DPI (ื‘ื“ื™ืงืช SSL) ื ื•ื’ื“ืช ืืช ื’ืจืขื™ืŸ ื”ื”ืฆืคื ื”, ืืš ื—ื‘ืจื•ืช ืžื™ื™ืฉืžื•ืช ื–ืืช

DPI (ื‘ื“ื™ืงืช SSL) ื ื•ื’ื“ืช ืืช ื’ืจืขื™ืŸ ื”ื”ืฆืคื ื”, ืืš ื—ื‘ืจื•ืช ืžื™ื™ืฉืžื•ืช ื–ืืช
ืฉืจืฉืจืช ืืžื•ืŸ. CC BY-SA 4.0 ื™ืื ืคืืก

ื‘ื“ื™ืงืช ืชืขื‘ื•ืจืช SSL (ืคืขื ื•ื— SSL/TLS, ื ื™ืชื•ื— SSL ืื• DPI) ื”ื•ืคื›ืช ืœื ื•ืฉื ื“ื™ื•ืŸ ื—ื ื™ื•ืชืจ ื•ื™ื•ืชืจ ื‘ืžื’ื–ืจ ื”ืืจื’ื•ื ื™. ื ืจืื” ืฉื”ืจืขื™ื•ืŸ ืฉืœ ืคืขื ื•ื— ืชืขื‘ื•ืจื” ืกื•ืชืจ ืืช ืขืฆื ื”ืจืขื™ื•ืŸ ืฉืœ ืงืจื™ืคื˜ื•ื’ืจืคื™ื”. ืขื ื–ืืช, ื”ืขื•ื‘ื“ื” ื”ื™ื ืขื•ื‘ื“ื”: ื™ื•ืชืจ ื•ื™ื•ืชืจ ื—ื‘ืจื•ืช ืžืฉืชืžืฉื•ืช ื‘ื˜ื›ื ื•ืœื•ื’ื™ื•ืช DPI, ืžื” ืฉืžืกื‘ื™ืจ ื–ืืช ื‘ืฆื•ืจืš ืœื‘ื“ื•ืง ืชื•ื›ืŸ ืขื‘ื•ืจ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช, ื“ืœื™ืคื•ืช ื ืชื•ื ื™ื ื•ื›ื•'.

ื•ื‘ื›ืŸ, ืื ื ืงื‘ืœ ืืช ื”ืขื•ื‘ื“ื” ืฉื˜ื›ื ื•ืœื•ื’ื™ื” ื›ื–ื• ืฆืจื™ื›ื” ืœื”ื™ื•ืช ืžื™ื•ืฉืžืช, ืื– ืขืœื™ื ื• ืœืฉืงื•ืœ ืœืคื—ื•ืช ื“ืจื›ื™ื ืœืขืฉื•ืช ื–ืืช ื‘ืฆื•ืจื” ื”ื‘ื˜ื•ื—ื” ื•ื”ืžื ื•ื”ืœืช ื‘ื™ื•ืชืจ ื”ืืคืฉืจื™ืช. ืœืคื—ื•ืช ืืœ ืชืกืชืžืš ืขืœ ื”ืื™ืฉื•ืจื™ื ื”ืืœื”, ืœืžืฉืœ, ืฉืกืคืง ืžืขืจื›ืช ื”-DPI ื ื•ืชืŸ ืœืš.

ื™ืฉ ื”ื™ื‘ื˜ ืื—ื“ ื‘ื™ื™ืฉื•ื ืฉืœื ื›ื•ืœื ื™ื•ื“ืขื™ื ืขืœื™ื•. ืœืžืขืฉื”, ืื ืฉื™ื ืจื‘ื™ื ื‘ืืžืช ืžื•ืคืชืขื™ื ื›ืฉื”ื ืฉื•ืžืขื™ื ืขืœ ื›ืš. ื–ื•ื”ื™ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืคืจื˜ื™ืช (CA). ื–ื” ืžื™ื™ืฆืจ ืื™ืฉื•ืจื™ื ื›ื“ื™ ืœืคืขื ื— ื•ืœื”ืฆืคื™ืŸ ืžื—ื“ืฉ ืชืขื‘ื•ืจื”.

