IETF ืžืื•ืฉืจ ACME - ื–ื”ื• ืชืงืŸ ืœืขื‘ื•ื“ื” ืขื ืชืขื•ื“ื•ืช SSL

IETF ืื•ืฉืจ ัั‚ะฐะฝะดะฐั€ั‚ ืกื‘ื™ื‘ืช ื ื™ื”ื•ืœ ืชืขื•ื“ื•ืช ืื•ื˜ื•ืžื˜ื™ืช (ACME), ืฉืชืขื–ื•ืจ ืœื”ืคื•ืš ืืช ืงื‘ืœืช ืชืขื•ื“ื•ืช SSL ืœืื•ื˜ื•ืžื˜ื™ื•ืช. ื‘ื•ืื• ื ืกืคืจ ืœื›ื ืื™ืš ื–ื” ืขื•ื‘ื“.

IETF ืžืื•ืฉืจ ACME - ื–ื”ื• ืชืงืŸ ืœืขื‘ื•ื“ื” ืขื ืชืขื•ื“ื•ืช SSL
/flickr/ ืงืœื™ืฃ ื’'ื•ื ืกื•ืŸ / CC BY-SA

ืžื“ื•ืข ื”ื™ื” ืฆื•ืจืš ื‘ืชืงืŸ?

ืžืžื•ืฆืข ืœื›ืœ ื”ื’ื“ืจื” ืชืขื•ื“ืช SSL ืขื‘ื•ืจ ื“ื•ืžื™ื™ืŸ, ื”ืžื ื”ืœ ื™ื›ื•ืœ ืœื‘ืœื•ืช ื‘ื™ืŸ ืฉืขื” ืœืฉืœื•ืฉ ืฉืขื•ืช. ืื ืชื˜ืขื•, ืชืฆื˜ืจื›ื• ืœื”ืžืชื™ืŸ ืขื“ ืœื“ื—ื™ื™ืช ื”ื‘ืงืฉื” ื•ืจืง ืœืื—ืจ ืžื›ืŸ ื ื™ืชืŸ ื™ื”ื™ื” ืœื”ื’ื™ืฉ ืื•ืชื” ืฉื•ื‘. ื›ืœ ื–ื” ืžืงืฉื” ืขืœ ืคืจื™ืกืช ืžืขืจื›ื•ืช ื‘ืงื ื” ืžื™ื“ื” ื’ื“ื•ืœ.

ื”ืœื™ืš ืื™ืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ืขื‘ื•ืจ ื›ืœ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืขืฉื•ื™ ืœื”ื™ื•ืช ืฉื•ื ื”. ื—ื•ืกืจ ืกื˜ื ื“ืจื˜ื™ื–ืฆื™ื” ืžื•ื‘ื™ืœ ืœืคืขืžื™ื ืœื‘ืขื™ื•ืช ืื‘ื˜ื—ื”. ืžืคื•ืจืกื ืžืงืจื”ื›ืืฉืจ, ืขืงื‘ ื‘ืื’ ื‘ืžืขืจื›ืช, CA ืื—ื“ ืื™ืžืช ืืช ื›ืœ ื”ื“ื•ืžื™ื™ื ื™ื ื”ืžื•ืฆื”ืจื™ื. ื‘ืžืฆื‘ื™ื ื›ืืœื”, ืื™ืฉื•ืจื™ SSL ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ืžื•ื ืคืงื™ื ืœืžืฉืื‘ื™ื ื”ื•ื ืื”.

