ื”ืืœื˜ืจื ื˜ื™ื‘ื” ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ืœืจืฉื•ืช ืื™ืฉื•ืจื™ื

ืœื ื ื™ืชืŸ ืœืกืžื•ืš ืขืœ ืžืฉืชืžืฉื™ื. ืœืจื•ื‘, ื”ื ืขืฆืœื ื™ื ื•ื‘ื•ื—ืจื™ื ื‘ื ื•ื—ื•ืช ืขืœ ืคื ื™ ื‘ื˜ื™ื—ื•ืช. ืœืคื™ ื”ืกื˜ื˜ื™ืกื˜ื™ืงื”, 21% ืจื•ืฉืžื™ื ืืช ื”ืกื™ืกืžืื•ืช ืฉืœื”ื ืœื—ืฉื‘ื•ื ื•ืช ืขื‘ื•ื“ื” ืขืœ ื”ื ื™ื™ืจ, 50% ืžืฆื™ื™ื ื™ื ืืช ืื•ืชืŸ ืกื™ืกืžืื•ืช ืœืขื‘ื•ื“ื” ื•ืœืฉื™ืจื•ืชื™ื ืื™ืฉื™ื™ื.

ื’ื ื”ืกื‘ื™ื‘ื” ืขื•ื™ื ืช. 74% ืžื”ืืจื’ื•ื ื™ื ืžืืคืฉืจื™ื ืœื”ื‘ื™ื ืžื›ืฉื™ืจื™ื ืื™ืฉื™ื™ื ืœืขื‘ื•ื“ื” ื•ืœื”ืชื—ื‘ืจ ืœืจืฉืช ื”ืืจื’ื•ื ื™ืช. 94% ืžื”ืžืฉืชืžืฉื™ื ืœื ื™ื›ื•ืœื™ื ืœื”ื‘ื—ื™ืŸ ื‘ื™ืŸ ืื™ืžื™ื™ืœ ืืžื™ืชื™ ืœื“ื™ื•ื’, 11% ืœื—ืฆื• ืขืœ ืงื‘ืฆื™ื ืžืฆื•ืจืคื™ื.

ื›ืœ ื”ื‘ืขื™ื•ืช ื”ืœืœื• ื ืคืชืจื•ืช ืขืœ ื™ื“ื™ ืชืฉืชื™ืช ืžืคืชื— ืฆื™ื‘ื•ืจื™ ืืจื’ื•ื ื™ (PKI), ื”ืžืกืคืงืช ื”ืฆืคื ืช ื“ื•ืืจ ื•ืื™ืžื•ืช, ื•ืžื—ืœื™ืคื” ืกื™ืกืžืื•ืช ื‘ืชืขื•ื“ื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช. ื ื™ืชืŸ ืœื”ืขืœื•ืช ืชืฉืชื™ืช ื–ื• ื‘-Windows Server. ืœืคื™ ืชื™ืื•ืจ ืžืžื™ืงืจื•ืกื•ืคื˜, Active Directory Certificate Services (AD CS) ื”ื•ื ืฉืจืช ื”ืžืืคืฉืจ ืœืš ืœื™ืฆื•ืจ PKI ื‘ืืจื’ื•ืŸ ืฉืœืš ื•ืœื”ืฉืชืžืฉ ื‘ื”ืฆืคื ืช ืžืคืชื— ืฆื™ื‘ื•ืจื™, ืื™ืฉื•ืจื™ื ื“ื™ื’ื™ื˜ืœื™ื™ื ื•ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช.

ืื‘ืœ ื”ืคืชืจื•ืŸ ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ื“ื™ ื™ืงืจ.