ื‘ืžืงื•ื ืœื”ืกืชืžืš ืขืœ ืื™ืฉื•ืจื™ื ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช ืื• ืื™ืฉื•ืจื™ื ืžืžื›ืฉื™ืจื™ DPI, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘-CA ื™ื™ืขื•ื“ื™ ืžืจืฉื•ืช ืื™ืฉื•ืจื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื›ื’ื•ืŸ GlobalSign. ืื‘ืœ ืงื•ื“ื ื›ืœ, ื‘ื•ืื• ื ืขืฉื” ืกืงื™ืจื” ืงื˜ื ื” ืฉืœ ื”ื‘ืขื™ื” ืขืฆืžื”.

ืžื”ื™ ื‘ื“ื™ืงืช SSL ื•ืžื“ื•ืข ืžืฉืชืžืฉื™ื ื‘ื”?

ื™ื•ืชืจ ื•ื™ื•ืชืจ ืืชืจื™ื ืฆื™ื‘ื•ืจื™ื™ื ืขื•ื‘ืจื™ื ืœ-HTTPS. ืœืžืฉืœ, ืœืคื™ ืกื˜ื˜ื™ืกื˜ื™ืงื•ืช ืฉืœ Chromeื‘ืชื—ื™ืœืช ืกืคื˜ืžื‘ืจ 2019, ื—ืœืงื” ืฉืœ ื”ืชืขื‘ื•ืจื” ื”ืžื•ืฆืคื ืช ื‘ืจื•ืกื™ื” ื”ื’ื™ืข ืœ-83%.

DPI (ื‘ื“ื™ืงืช SSL) ื ื•ื’ื“ืช ืืช ื’ืจืขื™ืŸ ื”ื”ืฆืคื ื”, ืืš ื—ื‘ืจื•ืช ืžื™ื™ืฉืžื•ืช ื–ืืช

ืœืžืจื‘ื” ื”ืฆืขืจ, ื”ืฆืคื ืช ืชืขื‘ื•ืจื” ื ืžืฆืืช ื™ื•ืชืจ ื•ื™ื•ืชืจ ื‘ืฉื™ืžื•ืฉ ืขืœ ื™ื“ื™ ืชื•ืงืคื™ื, ื‘ืžื™ื•ื—ื“ ืžืื– Let's Encrypt ืžืคื™ืฆื” ืืœืคื™ ืชืขื•ื“ื•ืช SSL ื‘ื—ื™ื ื ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™. ืœืคื™ื›ืš, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-HTTPS ื‘ื›ืœ ืžืงื•ื - ื•ื”ืžื ืขื•ืœ ื‘ืฉื•ืจืช ื”ื›ืชื•ื‘ืช ืฉืœ ื”ื“ืคื“ืคืŸ ื”ืคืกื™ืง ืœืฉืžืฉ ืื™ื ื“ื™ืงื˜ื•ืจ ืืžื™ืŸ ืœืื‘ื˜ื—ื”.

