Qhov kev txiav txim siab no yog npaj los ua kom Lub Zej Zog muaj kev txaus siab rau qhov teeb meem ntawm kev ceev ntiag tug, uas, nyob rau hauv lub teeb ntawm cov xwm txheej tshiab kawg yuav muaj feem ntau dua li yav dhau los.
Hauv cov txheej txheem:
Cov neeg txhawb nqa los ntawm cov zej zog ntawm cov chaw muab kev pabcuam hauv Internet "Medium" tab tom tsim lawv tus kheej lub tshuab tshawb nrhiav
Medium tau tsim ib txoj cai pov thawj tshiab, Medium Global Root CA. Leej twg yuav raug cuam tshuam los ntawm kev hloov pauv?
Daim ntawv pov thawj kev ruaj ntseg rau txhua lub tsev - yuav ua li cas los tsim koj tus kheej cov kev pabcuam ntawm Yggdrasil network thiab muab daim ntawv pov thawj SSL siv tau rau nws
Nco ntsoov - "Medium" yog dab tsi?
Medium (khej. Medium - "intermediary", thawj cov lus hais - Tsis txhob nug koj tus kheej. Nqa nws rov qab; kuj nyob rau hauv lus Askiv lo lus nruab nrab txhais tau tias "intermediate") - ib tug Lavxias teb sab decentralized Internet muab kev pab cuam nkag mus rau hauv lub network Yggdrasil dawb xwb.
Lub npe tag nrho: Tus Muab Kev Pabcuam Hauv Internet Nruab Nrab. Thaum xub thawj qhov project tau xeeb ua Mesh network в Kolomna nroog.
Cov neeg txhawb nqa los ntawm cov zej zog ntawm cov chaw muab kev pabcuam hauv Internet "Medium" tab tom tsim lawv tus kheej lub tshuab tshawb nrhiav
Keeb kwm online Yggdrasil, uas tus neeg muab kev pabcuam hauv Is Taws Nem kev sib faib nruab nrab siv los ua kev thauj mus los, tsis muaj nws tus kheej DNS server lossis pej xeem cov txheej txheem tseem ceeb - txawm li cas los xij, qhov yuav tsum tau muab daim ntawv pov thawj kev nyab xeeb rau Medium network kev pabcuam daws ob qhov teeb meem no.
Vim li cas koj thiaj xav tau PKI yog Yggdrasil tawm ntawm lub thawv muab lub peev xwm rau kev nkag mus ntawm cov phooj ywg?Tsis tas yuav siv HTTPS los txuas rau cov kev pabcuam hauv web ntawm Yggdrasil network yog tias koj txuas rau lawv los ntawm lub zos khiav Yggdrasil network router.
Xwb: Yggdrasil thauj yog nyob ntawm par raws tu qauv tso cai rau koj siv kev nyab xeeb hauv Yggdrasil network - muaj peev xwm ua MITM tawm tsam tsis suav tag nrho.
Medium tau tsim ib txoj cai pov thawj tshiab, Medium Global Root CA. Leej twg yuav raug cuam tshuam los ntawm kev hloov pauv?
Nag hmo, kev sim pej xeem ntawm kev ua haujlwm ntawm Medium Root CA certification center tau ua tiav. Thaum kawg ntawm kev sim, qhov ua yuam kev hauv kev ua haujlwm ntawm cov kev pabcuam pej xeem tseem ceeb tau raug kho thiab daim ntawv pov thawj hauv paus tshiab ntawm cov ntawv pov thawj "Medium Global Root CA" tau tsim.
Tag nrho cov nuances thiab cov yam ntxwv ntawm PKI tau raug coj mus rau hauv tus account - tam sim no daim ntawv pov thawj CA tshiab "Medium Global Root CA" yuav raug muab tawm tsuas yog kaum xyoo tom qab (tom qab hnub tas sijhawm). Tam sim no daim ntawv pov thawj kev ruaj ntseg tsuas yog muab los ntawm cov neeg pov thawj hauv nruab nrab - piv txwv li, "Medium Domain Validation Secure Server CA".