ืขืœื•ืช ื‘ืขืœื•ืช ื›ื•ืœืœืช ืขื‘ื•ืจ CA ืคืจื˜ื™ ืฉืœ Microsoft

ื”ืืœื˜ืจื ื˜ื™ื‘ื” ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ืœืจืฉื•ืช ืื™ืฉื•ืจื™ื
ื”ืฉื•ื•ืืช ืขืœื•ืช ื”ื‘ืขืœื•ืช ื‘ื™ืŸ Microsoft CA ืœื‘ื™ืŸ GlobalSign AEG. ืžืงื•ืจ

ื‘ืžืฆื‘ื™ื ืจื‘ื™ื ื ื•ื— ื•ื–ื•ืœ ื™ื•ืชืจ ืœื™ืฆื•ืจ ืืช ืื•ืชื” ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืคืจื˜ื™ืช, ืืš ืขื ื ื™ื”ื•ืœ ื—ื™ืฆื•ื ื™. ื–ื• ื‘ื“ื™ื•ืง ื”ื‘ืขื™ื” ืฉ-GlobalSign Auto Enrollment Gateway (AEG) ืคื•ืชืจ. ืžืกืคืจ ืฉื•ืจื•ืช ื”ื•ืฆืื•ืช ืื™ื ืŸ ื ื›ืœืœื•ืช ื‘ืขืœื•ืช ื”ื›ื•ืœืœืช ืฉืœ ื”ื‘ืขืœื•ืช (ืจื›ื™ืฉืช ืฆื™ื•ื“, ืขืœื•ื™ื•ืช ืชืžื™ื›ื”, ื”ื“ืจื›ืช ืฆื•ื•ืช ื•ื›ื•'). ื”ื—ื™ืกื›ื•ืŸ ื™ื›ื•ืœ ืœืขืœื•ืช 50% ืžืกืš ืขืœื•ืช ื”ื‘ืขืœื•ืช.

ืžื” ื–ื” AEG

ื”ืืœื˜ืจื ื˜ื™ื‘ื” ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ืœืจืฉื•ืช ืื™ืฉื•ืจื™ื

ืฉืขืจ ื”ืจืฉืžื” ืื•ื˜ื•ืžื˜ื™ (AEG) ื”ื•ื ืฉื™ืจื•ืช ืชื•ื›ื ื” ื”ืคื•ืขืœ ื›ืฉืขืจ ื‘ื™ืŸ ืฉื™ืจื•ืชื™ ืื™ืฉื•ืจ SaaS GlobalSign ืœื‘ื™ืŸ ืกื‘ื™ื‘ืช ืืจื’ื•ื ื™ืช ืฉืœ Windows.

AEG ืžืฉืชืœื‘ืช ืขื Active Directory, ื•ืžืืคืฉืจืช ืœืืจื’ื•ื ื™ื ืœื”ืคื•ืš ืืช ื”ืจื™ืฉื•ื, ื”ืืกืคืงื” โ€‹โ€‹ื•ื”ื ื™ื”ื•ืœ ืฉืœ ืชืขื•ื“ื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืฉืœ GlobalSign ื‘ืกื‘ื™ื‘ืช Windows ืœืื•ื˜ื•ืžื˜ื™. ืขืœ ื™ื“ื™ ื”ื—ืœืคืช CAs ืคื ื™ืžื™ื™ื ื‘ืฉื™ืจื•ืชื™ GlobalSign, ืืจื’ื•ื ื™ื ืžื’ื‘ื™ืจื™ื ืืช ื”ืื‘ื˜ื—ื” ื•ืžืคื—ื™ืชื™ื ืืช ื”ืขืœื•ืช ืฉืœ ื ื™ื”ื•ืœ CA ืคื ื™ืžื™ ืžื•ืจื›ื‘ ื•ื™ืงืจ ืฉืœ Microsoft.