ืคืจื•ื˜ื•ืงื•ืœ ACME ืžืื•ืฉืจ ืขืœ ื™ื“ื™ IETF (ืžืคืจื˜ RFC8555) ืฆืจื™ืš ืœื”ืคื•ืš ืœืื•ื˜ื•ืžื˜ื™ ื•ืœืชืงืŸ ืืช ืชื”ืœื™ืš ืงื‘ืœืช ื”ืื™ืฉื•ืจ. ื•ื‘ื™ื˜ื•ืœ ื”ื’ื•ืจื ื”ืื ื•ืฉื™ ื™ืขื–ื•ืจ ืœื”ื’ื‘ื™ืจ ืืช ื”ืžื”ื™ืžื ื•ืช ื•ื”ืื‘ื˜ื—ื” ืฉืœ ืื™ืžื•ืช ืฉื ื”ื“ื•ืžื™ื™ืŸ.

ื”ืชืงืŸ ืคืชื•ื— ื•ื›ืœ ืื—ื“ ื™ื›ื•ืœ ืœืชืจื•ื ืœืคื™ืชื•ื—ื•. IN ืžืื’ืจื™ื ื‘- GitHub ื”ื•ืจืื•ืช ืจืœื•ื•ื ื˜ื™ื•ืช ืคื•ืจืกืžื•.

ืึตื™ืš ืžึทืคืขึดื™ืœึดื™ื ืึถืช ื–ึถื”

ื‘ืงืฉื•ืช ืžื•ื—ืœืคื•ืช ื‘-ACME ื“ืจืš HTTPS ื‘ืืžืฆืขื•ืช ื”ื•ื“ืขื•ืช JSON. ื›ื“ื™ ืœืขื‘ื•ื“ ืขื ื”ืคืจื•ื˜ื•ืงื•ืœ, ืขืœื™ืš ืœื”ืชืงื™ืŸ ืืช ืœืงื•ื— ACME ื‘ืฆื•ืžืช ื”ื™ืขื“; ื”ื•ื ื™ื•ืฆืจ ื–ื•ื’ ืžืคืชื—ื•ืช ื™ื™ื—ื•ื“ื™ ื‘ืคืขื ื”ืจืืฉื•ื ื” ืฉืืชื” ื ื™ื’ืฉ ืœ-CA. ืœืื—ืจ ืžื›ืŸ, ื”ื ื™ืฉืžืฉื• ืœื—ืชื™ืžื” ืขืœ ื›ืœ ื”ื”ื•ื“ืขื•ืช ืžื”ืœืงื•ื— ื•ืžื”ืฉืจืช.

ื”ื”ื•ื“ืขื” ื”ืจืืฉื•ื ื” ืžื›ื™ืœื” ืžื™ื“ืข ืœื™ืฆื™ืจืช ืงืฉืจ ืขืœ ื‘ืขืœ ื”ื“ื•ืžื™ื™ืŸ. ื”ื•ื ื ื—ืชื ืขื ื”ืžืคืชื— ื”ืคืจื˜ื™ ื•ื ืฉืœื— ืœืฉืจืช ื™ื—ื“ ืขื ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™. ื”ื•ื ืžื•ื•ื“ื ืืช ื”ืื•ืชื ื˜ื™ื•ืช ืฉืœ ื”ื—ืชื™ืžื”, ื•ืื ื”ื›ืœ ืชืงื™ืŸ, ืžืชื—ื™ืœ ืืช ื”ื”ืœื™ืš ืœื”ื ืคืงืช ืชืขื•ื“ืช SSL.

ื›ื“ื™ ืœืงื‘ืœ ืื™ืฉื•ืจ, ืขืœ ื”ืœืงื•ื— ืœื”ื•ื›ื™ื— ืœืฉืจืช ืฉื”ื•ื ื”ื‘ืขืœื™ื ืฉืœ ื”ื“ื•ืžื™ื™ืŸ. ืœืฉื ื›ืš, ื”ื•ื ืžื‘ืฆืข ืคืขื•ืœื•ืช ืžืกื•ื™ืžื•ืช ื”ื–ืžื™ื ื•ืช ืจืง ืœื‘ืขืœื™ื. ืœื“ื•ื’ืžื”, ืจืฉื•ืช ืื™ืฉื•ืจื™ื ื™ื›ื•ืœื” ืœื™ืฆื•ืจ ืืกื™ืžื•ืŸ ื™ื™ื—ื•ื“ื™ ื•ืœื‘ืงืฉ ืžื”ืœืงื•ื— ืœืžืงื ืื•ืชื• ื‘ืืชืจ. ืœืื—ืจ ืžื›ืŸ, ื”-CA ืžื•ืฆื™ื ืฉืื™ืœืชืช ืื™ื ื˜ืจื ื˜ ืื• DNS ื›ื“ื™ ืœืื—ื–ืจ ืืช ื”ืžืคืชื— ืžืืกื™ืžื•ืŸ ื–ื”.