ื™ืฆืจื ื™ื ืฉืœ ืคืชืจื•ื ื•ืช DPI ืžืงื“ืžื™ื ืืช ื”ืžื•ืฆืจื™ื ืฉืœื”ื ืžืขืžื“ื•ืช ืืœื•. ื”ื ืžื•ื˜ืžืขื™ื ื‘ื™ืŸ ืžืฉืชืžืฉื™ ืงืฆื” (ื›ืœื•ืžืจ ื”ืขื•ื‘ื“ื™ื ืฉืœืš ื’ื•ืœืฉื™ื ื‘ืื™ื ื˜ืจื ื˜) ืœื‘ื™ืŸ ื”ืื™ื ื˜ืจื ื˜, ื•ืžืกื ื ื™ื ืชืขื‘ื•ืจื” ื–ื“ื•ื ื™ืช. ื™ืฉื ื ืžืกืคืจ ืžื•ืฆืจื™ื ื›ืืœื” ื‘ืฉื•ืง ื›ื™ื•ื, ืืš ื”ืชื”ืœื™ื›ื™ื ื–ื”ื™ื ื‘ืขืฆื. ืชืขื‘ื•ืจืช HTTPS ืขื•ื‘ืจืช ื“ืจืš ืžื›ืฉื™ืจ ื‘ื“ื™ืงื” ืฉื ื”ื™ื ืžืคื•ืขื ื—ืช ื•ื ื‘ื“ืงืช ืขื‘ื•ืจ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช.

ืœืื—ืจ ื”ืฉืœืžืช ื”ืื™ืžื•ืช, ื”ืžื›ืฉื™ืจ ื™ื•ืฆืจ ื”ืคืขืœืช SSL ื—ื“ืฉื” ืขื ืœืงื•ื— ื”ืงืฆื” ื›ื“ื™ ืœืคืขื ื— ื•ืœื”ืฆืคื™ืŸ ืžื—ื“ืฉ ืืช ื”ืชื•ื›ืŸ.

ื›ื™ืฆื“ ืคื•ืขืœ ืชื”ืœื™ืš ื”ืคืขื ื•ื—/ื”ื”ืฆืคื ื” ืžื—ื“ืฉ

ื›ื“ื™ ืฉืžื›ืฉื™ืจ ื‘ื“ื™ืงืช ื”-SSL ื™ืคืขื ื— ื•ืชืฆืคื™ืŸ ืžื—ื“ืฉ ืžื ื•ืช ืœืคื ื™ ืฉืœื™ื—ืชืŸ ืœืžืฉืชืžืฉื™ ืงืฆื”, ืขืœื™ื• ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœื”ื ืคื™ืง ืชืขื•ื“ื•ืช SSL ืชื•ืš ื›ื“ื™ ืชื ื•ืขื”. ื”ืžืฉืžืขื•ืช ื”ื™ื ืฉืขืœื™ื• ืœื”ื™ื•ืช ืžื•ืชืงืŸ ืื™ืฉื•ืจ CA.

ื—ืฉื•ื‘ ืœื—ื‘ืจื” (ืื• ืœื›ืœ ืžื™ ืฉื ืžืฆื ื‘ืืžืฆืข) ืฉืื™ืฉื•ืจื™ ื”-SSL ื”ืœืœื• ื™ื”ื™ื• ืžื”ื™ืžื ื™ื ืขืœ ื™ื“ื™ ื“ืคื“ืคื ื™ื (ื›ืœื•ืžืจ, ืœื ื™ืคืขื™ืœื• ื”ื•ื“ืขื•ืช ืื–ื”ืจื” ืžืคื—ื™ื“ื•ืช ื›ืžื• ื–ื• ืœืžื˜ื”). ืœื›ืŸ ืฉืจืฉืจืช ื”-CA (ืื• ื”ื”ื™ืจืจื›ื™ื”) ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ื‘ื—ื ื•ืช ื”ืืžื•ืŸ ืฉืœ ื”ื“ืคื“ืคืŸ. ืžื›ื™ื•ื•ืŸ ืฉืื™ืฉื•ืจื™ื ืืœื” ืื™ื ื ืžื•ื ืคืงื™ื ืžืจืฉื•ื™ื•ืช ืื™ืฉื•ืจื™ื ืžื”ื™ืžื ื•ืช ืฆื™ื‘ื•ืจื™ืช, ืขืœื™ืš ืœื”ืคื™ืฅ ื‘ืื•ืคืŸ ื™ื“ื ื™ ืืช ื”ื™ืจืจื›ื™ื™ืช ื”-CA ืœื›ืœ ืœืงื•ื—ื•ืช ื”ืงืฆื”.