GlobalSign SaaS Certificate Services ื”ื™ื ืืคืฉืจื•ืช ืืžื™ื ื” ื™ื•ืชืจ ืžืืฉืจ ืชืขื•ื“ื•ืช ื—ืœืฉื•ืช ื•ืœื ืžื ื•ื”ืœื•ืช ืขืœ ื”ืชืฉืชื™ืช ืฉืœืš. ื‘ื™ื˜ื•ืœ ื”ืฆื•ืจืš ื‘ื ื™ื”ื•ืœ CA ืคื ื™ืžื™ ืขืชื™ืจ ืžืฉืื‘ื™ื ืžืคื—ื™ืช ืืช ืขืœื•ืช ื”ื‘ืขืœื•ืช ื”ื›ื•ืœืœืช ืฉืœ PKI, ื›ืžื• ื’ื ืืช ื”ืกื™ื›ื•ืŸ ืœื›ืฉืœื™ื ื‘ืžืขืจื›ืช.

ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœื™ SCEP ื•-ACME ืžืจื—ื™ื‘ื” ืืช ื”ืชืžื™ื›ื” ืžืขื‘ืจ ืœ-Windows, ื›ื•ืœืœ ื”ื ืคืงืช ืื™ืฉื•ืจ ืื•ื˜ื•ืžื˜ื™ ืขื‘ื•ืจ ืฉืจืชื™ ืœื™ื ื•ืงืก, ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื, ื”ืชืงื ื™ ืจืฉืช ื•ื”ืชืงื ื™ื ืื—ืจื™ื, ื›ืžื• ื’ื ืžื—ืฉื‘ื™ Apple OSX ื”ืจืฉื•ืžื™ื ื‘-Active Directory.

ืื‘ื˜ื—ื” ืžืฉื•ืคืจืช

ื‘ื ื•ืกืฃ ืœื—ื™ืกื›ื•ืŸ ื‘ื›ืกืฃ, ื ื™ื”ื•ืœ PKI ื‘ืžื™ืงื•ืจ ื—ื•ืฅ ืžืฉืคืจ ืืช ืื‘ื˜ื—ืช ื”ืžืขืจื›ืช. ื›ืคื™ ืฉืžืฆื™ื™ืŸ ื”ืžื—ืงืจ ืฉืœ ืงื‘ื•ืฆืช Aberdeen, ืชืขื•ื“ื•ืช ืžืžื•ืงื“ื•ืช ื™ื•ืชืจ ื•ื™ื•ืชืจ ืขืœ ื™ื“ื™ ืชื•ืงืคื™ื ื”ืžื ืฆืœื™ื ื‘ื”ืฆืœื—ื” ืคื’ื™ืขื•ื™ื•ืช ื™ื“ื•ืขื•ืช ื›ื’ื•ืŸ ืื™ืฉื•ืจื™ื ืœื ืžื”ื™ืžื ื™ื ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช, ื”ืฆืคื ื” ื—ืœืฉื” ื•ืžื ื’ื ื•ื ื™ ื‘ื™ื˜ื•ืœ ืžืกื•ืจื‘ืœื™ื. ื‘ื ื•ืกืฃ, ื”ืชื•ืงืคื™ื ืฉืœื˜ื• ื‘ื ื™ืฆื•ืœื™ื ืžืชื•ื—ื›ืžื™ื ื™ื•ืชืจ, ื›ื’ื•ืŸ ื”ื ืคืงืช ืื™ืฉื•ืจื™ื ื‘ืžืจืžื” ืž-CAs ืžื”ื™ืžื ื™ื ื•ื–ื™ื•ืฃ ืื™ืฉื•ืจื™ ื—ืชื™ืžืช ืงื•ื“.