ืœื“ื•ื’ืžื”, ื‘ืžืงืจื” ืฉืœ HTTP, ื”ืžืคืชื— ืžื”ืืกื™ืžื•ืŸ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืžื•ืงื ื‘ืงื•ื‘ืฅ ืฉื™ื•ื’ืฉ ืขืœ ื™ื“ื™ ืฉืจืช ื”ืื™ื ื˜ืจื ื˜. ื‘ืžื”ืœืš ืื™ืžื•ืช DNS, ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื ืชื—ืคืฉ ืžืคืชื— ื™ื™ื—ื•ื“ื™ ื‘ืžืกืžืš ื”ื˜ืงืกื˜ ืฉืœ ืจืฉื•ืžืช ื”-DNS. ืื ื”ื›ืœ ื‘ืกื“ืจ, ื”ืฉืจืช ืžืืฉืจ ืฉื”ืœืงื•ื— ืขื‘ืจ ืื™ืžื•ืช ื•ื”-CA ืžื ืคื™ืง ืื™ืฉื•ืจ.

IETF ืžืื•ืฉืจ ACME - ื–ื”ื• ืชืงืŸ ืœืขื‘ื•ื“ื” ืขื ืชืขื•ื“ื•ืช SSL
/flickr/ ื‘ืœื•ื ื“ื™ื ืจื™ืงืืจื“ ืคืจื•ื‘ืจื’ / CC BY

ื“ืขื•ืช

ืขืœ ืขืœ ืคื™ IETF, ACME ื™ื”ื™ื• ืฉื™ืžื•ืฉื™ื™ื ืขื‘ื•ืจ ืžื ื”ืœื™ ืžืขืจื›ืช ืฉืฆืจื™ื›ื™ื ืœืขื‘ื•ื“ ืขื ืžืกืคืจ ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ. ื”ืชืงืŸ ื™ืขื–ื•ืจ ืœืงืฉืจ ื›ืœ ืื—ื“ ืžื”ื ืœ-SSLs ื”ื ื“ืจืฉื™ื.

ื‘ื™ืŸ ื”ื™ืชืจื•ื ื•ืช ืฉืœ ื”ืชืงืŸ, ืžื•ืžื—ื™ื ืžืฆื™ื™ื ื™ื ื’ื ื›ืžื” ืžื ื’ื ื•ื ื™ ืื‘ื˜ื—ื”. ืขืœื™ื”ื ืœื•ื•ื“ื ืฉืชืขื•ื“ื•ืช SSL ืžื•ื ืคืงื•ืช ืจืง ืœื‘ืขืœื™ ื“ื•ืžื™ื™ืŸ ืืžื™ืชื™ื™ื. ื‘ืคืจื˜, ืงื‘ื•ืฆื” ืฉืœ ื”ืจื—ื‘ื•ืช ืžืฉืžืฉืช ืœื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช DNS DNSSEC, ื•ื›ื“ื™ ืœื”ื’ืŸ ืžืคื ื™ DoS, ื”ืชืงืŸ ืžื’ื‘ื™ืœ ืืช ืžื”ื™ืจื•ืช ื”ื‘ื™ืฆื•ืข ืฉืœ ื‘ืงืฉื•ืช ื‘ื•ื“ื“ื•ืช - ืœื“ื•ื’ืžื”, HTTP ืขื‘ื•ืจ ื”ืฉื™ื˜ื” POST. ืžืคืชื—ื™ ACME ืขืฆืžื ืœื”ืžืœื™ืฅ ื›ื“ื™ ืœืฉืคืจ ืืช ื”ืื‘ื˜ื—ื”, ื”ื•ืกืฃ ืื ื˜ืจื•ืคื™ื” ืœืฉืื™ืœืชื•ืช DNS ื•ื”ืคืขืœ ืื•ืชืŸ ืžืžืกืคืจ ื ืงื•ื“ื•ืช ื‘ืจืฉืช.