DPI (ื‘ื“ื™ืงืช SSL) ื ื•ื’ื“ืช ืืช ื’ืจืขื™ืŸ ื”ื”ืฆืคื ื”, ืืš ื—ื‘ืจื•ืช ืžื™ื™ืฉืžื•ืช ื–ืืช
ื”ื•ื“ืขืช ืื–ื”ืจื” ืœืื™ืฉื•ืจ ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช ื‘-Chrome. ืžึธืงื•ึนืจ: BadSSL.com

ื‘ืžื—ืฉื‘ื™ Windows, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘-Active Directory ื•ื‘ืžื“ื™ื ื™ื•ืช ืงื‘ื•ืฆืชื™ืช, ืืš ืขื‘ื•ืจ ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื ื”ื”ืœื™ืš ืžืกื•ื‘ืš ื™ื•ืชืจ.

ื”ืžืฆื‘ ื”ื•ืคืš ืžืกื•ื‘ืš ืขื•ื“ ื™ื•ืชืจ ืื ืืชื” ืฆืจื™ืš ืœืชืžื•ืš ื‘ืชืขื•ื“ื•ืช ืฉื•ืจืฉ ืื—ืจื•ืช ื‘ืกื‘ื™ื‘ื” ืืจื’ื•ื ื™ืช, ืœืžืฉืœ, ืžื‘ื™ืช ืžื™ืงืจื•ืกื•ืคื˜, ืื• ืขืœ ื‘ืกื™ืก OpenSSL. ื‘ื ื•ืกืฃ ื”ื’ื ื” ื•ื ื™ื”ื•ืœ ืฉืœ ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื›ืš ืฉื›ืœ ืื—ื“ ืžื”ืžืคืชื—ื•ืช ืœื ื™ืคื•ื’ ื‘ืื•ืคืŸ ื‘ืœืชื™ ืฆืคื•ื™.

ื”ืืคืฉืจื•ืช ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ: ืชืขื•ื“ืช ืฉื•ืจืฉ ืคืจื˜ื™ืช ื•ื™ืขื•ื“ื™ืช ืž-CA ืฉืœ ืฆื“ ืฉืœื™ืฉื™

ืื ื ื™ื”ื•ืœ ืžืกืคืจ ืฉื•ืจืฉื™ื ืื• ืื™ืฉื•ืจื™ื ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช ืื™ื ื• ืžื•ืฉืš, ื™ืฉื ื” ืืคืฉืจื•ืช ื ื•ืกืคืช: ื”ืกืชืžื›ื•ืช ืขืœ CA ืฉืœ ืฆื“ ืฉืœื™ืฉื™. ื‘ืžืงืจื” ื–ื”, ืชืขื•ื“ื•ืช ืžื•ื ืคืงื•ืช ืž ืคืจื˜ื™ CA ื”ืžืงื•ืฉืจ ื‘ืฉืจืฉืจืช ืฉืœ ืืžื•ืŸ ืœ-CA ืฉื•ืจืฉ ื™ื™ืขื•ื“ื™ ื•ืคืจื˜ื™ ืฉื ื•ืฆืจ ื‘ืžื™ื•ื—ื“ ืขื‘ื•ืจ ื”ื—ื‘ืจื”.

DPI (ื‘ื“ื™ืงืช SSL) ื ื•ื’ื“ืช ืืช ื’ืจืขื™ืŸ ื”ื”ืฆืคื ื”, ืืš ื—ื‘ืจื•ืช ืžื™ื™ืฉืžื•ืช ื–ืืช
ืืจื›ื™ื˜ืงื˜ื•ืจื” ืคืฉื•ื˜ื” ืขื‘ื•ืจ ืื™ืฉื•ืจื™ ืฉื•ืจืฉ ื™ื™ืขื•ื“ื™ื™ื ืฉืœ ืœืงื•ื—