"ืจื•ื‘ ื”ืืจื’ื•ื ื™ื ืื™ื ื ืžื ื”ืœื™ื ื‘ืื•ืคืŸ ืคืขื™ืœ ืืช ื”ืกื™ื›ื•ื ื™ื ื”ื›ืจื•ื›ื™ื ื‘ื”ืชืงืคื•ืช ืืœื• ื•ืื™ื ื ืžื•ื›ื ื™ื ืœื”ื’ื™ื‘ ื‘ืžื”ื™ืจื•ืช ืœืคืฉืจื•ืช", ะฝะฐะฟะธัะฐะป ื“ืจืง ื. ื‘ืจื™ื ืง, ืกื’ืŸ ื ืฉื™ื ื•ืขืžื™ืช ืื‘ื˜ื—ืช IT ื‘ืงื‘ื•ืฆืช ืื‘ืจื“ื™ืŸ. "ืขืœ ื™ื“ื™ ืžืชืŸ ืืคืฉืจื•ืช ืœืืจื’ื•ื ื™ื ืœื”ืฆื™ื‘ ืืช ื”ื”ื™ื‘ื˜ื™ื ื”ืชืคืขื•ืœื™ื™ื ืฉืœ ื ื™ื”ื•ืœ ืชืขื•ื“ื•ืช ื‘ื™ื“ื™ ืžื•ืžื—ื™ื ืชื•ืš ืฉืžื™ืจื” ืขืœ ืฉืœื™ื˜ื” ืืจื’ื•ื ื™ืช ืขืœ ืžื“ื™ื ื™ื•ืช ืงื‘ื•ืฆืชื™ืช ื‘-Active Directory, GlobalSign ืฉื•ืืคืช ืœื”ื‘ื˜ื™ื— ืืช ื”ืฆืžื™ื—ื” ื”ืขืชื™ื“ื™ืช ืฉืœ ื”ืฉื™ืžื•ืฉ ื‘ืชืขื•ื“ื•ืช ืขืœ ื™ื“ื™ ื˜ื™ืคื•ืœ ื‘ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื•ืืžื•ืŸ ืžืขืฉื™ื•ืช ื‘ื™ืขื™ืœื•ืช ื•ื‘ืขืœื•ืช -ืžื•ื“ืœ ืคืจื™ืกื” ื™ืขื™ืœ."

ืื™ืš AEG ืขื•ื‘ื“

ื”ืืœื˜ืจื ื˜ื™ื‘ื” ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ืœืจืฉื•ืช ืื™ืฉื•ืจื™ื

ืžืขืจื›ืช ื˜ื™ืคื•ืกื™ืช ืขื AEG ื›ื•ืœืœืช ืืจื‘ืขื” ืžืจื›ื™ื‘ื™ ืžืคืชื— ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉื”ืื™ืฉื•ืจื™ื ื”ื ื›ื•ื ื™ื ื ืฉืœื—ื™ื ืœื ืงื•ื“ื•ืช ื”ื’ื™ืฉื” ื”ื ื›ื•ื ื•ืช:

  1. ืชื•ื›ื ืช AEG ื‘ืฉืจืช Windows.
  2. ืฉืจืชื™ Active Directory ืื• ื‘ืงืจื™ ืชื—ื•ื ื”ืžืืคืฉืจื™ื ืœืžื ื”ืœื™ ืžืขืจื›ืช ืœื ื”ืœ ื•ืœืื—ืกืŸ ืžื™ื“ืข ืขืœ ืžืฉืื‘ื™ื.
  3. ื ืงื•ื“ื•ืช ืงืฆื”: ืžืฉืชืžืฉื™ื, ืžื›ืฉื™ืจื™ื, ืฉืจืชื™ื ื•ืชื—ื ื•ืช ืขื‘ื•ื“ื” - ืœืžืขืฉื” ื›ืœ ื™ืฉื•ืช ืฉื”ื™ื "ืฆืจื›ืŸ" ืฉืœ ืชืขื•ื“ื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช.
  4. ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืฉืœ GlobalSign, ืื• GCC, ื”ื™ื•ืฉื‘ืช ืขืœ ื’ื‘ื™ ืคืœื˜ืคื•ืจืžืช ื”ื ืคืงืช ื•ื ื™ื”ื•ืœ ืชืขื•ื“ื•ืช ืžื”ื™ืžื ื•ืช. ื›ืืŸ ื ื•ืฆืจื•ืช ืื™ืฉื•ืจื™ื.

