ืคื•ืจื•ื CA/B ื”ืฆื‘ื™ืข ื ื’ื“ ืฆืžืฆื•ื ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ืชืขื•ื“ื•ืช SSL ืœ-397 ื™ืžื™ื

26 ื‘ื™ื•ืœื™ 2019 Google ื”ืฆื™ืข ื”ืฆืขื” ืœื”ืคื—ื™ืช ืืช ืชืงื•ืคืช ื”ืชื•ืงืฃ ื”ืžืงืกื™ืžืœื™ืช ืฉืœ ืื™ืฉื•ืจื™ ืฉืจืช SSL/TLS ืž-825 ื”ื™ืžื™ื ื”ื ื•ื›ื—ื™ื™ื ืœ-397 ื™ืžื™ื (ื›-13 ื—ื•ื“ืฉื™ื), ื›ืœื•ืžืจ ื‘ื›ืžื—ืฆื™ืช. ื’ื•ื’ืœ ืžืืžื™ื ื” ืฉืจืง ืื•ื˜ื•ืžืฆื™ื” ืžืœืื” ืฉืœ ืคืขื•ืœื•ืช ืขื ืชืขื•ื“ื•ืช ืชืคื˜ืจ ืžื‘ืขื™ื•ืช ื”ืื‘ื˜ื—ื” ื”ื ื•ื›ื—ื™ื•ืช, ืฉืžื™ื•ื—ืกื•ืช ืœืจื•ื‘ ืœื’ื•ืจืžื™ื ืื ื•ืฉื™ื™ื. ืœื›ืŸ, ื‘ืื•ืคืŸ ืื™ื“ื™ืืœื™, ื™ืฉ ืœืฉืื•ืฃ ืœื”ื ืคืงื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืชืขื•ื“ื•ืช ืงืฆืจื•ืช ืžื•ืขื“.

ื”ื ื•ืฉื ื”ื•ื‘ื ืœื”ืฆื‘ืขื” ื‘ืคื•ืจื•ื CA/ื“ืคื“ืคืŸ (CABF), ื”ืงื•ื‘ืข ื“ืจื™ืฉื•ืช ืœืชืขื•ื“ื•ืช SSL/TLS, ื›ื•ืœืœ ืชืงื•ืคืช ื”ืชื•ืงืฃ ื”ืžืงืกื™ืžืœื™ืช.

ื•ืื– 10 ื‘ืกืคื˜ืžื‘ืจ ืชื•ืฆืื•ืช ืฉื”ื•ื›ืจื–ื•: ื—ื‘ืจื™ ื”ืงื•ื ืกื•ืจืฆื™ื•ื ื”ืฆื‘ื™ืขื• ะฟั€ะพั‚ะธะฒ ื”ืฆืขื•ืช.

ืžืžืฆืื™ื

ื”ืฆื‘ืขื” ืฉืœ ืžื ืคื™ืง ืชืขื•ื“ื”

ื‘ืขื“ (11 ืงื•ืœื•ืช): Amazon, Buypass, Certigna (DHIMYOTIS), certSIGN, Sectigo (ืœืฉืขื‘ืจ Comodo CA), eMudhra, Kamu SM, Let's Encrypt, Logius, PKIoverheid, SHECA, SSL.com

ื ื’ื“ (20): Camerfirma, Certum (Asseco), CFCA, Chunghwa Telecom, Comsign, D-TRUST, DarkMatter, Entrust Datacard, Firmaprofesional, GDCA, GlobalSign, GoDaddy, Izenpe, Network Solutions, OATI, SECOM, SwissSign, TWCA, TrustCor, SecureTrust (ืœืฉืขื‘ืจ Trustwave)

ื ืžื ืข (2): HARICA, TurkTrust

ื”ืฆื‘ืขืช ืฆืจื›ื ื™ ืชืขื•ื“ื”

ืขื‘ื•ืจ (7): ืืคืœ, ืกื™ืกืงื•, ื’ื•ื’ืœ, ืžื™ืงืจื•ืกื•ืคื˜, ืžื•ื–ื™ืœื”, ืื•ืคืจื”, 360

ื ื’ื“: 0

ื ืžื ืข: 0

ืขืœ ืคื™ ื›ืœืœื™ CA/ืคื•ืจื•ื ื“ืคื“ืคืŸ, ืชืขื•ื“ื” ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ืžืื•ืฉืจืช ืขืœ ื™ื“ื™ ืฉื ื™ ืฉืœื™ืฉื™ื ืžืžื ืคื™ืงื™ ื”ืชืขื•ื“ื” ื•-50% ืคืœื•ืก ืงื•ืœ ืื—ื“ ื‘ืงืจื‘ ื”ืฆืจื›ื ื™ื.

