ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื”

ืื ื—ื ื• ืžื“ื‘ืจื™ื ืขืœ ืžื”ื™ ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœืื™ืžื•ืช ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื‘ืืžืฆืขื•ืช DNS ื•ืžื“ื•ืข ืื™ืŸ ื‘ื” ืฉื™ืžื•ืฉ ื ืจื—ื‘ ื‘ื“ืคื“ืคื ื™ื.

ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื”
/unsplash/ ืคืื•ืœื™ื•ืก ื“ืจืื’ื•ื ืืก

ืžื” ื–ื” DANE

ืจืฉื•ื™ื•ืช ืื™ืฉื•ืจื™ื (CA) ื”ืŸ ืืจื’ื•ื ื™ื ืืฉืจ ืžืื•ืจืกื™ื ืชืขื•ื“ื” ืงืจื™ืคื˜ื•ื’ืจืคื™ืช ืชืขื•ื“ื•ืช SSL. ื”ื ืฉืžื• ืขืœื™ื”ื ืืช ื”ื—ืชื™ืžื” ื”ืืœืงื˜ืจื•ื ื™ืช ืฉืœื”ื, ื”ืžืืฉืจื™ื ืืช ื”ืื•ืชื ื˜ื™ื•ืช ืฉืœื”ื. ืขื ื–ืืช, ืœืคืขืžื™ื ื ื•ืฆืจื™ื ืžืฆื‘ื™ื ืฉื‘ื”ื ืžื•ื ืคืงื™ื ืชืขื•ื“ื•ืช ืขื ื”ืคืจื•ืช. ืœื“ื•ื’ืžื”, ื‘ืฉื ื” ืฉืขื‘ืจื” ื’ื•ื’ืœ ื™ื–ืžื” "ื”ืœื™ืš ืฉืœ ืื™-ืืžื•ืŸ" ืขื‘ื•ืจ ืื™ืฉื•ืจื™ ืกื™ืžื ื˜ืง ืขืงื‘ ื”ืคืฉืจื” ืฉืœื”ื (ืกื™ืงืจื ื• ืืช ื”ืกื™ืคื•ืจ ื”ื–ื” ื‘ืคื™ืจื•ื˜ ื‘ื‘ืœื•ื’ ืฉืœื ื• - ื–ืžืŸ ะธ ะดะฒะฐ).

ื›ื“ื™ ืœืžื ื•ืข ืžืฆื‘ื™ื ื›ืืœื”, ืœืคื ื™ ืžืกืคืจ ืฉื ื™ื ื”-IETF ื”ืชื—ื™ืœ ืœื”ืชืคืชื— ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE (ืื‘ืœ ื”ื™ื ืœื ื ืžืฆืืช ื‘ืฉื™ืžื•ืฉ ื ืจื—ื‘ ื‘ื“ืคื“ืคื ื™ื - ื ื“ื‘ืจ ืขืœ ืœืžื” ื–ื” ืงืจื” ืžืื•ื—ืจ ื™ื•ืชืจ).

DANE (ืื™ืžื•ืช ืžื‘ื•ืกืก DNS ืฉืœ ื™ืฉื•ื™ื•ืช ืฉืžื•ืช) ื”ื•ื ืงื‘ื•ืฆื” ืฉืœ ืžืคืจื˜ื™ื ื”ืžืืคืฉืจืช ืœืš ืœื”ืฉืชืžืฉ ื‘-DNSSEC (Name System Security Extensions) ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ืชื•ืงืฃ ืฉืœ ืชืขื•ื“ื•ืช SSL. DNSSEC ื”ื™ื ื”ืจื—ื‘ื” ืœืžืขืจื›ืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ืฉืžืžื–ืขืจืช ืืช ื”ืชืงืคื•ืช ื–ื™ื•ืฃ ื›ืชื•ื‘ื•ืช. ื‘ืืžืฆืขื•ืช ืฉืชื™ ื”ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื”ืœืœื•, ืžื ื”ืœ ืืชืจื™ื ืื• ืœืงื•ื— ื™ื›ื•ืœื™ื ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืื—ื“ ืžืžืคืขื™ืœื™ ืื–ื•ืจ ื”-DNS ื•ืœืืฉืจ ืืช ืชืงืคื•ืช ื”ืื™ืฉื•ืจ ื‘ืฉื™ืžื•ืฉ.