ืฉืœื•ืฉื” ืžืชื•ืš ืืจื‘ืขืช ื”ืจื›ื™ื‘ื™ื ื”ืžื•ืฆื’ื™ื ื ืžืฆืื™ื ื‘ืืชืจ ื”ืœืงื•ื—, ื•ื”ืจื‘ื™ืขื™ ื ืžืฆื ื‘ืขื ืŸ.

ืจืืฉื™ืช, ื ืงื•ื“ื•ืช ื”ืงืฆื” ืžื•ื’ื“ืจื•ืช ืžืจืืฉ ื‘ืืžืฆืขื•ืช ืžื“ื™ื ื™ื•ืช ืงื‘ื•ืฆืชื™ืช: ืœืžืฉืœ, ืื™ืžื•ืช ืชืขื•ื“ื” ืœืื™ืžื•ืช ืžืฉืชืžืฉ, ื‘ืงืฉืช S/MIME ืขื‘ื•ืจ ื”ืชืขื•ื“ื” ื•ื›ืŸ ื”ืœืื” - ืœื—ื™ื‘ื•ืจ ืœืื—ืจ ืžื›ืŸ ืœืฉืจืช AEG. ื”ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— ื‘ืืžืฆืขื•ืช HTTPS.

ืฉืจืช AEG ืฉื•ืืœ ืืช Active Directory ื“ืจืš LDAP ืขื‘ื•ืจ ืจืฉื™ืžื” ืฉืœ ืชื‘ื ื™ื•ืช ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ ื ืงื•ื“ื•ืช ืงืฆื” ืืœื” ื•ืฉื•ืœื— ืืช ื”ืจืฉื™ืžื” ืœืœืงื•ื—ื•ืช ื™ื—ื“ ืขื ืžื™ืงื•ื ื”-CA. ืœืื—ืจ ืงื‘ืœืช ื›ืœืœื™ื ืืœื”, ื ืงื•ื“ื•ืช ื”ืงืฆื” ืžืชื—ื‘ืจื•ืช ืฉื•ื‘ ืœืฉืจืช AEG, ื”ืคืขื ื›ื“ื™ ืœื‘ืงืฉ ืืช ื”ืื™ืฉื•ืจื™ื ื‘ืคื•ืขืœ. AEG, ื‘ืชื•ืจื”, ื™ื•ืฆืจืช ืงืจื™ืืช API ืขื ื”ืคืจืžื˜ืจื™ื ืฉืฆื•ื™ื ื• ื•ืฉื•ืœื—ืช ืื•ืชื” ืœ-GlobalSign Certification Authority ืื• ืœ-GCC ืœืขื™ื‘ื•ื“.

ืœื‘ืกื•ืฃ, ื”ืงืฆื” ื”ืื—ื•ืจื™ ืฉืœ GCC ืžืขื‘ื“ ืืช ื”ื‘ืงืฉื•ืช, ื‘ื“ืจืš ื›ืœืœ ืชื•ืš ืžืกืคืจ ืฉื ื™ื•ืช, ื•ืฉื•ืœื— ืชื’ื•ื‘ืช API ื™ื—ื“ ืขื ืื™ืฉื•ืจ ืฉื™ื•ืชืงืŸ ื‘ื ืงื•ื“ื•ืช ื”ืงืฆื” ืœืคื™ ื‘ืงืฉื”.

ื”ืชื”ืœื™ืš ื›ื•ืœื• ืื•ืจืš ืžืกืคืจ ืฉื ื™ื•ืช ื•ื ื™ืชืŸ ืœื‘ืฆืข ืื•ื˜ื•ืžืฆื™ื” ืžืœืื” ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช ื ืงื•ื“ื•ืช ืงืฆื” ืœืงื‘ืœืช ืื™ืฉื•ืจื™ื ืื•ื˜ื•ืžื˜ื™ืช ื‘ืืžืฆืขื•ืช ืžื“ื™ื ื™ื•ืช ืงื‘ื•ืฆืชื™ืช.

