã€ã«ãæ°èŠäœæããŠã ã¡ãŒã«ã§éãããŠããå 容ãã³ããããã
ãã£ãã¡ã€ã³ã®å Žåã**Your RapidSSL certificate:**ãšããããã«ãèªåã®èšŒææžã ãã¡ãŒã«ã§éãããŠããŸããã§ã¯äžéèªèšŒå±èšŒææžã¯ã©ãããããšãããšãIntermediate CA certificateã®éšåã«URLãæžããŠããã®ã§ãããã«åŸããŸãã
Intermediate CA certificate ----------------------------------------------------- You need the Intermediate CA Certificate for your specific web server. You can download this certificate on your webserver as per the instructions mentioned in the URL. https://knowledge.rapidssl.com/support/ssl-certificate-support/index?page=content&id=AR1549
èªåã®ç°å¢ã¯Apache + MOD SSLã§ãã®ã§ãããŒãžäžå€®ã®Apache, Plesk & CPanelã«åŸããŸãã
ããããšã¯ç°¡åããšãããä»ã®æ¹ãã¡ãšã»ãŒåãã§ãDownload the RapidSSL CA BundleãããäžéèªèšŒå±èšŒææžãDLããšãããã³ããŒããŠãåŸã¯ãµãŒãåŽã«ããŒã¹ããApacheèšå®å€æŽãåèµ·åã§å®äºã§ãã
RapidSSLã®äžéèªèšŒå±èšŒææžã®äžèº«ãèŠããš-----BEGIN CERTIFICATE-----ã®ãããã¯ãïŒã€ãããŸãããããã¯ïŒæ®µéèªèšŒã®ããã§ãã以äžã®ãµã€ããªã©ãåèã«ãªããŸãã
httpsã§ã®æ¥ç¶
å šãŠã®èšå®ãå®äºããã®ã§èªåã®ãµã€ãã確èªããŠã¿ãŸãããŸãã¯httpsã§ã¢ã¯ã»ã¹ã

衚瀺ãããŸããã
ããããå ã®éšåã§è¿°ã¹ãããã«ãäžéèªèšŒå±èšŒææžãã€ã³ã¹ããŒã«ããªãã§ãäžèŠæ£ãã衚瀺ãããŠããŸãããçŸåšã®èšå®ã§æ¬åœã«ïŒæ®µéèªèšŒã§ããŠããã®ã§ããããã»ã»ã»ïŒ
ããã§ãæ€èšŒããŒã«ã䜿çšããŸããæ€èšŒããŒã«ã¯åèªèšŒå±ã®å ¬åŒãµã€ãããå©çšã§ããŸããä»åã®RapidSSLã¯ãžãªãã©ã¹ãã®ãµãŒãã¹ãªã®ã§ããžãªãã©ã¹ãã®æ€èšŒããŒã«ãå©çšããŸãã
ãŸãã¯äžéèªèšŒå±èšŒææžã®èšå®ãªãã§è©ŠããŠã¿ãŸãã

ãšã©ãŒãåºãŠããŸããŸããã
èšå®ããã ãšä»¥äžã®ããã«ãªããŸãã

4段éèªèšŒã§ããŠããããã§ãã
以äžã§ãã