ืคืชืจื•ื ื•ืช ื“ื•ืžื™ื

ืคืจื•ื˜ื•ืงื•ืœื™ื ืžืฉืžืฉื™ื ื’ื ืœื”ืฉื’ืช ืื™ืฉื•ืจื™ื SCEP ะธ EST.

ื”ืจืืฉื•ืŸ ืคื•ืชื— ื‘-Cisco Systems. ืžื˜ืจืชื• ื”ื™ื™ืชื” ืœืคืฉื˜ ืืช ื”ืœื™ืš ื”ื ืคืงืช ืชืขื•ื“ื•ืช X.509 ื“ื™ื’ื™ื˜ืœื™ื•ืช ื•ืœื”ืคื•ืš ืื•ืชื• ืœื“ืจื’ืชื™ ื›ื›ืœ ื”ืืคืฉืจ. ืœืคื ื™ SCEP, ืชื”ืœื™ืš ื–ื” ื”ืฆืจื™ืš ื”ืฉืชืชืคื•ืช ืคืขื™ืœื” ืฉืœ ืžื ื”ืœื™ ืžืขืจื›ืช ื•ืœื ื”ื•ื’ื“ืœ ื”ื™ื˜ื‘. ื›ื™ื•ื ืคืจื•ื˜ื•ืงื•ืœ ื–ื” ื”ื•ื ืื—ื“ ื”ื ืคื•ืฆื™ื ื‘ื™ื•ืชืจ.

ื‘ืืฉืจ ืœ-EST, ื–ื” ืžืืคืฉืจ ืœืœืงื•ื—ื•ืช PKI ืœืงื‘ืœ ืื™ืฉื•ืจื™ื ื‘ืขืจื•ืฆื™ื ืžืื•ื‘ื˜ื—ื™ื. ื”ื•ื ืžืฉืชืžืฉ ื‘-TLS ืœื”ืขื‘ืจืช ื”ื•ื“ืขื•ืช ื•ื”ื ืคืงืช SSL, ื›ืžื• ื’ื ื›ื“ื™ ืœืื’ื“ ืืช ื”-CSR ืœืฉื•ืœื—. ื‘ื ื•ืกืฃ, EST ืชื•ืžืš ื‘ืฉื™ื˜ื•ืช ื”ืฆืคื ื” ืืœื™ืคื˜ื™ื•ืช, ืžื” ืฉื™ื•ืฆืจ ืฉื›ื‘ืช ืื‘ื˜ื—ื” ื ื•ืกืคืช.

ืขืœ ื“ืขืช ืžื•ืžื—ื”, ืคืชืจื•ื ื•ืช ื›ืžื• ACME ื™ืฆื˜ืจื›ื• ืœื”ื™ื•ืช ื ืคื•ืฆื™ื ื™ื•ืชืจ. ื”ื ืžืฆื™ืขื™ื ืžื•ื“ืœ ื”ื’ื“ืจืช SSL ืคืฉื•ื˜ ื•ืžืื•ื‘ื˜ื— ื•ื’ื ืžืื™ืฆื™ื ืืช ื”ืชื”ืœื™ืš.

ืคื•ืกื˜ื™ื ื ื•ืกืคื™ื ืžื”ื‘ืœื•ื’ ื”ืืจื’ื•ื ื™ ืฉืœื ื•:

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”