Daim ntawv pov thawj kev ntseeg siab zoo li cas tam sim no?
Dab tsi yuav tsum tau ua rau txhua yam ua haujlwm yog tias koj yog tus neeg siv:
Txij li qee qhov kev pabcuam siv HSTS, ua ntej siv Medium network cov peev txheej, koj yuav tsum rho tawm cov ntaub ntawv los ntawm Medium intranet peev txheej. Koj tuaj yeem ua qhov no hauv keeb kwm tab ntawm koj tus browser.
Daim ntawv pov thawj kev ruaj ntseg rau txhua lub tsev - yuav ua li cas los tsim koj tus kheej cov kev pabcuam ntawm Yggdrasil network thiab muab daim ntawv pov thawj SSL siv tau rau nws
Vim muaj kev loj hlob ntawm tus naj npawb ntawm cov kev pabcuam intranet ntawm Medium network, yuav tsum tau muab daim ntawv pov thawj kev ruaj ntseg tshiab thiab teeb tsa lawv cov kev pabcuam kom lawv txhawb SSL tau nce.
[ req ]
default_bits = 2048
distinguished_name = req_distinguished_name
x509_extensions = v3_req
[ req_distinguished_name ]
countryName = Country Name (2 letter code)
countryName_default = RU
stateOrProvinceName = State or Province Name (full name)
stateOrProvinceName_default = Moscow Oblast
localityName = Locality Name (eg, city)
localityName_default = Kolomna
organizationName = Organization Name (eg, company)
organizationName_default = ACME, Inc.
commonName = Common Name (eg, YOUR name)
commonName_max = 64
commonName_default = *.domain.ygg
[ v3_req ]
subjectKeyIdentifier = hash
keyUsage = critical, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth
basicConstraints = CA:FALSE
nsCertType = server
authorityKeyIdentifier = keyid,issuer:always
crlDistributionPoints = URI:http://crl.medium.isp/Medium_Global_Root_CA.crl
authorityInfoAccess = OCSP;URI:http://ocsp.medium.isp
Kauj ruam 3. Xa daim ntawv thov daim ntawv pov thawj
Ua li no, luam cov ntsiab lus ntawm cov ntaub ntawv ua domain.ygg.csr thiab muab tshuaj txhuam rau hauv cov ntawv nyeem ntawm lub xaib pki.medium.isp.
Ua raws li cov lus qhia hauv lub vev xaib, tom qab ntawd nyem "Submit". Yog tias ua tiav, cov lus yuav raug xa mus rau email chaw nyob uas koj tau teev tseg uas muaj cov ntawv txuas nrog rau hauv daim ntawv pov thawj uas tau kos npe los ntawm ib qho kev lees paub nruab nrab.
Kauj ruam 4. Teeb tsa koj lub vev xaib server
Yog tias koj siv nginx ua koj lub vev xaib server, siv cov kev teeb tsa hauv qab no:
cov ntaub ntawv ua domain.ygg.conf hauv phau ntawv /etc/nginx/sites-available/
Daim ntawv pov thawj koj tau txais los ntawm email yuav tsum tau theej rau: /etc/ssl/certs/domain.ygg.crt. Tus yuam sij ntiag tug (domain.ygg.key) muab tso rau hauv ib phau ntawv /etc/ssl/private/.
Kauj ruam 5. Rov pib koj lub vev xaib server
sudo service nginx restart
Dawb Internet hauv Russia pib nrog koj
Koj tuaj yeem muab txhua yam kev pab cuam rau kev tsim Internet dawb hauv Russia hnub no. Peb tau sau ib daim ntawv teev npe raws nraim li cas koj tuaj yeem pab lub network:
Qhia rau koj cov phooj ywg thiab cov npoj yaig txog Medium network. Qhia suav siv rau tsab xov xwm no hauv social networks lossis tus kheej blog
Koom nrog hauv kev sib tham txog cov teeb meem kev lag luam ntawm Medium network ntawm GitHub
Tsim koj lub vev xaib kev pabcuam ntawm Yggdrasil network thiab ntxiv rau DNS ntawm Medium network