ืชื›ื•ื ื•ืช ื™ื™ื—ื•ื“ื™ื•ืช ืฉืœ AEG

  • ืืชื” ื™ื›ื•ืœ ืœื”ื™ืจืฉื ื“ืจืš ืคืœื˜ืคื•ืจืžืช MDM.
  • ืคื•ืชื— ืขืœ ื™ื“ื™ ืขื•ื‘ื“ื™ื ืœืฉืขื‘ืจ ืžืฆื•ื•ืช Microsoft Crypto.
  • ืคืชืจื•ืŸ ืœืœื ืœืงื•ื—.
  • ื”ื˜ืžืขื” ืคืฉื•ื˜ื” ื•ื ื™ื”ื•ืœ ืžื—ื–ื•ืจ ื—ื™ื™ื.

ื”ืืœื˜ืจื ื˜ื™ื‘ื” ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ืœืจืฉื•ืช ืื™ืฉื•ืจื™ื
ื“ื•ื’ืžืื•ืช ืื“ืจื™ื›ืœื•ืช

ืœืคื™ื›ืš, ื ื™ื”ื•ืœ PKI ื—ื™ืฆื•ื ื™ ื‘ืืžืฆืขื•ืช ืฉืขืจ GlobalSign AEG ืคื™ืจื•ืฉื• ืื‘ื˜ื—ื” ืžื•ื’ื‘ืจืช, ื—ื™ืกื›ื•ืŸ ื‘ืขืœื•ื™ื•ืช ื•ื”ืคื—ืชืช ืกื™ื›ื•ื ื™ื. ื™ืชืจื•ืŸ ื ื•ืกืฃ ื”ื•ื ืžื“ืจื’ื™ื•ืช ืงืœื” ื•ื‘ื™ืฆื•ืขื™ื ืžืฉื•ืคืจื™ื. PKI ืžื ื•ื”ืœ ื›ื”ืœื›ื” ืžื‘ื˜ื™ื— ื–ืžืŸ ืคืขื•ืœื” ืืจื•ืš, ืžื‘ื˜ืœ ื”ืคืจืขื•ืช ืœืคืขื•ืœื•ืช ืงืจื™ื˜ื™ื•ืช ืขืงื‘ ืื™ืฉื•ืจื™ื ืœื ื—ื•ืงื™ื™ื, ื•ืžืฆื™ืข ืœืขื•ื‘ื“ื™ื ื’ื™ืฉื” ืžืจื—ื•ืง ื•ืžืื•ื‘ื˜ื—ืช ืœืจืฉืชื•ืช ื”ื—ื‘ืจื”.

AEG ืชื•ืžืš ื‘ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืžืงืจื™ ืฉื™ืžื•ืฉ ื”ื“ื•ืจืฉื™ื ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™, ื”ื—ืœ ืžืœืงื•ื—ื•ืช ืงื‘ื•ืฆืช ืขื‘ื•ื“ื” ืžืจื•ื—ืงื™ื ื”ื ื™ื’ืฉื™ื ืœืจืฉืช ื‘ืืžืฆืขื•ืช VPN ื•-Wi-Fi, ื•ืขื“ ืœื’ื™ืฉื” ืžื•ืขื“ืคืช ืœืžืฉืื‘ื™ื ืจื’ื™ืฉื™ื ื‘ื™ื•ืชืจ ื‘ืืžืฆืขื•ืช ื›ืจื˜ื™ืกื™ื ื—ื›ืžื™ื.

GlobalSign ื”ื™ื ืžื•ื‘ื™ืœื” ืขื•ืœืžื™ืช ื‘ืืกืคืงืช ืคืชืจื•ื ื•ืช PKI ื‘ืขื ืŸ ื•ืจืฉืชื•ืช ืœื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช ื•ื’ื™ืฉื”. ืœืžื™ื“ืข ื ื•ืกืฃ ืขืœ ื”ืžื•ืฆืจ, ืื ื ืฆื•ืจ ืงืฉืจ ื”ืžื ื”ืœื™ื ืฉืœื ื•.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”