ื ืฆื™ื’ื™ Digicert ื”ืชื ืฆืœ ืขืœ ื“ื™ืœื•ื’ ืขืœ ื”ื”ืฆื‘ืขื”, ืฉื ื”ื™ื• ืžืฆื‘ื™ืขื™ื ื‘ืขื“ ืงื™ืฆื•ืจ ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ื”ืชืขื•ื“ื•ืช. ื”ื ืžืฆื™ื™ื ื™ื ืฉืขื‘ื•ืจ ื—ืœืง ืžื”ืœืงื•ื—ื•ืช, ืžืฉืš ื”ื–ืžืŸ ื”ืงืฆืจ ื™ื•ืชืจ ืขืฉื•ื™ ืœื”ื•ื•ืช ื‘ืขื™ื”, ืื‘ืœ ื™ืฉ ื™ืชืจื•ื ื•ืช ืื‘ื˜ื—ื” ืœื˜ื•ื•ื— ืืจื•ืš.

ื›ืš ืื• ืื—ืจืช, ื”ืชืขืฉื™ื™ื” ืขื“ื™ื™ืŸ ืœื ืžื•ื›ื ื” ืœืงืฆืจ ืืช ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ื”ืชืขื•ื“ื•ืช ื•ืœืขื‘ื•ืจ ืœื—ืœื•ื˜ื™ืŸ ืœืคืชืจื•ื ื•ืช ืื•ื˜ื•ืžื˜ื™ื™ื. ืจืฉื•ื™ื•ืช ื”ืื™ืฉื•ืจื™ื ืขืฆืžืŸ ื™ื›ื•ืœื•ืช ืœื”ืฆื™ืข ืฉื™ืจื•ืชื™ื ื›ืืœื”, ืืš ืœืงื•ื—ื•ืช ืจื‘ื™ื ื˜ืจื ื™ื™ืฉืžื• ืื•ื˜ื•ืžืฆื™ื”. ืœืคื™ื›ืš, ืงื™ืฆื•ืจ ื”ืžื•ืขื“ ืœ-397 ื™ืžื™ื ื ื“ื—ื” ืœืขืช ืขืชื”. ืื‘ืœ ื”ืฉืืœื” ื ืฉืืจืช ืคืชื•ื—ื”.

ื›ืขืช ื’ื•ื’ืœ ืขืฉื•ื™ื” ืœื ืกื•ืช ืœื™ื™ืฉื ืืช ื”ืชืงืŸ "ื‘ื›ื•ื—", ื›ืคื™ ืฉืขืฉืชื” ืขื ื”ืคืจื•ื˜ื•ืงื•ืœ ืฉืงื™ืคื•ืช ืชืขื•ื“ื”. ื™ืชืจ ืขืœ ื›ืŸ, ื”ื•ื ื ืชืžืš ื’ื ืขืœ ื™ื“ื™ ืžืคืชื—ื™ื ืื—ืจื™ื: ืืคืœ, ืžื™ืงืจื•ืกื•ืคื˜, ืžื•ื–ื™ืœื” ื•ืื•ืคืจื”.

ื‘ื•ืื• ื ื–ื›ื•ืจ ื›ื™ ืื•ื˜ื•ืžืฆื™ื” ืžืœืื” ื”ื™ื ืื—ื“ ื”ืขืงืจื•ื ื•ืช ืฉืขืœื™ื”ื ืžื‘ื•ืกืกืช ืขื‘ื•ื“ืช ืžืจื›ื– ื”ื”ืกืžื›ื” ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— Let's Encrypt. ื”ื™ื ืžื ืคื™ืงื” ืชืขื•ื“ื•ืช ื‘ื—ื™ื ื ืœื›ื•ืœื, ืืš ืชื•ื—ืœืช ื”ื—ื™ื™ื ื”ืžืงืกื™ืžืœื™ืช ืฉืœ ืชืขื•ื“ื” ืžื•ื’ื‘ืœืช ืœ-90 ื™ื•ื. ืœืชืขื•ื“ื•ืช ืื•ืจืš ื—ื™ื™ื ืงืฆืจ ืฉื ื™ ื™ืชืจื•ื ื•ืช ืขื™ืงืจื™ื™ื:

  1. ื”ื’ื‘ืœืช ื”ื ื–ืง ืžืžืคืชื—ื•ืช ืฉื ืคื’ืขื• ื•ืชืขื•ื“ื•ืช ืฉื”ื•ื ืคืงื• ื‘ืฆื•ืจื” ืฉื’ื•ื™ื”, ืžืื—ืจ ืฉื”ืฉื™ืžื•ืฉ ื‘ื”ื ื ืขืฉื” ืขืœ ืคื ื™ ืคืจืง ื–ืžืŸ ืงืฆืจ ื™ื•ืชืจ;
  2. ืื™ืฉื•ืจื™ื ืงืฆืจื™ ืžื•ืขื“ ืชื•ืžื›ื™ื ื•ืžืขื•ื“ื“ื™ื ืื•ื˜ื•ืžืฆื™ื”, ืฉื”ื™ื ื”ื›ืจื—ื™ืช ืœื—ืœื•ื˜ื™ืŸ ืœืงืœื•ืช ื”ืฉื™ืžื•ืฉ ื‘-HTTPS. ืื ืื ื—ื ื• ืžืชื›ื•ื•ื ื™ื ืœื”ืขื‘ื™ืจ ืืช ื›ืœ ื”-World Wide Web ืœ-HTTPS, ืื– ืœื ื ื•ื›ืœ ืœืฆืคื•ืช ืžื”ืžื ื”ืœ ืฉืœ ื›ืœ ืืชืจ ืงื™ื™ื ืœืขื“ื›ืŸ ืื™ืฉื•ืจื™ื ื‘ืื•ืคืŸ ื™ื“ื ื™. ื‘ืจื’ืข ืฉื”ื ืคืงืช ื•ื—ื™ื“ื•ืฉื™ ื”ืชืขื•ื“ื” ื”ื•ืคื›ื™ื ืœืื•ื˜ื•ืžื˜ื™ื™ื ืœื—ืœื•ื˜ื™ืŸ, ืชืงื•ืคื•ืช ื—ื™ื™ื ืงืฆืจื•ืช ื™ื•ืชืจ ืฉืœ ืชืขื•ื“ื•ืช ื™ื”ืคื›ื• ืœื ื•ื—ื™ื ื•ืžืขืฉื™ื™ื ื™ื•ืชืจ.

ืกืงืจ GlobalSign ืขืœ Habrรฉ ื”ืจืื” ื›ื™ 73,7% ืžื”ื ืฉืืœื™ื "ื“ื•ื•ืงื ืชื•ืžื›ื™ื" ื‘ืงื™ืฆื•ืจ ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ื”ืชืขื•ื“ื•ืช.

ื‘ืืฉืจ ืœื”ืกืชืจืช ืกืžืœ ื”-EV ืขื‘ื•ืจ ืชืขื•ื“ื•ืช SSL ื‘ืฉื•ืจืช ื”ื›ืชื•ื‘ืช, ื”ืงื•ื ืกื•ืจืฆื™ื•ื ืœื ื”ืฆื‘ื™ืข ื‘ื ื•ืฉื ื–ื”, ืžื›ื™ื•ื•ืŸ ืฉื ื•ืฉื ืžืžืฉืง ื”ืžืฉืชืžืฉ ืฉืœ ื”ื“ืคื“ืคืŸ ื ืžืฆื ืœื—ืœื•ื˜ื™ืŸ ื‘ืกืžื›ื•ืชื ืฉืœ ื”ืžืคืชื—ื™ื. ื‘ืกืคื˜ืžื‘ืจ-ืื•ืงื˜ื•ื‘ืจ ื™ืฉื•ื—ืจืจื• ื’ืจืกืื•ืช ื—ื“ืฉื•ืช ืฉืœ Chrome 77 ื•-Firefox 70, ืืฉืจ ื™ืฉืœืœื• ืžืื™ืฉื•ืจื™ EV ืžืงื•ื ืžื™ื•ื—ื“ ื‘ืฉื•ืจืช ื”ื›ืชื•ื‘ืช ืฉืœ ื”ื“ืคื“ืคืŸ. ื›ืš ื ืจืื” ื”ืฉื™ื ื•ื™ ื‘ืืžืฆืขื•ืช ื’ืจืกืช ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” ืฉืœ Firefox 70 ื›ื“ื•ื’ืžื”:

ื–ื” ื”ื™ื”:

ืคื•ืจื•ื CA/B ื”ืฆื‘ื™ืข ื ื’ื“ ืฆืžืฆื•ื ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ืชืขื•ื“ื•ืช SSL ืœ-397 ื™ืžื™ื

ื™ื”ื™ื”:

ืคื•ืจื•ื CA/B ื”ืฆื‘ื™ืข ื ื’ื“ ืฆืžืฆื•ื ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ืชืขื•ื“ื•ืช SSL ืœ-397 ื™ืžื™ื

ืœื“ื‘ืจื™ ืžื•ืžื—ื” ื”ืื‘ื˜ื—ื” ื˜ืจื•ื™ ื”ืื ื˜, ื”ืกืจืช ืžื™ื“ืข EV ืžืกืจื’ืœ ื”ื›ืชื•ื‘ื•ืช ืฉืœ ื“ืคื“ืคื ื™ื ืœืžืขืฉื” ืงื•ื‘ืจ ืกื•ื’ ื–ื” ืฉืœ ืชืขื•ื“ื•ืช.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”