ื‘ืขื™ืงืจื• ืฉืœ ื“ื‘ืจ, DANE ืคื•ืขืœืช ื›ืื™ืฉื•ืจ ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช (ื”ืขืจื‘ ืœืืžื™ื ื•ืชื• ื”ื•ื DNSSEC) ื•ืžืฉืœื™ื ืืช ื”ืคื•ื ืงืฆื™ื•ืช ืฉืœ CA.

ืึตื™ืš ืžึทืคืขึดื™ืœึดื™ื ืึถืช ื–ึถื”

ืžืคืจื˜ DANE ืžืชื•ืืจ ื‘ RFC6698. ืขืœ ืคื™ ื”ืžืกืžืš, ื‘ ืจืฉื•ืžื•ืช ืžืฉืื‘ื™ DNS ื ื•ืกืฃ ืกื•ื’ ื—ื“ืฉ - TLSA. ื”ื•ื ืžื›ื™ืœ ืžื™ื“ืข ืขืœ ื”ืชืขื•ื“ื” ื”ืžื•ืขื‘ืจืช, ื’ื•ื“ืœ ื•ืกื•ื’ ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื, ื›ืžื• ื’ื ื”ื ืชื•ื ื™ื ืขืฆืžื. ืžื ื”ืœ ื”ืืชืจ ื™ื•ืฆืจ ื˜ื‘ื™ืขืช ืืฆื‘ืข ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ื”ืชืขื•ื“ื”, ื—ื•ืชื ืขืœื™ื” ื‘-DNSSEC ื•ืžืฆื™ื‘ ืื•ืชื” ื‘-TLSA.

ื”ืœืงื•ื— ืžืชื—ื‘ืจ ืœืืชืจ ื‘ืื™ื ื˜ืจื ื˜ ื•ืžืฉื•ื•ื” ืืช ื”ืื™ืฉื•ืจ ืฉืœื• ืœ"ื”ืขืชืง" ืฉื”ืชืงื‘ืœ ืžืžืคืขื™ืœ ื”-DNS. ืื ื”ื ืชื•ืืžื™ื, ื”ืžืฉืื‘ ื ื—ืฉื‘ ืœืืžื™ืŸ.

ื“ืฃ ื”ื•ื•ื™ืงื™ ืฉืœ DANE ืžืกืคืง ืืช ื”ื“ื•ื’ืžื” ื”ื‘ืื” ืฉืœ ื‘ืงืฉืช DNS ืืœ example.org ื‘ื™ืฆื™ืืช TCP 443:

IN TLSA _443._tcp.example.org

ื”ืชืฉื•ื‘ื” ื ืจืื™ืช ื›ืš:

 _443._tcp.example.com. IN TLSA (
   3 0 0 30820307308201efa003020102020... )

ืœ-DANE ื™ืฉ ืžืกืคืจ ื”ืจื—ื‘ื•ืช ืฉืขื•ื‘ื“ื•ืช ืขื ืจืฉื•ืžื•ืช DNS ืžืœื‘ื“ TLSA. ื”ืจืืฉื•ืŸ ื”ื•ื ืจืฉื•ืžืช SSHFP DNS ืœืื™ืžื•ืช ืžืคืชื—ื•ืช ื‘ื—ื™ื‘ื•ืจื™ SSH. ื–ื” ืžืชื•ืืจ ื‘ RFC4255RFC6594 ะธ RFC7479. ื”ืฉื ื™ ื”ื•ื ืขืจืš OPENPGPKEY ืœื”ื—ืœืคืช ืžืคืชื—ื•ืช ื‘ืืžืฆืขื•ืช PGP (RFC7929). ืœื‘ืกื•ืฃ, ื”ืฉืœื™ืฉื™ ื”ื•ื ืจืฉื•ืžืช SMIMEA (ื”ืชืงืŸ ืื™ื ื• ืจืฉืžื™ ื‘-RFC, ื™ืฉ ืจืง ื˜ื™ื•ื˜ื” ืฉืœื•) ืœื”ื—ืœืคืช ืžืคืชื—ื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื ื‘ืืžืฆืขื•ืช S/MIME.