ื”ื’ื“ืจื” ื–ื• ืžื‘ื˜ืœืช ื—ืœืง ืžื”ื‘ืขื™ื•ืช ืฉื”ื•ื–ื›ืจื• ืงื•ื“ื: ืœืคื—ื•ืช ื”ื™ื ืžืฆืžืฆืžืช ืืช ืžืกืคืจ ื”ืฉื•ืจืฉื™ื ืฉืฆืจื™ืš ืœื ื”ืœ. ื›ืืŸ ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ืจืง ื‘ืจืฉื•ืช ืฉื•ืจืฉ ืคืจื˜ื™ืช ืื—ืช ืœื›ืœ ืฆืจื›ื™ ื”-PKI ื”ืคื ื™ืžื™ื™ื, ืขื ื›ืœ ืžืกืคืจ ืฉืœ CAs ื‘ื™ื ื™ื™ื. ืœื“ื•ื’ืžื”, ื”ื“ื™ืื’ืจืžื” ืฉืœืžืขืœื” ืžืฆื™ื’ื” ื”ื™ืจืจื›ื™ื” ืžืจื•ื‘ืช ืจืžื•ืช ืฉื‘ื” ืื—ื“ ืž-CAs ื”ื‘ื™ื ื™ื™ื ืžืฉืžืฉ ืœืื™ืžื•ืช/ืคืขื ื•ื— SSL ื•ื”ืฉื ื™ ืžืฉืžืฉ ืœืžื—ืฉื‘ื™ื ืคื ื™ืžื™ื™ื (ืžื—ืฉื‘ื™ื ื ื™ื™ื“ื™ื, ืฉืจืชื™ื, ืฉื•ืœื—ื ื•ืช ืขื‘ื•ื“ื” ื•ื›ื•').

ื‘ืขื™ืฆื•ื‘ ื–ื”, ืื™ืŸ ืฆื•ืจืš ืœืืจื— CA ื‘ื›ืœ ื”ืœืงื•ื—ื•ืช ืžื›ื™ื•ื•ืŸ ืฉื”-CA ื‘ืจืžื” ื”ืขืœื™ื•ื ื” ืžืชืืจื— ืขืœ ื™ื“ื™ GlobalSign, ืืฉืจ ืคื•ืชืจ ื‘ืขื™ื•ืช ื”ื’ื ืช ืžืคืชื— ืคืจื˜ื™ ื•ืชืคื•ื’ื”.

ื™ืชืจื•ืŸ ื ื•ืกืฃ ืฉืœ ื’ื™ืฉื” ื–ื• ื”ื•ื ื”ื™ื›ื•ืœืช ืœืฉืœื•ืœ ืืช ืกืžื›ื•ืช ื‘ื“ื™ืงืช ื”-SSL ืžื›ืœ ืกื™ื‘ื” ืฉื”ื™ื. ื‘ืžืงื•ื ื–ืืช, ืคืฉื•ื˜ ื ื•ืฆืจ ืื—ื“ ื—ื“ืฉ, ืฉืงืฉื•ืจ ืœืฉื•ืจืฉ ื”ืคืจื˜ื™ ื”ืžืงื•ืจื™ ืฉืœืš, ื•ืชื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ื• ืžื™ื“.

ืœืžืจื•ืช ื›ืœ ื”ืžื—ืœื•ืงืช, ืืจื’ื•ื ื™ื ืžื™ื™ืฉืžื™ื ื™ื•ืชืจ ื•ื™ื•ืชืจ ื‘ื“ื™ืงืช ืชืขื‘ื•ืจืช SSL ื›ื—ืœืง ืžืชืฉืชื™ืช ื”-PKI ื”ืคื ื™ืžื™ืช ืื• ื”ืคืจื˜ื™ืช ืฉืœื”ื. ืฉื™ืžื•ืฉื™ื ื ื•ืกืคื™ื ืขื‘ื•ืจ PKI ืคืจื˜ื™ื™ื ื›ื•ืœืœื™ื ื”ื ืคืงืช ืื™ืฉื•ืจื™ื ืœืื™ืžื•ืช ืžื›ืฉื™ืจ ืื• ืžืฉืชืžืฉ, SSL ืขื‘ื•ืจ ืฉืจืชื™ื ืคื ื™ืžื™ื™ื ื•ืชืฆื•ืจื•ืช ืฉื•ื ื•ืช ืฉืื™ื ืŸ ืžื•ืชืจื•ืช ื‘ืชืขื•ื“ื•ืช ืžื”ื™ืžื ื•ืช ืฆื™ื‘ื•ืจื™ื•ืช ื›ื ื“ืจืฉ ืขืœ ื™ื“ื™ ืคื•ืจื•ื ื”-CA/ื“ืคื“ืคืŸ.