ืžื” ื”ื‘ืขื™ื” ืขื DANE

ื‘ืืžืฆืข ื—ื•ื“ืฉ ืžืื™ ื”ืชืงื™ื™ื ื›ื ืก DNS-OARC (ืžื“ื•ื‘ืจ ื‘ืืจื’ื•ืŸ ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— ื”ืขื•ืกืง ื‘ืื‘ื˜ื—ื”, ื™ืฆื™ื‘ื•ืช ื•ืคื™ืชื•ื— ืžืขืจื›ืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ). ืžื•ืžื—ื™ื ื‘ืื—ื“ ื”ืคืื ืœื™ื ื”ื’ื™ืข ืœืžืกืงื ื”ืฉื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ื‘ื“ืคื“ืคื ื™ื ื ื›ืฉืœื” (ืœืคื—ื•ืช ื‘ื™ื™ืฉื•ื ื”ื ื•ื›ื—ื™ ืฉืœื”). ื ื›ื— ื‘ื›ื ืก ื’'ืฃ ื™ื•ืกื˜ื•ืŸ, ืžื“ืขืŸ ืžื—ืงืจ ืžื•ื‘ื™ืœ APNIC, ืื—ื“ ืžื—ืžื™ืฉื” ืจืฉืžื™ ืื™ื ื˜ืจื ื˜ ืื–ื•ืจื™ื™ื, ื”ืฉื™ื‘ ืขืœ DANE ื›"ื˜ื›ื ื•ืœื•ื’ื™ื” ืžืชื”".

ื“ืคื“ืคื ื™ื ืคื•ืคื•ืœืจื™ื™ื ืื™ื ื ืชื•ืžื›ื™ื ื‘ืื™ืžื•ืช ืชืขื•ื“ื•ืช ื‘ืืžืฆืขื•ืช DANE. ื‘ืฉื•ืง ื™ืฉ ืชื•ืกืคื™ื ืžื™ื•ื—ื“ื™ื, ืืฉืจ ื—ื•ืฉืคื™ื ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ืจืฉื•ืžื•ืช TLSA, ืืš ื’ื ืืช ืชืžื™ื›ืชืŸ ืœื”ืคืกื™ืง ื‘ื”ื“ืจื’ื”.

ื‘ืขื™ื•ืช ื‘ื”ืคืฆืช DANE ื‘ื“ืคื“ืคื ื™ื ืงืฉื•ืจื•ืช ืœืื•ืจืš ืชื”ืœื™ืš ื”ืื™ืžื•ืช ืฉืœ DNSSEC. ื”ืžืขืจื›ืช ื ืืœืฆืช ืœื‘ืฆืข ื—ื™ืฉื•ื‘ื™ื ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื ื›ื“ื™ ืœืืฉืจ ืืช ื”ืื•ืชื ื˜ื™ื•ืช ืฉืœ ืชืขื•ื“ืช ื”-SSL ื•ืœืขื‘ื•ืจ ืืช ื›ืœ ืฉืจืฉืจืช ืฉืจืชื™ ื”-DNS (ืžืื–ื•ืจ ื”ืฉื•ืจืฉ ื•ืขื“ ืœื“ื•ืžื™ื™ืŸ ื”ืžืืจื—) ื‘ืขืช ื”ื—ื™ื‘ื•ืจ ื”ืจืืฉื•ืŸ ืœืžืฉืื‘.

ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื”
/unsplash/ ืงื™ื™ืœื™ ื“ื™ืงืกื˜ืจื”

ืžื•ื–ื™ืœื” ื ื™ืกืชื” ืœื‘ื˜ืœ ืืช ื”ื—ื™ืกืจื•ืŸ ื”ื–ื” ื‘ืืžืฆืขื•ืช ื”ืžื ื’ื ื•ืŸ ื”ืืจื›ืช ืฉืจืฉืจืช DNSSEC ืขื‘ื•ืจ TLS. ื–ื” ื”ื™ื” ืืžื•ืจ ืœื”ืคื—ื™ืช ืืช ืžืกืคืจ ืจืฉื•ืžื•ืช ื”-DNS ืฉื”ืœืงื•ื— ื”ื™ื” ืฆืจื™ืš ืœื—ืคืฉ ื‘ืžื”ืœืš ื”ืื™ืžื•ืช. ืขื ื–ืืช, ื‘ืชื•ืš ืงื‘ื•ืฆืช ื”ืคื™ืชื•ื— ื”ืชื’ืœืขื• ื—ื™ืœื•ืงื™ ื“ืขื•ืช ืฉืœื ื ื™ืชืŸ ื”ื™ื” ืœืคืชื•ืจ. ื›ืชื•ืฆืื” ืžื›ืš, ื”ืคืจื•ื™ืงื˜ ื ื–ื ื—, ืœืžืจื•ืช ืฉืื•ืฉืจ ืขืœ ื™ื“ื™ ื”-IETF ื‘ืžืจืฅ 2018.

ืกื™ื‘ื” ื ื•ืกืคืช ืœืคื•ืคื•ืœืจื™ื•ืช ื”ื ืžื•ื›ื” ืฉืœ DANE ื”ื™ื ื”ืฉื›ื™ื—ื•ืช ื”ื ืžื•ื›ื” ืฉืœ DNSSEC ื‘ืขื•ืœื - ืจืง 19% ืžื”ืžืฉืื‘ื™ื ืขื•ื‘ื“ื™ื ืื™ืชื•. ืžื•ืžื—ื™ื ืกื‘ืจื• ืฉื–ื” ืœื ืžืกืคื™ืง ื›ื“ื™ ืœืงื“ื ืืช DANE ื‘ืื•ืคืŸ ืคืขื™ืœ.

ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉื”ืชืขืฉื™ื™ื” ืชืชืคืชื— ืœื›ื™ื•ื•ืŸ ืื—ืจ. ื‘ืžืงื•ื ืœื”ืฉืชืžืฉ ื‘-DNS ืœืื™ืžื•ืช ืชืขื•ื“ื•ืช SSL/TLS, ืฉื—ืงื ื™ ื”ืฉื•ืง ื™ืงื“ืžื• ื‘ืžืงื•ื ื–ืืช ืคืจื•ื˜ื•ืงื•ืœื™ DNS-over-TLS (DoT) ื•-DNS-over-HTTPS (DoH). ื”ื–ื›ืจื ื• ืืช ื”ืื—ืจื•ืŸ ื‘ืื—ื“ ืฉืœื ื• ื—ื•ืžืจื™ื ืงื•ื“ืžื™ื ืขืœ ื”ืื‘ืจื”. ื”ื ืžืฆืคื™ื ื™ื ื•ืžืืžืชื™ื ื‘ืงืฉื•ืช ืžืฉืชืžืฉื™ื ืœืฉืจืช ื”-DNS, ื•ืžื•ื ืขื™ื ืžืชื•ืงืคื™ื ืœื–ื™ื™ืฃ ื ืชื•ื ื™ื. ื‘ืชื—ื™ืœืช ื”ืฉื ื”, DoT ื›ื‘ืจ ื”ื™ื” ืžื•ื˜ืžืข ืœ-Google ืขื‘ื•ืจ ื”-DNS ื”ืฆื™ื‘ื•ืจื™ ืฉืœื”. ื‘ืืฉืจ ืœ-DANE, ื”ืื ื”ื˜ื›ื ื•ืœื•ื’ื™ื” ืชื•ื›ืœ "ืœื—ื–ื•ืจ ืœืื•ื›ืฃ" ื•ืขื“ื™ื™ืŸ ืœื”ื™ื•ืช ื ืคื•ืฆื” ื ื•ืชืจ ืœืจืื•ืช ื‘ืขืชื™ื“.

ืžื” ืขื•ื“ ื™ืฉ ืœื ื• ืœืงืจื™ืื” ื ื•ืกืคืช:

ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” ื›ื™ืฆื“ ืœื”ืคื•ืš ืืช ื ื™ื”ื•ืœ ืชืฉืชื™ื•ืช ื”-IT ืœืื•ื˜ื•ืžื˜ื™ - ื“ื™ื•ืŸ ื‘ืฉืœื•ืฉ ืžื’ืžื•ืช
ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” JMAP - ืคืจื•ื˜ื•ืงื•ืœ ืคืชื•ื— ืฉื™ื—ืœื™ืฃ ืืช IMAP ื‘ืขืช ื”ื—ืœืคืช ืžื™ื™ืœื™ื

ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” ื›ื™ืฆื“ ืœืฉืžื•ืจ ืขื ืžืžืฉืง ืชื›ื ื•ืช ื™ื™ืฉื•ืžื™ื
ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” DevOps ื‘ืฉื™ืจื•ืช ืขื ืŸ ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ 1cloud.ru
ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” ื”ืื‘ื•ืœื•ืฆื™ื” ืฉืœ ืืจื›ื™ื˜ืงื˜ื•ืจืช ื”ืขื ืŸ 1cloud

ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” ื›ื™ืฆื“ ืคื•ืขืœืช ื”ืชืžื™ื›ื” ื”ื˜ื›ื ื™ืช ืฉืœ 1cloud?
ื™ืฉ ื“ืขื”: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช DANE ืœื“ืคื“ืคื ื™ื ื ื›ืฉืœื” ืžื™ืชื•ืกื™ื ืขืœ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืขื ืŸ

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”