ื”ื“ืคื“ืคื ื™ื ื ืœื—ืžื™ื ื‘ื—ื–ืจื”

ื™ืฉ ืœืฆื™ื™ืŸ ืฉืžืคืชื—ื™ ื“ืคื“ืคื ื™ื ืžื ืกื™ื ืœื”ืชืžื•ื“ื“ ืขื ืžื’ืžื” ื–ื• ื•ืœื”ื’ืŸ ืขืœ ืžืฉืชืžืฉื™ ื”ืงืฆื” ืžืคื ื™ MiTM. ืœืžืฉืœ, ืœืคื ื™ ื›ืžื” ื™ืžื™ื ืžื•ื–ื™ืœื” ืงื™ื‘ืœ ื”ื—ืœื˜ื” ื”ืคืขืœ ืคืจื•ื˜ื•ืงื•ืœ DoH (DNS-over-HTTPS) ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืื—ืช ืžื’ืจืกืื•ืช ื”ื“ืคื“ืคืŸ ื”ื‘ืื•ืช ื‘ืคื™ื™ืจืคื•ืงืก. ืคืจื•ื˜ื•ืงื•ืœ DoH ืžืกืชื™ืจ ืฉืื™ืœืชื•ืช DNS ืžืžืขืจื›ืช DPI, ืžื” ืฉืžืงืฉื” ืขืœ ื‘ื“ื™ืงืช SSL.

ืขืœ ืชื•ื›ื ื™ื•ืช ื“ื•ืžื•ืช 10 ื‘ืกืคื˜ืžื‘ืจ 2019 ื”ื•ื›ืจื– ื’ื•ื’ืœ ืขื‘ื•ืจ ื“ืคื“ืคืŸ ื›ืจื•ื.

DPI (ื‘ื“ื™ืงืช SSL) ื ื•ื’ื“ืช ืืช ื’ืจืขื™ืŸ ื”ื”ืฆืคื ื”, ืืš ื—ื‘ืจื•ืช ืžื™ื™ืฉืžื•ืช ื–ืืช

ืจืง ืžืฉืชืžืฉื™ื ืจืฉื•ืžื™ื ื™ื›ื•ืœื™ื ืœื”ืฉืชืชืฃ ื‘ืกืงืจ. ืœื”ืชื—ื‘ืจื‘ื‘ืงืฉื”.

ื”ืื ืœื“ืขืชืš ื™ืฉ ืœื—ื‘ืจื” ืืช ื”ื–ื›ื•ืช ืœื‘ื“ื•ืง ืืช ืชืขื‘ื•ืจืช ื”-SSL ืฉืœ ืขื•ื‘ื“ื™ื”?

  • ื›ืŸ, ื‘ื”ืกื›ืžืชื

  • ืœื, ื‘ืงืฉืช ื”ืกื›ืžื” ื›ื–ื• ื”ื™ื ื‘ืœืชื™ ื—ื•ืงื™ืช ื•/ืื• ืœื ืืชื™ืช

122 ืžืฉืชืžืฉื™ื ื”ืฆื‘ื™ืขื•. 15 ืžืฉืชืžืฉื™ื ื ืžื ืขื•.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”